Does Turkish Data Protection Law Apply to Your Company? KVKK for Foreign Businesses
July 28, 2026KVKK/GDPR

Does Turkish Data Protection Law Apply to Your Company? KVKK for Foreign Businesses

All Articles
Last updated: August 2, 2026

Turkish data protection law can bind a company with no presence in Turkey. Law No. 6698, the Turkish Personal Data Protection Law known as KVKK, says nothing about its territorial scope, but the Turkish Data Protection Board has read it broadly, imposing fines on companies with no establishment here for processing the data of people who are in Turkey. The practical triggers are unremarkable: selling to customers in Turkey, running a Turkish-language website or app, employing people in the country, receiving HR and customer data from a Turkish subsidiary. Being GDPR-compliant helps, but it does not answer the Turkish questions, because KVKK diverges from the GDPR precisely at the points where compliance is operational rather than conceptual.

When KVKK reaches a foreign company

The Board's approach is effects-based. A Turkish-language interface, prices in lira, delivery to Turkish addresses, a measurable Turkish user base: each of these has featured in decisions extending KVKK to foreign controllers. Enforcement is complaint-driven in practice. A dissatisfied customer, a former employee or a competitor files a complaint, and the first thing the Board examines is whether the company has met its formal obligations. That is why the formal layer, unglamorous as it is, decides most files.

VERBİS registration and the Turkey representative

Data controllers established abroad are required to register with the Turkish data controllers' registry, VERBİS, before processing, and the exemption thresholds that spare many small Turkish companies do not apply to them. Registration requires appointing a representative in Turkey, either a Turkish citizen or a legal entity established here, through a formally executed and apostilled resolution.

For companies established in Turkey, including Turkish subsidiaries of foreign groups, registration depends on thresholds: as of mid-2026, fifty or more employees in a year, a balance sheet above the statutory figure, or processing of sensitive data as a main activity. The registry entry is public, and in complaint files the Board routinely compares what a company declared in VERBİS with what its privacy notices say and what it actually does. An inaccurate registration is worse than a late one.

The 2024 rewrite of cross-border transfers

This is the part experienced GDPR practitioners most often misread. Until 2024, transferring personal data out of Turkey rested in practice on explicit consent, because the alternative, a Board-approved undertaking, was rarely granted. Law No. 7499 rebuilt Article 9 of KVKK with a familiar-looking architecture: adequacy decisions, appropriate safeguards including standard contractual clauses published by the Authority, binding corporate rules, and explicit consent only as a residual option for occasional transfers.

Two operational points matter more than the architecture. First, the Board has not yet published adequacy decisions, so for routine intra-group flows the standard contractual clauses are the workhorse. Second, a signed standard contract must be notified to the Authority within five business days of signature, and missing that filing carries its own administrative fine, separate from any substantive violation. Every foreign group whose Turkish affiliate shares HR, CRM or finance data with headquarters needed new paperwork after September 2024. A surprising number still have none.

Where KVKK actually bites harder than the GDPR

The privacy notice, called aydınlatma, must be given at the moment of collection, with mandatory content, and for data subjects in Turkey it should be in Turkish. Consent must be specific and freely given; consent bundled into general terms is treated as invalid. KVKK recognises a legitimate-interest basis, but it is read more narrowly than its GDPR counterpart, so processing that comfortably rests on legitimate interest in Europe may need another basis here. Data breaches must be notified to the Board within seventy-two hours under established Board practice, and to affected individuals without delay; the Board publishes a selection of breach notifications on its website, which turns a legal problem into a public one. Administrative fines are revalued every year and the upper bands have grown well beyond symbolic levels. There is no DPO under KVKK: Turkish-established controllers appoint a contact person, and foreign controllers act through their registered representative.

What we recommend doing, in order

Map the data flows that touch Turkey, including the quiet ones such as a group HR system hosted abroad. Decide the registration question honestly, because it is the first thing the Board checks. Put standard contractual clauses under intra-group transfers and diarise the five-day filings. Bring the Turkish-language notices in line with what actually happens to the data. Prepare a breach playbook that assumes the seventy-two-hour clock starts on a Friday evening. In our experience, the companies that struggle are rarely the ones with bad intentions; they are the ones that assumed their GDPR file would translate itself.

Questions we are asked often

We are GDPR compliant. Is that enough? No. VERBİS registration, the representative, Turkish-language notices and transfer filings have no GDPR equivalent. The overlap in principles does not extend to the paperwork.

Do we need to establish a Turkish company? No. A registered representative satisfies the formal requirements. Whether you need an entity is a commercial and tax question, not a KVKK one.

What is the realistic exposure for a company with no assets in Turkey? Fines are harder to collect abroad, but that is rarely the point. Turkish counterparties increasingly demand KVKK compliance contractually, public breach listings damage the brand, and enforcement tends to arrive at the moment a company is negotiating something that matters in Turkey.

Uçkun Aktaş Öksüm advises international companies on KVKK compliance programmes, VERBİS registration, cross-border transfer documentation and breach response. This note is general information, not legal advice on any specific case, and reflects the law in force in July 2026.

Related practice area: Data Protection Law

Consultation

You may send your questions and documents regarding your situation; enquiries are treated in confidence.