Skip to content
normSight — Cyber Security

16 September 2026

KVKK compliance: what Turkey's data protection law actually requires

KVKK compliance consists of building a data inventory, tying each processing activity to a lawful basis, setting retention and destruction policy, issuing privacy notices, implementing technical and administrative measures, preparing a breach response plan, and registering with VERBİS.

In most organisations, KVKK compliance is considered “done” once a folder of documents has been produced. When an audit or a breach arrives, the picture that emerges is usually the same: the documents exist, but the system they describe was never actually built.

The sequence below treats compliance as a process that keeps running, not a task that gets finished.

Step 1: The personal data processing inventory

Everything starts here, because if the inventory is wrong nothing built on it can be right.

For each data category the inventory must answer: what data, for what purpose, on what lawful basis; where it is stored; who it is shared with; how long it is kept; how it is destroyed.

The places most often missed:

  • Candidate CVs in recruitment processes, including rejected candidates
  • CCTV recordings
  • Call centre voice recordings
  • Email lists inside marketing tools
  • Production data copied into development and test environments
  • Backups held with cloud providers

That fifth item matters more than it looks. Real customer data copied into a test environment is invisible in the inventory and far less protected than production.

Step 2: Tying each processing activity to a lawful basis

The law ties processing to specific lawful bases. Explicit consent is only one of them, and in practice the most fragile — because it can be withdrawn.

If an activity can rest on another basis, such as performance of a contract, a legal obligation or legitimate interest, relying on consent unnecessarily weakens your position: when the person withdraws it, you have to stop processing.

Step 3: Retention and destruction policy

Keeping data indefinitely is non-compliance. A retention period must be set for every data category, and destruction must actually run when the period expires.

The critical point here is technical: a destruction policy that is written but not automated stays on paper. If deleting expired data is not tied to a scheduled job, a database policy or a lifecycle rule, that data is not being deleted. Copies inside backups must fall under the same policy.

The duty to inform must be met at the moment data is collected, not afterwards — on the web form, during recruitment, in the call centre greeting, at every point of contact.

Where explicit consent is taken, it must be separate from the notice and freely given. Consent made a condition of receiving the service is not valid.

Step 5: Technical and administrative measures

This is where compliance work is most often weak, because it calls for technical rather than legal expertise.

The law requires an appropriate level of security for personal data. In practice that means:

  • Access rights limited by role and reviewed regularly
  • Security vulnerabilities that permit unauthorised access identified and closed
  • Logging and monitoring on systems holding personal data
  • Encrypted backups
  • Contractual assurance from data processors (suppliers)
  • Staff awareness training

The connection most organisations miss: a vulnerability that allows unauthorised access is also a compliance breach. An authorisation bypass found in a penetration test is a KVKK finding as much as a technical one. That is why compliance work should run alongside security testing; run separately, both come out incomplete.

Step 6: Breach response plan

When a breach occurs there is a limited window for notification, and it starts from the moment the breach becomes known. If no plan exists in advance, that window is spent working out what happened.

The plan must establish in advance: who is informed, who decides, who performs the technical investigation, who drafts the notification. We cover this in a separate article.

Step 7: VERBİS registration

Registration comes after the inventory is complete. Working the other way round — registering first and then fitting the inventory to it — produces a declaration that does not match reality.

Keeping the registration updated is part of the obligation. When you begin processing a new data category or add a transfer, the registration must be updated.

Three common mistakes

Documents that do not match the systems. The policy says data is kept for two years while the database holds eight years of records. This is the first place an audit looks.

Leaving suppliers out of scope. Every service provider processing your data — cloud, call centre, payroll, marketing tools — is in scope and requires contractual assurance.

Treating compliance as a one-off project. Launching a new application, onboarding a supplier or changing a process all change the inventory.

Where to start

With a gap analysis. Work done without knowing what is missing ends with the easy items completed and the risky ones skipped.

In normSight’s compliance consultancy we run compliance work alongside security testing: whether technical measures work as documented is verified through penetration testing. Get in touch to discuss your scope.

This article is general information and does not constitute legal advice. Obligations specific to your organisation should be assessed with your legal counsel.

  • KVKK
  • data protection
  • compliance
  • Turkey
  • VERBIS

Frequently Asked Questions

How long does KVKK compliance take?

In a mid-sized organisation, gap analysis and data inventory typically take four to eight weeks; remediating what they uncover extends over several months depending on the number of systems and process maturity. Compliance is not a project with an end date but a review that repeats with every new system and process.

We are a small company — does KVKK apply to us?

The law grants no exemption based on headcount. Every data controller processing personal data is in scope. Some thresholds apply to the VERBİS registration obligation, but not being required to register does not exempt you from the law's other obligations.

Should compliance work be done by lawyers or by security specialists?

Both. Lawful basis, privacy notices and contractual work require legal expertise; verifying that technical and administrative measures are actually implemented requires security expertise. Engagements that produce only documents do not survive an audit.

Is a privacy notice the same as explicit consent?

No. The notice is an obligation to inform and is required in every case. Explicit consent is only one of the lawful bases for processing; where another basis applies, such as performance of a contract or a legal obligation, consent is not required. Relying on consent unnecessarily is a common and risky mistake.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.