Skip to content
normSight — Cyber Security

Solutions

KVKK Compliance Consultancy

KVKK consultancy analyses an organisation's personal data processing activities under Turkish data protection law no. 6698 and determines the technical and administrative measures required for compliance.

When people register with, use and benefit from systems on the internet, certain information has to be provided to those systems. This information is referred to as personal data, and it spans many different categories: race, ethnic origin, philosophy, belief, denomination, dress, contact details, photographs, health information, records and security information. In this context, many companies and institutions commission KVKK consultancy services in order to protect the information users provide and to ensure it is handled safely, in line with the Personal Data Protection Law.

If personal data recorded in a system is transferred to another environment, stored, shared, disclosed, used or recorded — or if any of many similar operations is performed — this is referred to as the processing of personal data. Law no. 6698 on the Protection of Personal Data therefore sets out the obligations of natural and legal persons in respect of the privacy of private life, the protection of fundamental rights and freedoms, and the processing of personal data.

The Personal Data Protection Law gives rise to many legal procedures, and it is prudent to obtain professional consultancy in order to avoid penalties and to avoid putting users at risk. Through KVKK consultancy, the system can therefore be operated in accordance with the law, data can be retained appropriately and risks can be prevented.

While law no. 6698 continues to be applied and updated, a brand must act in line with corporate architecture, technological approaches and legal approaches in order to implement it. Through KVKK consultancy, a system that works without issue can therefore be achieved on points such as monitoring the system on an ongoing basis and recording or deleting data at the appropriate times.

Frequently Asked Questions

We have registered with VERBİS — does that make us compliant?

No. VERBİS registration is only one part of the obligation. Compliance covers the accuracy of the data inventory, the lawful basis for processing activities, retention and destruction periods, privacy notice and explicit consent processes, and the actual implementation of technical measures.

How does KVKK compliance relate to technical security?

The law requires appropriate technical measures to be taken to protect personal data. A security vulnerability that permits unauthorised access is at the same time a compliance breach, which is why we assess compliance work together with security testing.

What is delivered at the end of the engagement?

A gap analysis report, a data inventory and record of processing activities, a list of identified non-conformities prioritised by risk level, and a compliance roadmap with a timeline.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.