TürkiyeStartups
Guide11 Oct 20262 min read

KVKK for startups: the basics of Turkish data protection

Core obligations for startups under Turkey's data protection law (KVKK): privacy notices, explicit consent, security, VERBIS, cross-border transfers and breach notification.

By Editorial Team

Illustration of a shield with a lock protecting personal data cards

Every startup that takes user sign-ups, keeps an email list or processes customer data is subject to Law No. 6698 on the Protection of Personal Data (KVKK). Compliance is not only a legal duty but also the basis of user and investor trust, and it always comes up in due diligence.

Key concepts

  • Personal data: any information relating to an identified or identifiable person (name, email, phone, IP address, location)
  • Special category data: more strictly protected data such as health, biometrics, religion and political views
  • Data controller: whoever decides why and how data is processed (usually your company)
  • Data processor: a provider processing data on your behalf (cloud, email, accounting software)

Core obligations

1. Duty to inform

When collecting data, tell people what data is processed, for what purpose, on what legal basis, to whom it may be transferred and what their rights are. Prepare a clear privacy notice and make it accessible on sign-up, contact and newsletter forms.

2. Legal basis and explicit consent

Every processing activity needs a legal basis: performance of a contract, legal obligation, legitimate interest and so on. Without one, explicit consent is required. It must be specific, informed and freely given. Do not make use of the service conditional on marketing consent.

3. Commercial messages

Marketing emails and SMS require separate commercial-message consent and compliance with the Message Management System (İYS) rules.

4. Data security

  • Grant access on a need-to-know basis.
  • Store passwords securely and use two-factor authentication.
  • Encrypt data and keep regular backups.
  • Sign confidentiality agreements with staff.
  • Sign data processing agreements with providers.

5. VERBIS registration

Data controllers must register with the Data Controllers' Registry (VERBIS). By Board decision, companies below certain employee-count and annual balance-sheet thresholds whose main activity is not processing special category data may be exempt. Thresholds can change, so check current Board decisions.

6. Cross-border transfers

Using cloud, email or analytics services abroad may mean transferring data. 2024 amendments introduced tools such as adequacy decisions, standard contracts and binding corporate rules; when standard contracts are used, the Board must be notified. List the services you use.

7. Requests and breaches

  • Answer people's requests for information, correction and deletion within the legal deadline.
  • Notify the Board and affected people of a data breach as soon as possible (within 72 hours under the Board's decision).

Startup checklist

  1. Build a data inventory showing what data you hold, why and where.
  2. Publish a privacy notice, consent text and cookie policy.
  3. Collect marketing consent separately from the service agreement.
  4. Sign data processing agreements with providers.
  5. Set deletion and retention periods.
  6. Prepare a breach response plan.

These topics are reviewed in due diligence. See our own privacy notice for how Türkiye Startups applies them.

This guide is general information; work with a lawyer specialised in data protection for your company's compliance.

This guide is for general information only and is not legal, financial or investment advice. Check official sources and consult professionals for current terms.

More guides

All news and guides →