Turkey

Comprehensive

Personal Data Protection Law No. 6698 (KVKK)

Authority: Personal Data Protection Authority (KVKK) | Enforcement: Active | Enacted: April 2016

Overview

Turkey's KVKK law, effective since 2016, is modelled on the pre-GDPR EU Data Protection Directive. The KVKK authority actively enforces with significant fines. Turkey is seeking EU adequacy status as part of EU accession process.

14-Topic Coverage

Data Protection Authority

Fully Addressed

KVKK authority conducts investigations, handles complaints, and issues administrative fines.

Data Subject Rights

Fully Addressed

Rights to be informed, access, correction, deletion, objection, and compensation.

Cross-Border Transfer

Fully Addressed

KVKK Board must approve adequate countries. Binding undertaking mechanism for other transfers.

Breach Notification

Fully Addressed

Must notify KVKK Board without delay. Board determines whether data subjects must be notified.

DPO Requirements

Partially Addressed

Data Controller Registration (VERBIS) required. Contact person must be designated.

Children's Data

Partially Addressed

Sensitive data provisions apply. No specific age threshold in the law.

Penalties & Enforcement

Fully Addressed

Administrative fines from TRY 50K to TRY 3 million. Active enforcement with published decisions.

Sector-Specific Rules

Fully Addressed

BRSA banking rules, healthcare data regulations, e-commerce data provisions.

AI & Automated Decisions

Partially Addressed

Right to object to automated decisions under Article 11. National AI Strategy published.

Data Localisation

Partially Addressed

Some sector-specific localisation for financial and health data.

Significant Data Fiduciary

Not Addressed

VERBIS registration tiered by size but no SDF equivalent concept.

Government Data

Fully Addressed

KVKK applies to government processing with limited exemptions for national security.