Not publishable as-is. 1 of 5 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Turkey
TRschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 36
claims · 30 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
4Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Latest update · 29 September 2026
Lead Signal
Türkiye's data protection framework saw two developments of note this cycle, running in opposite directions on liberalisation and tightening. Law No. 7499 has replaced the KVKK's previous rigid explicit-consent-based model for cross-border data transfers with a GDPR-aligned architecture built on adequacy decisions, standard contractual clauses and binding corporate rules; explicit consent is now understood to be limited to incidental, non-recurring transfers rather than serving as the default mechanism. At the same time, a draft law amending KVKK Article 18, submitted to the Grand National Assembly on 9 January 2026, proposes direct administrative liability of 5% of prior-year turnover per infringing communication on digital platforms that permit unconsented sharing of AI-generated content depicting an identifiable individual.
Other Developments
KVKK Article 18's administrative fine bands were revalued for 2026 by a 25.49% rate published in Official Gazette No. 33090, pursuant to Tax Procedure Law General Communiqué No. 585. This is understood to be a routine annual inflation-linked adjustment rather than a substantive change to the regulator's enforcement powers or approach.
Cross-Monitor Connections
The proposed AI-generated-content platform-liability amendment sits adjacent to the artificial-intelligence monitor's own tracking of AI-content governance; this brief notes the data-protection-law vehicle for that liability (a KVKK Article 18 amendment) without re-analysing the AI-governance policy question itself, which belongs to that monitor's domain.
Outlook
Watch for whether the draft KVKK Article 18 amendment progresses from a submission before the Grand National Assembly toward enactment, and for the first published guidance or enforcement decisions applying Law No. 7499's adequacy-and-SCC cross-border transfer architecture in practice.
Standing brief · as of 25 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Turkiye's data protection framework saw two material developments this cycle, both centred on the aftermath of the 2024 KVKK amendment. Law No. 7499 amended the KVKK Law to introduce GDPR-aligned legal bases and a revised cross-border data transfer architecture, and this cycle's evidence indicates that architecture is now generating a distinct enforcement pattern: exporters using KVKK-model Standard Contractual Clauses for cross-border transfers must notify the Personal Data Protection Board within five business days of signature, and failure to meet that notification window has become the most common trigger for 2026 enforcement penalties. This is a procedural rather than substantive compliance failure driving enforcement, a meaningful shift from a rigid consent-based model toward a GDPR-style mechanism-based model. The KVKK Board itself, established under the KVKK Law in force since 2016, remains Turkiye's sole independent supervisory authority for data protection, issuing decisions, guidelines and administrative fines; Law No. 7499's 2024 amendment did not change this institutional structure but did materially change the substantive and procedural rules the Board now enforces, particularly around cross-border transfer.
Other Developments
Fine bands increased for 2026. The Personal Data Protection Board's administrative fine bands increased by 25.49% over 2025 figures, effective 1 January 2026, with maximum fines of approximately TRY17,092,242 applicable to data-security, VERBIS-registration and Board-decision non-compliance violations. This is a high-confidence, in-force development following the annual statutory revaluation published in Official Gazette No. 33090 (27 November 2025). The scale of the increase — over a quarter uplift year-on-year — indicates the Board is treating annual fine-band revaluation as a substantive deterrence lever rather than a purely inflation-tracking exercise.
Cross-Monitor Connections
Turkiye's payments and payment-infrastructure sector this cycle is separately the subject of a large-scale illegal-betting money-laundering enforcement wave tracked by the Financial Integrity Monitor and the World Payments Monitor; whether the Personal Data Protection Board has issued any enforcement decision specifically addressing the data-handling practices of the payment institutions implicated in that wave remains unresolved in this cycle's evidence and is not asserted here. Advennt's Gambling Regulatory Monitor separately covers the underlying illegal-gambling enforcement dimension of the same wave.
Outlook
The notification-timing enforcement pattern identified this cycle is likely to remain the dominant compliance-risk driver for cross-border data transfers out of Turkiye in the near term; organisations relying on KVKK-model SCCs should treat the five-business-day notification window as the single highest-priority procedural compliance point. The increased 2026 fine bands raise the financial stakes of any compliance failure, procedural or substantive, across the modules this cycle's evidence covers. Whether the notification-timing enforcement pattern evolves into a broader crackdown on substantive transfer-basis failures is the key open question for cross-border-transfer risk assessment going forward, and this cycle's evidence does not resolve it either way. Seven of the ten Data Protection Monitor modules were not populated this cycle given the pooled research budget; this is a coverage gap rather than an indication of regulatory stability in those areas, and should not be read as such.
trust tier: ai_unverified
Latest update · 29 September 2026
Regulatory Status
Türkiye's data-protection framework this cycle shows liberalisation on cross-border transfer mechanics alongside a proposed tightening on AI-generated-content platform liability. Law No. 7499 replaced the KVKK's rigid explicit-consent-based cross-border transfer model with a GDPR-aligned architecture using adequacy decisions, SCCs and BCRs, limiting explicit consent to incidental transfers. Separately, a draft law amending KVKK Article 18, submitted to the Grand National Assembly on 9 January 2026, proposes 5%-of-turnover administrative liability per infringing communication on platforms permitting unconsented sharing of AI-generated content depicting an individual; this remains at the proposed stage. KVKK Article 18's administrative fine bands were also revalued 25.49% for 2026, a routine inflation-linked adjustment.
Outlook
Watch for the draft AI-content-liability amendment's progress through the Grand National Assembly, and for the first practical applications of the Law No. 7499 adequacy-and-SCC transfer architecture.
Standing brief · as of 25 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Regulatory Status
Turkiye's data protection regime is administered by the Personal Data Protection Board (KVKK Kurumu) under the KVKK Law, in force since 2016. This cycle's material developments centre on the 2024 amendment, Law No. 7499, which introduced GDPR-aligned legal bases and a revised cross-border transfer architecture built around KVKK-model Standard Contractual Clauses; exporters must notify the Board within five business days of signing such clauses, and missing that window has become the most common trigger for 2026 enforcement penalties under the cross-border regime. Separately, the Board's administrative fine bands increased by 25.49% over 2025 figures effective 1 January 2026, with maximum fines now reported at approximately TRY17,092,242.
Seven of the ten modules in the standard Data Protection Monitor spine were not populated with qualifying material this cycle given a pooled research budget; this reflects a coverage gap in the current evidence base rather than an assessment that those modules are stable or inactive, and should be read accordingly.
Outlook
The five-business-day SCC notification window is currently the single highest-priority procedural compliance point for organisations transferring data out of Turkiye. The increased 2026 fine bands raise the financial stakes of any compliance failure across the modules covered this cycle. Whether KVKK enforcement activity intersects with the broader illegal-betting-related payments-sector enforcement wave affecting Turkiye this cycle remains an open question not resolved by current evidence.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Traffic-light rationale — GreenComprehensive statute in force with an operational, actively enforcing regulator (KVKK) and a functioning registration system (VERBIS).
Sub-modules (5)
Regulator And AuthorityGreen
KVKK is Turkey's dedicated personal-data-protection authority and Board, issuing binding decisions, guidance, and administrative fines.
Claims (1):
The Personal Data Protection Authority (KVKK) is Turkey's supervisory authority for the Law on the Protection of Personal Data No. 6698.
Act And InstrumentsGreen
LPPD (Law 6698, 2016) is the primary instrument; Law 7499 (2024) amended Articles 6, 9 and 18.
Claims (2):
The Law on Protection of Personal Data No. 6698 (LPPD) was published in the Official Gazette on 7 April 2016 and entered into force as Turkey's first general data protection law.
Law No. 7499, amending the Code of Criminal Procedure and Certain Laws, introduced amendments to Articles 6, 9 and 18 of the LPPD, with the first segment published in the Official Gazette on 12 March 2024 and effective 1 June 2024.
Material ScopeGreen
Scope mirrors GDPR's automated-processing/filing-system test and shares comparable definitions of 'processing' and 'personal data'.
Claims (1):
The LPPD and GDPR provide comparable definitions of 'processing', 'personal data' and 'sensitive data', and both apply to automated or filing-system-based processing.
Territorial ScopeAmber
The LPPD is textually silent on extraterritorial scope but VERBIS registration is applied to foreign controllers processing data collected from Turkey.
Claims (1):
VERBIS registration requirements extend extraterritorially to foreign (non-Turkey-established) data controllers that collect or process personal data originating in Turkey.
Regulator Registration And FilingGreen
VERBIS registration is mandatory for qualifying controllers (Turkish controllers with ≥50 employees or ≥TRY 25m turnover, and foreign controllers), and KVKK continues to issue clarifying announcements (e.g., on partnership structures in March 2026).
Claims (2):
Turkish data controllers with 50 or more employees, or annual turnover of TRY 25,000,000 or more, must register with VERBIS; failure to register can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.
In a March 2026 public announcement, KVKK clarified that partners in business partnerships, consortiums and ordinary partnerships must incorporate partnership-related personal data processing into their own individual VERBİS registrations rather than creating separate registrations.
Key findings (3)
KVKK-enforced LPPD (2016, amended 2024 by Law 7499) with VERBIS registration; March 2026 partnership clarification; VERBIS thresholds/fines corrected via challenger fold to Board Decision 2023/1154 and 2026-revalued figures. — source on file
KVKK-enforced LPPD (2016, amended 2024 by Law 7499) with VERBIS registration; March 2026 partnership clarification; VERBIS thresholds/fines corrected via challenger fold to Board Decision 2023/1154 and 2026-revalued figures. — source on file
KVKK-enforced LPPD (2016, amended 2024 by Law 7499) with VERBIS registration; March 2026 partnership clarification; VERBIS thresholds/fines corrected via challenger fold to Board Decision 2023/1154 and 2026-revalued figures. — source on file
Category narrative100 words
Turkey operates a comprehensive omnibus regime under Law No. 6698 on the Protection of Personal Data (LPPD/KVKK Law), enforced by the Personal Data Protection Authority (KVKK/Kurul). The law was modelled on the pre-GDPR EU Data Protection Directive 95/46/EC and has been progressively amended (most recently by Law No. 7499 in 2024) to narrow the gap with the GDPR, particularly on special-category processing and cross-border transfers. Material and territorial scope closely track the GDPR's automated/filing-system test, and the LPPD has a recognised (if textually silent) extraterritorial reach implemented administratively through the VERBIS data-controller registry, which also functions as Turkey's registration/filing mechanism.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (7)
UncertainDataGuidance — The Personal Data Protection Authority (KVKK) is Turkey's supervisory authority for the Law on the Protection of Personal Data No. 6698.observed
UncertainDataGuidance / Esin Attorney Partnership — The Law on Protection of Personal Data No. 6698 (LPPD) was published in the Official Gazette on 7 April 2016 and entered into force as Turkey's first general data protection law.observed
UncertainIAPP — Law No. 7499, amending the Code of Criminal Procedure and Certain Laws, introduced amendments to Articles 6, 9 and 18 of the LPPD, with the first segment published in the Official Gazette on 12 March 2024 and effective 1 June 2024.observed
UncertainDataGuidance / Esin Attorney Partnership — The LPPD and GDPR provide comparable definitions of 'processing', 'personal data' and 'sensitive data', and both apply to automated or filing-system-based processing.observed
UncertainIAPP — VERBIS registration requirements extend extraterritorially to foreign (non-Turkey-established) data controllers that collect or process personal data originating in Turkey.observed
UncertainIAPP — Turkish data controllers with 50 or more employees, or annual turnover of TRY 25,000,000 or more, must register with VERBIS; failure to register can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.observed
UncertainDataGuidance — In a March 2026 public announcement, KVKK clarified that partners in business partnerships, consortiums and ordinary partnerships must incorporate partnership-related personal data processing into their own individual VERBİS registrations rather than creating separate registrations.observed
Core lawful-basis and special-category architecture is codified and enforced, but consent-thresholds guidance is comparatively thin relative to GDPR-level granularity, and some 2024 amendment detail was not independently verified this run.
Primary frameworkLaw No. 6698 (LPPD), Articles 5-6, as amended by Law No. 7499 (2024)
Traffic-light rationale — Not assessedCore lawful-basis and special-category architecture is codified and enforced, but consent-thresholds guidance is comparatively thin relative to GDPR-level granularity, and some 2024 amendment detail was not independently verified this run.
Sub-modules (4)
Lawful BasesAmber
Article 5 LPPD sets out the legal grounds for processing (paralleling GDPR Art 6), referenced also as the general-ground gateway for cross-border transfer analysis.
Claims (1):
Personal data may be transferred and otherwise processed on legal grounds set out under Article 5 of the LPPD, which operates as the general lawful-basis gateway analogous to GDPR Article 6.
Consent ThresholdsAmber
Explicit consent has historically been the dominant, most reliable practical basis in the absence of a KVKK safe-country list, particularly for transfers; granular consent-quality standards (freely given/informed/revocable) were not independently re-confirmed with primary-text citations this run.
Absence provenance: unavailable. Searched: KVKK consent standard freely given informed revocable Article 3 definitions.
Claims (1):
In the absence of a KVKK-issued safe-country list, obtaining the data subject's explicit consent has been, in practice, the only readily viable method to legalize cross-border personal data transfers under the pre-2024 regime.
Special CategoriesGreen
Article 6 LPPD enumerates special categories of personal data and was amended by Law 7499 in 2024.
Claims (2):
Article 6 of the LPPD regulates special categories of personal data, covering race, ethnicity, political opinion, philosophical belief, religion, sect or other belief, association/foundation/trade-union membership, health and sexual life, among other attributes.
Law No. 7499 (2024) amended Article 6 of the LPPD concerning the processing of special categories of personal data, effective 1 June 2024.
Pseudonymisation And AnonymisationGreen
A dedicated KVKK Regulation governs deletion, destruction and anonymisation, requiring retention/destruction policies and time periods.
Claims (1):
KVKK's Regulation on the deletion, destruction and anonymisation of personal data requires data controllers to prepare retention and destruction policies with applicable time periods, and to delete, destroy or anonymise data once the processing purpose ceases to exist.
Key findings (3)
Article 5 lawful bases and Article 6 special categories (amended 2024); pre-2024 transfer-consent framing corrected to reflect two available routes. — source on file
Article 5 lawful bases and Article 6 special categories (amended 2024); pre-2024 transfer-consent framing corrected to reflect two available routes. — source on file
Article 5 lawful bases and Article 6 special categories (amended 2024); pre-2024 transfer-consent framing corrected to reflect two available routes. — source on file
Category narrative93 words
The LPPD's Article 5 sets out lawful-processing grounds broadly analogous to GDPR Art 6, while Article 6 enumerates special/sensitive categories (race, ethnicity, political opinion, philosophical belief, religion/sect, association/union membership, health, sexual life, and related attributes), amended by Law 7499 (2024). Explicit consent remains central in practice given persistent gaps in secondary guidance on alternative grounds. A dedicated Regulation on the Deletion, Destruction and Anonymisation of Personal Data obliges controllers to destroy, delete or anonymise data once the processing purpose lapses, and KVKK biometric-data guidance (2021) further conditions special-category biometric processing on necessity/proportionality principles.
Sources and claims (5)
UncertainIAPP — Personal data may be transferred and otherwise processed on legal grounds set out under Article 5 of the LPPD, which operates as the general lawful-basis gateway analogous to GDPR Article 6.observed
UncertainIAPP — Article 6 of the LPPD regulates special categories of personal data, covering race, ethnicity, political opinion, philosophical belief, religion, sect or other belief, association/foundation/trade-union membership, health and sexual life, among other attributes.observed
UncertainIAPP — Law No. 7499 (2024) amended Article 6 of the LPPD concerning the processing of special categories of personal data, effective 1 June 2024.observed
UncertainDataGuidance — KVKK's Regulation on the deletion, destruction and anonymisation of personal data requires data controllers to prepare retention and destruction policies with applicable time periods, and to delete, destroy or anonymise data once the processing purpose ceases to exist.observed
UncertainIAPP — In the absence of a KVKK-issued safe-country list, obtaining the data subject's explicit consent has been, in practice, the only readily viable method to legalize cross-border personal data transfers under the pre-2024 regime.observed
Access-right and erasure-adjacent mechanisms are confirmed and codified, but restriction/objection, portability, and precise response-deadline provisions could not be independently verified with primary citations this run.
Traffic-light rationale — AmberAccess-right and erasure-adjacent mechanisms are confirmed and codified, but restriction/objection, portability, and precise response-deadline provisions could not be independently verified with primary citations this run.
Sub-modules (5)
Access RightGreen
Article 11 LPPD grants data subjects rights including access to their processed data; KVKK issued a 2018 Regulation consolidating subject-access-request (SAR) procedures.
Claims (1):
KVKK published a supplementary Regulation on 10 March 2018 consolidating the procedure to be followed by data subjects and controllers with respect to subject access requests under Article 11 of the LPPD.
Rectification And ErasureAmber
Erasure/destruction obligations are anchored in the Deletion, Destruction and Anonymisation Regulation, which requires controllers to delete or anonymise data once the processing purpose lapses.
Claims (1):
Data controllers must delete, destroy or anonymise personal data once the legal reasons for its processing cease to exist, per KVKK's regulation on deletion, destruction and anonymisation.
Restriction And ObjectionRed
No primary-source detail on a distinct restriction-of-processing or objection-to-profiling mechanism was retrieved this run.
No confirmed evidence of a GDPR Article 20-style portability right was retrieved this run.
Absence provenance: unavailable. Searched: Turkey LPPD data portability right Article 20 equivalent.
Deadlines And Response WindowsAmber
Retrieved sources confirm a subject-access-request procedural regulation exists, but the precise statutory response-window (day-count) was not confirmed via primary-text excerpt this run.
Article 11 access right consolidated by 2018 SAR Regulation; erasure via Deletion/Destruction/Anonymisation Regulation; portability, restriction/objection and response-window specifics unconfirmed. — source on file
Article 11 access right consolidated by 2018 SAR Regulation; erasure via Deletion/Destruction/Anonymisation Regulation; portability, restriction/objection and response-window specifics unconfirmed. — source on file
Article 11 access right consolidated by 2018 SAR Regulation; erasure via Deletion/Destruction/Anonymisation Regulation; portability, restriction/objection and response-window specifics unconfirmed. — source on file
Category narrative64 words
Article 11 of the LPPD provides an access-right framework comparable to GDPR subject-access rights, consolidated procedurally by a 2018 KVKK Regulation. Erasure is operationalised primarily through the Deletion/Destruction/Anonymisation Regulation rather than a standalone Article-17-style 'right to be forgotten' clause. Direct primary-source confirmation of exact statutory response-window day-counts, and of restriction/objection and portability mechanics, was not obtained this run and is flagged as a gap.
Sources and claims (2)
UncertainDataGuidance — KVKK published a supplementary Regulation on 10 March 2018 consolidating the procedure to be followed by data subjects and controllers with respect to subject access requests under Article 11 of the LPPD.observed
UncertainDataGuidance — Data controllers must delete, destroy or anonymise personal data once the legal reasons for its processing cease to exist, per KVKK's regulation on deletion, destruction and anonymisation.observed
Security and breach-notification duties are well-evidenced and actively enforced; DPIA and formal DPO-independence requirements are absent relative to GDPR, which is a structural gap rather than a mere evidentiary one.
Traffic-light rationale — AmberSecurity and breach-notification duties are well-evidenced and actively enforced; DPIA and formal DPO-independence requirements are absent relative to GDPR, which is a structural gap rather than a mere evidentiary one.
Sub-modules (7)
Accountability And DpiaRed
The LPPD contains no express DPIA obligation or equivalent risk-evaluation requirement, unlike GDPR Article 35.
Claims (1):
Unlike the GDPR, the LPPD does not include any requirement to undertake a Data Protection Impact Assessment or any similar formal obligation to evaluate the risk of personal data processing.
Dpo RequirementsAmber
DPO appointment is not mandatory; KVKK's 2021 Communiqué established a voluntary personnel-certification mechanism rather than a binding appointment threshold.
Claims (1):
KVKK introduced the concept of a data protection officer via the Communiqué on the Procedures and Principles Regarding the Personnel Certification Mechanism (6 December 2021); however, appointment of a DPO is not a mandatory requirement under the LPPD.
Ropa RequirementsAmber
VERBIS, maintained by KVKK, serves as the functional equivalent of a records-of-processing registry, though it is structurally different from controller-held GDPR Article 30 records.
Claims (1):
VERBIS is principally kept and maintained by KVKK and is fundamentally different from GDPR Article 30 records kept directly by controllers, though it requires controllers to submit a data-processing inventory.
Joint Controller ArrangementsGreen
Controllers processing via processors remain jointly responsible with data processors, and processors are barred from using data for purposes beyond the original processing purpose.
Claims (1):
Where personal data is processed by a natural or legal person on behalf of a data controller, the controller is jointly responsible with data processors, who are in turn prohibited from disclosing or using data obtained from the controller for purposes other than the original processing purpose.
Security MeasuresGreen
Article 18(b) imposes the highest fine tier for security-of-processing failures, and KVKK has issued technical/administrative measures guidance; enforcement precedent (e.g., against tourism, banking, and e-commerce controllers) confirms active application.
Claims (1):
Article 18 of the LPPD imposes fines for failure to fulfil data-security provisions (historically ranging roughly TRY 15,000 to TRY 1,000,000, revalued annually), and this security-violation category has produced the highest observed fines in KVKK enforcement practice.
Breach NotificationGreen
KVKK Board principle-decision interprets the Article 12(5) breach-notification deadline as 72 hours, requiring standard forms, incident logs and a breach response plan; multiple controllers have been fined for late notification.
Claims (1):
KVKK's Board issued a principle decision interpreting the Article 12(5) breach-notification deadline as 72 hours, requiring controllers to report delay reasons, use a standard breach notification form, log breach information, and prepare a data breach response plan.
Retention And DisposalGreen
Retention limits and disposal duties are set by the Deletion, Destruction and Anonymisation Regulation.
Claims (1):
KVKK's Regulation on deletion, destruction and anonymisation requires data controllers to prepare data retention and destruction policies specifying applicable time periods.
Key findings (3)
72-hour breach-notification Board interpretation and Article 18 security fines are strong; no DPIA requirement exists; DPO appointment remains voluntary. — source on file
72-hour breach-notification Board interpretation and Article 18 security fines are strong; no DPIA requirement exists; DPO appointment remains voluntary. — source on file
72-hour breach-notification Board interpretation and Article 18 security fines are strong; no DPIA requirement exists; DPO appointment remains voluntary. — source on file
Category narrative86 words
The LPPD imposes accountability-adjacent duties (VERBIS registration/inventory, security-of-processing obligations, breach notification) but -- unlike the GDPR -- contains no express DPIA requirement, and DPO appointment remains voluntary notwithstanding a 2021 KVKK Communiqué establishing a personnel-certification mechanism. Breach notification is interpreted by Board principle-decision as a 72-hour standard, reinforced by real enforcement precedent (Clickbus, Marriott, Cathay Pacific fines for late notification). Security-of-processing failures attract the highest fine tier under Article 18(b). VERBIS functions as Turkey's de facto records-of-processing (ROPA) mechanism, though structurally distinct from GDPR Article 30.
Sources and claims (7)
UncertainDataGuidance — Unlike the GDPR, the LPPD does not include any requirement to undertake a Data Protection Impact Assessment or any similar formal obligation to evaluate the risk of personal data processing.observed
UncertainDataGuidance — KVKK introduced the concept of a data protection officer via the Communiqué on the Procedures and Principles Regarding the Personnel Certification Mechanism (6 December 2021); however, appointment of a DPO is not a mandatory requirement under the LPPD.observed
UncertainDataGuidance / Esin Attorney Partnership — VERBIS is principally kept and maintained by KVKK and is fundamentally different from GDPR Article 30 records kept directly by controllers, though it requires controllers to submit a data-processing inventory.observed
UncertainDataGuidance / Esin Attorney Partnership — Where personal data is processed by a natural or legal person on behalf of a data controller, the controller is jointly responsible with data processors, who are in turn prohibited from disclosing or using data obtained from the controller for purposes other than the original processing purpose.observed
UncertainIAPP — Article 18 of the LPPD imposes fines for failure to fulfil data-security provisions (historically ranging roughly TRY 15,000 to TRY 1,000,000, revalued annually), and this security-violation category has produced the highest observed fines in KVKK enforcement practice.observed
UncertainIAPP — KVKK's Board issued a principle decision interpreting the Article 12(5) breach-notification deadline as 72 hours, requiring controllers to report delay reasons, use a standard breach notification form, log breach information, and prepare a data breach response plan.observed
UncertainDataGuidance — KVKK's Regulation on deletion, destruction and anonymisation requires data controllers to prepare data retention and destruction policies specifying applicable time periods.observed
A GDPR-aligned SCC/BCR framework is now codified and operative (2024), representing significant convergence, but no safe-country/adequacy list has been published and no reciprocal adequacy status with the EU/UK was confirmed.
Primary frameworkLPPD Article 9, as amended by Law No. 7499 (2024); By-Law on Procedures and Principles for the Transfer of Personal Data Abroad (July 2024)
Traffic-light rationale — AmberA GDPR-aligned SCC/BCR framework is now codified and operative (2024), representing significant convergence, but no safe-country/adequacy list has been published and no reciprocal adequacy status with the EU/UK was confirmed.
Sub-modules (6)
Transfer MechanismsAmber
Pre-2024, transfer mechanisms were limited to explicit consent, an undertaking-plus-KVKK-permit route, or approved BCRs; the 2024 reform added a standardized-undertaking notification route and formalized SCCs/BCRs.
Claims (2):
Under the pre-2024 regime, in the absence of a KVKK adequacy decision, data could be transferred abroad via notification to KVKK with a standard undertaking, submission of a written agreement with protective measures and obtaining a permit, approval of BCRs, or agreement between compatible public entities.
The By-Law on the Procedures and Principles for the Transfer of Personal Data Abroad, implementing amended Article 9 of the LPPD, was published and entered into force in July 2024, alongside KVKK's publication of Turkish standard contract and BCR documents.
Adequacy ReceivedRed
No confirmation was found this run that Turkey has received an adequacy decision from the EU or UK; this is treated as an open gap requiring EDPB/EU-Commission primary-source confirmation.
Absence provenance: unavailable. Searched: Turkey EU adequacy decision GDPR, Turkey UK adequacy decision.
Adequacy GrantedRed
KVKK has not issued a 'safe country' or adequacy list of its own, meaning the adequacy-based transfer ground under Article 9 remains practically unavailable.
Claims (1):
As KVKK has not issued a safe-country list, the adequacy-based transfer ground under Article 9 of the LPPD has not been practically available.
Sccs And BcrsGreen
Turkish SCCs (bilateral) and BCRs now require KVKK notification/approval, with wet-ink or secure e-signature execution and further KVKK guidance expected on SCC validity.
Claims (1):
Turkish Standard Contractual Clauses are bilateral, require careful data-flow analysis and KVKK notification, and must be executed with wet-ink or secure e-signatures; BCRs also require KVKK approval.
Transfer Impact AssessmentRed
No TIA-equivalent requirement was identified in the sources reviewed this run.
No general/absolute data-localisation mandate was identified; VERBIS imposes registration/administrative obligations rather than a data-residency requirement.
Absence provenance: unavailable. Searched: Turkey data localisation requirement KVKK sector-specific.
Key findings (3)
July 2024 By-Law operationalises Turkish SCCs and BCRs; no EU/UK adequacy decision or KVKK safe-country list confirmed. — source on file
July 2024 By-Law operationalises Turkish SCCs and BCRs; no EU/UK adequacy decision or KVKK safe-country list confirmed. — source on file
July 2024 By-Law operationalises Turkish SCCs and BCRs; no EU/UK adequacy decision or KVKK safe-country list confirmed. — source on file
Category narrative111 words
Turkey substantially overhauled its cross-border transfer regime via the March 2024 Law 7499 amendments to LPPD Article 9 and the implementing By-Law on Procedures and Principles for the Transfer of Personal Data Abroad (entered into force July 2024). The reform introduced Turkish Standard Contractual Clauses (bilateral, requiring KVKK notification and wet-ink/secure e-signature) and Binding Corporate Rules requiring KVKK approval, moving away from the pre-2024 regime under which -- absent any KVKK-issued adequacy/safe-country list -- explicit consent or an undertaking-plus-permit process were the only practical transfer routes. KVKK has not issued an EU-style adequacy decision covering Turkey, nor is Turkey confirmed to have received an adequacy decision from the EU or UK.
Periodic update · new data 2026-09-29
Cross-Border & Adequacy
Law No. 7499 is understood to have replaced the KVKK's previously rigid, explicit-consent-based model for cross-border personal-data transfers with a GDPR-aligned architecture. Under this modernised structure, transfers may proceed on the basis of adequacy decisions, standard contractual clauses or binding corporate rules, with explicit data-subject consent now limited to incidental, non-recurring transfers rather than functioning as the default legal basis it previously was. This represents a material liberalisation of the transfer mechanism available to controllers moving personal data out of Turkey, bringing the regime structurally closer to the EU's own adequacy-and-safeguards model rather than relying on a consent-heavy approach that had been criticised as impractical for routine international data flows. The practical operation of the new adequacy and SCC mechanisms, including which jurisdictions may in due course receive an adequacy determination from Turkish authorities, has not yet been evidenced this cycle; this remains an open question for future monitoring.
Outlook
Watch for the first adequacy determinations or officially published standard contractual clause templates issued under the Law No. 7499 architecture, and for any KVKK guidance clarifying the boundary between incidental transfers still permitted on a consent basis and recurring transfers now requiring an adequacy or SCC/BCR mechanism.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (4)
UncertainIAPP — Under the pre-2024 regime, in the absence of a KVKK adequacy decision, data could be transferred abroad via notification to KVKK with a standard undertaking, submission of a written agreement with protective measures and obtaining a permit, approval of BCRs, or agreement between compatible public entities.observed
UncertainDataGuidance — The By-Law on the Procedures and Principles for the Transfer of Personal Data Abroad, implementing amended Article 9 of the LPPD, was published and entered into force in July 2024, alongside KVKK's publication of Turkish standard contract and BCR documents.observed
UncertainIAPP — As KVKK has not issued a safe-country list, the adequacy-based transfer ground under Article 9 of the LPPD has not been practically available.observed
UncertainDataGuidance — Turkish Standard Contractual Clauses are bilateral, require careful data-flow analysis and KVKK notification, and must be executed with wet-ink or secure e-signatures; BCRs also require KVKK approval.observed
Only the employment_data sub-module has direct, substantive evidentiary support this run; the remaining six sub-modules lack confirmed sector-specific overlay findings.
Traffic-light rationale — RedOnly the employment_data sub-module has direct, substantive evidentiary support this run; the remaining six sub-modules lack confirmed sector-specific overlay findings.
Sub-modules (7)
Financial Sector OverlayRed
No financial-sector-specific DP overlay (e.g., Banking Law secrecy provisions vs. LPPD) was substantively retrieved this run.
Absence provenance: unavailable. Searched: Turkey Banking Law data protection KVKK financial sector overlay.
Health Sector OverlayRed
No health-sector-specific overlay statute content was retrieved this run.
Absence provenance: unavailable. Searched: Turkey health data law KVKK Ministry of Health overlay.
Telecoms And EprivacyRed
No substantive content on Electronic Communications Law No. 5809 or an ePrivacy-style overlay was retrieved this run.
Absence provenance: unavailable. Searched: Turkey electronic communications law 5809 KVKK direct marketing cookies ePrivacy.
Employment DataAmber
KVKK issued a public announcement (June 2026) on considerations for CCTV/security-camera use in workplaces, requiring employers to establish a legal basis under Article 5 and comply with core LPPD principles.
Claims (1):
KVKK's June 2026 announcement on workplace security cameras requires employers to ensure that data processing via CCTV has a legal basis under Article 5 of the LPPD and adheres to fundamental processing principles.
Credit And ScoringRed
No credit-scoring-specific overlay content was retrieved this run.
No education-sector-specific overlay content was retrieved this run.
Absence provenance: unavailable. Searched: Turkey education sector personal data KVKK overlay.
InsuranceRed
No insurance-sector-specific overlay content was retrieved this run.
Absence provenance: unavailable. Searched: Turkey insurance sector personal data KVKK overlay.
Key findings (3)
Only employment_data (workplace CCTV, June 2026) substantively evidenced; banking, health, telecoms, credit, education and insurance overlays unresearched. — source on file
Only employment_data (workplace CCTV, June 2026) substantively evidenced; banking, health, telecoms, credit, education and insurance overlays unresearched. — source on file
Only employment_data (workplace CCTV, June 2026) substantively evidenced; banking, health, telecoms, credit, education and insurance overlays unresearched. — source on file
Category narrative57 words
Direct sector-specific overlay statutes (banking secrecy, health-sector regulation, telecoms/ePrivacy, credit scoring, education, insurance) were not substantively retrieved this run beyond general LPPD application and one workplace-specific KVKK guidance document on CCTV/surveillance in employment settings. This module is materially thin and requires dedicated follow-up research into Turkey's Banking Law, Electronic Communications Law No. 5809, and health-data-specific secondary legislation.
Sources and claims (1)
UncertainDataGuidance — KVKK's June 2026 announcement on workplace security cameras requires employers to ensure that data processing via CCTV has a legal basis under Article 5 of the LPPD and adheres to fundamental processing principles.observed
No sub-module in this module reached a substantive, citable evidentiary threshold this run; all six sub-modules carry explicit absent_field_provenance.
Traffic-light rationale — Not assessedNo sub-module in this module reached a substantive, citable evidentiary threshold this run; all six sub-modules carry explicit absent_field_provenance.
Sub-modules (6)
Cookies And TrackersRed
KVKK has published draft/guidance material on cookies, but substantive content was not retrieved this run beyond titles.
No Turkey-specific dark-pattern prohibition content was located.
Absence provenance: unavailable. Searched: Turkey KVKK dark patterns prohibition.
Opt Out SignalsRed
No GPC/DAA-equivalent opt-out-signal recognition was located for Turkey.
Absence provenance: unavailable. Searched: Turkey Global Privacy Control opt-out signal recognition.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room-specific KVKK rule was located.
Absence provenance: unavailable. Searched: Turkey KVKK data clean room data collaboration room.
Cross Context AdvertisingRed
No CPRA-style 'sale'/'share' analogue was located for Turkey.
Absence provenance: unavailable. Searched: Turkey cross-context advertising personal data sale share equivalent.
Direct MarketingRed
Turkey separately regulates commercial electronic messages and KVKK has issued at least one no-violation finding on SMS marketing, but substantive detail was not retrieved this run.
No substantive citable findings; cookie guidance and commercial e-messaging regulation located at title level only. — source on file
No substantive citable findings; cookie guidance and commercial e-messaging regulation located at title level only. — source on file
No substantive citable findings; cookie guidance and commercial e-messaging regulation located at title level only. — source on file
Category narrative62 words
KVKK has issued cookie-related guidance and Turkey separately regulates commercial electronic messaging, but this run only retrieved title-level references (draft cookie guidelines, Commercial Electronic Message Management Regulation, an SMS-marketing no-violation finding) without substantive body content sufficient for citable claims. Dark patterns, opt-out signals (GPC/DAA), clean-room/data-collaboration rules, and cross-context advertising concepts akin to CPRA's 'sale'/'share' were not located in Turkish-specific sources this run.
Biometric-data guidance is well-evidenced; AI-specific and ADM-transparency findings rest on title-level sources only and are marked Uncertain pending primary-text confirmation.
Traffic-light rationale — AmberBiometric-data guidance is well-evidenced; AI-specific and ADM-transparency findings rest on title-level sources only and are marked Uncertain pending primary-text confirmation.
Sub-modules (6)
Profiling RestrictionsRed
No Turkey-specific Article 22-equivalent profiling restriction was confirmed this run.
A parliamentary AI bill and a KVKK generative-AI guide were reported to exist (late 2025), but detail was not retrieved beyond titles.
Absence provenance: unavailable. Searched: Turkey AI bill parliamentary committee KVKK generative AI guide content.
Claims (1):
A parliamentary bill to regulate artificial intelligence in Turkey was reported as introduced around November 2025, alongside a KVKK guide addressing generative AI and personal data protection.
Biometric RegimeGreen
KVKK's September 2021 guidance defines biometric data and sets processing principles under Articles 4 and 6 of the LPPD.
Claims (1):
KVKK published guidance on 16 September 2021 on the considerations for processing biometric data, defining biometric data and requiring that processing methods be suitable for and proportionate to the purpose, that data be retained only as long as necessary, and that data subjects be informed in accordance with Article 10.
Genetic DataRed
No genetic-data-specific regime distinct from the general 'health' special category was confirmed this run.
Absence provenance: unavailable. Searched: Turkey KVKK genetic data specific regime.
State Surveillance CarveoutsAmber
The LPPD excludes processing of personal data for public-security or law-enforcement purposes from its general application, functioning as a national-security carve-out comparable to GDPR Art 2(2)/23 exemptions.
Claims (1):
Both the GDPR and the LPPD provide similar exclusions from their application, including for processing of personal data in the context of public security or law enforcement.
Key findings (3)
2021 biometric guidance confirmed; November 2025 AI bill and generative-AI guide remain title-level only; public-security/law-enforcement carve-out confirmed. — source on file
2021 biometric guidance confirmed; November 2025 AI bill and generative-AI guide remain title-level only; public-security/law-enforcement carve-out confirmed. — source on file
2021 biometric guidance confirmed; November 2025 AI bill and generative-AI guide remain title-level only; public-security/law-enforcement carve-out confirmed. — source on file
Category narrative87 words
KVKK issued dedicated guidance on biometric data processing (September 2021), grounding biometric processing in Articles 4 and 6 principles (necessity, proportionality, minimal retention, transparency). A parliamentary bill to regulate artificial intelligence was reportedly introduced (November 2025) and KVKK reportedly published a guide on generative AI and personal data protection (November 2025), though substantive text of both was not retrieved this run. The LPPD generally excludes processing for public-security/law-enforcement purposes from its scope, functioning as a national-security carve-out. No Turkey-specific ADM-transparency (Article 22-equivalent) or genetic-data-specific regime was confirmed.
no periodic updates on record for this sub-brief
Sources and claims (3)
UncertainDataGuidance — KVKK published guidance on 16 September 2021 on the considerations for processing biometric data, defining biometric data and requiring that processing methods be suitable for and proportionate to the purpose, that data be retained only as long as necessary, and that data subjects be informed in accordance with Article 10.observed
UncertainDataGuidance / Esin Attorney Partnership — Both the GDPR and the LPPD provide similar exclusions from their application, including for processing of personal data in the context of public security or law enforcement.observed
UncertainDataGuidance — A parliamentary bill to regulate artificial intelligence in Turkey was reported as introduced around November 2025, alongside a KVKK guide addressing generative AI and personal data protection.observed
This is a confirmed statutory gap: the LPPD contains no children-specific consent, age-verification, or profiling-ban regime, and no dependent-adult-specific regime was found.
Primary frameworkLaw No. 6698 (LPPD) -- no children-specific provisions
Traffic-light rationale — RedThis is a confirmed statutory gap: the LPPD contains no children-specific consent, age-verification, or profiling-ban regime, and no dependent-adult-specific regime was found.
Sub-modules (5)
Age VerificationRed
The LPPD does not set an age limit for consent or for the notification requirement.
Claims (1):
The LPPD does not set an age limit for consent, and there is no age limit set for the notification requirement.
Parental ConsentRed
The LPPD does not specify whether parental or guardian consent is required for processing children's data or for providing information-society services to a child.
Claims (1):
Unlike the GDPR, the LPPD does not grant special protection to children's personal data, nor does it specify whether the consent of a parent or guardian is needed when processing children's data or providing information-society services to a child.
Minor Profiling BansRed
No minor-specific profiling ban was identified; KVKK's only children-data output located is a non-binding 2020 brochure.
Claims (1):
KVKK's only substantive output addressing children's data is a 23 April 2020 brochure bearing similarities with GDPR protective measures, rather than a binding profiling ban.
Education SettingsRed
No education-setting-specific children's-data rule was identified this run.
Absence provenance: unavailable. Searched: Turkey KVKK children data education setting specific rule.
Dependent AdultsRed
No dependent-adult (elderly/incapacitated)-specific protection was identified this run.
Confirmed structural gap: no age-verification, parental-consent, or minor-profiling-ban regime; only a non-binding 2020 brochure exists. — source on file
Confirmed structural gap: no age-verification, parental-consent, or minor-profiling-ban regime; only a non-binding 2020 brochure exists. — source on file
Confirmed structural gap: no age-verification, parental-consent, or minor-profiling-ban regime; only a non-binding 2020 brochure exists. — source on file
Category narrative66 words
Unlike the GDPR (Article 8), the LPPD does not grant special statutory protection to children's personal data, does not set an age of consent, and does not specify whether parental/guardian consent is required for information-society services directed at minors. KVKK has issued only soft, non-binding awareness material (a 2020 brochure on children's data) rather than binding age-verification, parental-consent, or minor-profiling-ban provisions. Dependent-adult-specific protections were not identified.
Sources and claims (3)
UncertainDataGuidance — The LPPD does not set an age limit for consent, and there is no age limit set for the notification requirement.observed
UncertainDataGuidance — Unlike the GDPR, the LPPD does not grant special protection to children's personal data, nor does it specify whether the consent of a parent or guardian is needed when processing children's data or providing information-society services to a child.observed
UncertainDataGuidance — KVKK's only substantive output addressing children's data is a 23 April 2020 brochure bearing similarities with GDPR protective measures, rather than a binding profiling ban.observed
Traffic-light rationale — AmberPowers, penalty tiers, and enforcement-activity evidence are strong; funding/capacity, collective-redress, and private-right-of-action sub-modules remain evidentiary gaps.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Article 18 sets four fine tiers, revalued annually; VERBIS non-registration alone can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.
Claims (2):
Article 18 of the LPPD defines four administrative fine categories: failure to fulfil the obligation to inform, failure to fulfil data-security provisions, failure to fulfil Board decisions, and failure to fulfil VERBIS registration/notification obligations, with amounts revalued annually.
Failure to register in time with VERBIS may result in an administrative fine of up to TRY 1,802,000, plus a second administrative fine of up to TRY 1,802,000 for non-compliance with KVKK's decisions, and KVKK may restrict the controller's data-processing activities in Turkey.
Enforcement Activity IndexGreen
KVKK has fined multiple international controllers for late breach notification and security-of-processing failures.
Claims (1):
KVKK has fined controllers for late breach notification, including Clickbus Travel Services (TRY 100,000 for notifying two months late), Marriott International (TRY 350,000 for late notification to the DPA and data subjects), and Cathay Pacific Airways (TRY 100,000 for a five-month delay).
Regulator Funding And CapacityRed
No funding or headcount data for KVKK was retrieved this run.
No Turkey-specific collective-redress or class-action mechanism for data-protection claims was confirmed this run.
Absence provenance: unavailable. Searched: Turkey collective redress class action data protection KVKK.
Private Right Of ActionRed
No specific confirmation of a standalone private right of direct court access (distinct from KVKK complaint channels) was retrieved this run.
Absence provenance: unavailable. Searched: Turkey LPPD private right of action court data protection.
Recent Developments 180DGreen
Within the 180 days preceding this run (roughly February-August 2026), KVKK issued a VERBİS business-partnership clarification (March 2026) and two CCTV/security-camera guidance announcements for workplaces and residential complexes (June 2026).
Claims (3):
In a March 2026 public announcement, KVKK clarified that partners in business partnerships, consortiums and ordinary partnerships must incorporate partnership-related personal data processing into their own individual VERBİS registrations rather than creating separate registrations.
KVKK's June 2026 announcement on workplace security cameras requires employers to ensure that data processing via CCTV has a legal basis under Article 5 of the LPPD and adheres to fundamental processing principles.
On 31 December 2025, KVKK announced updated administrative fine amounts under Article 18 of the LPPD, reflecting the revaluation rate for 2017-2026.
Key findings (3)
Four-tier Article 18 fine architecture and active enforcement (Clickbus, Marriott, Cathay Pacific); VERBIS fine ceiling corrected via challenger fold; funding, collective redress and private right of action unconfirmed. — source on file
Four-tier Article 18 fine architecture and active enforcement (Clickbus, Marriott, Cathay Pacific); VERBIS fine ceiling corrected via challenger fold; funding, collective redress and private right of action unconfirmed. — source on file
Four-tier Article 18 fine architecture and active enforcement (Clickbus, Marriott, Cathay Pacific); VERBIS fine ceiling corrected via challenger fold; funding, collective redress and private right of action unconfirmed. — source on file
Category narrative98 words
KVKK has broad investigative and sanctioning powers under Article 18 of the LPPD, with four fine tiers (failure to inform; data-security failures; non-compliance with Board decisions; VERBIS registration failures), annually revalued and reaching over TRY 1.8 million per violation category by the 2020s. Enforcement activity includes real fines for late breach notification (Clickbus, Marriott, Cathay Pacific) and for security-of-processing failures. Recent (within-180-day) developments include KVKK's March 2026 VERBİS partnership clarification and June 2026 CCTV/workplace and residential guidance. Regulator funding/headcount signals, collective-redress mechanisms, and a distinct private right of action were not confirmed with citable primary sources this run.
Periodic update · new data 2026-09-29
Enforcement & Redress
KVKK Article 18's administrative fine bands were revalued for 2026, applying a 25.49% uplift published in Official Gazette No. 33090 pursuant to Tax Procedure Law General Communiqué No. 585. This is understood to be a routine, inflation-indexed annual adjustment to the existing fine-band structure rather than a substantive expansion of the regulator's enforcement powers, investigative authority, or the categories of conduct subject to administrative fines. The adjustment took effect from 1 January 2026. Considered alongside the proposed KVKK Article 18 amendment on AI-generated-content platform liability, the enforcement and redress landscape in Turkey shows two distinct tracks moving at different speeds: the existing fine-band structure is being maintained and adjusted for inflation on its normal annual cycle, while a separate and more consequential proposed liability mechanism specific to AI-generated content remains at the draft stage before the legislature.
Outlook
Watch for the KVKK's enforcement activity and decision publications through the remainder of 2026 to assess whether the revalued fine bands are being applied in practice, and for how the proposed AI-generated-content liability provision, if enacted, would integrate with or sit alongside the existing Article 18 fine structure.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (4)
UncertainIAPP — Article 18 of the LPPD defines four administrative fine categories: failure to fulfil the obligation to inform, failure to fulfil data-security provisions, failure to fulfil Board decisions, and failure to fulfil VERBIS registration/notification obligations, with amounts revalued annually.observed
UncertainIAPP — Failure to register in time with VERBIS may result in an administrative fine of up to TRY 1,802,000, plus a second administrative fine of up to TRY 1,802,000 for non-compliance with KVKK's decisions, and KVKK may restrict the controller's data-processing activities in Turkey.observed
UncertainIAPP — KVKK has fined controllers for late breach notification, including Clickbus Travel Services (TRY 100,000 for notifying two months late), Marriott International (TRY 350,000 for late notification to the DPA and data subjects), and Cathay Pacific Airways (TRY 100,000 for a five-month delay).observed
UncertainDataGuidance — On 31 December 2025, KVKK announced updated administrative fine amounts under Article 18 of the LPPD, reflecting the revaluation rate for 2017-2026.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 1 failing check(s).
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
4.35
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Turkey
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s) (36 category placement(s)), 30 source(s) in the cumulative register.
Strong (T1/T2-grounded) coverage was achieved for regulator_and_framework, the special_categories/pseudonymisation sub-modules of lawful_processing_and_special_data, controller_processor_duties (security_measures, breach_notification, retention_and_disposal, dpo_requirements), cross_border_and_adequacy (transfer_mechanisms, sccs_and_bcrs), the biometric_regime sub-module of algorithmic_biometric_and_surveillance_governance, and enforcement_and_redress (regulator_powers_and_penalties, enforcement_activity_index, recent_developments_180d). Coverage relied on T3 analytical/opinion sources for consent_thresholds, adequacy_received/granted framing, and fines-methodology context. sectoral_watch and adtech_and_commercial_privacy are materially thin this run, resting mostly on absent_field_provenance across sub-modules due to searches not being extended into Turkish banking, health, telecoms/ePrivacy, and commercial-electronic-messaging primary legislation. data_subject_rights (restriction_and_objection, data_portability, deadlines_and_response_windows) and children_and_vulnerable_groups (education_settings, dependent_adults) likewise rely on absent_field_provenance rather than confirmed findings.
Unresolved questions (7):
What is the LPPD's exact statutory response-window (day-count) for data-subject requests under Article 13, verified against primary Official Gazette text?
Does the LPPD (as amended) provide any GDPR Article 20-style data portability right, and if so under what conditions?
Has the EU or UK issued (or is either considering) an adequacy decision covering Turkey, and conversely has KVKK published any 'safe country' list post-2024 reform?
What sector-specific overlays apply under Turkey's Banking Law, Electronic Communications Law No. 5809, and health-data secondary legislation relative to the LPPD?
What is the substantive content and legal status (draft vs. enacted) of the AI bill reported as introduced to the Turkish Grand National Assembly in November 2025?
Does Turkish law provide any collective-redress/class-action mechanism or standalone private right of action distinct from KVKK's administrative complaint channel?
What are KVKK's current funding, staffing and institutional-capacity signals?