Turkey KVKK
Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach
Per KVKK: 72-hour breach notification to KVKK Authority + affected subjects + administrative fines + criminal penalties.
- KVKK evidence for TURKEYKVKK-7
- VERBIS + 2024 amendments + 72hr breach partial
Cross-Border
Per KVKK Article 9 + 2024 amendments: Cross Border Data Transfers including adequacy + safeguards (SCCs + BCRs + AppropriateGarantor) + derogations + explicit consent.
- KVKK evidence for TURKEYKVKK-5
- VERBIS + 2024 amendments + 72hr breach partial
Governance
Per KVKK + Turkey: DPO + KVKK Authority cooperation + training + records.
- KVKK evidence for TURKEYKVKK-6
- VERBIS + 2024 amendments + 72hr breach partial
KVKK Article 12: Security of Processing
Controllers must take all necessary technical and organisational measures to prevent unlawful processing, unlawful access, and to ensure data preservation. Must conduct audits, ensure processor compliance, and notify the KVKK Board and affected data subjects of breaches within reasonable period (72 hours per Board guidance).
- Technical and organisational measures register
- Information security policy in Turkish
- Encryption, access control, logging evidence
- Breach notification procedure with 72-hour target
- Breach notification forms filed with KVKK
- No documented TOMs aligned to KVKK Board adequate measures list
- Breach notifications delayed beyond 72 hours
- No periodic security audits
- Processor audits not conducted
Controllers must notify the KVKK Board within 72 hours of becoming aware of a breach, and notify affected data subjects in reasonable time. KVKK Board provides a notification form requiring breach scope, affected categories, measures taken, and remediation plan.
- Breach response procedure with 72-hour clock
- KVKK Board notification form submissions
- Affected data subject communication evidence
- Post-incident review records
- No 72-hour notification target
- Late notification to Board
- No notification to affected subjects
- Inadequate root cause analysis
Processors are jointly responsible with controllers for taking Art 12 security measures. Controllers must contractually bind processors and ensure ongoing compliance. Processor liability under KVKK is direct.
- Processor register
- KVKK-compliant data processing agreements in Turkish
- Processor security assessments
- Audit rights and audit evidence
- No DPAs with processors
- DPAs only in English without Turkish
- No processor due diligence
- Audit rights not exercised
KVKK Article 16: VERBIS Registry and Governance
Data controllers must register with VERBIS (Veri Sorumlulari Sicili Bilgi Sistemi) before processing. Registration includes controller identity, processing purposes, data categories, recipient categories, transfers abroad, retention periods, and security measures. Thresholds and exemptions set by Board.
- VERBIS registration certificate
- Inventory of processing activities (Kisisel Veri Isleme Envanteri)
- VERBIS public registration entries
- Annual VERBIS update records
- DPO/Contact Person appointment (irtibat kisisi) for foreign controllers
- Not registered in VERBIS despite meeting threshold (>50 employees or >TRY 100M balance sheet)
- VERBIS entries not aligned to actual inventory
- Foreign controller without appointed contact person
- Inventory not updated
VERBIS-registered controllers must appoint an irtibat kisisi (contact person) for communication with KVKK Board and data subjects. Foreign controllers must appoint a Turkey-resident representative. DPO role not mandated but recommended for large controllers; 2024 amendments referenced future regulation.
- Contact person appointment letter filed with VERBIS
- Foreign representative agreement and registration
- DPO/contact person job description
- Reporting line documentation
- No contact person appointed
- Foreign controllers without Turkey representative
- Contact person without authority or resources
VERBIS-registered controllers must maintain a detailed personal data processing inventory (Kisisel Veri Isleme Envanteri) that goes beyond the public VERBIS entry, covering specific data fields, recipients, retention, and measures per processing activity.
- Personal Data Processing Inventory in Turkish
- Mapping of inventory to VERBIS entries
- Periodic inventory review evidence
- Owner per processing activity
- Inventory only equals VERBIS public entry (insufficient detail)
- No periodic review
- Activities not mapped to lawful basis
KVKK Articles 10 to 11: Information Notice and Data Subject Rights
Controllers must inform data subjects at the time of data collection of: controller identity, processing purposes, recipients and purposes of transfer, method and legal basis of collection, and rights under Art 11. Aydinlatma Yukumlulugu (Information Obligation).
- Aydinlatma Metni (Information Notice) templates in Turkish
- Channel-specific notices (web, employee, customer, recruitment)
- Notice delivery evidence
- Version history of information notices
- No Turkish-language information notice
- Missing transfer recipient categories
- Notice not provided at collection time
- Generic notices not channel-specific
Data subjects have rights to: learn whether data is processed, request information, learn the purpose, know third parties to whom data is transferred (domestic/abroad), request correction, request erasure or destruction, request notification of corrections to third parties, object to automated decisions, and request compensation for damages.
- DSR intake form per Communique on Application Procedures
- DSR response log with 30-day SLA
- Identity verification procedure
- Response templates in Turkish
- Rejection justification records
- No documented DSR procedure
- Missing 30-day response tracking
- No identity verification
- Responses only in English
KVKK Articles 13 to 15: Applications, Complaints and Board Powers
Data subjects apply to controller in writing or via methods set by Board. Controller must respond within 30 days, free of charge unless cost is incurred (max tariff set by Board). Rejections must be justified.
- Application channels published (KEP, registered mail, secure email)
- Response log with date-received and date-responded
- Fee tariff posted if applicable
- Rejection justification records
- No KEP (registered electronic mail) address
- Charging for free requests
- Response beyond 30 days
- Unclear submission channels
Where controller rejects or fails to respond within 30 days, data subject may complain to KVKK Board within 30 days of becoming aware (and within 60 days of application date). Board investigates and may issue binding decisions.
- KVKK Board complaint response procedure
- Investigation cooperation records
- Board decision implementation evidence
- No procedure to handle Board investigations
- Slow response to Board information requests
- Failure to implement Board decisions
KVKK Board may investigate ex officio or upon complaint, request information, conduct on-site inspections, and order remedial measures including suspension of processing. Cooperation is mandatory; obstruction is sanctionable.
- Inspection cooperation protocol
- Information request log
- Board correspondence file
- Remediation tracker for Board orders
- No designated KVKK liaison
- Slow document production during investigation
- No tracking of Board orders
KVKK Articles 17 to 18: Offences and Administrative Fines
Criminal provisions in Turkish Penal Code Arts 135-140 apply: unlawful recording of personal data (1-3 years imprisonment), special categories (sentence increased by half), unlawful transfer or seizure (2-4 years), failure to destroy when required (1-2 years).
- Criminal liability awareness training records
- Acceptable use policy referencing Penal Code Arts 135-140
- Personnel confidentiality undertakings
- No awareness of criminal exposure
- No confidentiality undertakings for staff handling data
- Insider risk controls absent
Administrative fines for failure to provide information notice, failure to take security measures, failure to comply with Board decisions, or failure to register with VERBIS. Fine ranges increase annually with inflation; 2024 ranges from approximately TRY 47,000 to TRY 9.4M per violation, with significantly higher caps following 2024 amendments.
- KVKK fine register
- Internal compliance assessments
- Board decision compliance evidence
- Annual fine threshold update tracking
- No tracking of annually updated fine amounts
- No compliance gap remediation plan
- Unaware of 2024 amendment fine increases
KVKK Articles 3 to 7: Definitions, Principles and Lawful Basis
Anonymisation must render data permanently and irreversibly non-identifiable, considering means reasonably likely to be used. KVKK Board Anonymisation Guidelines (2018) cover techniques (generalisation, masking, perturbation, k-anonymity) and re-identification risk testing.
- Anonymisation procedure documentation
- Technique selection rationale per dataset
- Re-identification risk assessment
- Periodic re-assessment evidence
- Pseudonymisation labelled as anonymisation
- No re-identification risk testing
- Static techniques without periodic re-assessment
Defines personal data, special categories, data subject, data controller, data processor, processing, anonymisation, and explicit consent. Establishes the conceptual foundations for KVKK obligations.
- KVKK glossary aligned to Turkish definitions
- Data controller vs processor mapping
- Definitions section in privacy policy in Turkish
- Internal policy referencing KVKK Art 3 terminology
- Using GDPR definitions verbatim without Turkish equivalents
- Confusing controller and processor roles
- No Turkish-language definitions
Personal data must be processed lawfully and fairly, accurately and kept up to date, for specific, explicit and legitimate purposes, relevant and limited to purposes, and retained only for the period required by law or purpose.
- Processing principles policy
- Data minimisation review records
- Accuracy and update procedures
- Retention schedule mapped to KVKK Art 4
- Purpose limitation register
- No documented retention periods
- Collecting more data than necessary
- No accuracy review cadence
- Vague processing purposes
Personal data may not be processed without the explicit consent of the data subject, unless one of the exceptions in Art 5(2) applies. Consent must be informed, specific to the processing, and freely given.
- Explicit consent form templates in Turkish
- Consent capture logs with timestamp and version
- Withdrawal mechanism evidence
- Consent vs other lawful basis decision matrix
- Granular consent UI screenshots
- Bundled consent with terms acceptance
- Pre-ticked boxes
- No withdrawal mechanism
- Consent used where another basis applies
Processing without explicit consent is allowed where expressly provided by law, necessary to protect life or physical integrity, necessary for contract performance, necessary for legal obligation, data made public by subject, necessary for establishment of right, or legitimate interests of controller not overriding subject rights.
- Lawful basis register per processing activity
- Legitimate interests assessments (LIA)
- Legal obligation citations to Turkish law
- Contract necessity analysis
- Defaulting to consent when another basis applies
- No LIA documentation
- Vague legal obligation references
- No balancing test for legitimate interests
Special categories include race, ethnicity, political opinion, philosophical belief, religion, sect, appearance, association/foundation/union membership, health, sexual life, criminal convictions, biometric and genetic data. Processing requires explicit consent or specific legal authorisation. Health and sexual life data have additional restrictions.
- Special category data inventory
- Adequate measures policy per KVKK Board decision 2018/10
- Encryption controls for sensitive data
- Access logs to special category records
- Separate consent for special categories
- No separation of sensitive data from regular data
- Missing adequate measures per Board decision 2018/10
- Health data processed without proper legal basis
- Biometric data without explicit consent
When reasons for processing cease, personal data must be erased, destroyed or anonymised ex officio or upon request. The Regulation on Erasure, Destruction or Anonymisation establishes procedures and the Personal Data Storage and Destruction Policy obligation for VERBIS-registered controllers.
- Personal Data Storage and Destruction Policy in Turkish
- Periodic destruction schedule (max 6 months)
- Destruction logs with method and timestamp
- Anonymisation technique documentation
- Erasure request fulfilment records
- No Storage and Destruction Policy
- No periodic destruction cadence
- Anonymisation without irreversibility testing
- Backups retained beyond schedule
Personal Data Storage and Destruction Policy must define retention periods for each data category based on legal requirements (e.g., Tax Procedure Law 5 years, Labour Law 10 years, Commercial Code 10 years) and justify storage beyond legal minimums.
- Saklama ve Imha Politikasi (Storage and Destruction Policy)
- Retention schedule per data category with legal basis citation
- Periodic destruction logs (6-month max cadence)
- Backup retention alignment
- No documented retention rationale
- Retention beyond legal minimum without basis
- Backups outliving primary records
- No periodic destruction
KVKK Articles 8 to 9: Domestic and Cross-Border Transfers
Transfer of personal data within Turkey requires explicit consent or one of the Art 5(2) or Art 6(3) exceptions. Adequate measures apply when transferring sensitive data domestically.
- Domestic transfer register
- Data processing agreements with Turkish processors
- Lawful basis documentation for each transfer
- Adequate measures evidence for sensitive transfers
- No DPA with domestic processors
- Transfers without explicit lawful basis
- No record of domestic onward transfers
Historically, transfers abroad required explicit consent or transfer to a country with adequate protection (none declared) or written undertaking between exporter and importer plus KVKK Board authorisation. Heavily restrictive prior to March 2024 amendments.
- Legacy cross-border transfer undertakings filed with KVKK Board
- KVKK Board authorisation letters
- Explicit consent records for international transfers
- Transfer destination register
- Transfers abroad without Board authorisation
- Reliance on consent for ongoing business transfers
- No undertaking signed for intra-group flows
Law No. 7499 (effective 1 June 2024) amended Art 9 to align with GDPR. Transfers allowed via adequacy decision, appropriate safeguards (standard contracts, BCRs, codes of conduct, certifications) with Board notification, or specific derogations. Standard contracts must be notified to KVKK within 5 business days.
- KVKK Standard Contractual Clauses signed copies
- KVKK Standard Contract notification receipts (5 business days)
- Binding Corporate Rules approved by KVKK Board
- Adequacy decision register
- Transfer Impact Assessments
- No KVKK SCC version in place (using only GDPR SCCs)
- Missing 5-day notification to KVKK
- BCRs not approved by KVKK Board
- No TIA documented
KVKK itself does not mandate localisation but historically restricted cross-border transfers (pre-2024). Sectoral rules (BDDK for banking, SPK for capital markets, healthcare under Ministry of Health) impose localisation for specific data sets.
- Hosting location register per data category
- Sectoral localisation compliance mapping
- Cloud provider Turkey region selection evidence
- Banking primary data hosted abroad without BDDK approval
- Healthcare data outside Turkey without legal basis
- No hosting location inventory
KVKK Compliance Programme and Sector Application
KVKK Board Decision 2019/10 requires periodic internal audits as part of adequate measures. Audits cover processing inventory accuracy, lawful basis assessment, security controls, processor compliance, DSR handling, and training effectiveness.
- Annual KVKK internal audit plan
- Audit report and findings register
- Remediation tracker
- Board-level reporting evidence
- No internal audit programme
- Audit findings not remediated
- No board-level KVKK reporting
Banking, insurance, and capital markets sectors are subject to KVKK alongside sectoral secrecy laws (Banking Law, BDDK regulations). Specific localisation requirements apply for primary and secondary banking systems per BDDK Regulation on Information Systems.
- Sector regulatory mapping (KVKK + BDDK + SPK + insurance)
- Banking data localisation evidence
- Cloud arrangement BDDK notifications
- Customer secrecy and KVKK alignment
- Treating KVKK as sole obligation
- Banking primary systems hosted abroad without BDDK approval
- No alignment between KVKK and Banking Law obligations
Cookies and similar trackers handling personal data require KVKK compliance. KVKK Board issued cookie guidance (June 2022) requiring informed consent for non-essential cookies, with prior consent before placing trackers. Distinct from EU ePrivacy but similar in operation.
- KVKK-compliant cookie banner with reject option
- Cookie inventory and categorisation
- Cookie consent logs
- Cookie policy in Turkish
- No reject-all option
- Pre-loaded non-essential cookies before consent
- No cookie inventory
- Cookie policy only in English
While KVKK does not mandate GDPR-style DPIA, KVKK Board guidance and the 2024 amendments encourage risk assessments for high-risk processing including new technologies, biometrics, and large-scale special category processing.
- Risk assessment template
- Completed risk assessments per high-risk activity
- Risk register linked to processing inventory
- Mitigation tracking
- No formal risk assessment process
- DPIA only for GDPR processing, not KVKK
- No biometric or AI risk reviews
Employee personal data processing must rely on contract performance or legal obligation rather than consent (due to imbalance of power). Specific notices required for HR processing, monitoring, and biometric access controls. KVKK Board has issued multiple decisions on workplace monitoring.
- Employee Aydinlatma Metni (HR notice)
- Workplace monitoring policy
- Biometric processing legal basis assessment
- Employee data inventory
- Consent used as basis for mandatory HR processing
- No monitoring notice
- Biometric access without explicit consent
- No separate employee inventory
Direct electronic marketing requires explicit consent under KVKK plus separate consent under Law No. 6563 on Electronic Commerce and IYS (Iletisim Yonetim Sistemi) registration. Opt-out must be honoured.
- IYS registration evidence
- Marketing consent records synced to IYS
- Opt-out logs
- Marketing notice template
- No IYS registration
- Consents not uploaded to IYS
- B2B marketing without consent (post-2020 reform)
- No opt-out within campaign
KVKK Board Decision 2018/10 and 2019/10 require periodic personnel training on personal data protection as part of adequate technical and organisational measures. Records of training are evidence of compliance.
- Annual KVKK training records
- Training content in Turkish
- Completion certificates
- Role-based training for HR, IT, marketing
- Onboarding KVKK module
- No annual refresh
- Training only at hire
- No role-specific content
- Training not in Turkish
Notice and Rights
Per KVKK: Aydinlatma Metni (Information Notice) + data subject rights via Veribasvuru.
- KVKK evidence for TURKEYKVKK-2
- VERBIS + 2024 amendments + 72hr breach partial
Registration
Per Turkey KVKK (Kisisel Verilerin Korunmasi Kanunu Law 6698): VERBIS Registration with KVKK + lawful basis + Explicit Consent.
- KVKK evidence for TURKEYKVKK-1
- VERBIS + 2024 amendments + 72hr breach partial
Security
Per KVKK + KVKK Authority Guidelines: security + processor management + administrative + technical measures.
- KVKK evidence for TURKEYKVKK-4
- VERBIS + 2024 amendments + 72hr breach partial
Sensitive
Per KVKK: special categories including health + biometric + religious + political + criminal + with explicit consent requirements.
- KVKK evidence for TURKEYKVKK-3
- VERBIS + 2024 amendments + 72hr breach partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Turkey KVKK framework page.