KVKK and Cross-Border Data Transfers for Foreign-Owned Companies in Turkey

KVKK and Cross-Border Data Transfers for Foreign-Owned Companies in Turkey

KVKK and Cross-Border Data Transfers for Foreign-Owned Companies in Turkey

A foreign group that establishes a Turkish subsidiary usually discovers data protection late — often when the parent's HR system needs employee records, or when a customer database is to be consolidated. Turkish law treats both as a transfer abroad, and until 2024 that was a considerably harder problem than most groups expected. The framework has since changed. This article sets out where it now stands and what a foreign-owned company should actually do.

The framework

Personal data protection in Türkiye is governed by Law No. 6698 on the Protection of Personal Data — the KVKK — supervised by the Personal Data Protection Authority and its Board. The law is modelled on European data protection principles and predates the GDPR, with which it shares much of its architecture and from which it differs in important details.

The law applies to any controller processing personal data in Türkiye, including a Turkish subsidiary of a foreign group and, in defined circumstances, a foreign company processing the data of people in Türkiye.

The 2024 change on transfers abroad

This is the development that matters most to foreign-owned companies.

Under the original Article 9, transferring personal data abroad required either explicit consent or one of the lawful bases plus adequate protection — which in practice meant either a Board decision that the destination country provided adequate protection, or a written undertaking approved by the Board. The Board published no adequacy decisions, and approvals of undertakings were rare and slow. The result was a system in which lawful transfer was theoretically possible and practically very difficult, and a great deal of transferring happened on explicit consent that was fragile.

Article 9 was amended with effect from June 2024 to introduce a structure closer to the European model, providing for transfers on the basis of adequacy decisions, and — in their absence — on appropriate safeguards including standard contractual clauses, binding corporate rules, undertakings and international agreements, with defined exceptional cases for occasional transfers.

Where standard contractual clauses are used, the executed clauses must be notified to the Authority within a prescribed period. That notification obligation is the practical trap: groups adopt the clauses, treat the matter as closed, and overlook the filing.

What a foreign-owned Turkish company must do

  • Register with VERBIS, the Data Controllers' Registry, where the applicable thresholds are met. Registration is public and its absence is visible.
  • Maintain a personal data inventory — what data, from whom, why, on what basis, retained how long, shared with whom.
  • Issue clarification notices to employees, customers and website users at the point of collection.
  • Obtain explicit consent where it is the basis relied on, in a form that is specific, informed and freely given — and remember that consent conditioned on employment or on receiving a service is not freely given.
  • Document the transfer basis for every flow of data to the parent or to group systems.
  • Notify standard contractual clauses to the Authority where they are the basis relied on.
  • Implement technical and organisational measures proportionate to the data.
  • Have a breach procedure. Breaches must be notified to the Authority within a short period, and to affected individuals.
  • Apply retention and destruction periods, with a documented policy.

The flows that catch groups out

The word "transfer" is broader than it sounds. Each of the following is a transfer abroad:

  • A group HR system hosted outside Türkiye holding Turkish employees' records.
  • A CRM system on servers abroad containing Turkish customer data.
  • Cloud storage, email and collaboration platforms hosted outside the country.
  • Sending customer or employee data to the parent for reporting or consolidation.
  • Group-wide compliance and whistleblowing systems.
  • Support arrangements under which a foreign team can access Turkish systems remotely — access is transfer.

Almost every foreign-owned company does several of these. The question is not whether transfers happen but whether their basis is documented.

KVKK and GDPR are not the same

A group that is GDPR-compliant has a substantial head start and is not compliant in Türkiye by virtue of that fact. Differences that matter in practice:

  • Turkish law requires registration with VERBIS; the GDPR has no equivalent general register.
  • The transfer regime, though now closer, has its own mechanisms and its own notification requirement for standard contractual clauses.
  • The lawful bases and the treatment of consent differ in detail, and the Turkish position on consent in an employment context is strict.
  • Breach notification periods and formats differ.
  • Documentation is expected in Turkish.

Adapting group policies is usually the right approach — translating them and assuming equivalence is not.

Enforcement

The Authority publishes decisions and imposes administrative fines, which are revalued annually and can be substantial for a mid-sized business. Enforcement in practice has focused on failure to register with VERBIS, inadequate clarification and consent practices, security failures leading to breaches, and transfers abroad without a proper basis.

Individuals may also complain to the Authority and may bring claims. Reputational exposure follows from the publication of decisions.

A practical order of work

  • Map the data. What the Turkish company holds, and every system it flows into. This is the foundation and it is usually the step that is skipped.
  • Identify every transfer abroad, including cloud services and remote access.
  • Choose and document a basis for each — adequacy where available, otherwise appropriate safeguards.
  • Execute standard contractual clauses where used, and notify them to the Authority within the prescribed period.
  • Register with VERBIS if within scope.
  • Localise notices and consents into Turkish and into the actual collection points.
  • Set retention periods and a destruction policy.
  • Prepare a breach procedure with named responsibilities.
  • Review annually, because systems change faster than documentation.

Frequently asked questions

Does the KVKK apply to our Turkish subsidiary? Yes, as a controller processing data in Türkiye.

Can we host Turkish employee data abroad? Yes, with a documented transfer basis under the amended Article 9.

Do we have to notify standard contractual clauses? Yes, within the prescribed period, where they are the basis relied on.

Is GDPR compliance enough? No. It helps substantially and does not substitute.

Do we have to register with VERBIS? Where the thresholds apply. Check rather than assume.

What are the fines? Administrative fines revalued annually; amounts vary by breach type and can be significant.

Can we rely on employee consent for HR transfers? Consent in an employment relationship is treated cautiously because it may not be freely given. Prefer another basis where available.

Getting it in order

Data protection is the compliance area foreign groups most often defer and most often get caught by, because the exposure accumulates silently while systems are integrated. The 2024 amendments made lawful transfer considerably more workable — but only for companies that actually adopt a mechanism and file it.

Dural Hukuk advises foreign-owned companies on KVKK compliance, data mapping, transfer mechanisms and their notification, VERBIS registration and breach response. Call +90 535 260 74 54 or use the contact form on this site.

This article is general information on Turkish law as at August 2026 and is not legal advice. The data protection framework and its secondary legislation continue to develop; obtain advice on your own processing before relying on any mechanism.