KVKK (Turkish Personal Data Protection Law No. 6698)
KVKK is Türkiye's Personal Data Protection Law No. 6698, which governs personal data processing, controller duties and data subject rights.
Stands for: Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu)
Personal Data Protection Law No. 6698 (KVKK) was published in the Turkish Official Gazette on 7 April 2016. It treats any information relating to an identified or identifiable natural person as personal data. That covers names and Turkish ID numbers, and also phone numbers, IP addresses, location and device data when they can be linked to a specific person. Enforcement is overseen by the Personal Data Protection Authority and its decision-making body, the Personal Data Protection Board.
Personal data must be processed lawfully and fairly, for specified, explicit and legitimate purposes, and in a manner that is relevant, limited and proportionate. Processing requires explicit consent or one of the other legal grounds listed in the law, such as being expressly provided for by law, the conclusion or performance of a contract, compliance with a legal obligation or legitimate interest. Stricter conditions apply to special categories such as health and biometric data. Data controllers must inform individuals at the time of collection and take the technical and administrative measures needed to keep data secure.
Data subjects have rights such as learning whether their data is processed, requesting correction or erasure, and claiming compensation for damage. Applications must be concluded within 30 days at the latest. Under a Board decision, data breaches are expected to be notified to the Board within 72 hours of discovery. Data controllers meeting certain criteria must register with the Data Controllers' Registry Information System (VERBİS). A 2024 amendment revised the conditions for processing special categories of data and the rules for cross-border transfers, introducing tools such as standard contracts and binding corporate rules.
Systems such as guest Wi-Fi, CRM, omnichannel messaging and log management process large amounts of personal data. For these, organisations should retain privacy notices and consent records, restrict and log access to data, delete or anonymise data whose retention period has expired, and assess whether services hosted abroad comply with transfer rules. Retention duties arising from specific laws such as Law No. 5651 rely, from a KVKK perspective, on the legal-obligation ground for processing.
Often used with
WiPoint
Guest Wi-Fi, Hotspot & Law 5651 Logging
Guest Wi-Fi platform at 15,000+ locations: cloud hotspot, 12 login methods, central management and Law 5651 logs with RFC 3161 timestamps.
Learn moreWiChat
Omnichannel Customer Messaging & AI Assistant
WhatsApp, Instagram, Messenger, Telegram, WebChat and phone in one inbox, with an AI assistant that answers from your CRM records.
Learn moreCetvel
ISP & SME Management: CRM, Pre-Accounting & WiRadius
Cetvel cloud CRM and pre-accounting, with WiRadius ISP subscriber management on top: RADIUS sync, TR-069, BTK reports and a field app.
Learn more
Syslog
Cloud & On-Premises Log Management
Collects logs from any syslog-capable device and stores them in the cloud or on your own server. Search and reports run in a web panel.
Learn moreHave a project in mind?
Tell us briefly what you want to set up, or give us a call. We'll pass it to the right team.