Technology

Turkey's Data Protection Law (KVKK, Law No. 6698) for Foreign Companies: Who Is Caught, VERBİS Registration and the Turkish Representative, the 2024 Cross-Border Transfer Rules, Breach Deadlines and the 2026 Fines

Turkey's data protection law (KVKK, Law 6698) for foreign companies: VERBİS registration, the 2024 transfer rules, breach deadlines and the 2026 fines.

Rohat Kahraman· 9 September 2026Updated · 9 September 2026
Turkey data protection law 6698 (KVKK) for foreign companies: registration, transfers abroad, breach deadlines and fines

Turkey's data protection law is older than the GDPR, was modelled on the directive the GDPR replaced, and since June 2024 has a transfer regime that looks European and is enforced by an authority that has published no adequacy decision for any country. In my files the American software group that runs its Turkish subsidiary's payroll on a system in Virginia, the German parent whose Istanbul office reports to a shared HR platform in Munich, and the British online retailer that ships to Turkish customers from Manchester are all transferring personal data abroad under Law 6698, all needed a standard contract filed with the Authority within five business days of signing it, and two of them needed a Turkish representative on a public register before they processed a single record. This page sets out who the law reaches, the legal bases and what changed in 2024, the registry and the representative, the cross-border transfer regime as it stands in 2026, the breach deadlines, and the fines as revalued for 2026.

Sources, checked 9 September 2026. Law No. 6698 on the Protection of Personal Data (Official Gazette 29677, 7 April 2016) as amended by Law No. 7499 (Official Gazette 32487, 12 March 2024), Articles 3 to 7, 9 to 18 and Provisional Article 3; Regulation on the Data Controllers' Registry (Official Gazette 30286, 30 December 2017, amended 28 April 2019); Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (Official Gazette 32598, 10 July 2024); Personal Data Protection Board decisions 2018/87 and 2023/1154 on registration exemptions, 2025/1572 of 4 September 2025, 2019/10 of 24 January 2019 on breach notification, 2024/959 of 4 June 2024 on standard contracts and binding corporate rules, and 2025/2451 of 25 December 2025 on the publication of breach notices; the Authority's table of administrative fines for 2026 (31 December 2025) and its Guide No. 48 on transfers abroad (January 2025).

Who the law reaches: the subsidiary, the branch, the office and the parent abroad

Law 6698 applies to every natural or legal person that processes personal data wholly or partly by automated means, or as part of a filing system. Article 3 defines the data controller as the person who determines the purposes and means of processing and is responsible for the filing system, and the data processor as the person who processes on the controller's behalf and authority. There is no threshold of size, no exemption for foreign ownership and no separate regime for a company that has just arrived. A Turkish subsidiary is a controller for its employees, customers and suppliers from the day it hires or sells. A liaison office that may not trade still employs people and is a controller for their data; the forms and their limits are on the liaison office, branch and subsidiary page. A foreign parent that decides how the group's HR or customer systems work, and receives the Turkish data into them, is a controller in its own right, and the Turkish company that feeds those systems is a controller exporting data abroad.

The law has no territorial-scope article of the GDPR kind, but the Authority applies it to companies outside Turkey through two instruments. Article 11 of the Registry Regulation requires a legal person established abroad that is a controller to appoint a data controller representative, who must be a legal person established in Turkey or a Turkish citizen, by a certified resolution submitted through the representative, and the appointment does not shift liability: the Authority's own guidance states that responsibility for the law's obligations and sanctions stays with the foreign controller's authorised organs. Board decision 2019/10 then requires a controller established abroad to notify the Board of a breach on the same terms as a Turkish one where the breach affects persons in Turkey who use its products or services in Turkey. A foreign company selling to Turkish residents online, or hiring them remotely, should assume it is inside the law rather than argue later that it was not.

Article 5 starts from explicit consent, defined in Article 3 as freely given, specific and informed, and then lists the bases on which data may be processed without it: an express provision of law; protection of life or physical integrity; processing necessary for a contract with the data subject; a legal obligation of the controller; data made public by the data subject; the establishment, exercise or protection of a right; and the controller's legitimate interests where they do not override the data subject's fundamental rights. Article 4 adds the principles of lawfulness, accuracy, purpose limitation, proportionality and limited retention, and Article 7 requires erasure, destruction or anonymisation when the purpose ends.

Article 6 is where the 2024 amendment mattered most for employers. Special categories, which include health, biometric and genetic data, trade union membership and criminal convictions, were until June 2024 processable in practice only with explicit consent or, for health data, by persons under a duty of confidentiality. Law 7499 rewrote Article 6(3) and now permits processing where a law expressly provides for it, where it is necessary to protect life, where the data subject made the data public, where it is needed to establish or defend a right, for health services by confidentiality-bound persons or competent bodies, and where it is necessary to fulfil legal obligations in employment, occupational health and safety, social security and social assistance. A Turkish employer's medical reports and workplace physician files, which sit under the obligations described on the employment law page, now have a statutory basis; biometric attendance systems do not, and are the subject of the Board's principle decision 2026/921 of 29 April 2026 on biometric time tracking. Explicit consent from an employee remains a weak basis because of the imbalance between the parties, and I do not let a client build a payroll or monitoring process on it.

Two duties attach to every processing operation whatever the basis. Article 10 requires the controller, or the person it authorises, to inform data subjects at the time of collection of the controller's identity and that of any representative, the purpose, to whom and why the data may be transferred, the method and legal basis of collection, and the rights under Article 11. Article 13 requires the controller to answer a data subject's request within thirty days and free of charge; under Article 14 the data subject may complain to the Board within thirty days of the answer or sixty days of the request, and under Article 15 the Board may demand documents within fifteen days, inspect on the spot, and order remedies to be carried out within thirty days.

VERBİS: the public registry, the thresholds and the representative

Article 16 requires anyone who processes personal data to register with the Data Controllers' Registry, VERBİS, before starting to process, unless the Board has exempted them. The exemption that matters to a new subsidiary is the one in Board decision 2018/87 as amended by decision 2023/1154: a controller with fewer than fifty employees and an annual balance sheet total below one hundred million lira is exempt, unless its main activity is the processing of special categories of data. Decision 2025/1572 of 4 September 2025 added a narrower exemption for controllers whose main activity is special-category data, at fewer than ten employees and a balance sheet below ten million lira. A subsidiary that crosses either line registers, and a registered controller must keep a personal data processing inventory and a retention and destruction policy in the form the Registry Regulation prescribes, and enter a contact person in Turkey who liaises with the Authority but does not represent the controller.

For the parent abroad the position is different. A controller established outside Turkey registers through its Turkish representative under Article 11 of the Regulation, and the representative's appointment resolution, certified, is filed with the Authority. Registration is public: the Authority publishes the registry on its website, so the parent's data categories, purposes, recipient groups and retention periods are visible to anyone. Failure to register or to keep the entry current is fined under Article 18(1)(ç), which in 2026 runs from 341,809 to 17,092,242 lira. The company formation steps that precede the first registration are on the company set-up page.

Cross-border transfers since 1 June 2024: adequacy, safeguards, exceptions

Until June 2024 Article 9 allowed a transfer abroad only with explicit consent, or to a country the Board had declared adequate, or on a written undertaking approved by the Board; the Board never declared any country adequate, and approvals of undertakings were rare, so most groups ran on consent. Law 7499 replaced Article 9 with effect from 1 June 2024, kept the old consent route alive alongside the new regime until 1 September 2024 under Provisional Article 3, and the Regulation of 10 July 2024 filled in the procedure.

The new regime has three tiers. Under Article 9(1) a transfer is permitted where a processing condition under Article 5 or 6 is met and the Board has issued an adequacy decision for the destination country, a sector within it or an international organisation; adequacy decisions are published in the Official Gazette and reviewed at least every four years. The Authority's transfer page states that no such decision has yet been made, so this tier is empty in 2026. Under Article 9(4), absent an adequacy decision, a transfer is permitted where a processing condition is met, the data subject retains enforceable rights and effective remedies in the destination, and one of four safeguards is in place: an agreement between public bodies with the Board's approval; binding corporate rules approved by the Board for a group of undertakings; a standard contract in the form published by the Board; or a written undertaking of adequate protection with the Board's approval. Under Article 9(6), where neither tier is available, a transfer may be made only if it is incidental and one of the listed circumstances applies: explicit consent after information about the risks, performance of a contract with or for the benefit of the data subject, an overriding public interest, the establishment or defence of a right, protection of life, or transfer from a public register. Article 9(8) extends the safeguards to onward transfers from the recipient.

For a foreign-owned company the standard contract is the working tool. The Board adopted four templates by decision 2024/959 of 4 June 2024, for controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers, and the Regulation requires the parties to use the template that fits their roles, to sign it through persons authorised to bind them, and to treat the Turkish text as authoritative where a foreign-language version is also signed. Article 9(5) then requires the controller or processor to notify the signed contract to the Authority within five business days of the last signature. Missing that deadline is a separate offence under Article 18(1)(d), fined in 2026 from 90,308 to 1,806,177 lira, and the fine may be imposed on the controller or on a private-law processor. Binding corporate rules are the alternative for a large group and require a Board approval on an application with notarised translations of every foreign-language document.

What counts as a transfer is broad: transmitting data to a recipient abroad or making it accessible from abroad. A Turkish subsidiary whose payroll, e-mail, customer relationship or document systems are hosted or administered outside Turkey is transferring, and so is a group service desk that can open the Turkish records remotely. The identity documents a foreign founder or client hands over at onboarding, described on the remote onboarding page, and the know-your-customer files a bank collects, described on the bank account page, are the everyday examples of data that leaves Turkey when a group centralises compliance.

Security and breach: seventy-two hours, and the sixty-day notice board

Article 12 obliges the controller to take every technical and organisational measure needed to prevent unlawful processing and access and to keep the data, makes it jointly responsible with any processor for those measures, requires it to audit its own compliance, and in paragraph 5 requires it to notify the data subject and the Board "within the shortest time" when data are obtained by others unlawfully. Board decision 2019/10 fixed that phrase at seventy-two hours from the moment the controller learns of the breach, with the reasons for any delay to be explained, notification on the Board's form, information supplied in stages where it cannot all be given at once, affected persons informed within the shortest reasonable time directly or, failing a contact address, through the controller's website, a written record of every breach kept for the Board, a duty on processors to inform the controller without delay, a breach response plan assigning internal responsibility, and, as noted above, the same duty for controllers abroad whose breach affects users in Turkey. By decision 2025/2451 of 25 December 2025 the Board limited its own publication of breach notices on its website to sixty days, and removes a notice earlier where the controller proves it has informed the affected persons within a shorter period; the seventy-two-hour rule is unchanged. A security failure is fined under Article 18(1)(b), in 2026 from 256,357 to 17,092,242 lira, and the crimes in Articles 135 to 140 of the Penal Code, to which Article 17 refers, sit behind the administrative fine.

The fines in 2026, and how they are challenged

BreachProvision2026 range in lira
Failure to inform data subjects under Article 10Article 18(1)(a)85,437 to 1,709,200
Failure to meet the security obligations of Article 12Article 18(1)(b)256,357 to 17,092,242
Failure to comply with a Board decision under Article 15Article 18(1)(c)427,263 to 17,092,242
Breach of the registry and notification duties of Article 16Article 18(1)(ç)341,809 to 17,092,242
Failure to notify a standard contract within five business days under Article 9(5)Article 18(1)(d)90,308 to 1,806,177

The statutory amounts are revalued every January under the Misdemeanours Law at the revaluation rate, which was 25.49 per cent for 2026, and the Authority publishes the table each December. Article 18(2) imposes the first four fines on the controller and the fifth on the controller or a private-law processor. Since 1 June 2024, Article 18(3) sends appeals against the Board's fines to the administrative courts rather than the criminal judgeships of the peace, with applications already pending on that date left where they were under Provisional Article 3. Where the offender is a public body, disciplinary rules apply instead.

A foreign company's first year, in one table

SituationWhat the law requiresWhere the risk sits
Turkish subsidiary formed, first employees hiredPrivacy notices under Article 10, a lawful basis per process, a retention policy, a contact person; VERBİS registration once the subsidiary has fifty employees or a hundred-million-lira balance sheetConsent used as the basis for payroll and monitoring; special-category data without an Article 6(3) basis
Group HR, e-mail or CRM hosted abroadA processing condition, a standard contract in the Board's template signed by both sides, notification within five business days, onward-transfer termsThe five-day deadline; a modified or English-only template; no notification when the processor changes
Parent abroad decides purposes for Turkish dataTurkish representative appointed by certified resolution, VERBİS registration through the representative, public entry kept currentAssuming the parent is outside the law because it has no Turkish entity
Foreign retailer or platform serving Turkish customersNotices, bases and rights handling for Turkish users, representative and registration, breach notification to the BoardBreach in the foreign system affecting Turkish users, unreported within seventy-two hours
Short-term rental host or hotel keeping guest recordsIdentity data processed under the reporting duties on the short-term rental page, retention limited to the legal periodCopies of passports kept indefinitely or e-mailed abroad

Whose side we are on, and how we are paid

The software vendor that sold the HR platform is paid whether or not a standard contract was filed. The consultancy that sells compliance packages is paid per document. None of them is paid to tell you that the parent needs a Turkish representative, that consent will not carry the payroll, or that the five-day clock on the standard contract has already run.

We take no commission or referral fee from software vendors, consultancies or corporate service providers, in any form, on any file. The fee you pay us is our only income from your matter, and it does not depend on how many documents you buy or which system you choose. Because our position does not move with the outcome, telling you that your existing group agreement already does most of the work, or that your data does not leave Turkey at all, costs us nothing to say.

One boundary, stated plainly. We are lawyers, not licensed investment advisers and not your information security contractor. We do not certify systems or choose your cloud. What we protect is the Turkish legal position: the classification of each entity as controller or processor, the basis for each process, the registration and the representative, the transfer instrument that fits the flow and its filing, the breach procedure, and the answers when the Board asks.

Before you connect the Turkish company to the group

Send us a map of the systems the Turkish company will use and where each is hosted, the group's existing data processing agreements, the headcount and balance sheet you expect, and any special categories the business handles. We will tell you which entities are controllers, whether registration is due and for whom, which transfer instrument fits each flow and what must be filed and when, what the notices and the retention policy must say, and what the breach plan must contain. Our corporate work is described on the corporate law page, and the work permits for the staff who will run these systems on the founder work permit page.

What this page does not settle

Commercial electronic messages and the message management system under the Electronic Commerce Law, the Board's cookie guidance, sector rules for banks, telecommunications and health providers, employee monitoring beyond the biometric principle decision noted above, the Board's decisions on artificial intelligence, and the criminal procedure under the Penal Code are separate subjects. Fine amounts are revalued each January and Board decisions change the practice; the figures above are those in force on the date checked.

Legal basis

  • Kişisel Verilerin Korunması Kanunu (Law No. 6698)m.3, 4, 5, 6, 7, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, geçici m.3Consolidated text with Law 7499 amendments: definitions, bases, special categories, transfers abroad, information duty, rights, security and breach, requests and complaints, registry, crimes, fines and appeals, transitionOfficial text
  • Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelikm.5, 6, 10, 14, 16Official Gazette 32598, 10 July 2024: transfer tiers, safeguards, standard contract signature, language and notification, incidental transfersOfficial text
  • Veri Sorumluları Sicili Hakkında Yönetmelikm.4, 5, 11, 12Official Gazette 30286, 30 December 2017, amended 28 April 2019: registration before processing, foreign controllers through a representative, inventory, contact person, communicationOfficial text
  • Kişisel Verileri Koruma Kurulu Kararı 2023/11546 July 2023: registration exemption threshold raised to under 50 employees and under TRY 100 million balance sheet, amending decision 2018/87Official text
  • Kişisel Verileri Koruma Kurumu Kamuoyu Duyurusu, Kurul Kararı 2025/15721 October 2025: special-category controllers under 10 employees and TRY 10 million exempt from registrationOfficial text
  • Kişisel Verileri Koruma Kurulu Kararı 2019/1024 January 2019: 72-hour breach notification, affected persons, form, response plan, processors, foreign controllersOfficial text
  • Kişisel Verileri Koruma Kurumu, Yurt Dışına AktarımAuthority page: amended Article 9 in force 1 June 2024, decision 2024/959 on standard contracts and binding corporate rules, no adequacy decision yet madeOfficial text
  • Kişisel Verileri Koruma Kurumu, Kişisel Verilerin Yurt Dışına Aktarılması Rehberi (Yayın No. 48)January 2025: five-business-day notification, incidental transfers, standard contract language and signature, binding corporate rules applicationsOfficial text
  • Kişisel Verileri Koruma Kurumu, 6698 Sayılı Kanun Kapsamında İdari Para Cezası Tutarları31 December 2025: 2017 to 2026 fine table, 2026 revaluation 25.49%Official text
  • Kişisel Verileri Koruma Kurulu Kararı 2025/245125 December 2025: breach notices published for at most 60 days, earlier removal on proof of notifying affected persons; Authority announcement of 20 January 2026 read in this reproduction, official page not located on the date checkedOfficial text

Frequently asked questions

Does Turkey's data protection law apply to a company with no Turkish entity?

In practice yes. A controller established abroad that processes data of persons in Turkey must appoint a Turkish representative and register under Article 11 of the Registry Regulation, and Board decision 2019/10 requires it to notify breaches affecting users in Turkey.

Is Turkey covered by a GDPR adequacy decision?

No, and the reverse is also true: the Turkish Board has published no adequacy decision for any country, so transfers out of Turkey rely on the safeguards in Article 9(4), usually the Board's standard contract.

What is the deadline for notifying a standard contract?

Five business days after the last signature, under Article 9(5), by the controller or the processor. The 2026 fine for missing it runs from 90,308 to 1,806,177 lira under Article 18(1)(d).

When must a Turkish subsidiary register with VERBİS?

Before processing, unless exempt. Under Board decisions 2018/87 and 2023/1154 a controller with fewer than fifty employees and a balance sheet under one hundred million lira is exempt, unless its main activity is special-category data.

How quickly must a data breach be reported in Turkey?

To the Board within seventy-two hours of learning of it under decision 2019/10, and to affected persons within the shortest reasonable time; since decision 2025/2451 the Board publishes notices for at most sixty days.

Can an employer rely on employee consent?

It is a lawful basis in form, but a weak one given the imbalance between the parties. Since June 2024, Article 6(3)(f) gives a statutory basis for special-category data needed to meet employment, health and safety and social security obligations.

What are the maximum fines in 2026?

17,092,242 lira for security failures, non-compliance with Board decisions and registry breaches; 1,709,200 lira for failure to inform; 1,806,177 lira for failure to notify a standard contract.

Where are Board fines appealed?

Since 1 June 2024, in the administrative courts under Article 18(3), replacing the criminal judgeships of the peace.