Skip to content

Data Protection (KVKK) Consulting

Modern corporate architecture — skyscrapers from below
Complementary Practice

Data Protection (KVKK) Consulting

Mapping your data-processing activities under KVKK and GDPR: policies, VERBIS filings and breach response.

Türkiye’s Law No. 6698 on the Protection of Personal Data reaches almost every business that processes personal data — an online retailer, a manufacturer keeping customer records in its accounting software, any employer holding personnel files. Falling outside its scope is far harder than most companies assume.

The purpose of a compliance programme is not to produce a folder of documents. It is to make knowable where data enters the company, where it sits, who it is shared with and when it is deleted. A company that cannot answer those questions cannot explain itself in an audit or a breach — that is where the real exposure lies.

Core obligations

  1. Data inventory. What data is processed, for what purpose, on what legal basis; where it is stored, to whom it is transferred, for how long it is kept. The whole structure rests on this inventory; policies drafted without one do not describe reality.
  2. Legal basis analysis. Every processing activity needs a legal basis. Explicit consent is only one of them and often the weakest: being revocable, it is unsuited to processing that must continue. Performance of a contract, legal obligation and legitimate interest are sounder in most scenarios.
  3. Information duty. Data subjects must be informed when their data is collected. The information notice and the consent text are separate documents and should not be merged into a single tick-box — a frequent mistake.
  4. VERBIS registration. Controllers meeting the statutory thresholds must register with the Data Controllers’ Registry and keep their entry current. It is not a one-off task; it must be updated as the inventory changes.
  5. Retention and destruction policy. How long data is kept and how it is deleted when the period ends, set out in writing and actually applied. Data retained indefinitely "in case we need it" is among the most common causes of breach.
  6. Technical and organisational measures. Access matrices, logging, encryption, backups, staff confidentiality undertakings and regular awareness training. A measure on paper has no defensive value unless it is operated.

Breach: the 72-hour window

When a breach occurs — ransomware, unauthorised access, a list sent to the wrong recipient — it must be notified to the Board as soon as reasonably possible; in practice this is expected within seventy-two hours of becoming aware. Notification to affected individuals may also be required.

The shortness of that window is the real problem for an unprepared company. If it is not settled in advance who decides, who investigates and who drafts the notification, the time is consumed by the technical investigation. The most practical output of a compliance programme is therefore a pre-written incident response plan.

Transfers abroad

Cloud services, email infrastructure, CRM and analytics tools — much of the everyday stack amounts to transferring data abroad. Those transfers need their own legal basis and, where required, appropriate safeguards. Most companies discover which tools send data where during the inventory exercise.

Relationship with the GDPR

If you offer goods or services to people in the EU or monitor their behaviour, you may fall within the GDPR even while established in Türkiye. KVKK and GDPR share a logic but diverge in concepts and obligations. For exporters with EU customers, compliance work has to address both regimes together.

Where this meets intellectual property

Data compliance is the natural neighbour of IP work. Employee confidentiality undertakings protect both personal data and trade secrets; customer lists and price tables are usually both at once. In acquisition due diligence, IP and data compliance are examined at the same table.

Internal use of AI tools creates a new intersection: content fed in as input has to be assessed for data protection and copyright at the same time.

How the work runs

  • Current-state assessment — which systems are in use, where data sits, what existing texts say.
  • Building the data inventory and processing records, verified through departmental interviews.
  • Mapping legal bases and prioritising risk — not every gap carries the same urgency.
  • Document set: information notices, consent texts, retention and destruction policy, employee undertakings, processor agreements.
  • VERBIS registration or update.
  • Incident response plan and responsibility matrix.
  • Awareness training and a periodic review schedule.

Data subject requests: the thirty-day duty

Anyone whose data is processed may ask the controller for access, rectification, erasure, or notification to third parties the data was transferred to. A written request must be answered within thirty days.

The practical difficulty is operational rather than legal. "Delete all of this person’s data" cannot be satisfied in thirty days by a company whose data sits scattered across a CRM, accounting software, an email archive, backups and marketing tools. This is where the inventory earns its keep: meeting the request depends on already knowing where the data is.

Requests left unanswered or answered late open the route to a complaint to the Board — in practice the most common way an investigation begins.

Employee data: the most overlooked area

Companies tend to frame compliance around customer data, yet the most sensitive categories usually sit in HR files: medical reports, criminal record certificates, personnel file documents and candidate data gathered during recruitment.

  • How long are the CVs of unsuccessful candidates kept? Indefinite retention is a frequent breach.
  • Who can access health data — is the line between the workplace physician and HR actually drawn?
  • Are the purpose, retention period and access rights for CCTV and entry logs defined?
  • If corporate devices and email are monitored, were employees informed in advance?
  • On termination, which data is retained, for how long, and which is destroyed?

Frequently asked questions

We are a small company — does KVKK apply to us?

The law does not exempt by company size; any business processing staff or customer data is a controller. VERBIS registration depends on thresholds, but not having to register does not exempt you from the other obligations.

Is a privacy notice on our website enough?

No. Without an inventory and processes actually operated behind it, a notice is only an assertion. The audit question is not "do you have a text" but "do you work the way your text says".

Should we collect explicit consent for everything?

No — in most cases you should not. Consent is revocable, and basing processing on it where performance of a contract or a legal obligation would serve leaves you without a basis the moment consent is withdrawn. Choosing the right legal basis is the most technical and most consequential decision in compliance.

Is compliance a one-off project?

No. A new tool, a new marketing channel or a new department changes the inventory. Compliance is a standing structure that needs reviewing at least annually.

Does using a cloud service count as transfer abroad?

Storing data on servers outside the country is a transfer, and the provider having a Turkish office does not change that. What matters is where the data actually sits and who can reach it. Each tool’s data location should therefore be established during the inventory — the location in practice, not the one in the contract.

We use a processor — does responsibility pass to them?

No. Controller status cannot be delegated; working with an accountancy firm, a call centre or a software vendor does not discharge you. Such relationships need a written processor agreement and verification of the supplier’s security measures. If a breach happens on their systems, you will still be answering for it.

Let us map your data processes — get in touch.

This page is general information and does not constitute legal advice. The scope of obligations depends on the categories of data and the processing activities involved.

Call nowWhatsAppMessage us