Skip to content

Evidence request lists

Turkey KVKK

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach

TURKEYKVKK-7
Breach Notification and Enforcement

Per KVKK: 72-hour breach notification to KVKK Authority + affected subjects + administrative fines + criminal penalties.

Artefacts an auditor will ask for
  • KVKK evidence for TURKEYKVKK-7
Where this commonly fails
  • VERBIS + 2024 amendments + 72hr breach partial

Cross-Border

TURKEYKVKK-5
Cross-Border Transfer (Pre-2024 vs 2024 Amendments)

Per KVKK Article 9 + 2024 amendments: Cross Border Data Transfers including adequacy + safeguards (SCCs + BCRs + AppropriateGarantor) + derogations + explicit consent.

Artefacts an auditor will ask for
  • KVKK evidence for TURKEYKVKK-5
Where this commonly fails
  • VERBIS + 2024 amendments + 72hr breach partial

Governance

TURKEYKVKK-6
DPO + Governance

Per KVKK + Turkey: DPO + KVKK Authority cooperation + training + records.

Artefacts an auditor will ask for
  • KVKK evidence for TURKEYKVKK-6
Where this commonly fails
  • VERBIS + 2024 amendments + 72hr breach partial

KVKK Article 12: Security of Processing

KVKK-Art12
Data Security Obligations

Controllers must take all necessary technical and organisational measures to prevent unlawful processing, unlawful access, and to ensure data preservation. Must conduct audits, ensure processor compliance, and notify the KVKK Board and affected data subjects of breaches within reasonable period (72 hours per Board guidance).

Artefacts an auditor will ask for
  • Technical and organisational measures register
  • Information security policy in Turkish
  • Encryption, access control, logging evidence
  • Breach notification procedure with 72-hour target
  • Breach notification forms filed with KVKK
Where this commonly fails
  • No documented TOMs aligned to KVKK Board adequate measures list
  • Breach notifications delayed beyond 72 hours
  • No periodic security audits
  • Processor audits not conducted
KVKK-Breach
Data Breach Notification

Controllers must notify the KVKK Board within 72 hours of becoming aware of a breach, and notify affected data subjects in reasonable time. KVKK Board provides a notification form requiring breach scope, affected categories, measures taken, and remediation plan.

Artefacts an auditor will ask for
  • Breach response procedure with 72-hour clock
  • KVKK Board notification form submissions
  • Affected data subject communication evidence
  • Post-incident review records
Where this commonly fails
  • No 72-hour notification target
  • Late notification to Board
  • No notification to affected subjects
  • Inadequate root cause analysis
KVKK-Processor
Data Processor Obligations

Processors are jointly responsible with controllers for taking Art 12 security measures. Controllers must contractually bind processors and ensure ongoing compliance. Processor liability under KVKK is direct.

Artefacts an auditor will ask for
  • Processor register
  • KVKK-compliant data processing agreements in Turkish
  • Processor security assessments
  • Audit rights and audit evidence
Where this commonly fails
  • No DPAs with processors
  • DPAs only in English without Turkish
  • No processor due diligence
  • Audit rights not exercised

KVKK Article 16: VERBIS Registry and Governance

KVKK-Art16
VERBIS Data Controllers Registry

Data controllers must register with VERBIS (Veri Sorumlulari Sicili Bilgi Sistemi) before processing. Registration includes controller identity, processing purposes, data categories, recipient categories, transfers abroad, retention periods, and security measures. Thresholds and exemptions set by Board.

Artefacts an auditor will ask for
  • VERBIS registration certificate
  • Inventory of processing activities (Kisisel Veri Isleme Envanteri)
  • VERBIS public registration entries
  • Annual VERBIS update records
  • DPO/Contact Person appointment (irtibat kisisi) for foreign controllers
Where this commonly fails
  • Not registered in VERBIS despite meeting threshold (>50 employees or >TRY 100M balance sheet)
  • VERBIS entries not aligned to actual inventory
  • Foreign controller without appointed contact person
  • Inventory not updated
KVKK-DPO
Contact Person and DPO Role

VERBIS-registered controllers must appoint an irtibat kisisi (contact person) for communication with KVKK Board and data subjects. Foreign controllers must appoint a Turkey-resident representative. DPO role not mandated but recommended for large controllers; 2024 amendments referenced future regulation.

Artefacts an auditor will ask for
  • Contact person appointment letter filed with VERBIS
  • Foreign representative agreement and registration
  • DPO/contact person job description
  • Reporting line documentation
Where this commonly fails
  • No contact person appointed
  • Foreign controllers without Turkey representative
  • Contact person without authority or resources
KVKK-Inventory
Personal Data Processing Inventory

VERBIS-registered controllers must maintain a detailed personal data processing inventory (Kisisel Veri Isleme Envanteri) that goes beyond the public VERBIS entry, covering specific data fields, recipients, retention, and measures per processing activity.

Artefacts an auditor will ask for
  • Personal Data Processing Inventory in Turkish
  • Mapping of inventory to VERBIS entries
  • Periodic inventory review evidence
  • Owner per processing activity
Where this commonly fails
  • Inventory only equals VERBIS public entry (insufficient detail)
  • No periodic review
  • Activities not mapped to lawful basis

KVKK Articles 10 to 11: Information Notice and Data Subject Rights

KVKK-Art10
Information Notice Obligation

Controllers must inform data subjects at the time of data collection of: controller identity, processing purposes, recipients and purposes of transfer, method and legal basis of collection, and rights under Art 11. Aydinlatma Yukumlulugu (Information Obligation).

Artefacts an auditor will ask for
  • Aydinlatma Metni (Information Notice) templates in Turkish
  • Channel-specific notices (web, employee, customer, recruitment)
  • Notice delivery evidence
  • Version history of information notices
Where this commonly fails
  • No Turkish-language information notice
  • Missing transfer recipient categories
  • Notice not provided at collection time
  • Generic notices not channel-specific
KVKK-Art11
Data Subject Rights

Data subjects have rights to: learn whether data is processed, request information, learn the purpose, know third parties to whom data is transferred (domestic/abroad), request correction, request erasure or destruction, request notification of corrections to third parties, object to automated decisions, and request compensation for damages.

Artefacts an auditor will ask for
  • DSR intake form per Communique on Application Procedures
  • DSR response log with 30-day SLA
  • Identity verification procedure
  • Response templates in Turkish
  • Rejection justification records
Where this commonly fails
  • No documented DSR procedure
  • Missing 30-day response tracking
  • No identity verification
  • Responses only in English

KVKK Articles 13 to 15: Applications, Complaints and Board Powers

KVKK-Art13
Application to Controller Procedure

Data subjects apply to controller in writing or via methods set by Board. Controller must respond within 30 days, free of charge unless cost is incurred (max tariff set by Board). Rejections must be justified.

Artefacts an auditor will ask for
  • Application channels published (KEP, registered mail, secure email)
  • Response log with date-received and date-responded
  • Fee tariff posted if applicable
  • Rejection justification records
Where this commonly fails
  • No KEP (registered electronic mail) address
  • Charging for free requests
  • Response beyond 30 days
  • Unclear submission channels
KVKK-Art14
Complaint to KVKK Board

Where controller rejects or fails to respond within 30 days, data subject may complain to KVKK Board within 30 days of becoming aware (and within 60 days of application date). Board investigates and may issue binding decisions.

Artefacts an auditor will ask for
  • KVKK Board complaint response procedure
  • Investigation cooperation records
  • Board decision implementation evidence
Where this commonly fails
  • No procedure to handle Board investigations
  • Slow response to Board information requests
  • Failure to implement Board decisions
KVKK-Art15
KVKK Board Investigation Powers

KVKK Board may investigate ex officio or upon complaint, request information, conduct on-site inspections, and order remedial measures including suspension of processing. Cooperation is mandatory; obstruction is sanctionable.

Artefacts an auditor will ask for
  • Inspection cooperation protocol
  • Information request log
  • Board correspondence file
  • Remediation tracker for Board orders
Where this commonly fails
  • No designated KVKK liaison
  • Slow document production during investigation
  • No tracking of Board orders

KVKK Articles 17 to 18: Offences and Administrative Fines

KVKK-Art17
Criminal Offences

Criminal provisions in Turkish Penal Code Arts 135-140 apply: unlawful recording of personal data (1-3 years imprisonment), special categories (sentence increased by half), unlawful transfer or seizure (2-4 years), failure to destroy when required (1-2 years).

Artefacts an auditor will ask for
  • Criminal liability awareness training records
  • Acceptable use policy referencing Penal Code Arts 135-140
  • Personnel confidentiality undertakings
Where this commonly fails
  • No awareness of criminal exposure
  • No confidentiality undertakings for staff handling data
  • Insider risk controls absent
KVKK-Art18
Administrative Fines

Administrative fines for failure to provide information notice, failure to take security measures, failure to comply with Board decisions, or failure to register with VERBIS. Fine ranges increase annually with inflation; 2024 ranges from approximately TRY 47,000 to TRY 9.4M per violation, with significantly higher caps following 2024 amendments.

Artefacts an auditor will ask for
  • KVKK fine register
  • Internal compliance assessments
  • Board decision compliance evidence
  • Annual fine threshold update tracking
Where this commonly fails
  • No tracking of annually updated fine amounts
  • No compliance gap remediation plan
  • Unaware of 2024 amendment fine increases

KVKK Articles 3 to 7: Definitions, Principles and Lawful Basis

KVKK-Anonymisation
Anonymisation Standards

Anonymisation must render data permanently and irreversibly non-identifiable, considering means reasonably likely to be used. KVKK Board Anonymisation Guidelines (2018) cover techniques (generalisation, masking, perturbation, k-anonymity) and re-identification risk testing.

Artefacts an auditor will ask for
  • Anonymisation procedure documentation
  • Technique selection rationale per dataset
  • Re-identification risk assessment
  • Periodic re-assessment evidence
Where this commonly fails
  • Pseudonymisation labelled as anonymisation
  • No re-identification risk testing
  • Static techniques without periodic re-assessment
KVKK-Art3
Definitions and Key Concepts

Defines personal data, special categories, data subject, data controller, data processor, processing, anonymisation, and explicit consent. Establishes the conceptual foundations for KVKK obligations.

Artefacts an auditor will ask for
  • KVKK glossary aligned to Turkish definitions
  • Data controller vs processor mapping
  • Definitions section in privacy policy in Turkish
  • Internal policy referencing KVKK Art 3 terminology
Where this commonly fails
  • Using GDPR definitions verbatim without Turkish equivalents
  • Confusing controller and processor roles
  • No Turkish-language definitions
KVKK-Art4
General Principles of Processing

Personal data must be processed lawfully and fairly, accurately and kept up to date, for specific, explicit and legitimate purposes, relevant and limited to purposes, and retained only for the period required by law or purpose.

Artefacts an auditor will ask for
  • Processing principles policy
  • Data minimisation review records
  • Accuracy and update procedures
  • Retention schedule mapped to KVKK Art 4
  • Purpose limitation register
Where this commonly fails
  • No documented retention periods
  • Collecting more data than necessary
  • No accuracy review cadence
  • Vague processing purposes
KVKK-Art5-1
Explicit Consent as Lawful Basis

Personal data may not be processed without the explicit consent of the data subject, unless one of the exceptions in Art 5(2) applies. Consent must be informed, specific to the processing, and freely given.

Artefacts an auditor will ask for
  • Explicit consent form templates in Turkish
  • Consent capture logs with timestamp and version
  • Withdrawal mechanism evidence
  • Consent vs other lawful basis decision matrix
  • Granular consent UI screenshots
Where this commonly fails
  • Bundled consent with terms acceptance
  • Pre-ticked boxes
  • No withdrawal mechanism
  • Consent used where another basis applies
KVKK-Art5-2
Exceptions to Explicit Consent Requirement

Processing without explicit consent is allowed where expressly provided by law, necessary to protect life or physical integrity, necessary for contract performance, necessary for legal obligation, data made public by subject, necessary for establishment of right, or legitimate interests of controller not overriding subject rights.

Artefacts an auditor will ask for
  • Lawful basis register per processing activity
  • Legitimate interests assessments (LIA)
  • Legal obligation citations to Turkish law
  • Contract necessity analysis
Where this commonly fails
  • Defaulting to consent when another basis applies
  • No LIA documentation
  • Vague legal obligation references
  • No balancing test for legitimate interests
KVKK-Art6
Special Categories of Personal Data

Special categories include race, ethnicity, political opinion, philosophical belief, religion, sect, appearance, association/foundation/union membership, health, sexual life, criminal convictions, biometric and genetic data. Processing requires explicit consent or specific legal authorisation. Health and sexual life data have additional restrictions.

Artefacts an auditor will ask for
  • Special category data inventory
  • Adequate measures policy per KVKK Board decision 2018/10
  • Encryption controls for sensitive data
  • Access logs to special category records
  • Separate consent for special categories
Where this commonly fails
  • No separation of sensitive data from regular data
  • Missing adequate measures per Board decision 2018/10
  • Health data processed without proper legal basis
  • Biometric data without explicit consent
KVKK-Art7
Erasure, Destruction and Anonymisation

When reasons for processing cease, personal data must be erased, destroyed or anonymised ex officio or upon request. The Regulation on Erasure, Destruction or Anonymisation establishes procedures and the Personal Data Storage and Destruction Policy obligation for VERBIS-registered controllers.

Artefacts an auditor will ask for
  • Personal Data Storage and Destruction Policy in Turkish
  • Periodic destruction schedule (max 6 months)
  • Destruction logs with method and timestamp
  • Anonymisation technique documentation
  • Erasure request fulfilment records
Where this commonly fails
  • No Storage and Destruction Policy
  • No periodic destruction cadence
  • Anonymisation without irreversibility testing
  • Backups retained beyond schedule
KVKK-Retention
Retention Policy and Schedules

Personal Data Storage and Destruction Policy must define retention periods for each data category based on legal requirements (e.g., Tax Procedure Law 5 years, Labour Law 10 years, Commercial Code 10 years) and justify storage beyond legal minimums.

Artefacts an auditor will ask for
  • Saklama ve Imha Politikasi (Storage and Destruction Policy)
  • Retention schedule per data category with legal basis citation
  • Periodic destruction logs (6-month max cadence)
  • Backup retention alignment
Where this commonly fails
  • No documented retention rationale
  • Retention beyond legal minimum without basis
  • Backups outliving primary records
  • No periodic destruction

KVKK Articles 8 to 9: Domestic and Cross-Border Transfers

KVKK-Art8
Domestic Transfers of Personal Data

Transfer of personal data within Turkey requires explicit consent or one of the Art 5(2) or Art 6(3) exceptions. Adequate measures apply when transferring sensitive data domestically.

Artefacts an auditor will ask for
  • Domestic transfer register
  • Data processing agreements with Turkish processors
  • Lawful basis documentation for each transfer
  • Adequate measures evidence for sensitive transfers
Where this commonly fails
  • No DPA with domestic processors
  • Transfers without explicit lawful basis
  • No record of domestic onward transfers
KVKK-Art9
Cross-Border Transfers (Pre-2024 Regime)

Historically, transfers abroad required explicit consent or transfer to a country with adequate protection (none declared) or written undertaking between exporter and importer plus KVKK Board authorisation. Heavily restrictive prior to March 2024 amendments.

Artefacts an auditor will ask for
  • Legacy cross-border transfer undertakings filed with KVKK Board
  • KVKK Board authorisation letters
  • Explicit consent records for international transfers
  • Transfer destination register
Where this commonly fails
  • Transfers abroad without Board authorisation
  • Reliance on consent for ongoing business transfers
  • No undertaking signed for intra-group flows
KVKK-Art9-2024
Cross-Border Transfers (2024 Amended Regime)

Law No. 7499 (effective 1 June 2024) amended Art 9 to align with GDPR. Transfers allowed via adequacy decision, appropriate safeguards (standard contracts, BCRs, codes of conduct, certifications) with Board notification, or specific derogations. Standard contracts must be notified to KVKK within 5 business days.

Artefacts an auditor will ask for
  • KVKK Standard Contractual Clauses signed copies
  • KVKK Standard Contract notification receipts (5 business days)
  • Binding Corporate Rules approved by KVKK Board
  • Adequacy decision register
  • Transfer Impact Assessments
Where this commonly fails
  • No KVKK SCC version in place (using only GDPR SCCs)
  • Missing 5-day notification to KVKK
  • BCRs not approved by KVKK Board
  • No TIA documented
KVKK-Localisation
Data Localisation Considerations

KVKK itself does not mandate localisation but historically restricted cross-border transfers (pre-2024). Sectoral rules (BDDK for banking, SPK for capital markets, healthcare under Ministry of Health) impose localisation for specific data sets.

Artefacts an auditor will ask for
  • Hosting location register per data category
  • Sectoral localisation compliance mapping
  • Cloud provider Turkey region selection evidence
Where this commonly fails
  • Banking primary data hosted abroad without BDDK approval
  • Healthcare data outside Turkey without legal basis
  • No hosting location inventory

KVKK Compliance Programme and Sector Application

KVKK-Audit
Internal Audit and Compliance Programme

KVKK Board Decision 2019/10 requires periodic internal audits as part of adequate measures. Audits cover processing inventory accuracy, lawful basis assessment, security controls, processor compliance, DSR handling, and training effectiveness.

Artefacts an auditor will ask for
  • Annual KVKK internal audit plan
  • Audit report and findings register
  • Remediation tracker
  • Board-level reporting evidence
Where this commonly fails
  • No internal audit programme
  • Audit findings not remediated
  • No board-level KVKK reporting
KVKK-Banking
Sector Overlap with Banking Secrecy

Banking, insurance, and capital markets sectors are subject to KVKK alongside sectoral secrecy laws (Banking Law, BDDK regulations). Specific localisation requirements apply for primary and secondary banking systems per BDDK Regulation on Information Systems.

Artefacts an auditor will ask for
  • Sector regulatory mapping (KVKK + BDDK + SPK + insurance)
  • Banking data localisation evidence
  • Cloud arrangement BDDK notifications
  • Customer secrecy and KVKK alignment
Where this commonly fails
  • Treating KVKK as sole obligation
  • Banking primary systems hosted abroad without BDDK approval
  • No alignment between KVKK and Banking Law obligations
KVKK-Cookies
Cookies and Electronic Tracking

Cookies and similar trackers handling personal data require KVKK compliance. KVKK Board issued cookie guidance (June 2022) requiring informed consent for non-essential cookies, with prior consent before placing trackers. Distinct from EU ePrivacy but similar in operation.

Artefacts an auditor will ask for
  • KVKK-compliant cookie banner with reject option
  • Cookie inventory and categorisation
  • Cookie consent logs
  • Cookie policy in Turkish
Where this commonly fails
  • No reject-all option
  • Pre-loaded non-essential cookies before consent
  • No cookie inventory
  • Cookie policy only in English
KVKK-DPIA
Risk Assessment and DPIA-equivalent

While KVKK does not mandate GDPR-style DPIA, KVKK Board guidance and the 2024 amendments encourage risk assessments for high-risk processing including new technologies, biometrics, and large-scale special category processing.

Artefacts an auditor will ask for
  • Risk assessment template
  • Completed risk assessments per high-risk activity
  • Risk register linked to processing inventory
  • Mitigation tracking
Where this commonly fails
  • No formal risk assessment process
  • DPIA only for GDPR processing, not KVKK
  • No biometric or AI risk reviews
KVKK-Employees
Employee Data Processing

Employee personal data processing must rely on contract performance or legal obligation rather than consent (due to imbalance of power). Specific notices required for HR processing, monitoring, and biometric access controls. KVKK Board has issued multiple decisions on workplace monitoring.

Artefacts an auditor will ask for
  • Employee Aydinlatma Metni (HR notice)
  • Workplace monitoring policy
  • Biometric processing legal basis assessment
  • Employee data inventory
Where this commonly fails
  • Consent used as basis for mandatory HR processing
  • No monitoring notice
  • Biometric access without explicit consent
  • No separate employee inventory
KVKK-Marketing
Direct Marketing Communications

Direct electronic marketing requires explicit consent under KVKK plus separate consent under Law No. 6563 on Electronic Commerce and IYS (Iletisim Yonetim Sistemi) registration. Opt-out must be honoured.

Artefacts an auditor will ask for
  • IYS registration evidence
  • Marketing consent records synced to IYS
  • Opt-out logs
  • Marketing notice template
Where this commonly fails
  • No IYS registration
  • Consents not uploaded to IYS
  • B2B marketing without consent (post-2020 reform)
  • No opt-out within campaign
KVKK-Training
Staff Training and Awareness

KVKK Board Decision 2018/10 and 2019/10 require periodic personnel training on personal data protection as part of adequate technical and organisational measures. Records of training are evidence of compliance.

Artefacts an auditor will ask for
  • Annual KVKK training records
  • Training content in Turkish
  • Completion certificates
  • Role-based training for HR, IT, marketing
  • Onboarding KVKK module
Where this commonly fails
  • No annual refresh
  • Training only at hire
  • No role-specific content
  • Training not in Turkish

Notice and Rights

TURKEYKVKK-2
Information Notice and Data Subject Rights

Per KVKK: Aydinlatma Metni (Information Notice) + data subject rights via Veribasvuru.

Artefacts an auditor will ask for
  • KVKK evidence for TURKEYKVKK-2
Where this commonly fails
  • VERBIS + 2024 amendments + 72hr breach partial

Registration

TURKEYKVKK-1
VERBIS Registration and Lawful Basis

Per Turkey KVKK (Kisisel Verilerin Korunmasi Kanunu Law 6698): VERBIS Registration with KVKK + lawful basis + Explicit Consent.

Artefacts an auditor will ask for
  • KVKK evidence for TURKEYKVKK-1
Where this commonly fails
  • VERBIS + 2024 amendments + 72hr breach partial

Security

TURKEYKVKK-4
Security and Processor Management

Per KVKK + KVKK Authority Guidelines: security + processor management + administrative + technical measures.

Artefacts an auditor will ask for
  • KVKK evidence for TURKEYKVKK-4
Where this commonly fails
  • VERBIS + 2024 amendments + 72hr breach partial

Sensitive

TURKEYKVKK-3
Special Categories and Sensitive Data

Per KVKK: special categories including health + biometric + religious + political + criminal + with explicit consent requirements.

Artefacts an auditor will ask for
  • KVKK evidence for TURKEYKVKK-3
Where this commonly fails
  • VERBIS + 2024 amendments + 72hr breach partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Turkey KVKK framework page.