Legalifi Logo
Back to blog
KVKKData ProtectionCompliance
June 26, 2026·6 min read

Türkiye’s Personal Data Protection Law (KVKK): Key Principles, Rights and Obligations

A practical overview of Türkiye’s Personal Data Protection Law (KVKK), covering personal data, processing conditions, data subject rights, controller obligations, data security and compliance requirements.

Alperen Turhal

Alperen Turhal

Tech Lawyer

Secure digital records, redacted personal information and identity data representing KVKK and personal data protection in Türkiye.

Türkiye’s Personal Data Protection Law (KVKK)

Almost every day, we hear about personal information being stolen, accessed without authorisation or used unlawfully for financial or other benefits.

Türkiye’s first comprehensive legislation specifically regulating personal data protection is Law No. 6698 on the Protection of Personal Data, commonly known as KVKK, which entered into force on 7 April 2016.

KVKK establishes the main principles governing personal data protection in Türkiye. It regulates concepts such as personal data, data controllers and data processors, the conditions for processing personal data, the obligations of controllers and the rights of data subjects.

What Is Personal Data?

KVKK defines personal data as:

“Any information relating to an identified or identifiable natural person.”

Accordingly, any information that can be associated with an identified or identifiable individual may qualify as personal data.

This can include:

  • Name and surname
  • Turkish identification number
  • Contact information
  • IP address
  • Location data
  • Technical identifiers
  • Other information that can be linked to a natural person

The concept of personal data is therefore not limited to information that directly identifies an individual.

Data that enables indirect identification may also fall within the scope of KVKK.

Data Controller and Data Processor

One of the most important actors under KVKK is the data controller.

A data controller is the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.

The data controller is also one of the principal parties responsible for compliance with KVKK and may be directly subject to administrative sanctions where statutory obligations are not fulfilled.

A data processor, on the other hand, is a natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the controller.

The authority and responsibility of the data processor therefore arise within the framework determined by the data controller.

This distinction also demonstrates the importance of the controller’s role in ensuring lawful and secure personal data processing activities.

Principles Applicable to the Processing of Personal Data

Articles 4 and 5 of KVKK are among the most important provisions governing personal data processing.

Article 4 sets out the general principles that must be followed when personal data is processed.

Principles Under Article 4(2)

Personal data must be:

  1. Processed lawfully and fairly.
  2. Accurate and, where necessary, kept up to date.
  3. Processed for specified, explicit and legitimate purposes.
  4. Relevant, limited and proportionate to the purposes for which they are processed.
  5. Retained only for the period prescribed by applicable legislation or required for the purpose of processing.

These principles form the foundation of personal data processing activities under KVKK.

Conditions for Processing Personal Data

As a general rule, personal data cannot be processed without the explicit consent of the data subject.

However, Article 5(2) provides several legal grounds under which personal data may be processed without obtaining explicit consent.

These grounds include:

  1. Processing is expressly provided for by law.
  2. Processing is necessary for the protection of the life or physical integrity of a person who is unable to express consent due to actual impossibility or whose consent is not legally valid.
  3. Processing is necessary for the conclusion or performance of a contract, provided that it is directly related to the personal data of the parties to the contract.
  4. Processing is necessary for the data controller to fulfil a legal obligation.
  5. The personal data has been made public by the data subject.
  6. Processing is necessary for the establishment, exercise or protection of a legal right.
  7. Processing is necessary for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not harmed.

For this reason, businesses should identify the appropriate legal basis before carrying out any personal data processing activity.

Special Categories of Personal Data

KVKK provides enhanced protection for certain categories of personal data.

These include information relating to:

  • Race
  • Ethnic origin
  • Political opinions
  • Philosophical beliefs
  • Religion or other beliefs
  • Appearance and clothing
  • Membership in associations, foundations or trade unions
  • Health
  • Sexual life
  • Criminal convictions and security measures
  • Biometric data
  • Genetic data

Because of their sensitive nature, these categories are subject to stricter processing conditions and security requirements.

Rights of the Data Subject

KVKK grants individuals several rights concerning the processing of their personal data.

These rights are mainly regulated under Article 11.

A data subject may apply to the data controller to:

  1. Learn whether their personal data is being processed.
  2. Request information if their personal data has been processed.
  3. Learn the purpose of processing and whether the data is being used in accordance with that purpose.
  4. Know the third parties to whom personal data has been transferred domestically or abroad.
  5. Request correction where personal data has been processed incompletely or incorrectly.
  6. Request the deletion or destruction of personal data under the conditions set out in Article 7.
  7. Request that correction, deletion or destruction operations be notified to third parties to whom the personal data has been transferred.
  8. Object to a result arising against the individual through the analysis of processed data exclusively by automated systems.
  9. Request compensation where the individual suffers damage due to unlawful processing of personal data.

These rights provide individuals with a significant degree of control over how their personal data is collected, used, transferred and retained.

What Does Processing Personal Data Mean?

KVKK defines processing broadly.

Processing includes any operation performed on personal data, whether wholly or partly by automated means or by non-automated means forming part of a data recording system.

Examples include:

  • Collection
  • Recording
  • Storage
  • Retention
  • Modification
  • Reorganisation
  • Disclosure
  • Transfer
  • Acquisition
  • Making data available
  • Classification
  • Restricting use

Accordingly, personal data processing is not limited to collecting information.

Almost every stage in the lifecycle of personal data may constitute a processing activity.

Personal Data Protection Authority

The Personal Data Protection Authority is the competent public authority responsible for supervising and regulating personal data protection practices under KVKK.

Its role includes monitoring compliance with the legislation and exercising the powers granted under the applicable regulatory framework.

Obligations of the Data Controller

Data controllers must conduct their personal data processing activities in compliance with the principles and conditions established under KVKK.

Two of the most important obligations concern:

  • The obligation to inform data subjects
  • The obligation to ensure personal data security

Obligation to Inform Under Article 10

When personal data is collected, the data controller or its authorised representative must provide the data subject with information regarding:

  1. The identity of the data controller and, where applicable, its representative.
  2. The purposes for which personal data will be processed.
  3. The persons or organisations to whom processed personal data may be transferred and the purposes of such transfers.
  4. The method and legal basis for collecting personal data.
  5. The rights available to the data subject under Article 11.

The information provided should be clear, accessible and appropriate to the relevant personal data processing activity.

Data Security Obligations Under Article 12

Data controllers are required to take the necessary technical and administrative measures to ensure an appropriate level of security.

These measures must aim to:

  1. Prevent unlawful processing of personal data.
  2. Prevent unlawful access to personal data.
  3. Ensure the secure storage and protection of personal data.

Data security should therefore be regarded as a continuing compliance obligation rather than a one-time technical measure.

Companies should regularly review their access controls, data retention practices, cybersecurity measures and internal procedures.

Data Controllers Registry

KVKK also establishes registration obligations for certain data controllers through the Data Controllers Registry.

Businesses should therefore assess whether they are required to register and whether their existing registrations and declarations accurately reflect their personal data processing activities.

Conclusion

The lawful processing, transfer, storage and protection of personal data has become a critical issue for businesses and individuals.

As technologies capable of collecting, analysing and combining large volumes of personal information continue to develop, the risks arising from unlawful processing are also becoming increasingly significant.

For businesses, failure to comply with KVKK may result in administrative sanctions as well as reputational, operational and commercial risks.

For this reason, personal data processing activities should be reviewed comprehensively and managed through appropriate legal, technical and organisational measures.

Legalifi helps organisations make their personal data compliance processes more understandable, manageable and predictable through technology-supported solutions developed with KVKK and broader data protection requirements in mind.

Alperen Turhal

Written by

Alperen Turhal

Tech Lawyer

He graduated from the Ankara University Faculty of Law. He then completed his mandatory legal internship at a corporate law firm in 2025 and obtained his attorney’s license. Within Karakod, he actively works on the Legalifi RegTech software, focusing particularly on intellectual property law (trademarks), personal data protection, and AI law.