Turkey's data protection law is older than the GDPR, was modelled on the directive the GDPR replaced, and since June 2024 has a transfer regime that looks European and is enforced by an authority that has published no adequacy decision for any country. In my files the American software group that runs its Turkish subsidiary's payroll on a system in Virginia, the German parent whose Istanbul office reports to a shared HR platform in Munich, and the British online retailer that ships to Turkish customers from Manchester are all transferring personal data abroad under Law 6698, all needed a standard contract filed with the Authority within five business days of signing it, and two of them needed a Turkish representative on a public register before they processed a single record. This page sets out who the law reaches, the legal bases and what changed in 2024, the registry and the representative, the cross-border transfer regime as it stands in 2026, the breach deadlines, and the fines as revalued for 2026.
Sources, checked 9 September 2026. Law No. 6698 on the Protection of Personal Data (Official Gazette 29677, 7 April 2016) as amended by Law No. 7499 (Official Gazette 32487, 12 March 2024), Articles 3 to 7, 9 to 18 and Provisional Article 3; Regulation on the Data Controllers' Registry (Official Gazette 30286, 30 December 2017, amended 28 April 2019); Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (Official Gazette 32598, 10 July 2024); Personal Data Protection Board decisions 2018/87 and 2023/1154 on registration exemptions, 2025/1572 of 4 September 2025, 2019/10 of 24 January 2019 on breach notification, 2024/959 of 4 June 2024 on standard contracts and binding corporate rules, and 2025/2451 of 25 December 2025 on the publication of breach notices; the Authority's table of administrative fines for 2026 (31 December 2025) and its Guide No. 48 on transfers abroad (January 2025).
Who the law reaches: the subsidiary, the branch, the office and the parent abroad
Law 6698 applies to every natural or legal person that processes personal data wholly or partly by automated means, or as part of a filing system. Article 3 defines the data controller as the person who determines the purposes and means of processing and is responsible for the filing system, and the data processor as the person who processes on the controller's behalf and authority. There is no threshold of size, no exemption for foreign ownership and no separate regime for a company that has just arrived. A Turkish subsidiary is a controller for its employees, customers and suppliers from the day it hires or sells. A liaison office that may not trade still employs people and is a controller for their data; the forms and their limits are on the liaison office, branch and subsidiary page. A foreign parent that decides how the group's HR or customer systems work, and receives the Turkish data into them, is a controller in its own right, and the Turkish company that feeds those systems is a controller exporting data abroad.
The law has no territorial-scope article of the GDPR kind, but the Authority applies it to companies outside Turkey through two instruments. Article 11 of the Registry Regulation requires a legal person established abroad that is a controller to appoint a data controller representative, who must be a legal person established in Turkey or a Turkish citizen, by a certified resolution submitted through the representative, and the appointment does not shift liability: the Authority's own guidance states that responsibility for the law's obligations and sanctions stays with the foreign controller's authorised organs. Board decision 2019/10 then requires a controller established abroad to notify the Board of a breach on the same terms as a Turkish one where the breach affects persons in Turkey who use its products or services in Turkey. A foreign company selling to Turkish residents online, or hiring them remotely, should assume it is inside the law rather than argue later that it was not.
The legal bases, and where a foreign company usually goes wrong
Article 5 starts from explicit consent, defined in Article 3 as freely given, specific and informed, and then lists the bases on which data may be processed without it: an express provision of law; protection of life or physical integrity; processing necessary for a contract with the data subject; a legal obligation of the controller; data made public by the data subject; the establishment, exercise or protection of a right; and the controller's legitimate interests where they do not override the data subject's fundamental rights. Article 4 adds the principles of lawfulness, accuracy, purpose limitation, proportionality and limited retention, and Article 7 requires erasure, destruction or anonymisation when the purpose ends.
Article 6 is where the 2024 amendment mattered most for employers. Special categories, which include health, biometric and genetic data, trade union membership and criminal convictions, were until June 2024 processable in practice only with explicit consent or, for health data, by persons under a duty of confidentiality. Law 7499 rewrote Article 6(3) and now permits processing where a law expressly provides for it, where it is necessary to protect life, where the data subject made the data public, where it is needed to establish or defend a right, for health services by confidentiality-bound persons or competent bodies, and where it is necessary to fulfil legal obligations in employment, occupational health and safety, social security and social assistance. A Turkish employer's medical reports and workplace physician files, which sit under the obligations described on the employment law page, now have a statutory basis; biometric attendance systems do not, and are the subject of the Board's principle decision 2026/921 of 29 April 2026 on biometric time tracking. Explicit consent from an employee remains a weak basis because of the imbalance between the parties, and I do not let a client build a payroll or monitoring process on it.
Two duties attach to every processing operation whatever the basis. Article 10 requires the controller, or the person it authorises, to inform data subjects at the time of collection of the controller's identity and that of any representative, the purpose, to whom and why the data may be transferred, the method and legal basis of collection, and the rights under Article 11. Article 13 requires the controller to answer a data subject's request within thirty days and free of charge; under Article 14 the data subject may complain to the Board within thirty days of the answer or sixty days of the request, and under Article 15 the Board may demand documents within fifteen days, inspect on the spot, and order remedies to be carried out within thirty days.
VERBİS: the public registry, the thresholds and the representative
Article 16 requires anyone who processes personal data to register with the Data Controllers' Registry, VERBİS, before starting to process, unless the Board has exempted them. The exemption that matters to a new subsidiary is the one in Board decision 2018/87 as amended by decision 2023/1154: a controller with fewer than fifty employees and an annual balance sheet total below one hundred million lira is exempt, unless its main activity is the processing of special categories of data. Decision 2025/1572 of 4 September 2025 added a narrower exemption for controllers whose main activity is special-category data, at fewer than ten employees and a balance sheet below ten million lira. A subsidiary that crosses either line registers, and a registered controller must keep a personal data processing inventory and a retention and destruction policy in the form the Registry Regulation prescribes, and enter a contact person in Turkey who liaises with the Authority but does not represent the controller.
For the parent abroad the position is different. A controller established outside Turkey registers through its Turkish representative under Article 11 of the Regulation, and the representative's appointment resolution, certified, is filed with the Authority. Registration is public: the Authority publishes the registry on its website, so the parent's data categories, purposes, recipient groups and retention periods are visible to anyone. Failure to register or to keep the entry current is fined under Article 18(1)(ç), which in 2026 runs from 341,809 to 17,092,242 lira. The company formation steps that precede the first registration are on the company set-up page.
Cross-border transfers since 1 June 2024: adequacy, safeguards, exceptions
Until June 2024 Article 9 allowed a transfer abroad only with explicit consent, or to a country the Board had declared adequate, or on a written undertaking approved by the Board; the Board never declared any country adequate, and approvals of undertakings were rare, so most groups ran on consent. Law 7499 replaced Article 9 with effect from 1 June 2024, kept the old consent route alive alongside the new regime until 1 September 2024 under Provisional Article 3, and the Regulation of 10 July 2024 filled in the procedure.
The new regime has three tiers. Under Article 9(1) a transfer is permitted where a processing condition under Article 5 or 6 is met and the Board has issued an adequacy decision for the destination country, a sector within it or an international organisation; adequacy decisions are published in the Official Gazette and reviewed at least every four years. The Authority's transfer page states that no such decision has yet been made, so this tier is empty in 2026. Under Article 9(4), absent an adequacy decision, a transfer is permitted where a processing condition is met, the data subject retains enforceable rights and effective remedies in the destination, and one of four safeguards is in place: an agreement between public bodies with the Board's approval; binding corporate rules approved by the Board for a group of undertakings; a standard contract in the form published by the Board; or a written undertaking of adequate protection with the Board's approval. Under Article 9(6), where neither tier is available, a transfer may be made only if it is incidental and one of the listed circumstances applies: explicit consent after information about the risks, performance of a contract with or for the benefit of the data subject, an overriding public interest, the establishment or defence of a right, protection of life, or transfer from a public register. Article 9(8) extends the safeguards to onward transfers from the recipient.
For a foreign-owned company the standard contract is the working tool. The Board adopted four templates by decision 2024/959 of 4 June 2024, for controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers, and the Regulation requires the parties to use the template that fits their roles, to sign it through persons authorised to bind them, and to treat the Turkish text as authoritative where a foreign-language version is also signed. Article 9(5) then requires the controller or processor to notify the signed contract to the Authority within five business days of the last signature. Missing that deadline is a separate offence under Article 18(1)(d), fined in 2026 from 90,308 to 1,806,177 lira, and the fine may be imposed on the controller or on a private-law processor. Binding corporate rules are the alternative for a large group and require a Board approval on an application with notarised translations of every foreign-language document.
What counts as a transfer is broad: transmitting data to a recipient abroad or making it accessible from abroad. A Turkish subsidiary whose payroll, e-mail, customer relationship or document systems are hosted or administered outside Turkey is transferring, and so is a group service desk that can open the Turkish records remotely. The identity documents a foreign founder or client hands over at onboarding, described on the remote onboarding page, and the know-your-customer files a bank collects, described on the bank account page, are the everyday examples of data that leaves Turkey when a group centralises compliance.
Security and breach: seventy-two hours, and the sixty-day notice board
Article 12 obliges the controller to take every technical and organisational measure needed to prevent unlawful processing and access and to keep the data, makes it jointly responsible with any processor for those measures, requires it to audit its own compliance, and in paragraph 5 requires it to notify the data subject and the Board "within the shortest time" when data are obtained by others unlawfully. Board decision 2019/10 fixed that phrase at seventy-two hours from the moment the controller learns of the breach, with the reasons for any delay to be explained, notification on the Board's form, information supplied in stages where it cannot all be given at once, affected persons informed within the shortest reasonable time directly or, failing a contact address, through the controller's website, a written record of every breach kept for the Board, a duty on processors to inform the controller without delay, a breach response plan assigning internal responsibility, and, as noted above, the same duty for controllers abroad whose breach affects users in Turkey. By decision 2025/2451 of 25 December 2025 the Board limited its own publication of breach notices on its website to sixty days, and removes a notice earlier where the controller proves it has informed the affected persons within a shorter period; the seventy-two-hour rule is unchanged. A security failure is fined under Article 18(1)(b), in 2026 from 256,357 to 17,092,242 lira, and the crimes in Articles 135 to 140 of the Penal Code, to which Article 17 refers, sit behind the administrative fine.
The fines in 2026, and how they are challenged
| Breach | Provision | 2026 range in lira |
|---|---|---|
| Failure to inform data subjects under Article 10 | Article 18(1)(a) | 85,437 to 1,709,200 |
| Failure to meet the security obligations of Article 12 | Article 18(1)(b) | 256,357 to 17,092,242 |
| Failure to comply with a Board decision under Article 15 | Article 18(1)(c) | 427,263 to 17,092,242 |
| Breach of the registry and notification duties of Article 16 | Article 18(1)(ç) | 341,809 to 17,092,242 |
| Failure to notify a standard contract within five business days under Article 9(5) | Article 18(1)(d) | 90,308 to 1,806,177 |
The statutory amounts are revalued every January under the Misdemeanours Law at the revaluation rate, which was 25.49 per cent for 2026, and the Authority publishes the table each December. Article 18(2) imposes the first four fines on the controller and the fifth on the controller or a private-law processor. Since 1 June 2024, Article 18(3) sends appeals against the Board's fines to the administrative courts rather than the criminal judgeships of the peace, with applications already pending on that date left where they were under Provisional Article 3. Where the offender is a public body, disciplinary rules apply instead.
A foreign company's first year, in one table
| Situation | What the law requires | Where the risk sits |
|---|---|---|
| Turkish subsidiary formed, first employees hired | Privacy notices under Article 10, a lawful basis per process, a retention policy, a contact person; VERBİS registration once the subsidiary has fifty employees or a hundred-million-lira balance sheet | Consent used as the basis for payroll and monitoring; special-category data without an Article 6(3) basis |
| Group HR, e-mail or CRM hosted abroad | A processing condition, a standard contract in the Board's template signed by both sides, notification within five business days, onward-transfer terms | The five-day deadline; a modified or English-only template; no notification when the processor changes |
| Parent abroad decides purposes for Turkish data | Turkish representative appointed by certified resolution, VERBİS registration through the representative, public entry kept current | Assuming the parent is outside the law because it has no Turkish entity |
| Foreign retailer or platform serving Turkish customers | Notices, bases and rights handling for Turkish users, representative and registration, breach notification to the Board | Breach in the foreign system affecting Turkish users, unreported within seventy-two hours |
| Short-term rental host or hotel keeping guest records | Identity data processed under the reporting duties on the short-term rental page, retention limited to the legal period | Copies of passports kept indefinitely or e-mailed abroad |
Whose side we are on, and how we are paid
The software vendor that sold the HR platform is paid whether or not a standard contract was filed. The consultancy that sells compliance packages is paid per document. None of them is paid to tell you that the parent needs a Turkish representative, that consent will not carry the payroll, or that the five-day clock on the standard contract has already run.
We take no commission or referral fee from software vendors, consultancies or corporate service providers, in any form, on any file. The fee you pay us is our only income from your matter, and it does not depend on how many documents you buy or which system you choose. Because our position does not move with the outcome, telling you that your existing group agreement already does most of the work, or that your data does not leave Turkey at all, costs us nothing to say.
One boundary, stated plainly. We are lawyers, not licensed investment advisers and not your information security contractor. We do not certify systems or choose your cloud. What we protect is the Turkish legal position: the classification of each entity as controller or processor, the basis for each process, the registration and the representative, the transfer instrument that fits the flow and its filing, the breach procedure, and the answers when the Board asks.
Before you connect the Turkish company to the group
Send us a map of the systems the Turkish company will use and where each is hosted, the group's existing data processing agreements, the headcount and balance sheet you expect, and any special categories the business handles. We will tell you which entities are controllers, whether registration is due and for whom, which transfer instrument fits each flow and what must be filed and when, what the notices and the retention policy must say, and what the breach plan must contain. Our corporate work is described on the corporate law page, and the work permits for the staff who will run these systems on the founder work permit page.
What this page does not settle
Commercial electronic messages and the message management system under the Electronic Commerce Law, the Board's cookie guidance, sector rules for banks, telecommunications and health providers, employee monitoring beyond the biometric principle decision noted above, the Board's decisions on artificial intelligence, and the criminal procedure under the Penal Code are separate subjects. Fine amounts are revalued each January and Board decisions change the practice; the figures above are those in force on the date checked.




