In most organisations, KVKK compliance is considered “done” once a folder of documents has been produced. When an audit or a breach arrives, the picture that emerges is usually the same: the documents exist, but the system they describe was never actually built.
The sequence below treats compliance as a process that keeps running, not a task that gets finished.
Step 1: The personal data processing inventory
Everything starts here, because if the inventory is wrong nothing built on it can be right.
For each data category the inventory must answer: what data, for what purpose, on what lawful basis; where it is stored; who it is shared with; how long it is kept; how it is destroyed.
The places most often missed:
- Candidate CVs in recruitment processes, including rejected candidates
- CCTV recordings
- Call centre voice recordings
- Email lists inside marketing tools
- Production data copied into development and test environments
- Backups held with cloud providers
That fifth item matters more than it looks. Real customer data copied into a test environment is invisible in the inventory and far less protected than production.
Step 2: Tying each processing activity to a lawful basis
The law ties processing to specific lawful bases. Explicit consent is only one of them, and in practice the most fragile — because it can be withdrawn.
If an activity can rest on another basis, such as performance of a contract, a legal obligation or legitimate interest, relying on consent unnecessarily weakens your position: when the person withdraws it, you have to stop processing.
Step 3: Retention and destruction policy
Keeping data indefinitely is non-compliance. A retention period must be set for every data category, and destruction must actually run when the period expires.
The critical point here is technical: a destruction policy that is written but not automated stays on paper. If deleting expired data is not tied to a scheduled job, a database policy or a lifecycle rule, that data is not being deleted. Copies inside backups must fall under the same policy.
Step 4: Privacy notices and consent
The duty to inform must be met at the moment data is collected, not afterwards — on the web form, during recruitment, in the call centre greeting, at every point of contact.
Where explicit consent is taken, it must be separate from the notice and freely given. Consent made a condition of receiving the service is not valid.
Step 5: Technical and administrative measures
This is where compliance work is most often weak, because it calls for technical rather than legal expertise.
The law requires an appropriate level of security for personal data. In practice that means:
- Access rights limited by role and reviewed regularly
- Security vulnerabilities that permit unauthorised access identified and closed
- Logging and monitoring on systems holding personal data
- Encrypted backups
- Contractual assurance from data processors (suppliers)
- Staff awareness training
The connection most organisations miss: a vulnerability that allows unauthorised access is also a compliance breach. An authorisation bypass found in a penetration test is a KVKK finding as much as a technical one. That is why compliance work should run alongside security testing; run separately, both come out incomplete.
Step 6: Breach response plan
When a breach occurs there is a limited window for notification, and it starts from the moment the breach becomes known. If no plan exists in advance, that window is spent working out what happened.
The plan must establish in advance: who is informed, who decides, who performs the technical investigation, who drafts the notification. We cover this in a separate article.
Step 7: VERBİS registration
Registration comes after the inventory is complete. Working the other way round — registering first and then fitting the inventory to it — produces a declaration that does not match reality.
Keeping the registration updated is part of the obligation. When you begin processing a new data category or add a transfer, the registration must be updated.
Three common mistakes
Documents that do not match the systems. The policy says data is kept for two years while the database holds eight years of records. This is the first place an audit looks.
Leaving suppliers out of scope. Every service provider processing your data — cloud, call centre, payroll, marketing tools — is in scope and requires contractual assurance.
Treating compliance as a one-off project. Launching a new application, onboarding a supplier or changing a process all change the inventory.
Where to start
With a gap analysis. Work done without knowing what is missing ends with the easy items completed and the risky ones skipped.
In normSight’s compliance consultancy we run compliance work alongside security testing: whether technical measures work as documented is verified through penetration testing. Get in touch to discuss your scope.
This article is general information and does not constitute legal advice. Obligations specific to your organisation should be assessed with your legal counsel.
- KVKK
- data protection
- compliance
- Turkey
- VERBIS