Law No. 6698, Turkish and English on one fold, consolidated to March 2024. Read the statute

Schedule of work · 6 heads · Revised 09.09.2026

Personal data compliance services

We provide end-to-end data privacy compliance services for organisations operating in or targeting the Turkish market. Whether you need to comply with KVKK from a standing start, adapt an existing GDPR, UK GDPR or CCPA programme for Türkiye, or build a defensible cross-border transfer framework, the approach is the same: read the instrument, map it to what you actually do, and document the gap before anyone drafts a policy.

Standing

Every engagement produces artefacts you keep — an inventory, a lawful-basis map, a retention schedule, a transfer register, notices in Turkish and English — not a report that describes them.

Service register

  1. Compliance and governance

    Independent review of current practice against Law No. 6698. We identify the material gaps, build or repair the record of processing activities, map lawful bases article by article, and set retention and destruction policies that a Board inspection can follow. Where documentation predates the March 2024 amendments, we re-base it on the current text rather than patching the old one.

    Who this is for

    Controllers that have never been reviewed, and controllers whose file was written before Law No. 7499 changed the transfer regime.

    Fixed-scope gap assessment

    An independent review of what you actually do against Law No. 6698 — the material gaps, the record of processing activities, lawful bases mapped article by article, and a retention and destruction schedule a Board inspection can follow. Fixed scope, fixed fee, quoted before we start.

    Scope a gap assessment
  2. Registration and representation

    Assessment of registry obligations under Article 16 against the Authority’s current exemption criteria, and preparation of the VERBİS submission where registration is required. For controllers established outside Türkiye, we coordinate the appointment of a data controller representative and run the liaison with the Authority on your behalf.

    Who this is for

    Non-resident controllers with Turkish customers, users or employees, and Turkish controllers above the registration thresholds.

    VERBİS registration test

    A written yes or no with the reasoning, tested against the Authority’s current exemption criteria — and, for controllers established outside Türkiye, whether a representative in Türkiye must be appointed first and what that appointment actually obliges.

    Test the obligation
  3. Data transfers and contracts

    Selection and implementation of the right transfer mechanism under Article 9 and the 2024 By-Law: standard contract, binding corporate rules, written undertaking, or an occasional-transfer assessment where the derogation genuinely applies. We prepare the instrument, run the notification to the Authority within the five-business-day window, and handle the prior-authorisation file where the Board’s approval is required. Includes drafting and review of data processing agreements, sub-processor governance and vendor due diligence.

    Who this is for

    Groups moving HR, CRM, ticketing, telemetry or cloud-hosted data out of Türkiye, and processors serving Turkish controllers from abroad.

    Transfer regime readiness check

    We read your actual transfers against Article 9 and the 2024 By-Law and tell you which mechanism carries each one — standard contract, binding corporate rules, written undertaking, or a genuine occasional-transfer derogation — whether a notification was due, and where a late one leaves you.

    Have a transfer checked
  4. Websites, apps and marketing

    Preparation or revision of privacy notices, cookie and consent interfaces, and marketing consent language. We align consent records and preference management with what the Board expects to see in an inspection, and reconcile KVKK requirements with the separate commercial electronic message regime and the İleti Yönetim Sistemi (İYS).

    Who this is for

    E-commerce, adtech, publishers and any team operating consent at scale across web and mobile.

  5. DPO, training and ongoing support

    External data protection support on a standing basis: a named contact for day-to-day questions, periodic document review, role-based training for legal, HR, IT, security and marketing, and incident response — including the sequencing of Board notification, data subject communication and internal containment when the 72-hour expectation is running.

    Who this is for

    Organisations with no in-house privacy function, and in-house teams that need a Turkish-law second opinion on call.

  6. Sector-specific and AI programmes

    Focused work where the general framework is not enough: HR and workplace monitoring, healthcare and pharmaceuticals, retail and duty-free, media and adtech, and AI and LLM deployments. We develop sector-specific policies, impact assessments and control frameworks, and address the questions the Board has already spoken to on chatbots, deepfakes and biometric processing.

    Who this is for

    Teams deploying large language models, biometric systems, profiling or automated decision-making in the Turkish market.

Method

Expertise you can trust

  1. Local insight

    We work from the Turkish text and the Board’s own decisions, not from a translation of a European template.

  2. Tailored solutions

    Deliverables are built around what you actually process, not around a maturity model.

  3. Business-focused

    Compliance that survives contact with operations. If a control cannot be run by the team that owns it, it is not a control.

Where to start

Three named pieces of work, each of them bounded.

  • Fixed-scope gap assessment

    Most KVKK files in use today were written against a transfer regime that no longer exists: Law No. 7499 rewrote Article 9 in March 2024 and repealed Article 6(2).

    An independent review of what you actually do against Law No. 6698 — the material gaps, the record of processing activities, lawful bases mapped article by article, and a retention and destruction schedule a Board inspection can follow. Fixed scope, fixed fee, quoted before we start.

    Scope a gap assessment
  • VERBİS registration test

    Article 16 requires registration with the Data Controllers’ Registry before processing begins, and the exemption criteria are not printed in the statute you are reading — they are the Authority’s, and they move.

    A written yes or no with the reasoning, tested against the Authority’s current exemption criteria — and, for controllers established outside Türkiye, whether a representative in Türkiye must be appointed first and what that appointment actually obliges.

    Test the obligation
  • Transfer regime readiness check

    A standard contract signed under Article 9(4)(c) must be notified to the Authority within five business days of signature, and late notification is itself a breach.

    We read your actual transfers against Article 9 and the 2024 By-Law and tell you which mechanism carries each one — standard contract, binding corporate rules, written undertaking, or a genuine occasional-transfer derogation — whether a notification was due, and where a late one leaves you.

    Have a transfer checked

If none of the three is your question, write anyway. Describe what you process and where it goes, and you will get a written answer saying which of them applies to you — or that none does, which is also an answer.