🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
TR · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 16 sources retrieved model claude-sonnet-5 ·

Turkey

TR schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 36 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute in force with an operational, actively enforcing regulator (KVKK) and a functioning registration system (VERBIS).

Primary frameworkLaw No. 6698 on the Protection of Personal Data (LPPD), as amended by Law No. 7499 (2024)
Traffic-light rationale — GreenComprehensive statute in force with an operational, actively enforcing regulator (KVKK) and a functioning registration system (VERBIS).

Sub-modules (5)

Regulator And AuthorityGreen

KVKK is Turkey's dedicated personal-data-protection authority and Board, issuing binding decisions, guidance, and administrative fines.

Claims: CLM-TR-1a2b3c4d

Act And InstrumentsGreen

LPPD (Law 6698, 2016) is the primary instrument; Law 7499 (2024) amended Articles 6, 9 and 18.

Claims: CLM-TR-2b3c4d5e, CLM-TR-3c4d5e6f

Material ScopeGreen

Scope mirrors GDPR's automated-processing/filing-system test and shares comparable definitions of 'processing' and 'personal data'.

Claims: CLM-TR-4d5e6f70

Territorial ScopeAmber

The LPPD is textually silent on extraterritorial scope but VERBIS registration is applied to foreign controllers processing data collected from Turkey.

Claims: CLM-TR-5e6f7081

Regulator Registration And FilingGreen

VERBIS registration is mandatory for qualifying controllers (Turkish controllers with ≥50 employees or ≥TRY 25m turnover, and foreign controllers), and KVKK continues to issue clarifying announcements (e.g., on partnership structures in March 2026).

Claims: CLM-TR-6f708192, CLM-TR-70819a3b

Category narrative100 words

Turkey operates a comprehensive omnibus regime under Law No. 6698 on the Protection of Personal Data (LPPD/KVKK Law), enforced by the Personal Data Protection Authority (KVKK/Kurul). The law was modelled on the pre-GDPR EU Data Protection Directive 95/46/EC and has been progressively amended (most recently by Law No. 7499 in 2024) to narrow the gap with the GDPR, particularly on special-category processing and cross-border transfers. Material and territorial scope closely track the GDPR's automated/filing-system test, and the LPPD has a recognised (if textually silent) extraterritorial reach implemented administratively through the VERBIS data-controller registry, which also functions as Turkey's registration/filing mechanism.

Sources and claims (7)
  1. ConfirmedDataGuidanceThe Personal Data Protection Authority (KVKK) is Turkey's supervisory authority for the Law on the Protection of Personal Data No. 6698.
  2. ConfirmedDataGuidance / Esin Attorney PartnershipThe Law on Protection of Personal Data No. 6698 (LPPD) was published in the Official Gazette on 7 April 2016 and entered into force as Turkey's first general data protection law.
  3. ConfirmedIAPPLaw No. 7499, amending the Code of Criminal Procedure and Certain Laws, introduced amendments to Articles 6, 9 and 18 of the LPPD, with the first segment published in the Official Gazette on 12 March 2024 and effective 1 June 2024.
  4. ConfirmedDataGuidance / Esin Attorney PartnershipThe LPPD and GDPR provide comparable definitions of 'processing', 'personal data' and 'sensitive data', and both apply to automated or filing-system-based processing.
  5. ConfirmedIAPPVERBIS registration requirements extend extraterritorially to foreign (non-Turkey-established) data controllers that collect or process personal data originating in Turkey.
  6. ConfirmedIAPPTurkish data controllers with 50 or more employees, or annual turnover of TRY 25,000,000 or more, must register with VERBIS; failure to register can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.
  7. ConfirmedDataGuidanceIn a March 2026 public announcement, KVKK clarified that partners in business partnerships, consortiums and ordinary partnerships must incorporate partnership-related personal data processing into their own individual VERBİS registrations rather than creating separate registrations.

#

Core lawful-basis and special-category architecture is codified and enforced, but consent-thresholds guidance is comparatively thin relative to GDPR-level granularity, and some 2024 amendment detail was not independently verified this run.

Primary frameworkLaw No. 6698 (LPPD), Articles 5-6, as amended by Law No. 7499 (2024)
Supervisory authorityKVKK
Traffic-light rationale — Not assessedCore lawful-basis and special-category architecture is codified and enforced, but consent-thresholds guidance is comparatively thin relative to GDPR-level granularity, and some 2024 amendment detail was not independently verified this run.

Sub-modules (4)

Lawful BasesAmber

Article 5 LPPD sets out the legal grounds for processing (paralleling GDPR Art 6), referenced also as the general-ground gateway for cross-border transfer analysis.

Claims: CLM-TR-8192a3b4

Special CategoriesGreen

Article 6 LPPD enumerates special categories of personal data and was amended by Law 7499 in 2024.

Claims: CLM-TR-92a3b4c5, CLM-TR-a3b4c5d6

Pseudonymisation And AnonymisationGreen

A dedicated KVKK Regulation governs deletion, destruction and anonymisation, requiring retention/destruction policies and time periods.

Claims: CLM-TR-b4c5d6e7

Category narrative93 words

The LPPD's Article 5 sets out lawful-processing grounds broadly analogous to GDPR Art 6, while Article 6 enumerates special/sensitive categories (race, ethnicity, political opinion, philosophical belief, religion/sect, association/union membership, health, sexual life, and related attributes), amended by Law 7499 (2024). Explicit consent remains central in practice given persistent gaps in secondary guidance on alternative grounds. A dedicated Regulation on the Deletion, Destruction and Anonymisation of Personal Data obliges controllers to destroy, delete or anonymise data once the processing purpose lapses, and KVKK biometric-data guidance (2021) further conditions special-category biometric processing on necessity/proportionality principles.

Sources and claims (5)
  1. ConfirmedIAPPPersonal data may be transferred and otherwise processed on legal grounds set out under Article 5 of the LPPD, which operates as the general lawful-basis gateway analogous to GDPR Article 6.
  2. ConfirmedIAPPArticle 6 of the LPPD regulates special categories of personal data, covering race, ethnicity, political opinion, philosophical belief, religion, sect or other belief, association/foundation/trade-union membership, health and sexual life, among other attributes.
  3. ProbableIAPPLaw No. 7499 (2024) amended Article 6 of the LPPD concerning the processing of special categories of personal data, effective 1 June 2024.
  4. ConfirmedDataGuidanceKVKK's Regulation on the deletion, destruction and anonymisation of personal data requires data controllers to prepare retention and destruction policies with applicable time periods, and to delete, destroy or anonymise data once the processing purpose ceases to exist.
  5. ProbableIAPPIn the absence of a KVKK-issued safe-country list, obtaining the data subject's explicit consent has been, in practice, the only readily viable method to legalize cross-border personal data transfers under the pre-2024 regime.

#

Access-right and erasure-adjacent mechanisms are confirmed and codified, but restriction/objection, portability, and precise response-deadline provisions could not be independently verified with primary citations this run.

Primary frameworkLaw No. 6698 (LPPD), Article 11
Supervisory authorityKVKK
Traffic-light rationale — AmberAccess-right and erasure-adjacent mechanisms are confirmed and codified, but restriction/objection, portability, and precise response-deadline provisions could not be independently verified with primary citations this run.

Sub-modules (5)

Access RightGreen

Article 11 LPPD grants data subjects rights including access to their processed data; KVKK issued a 2018 Regulation consolidating subject-access-request (SAR) procedures.

Claims: CLM-TR-d6e7f8a9

Rectification And ErasureAmber

Erasure/destruction obligations are anchored in the Deletion, Destruction and Anonymisation Regulation, which requires controllers to delete or anonymise data once the processing purpose lapses.

Claims: CLM-TR-e7f8a9b0

Restriction And ObjectionRed

No primary-source detail on a distinct restriction-of-processing or objection-to-profiling mechanism was retrieved this run.

Absence provenance: not recorded. Searched: Turkey LPPD Article 7 restriction processing objection profiling right.

Data PortabilityRed

No confirmed evidence of a GDPR Article 20-style portability right was retrieved this run.

Absence provenance: not recorded. Searched: Turkey LPPD data portability right Article 20 equivalent.

Deadlines And Response WindowsAmber

Retrieved sources confirm a subject-access-request procedural regulation exists, but the precise statutory response-window (day-count) was not confirmed via primary-text excerpt this run.

Absence provenance: not recorded. Searched: Article 13 LPPD 30 days response deadline KVKK.

Category narrative64 words

Article 11 of the LPPD provides an access-right framework comparable to GDPR subject-access rights, consolidated procedurally by a 2018 KVKK Regulation. Erasure is operationalised primarily through the Deletion/Destruction/Anonymisation Regulation rather than a standalone Article-17-style 'right to be forgotten' clause. Direct primary-source confirmation of exact statutory response-window day-counts, and of restriction/objection and portability mechanics, was not obtained this run and is flagged as a gap.

Sources and claims (2)
  1. ConfirmedDataGuidanceKVKK published a supplementary Regulation on 10 March 2018 consolidating the procedure to be followed by data subjects and controllers with respect to subject access requests under Article 11 of the LPPD.
  2. ConfirmedDataGuidanceData controllers must delete, destroy or anonymise personal data once the legal reasons for its processing cease to exist, per KVKK's regulation on deletion, destruction and anonymisation.

#

Security and breach-notification duties are well-evidenced and actively enforced; DPIA and formal DPO-independence requirements are absent relative to GDPR, which is a structural gap rather than a mere evidentiary one.

Primary frameworkLaw No. 6698 (LPPD), Articles 12, 16, 18; KVKK secondary regulations/communiqués
Supervisory authorityKVKK
Traffic-light rationale — AmberSecurity and breach-notification duties are well-evidenced and actively enforced; DPIA and formal DPO-independence requirements are absent relative to GDPR, which is a structural gap rather than a mere evidentiary one.

Sub-modules (7)

Accountability And DpiaRed

The LPPD contains no express DPIA obligation or equivalent risk-evaluation requirement, unlike GDPR Article 35.

Claims: CLM-TR-c1d2e3f4

Dpo RequirementsAmber

DPO appointment is not mandatory; KVKK's 2021 Communiqué established a voluntary personnel-certification mechanism rather than a binding appointment threshold.

Claims: CLM-TR-d2e3f4a5

Ropa RequirementsAmber

VERBIS, maintained by KVKK, serves as the functional equivalent of a records-of-processing registry, though it is structurally different from controller-held GDPR Article 30 records.

Claims: CLM-TR-e3f4a5b6

Joint Controller ArrangementsGreen

Controllers processing via processors remain jointly responsible with data processors, and processors are barred from using data for purposes beyond the original processing purpose.

Claims: CLM-TR-f4a5b6c7

Security MeasuresGreen

Article 18(b) imposes the highest fine tier for security-of-processing failures, and KVKK has issued technical/administrative measures guidance; enforcement precedent (e.g., against tourism, banking, and e-commerce controllers) confirms active application.

Claims: CLM-TR-a5b6c7d8

Breach NotificationGreen

KVKK Board principle-decision interprets the Article 12(5) breach-notification deadline as 72 hours, requiring standard forms, incident logs and a breach response plan; multiple controllers have been fined for late notification.

Claims: CLM-TR-b6c7d8e9

Retention And DisposalGreen

Retention limits and disposal duties are set by the Deletion, Destruction and Anonymisation Regulation.

Claims: CLM-TR-d8e9f0a1

Category narrative86 words

The LPPD imposes accountability-adjacent duties (VERBIS registration/inventory, security-of-processing obligations, breach notification) but -- unlike the GDPR -- contains no express DPIA requirement, and DPO appointment remains voluntary notwithstanding a 2021 KVKK Communiqué establishing a personnel-certification mechanism. Breach notification is interpreted by Board principle-decision as a 72-hour standard, reinforced by real enforcement precedent (Clickbus, Marriott, Cathay Pacific fines for late notification). Security-of-processing failures attract the highest fine tier under Article 18(b). VERBIS functions as Turkey's de facto records-of-processing (ROPA) mechanism, though structurally distinct from GDPR Article 30.

Sources and claims (7)
  1. ConfirmedDataGuidanceUnlike the GDPR, the LPPD does not include any requirement to undertake a Data Protection Impact Assessment or any similar formal obligation to evaluate the risk of personal data processing.
  2. ConfirmedDataGuidanceKVKK introduced the concept of a data protection officer via the Communiqué on the Procedures and Principles Regarding the Personnel Certification Mechanism (6 December 2021); however, appointment of a DPO is not a mandatory requirement under the LPPD.
  3. ConfirmedDataGuidance / Esin Attorney PartnershipVERBIS is principally kept and maintained by KVKK and is fundamentally different from GDPR Article 30 records kept directly by controllers, though it requires controllers to submit a data-processing inventory.
  4. ConfirmedDataGuidance / Esin Attorney PartnershipWhere personal data is processed by a natural or legal person on behalf of a data controller, the controller is jointly responsible with data processors, who are in turn prohibited from disclosing or using data obtained from the controller for purposes other than the original processing purpose.
  5. ConfirmedIAPPArticle 18 of the LPPD imposes fines for failure to fulfil data-security provisions (historically ranging roughly TRY 15,000 to TRY 1,000,000, revalued annually), and this security-violation category has produced the highest observed fines in KVKK enforcement practice.
  6. ConfirmedIAPPKVKK's Board issued a principle decision interpreting the Article 12(5) breach-notification deadline as 72 hours, requiring controllers to report delay reasons, use a standard breach notification form, log breach information, and prepare a data breach response plan.
  7. ConfirmedDataGuidanceKVKK's Regulation on deletion, destruction and anonymisation requires data controllers to prepare data retention and destruction policies specifying applicable time periods.

#

A GDPR-aligned SCC/BCR framework is now codified and operative (2024), representing significant convergence, but no safe-country/adequacy list has been published and no reciprocal adequacy status with the EU/UK was confirmed.

Primary frameworkLPPD Article 9, as amended by Law No. 7499 (2024); By-Law on Procedures and Principles for the Transfer of Personal Data Abroad (July 2024)
Supervisory authorityKVKK
Traffic-light rationale — AmberA GDPR-aligned SCC/BCR framework is now codified and operative (2024), representing significant convergence, but no safe-country/adequacy list has been published and no reciprocal adequacy status with the EU/UK was confirmed.

Sub-modules (6)

Transfer MechanismsAmber

Pre-2024, transfer mechanisms were limited to explicit consent, an undertaking-plus-KVKK-permit route, or approved BCRs; the 2024 reform added a standardized-undertaking notification route and formalized SCCs/BCRs.

Claims: CLM-TR-e9f0a1b2, CLM-TR-f0a1b2c3

Adequacy ReceivedRed

No confirmation was found this run that Turkey has received an adequacy decision from the EU or UK; this is treated as an open gap requiring EDPB/EU-Commission primary-source confirmation.

Absence provenance: not recorded. Searched: Turkey EU adequacy decision GDPR, Turkey UK adequacy decision.

Adequacy GrantedRed

KVKK has not issued a 'safe country' or adequacy list of its own, meaning the adequacy-based transfer ground under Article 9 remains practically unavailable.

Claims: CLM-TR-b2c3d4e5

Sccs And BcrsGreen

Turkish SCCs (bilateral) and BCRs now require KVKK notification/approval, with wet-ink or secure e-signature execution and further KVKK guidance expected on SCC validity.

Claims: CLM-TR-c3d4e5f6

Transfer Impact AssessmentRed

No TIA-equivalent requirement was identified in the sources reviewed this run.

Absence provenance: not recorded. Searched: KVKK transfer impact assessment requirement By-Law 2024.

Data LocalisationAmber

No general/absolute data-localisation mandate was identified; VERBIS imposes registration/administrative obligations rather than a data-residency requirement.

Absence provenance: not recorded. Searched: Turkey data localisation requirement KVKK sector-specific.

Category narrative111 words

Turkey substantially overhauled its cross-border transfer regime via the March 2024 Law 7499 amendments to LPPD Article 9 and the implementing By-Law on Procedures and Principles for the Transfer of Personal Data Abroad (entered into force July 2024). The reform introduced Turkish Standard Contractual Clauses (bilateral, requiring KVKK notification and wet-ink/secure e-signature) and Binding Corporate Rules requiring KVKK approval, moving away from the pre-2024 regime under which -- absent any KVKK-issued adequacy/safe-country list -- explicit consent or an undertaking-plus-permit process were the only practical transfer routes. KVKK has not issued an EU-style adequacy decision covering Turkey, nor is Turkey confirmed to have received an adequacy decision from the EU or UK.

Sources and claims (4)
  1. ConfirmedIAPPUnder the pre-2024 regime, in the absence of a KVKK adequacy decision, data could be transferred abroad via notification to KVKK with a standard undertaking, submission of a written agreement with protective measures and obtaining a permit, approval of BCRs, or agreement between compatible public entities.
  2. ConfirmedDataGuidanceThe By-Law on the Procedures and Principles for the Transfer of Personal Data Abroad, implementing amended Article 9 of the LPPD, was published and entered into force in July 2024, alongside KVKK's publication of Turkish standard contract and BCR documents.
  3. ConfirmedIAPPAs KVKK has not issued a safe-country list, the adequacy-based transfer ground under Article 9 of the LPPD has not been practically available.
  4. ConfirmedDataGuidanceTurkish Standard Contractual Clauses are bilateral, require careful data-flow analysis and KVKK notification, and must be executed with wet-ink or secure e-signatures; BCRs also require KVKK approval.

#

Only the employment_data sub-module has direct, substantive evidentiary support this run; the remaining six sub-modules lack confirmed sector-specific overlay findings.

Supervisory authorityKVKK
Traffic-light rationale — RedOnly the employment_data sub-module has direct, substantive evidentiary support this run; the remaining six sub-modules lack confirmed sector-specific overlay findings.

Sub-modules (7)

Financial Sector OverlayRed

No financial-sector-specific DP overlay (e.g., Banking Law secrecy provisions vs. LPPD) was substantively retrieved this run.

Absence provenance: not recorded. Searched: Turkey Banking Law data protection KVKK financial sector overlay.

Health Sector OverlayRed

No health-sector-specific overlay statute content was retrieved this run.

Absence provenance: not recorded. Searched: Turkey health data law KVKK Ministry of Health overlay.

Telecoms And EprivacyRed

No substantive content on Electronic Communications Law No. 5809 or an ePrivacy-style overlay was retrieved this run.

Absence provenance: not recorded. Searched: Turkey electronic communications law 5809 KVKK direct marketing cookies ePrivacy.

Employment DataAmber

KVKK issued a public announcement (June 2026) on considerations for CCTV/security-camera use in workplaces, requiring employers to establish a legal basis under Article 5 and comply with core LPPD principles.

Claims: CLM-TR-e0f1a2b3

Credit And ScoringRed

No credit-scoring-specific overlay content was retrieved this run.

Absence provenance: not recorded. Searched: Turkey credit scoring KKB data protection overlay.

EducationRed

No education-sector-specific overlay content was retrieved this run.

Absence provenance: not recorded. Searched: Turkey education sector personal data KVKK overlay.

InsuranceRed

No insurance-sector-specific overlay content was retrieved this run.

Absence provenance: not recorded. Searched: Turkey insurance sector personal data KVKK overlay.

Category narrative57 words

Direct sector-specific overlay statutes (banking secrecy, health-sector regulation, telecoms/ePrivacy, credit scoring, education, insurance) were not substantively retrieved this run beyond general LPPD application and one workplace-specific KVKK guidance document on CCTV/surveillance in employment settings. This module is materially thin and requires dedicated follow-up research into Turkey's Banking Law, Electronic Communications Law No. 5809, and health-data-specific secondary legislation.

Sources and claims (1)
  1. ConfirmedDataGuidanceKVKK's June 2026 announcement on workplace security cameras requires employers to ensure that data processing via CCTV has a legal basis under Article 5 of the LPPD and adheres to fundamental processing principles.

#

No sub-module in this module reached a substantive, citable evidentiary threshold this run; all six sub-modules carry explicit absent_field_provenance.

Supervisory authorityKVKK
Traffic-light rationale — RedNo sub-module in this module reached a substantive, citable evidentiary threshold this run; all six sub-modules carry explicit absent_field_provenance.

Sub-modules (6)

Cookies And TrackersRed

KVKK has published draft/guidance material on cookies, but substantive content was not retrieved this run beyond titles.

Absence provenance: not recorded. Searched: Turkey KVKK cookie guidelines applications.

Dark PatternsRed

No Turkey-specific dark-pattern prohibition content was located.

Absence provenance: not recorded. Searched: Turkey KVKK dark patterns prohibition.

Opt Out SignalsRed

No GPC/DAA-equivalent opt-out-signal recognition was located for Turkey.

Absence provenance: not recorded. Searched: Turkey Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific KVKK rule was located.

Absence provenance: not recorded. Searched: Turkey KVKK data clean room data collaboration room.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' analogue was located for Turkey.

Absence provenance: not recorded. Searched: Turkey cross-context advertising personal data sale share equivalent.

Direct MarketingRed

Turkey separately regulates commercial electronic messages and KVKK has issued at least one no-violation finding on SMS marketing, but substantive detail was not retrieved this run.

Absence provenance: not recorded. Searched: Turkey commercial electronic message management regulation KVKK SMS marketing.

Category narrative62 words

KVKK has issued cookie-related guidance and Turkey separately regulates commercial electronic messaging, but this run only retrieved title-level references (draft cookie guidelines, Commercial Electronic Message Management Regulation, an SMS-marketing no-violation finding) without substantive body content sufficient for citable claims. Dark patterns, opt-out signals (GPC/DAA), clean-room/data-collaboration rules, and cross-context advertising concepts akin to CPRA's 'sale'/'share' were not located in Turkish-specific sources this run.

#

Biometric-data guidance is well-evidenced; AI-specific and ADM-transparency findings rest on title-level sources only and are marked Uncertain pending primary-text confirmation.

Primary frameworkLaw No. 6698 (LPPD), Articles 4 and 6; KVKK biometric-data guidance (2021)
Supervisory authorityKVKK
Traffic-light rationale — AmberBiometric-data guidance is well-evidenced; AI-specific and ADM-transparency findings rest on title-level sources only and are marked Uncertain pending primary-text confirmation.

Sub-modules (6)

Profiling RestrictionsRed

No Turkey-specific Article 22-equivalent profiling restriction was confirmed this run.

Absence provenance: not recorded. Searched: Turkey LPPD profiling restriction automated decision Article 22 equivalent.

Automated Decision Making TransparencyRed

No ADM-transparency-specific KVKK rule was confirmed this run.

Absence provenance: not recorded. Searched: Turkey KVKK automated decision-making transparency explanation right.

Ai Risk AssessmentsAmber

A parliamentary AI bill and a KVKK generative-AI guide were reported to exist (late 2025), but detail was not retrieved beyond titles.

Absence provenance: not recorded. Searched: Turkey AI bill parliamentary committee KVKK generative AI guide content.

Claims: CLM-TR-f1a2b3c4

Biometric RegimeGreen

KVKK's September 2021 guidance defines biometric data and sets processing principles under Articles 4 and 6 of the LPPD.

Claims: CLM-TR-a2b3c4d5

Genetic DataRed

No genetic-data-specific regime distinct from the general 'health' special category was confirmed this run.

Absence provenance: not recorded. Searched: Turkey KVKK genetic data specific regime.

State Surveillance CarveoutsAmber

The LPPD excludes processing of personal data for public-security or law-enforcement purposes from its general application, functioning as a national-security carve-out comparable to GDPR Art 2(2)/23 exemptions.

Claims: CLM-TR-b3c4d5e6

Category narrative87 words

KVKK issued dedicated guidance on biometric data processing (September 2021), grounding biometric processing in Articles 4 and 6 principles (necessity, proportionality, minimal retention, transparency). A parliamentary bill to regulate artificial intelligence was reportedly introduced (November 2025) and KVKK reportedly published a guide on generative AI and personal data protection (November 2025), though substantive text of both was not retrieved this run. The LPPD generally excludes processing for public-security/law-enforcement purposes from its scope, functioning as a national-security carve-out. No Turkey-specific ADM-transparency (Article 22-equivalent) or genetic-data-specific regime was confirmed.

Sources and claims (3)
  1. ConfirmedDataGuidanceKVKK published guidance on 16 September 2021 on the considerations for processing biometric data, defining biometric data and requiring that processing methods be suitable for and proportionate to the purpose, that data be retained only as long as necessary, and that data subjects be informed in accordance with Article 10.
  2. ConfirmedDataGuidance / Esin Attorney PartnershipBoth the GDPR and the LPPD provide similar exclusions from their application, including for processing of personal data in the context of public security or law enforcement.
  3. UncertainDataGuidanceA parliamentary bill to regulate artificial intelligence in Turkey was reported as introduced around November 2025, alongside a KVKK guide addressing generative AI and personal data protection.

#

This is a confirmed statutory gap: the LPPD contains no children-specific consent, age-verification, or profiling-ban regime, and no dependent-adult-specific regime was found.

Primary frameworkLaw No. 6698 (LPPD) -- no children-specific provisions
Supervisory authorityKVKK
Traffic-light rationale — RedThis is a confirmed statutory gap: the LPPD contains no children-specific consent, age-verification, or profiling-ban regime, and no dependent-adult-specific regime was found.

Sub-modules (5)

Age VerificationRed

The LPPD does not set an age limit for consent or for the notification requirement.

Claims: CLM-TR-c4d5e6f7

Minor Profiling BansRed

No minor-specific profiling ban was identified; KVKK's only children-data output located is a non-binding 2020 brochure.

Claims: CLM-TR-e6f7a8b9

Education SettingsRed

No education-setting-specific children's-data rule was identified this run.

Absence provenance: not recorded. Searched: Turkey KVKK children data education setting specific rule.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated)-specific protection was identified this run.

Absence provenance: not recorded. Searched: Turkey KVKK dependent adults vulnerable persons data protection.

Category narrative66 words

Unlike the GDPR (Article 8), the LPPD does not grant special statutory protection to children's personal data, does not set an age of consent, and does not specify whether parental/guardian consent is required for information-society services directed at minors. KVKK has issued only soft, non-binding awareness material (a 2020 brochure on children's data) rather than binding age-verification, parental-consent, or minor-profiling-ban provisions. Dependent-adult-specific protections were not identified.

Sources and claims (3)
  1. ConfirmedDataGuidanceThe LPPD does not set an age limit for consent, and there is no age limit set for the notification requirement.
  2. ConfirmedDataGuidanceUnlike the GDPR, the LPPD does not grant special protection to children's personal data, nor does it specify whether the consent of a parent or guardian is needed when processing children's data or providing information-society services to a child.
  3. ConfirmedDataGuidanceKVKK's only substantive output addressing children's data is a 23 April 2020 brochure bearing similarities with GDPR protective measures, rather than a binding profiling ban.

#

Powers, penalty tiers, and enforcement-activity evidence are strong; funding/capacity, collective-redress, and private-right-of-action sub-modules remain evidentiary gaps.

Primary frameworkLaw No. 6698 (LPPD), Article 18 (administrative fines) and Article 15 (investigative powers)
Supervisory authorityKVKK
Traffic-light rationale — AmberPowers, penalty tiers, and enforcement-activity evidence are strong; funding/capacity, collective-redress, and private-right-of-action sub-modules remain evidentiary gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Article 18 sets four fine tiers, revalued annually; VERBIS non-registration alone can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.

Claims: CLM-TR-a6b7c8d9, CLM-TR-b7c8d9e0

Enforcement Activity IndexGreen

KVKK has fined multiple international controllers for late breach notification and security-of-processing failures.

Claims: CLM-TR-c8d9e0f1

Regulator Funding And CapacityRed

No funding or headcount data for KVKK was retrieved this run.

Absence provenance: not recorded. Searched: KVKK budget headcount staffing capacity.

Collective Redress And Class ActionsRed

No Turkey-specific collective-redress or class-action mechanism for data-protection claims was confirmed this run.

Absence provenance: not recorded. Searched: Turkey collective redress class action data protection KVKK.

Private Right Of ActionRed

No specific confirmation of a standalone private right of direct court access (distinct from KVKK complaint channels) was retrieved this run.

Absence provenance: not recorded. Searched: Turkey LPPD private right of action court data protection.

Recent Developments 180DGreen

Within the 180 days preceding this run (roughly February-August 2026), KVKK issued a VERBİS business-partnership clarification (March 2026) and two CCTV/security-camera guidance announcements for workplaces and residential complexes (June 2026).

Claims: CLM-TR-70819a3b, CLM-TR-e0f1a2b3, CLM-TR-d9e0f1a2

Category narrative98 words

KVKK has broad investigative and sanctioning powers under Article 18 of the LPPD, with four fine tiers (failure to inform; data-security failures; non-compliance with Board decisions; VERBIS registration failures), annually revalued and reaching over TRY 1.8 million per violation category by the 2020s. Enforcement activity includes real fines for late breach notification (Clickbus, Marriott, Cathay Pacific) and for security-of-processing failures. Recent (within-180-day) developments include KVKK's March 2026 VERBİS partnership clarification and June 2026 CCTV/workplace and residential guidance. Regulator funding/headcount signals, collective-redress mechanisms, and a distinct private right of action were not confirmed with citable primary sources this run.

Sources and claims (4)
  1. ConfirmedIAPPArticle 18 of the LPPD defines four administrative fine categories: failure to fulfil the obligation to inform, failure to fulfil data-security provisions, failure to fulfil Board decisions, and failure to fulfil VERBIS registration/notification obligations, with amounts revalued annually.
  2. ConfirmedIAPPFailure to register in time with VERBIS may result in an administrative fine of up to TRY 1,802,000, plus a second administrative fine of up to TRY 1,802,000 for non-compliance with KVKK's decisions, and KVKK may restrict the controller's data-processing activities in Turkey.
  3. ConfirmedIAPPKVKK has fined controllers for late breach notification, including Clickbus Travel Services (TRY 100,000 for notifying two months late), Marriott International (TRY 350,000 for late notification to the DPA and data subjects), and Cathay Pacific Airways (TRY 100,000 for a five-month delay).
  4. ConfirmedDataGuidanceOn 31 December 2025, KVKK announced updated administrative fine amounts under Article 18 of the LPPD, reflecting the revaluation rate for 2017-2026.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Turkey
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s), 39 source(s) in the cumulative register.