Traffic-light rationale — GreenComprehensive statute in force with an operational, actively enforcing regulator (KVKK) and a functioning registration system (VERBIS).
Sub-modules (5)
Regulator And AuthorityGreen
KVKK is Turkey's dedicated personal-data-protection authority and Board, issuing binding decisions, guidance, and administrative fines.
Claims: CLM-TR-1a2b3c4d
Act And InstrumentsGreen
LPPD (Law 6698, 2016) is the primary instrument; Law 7499 (2024) amended Articles 6, 9 and 18.
Claims: CLM-TR-2b3c4d5e, CLM-TR-3c4d5e6f
Material ScopeGreen
Scope mirrors GDPR's automated-processing/filing-system test and shares comparable definitions of 'processing' and 'personal data'.
Claims: CLM-TR-4d5e6f70
Territorial ScopeAmber
The LPPD is textually silent on extraterritorial scope but VERBIS registration is applied to foreign controllers processing data collected from Turkey.
Claims: CLM-TR-5e6f7081
Regulator Registration And FilingGreen
VERBIS registration is mandatory for qualifying controllers (Turkish controllers with ≥50 employees or ≥TRY 25m turnover, and foreign controllers), and KVKK continues to issue clarifying announcements (e.g., on partnership structures in March 2026).
Claims: CLM-TR-6f708192, CLM-TR-70819a3b
Category narrative100 words
Turkey operates a comprehensive omnibus regime under Law No. 6698 on the Protection of Personal Data (LPPD/KVKK Law), enforced by the Personal Data Protection Authority (KVKK/Kurul). The law was modelled on the pre-GDPR EU Data Protection Directive 95/46/EC and has been progressively amended (most recently by Law No. 7499 in 2024) to narrow the gap with the GDPR, particularly on special-category processing and cross-border transfers. Material and territorial scope closely track the GDPR's automated/filing-system test, and the LPPD has a recognised (if textually silent) extraterritorial reach implemented administratively through the VERBIS data-controller registry, which also functions as Turkey's registration/filing mechanism.
Sources and claims (7)
ConfirmedDataGuidance — The Personal Data Protection Authority (KVKK) is Turkey's supervisory authority for the Law on the Protection of Personal Data No. 6698.
ConfirmedDataGuidance / Esin Attorney Partnership — The Law on Protection of Personal Data No. 6698 (LPPD) was published in the Official Gazette on 7 April 2016 and entered into force as Turkey's first general data protection law.
ConfirmedIAPP — Law No. 7499, amending the Code of Criminal Procedure and Certain Laws, introduced amendments to Articles 6, 9 and 18 of the LPPD, with the first segment published in the Official Gazette on 12 March 2024 and effective 1 June 2024.
ConfirmedDataGuidance / Esin Attorney Partnership — The LPPD and GDPR provide comparable definitions of 'processing', 'personal data' and 'sensitive data', and both apply to automated or filing-system-based processing.
ConfirmedIAPP — VERBIS registration requirements extend extraterritorially to foreign (non-Turkey-established) data controllers that collect or process personal data originating in Turkey.
ConfirmedIAPP — Turkish data controllers with 50 or more employees, or annual turnover of TRY 25,000,000 or more, must register with VERBIS; failure to register can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.
ConfirmedDataGuidance — In a March 2026 public announcement, KVKK clarified that partners in business partnerships, consortiums and ordinary partnerships must incorporate partnership-related personal data processing into their own individual VERBİS registrations rather than creating separate registrations.
Core lawful-basis and special-category architecture is codified and enforced, but consent-thresholds guidance is comparatively thin relative to GDPR-level granularity, and some 2024 amendment detail was not independently verified this run.
Primary frameworkLaw No. 6698 (LPPD), Articles 5-6, as amended by Law No. 7499 (2024)
Traffic-light rationale — Not assessedCore lawful-basis and special-category architecture is codified and enforced, but consent-thresholds guidance is comparatively thin relative to GDPR-level granularity, and some 2024 amendment detail was not independently verified this run.
Sub-modules (4)
Lawful BasesAmber
Article 5 LPPD sets out the legal grounds for processing (paralleling GDPR Art 6), referenced also as the general-ground gateway for cross-border transfer analysis.
Claims: CLM-TR-8192a3b4
Consent ThresholdsAmber
Explicit consent has historically been the dominant, most reliable practical basis in the absence of a KVKK safe-country list, particularly for transfers; granular consent-quality standards (freely given/informed/revocable) were not independently re-confirmed with primary-text citations this run.
Absence provenance: not recorded. Searched: KVKK consent standard freely given informed revocable Article 3 definitions.
Claims: CLM-TR-c5d6e7f8
Special CategoriesGreen
Article 6 LPPD enumerates special categories of personal data and was amended by Law 7499 in 2024.
Claims: CLM-TR-92a3b4c5, CLM-TR-a3b4c5d6
Pseudonymisation And AnonymisationGreen
A dedicated KVKK Regulation governs deletion, destruction and anonymisation, requiring retention/destruction policies and time periods.
Claims: CLM-TR-b4c5d6e7
Category narrative93 words
The LPPD's Article 5 sets out lawful-processing grounds broadly analogous to GDPR Art 6, while Article 6 enumerates special/sensitive categories (race, ethnicity, political opinion, philosophical belief, religion/sect, association/union membership, health, sexual life, and related attributes), amended by Law 7499 (2024). Explicit consent remains central in practice given persistent gaps in secondary guidance on alternative grounds. A dedicated Regulation on the Deletion, Destruction and Anonymisation of Personal Data obliges controllers to destroy, delete or anonymise data once the processing purpose lapses, and KVKK biometric-data guidance (2021) further conditions special-category biometric processing on necessity/proportionality principles.
Sources and claims (5)
ConfirmedIAPP — Personal data may be transferred and otherwise processed on legal grounds set out under Article 5 of the LPPD, which operates as the general lawful-basis gateway analogous to GDPR Article 6.
ConfirmedIAPP — Article 6 of the LPPD regulates special categories of personal data, covering race, ethnicity, political opinion, philosophical belief, religion, sect or other belief, association/foundation/trade-union membership, health and sexual life, among other attributes.
ProbableIAPP — Law No. 7499 (2024) amended Article 6 of the LPPD concerning the processing of special categories of personal data, effective 1 June 2024.
ConfirmedDataGuidance — KVKK's Regulation on the deletion, destruction and anonymisation of personal data requires data controllers to prepare retention and destruction policies with applicable time periods, and to delete, destroy or anonymise data once the processing purpose ceases to exist.
ProbableIAPP — In the absence of a KVKK-issued safe-country list, obtaining the data subject's explicit consent has been, in practice, the only readily viable method to legalize cross-border personal data transfers under the pre-2024 regime.
Access-right and erasure-adjacent mechanisms are confirmed and codified, but restriction/objection, portability, and precise response-deadline provisions could not be independently verified with primary citations this run.
Traffic-light rationale — AmberAccess-right and erasure-adjacent mechanisms are confirmed and codified, but restriction/objection, portability, and precise response-deadline provisions could not be independently verified with primary citations this run.
Sub-modules (5)
Access RightGreen
Article 11 LPPD grants data subjects rights including access to their processed data; KVKK issued a 2018 Regulation consolidating subject-access-request (SAR) procedures.
Claims: CLM-TR-d6e7f8a9
Rectification And ErasureAmber
Erasure/destruction obligations are anchored in the Deletion, Destruction and Anonymisation Regulation, which requires controllers to delete or anonymise data once the processing purpose lapses.
Claims: CLM-TR-e7f8a9b0
Restriction And ObjectionRed
No primary-source detail on a distinct restriction-of-processing or objection-to-profiling mechanism was retrieved this run.
No confirmed evidence of a GDPR Article 20-style portability right was retrieved this run.
Absence provenance: not recorded. Searched: Turkey LPPD data portability right Article 20 equivalent.
Deadlines And Response WindowsAmber
Retrieved sources confirm a subject-access-request procedural regulation exists, but the precise statutory response-window (day-count) was not confirmed via primary-text excerpt this run.
Absence provenance: not recorded. Searched: Article 13 LPPD 30 days response deadline KVKK.
Category narrative64 words
Article 11 of the LPPD provides an access-right framework comparable to GDPR subject-access rights, consolidated procedurally by a 2018 KVKK Regulation. Erasure is operationalised primarily through the Deletion/Destruction/Anonymisation Regulation rather than a standalone Article-17-style 'right to be forgotten' clause. Direct primary-source confirmation of exact statutory response-window day-counts, and of restriction/objection and portability mechanics, was not obtained this run and is flagged as a gap.
Sources and claims (2)
ConfirmedDataGuidance — KVKK published a supplementary Regulation on 10 March 2018 consolidating the procedure to be followed by data subjects and controllers with respect to subject access requests under Article 11 of the LPPD.
ConfirmedDataGuidance — Data controllers must delete, destroy or anonymise personal data once the legal reasons for its processing cease to exist, per KVKK's regulation on deletion, destruction and anonymisation.
Security and breach-notification duties are well-evidenced and actively enforced; DPIA and formal DPO-independence requirements are absent relative to GDPR, which is a structural gap rather than a mere evidentiary one.
Traffic-light rationale — AmberSecurity and breach-notification duties are well-evidenced and actively enforced; DPIA and formal DPO-independence requirements are absent relative to GDPR, which is a structural gap rather than a mere evidentiary one.
Sub-modules (7)
Accountability And DpiaRed
The LPPD contains no express DPIA obligation or equivalent risk-evaluation requirement, unlike GDPR Article 35.
Claims: CLM-TR-c1d2e3f4
Dpo RequirementsAmber
DPO appointment is not mandatory; KVKK's 2021 Communiqué established a voluntary personnel-certification mechanism rather than a binding appointment threshold.
Claims: CLM-TR-d2e3f4a5
Ropa RequirementsAmber
VERBIS, maintained by KVKK, serves as the functional equivalent of a records-of-processing registry, though it is structurally different from controller-held GDPR Article 30 records.
Claims: CLM-TR-e3f4a5b6
Joint Controller ArrangementsGreen
Controllers processing via processors remain jointly responsible with data processors, and processors are barred from using data for purposes beyond the original processing purpose.
Claims: CLM-TR-f4a5b6c7
Security MeasuresGreen
Article 18(b) imposes the highest fine tier for security-of-processing failures, and KVKK has issued technical/administrative measures guidance; enforcement precedent (e.g., against tourism, banking, and e-commerce controllers) confirms active application.
Claims: CLM-TR-a5b6c7d8
Breach NotificationGreen
KVKK Board principle-decision interprets the Article 12(5) breach-notification deadline as 72 hours, requiring standard forms, incident logs and a breach response plan; multiple controllers have been fined for late notification.
Claims: CLM-TR-b6c7d8e9
Retention And DisposalGreen
Retention limits and disposal duties are set by the Deletion, Destruction and Anonymisation Regulation.
Claims: CLM-TR-d8e9f0a1
Category narrative86 words
The LPPD imposes accountability-adjacent duties (VERBIS registration/inventory, security-of-processing obligations, breach notification) but -- unlike the GDPR -- contains no express DPIA requirement, and DPO appointment remains voluntary notwithstanding a 2021 KVKK Communiqué establishing a personnel-certification mechanism. Breach notification is interpreted by Board principle-decision as a 72-hour standard, reinforced by real enforcement precedent (Clickbus, Marriott, Cathay Pacific fines for late notification). Security-of-processing failures attract the highest fine tier under Article 18(b). VERBIS functions as Turkey's de facto records-of-processing (ROPA) mechanism, though structurally distinct from GDPR Article 30.
Sources and claims (7)
ConfirmedDataGuidance — Unlike the GDPR, the LPPD does not include any requirement to undertake a Data Protection Impact Assessment or any similar formal obligation to evaluate the risk of personal data processing.
ConfirmedDataGuidance — KVKK introduced the concept of a data protection officer via the Communiqué on the Procedures and Principles Regarding the Personnel Certification Mechanism (6 December 2021); however, appointment of a DPO is not a mandatory requirement under the LPPD.
ConfirmedDataGuidance / Esin Attorney Partnership — VERBIS is principally kept and maintained by KVKK and is fundamentally different from GDPR Article 30 records kept directly by controllers, though it requires controllers to submit a data-processing inventory.
ConfirmedDataGuidance / Esin Attorney Partnership — Where personal data is processed by a natural or legal person on behalf of a data controller, the controller is jointly responsible with data processors, who are in turn prohibited from disclosing or using data obtained from the controller for purposes other than the original processing purpose.
ConfirmedIAPP — Article 18 of the LPPD imposes fines for failure to fulfil data-security provisions (historically ranging roughly TRY 15,000 to TRY 1,000,000, revalued annually), and this security-violation category has produced the highest observed fines in KVKK enforcement practice.
ConfirmedIAPP — KVKK's Board issued a principle decision interpreting the Article 12(5) breach-notification deadline as 72 hours, requiring controllers to report delay reasons, use a standard breach notification form, log breach information, and prepare a data breach response plan.
ConfirmedDataGuidance — KVKK's Regulation on deletion, destruction and anonymisation requires data controllers to prepare data retention and destruction policies specifying applicable time periods.
A GDPR-aligned SCC/BCR framework is now codified and operative (2024), representing significant convergence, but no safe-country/adequacy list has been published and no reciprocal adequacy status with the EU/UK was confirmed.
Primary frameworkLPPD Article 9, as amended by Law No. 7499 (2024); By-Law on Procedures and Principles for the Transfer of Personal Data Abroad (July 2024)
Traffic-light rationale — AmberA GDPR-aligned SCC/BCR framework is now codified and operative (2024), representing significant convergence, but no safe-country/adequacy list has been published and no reciprocal adequacy status with the EU/UK was confirmed.
Sub-modules (6)
Transfer MechanismsAmber
Pre-2024, transfer mechanisms were limited to explicit consent, an undertaking-plus-KVKK-permit route, or approved BCRs; the 2024 reform added a standardized-undertaking notification route and formalized SCCs/BCRs.
Claims: CLM-TR-e9f0a1b2, CLM-TR-f0a1b2c3
Adequacy ReceivedRed
No confirmation was found this run that Turkey has received an adequacy decision from the EU or UK; this is treated as an open gap requiring EDPB/EU-Commission primary-source confirmation.
Absence provenance: not recorded. Searched: Turkey EU adequacy decision GDPR, Turkey UK adequacy decision.
Adequacy GrantedRed
KVKK has not issued a 'safe country' or adequacy list of its own, meaning the adequacy-based transfer ground under Article 9 remains practically unavailable.
Claims: CLM-TR-b2c3d4e5
Sccs And BcrsGreen
Turkish SCCs (bilateral) and BCRs now require KVKK notification/approval, with wet-ink or secure e-signature execution and further KVKK guidance expected on SCC validity.
Claims: CLM-TR-c3d4e5f6
Transfer Impact AssessmentRed
No TIA-equivalent requirement was identified in the sources reviewed this run.
Absence provenance: not recorded. Searched: KVKK transfer impact assessment requirement By-Law 2024.
Data LocalisationAmber
No general/absolute data-localisation mandate was identified; VERBIS imposes registration/administrative obligations rather than a data-residency requirement.
Absence provenance: not recorded. Searched: Turkey data localisation requirement KVKK sector-specific.
Category narrative111 words
Turkey substantially overhauled its cross-border transfer regime via the March 2024 Law 7499 amendments to LPPD Article 9 and the implementing By-Law on Procedures and Principles for the Transfer of Personal Data Abroad (entered into force July 2024). The reform introduced Turkish Standard Contractual Clauses (bilateral, requiring KVKK notification and wet-ink/secure e-signature) and Binding Corporate Rules requiring KVKK approval, moving away from the pre-2024 regime under which -- absent any KVKK-issued adequacy/safe-country list -- explicit consent or an undertaking-plus-permit process were the only practical transfer routes. KVKK has not issued an EU-style adequacy decision covering Turkey, nor is Turkey confirmed to have received an adequacy decision from the EU or UK.
Sources and claims (4)
ConfirmedIAPP — Under the pre-2024 regime, in the absence of a KVKK adequacy decision, data could be transferred abroad via notification to KVKK with a standard undertaking, submission of a written agreement with protective measures and obtaining a permit, approval of BCRs, or agreement between compatible public entities.
ConfirmedDataGuidance — The By-Law on the Procedures and Principles for the Transfer of Personal Data Abroad, implementing amended Article 9 of the LPPD, was published and entered into force in July 2024, alongside KVKK's publication of Turkish standard contract and BCR documents.
ConfirmedIAPP — As KVKK has not issued a safe-country list, the adequacy-based transfer ground under Article 9 of the LPPD has not been practically available.
ConfirmedDataGuidance — Turkish Standard Contractual Clauses are bilateral, require careful data-flow analysis and KVKK notification, and must be executed with wet-ink or secure e-signatures; BCRs also require KVKK approval.
Only the employment_data sub-module has direct, substantive evidentiary support this run; the remaining six sub-modules lack confirmed sector-specific overlay findings.
Traffic-light rationale — RedOnly the employment_data sub-module has direct, substantive evidentiary support this run; the remaining six sub-modules lack confirmed sector-specific overlay findings.
Sub-modules (7)
Financial Sector OverlayRed
No financial-sector-specific DP overlay (e.g., Banking Law secrecy provisions vs. LPPD) was substantively retrieved this run.
Absence provenance: not recorded. Searched: Turkey Banking Law data protection KVKK financial sector overlay.
Health Sector OverlayRed
No health-sector-specific overlay statute content was retrieved this run.
Absence provenance: not recorded. Searched: Turkey health data law KVKK Ministry of Health overlay.
Telecoms And EprivacyRed
No substantive content on Electronic Communications Law No. 5809 or an ePrivacy-style overlay was retrieved this run.
Absence provenance: not recorded. Searched: Turkey electronic communications law 5809 KVKK direct marketing cookies ePrivacy.
Employment DataAmber
KVKK issued a public announcement (June 2026) on considerations for CCTV/security-camera use in workplaces, requiring employers to establish a legal basis under Article 5 and comply with core LPPD principles.
Claims: CLM-TR-e0f1a2b3
Credit And ScoringRed
No credit-scoring-specific overlay content was retrieved this run.
Absence provenance: not recorded. Searched: Turkey credit scoring KKB data protection overlay.
EducationRed
No education-sector-specific overlay content was retrieved this run.
Absence provenance: not recorded. Searched: Turkey education sector personal data KVKK overlay.
InsuranceRed
No insurance-sector-specific overlay content was retrieved this run.
Absence provenance: not recorded. Searched: Turkey insurance sector personal data KVKK overlay.
Category narrative57 words
Direct sector-specific overlay statutes (banking secrecy, health-sector regulation, telecoms/ePrivacy, credit scoring, education, insurance) were not substantively retrieved this run beyond general LPPD application and one workplace-specific KVKK guidance document on CCTV/surveillance in employment settings. This module is materially thin and requires dedicated follow-up research into Turkey's Banking Law, Electronic Communications Law No. 5809, and health-data-specific secondary legislation.
Sources and claims (1)
ConfirmedDataGuidance — KVKK's June 2026 announcement on workplace security cameras requires employers to ensure that data processing via CCTV has a legal basis under Article 5 of the LPPD and adheres to fundamental processing principles.
No sub-module in this module reached a substantive, citable evidentiary threshold this run; all six sub-modules carry explicit absent_field_provenance.
Traffic-light rationale — RedNo sub-module in this module reached a substantive, citable evidentiary threshold this run; all six sub-modules carry explicit absent_field_provenance.
Sub-modules (6)
Cookies And TrackersRed
KVKK has published draft/guidance material on cookies, but substantive content was not retrieved this run beyond titles.
Absence provenance: not recorded. Searched: Turkey KVKK cookie guidelines applications.
Dark PatternsRed
No Turkey-specific dark-pattern prohibition content was located.
Absence provenance: not recorded. Searched: Turkey KVKK dark patterns prohibition.
Opt Out SignalsRed
No GPC/DAA-equivalent opt-out-signal recognition was located for Turkey.
Absence provenance: not recorded. Searched: Turkey Global Privacy Control opt-out signal recognition.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room-specific KVKK rule was located.
Absence provenance: not recorded. Searched: Turkey KVKK data clean room data collaboration room.
Cross Context AdvertisingRed
No CPRA-style 'sale'/'share' analogue was located for Turkey.
Absence provenance: not recorded. Searched: Turkey cross-context advertising personal data sale share equivalent.
Direct MarketingRed
Turkey separately regulates commercial electronic messages and KVKK has issued at least one no-violation finding on SMS marketing, but substantive detail was not retrieved this run.
KVKK has issued cookie-related guidance and Turkey separately regulates commercial electronic messaging, but this run only retrieved title-level references (draft cookie guidelines, Commercial Electronic Message Management Regulation, an SMS-marketing no-violation finding) without substantive body content sufficient for citable claims. Dark patterns, opt-out signals (GPC/DAA), clean-room/data-collaboration rules, and cross-context advertising concepts akin to CPRA's 'sale'/'share' were not located in Turkish-specific sources this run.
Biometric-data guidance is well-evidenced; AI-specific and ADM-transparency findings rest on title-level sources only and are marked Uncertain pending primary-text confirmation.
Traffic-light rationale — AmberBiometric-data guidance is well-evidenced; AI-specific and ADM-transparency findings rest on title-level sources only and are marked Uncertain pending primary-text confirmation.
Sub-modules (6)
Profiling RestrictionsRed
No Turkey-specific Article 22-equivalent profiling restriction was confirmed this run.
A parliamentary AI bill and a KVKK generative-AI guide were reported to exist (late 2025), but detail was not retrieved beyond titles.
Absence provenance: not recorded. Searched: Turkey AI bill parliamentary committee KVKK generative AI guide content.
Claims: CLM-TR-f1a2b3c4
Biometric RegimeGreen
KVKK's September 2021 guidance defines biometric data and sets processing principles under Articles 4 and 6 of the LPPD.
Claims: CLM-TR-a2b3c4d5
Genetic DataRed
No genetic-data-specific regime distinct from the general 'health' special category was confirmed this run.
Absence provenance: not recorded. Searched: Turkey KVKK genetic data specific regime.
State Surveillance CarveoutsAmber
The LPPD excludes processing of personal data for public-security or law-enforcement purposes from its general application, functioning as a national-security carve-out comparable to GDPR Art 2(2)/23 exemptions.
Claims: CLM-TR-b3c4d5e6
Category narrative87 words
KVKK issued dedicated guidance on biometric data processing (September 2021), grounding biometric processing in Articles 4 and 6 principles (necessity, proportionality, minimal retention, transparency). A parliamentary bill to regulate artificial intelligence was reportedly introduced (November 2025) and KVKK reportedly published a guide on generative AI and personal data protection (November 2025), though substantive text of both was not retrieved this run. The LPPD generally excludes processing for public-security/law-enforcement purposes from its scope, functioning as a national-security carve-out. No Turkey-specific ADM-transparency (Article 22-equivalent) or genetic-data-specific regime was confirmed.
Sources and claims (3)
ConfirmedDataGuidance — KVKK published guidance on 16 September 2021 on the considerations for processing biometric data, defining biometric data and requiring that processing methods be suitable for and proportionate to the purpose, that data be retained only as long as necessary, and that data subjects be informed in accordance with Article 10.
ConfirmedDataGuidance / Esin Attorney Partnership — Both the GDPR and the LPPD provide similar exclusions from their application, including for processing of personal data in the context of public security or law enforcement.
UncertainDataGuidance — A parliamentary bill to regulate artificial intelligence in Turkey was reported as introduced around November 2025, alongside a KVKK guide addressing generative AI and personal data protection.
This is a confirmed statutory gap: the LPPD contains no children-specific consent, age-verification, or profiling-ban regime, and no dependent-adult-specific regime was found.
Primary frameworkLaw No. 6698 (LPPD) -- no children-specific provisions
Traffic-light rationale — RedThis is a confirmed statutory gap: the LPPD contains no children-specific consent, age-verification, or profiling-ban regime, and no dependent-adult-specific regime was found.
Sub-modules (5)
Age VerificationRed
The LPPD does not set an age limit for consent or for the notification requirement.
Claims: CLM-TR-c4d5e6f7
Parental ConsentRed
The LPPD does not specify whether parental or guardian consent is required for processing children's data or for providing information-society services to a child.
Claims: CLM-TR-d5e6f7a8
Minor Profiling BansRed
No minor-specific profiling ban was identified; KVKK's only children-data output located is a non-binding 2020 brochure.
Claims: CLM-TR-e6f7a8b9
Education SettingsRed
No education-setting-specific children's-data rule was identified this run.
Absence provenance: not recorded. Searched: Turkey KVKK children data education setting specific rule.
Dependent AdultsRed
No dependent-adult (elderly/incapacitated)-specific protection was identified this run.
Absence provenance: not recorded. Searched: Turkey KVKK dependent adults vulnerable persons data protection.
Category narrative66 words
Unlike the GDPR (Article 8), the LPPD does not grant special statutory protection to children's personal data, does not set an age of consent, and does not specify whether parental/guardian consent is required for information-society services directed at minors. KVKK has issued only soft, non-binding awareness material (a 2020 brochure on children's data) rather than binding age-verification, parental-consent, or minor-profiling-ban provisions. Dependent-adult-specific protections were not identified.
Sources and claims (3)
ConfirmedDataGuidance — The LPPD does not set an age limit for consent, and there is no age limit set for the notification requirement.
ConfirmedDataGuidance — Unlike the GDPR, the LPPD does not grant special protection to children's personal data, nor does it specify whether the consent of a parent or guardian is needed when processing children's data or providing information-society services to a child.
ConfirmedDataGuidance — KVKK's only substantive output addressing children's data is a 23 April 2020 brochure bearing similarities with GDPR protective measures, rather than a binding profiling ban.
Traffic-light rationale — AmberPowers, penalty tiers, and enforcement-activity evidence are strong; funding/capacity, collective-redress, and private-right-of-action sub-modules remain evidentiary gaps.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Article 18 sets four fine tiers, revalued annually; VERBIS non-registration alone can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.
Claims: CLM-TR-a6b7c8d9, CLM-TR-b7c8d9e0
Enforcement Activity IndexGreen
KVKK has fined multiple international controllers for late breach notification and security-of-processing failures.
Claims: CLM-TR-c8d9e0f1
Regulator Funding And CapacityRed
No funding or headcount data for KVKK was retrieved this run.
Absence provenance: not recorded. Searched: KVKK budget headcount staffing capacity.
Collective Redress And Class ActionsRed
No Turkey-specific collective-redress or class-action mechanism for data-protection claims was confirmed this run.
Absence provenance: not recorded. Searched: Turkey collective redress class action data protection KVKK.
Private Right Of ActionRed
No specific confirmation of a standalone private right of direct court access (distinct from KVKK complaint channels) was retrieved this run.
Absence provenance: not recorded. Searched: Turkey LPPD private right of action court data protection.
Recent Developments 180DGreen
Within the 180 days preceding this run (roughly February-August 2026), KVKK issued a VERBİS business-partnership clarification (March 2026) and two CCTV/security-camera guidance announcements for workplaces and residential complexes (June 2026).
KVKK has broad investigative and sanctioning powers under Article 18 of the LPPD, with four fine tiers (failure to inform; data-security failures; non-compliance with Board decisions; VERBIS registration failures), annually revalued and reaching over TRY 1.8 million per violation category by the 2020s. Enforcement activity includes real fines for late breach notification (Clickbus, Marriott, Cathay Pacific) and for security-of-processing failures. Recent (within-180-day) developments include KVKK's March 2026 VERBİS partnership clarification and June 2026 CCTV/workplace and residential guidance. Regulator funding/headcount signals, collective-redress mechanisms, and a distinct private right of action were not confirmed with citable primary sources this run.
Sources and claims (4)
ConfirmedIAPP — Article 18 of the LPPD defines four administrative fine categories: failure to fulfil the obligation to inform, failure to fulfil data-security provisions, failure to fulfil Board decisions, and failure to fulfil VERBIS registration/notification obligations, with amounts revalued annually.
ConfirmedIAPP — Failure to register in time with VERBIS may result in an administrative fine of up to TRY 1,802,000, plus a second administrative fine of up to TRY 1,802,000 for non-compliance with KVKK's decisions, and KVKK may restrict the controller's data-processing activities in Turkey.
ConfirmedIAPP — KVKK has fined controllers for late breach notification, including Clickbus Travel Services (TRY 100,000 for notifying two months late), Marriott International (TRY 350,000 for late notification to the DPA and data subjects), and Cathay Pacific Airways (TRY 100,000 for a five-month delay).
ConfirmedDataGuidance — On 31 December 2025, KVKK announced updated administrative fine amounts under Article 18 of the LPPD, reflecting the revaluation rate for 2017-2026.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Turkey
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s), 39 source(s) in the cumulative register.