🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
TR v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing16 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Turkey

TR schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 36 claims · 30 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
4Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 29 September 2026

Lead Signal

Türkiye's data protection framework saw two developments of note this cycle, running in opposite directions on liberalisation and tightening. Law No. 7499 has replaced the KVKK's previous rigid explicit-consent-based model for cross-border data transfers with a GDPR-aligned architecture built on adequacy decisions, standard contractual clauses and binding corporate rules; explicit consent is now understood to be limited to incidental, non-recurring transfers rather than serving as the default mechanism. At the same time, a draft law amending KVKK Article 18, submitted to the Grand National Assembly on 9 January 2026, proposes direct administrative liability of 5% of prior-year turnover per infringing communication on digital platforms that permit unconsented sharing of AI-generated content depicting an identifiable individual.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute in force with an operational, actively enforcing regulator (KVKK) and a functioning registration system (VERBIS).

Primary frameworkLaw No. 6698 on the Protection of Personal Data (LPPD), as amended by Law No. 7499 (2024)
Traffic-light rationale — GreenComprehensive statute in force with an operational, actively enforcing regulator (KVKK) and a functioning registration system (VERBIS).

Sub-modules (5)

Regulator And AuthorityGreen

KVKK is Turkey's dedicated personal-data-protection authority and Board, issuing binding decisions, guidance, and administrative fines.

Claims (1):

  • The Personal Data Protection Authority (KVKK) is Turkey's supervisory authority for the Law on the Protection of Personal Data No. 6698.

Act And InstrumentsGreen

LPPD (Law 6698, 2016) is the primary instrument; Law 7499 (2024) amended Articles 6, 9 and 18.

Claims (2):

  • The Law on Protection of Personal Data No. 6698 (LPPD) was published in the Official Gazette on 7 April 2016 and entered into force as Turkey's first general data protection law.
  • Law No. 7499, amending the Code of Criminal Procedure and Certain Laws, introduced amendments to Articles 6, 9 and 18 of the LPPD, with the first segment published in the Official Gazette on 12 March 2024 and effective 1 June 2024.

Material ScopeGreen

Scope mirrors GDPR's automated-processing/filing-system test and shares comparable definitions of 'processing' and 'personal data'.

Claims (1):

  • The LPPD and GDPR provide comparable definitions of 'processing', 'personal data' and 'sensitive data', and both apply to automated or filing-system-based processing.

Territorial ScopeAmber

The LPPD is textually silent on extraterritorial scope but VERBIS registration is applied to foreign controllers processing data collected from Turkey.

Claims (1):

  • VERBIS registration requirements extend extraterritorially to foreign (non-Turkey-established) data controllers that collect or process personal data originating in Turkey.

Regulator Registration And FilingGreen

VERBIS registration is mandatory for qualifying controllers (Turkish controllers with ≥50 employees or ≥TRY 25m turnover, and foreign controllers), and KVKK continues to issue clarifying announcements (e.g., on partnership structures in March 2026).

Claims (2):

  • Turkish data controllers with 50 or more employees, or annual turnover of TRY 25,000,000 or more, must register with VERBIS; failure to register can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.
  • In a March 2026 public announcement, KVKK clarified that partners in business partnerships, consortiums and ordinary partnerships must incorporate partnership-related personal data processing into their own individual VERBİS registrations rather than creating separate registrations.

Key findings (3)

  • KVKK-enforced LPPD (2016, amended 2024 by Law 7499) with VERBIS registration; March 2026 partnership clarification; VERBIS thresholds/fines corrected via challenger fold to Board Decision 2023/1154 and 2026-revalued figures. — source on file
  • KVKK-enforced LPPD (2016, amended 2024 by Law 7499) with VERBIS registration; March 2026 partnership clarification; VERBIS thresholds/fines corrected via challenger fold to Board Decision 2023/1154 and 2026-revalued figures. — source on file
  • KVKK-enforced LPPD (2016, amended 2024 by Law 7499) with VERBIS registration; March 2026 partnership clarification; VERBIS thresholds/fines corrected via challenger fold to Board Decision 2023/1154 and 2026-revalued figures. — source on file
Category narrative100 words

Turkey operates a comprehensive omnibus regime under Law No. 6698 on the Protection of Personal Data (LPPD/KVKK Law), enforced by the Personal Data Protection Authority (KVKK/Kurul). The law was modelled on the pre-GDPR EU Data Protection Directive 95/46/EC and has been progressively amended (most recently by Law No. 7499 in 2024) to narrow the gap with the GDPR, particularly on special-category processing and cross-border transfers. Material and territorial scope closely track the GDPR's automated/filing-system test, and the LPPD has a recognised (if textually silent) extraterritorial reach implemented administratively through the VERBIS data-controller registry, which also functions as Turkey's registration/filing mechanism.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. UncertainDataGuidance — The Personal Data Protection Authority (KVKK) is Turkey's supervisory authority for the Law on the Protection of Personal Data No. 6698.observed
  2. UncertainDataGuidance / Esin Attorney Partnership — The Law on Protection of Personal Data No. 6698 (LPPD) was published in the Official Gazette on 7 April 2016 and entered into force as Turkey's first general data protection law.observed
  3. UncertainIAPP — Law No. 7499, amending the Code of Criminal Procedure and Certain Laws, introduced amendments to Articles 6, 9 and 18 of the LPPD, with the first segment published in the Official Gazette on 12 March 2024 and effective 1 June 2024.observed
  4. UncertainDataGuidance / Esin Attorney Partnership — The LPPD and GDPR provide comparable definitions of 'processing', 'personal data' and 'sensitive data', and both apply to automated or filing-system-based processing.observed
  5. UncertainIAPP — VERBIS registration requirements extend extraterritorially to foreign (non-Turkey-established) data controllers that collect or process personal data originating in Turkey.observed
  6. UncertainIAPP — Turkish data controllers with 50 or more employees, or annual turnover of TRY 25,000,000 or more, must register with VERBIS; failure to register can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.observed
  7. UncertainDataGuidance — In a March 2026 public announcement, KVKK clarified that partners in business partnerships, consortiums and ordinary partnerships must incorporate partnership-related personal data processing into their own individual VERBİS registrations rather than creating separate registrations.observed

#

Core lawful-basis and special-category architecture is codified and enforced, but consent-thresholds guidance is comparatively thin relative to GDPR-level granularity, and some 2024 amendment detail was not independently verified this run.

Primary frameworkLaw No. 6698 (LPPD), Articles 5-6, as amended by Law No. 7499 (2024)
Supervisory authorityKVKK
Traffic-light rationale — Not assessedCore lawful-basis and special-category architecture is codified and enforced, but consent-thresholds guidance is comparatively thin relative to GDPR-level granularity, and some 2024 amendment detail was not independently verified this run.

Sub-modules (4)

Lawful BasesAmber

Article 5 LPPD sets out the legal grounds for processing (paralleling GDPR Art 6), referenced also as the general-ground gateway for cross-border transfer analysis.

Claims (1):

  • Personal data may be transferred and otherwise processed on legal grounds set out under Article 5 of the LPPD, which operates as the general lawful-basis gateway analogous to GDPR Article 6.

Special CategoriesGreen

Article 6 LPPD enumerates special categories of personal data and was amended by Law 7499 in 2024.

Claims (2):

  • Article 6 of the LPPD regulates special categories of personal data, covering race, ethnicity, political opinion, philosophical belief, religion, sect or other belief, association/foundation/trade-union membership, health and sexual life, among other attributes.
  • Law No. 7499 (2024) amended Article 6 of the LPPD concerning the processing of special categories of personal data, effective 1 June 2024.

Pseudonymisation And AnonymisationGreen

A dedicated KVKK Regulation governs deletion, destruction and anonymisation, requiring retention/destruction policies and time periods.

Claims (1):

  • KVKK's Regulation on the deletion, destruction and anonymisation of personal data requires data controllers to prepare retention and destruction policies with applicable time periods, and to delete, destroy or anonymise data once the processing purpose ceases to exist.

Key findings (3)

  • Article 5 lawful bases and Article 6 special categories (amended 2024); pre-2024 transfer-consent framing corrected to reflect two available routes. — source on file
  • Article 5 lawful bases and Article 6 special categories (amended 2024); pre-2024 transfer-consent framing corrected to reflect two available routes. — source on file
  • Article 5 lawful bases and Article 6 special categories (amended 2024); pre-2024 transfer-consent framing corrected to reflect two available routes. — source on file
Category narrative93 words

The LPPD's Article 5 sets out lawful-processing grounds broadly analogous to GDPR Art 6, while Article 6 enumerates special/sensitive categories (race, ethnicity, political opinion, philosophical belief, religion/sect, association/union membership, health, sexual life, and related attributes), amended by Law 7499 (2024). Explicit consent remains central in practice given persistent gaps in secondary guidance on alternative grounds. A dedicated Regulation on the Deletion, Destruction and Anonymisation of Personal Data obliges controllers to destroy, delete or anonymise data once the processing purpose lapses, and KVKK biometric-data guidance (2021) further conditions special-category biometric processing on necessity/proportionality principles.

Sources and claims (5)
  1. UncertainIAPP — Personal data may be transferred and otherwise processed on legal grounds set out under Article 5 of the LPPD, which operates as the general lawful-basis gateway analogous to GDPR Article 6.observed
  2. UncertainIAPP — Article 6 of the LPPD regulates special categories of personal data, covering race, ethnicity, political opinion, philosophical belief, religion, sect or other belief, association/foundation/trade-union membership, health and sexual life, among other attributes.observed
  3. UncertainIAPP — Law No. 7499 (2024) amended Article 6 of the LPPD concerning the processing of special categories of personal data, effective 1 June 2024.observed
  4. UncertainDataGuidance — KVKK's Regulation on the deletion, destruction and anonymisation of personal data requires data controllers to prepare retention and destruction policies with applicable time periods, and to delete, destroy or anonymise data once the processing purpose ceases to exist.observed
  5. UncertainIAPP — In the absence of a KVKK-issued safe-country list, obtaining the data subject's explicit consent has been, in practice, the only readily viable method to legalize cross-border personal data transfers under the pre-2024 regime.observed

#

Access-right and erasure-adjacent mechanisms are confirmed and codified, but restriction/objection, portability, and precise response-deadline provisions could not be independently verified with primary citations this run.

Primary frameworkLaw No. 6698 (LPPD), Article 11
Supervisory authorityKVKK
Traffic-light rationale — AmberAccess-right and erasure-adjacent mechanisms are confirmed and codified, but restriction/objection, portability, and precise response-deadline provisions could not be independently verified with primary citations this run.

Sub-modules (5)

Access RightGreen

Article 11 LPPD grants data subjects rights including access to their processed data; KVKK issued a 2018 Regulation consolidating subject-access-request (SAR) procedures.

Claims (1):

  • KVKK published a supplementary Regulation on 10 March 2018 consolidating the procedure to be followed by data subjects and controllers with respect to subject access requests under Article 11 of the LPPD.

Rectification And ErasureAmber

Erasure/destruction obligations are anchored in the Deletion, Destruction and Anonymisation Regulation, which requires controllers to delete or anonymise data once the processing purpose lapses.

Claims (1):

  • Data controllers must delete, destroy or anonymise personal data once the legal reasons for its processing cease to exist, per KVKK's regulation on deletion, destruction and anonymisation.

Restriction And ObjectionRed

No primary-source detail on a distinct restriction-of-processing or objection-to-profiling mechanism was retrieved this run.

Absence provenance: unavailable. Searched: Turkey LPPD Article 7 restriction processing objection profiling right.

Data PortabilityRed

No confirmed evidence of a GDPR Article 20-style portability right was retrieved this run.

Absence provenance: unavailable. Searched: Turkey LPPD data portability right Article 20 equivalent.

Deadlines And Response WindowsAmber

Retrieved sources confirm a subject-access-request procedural regulation exists, but the precise statutory response-window (day-count) was not confirmed via primary-text excerpt this run.

Absence provenance: unavailable. Searched: Article 13 LPPD 30 days response deadline KVKK.

Key findings (3)

  • Article 11 access right consolidated by 2018 SAR Regulation; erasure via Deletion/Destruction/Anonymisation Regulation; portability, restriction/objection and response-window specifics unconfirmed. — source on file
  • Article 11 access right consolidated by 2018 SAR Regulation; erasure via Deletion/Destruction/Anonymisation Regulation; portability, restriction/objection and response-window specifics unconfirmed. — source on file
  • Article 11 access right consolidated by 2018 SAR Regulation; erasure via Deletion/Destruction/Anonymisation Regulation; portability, restriction/objection and response-window specifics unconfirmed. — source on file
Category narrative64 words

Article 11 of the LPPD provides an access-right framework comparable to GDPR subject-access rights, consolidated procedurally by a 2018 KVKK Regulation. Erasure is operationalised primarily through the Deletion/Destruction/Anonymisation Regulation rather than a standalone Article-17-style 'right to be forgotten' clause. Direct primary-source confirmation of exact statutory response-window day-counts, and of restriction/objection and portability mechanics, was not obtained this run and is flagged as a gap.

Sources and claims (2)
  1. UncertainDataGuidance — KVKK published a supplementary Regulation on 10 March 2018 consolidating the procedure to be followed by data subjects and controllers with respect to subject access requests under Article 11 of the LPPD.observed
  2. UncertainDataGuidance — Data controllers must delete, destroy or anonymise personal data once the legal reasons for its processing cease to exist, per KVKK's regulation on deletion, destruction and anonymisation.observed

#

Security and breach-notification duties are well-evidenced and actively enforced; DPIA and formal DPO-independence requirements are absent relative to GDPR, which is a structural gap rather than a mere evidentiary one.

Primary frameworkLaw No. 6698 (LPPD), Articles 12, 16, 18; KVKK secondary regulations/communiqués
Supervisory authorityKVKK
Traffic-light rationale — AmberSecurity and breach-notification duties are well-evidenced and actively enforced; DPIA and formal DPO-independence requirements are absent relative to GDPR, which is a structural gap rather than a mere evidentiary one.

Sub-modules (7)

Accountability And DpiaRed

The LPPD contains no express DPIA obligation or equivalent risk-evaluation requirement, unlike GDPR Article 35.

Claims (1):

  • Unlike the GDPR, the LPPD does not include any requirement to undertake a Data Protection Impact Assessment or any similar formal obligation to evaluate the risk of personal data processing.

Dpo RequirementsAmber

DPO appointment is not mandatory; KVKK's 2021 Communiqué established a voluntary personnel-certification mechanism rather than a binding appointment threshold.

Claims (1):

  • KVKK introduced the concept of a data protection officer via the Communiqué on the Procedures and Principles Regarding the Personnel Certification Mechanism (6 December 2021); however, appointment of a DPO is not a mandatory requirement under the LPPD.

Ropa RequirementsAmber

VERBIS, maintained by KVKK, serves as the functional equivalent of a records-of-processing registry, though it is structurally different from controller-held GDPR Article 30 records.

Claims (1):

  • VERBIS is principally kept and maintained by KVKK and is fundamentally different from GDPR Article 30 records kept directly by controllers, though it requires controllers to submit a data-processing inventory.

Joint Controller ArrangementsGreen

Controllers processing via processors remain jointly responsible with data processors, and processors are barred from using data for purposes beyond the original processing purpose.

Claims (1):

  • Where personal data is processed by a natural or legal person on behalf of a data controller, the controller is jointly responsible with data processors, who are in turn prohibited from disclosing or using data obtained from the controller for purposes other than the original processing purpose.

Security MeasuresGreen

Article 18(b) imposes the highest fine tier for security-of-processing failures, and KVKK has issued technical/administrative measures guidance; enforcement precedent (e.g., against tourism, banking, and e-commerce controllers) confirms active application.

Claims (1):

  • Article 18 of the LPPD imposes fines for failure to fulfil data-security provisions (historically ranging roughly TRY 15,000 to TRY 1,000,000, revalued annually), and this security-violation category has produced the highest observed fines in KVKK enforcement practice.

Breach NotificationGreen

KVKK Board principle-decision interprets the Article 12(5) breach-notification deadline as 72 hours, requiring standard forms, incident logs and a breach response plan; multiple controllers have been fined for late notification.

Claims (1):

  • KVKK's Board issued a principle decision interpreting the Article 12(5) breach-notification deadline as 72 hours, requiring controllers to report delay reasons, use a standard breach notification form, log breach information, and prepare a data breach response plan.

Retention And DisposalGreen

Retention limits and disposal duties are set by the Deletion, Destruction and Anonymisation Regulation.

Claims (1):

  • KVKK's Regulation on deletion, destruction and anonymisation requires data controllers to prepare data retention and destruction policies specifying applicable time periods.

Key findings (3)

  • 72-hour breach-notification Board interpretation and Article 18 security fines are strong; no DPIA requirement exists; DPO appointment remains voluntary. — source on file
  • 72-hour breach-notification Board interpretation and Article 18 security fines are strong; no DPIA requirement exists; DPO appointment remains voluntary. — source on file
  • 72-hour breach-notification Board interpretation and Article 18 security fines are strong; no DPIA requirement exists; DPO appointment remains voluntary. — source on file
Category narrative86 words

The LPPD imposes accountability-adjacent duties (VERBIS registration/inventory, security-of-processing obligations, breach notification) but -- unlike the GDPR -- contains no express DPIA requirement, and DPO appointment remains voluntary notwithstanding a 2021 KVKK Communiqué establishing a personnel-certification mechanism. Breach notification is interpreted by Board principle-decision as a 72-hour standard, reinforced by real enforcement precedent (Clickbus, Marriott, Cathay Pacific fines for late notification). Security-of-processing failures attract the highest fine tier under Article 18(b). VERBIS functions as Turkey's de facto records-of-processing (ROPA) mechanism, though structurally distinct from GDPR Article 30.

Sources and claims (7)
  1. UncertainDataGuidance — Unlike the GDPR, the LPPD does not include any requirement to undertake a Data Protection Impact Assessment or any similar formal obligation to evaluate the risk of personal data processing.observed
  2. UncertainDataGuidance — KVKK introduced the concept of a data protection officer via the Communiqué on the Procedures and Principles Regarding the Personnel Certification Mechanism (6 December 2021); however, appointment of a DPO is not a mandatory requirement under the LPPD.observed
  3. UncertainDataGuidance / Esin Attorney Partnership — VERBIS is principally kept and maintained by KVKK and is fundamentally different from GDPR Article 30 records kept directly by controllers, though it requires controllers to submit a data-processing inventory.observed
  4. UncertainDataGuidance / Esin Attorney Partnership — Where personal data is processed by a natural or legal person on behalf of a data controller, the controller is jointly responsible with data processors, who are in turn prohibited from disclosing or using data obtained from the controller for purposes other than the original processing purpose.observed
  5. UncertainIAPP — Article 18 of the LPPD imposes fines for failure to fulfil data-security provisions (historically ranging roughly TRY 15,000 to TRY 1,000,000, revalued annually), and this security-violation category has produced the highest observed fines in KVKK enforcement practice.observed
  6. UncertainIAPP — KVKK's Board issued a principle decision interpreting the Article 12(5) breach-notification deadline as 72 hours, requiring controllers to report delay reasons, use a standard breach notification form, log breach information, and prepare a data breach response plan.observed
  7. UncertainDataGuidance — KVKK's Regulation on deletion, destruction and anonymisation requires data controllers to prepare data retention and destruction policies specifying applicable time periods.observed

#

A GDPR-aligned SCC/BCR framework is now codified and operative (2024), representing significant convergence, but no safe-country/adequacy list has been published and no reciprocal adequacy status with the EU/UK was confirmed.

Primary frameworkLPPD Article 9, as amended by Law No. 7499 (2024); By-Law on Procedures and Principles for the Transfer of Personal Data Abroad (July 2024)
Supervisory authorityKVKK
Traffic-light rationale — AmberA GDPR-aligned SCC/BCR framework is now codified and operative (2024), representing significant convergence, but no safe-country/adequacy list has been published and no reciprocal adequacy status with the EU/UK was confirmed.

Sub-modules (6)

Transfer MechanismsAmber

Pre-2024, transfer mechanisms were limited to explicit consent, an undertaking-plus-KVKK-permit route, or approved BCRs; the 2024 reform added a standardized-undertaking notification route and formalized SCCs/BCRs.

Claims (2):

  • Under the pre-2024 regime, in the absence of a KVKK adequacy decision, data could be transferred abroad via notification to KVKK with a standard undertaking, submission of a written agreement with protective measures and obtaining a permit, approval of BCRs, or agreement between compatible public entities.
  • The By-Law on the Procedures and Principles for the Transfer of Personal Data Abroad, implementing amended Article 9 of the LPPD, was published and entered into force in July 2024, alongside KVKK's publication of Turkish standard contract and BCR documents.

Adequacy ReceivedRed

No confirmation was found this run that Turkey has received an adequacy decision from the EU or UK; this is treated as an open gap requiring EDPB/EU-Commission primary-source confirmation.

Absence provenance: unavailable. Searched: Turkey EU adequacy decision GDPR, Turkey UK adequacy decision.

Adequacy GrantedRed

KVKK has not issued a 'safe country' or adequacy list of its own, meaning the adequacy-based transfer ground under Article 9 remains practically unavailable.

Claims (1):

  • As KVKK has not issued a safe-country list, the adequacy-based transfer ground under Article 9 of the LPPD has not been practically available.

Sccs And BcrsGreen

Turkish SCCs (bilateral) and BCRs now require KVKK notification/approval, with wet-ink or secure e-signature execution and further KVKK guidance expected on SCC validity.

Claims (1):

  • Turkish Standard Contractual Clauses are bilateral, require careful data-flow analysis and KVKK notification, and must be executed with wet-ink or secure e-signatures; BCRs also require KVKK approval.

Transfer Impact AssessmentRed

No TIA-equivalent requirement was identified in the sources reviewed this run.

Absence provenance: unavailable. Searched: KVKK transfer impact assessment requirement By-Law 2024.

Data LocalisationAmber

No general/absolute data-localisation mandate was identified; VERBIS imposes registration/administrative obligations rather than a data-residency requirement.

Absence provenance: unavailable. Searched: Turkey data localisation requirement KVKK sector-specific.

Key findings (3)

  • July 2024 By-Law operationalises Turkish SCCs and BCRs; no EU/UK adequacy decision or KVKK safe-country list confirmed. — source on file
  • July 2024 By-Law operationalises Turkish SCCs and BCRs; no EU/UK adequacy decision or KVKK safe-country list confirmed. — source on file
  • July 2024 By-Law operationalises Turkish SCCs and BCRs; no EU/UK adequacy decision or KVKK safe-country list confirmed. — source on file
Category narrative111 words

Turkey substantially overhauled its cross-border transfer regime via the March 2024 Law 7499 amendments to LPPD Article 9 and the implementing By-Law on Procedures and Principles for the Transfer of Personal Data Abroad (entered into force July 2024). The reform introduced Turkish Standard Contractual Clauses (bilateral, requiring KVKK notification and wet-ink/secure e-signature) and Binding Corporate Rules requiring KVKK approval, moving away from the pre-2024 regime under which -- absent any KVKK-issued adequacy/safe-country list -- explicit consent or an undertaking-plus-permit process were the only practical transfer routes. KVKK has not issued an EU-style adequacy decision covering Turkey, nor is Turkey confirmed to have received an adequacy decision from the EU or UK.

Periodic update · new data 2026-09-29

Cross-Border & Adequacy

Law No. 7499 is understood to have replaced the KVKK's previously rigid, explicit-consent-based model for cross-border personal-data transfers with a GDPR-aligned architecture. Under this modernised structure, transfers may proceed on the basis of adequacy decisions, standard contractual clauses or binding corporate rules, with explicit data-subject consent now limited to incidental, non-recurring transfers rather than functioning as the default legal basis it previously was. This represents a material liberalisation of the transfer mechanism available to controllers moving personal data out of Turkey, bringing the regime structurally closer to the EU's own adequacy-and-safeguards model rather than relying on a consent-heavy approach that had been criticised as impractical for routine international data flows. The practical operation of the new adequacy and SCC mechanisms, including which jurisdictions may in due course receive an adequacy determination from Turkish authorities, has not yet been evidenced this cycle; this remains an open question for future monitoring.

Outlook

Watch for the first adequacy determinations or officially published standard contractual clause templates issued under the Law No. 7499 architecture, and for any KVKK guidance clarifying the boundary between incidental transfers still permitted on a consent basis and recurring transfers now requiring an adequacy or SCC/BCR mechanism.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. UncertainIAPP — Under the pre-2024 regime, in the absence of a KVKK adequacy decision, data could be transferred abroad via notification to KVKK with a standard undertaking, submission of a written agreement with protective measures and obtaining a permit, approval of BCRs, or agreement between compatible public entities.observed
  2. UncertainDataGuidance — The By-Law on the Procedures and Principles for the Transfer of Personal Data Abroad, implementing amended Article 9 of the LPPD, was published and entered into force in July 2024, alongside KVKK's publication of Turkish standard contract and BCR documents.observed
  3. UncertainIAPP — As KVKK has not issued a safe-country list, the adequacy-based transfer ground under Article 9 of the LPPD has not been practically available.observed
  4. UncertainDataGuidance — Turkish Standard Contractual Clauses are bilateral, require careful data-flow analysis and KVKK notification, and must be executed with wet-ink or secure e-signatures; BCRs also require KVKK approval.observed

#

Only the employment_data sub-module has direct, substantive evidentiary support this run; the remaining six sub-modules lack confirmed sector-specific overlay findings.

Supervisory authorityKVKK
Traffic-light rationale — RedOnly the employment_data sub-module has direct, substantive evidentiary support this run; the remaining six sub-modules lack confirmed sector-specific overlay findings.

Sub-modules (7)

Financial Sector OverlayRed

No financial-sector-specific DP overlay (e.g., Banking Law secrecy provisions vs. LPPD) was substantively retrieved this run.

Absence provenance: unavailable. Searched: Turkey Banking Law data protection KVKK financial sector overlay.

Health Sector OverlayRed

No health-sector-specific overlay statute content was retrieved this run.

Absence provenance: unavailable. Searched: Turkey health data law KVKK Ministry of Health overlay.

Telecoms And EprivacyRed

No substantive content on Electronic Communications Law No. 5809 or an ePrivacy-style overlay was retrieved this run.

Absence provenance: unavailable. Searched: Turkey electronic communications law 5809 KVKK direct marketing cookies ePrivacy.

Employment DataAmber

KVKK issued a public announcement (June 2026) on considerations for CCTV/security-camera use in workplaces, requiring employers to establish a legal basis under Article 5 and comply with core LPPD principles.

Claims (1):

  • KVKK's June 2026 announcement on workplace security cameras requires employers to ensure that data processing via CCTV has a legal basis under Article 5 of the LPPD and adheres to fundamental processing principles.

Credit And ScoringRed

No credit-scoring-specific overlay content was retrieved this run.

Absence provenance: unavailable. Searched: Turkey credit scoring KKB data protection overlay.

EducationRed

No education-sector-specific overlay content was retrieved this run.

Absence provenance: unavailable. Searched: Turkey education sector personal data KVKK overlay.

InsuranceRed

No insurance-sector-specific overlay content was retrieved this run.

Absence provenance: unavailable. Searched: Turkey insurance sector personal data KVKK overlay.

Key findings (3)

  • Only employment_data (workplace CCTV, June 2026) substantively evidenced; banking, health, telecoms, credit, education and insurance overlays unresearched. — source on file
  • Only employment_data (workplace CCTV, June 2026) substantively evidenced; banking, health, telecoms, credit, education and insurance overlays unresearched. — source on file
  • Only employment_data (workplace CCTV, June 2026) substantively evidenced; banking, health, telecoms, credit, education and insurance overlays unresearched. — source on file
Category narrative57 words

Direct sector-specific overlay statutes (banking secrecy, health-sector regulation, telecoms/ePrivacy, credit scoring, education, insurance) were not substantively retrieved this run beyond general LPPD application and one workplace-specific KVKK guidance document on CCTV/surveillance in employment settings. This module is materially thin and requires dedicated follow-up research into Turkey's Banking Law, Electronic Communications Law No. 5809, and health-data-specific secondary legislation.

Sources and claims (1)
  1. UncertainDataGuidance — KVKK's June 2026 announcement on workplace security cameras requires employers to ensure that data processing via CCTV has a legal basis under Article 5 of the LPPD and adheres to fundamental processing principles.observed

#

No sub-module in this module reached a substantive, citable evidentiary threshold this run; all six sub-modules carry explicit absent_field_provenance.

Supervisory authorityKVKK
Traffic-light rationale — Not assessedNo sub-module in this module reached a substantive, citable evidentiary threshold this run; all six sub-modules carry explicit absent_field_provenance.

Sub-modules (6)

Cookies And TrackersRed

KVKK has published draft/guidance material on cookies, but substantive content was not retrieved this run beyond titles.

Absence provenance: unavailable. Searched: Turkey KVKK cookie guidelines applications.

Dark PatternsRed

No Turkey-specific dark-pattern prohibition content was located.

Absence provenance: unavailable. Searched: Turkey KVKK dark patterns prohibition.

Opt Out SignalsRed

No GPC/DAA-equivalent opt-out-signal recognition was located for Turkey.

Absence provenance: unavailable. Searched: Turkey Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific KVKK rule was located.

Absence provenance: unavailable. Searched: Turkey KVKK data clean room data collaboration room.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' analogue was located for Turkey.

Absence provenance: unavailable. Searched: Turkey cross-context advertising personal data sale share equivalent.

Direct MarketingRed

Turkey separately regulates commercial electronic messages and KVKK has issued at least one no-violation finding on SMS marketing, but substantive detail was not retrieved this run.

Absence provenance: unavailable. Searched: Turkey commercial electronic message management regulation KVKK SMS marketing.

Key findings (3)

  • No substantive citable findings; cookie guidance and commercial e-messaging regulation located at title level only. — source on file
  • No substantive citable findings; cookie guidance and commercial e-messaging regulation located at title level only. — source on file
  • No substantive citable findings; cookie guidance and commercial e-messaging regulation located at title level only. — source on file
Category narrative62 words

KVKK has issued cookie-related guidance and Turkey separately regulates commercial electronic messaging, but this run only retrieved title-level references (draft cookie guidelines, Commercial Electronic Message Management Regulation, an SMS-marketing no-violation finding) without substantive body content sufficient for citable claims. Dark patterns, opt-out signals (GPC/DAA), clean-room/data-collaboration rules, and cross-context advertising concepts akin to CPRA's 'sale'/'share' were not located in Turkish-specific sources this run.

#

Biometric-data guidance is well-evidenced; AI-specific and ADM-transparency findings rest on title-level sources only and are marked Uncertain pending primary-text confirmation.

Primary frameworkLaw No. 6698 (LPPD), Articles 4 and 6; KVKK biometric-data guidance (2021)
Supervisory authorityKVKK
Traffic-light rationale — AmberBiometric-data guidance is well-evidenced; AI-specific and ADM-transparency findings rest on title-level sources only and are marked Uncertain pending primary-text confirmation.

Sub-modules (6)

Profiling RestrictionsRed

No Turkey-specific Article 22-equivalent profiling restriction was confirmed this run.

Absence provenance: unavailable. Searched: Turkey LPPD profiling restriction automated decision Article 22 equivalent.

Automated Decision Making TransparencyRed

No ADM-transparency-specific KVKK rule was confirmed this run.

Absence provenance: unavailable. Searched: Turkey KVKK automated decision-making transparency explanation right.

Ai Risk AssessmentsAmber

A parliamentary AI bill and a KVKK generative-AI guide were reported to exist (late 2025), but detail was not retrieved beyond titles.

Absence provenance: unavailable. Searched: Turkey AI bill parliamentary committee KVKK generative AI guide content.

Claims (1):

  • A parliamentary bill to regulate artificial intelligence in Turkey was reported as introduced around November 2025, alongside a KVKK guide addressing generative AI and personal data protection.

Biometric RegimeGreen

KVKK's September 2021 guidance defines biometric data and sets processing principles under Articles 4 and 6 of the LPPD.

Claims (1):

  • KVKK published guidance on 16 September 2021 on the considerations for processing biometric data, defining biometric data and requiring that processing methods be suitable for and proportionate to the purpose, that data be retained only as long as necessary, and that data subjects be informed in accordance with Article 10.

Genetic DataRed

No genetic-data-specific regime distinct from the general 'health' special category was confirmed this run.

Absence provenance: unavailable. Searched: Turkey KVKK genetic data specific regime.

State Surveillance CarveoutsAmber

The LPPD excludes processing of personal data for public-security or law-enforcement purposes from its general application, functioning as a national-security carve-out comparable to GDPR Art 2(2)/23 exemptions.

Claims (1):

  • Both the GDPR and the LPPD provide similar exclusions from their application, including for processing of personal data in the context of public security or law enforcement.

Key findings (3)

  • 2021 biometric guidance confirmed; November 2025 AI bill and generative-AI guide remain title-level only; public-security/law-enforcement carve-out confirmed. — source on file
  • 2021 biometric guidance confirmed; November 2025 AI bill and generative-AI guide remain title-level only; public-security/law-enforcement carve-out confirmed. — source on file
  • 2021 biometric guidance confirmed; November 2025 AI bill and generative-AI guide remain title-level only; public-security/law-enforcement carve-out confirmed. — source on file
Category narrative87 words

KVKK issued dedicated guidance on biometric data processing (September 2021), grounding biometric processing in Articles 4 and 6 principles (necessity, proportionality, minimal retention, transparency). A parliamentary bill to regulate artificial intelligence was reportedly introduced (November 2025) and KVKK reportedly published a guide on generative AI and personal data protection (November 2025), though substantive text of both was not retrieved this run. The LPPD generally excludes processing for public-security/law-enforcement purposes from its scope, functioning as a national-security carve-out. No Turkey-specific ADM-transparency (Article 22-equivalent) or genetic-data-specific regime was confirmed.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. UncertainDataGuidance — KVKK published guidance on 16 September 2021 on the considerations for processing biometric data, defining biometric data and requiring that processing methods be suitable for and proportionate to the purpose, that data be retained only as long as necessary, and that data subjects be informed in accordance with Article 10.observed
  2. UncertainDataGuidance / Esin Attorney Partnership — Both the GDPR and the LPPD provide similar exclusions from their application, including for processing of personal data in the context of public security or law enforcement.observed
  3. UncertainDataGuidance — A parliamentary bill to regulate artificial intelligence in Turkey was reported as introduced around November 2025, alongside a KVKK guide addressing generative AI and personal data protection.observed

#

This is a confirmed statutory gap: the LPPD contains no children-specific consent, age-verification, or profiling-ban regime, and no dependent-adult-specific regime was found.

Primary frameworkLaw No. 6698 (LPPD) -- no children-specific provisions
Supervisory authorityKVKK
Traffic-light rationale — RedThis is a confirmed statutory gap: the LPPD contains no children-specific consent, age-verification, or profiling-ban regime, and no dependent-adult-specific regime was found.

Sub-modules (5)

Age VerificationRed

The LPPD does not set an age limit for consent or for the notification requirement.

Claims (1):

  • The LPPD does not set an age limit for consent, and there is no age limit set for the notification requirement.

Minor Profiling BansRed

No minor-specific profiling ban was identified; KVKK's only children-data output located is a non-binding 2020 brochure.

Claims (1):

  • KVKK's only substantive output addressing children's data is a 23 April 2020 brochure bearing similarities with GDPR protective measures, rather than a binding profiling ban.

Education SettingsRed

No education-setting-specific children's-data rule was identified this run.

Absence provenance: unavailable. Searched: Turkey KVKK children data education setting specific rule.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated)-specific protection was identified this run.

Absence provenance: unavailable. Searched: Turkey KVKK dependent adults vulnerable persons data protection.

Key findings (3)

  • Confirmed structural gap: no age-verification, parental-consent, or minor-profiling-ban regime; only a non-binding 2020 brochure exists. — source on file
  • Confirmed structural gap: no age-verification, parental-consent, or minor-profiling-ban regime; only a non-binding 2020 brochure exists. — source on file
  • Confirmed structural gap: no age-verification, parental-consent, or minor-profiling-ban regime; only a non-binding 2020 brochure exists. — source on file
Category narrative66 words

Unlike the GDPR (Article 8), the LPPD does not grant special statutory protection to children's personal data, does not set an age of consent, and does not specify whether parental/guardian consent is required for information-society services directed at minors. KVKK has issued only soft, non-binding awareness material (a 2020 brochure on children's data) rather than binding age-verification, parental-consent, or minor-profiling-ban provisions. Dependent-adult-specific protections were not identified.

Sources and claims (3)
  1. UncertainDataGuidance — The LPPD does not set an age limit for consent, and there is no age limit set for the notification requirement.observed
  2. UncertainDataGuidance — Unlike the GDPR, the LPPD does not grant special protection to children's personal data, nor does it specify whether the consent of a parent or guardian is needed when processing children's data or providing information-society services to a child.observed
  3. UncertainDataGuidance — KVKK's only substantive output addressing children's data is a 23 April 2020 brochure bearing similarities with GDPR protective measures, rather than a binding profiling ban.observed

#

Powers, penalty tiers, and enforcement-activity evidence are strong; funding/capacity, collective-redress, and private-right-of-action sub-modules remain evidentiary gaps.

Primary frameworkLaw No. 6698 (LPPD), Article 18 (administrative fines) and Article 15 (investigative powers)
Supervisory authorityKVKK
Traffic-light rationale — AmberPowers, penalty tiers, and enforcement-activity evidence are strong; funding/capacity, collective-redress, and private-right-of-action sub-modules remain evidentiary gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Article 18 sets four fine tiers, revalued annually; VERBIS non-registration alone can trigger fines up to TRY 1,802,000 plus a second fine for non-compliance with Board decisions.

Claims (2):

  • Article 18 of the LPPD defines four administrative fine categories: failure to fulfil the obligation to inform, failure to fulfil data-security provisions, failure to fulfil Board decisions, and failure to fulfil VERBIS registration/notification obligations, with amounts revalued annually.
  • Failure to register in time with VERBIS may result in an administrative fine of up to TRY 1,802,000, plus a second administrative fine of up to TRY 1,802,000 for non-compliance with KVKK's decisions, and KVKK may restrict the controller's data-processing activities in Turkey.

Enforcement Activity IndexGreen

KVKK has fined multiple international controllers for late breach notification and security-of-processing failures.

Claims (1):

  • KVKK has fined controllers for late breach notification, including Clickbus Travel Services (TRY 100,000 for notifying two months late), Marriott International (TRY 350,000 for late notification to the DPA and data subjects), and Cathay Pacific Airways (TRY 100,000 for a five-month delay).

Regulator Funding And CapacityRed

No funding or headcount data for KVKK was retrieved this run.

Absence provenance: unavailable. Searched: KVKK budget headcount staffing capacity.

Collective Redress And Class ActionsRed

No Turkey-specific collective-redress or class-action mechanism for data-protection claims was confirmed this run.

Absence provenance: unavailable. Searched: Turkey collective redress class action data protection KVKK.

Private Right Of ActionRed

No specific confirmation of a standalone private right of direct court access (distinct from KVKK complaint channels) was retrieved this run.

Absence provenance: unavailable. Searched: Turkey LPPD private right of action court data protection.

Recent Developments 180DGreen

Within the 180 days preceding this run (roughly February-August 2026), KVKK issued a VERBİS business-partnership clarification (March 2026) and two CCTV/security-camera guidance announcements for workplaces and residential complexes (June 2026).

Claims (3):

  • In a March 2026 public announcement, KVKK clarified that partners in business partnerships, consortiums and ordinary partnerships must incorporate partnership-related personal data processing into their own individual VERBİS registrations rather than creating separate registrations.
  • KVKK's June 2026 announcement on workplace security cameras requires employers to ensure that data processing via CCTV has a legal basis under Article 5 of the LPPD and adheres to fundamental processing principles.
  • On 31 December 2025, KVKK announced updated administrative fine amounts under Article 18 of the LPPD, reflecting the revaluation rate for 2017-2026.

Key findings (3)

  • Four-tier Article 18 fine architecture and active enforcement (Clickbus, Marriott, Cathay Pacific); VERBIS fine ceiling corrected via challenger fold; funding, collective redress and private right of action unconfirmed. — source on file
  • Four-tier Article 18 fine architecture and active enforcement (Clickbus, Marriott, Cathay Pacific); VERBIS fine ceiling corrected via challenger fold; funding, collective redress and private right of action unconfirmed. — source on file
  • Four-tier Article 18 fine architecture and active enforcement (Clickbus, Marriott, Cathay Pacific); VERBIS fine ceiling corrected via challenger fold; funding, collective redress and private right of action unconfirmed. — source on file
Category narrative98 words

KVKK has broad investigative and sanctioning powers under Article 18 of the LPPD, with four fine tiers (failure to inform; data-security failures; non-compliance with Board decisions; VERBIS registration failures), annually revalued and reaching over TRY 1.8 million per violation category by the 2020s. Enforcement activity includes real fines for late breach notification (Clickbus, Marriott, Cathay Pacific) and for security-of-processing failures. Recent (within-180-day) developments include KVKK's March 2026 VERBİS partnership clarification and June 2026 CCTV/workplace and residential guidance. Regulator funding/headcount signals, collective-redress mechanisms, and a distinct private right of action were not confirmed with citable primary sources this run.

Periodic update · new data 2026-09-29

Enforcement & Redress

KVKK Article 18's administrative fine bands were revalued for 2026, applying a 25.49% uplift published in Official Gazette No. 33090 pursuant to Tax Procedure Law General Communiqué No. 585. This is understood to be a routine, inflation-indexed annual adjustment to the existing fine-band structure rather than a substantive expansion of the regulator's enforcement powers, investigative authority, or the categories of conduct subject to administrative fines. The adjustment took effect from 1 January 2026. Considered alongside the proposed KVKK Article 18 amendment on AI-generated-content platform liability, the enforcement and redress landscape in Turkey shows two distinct tracks moving at different speeds: the existing fine-band structure is being maintained and adjusted for inflation on its normal annual cycle, while a separate and more consequential proposed liability mechanism specific to AI-generated content remains at the draft stage before the legislature.

Outlook

Watch for the KVKK's enforcement activity and decision publications through the remainder of 2026 to assess whether the revalued fine bands are being applied in practice, and for how the proposed AI-generated-content liability provision, if enacted, would integrate with or sit alongside the existing Article 18 fine structure.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. UncertainIAPP — Article 18 of the LPPD defines four administrative fine categories: failure to fulfil the obligation to inform, failure to fulfil data-security provisions, failure to fulfil Board decisions, and failure to fulfil VERBIS registration/notification obligations, with amounts revalued annually.observed
  2. UncertainIAPP — Failure to register in time with VERBIS may result in an administrative fine of up to TRY 1,802,000, plus a second administrative fine of up to TRY 1,802,000 for non-compliance with KVKK's decisions, and KVKK may restrict the controller's data-processing activities in Turkey.observed
  3. UncertainIAPP — KVKK has fined controllers for late breach notification, including Clickbus Travel Services (TRY 100,000 for notifying two months late), Marriott International (TRY 350,000 for late notification to the DPA and data subjects), and Cathay Pacific Airways (TRY 100,000 for a five-month delay).observed
  4. UncertainDataGuidance — On 31 December 2025, KVKK announced updated administrative fine amounts under Article 18 of the LPPD, reflecting the revaluation rate for 2017-2026.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct4.35
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Turkey
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s) (36 category placement(s)), 30 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacytransfer mechanisms
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacysccs and bcrs
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressenforcement activity index
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Strong (T1/T2-grounded) coverage was achieved for regulator_and_framework, the special_categories/pseudonymisation sub-modules of lawful_processing_and_special_data, controller_processor_duties (security_measures, breach_notification, retention_and_disposal, dpo_requirements), cross_border_and_adequacy (transfer_mechanisms, sccs_and_bcrs), the biometric_regime sub-module of algorithmic_biometric_and_surveillance_governance, and enforcement_and_redress (regulator_powers_and_penalties, enforcement_activity_index, recent_developments_180d). Coverage relied on T3 analytical/opinion sources for consent_thresholds, adequacy_received/granted framing, and fines-methodology context. sectoral_watch and adtech_and_commercial_privacy are materially thin this run, resting mostly on absent_field_provenance across sub-modules due to searches not being extended into Turkish banking, health, telecoms/ePrivacy, and commercial-electronic-messaging primary legislation. data_subject_rights (restriction_and_objection, data_portability, deadlines_and_response_windows) and children_and_vulnerable_groups (education_settings, dependent_adults) likewise rely on absent_field_provenance rather than confirmed findings.

Unresolved questions (7):

  • What is the LPPD's exact statutory response-window (day-count) for data-subject requests under Article 13, verified against primary Official Gazette text?
  • Does the LPPD (as amended) provide any GDPR Article 20-style data portability right, and if so under what conditions?
  • Has the EU or UK issued (or is either considering) an adequacy decision covering Turkey, and conversely has KVKK published any 'safe country' list post-2024 reform?
  • What sector-specific overlays apply under Turkey's Banking Law, Electronic Communications Law No. 5809, and health-data secondary legislation relative to the LPPD?
  • What is the substantive content and legal status (draft vs. enacted) of the AI bill reported as introduced to the Turkish Grand National Assembly in November 2025?
  • Does Turkish law provide any collective-redress/class-action mechanism or standalone private right of action distinct from KVKK's administrative complaint channel?
  • What are KVKK's current funding, staffing and institutional-capacity signals?

Escalate to primary-source review: yes