Data Protection

KVKK vs GDPR: What Foreign Companies Need to Know

If you already know the GDPR, you have a head start on Turkey's data protection law (KVKKKVKKPersonal Data Protection Law No. 6698Türkiye's data protection statute — the rules on collecting, storing and transferring personal data, and the authority that enforces them.Glossary →, Law No. 6698) — but not a free pass. The two regimes share the same architecture: both are rights-based, both run on a data controller / data processor model, and both rest on the same core principles. The differences, though, are real and they catch foreign companies out. KVKK grew from an explicit-consent culture, it carries a registration step (VERBİS) that has no GDPR equivalent, it does not impose a Data Protection Officer mandate in the GDPR sense, and after the March 2024 reform (Law No. 7499) its cross-border transfer rules changed substantially. The single most important takeaway is this: being GDPR-compliant does not make you KVKK-compliant. This guide maps the overlaps and, more usefully, the gaps.

The Short Answer: Same Blueprint, Different Building

For a foreign company that already runs a GDPR programme, the honest summary is: you can reuse most of your thinking, but you cannot copy-paste your compliance. Turkey's Law on the Protection of Personal Data No. 6698 — the Kişisel Verilerin Korunması Kanunu, or KVKK — was built on the same European foundations as the GDPR. It protects the same right, uses the same vocabulary, and asks you to do many of the same things.

But KVKK is a sovereign Turkish law, enforced by a Turkish authority, with its own procedures, its own registry, and its own penalties denominated in Turkish lira. Where GDPR and KVKK diverge, the Turkish version controls inside Turkey — and assuming the two are interchangeable is the most common and most expensive mistake foreign businesses make.

The headline: Complying with the GDPR does not automatically make you compliant with KVKK. Treat them as two overlapping obligations, and build to the stricter standard in each area where they differ.

Which of these is your situation?

Treat KVKK readiness as a gap analysis against your existing programme, not a copy of it. Large parts translate directly: the rights-based approach, the data controller (veri sorumlusu) and data processor (veri işleyen) split, and the core processing principles. What does not translate is the lawful-basis wording, the VERBİS registration step, the roles, and the Turkish transfer instruments. A fully GDPR-compliant company can still be in breach in Türkiye purely for never having registered.
This is the divergence that catches EU teams most often. The GDPR offers six bases and lets you choose the most appropriate one; KVKK grew up explicit-consent-centric (açık rıza), with a defined list of statutory exceptions around it and narrower room for anything resembling legitimate interests. The habits of Turkish regulators and counterparties still reflect that consent-first history. Re-map the basis for each processing activity against Article 5 of Law No. 6698 rather than assuming your GDPR basis carries over.
Since Law No. 7499 of 12 March 2024 and its implementing regulation, data may leave Türkiye through an adequacy decision, appropriate safeguards such as the Board's standard contractual clauses or binding corporate rules for intra-group flows, or limited exceptional cases. The shape resembles GDPR Chapter V, but the instruments are Turkish: the Board's clauses are not the EU Commission's, and the Turkish text governs. There are also procedural steps with no GDPR equivalent, including a notification to the Authority within a set short period after signing the Board's clauses. Confirm the current mechanism and timing for your specific transfer before you move data.
That direction is a separate problem governed by the GDPR, not KVKK. Because the EU has not issued an adequacy decision recognising Türkiye, transfers from the EU into Türkiye generally need their own GDPR safeguard, typically the EU Commission's standard contractual clauses put in place by the EU sender. This is entirely separate from the Turkish instrument you need for data leaving Türkiye, which is why many groups run two parallel sets of transfer contracts.

Where KVKK and GDPR Line Up

Start with the good news, because it is substantial. If your organisation is GDPR-mature, large parts of your framework will translate directly.

Both are rights-based regimes

KVKK, like the GDPR, treats data protection as a fundamental right of the individual rather than a mere compliance formality. In Turkey that right is anchored in the Constitution and given detail by Law No. 6698. Individuals (in KVKK language, the ilgili kişi — the "data subject" or "relevant person") hold enforceable rights: to learn whether their data is processed, to request information, to seek correction or erasure, and to object. These mirror the GDPR's data subject rights closely enough that a GDPR rights-handling process is a strong starting point.

The controller / processor model is the same

KVKK uses the same two-actor structure you know from the GDPR:

  • Data controller (veri sorumlusu) — the party that determines the purposes and means of processing. This is the GDPR "controller."
  • Data processor (veri işleyen) — the party that processes data on the controller's behalf and under its instruction. This is the GDPR "processor."

Allocating roles, papering processor relationships, and pinning down who is accountable for what all work the way your GDPR programme already does.

The core principles overlap

Both laws require that personal data be processed lawfully and fairly, for specified and legitimate purposes, kept accurate and up to date, limited to what is necessary, and retained no longer than needed. A GDPR data-protection-by-design mindset maps cleanly onto KVKK's principles. The destination is similar; it is the route and the paperwork that differ.

Where KVKK and GDPR Diverge — The Parts That Catch Foreign Companies

This is the section that matters. The similarities are comforting; the differences are where compliance fails. The table below is a high-level map, and the subsections that follow explain the four divergences that most often trip up foreign companies.

IssueGDPR (EU)KVKK (Turkey, Law No. 6698)
Lawful basesSix bases, including a flexible legitimate-interests groundExplicit consent plus a defined list of statutory exceptions; historically more consent-centric
RegistrationNo central registry of controllersVERBİS — a mandatory data controllers' registry for those over the thresholds
Designated officerData Protection Officer (DPO) mandate in defined casesNo DPO mandate in the GDPR sense; a registry "contact person" (irtibat kişisi) instead
Cross-border transfersAdequacy / safeguards / derogationsReformed in 2024 (Law No. 7499) into a tiered model with new instruments
PenaltiesEU-wide framework tied to global turnoverTurkish-lira administrative fines, re-indexed annually

1. The explicit-consent legacy

The most important cultural difference is how each law thinks about lawful basis. The GDPR deliberately offers six bases and lets you choose the most appropriate one; in practice many EU controllers rely on contract, legal obligation, or legitimate interests, keeping consent as a last resort.

KVKK grew up the other way around. For years it was read as explicit-consent-centric: explicit consent (açık rıza) sat at the centre, with a defined list of statutory exceptions around it, and the room to lean on something resembling the GDPR's "legitimate interests" was narrower. The 2024 reform moved KVKK closer to the GDPR's approach to lawful bases, but the wording is its own, and the practical habits of Turkish regulators and counterparties still reflect that consent-first history.

Practical trap: A processing activity you comfortably run on "legitimate interests" under the GDPR may not rest on the equivalent footing under KVKK. Re-map your lawful basis for each activity against Article 5 of Law No. 6698 rather than assuming your GDPR basis carries over.

2. VERBİS — a registry with no GDPR equivalent

There is no GDPR analogue to VERBİS (the Veri Sorumluları Sicili, the Data Controllers' Registry). The GDPR scrapped general notification-to-the-regulator years ago; Turkey kept a registry. Many data controllers operating in Turkey must enrol in VERBİS and keep their entry current.

Whether your organisation is obliged to register depends on thresholds set by the Board — typically tied to factors such as employee numbers and annual financial figures, with sector-specific exemptions. Because those thresholds are set qualitatively here and change over time, you should confirm your specific position rather than assume you fall in or out. A foreign company that is fully GDPR-compliant can still be in breach in Turkey purely for never having registered.

3. No DPO mandate — but a "contact person"

The GDPR requires a Data Protection Officer (DPO) in defined situations — an independent role with statutory tasks and protections. KVKK has no DPO mandate in that sense.

What KVKK requires instead, for controllers registered in VERBİS, is a contact person (irtibat kişisi). This is a narrower role: a liaison point between the company and the Authority, not an independent supervisor of the company's processing. Foreign controllers established outside Turkey may also need to designate a representative in Turkey. The practical point: do not assume your existing DPO satisfies KVKK, and do not assume a VERBİS contact person discharges your GDPR DPO duties. They are different roles solving different problems.

Tip: A group caught by both regimes can end up needing all of these at once — a GDPR DPO (where required), a VERBİS contact person in Turkey, and possibly a Turkish representative. They are not substitutes for one another.

4. Cross-border transfers — overhauled in 2024

This is the area where the two regimes have moved closest and yet where foreign companies most often breach KVKK. It deserves its own section, below.

The 2024 Reform and Cross-Border Transfers

On 12 March 2024, Law No. 7499 amended KVKK and, together with the implementing regulation that followed, replaced Turkey's old, heavily consent-based model for sending personal data abroad with a tiered framework that tracks the structure GDPR users already recognise.

At a high level, personal data may now leave Turkey through one of three routes:

  1. An adequacy decision — transfer to a country, sector, or international organisation the Board has formally recognised as providing adequate protection.
  2. Appropriate safeguards — where there is no adequacy decision, transfer based on instruments such as the Board's standard contractual clauses (SCCs), binding corporate rules (BCRs) for intra-group flows, or an approved undertaking.
  3. Exceptional cases — limited, occasional transfers resting on explicit consent or specific statutory grounds.

If you know GDPR Chapter V, this shape will feel familiar. But the instruments are Turkish: the Board's SCCs are not the EU Commission's SCCs, the Turkish text governs, and there are procedural steps — including a notification to the Authority within a set short period after signing the Board's SCCs — that have no GDPR equivalent.

Verify before you move data: The transitional arrangements, deadlines, the precise filing window, and the catalogue of approved instruments are detailed and have changed since 2024. Do not rely on a remembered figure — confirm the current mechanism and timing for your specific transfer before you act.

The two-direction problem

There is also a structural asymmetry GDPR-mature groups must plan for. Because the EU has not issued an adequacy decision recognising Turkey, data flowing into Turkey from the EU still needs its own GDPR safeguards (typically the EU Commission's SCCs put in place by the EU sender) — entirely separate from the Turkish instruments needed for data flowing out of Turkey. Many groups therefore run two parallel sets of transfer contracts.

Direction of dataGoverning regimeWhat you generally need
Leaving Turkey (to the EU or elsewhere)KVKK (Law No. 6698, as reformed)A Turkish transfer mechanism — e.g. the Board's SCCs (Turkish text) or BCRs, plus any required filing
Entering Turkey from the EUGDPRA GDPR safeguard (e.g. EU Commission SCCs) put in place by the EU sender

For the agreements that sit behind these flows, this overlaps with how we handle data-processing agreements and contractual clauses.

Common belief

We are GDPR-compliant, so we are compliant in Türkiye.

In fact

KVKK is a sovereign Turkish law, enforced by a Turkish authority, with its own procedures, its own registry and its own penalties denominated in Turkish lira. The two are overlapping obligations, not interchangeable ones, and where they diverge the Turkish version controls inside Türkiye — so build to the stricter standard in each area of difference.

Common belief

Our Data Protection Officer covers the Turkish requirement too.

In fact

KVKK imposes no DPO mandate in the GDPR sense. Controllers registered in VERBİS appoint a contact person (irtibat kişisi), a narrower liaison role with the Authority rather than an independent supervisor of your processing, and foreign controllers may additionally need a representative in Türkiye. These are different roles solving different problems and are not substitutes for one another.

Common belief

Standard contractual clauses are standard — the ones we already signed will do.

In fact

The Board's standard contractual clauses are not the EU Commission's clauses. The Turkish text governs, and there are procedural steps with no GDPR equivalent, including a notification to the Authority within a set short period after signing. The transitional arrangements and the catalogue of approved instruments have also changed since 2024.

Common belief

The fine figure quoted in the guide we read is what we would face.

In fact

KVKK fines are set in Turkish lira and re-indexed each year, so any specific number dates quickly; treat a quoted figure as a starting point to verify rather than a fixed fact. Serious unlawful processing can additionally engage the criminal provisions of the Turkish Penal Code (Law No. 5237), and EU authorities can act in parallel under the GDPR.

A Practical Mapping Exercise for GDPR-Mature Companies

Rather than rebuilding from scratch, treat KVKK readiness as a gap analysis against your existing GDPR programme. A defensible approach usually runs as follows:

  • Re-map lawful bases. Take each processing activity and check its basis against Article 5 of Law No. 6698 — do not assume your GDPR basis (especially legitimate interests) transfers.
  • Check VERBİS. Determine whether you meet the registration thresholds, register if so, appoint a contact person, and keep the entry current.
  • Localise your notices. KVKK requires its own clarification text (aydınlatma metni) and, where relied on, explicit consent forms — these are not the same documents as your GDPR privacy notice.
  • Rebuild transfers. Identify every flow that leaves Turkey, select a current 2024-regime mechanism, and complete any required filing; separately confirm the GDPR safeguards for flows into Turkey.
  • Sort out roles. Confirm whether you need a GDPR DPO, a VERBİS contact person, a Turkish representative — or some combination.
  • Align incident response. Both regimes require breach notification; build one procedure that satisfies the stricter of the two timelines (confirm the current Turkish requirement) and run it under realistic time pressure.
The law: The governing instrument in Turkey is the Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu), as amended by Law No. 7499 of 2024. GDPR compliance is evidence of good data hygiene, but it is not a defence to a KVKK breach.

Penalties: Two Regimes, Two Separate Exposures

Non-compliance is assessed under each regime independently, and the two can bite at once.

Under KVKK, the Authority's Board can impose administrative fines — for example for security failures, registration failures, or breaches of its decisions — alongside corrective orders. These fines are set in Turkish lira and re-indexed each year, so any specific figure dates quickly; confirm the current bands before relying on them. Serious unlawful processing can additionally engage criminal provisions of the Turkish Penal Code (Law No. 5237).

Under the GDPR, EU supervisory authorities can impose their own fines and enforcement measures, and data subjects may bring civil claims. For an international group, the real danger is parallel exposure: a single misconfigured transfer or one missing notice can trigger consequences in Turkey and in the EU simultaneously.

Watch the figures: KVKK fine bands change every January and GDPR enforcement evolves. Treat any number you have seen quoted as a starting point to verify, not a fixed fact — and build your programme so that one operational slip does not cascade into double enforcement.

Data protection rarely sits alone. If you are setting up a foreign-owned company in Turkey, it is far cheaper to bake KVKK in from day one than to retrofit it; and in a deal it forms part of data-protection due diligence. For a structured KVKK-versus-GDPR gap review, speak with our Istanbul team.

6698LAW NO.
Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu) · Art. 5

The governing Turkish statute; its lawful bases are the point at which a GDPR basis, especially legitimate interests, most often fails to carry over.

7499LAW NO.
Law amending the Personal Data Protection Law, 12 March 2024

Replaced the old, heavily consent-based model for sending data abroad with a tiered framework of adequacy decisions, appropriate safeguards and exceptional cases.

5237LAW NO.
Turkish Penal Code

Can be engaged separately from KVKK administrative fines where unlawful processing is serious.

What to bring to a KVKK-versus-GDPR gap review

The review is faster and more useful if you arrive with your existing GDPR material and a few Türkiye-specific facts. All of it is information you already hold.

Frequently asked questions

Does GDPR compliance mean my company is KVKK compliant?

No. KVKK (Law No. 6698) and the GDPR share the same architecture — both are rights-based and use the controller/processor model — but they are separate laws. KVKK has its own registration step (VERBİS), its own transfer rules (reformed in 2024 by Law No. 7499), its own lawful-basis wording, and its own Turkish-lira penalties. A fully GDPR-compliant company can still breach KVKK, for example by never registering with VERBİS. Treat KVKK readiness as a gap analysis against your GDPR programme, not a copy of it.

What is the main structural difference between KVKK and GDPR?

At the structural level they are very similar: both treat data protection as a fundamental right, both use the data controller (veri sorumlusu) / data processor (veri işleyen) split, and both share the same core processing principles. The practical differences are KVKK's historically explicit-consent-centric approach to lawful basis, the VERBİS registry (which has no GDPR equivalent), the absence of a Data Protection Officer mandate in the GDPR sense, and the 2024 overhaul of cross-border transfer rules.

What is VERBİS and does the GDPR have an equivalent?

VERBİS (the Veri Sorumluları Sicili, or Data Controllers' Registry) is a Turkish registry that many data controllers must enrol in and keep current. The GDPR has no equivalent — it abolished general notification to regulators. Whether your company must register depends on thresholds set by the Board, typically tied to factors such as employee numbers and annual financial figures, with some exemptions, so you should confirm your specific position rather than assume.

Does KVKK require a Data Protection Officer like the GDPR?

Not in the GDPR sense. KVKK does not impose a Data Protection Officer mandate. Instead, controllers registered in VERBİS must appoint a contact person (irtibat kişisi), which is a narrower liaison role with the Authority, not an independent supervisory officer. Foreign controllers may also need a representative in Turkey. A GDPR DPO and a VERBİS contact person are different roles and are not substitutes for each other.

How did the 2024 reform change cross-border data transfers from Turkey?

Law No. 7499 of 2024, with its implementing regulation, replaced the old, heavily consent-based model with a tiered framework: adequacy decisions, appropriate safeguards (such as the Board's standard contractual clauses or binding corporate rules), and limited exceptional cases. The structure resembles GDPR Chapter V, but the instruments are Turkish, the Turkish text governs, and there are procedural steps with no GDPR equivalent. Because deadlines and filing windows are detailed and have changed, confirm the current mechanism for your specific transfer before moving any data.

Can I transfer personal data from the EU into my Turkish company?

That direction is governed by the GDPR, not KVKK. Because the EU has not issued an adequacy decision for Turkey, transfers from the EU into Turkey generally need their own GDPR safeguards — commonly the EU Commission's standard contractual clauses, put in place by the EU sender. This is separate from the Turkish mechanism you need for data leaving Turkey, which is why many groups run two parallel sets of transfer contracts.

Need a lawyer for this?We handle data protection (kvkk) for foreigners, end to end, in English, on a fixed fee.
Data Protection (KVKK)

Related articles

GDPR and Turkish Companies: Navigating ComplianceTurkey's Cybersecurity Law No. 7545: Scope & PrinciplesLawful Processing of Personal Data Under KVKK: The Legal BasesData Breaches Under Türkiye's KVKK: Notification Duties and Penalties
Let's begin

Speak to a Turkish lawyer who speaks your language.

Tell us your commercial, corporate or personal matter and get a clear, fixed-fee answer from a real Turkish lawyer — usually within one business day.

★★★★★ 4.9 from 60 Google reviews · Recognised on Mondaq, Clutch & Trustpilot
WhatsApp us
A real lawyer replies — usually within a day
WhatsAppEmailBook a consultation