WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Europe

Turkey Privacy & Data Protection Laws

Every regime below can apply to a business handling Turkey residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

April 7, 2016; the Law No. 7499 amendments to Arts. 6, 9 and 18 entered into force June 1, 2024
Law on the Protection of Personal Data No. 6698 (Kisisel Verilerin Korunmasi Kanunu)
KVKK
Verify details

KVKK contains no express GDPR-Article-3-style extraterritoriality clause. In practice the Turkish Data Protection Authority (KVKK Board) applies the Law to foreign data controllers that process the personal data of people in Türkiye, and requires such controllers to register in the VERBIS controller registry and appoint a Türkiye-resident representative — so the modeled established/offering/monitoring triggers reflect regulator practice rather than statutory text, and a legal reviewer should confirm the specific basis for any given business. The March 2024 amendments (in force June 1, 2024) were substantial: they replaced the near-consent-only regime for special categories of personal data with a broader set of legal bases, and rebuilt cross-border transfers around adequacy decisions, standard contractual clauses (notifiable to the Board within five business days), binding corporate rules, and narrow derogations — replacing the previous reliance on explicit consent, which was permitted only through a transition period ending September 1, 2024.

Law No. 6698 (Official Gazette, April 7, 2016), as amended by Law No. 7499 (Official Gazette, March 12, 2024)Read regulation →

Data Security & Breach Notification · 1

April 7, 2016 (Law); Board Decision No. 2019/10 dated January 24, 2019
Law on the Protection of Personal Data No. 6698 — data security and breach notification
KVKK Art. 12(5)

Art. 12(5) of the Law itself says only that a breach must be reported to the data subject and the Board 'in the shortest time' — no number. The operative deadline comes from Board Decision No. 2019/10, in which the Board fixed that as no later than 72 hours from becoming aware, with reasons required if that is missed. Read the two together: the citation a Turkish regulator will enforce against is the statute, but the timeline is regulator interpretation, and a reviewer should check whether later Board decisions have refined it. Foreign data controllers caught by the Board's practice of applying KVKK to processing of data about people in Turkiye owe this duty too, alongside the VERBIS registration and local-representative requirements described in the comprehensive-law entry.

Law No. 6698, Art. 12(5); Personal Data Protection Board Decision No. 2019/10 of 24.01.2019Read regulation →

Other Europe jurisdictions