Turkey Personal Data Protection Law (KVKK - Law No. 6698)
Turkey's Personal Data Protection Law (KVKK, Law No. 6698 of 2016) establishes comprehensive data protection rules modelled on the EU Data Protection Directive (95/46/EC). The Personal Data Protection Authority (KVKK Board) oversees compliance. Amended in 2024 to strengthen cross-border transfer provisions with an EU GDPR-aligned approach. Applies to all natural and legal persons processing personal data in Turkey.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (27)
Assurance
| Code | Title |
|---|---|
| KVKK-18 | Internal Audit and Compliance Monitoring |
Chapter Five - Crimes and Misdemeanours
| Code | Title |
|---|---|
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
Chapter Four - Requests, Complaints and Registry
| Code | Title |
|---|---|
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 14 | Human Oversight |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
Chapter One - Purpose, Scope and Definitions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
Chapter Seven - Miscellaneous Provisions
| Code | Title |
|---|---|
| Art. 28 | Notifying Authorities |
| Art. 30 | Privacy Policy |
Chapter Six - Personal Data Protection Authority
| Code | Title |
|---|---|
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
Chapter Three - Rights and Obligations
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 12 | Record-Keeping |
Chapter Two - Processing of Personal Data
| Code | Title |
|---|---|
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
Cross Border Governance
| Code | Title |
|---|---|
| KVKK-19 | Foreign Controller Representative |
Cross-Border Transfers
| Code | Title |
|---|---|
| KVKK-05 | Cross Border Data Transfers |
Electronic Communications
| Code | Title |
|---|---|
| KVKK-13 | Marketing and Cookies |
Governance
| Code | Title |
|---|---|
| KVKK-11 | Data Protection Officer or Contact Person |
Incident Response
| Code | Title |
|---|---|
| KVKK-09 | Data Breach Notification |
Information Security
| Code | Title |
|---|---|
| KVKK-08 | Security Measures |
Lawfulness
| Code | Title |
|---|---|
| KVKK-02 | Explicit Consent and Lawful Basis |
Lifecycle Management
| Code | Title |
|---|---|
| KVKK-07 | Data Retention and Destruction Policy |
People
| Code | Title |
|---|---|
| KVKK-12 | Personnel and Training |
Regulator Engagement
| Code | Title |
|---|---|
| KVKK-01 | VERBIS Registration |
Regulatory Tracking
| Code | Title |
|---|---|
| KVKK-16 | KVKK Board Decisions and Guidance |
Rights Management
| Code | Title |
|---|---|
| KVKK-04 | Data Subject Rights and Veribasvuru |
Risk Management
| Code | Title |
|---|---|
| KVKK-17 | Privacy Impact Assessment |
Special Categories
| Code | Title |
|---|---|
| KVKK-06 | Special Categories of Personal Data |
Third Party Management
| Code | Title |
|---|---|
| KVKK-10 | Processor Oversight |
Transparency
| Code | Title |
|---|---|
| KVKK-03 | Information Notice (Aydinlatma Metni) |
Vulnerable Subjects
| Code | Title |
|---|---|
| KVKK-20 | Children and Minors |
Workplace Privacy
| Code | Title |
|---|---|
| KVKK-14 | Employee and HR Data |
Workplace and Public Surveillance
| Code | Title |
|---|---|
| KVKK-15 | Video Surveillance and Biometrics |
Your Compliance Coverage
If you comply with Turkey Personal Data Protection Law (KVKK - Law No. 6698), you already cover:
BS 65000:2014 - Guidance on Organizational Resilience
48%
21 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
48%
21 controls mapped
Compare →EU AI Act
45%
20 controls mapped
Compare →+ 644 more: ILO Nursing Personnel Convention C149 (1977) (45%), 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) - superseded by AMLD7 (45%)
See all 647 mapped frameworks ↓Maps to 647 other frameworks
Frequently Asked Questions
What is Turkey Personal Data Protection Law (KVKK - Law No. 6698)?
Turkey Personal Data Protection Law (KVKK - Law No. 6698) is a compliance framework from Turkey with 27 domains and 44 controls. Turkey's Personal Data Protection Law (KVKK, Law No. 6698 of 2016) establishes comprehensive data protection rules modelled on the EU Data Protection Directive (95/46/EC). The Personal Data Protection Authority (KVKK Board) oversees compliance. Amended in 2024 to strengthen cross-border transfer provisions with an EU GDPR-aligned approach. Applies to all natural and legal persons processing personal data in Turkey. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Turkey Personal Data Protection Law (KVKK - Law No. 6698) have?
Turkey Personal Data Protection Law (KVKK - Law No. 6698) has 44 controls organised across 27 domains. The largest domains are Chapter Two - Processing of Personal Data (6 controls), Chapter Four - Requests, Complaints and Registry (4 controls), Chapter Six - Personal Data Protection Authority (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Turkey Personal Data Protection Law (KVKK - Law No. 6698) map to?
Turkey Personal Data Protection Law (KVKK - Law No. 6698) maps to 647 other compliance frameworks. The top mapping partners are BS 65000:2014 - Guidance on Organizational Resilience (48% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (48% coverage), EU AI Act (45% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Turkey Personal Data Protection Law (KVKK - Law No. 6698) compliance?
Start your Turkey Personal Data Protection Law (KVKK - Law No. 6698) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Turkey Personal Data Protection Law (KVKK - Law No. 6698) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required