# KVKK (Turkish Personal Data Protection Law No. 6698)

*Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu)* · Regulation

> KVKK is Türkiye's Personal Data Protection Law No. 6698, which governs personal data processing, controller duties and data subject rights.

Personal Data Protection Law No. 6698 (KVKK) was published in the Turkish Official Gazette on 7 April 2016. It treats any information relating to an identified or identifiable natural person as personal data. That covers names and Turkish ID numbers, and also phone numbers, IP addresses, location and device data when they can be linked to a specific person. Enforcement is overseen by the Personal Data Protection Authority and its decision-making body, the Personal Data Protection Board.

Personal data must be processed lawfully and fairly, for specified, explicit and legitimate purposes, and in a manner that is relevant, limited and proportionate. Processing requires explicit consent or one of the other legal grounds listed in the law, such as being expressly provided for by law, the conclusion or performance of a contract, compliance with a legal obligation or legitimate interest. Stricter conditions apply to special categories such as health and biometric data. Data controllers must inform individuals at the time of collection and take the technical and administrative measures needed to keep data secure.

Data subjects have rights such as learning whether their data is processed, requesting correction or erasure, and claiming compensation for damage. Applications must be concluded within 30 days at the latest. Under a Board decision, data breaches are expected to be notified to the Board within 72 hours of discovery. Data controllers meeting certain criteria must register with the Data Controllers' Registry Information System (VERBİS). A 2024 amendment revised the conditions for processing special categories of data and the rules for cross-border transfers, introducing tools such as standard contracts and binding corporate rules.

Systems such as guest Wi-Fi, CRM, omnichannel messaging and log management process large amounts of personal data. For these, organisations should retain privacy notices and consent records, restrict and log access to data, delete or anonymise data whose retention period has expired, and assess whether services hosted abroad comply with transfer rules. Retention duties arising from specific laws such as Law No. 5651 rely, from a KVKK perspective, on the legal-obligation ground for processing.

---
Canonical: https://internetten.com.tr/en/glossary/kvkk
