Turkey
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Turkey lets personal data leave, but only after you build the paperwork yourself. The regulator has never declared a single country safe, so the approved-destination list is empty. Most companies use a government-published standard contract and must file it within five working days. The regulator is busy: it fined 876 organisations in 2025.
Eight questions about Turkey
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Turkey's rules apply to my company?
Yes. A company with no office in Turkey is still caught, and it is caught harder than a local one. Any organisation based outside Turkey that decides why and how Turkish people's data is used must appoint a representative inside Turkey and sign up to the public register of data controllers before it starts processing. That representative has to be a company set up in Turkey or a Turkish citizen. Turkish small businesses can escape the register if they have fewer than 50 staff and a balance sheet under 100 million lira, but there is no such let-off for foreign companies.
Law 6698 has no single article spelling out extraterritorial reach in the way Europe's General Data Protection Regulation does. Reach is instead built from the Registry of Data Controllers Regulation, which defines a 'data controller representative' as a legal person resident in Turkey or a citizen of the Republic of Turkey, and which set 1 October 2018 as the start and 31 December 2021 as the deadline for registration by controllers resident abroad, with no headcount or balance-sheet threshold attached to that category. The Board's breach decision points the same way: a controller based abroad must report to the Board where the breach affects people in Turkey who use its goods or services. The size exemption (fewer than 50 employees and annual balance sheet under 100 million lira, where processing sensitive data is not the main business) comes from Board Decision 2018/87 as amended by Decision 2023/1154, and on its face applies to controllers generally; the registration timetable nevertheless lists controllers resident abroad as a separate group with no threshold.
Sources
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
“Veri sorumlusu temsilcisi: Turkiye'de yerlesik olmayan veri sorumlularini bu Yonetmeligin 11 inci maddesinin ucuncu fikrasinda belirtilen konularda asgari temsile yetkili Turkiye'de yerlesik tuzel kisi ya da Turkiye Cumhuriyeti vatandasi gercek kisiyi[ ifade eder]”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
“Turkiye'de yerlesik olmayan veri sorumlulari, veri islemeye baslamadan once veri sorumlusu temsilcisi marifetiyle Sicile kaydolmak zorundadir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“Yurtdisinda yerlesik gercek veya tuzel kisi veri sorumlulari [kayit yukumlulugu baslangic tarihi] 01.10.2018 [son tarih] 31.12.2021”
Link checked 18 August 2026
Can I store my users' data outside Turkey?
It depends entirely on your industry, which is why Turkey is rated 'sectoral'. Under the general privacy law data may leave, but only after you put an approved safeguard in place, because the regulator has not yet declared any country safe. In payments and banking the answer flips to no: systems, backups and data have to sit inside Turkey. Public bodies, critical infrastructure, telecoms networks and health records all carry their own extra restrictions on top.
The general law works in three steps. Step one: is there a decision that the destination country, a sector inside it, or an international organisation offers adequate protection? Step two, if not: have the parties put in place one of the appropriate safeguards listed in the law? Step three, if neither: does one of a short, closed list of one-off exceptions apply? Step one is currently empty. The Authority's own page says in terms that no determination has been made. Sector overrides, strongest first: payment and electronic money institutions (systems, backups and data in Turkey, cloud only from a named approved list); banks (the Banking Regulation and Supervision Agency's information systems regulation is the controlling instrument); public bodies and critical infrastructure (the 2019 information and communication security circular and the guide issued under it, now overseen by the Cybersecurity Directorate); telecoms (the Information and Communication Technologies Authority regulates subscriber, traffic and location data separately); health (Ministry of Health rules and the central health data system); insurance (support services and internal systems regulations, the support services one amended on 23 July 2026).
Sources
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
“Yeterli korumanin bulundugu ulkeler: Bu konuda Kurul tarafindan henuz bir belirleme yapilmamistir.”
Link checked 18 August 2026
- Official sourceTurkiye Cumhuriyet Merkez Bankasi (Central Bank of the Republic of Turkiye)Communique on the Information Systems of Payment and Electronic Money Institutions, Official Gazette 1 December 2021 No 31676, article 21
tcmb.gov.tr
“Kuruluslarin birincil ve ikincil sistemleri ile veri yedekleme merkezlerini yurt icinde bulundurmalari zorunludur.”
Link checked 18 August 2026
- Official sourceBankacilik Duzenleme ve Denetleme Kurumu (Banking Regulation and Supervision Agency)Legislation index of the Banking Regulation and Supervision Agency, listing the Regulation on Banks' Information Systems and Electronic Banking Services
bddk.org.tr
Link checked 18 August 2026
- Official sourceBilgi Teknolojileri ve Iletisim Kurumu (Information and Communication Technologies Authority)Regulations index of the Information and Communication Technologies Authority, listing the Regulation on Processing of Personal Data and Protection of Privacy in the Electronic Communications Sector
btk.gov.tr
Link checked 18 August 2026
What do I need in place before data leaves Turkey?
The model is an approved-destination list, and the list is empty. Nobody can rely on their country being blessed, so almost everyone uses one of the safeguards instead. The usual route is signing one of four standard contracts the regulator publishes, then telling the regulator within five working days of signing. Group companies can instead get binding corporate rules approved, and there is a permission route for bespoke undertakings, but that route almost always fails.
Routes in practice. (1) Standard contract: four versions exist (controller to controller, controller to processor, processor to processor, processor to controller), adopted by Board Decision 2024/959 of 4 June 2024. It must be notified to the Authority within five working days of the last signature, on paper or through registered electronic mail. Failure to notify is itself a fineable offence. Filing is not a formality: in 2025 the Authority received 2,497 standard contracts, opened 70 own-motion investigations off the back of them, finished 21 and fined 3 organisations a total of 150,000 lira. (2) Binding corporate rules: approved once by the Board, then the group transfers without asking again. Application forms and guides are published. (3) Written undertaking plus Board permission: in 2025, 90 undertakings were submitted, 89 were decided, 13 were allowed and 76 were refused. Treat this route as a last resort. (4) One-off exceptions such as the person's informed explicit consent, contract necessity, an overriding public interest, or legal claims. The law and regulation both say these are for occasional, irregular transfers, not routine flows.
Sources
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“standart sozlesmeler, imzalarin tamamlanmasindan itibaren bes is gunu icinde fiziki olarak veya kayitli elektronik posta (KEP) adresi ya da Kurul tarafindan belirlenen diger yontemlerle Kuruma bildirilir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“[Yurtdisina veri aktarim taahhutnameleri 2025] Sunulan Taahhutname 90 / Incelemesi Bitirilen 89 / Aktarima Izin Verilen 13 / Aktarima Izin Verilmeyen 76”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceLink may be brokenResmi Gazete (Official Gazette)Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, Official Gazette 10 July 2024
resmigazete.gov.tr
Link checked 18 August 2026
Who enforces the rules in Turkey, and what can they do?
The Personal Data Protection Authority, and it is fully up and running. In 2025 its board met 42 times, took 2,528 decisions, handled 12,512 complaints and fined 876 organisations a combined 352.5 million lira, which is roughly 8 million US dollars. It publishes named breach announcements most weeks. Financial, telecoms and insurance regulators enforce their own rules alongside it, and a new Cybersecurity Directorate has taken over the national cyber incident centre.
Enforcement is rated active rather than aggressive: the volume is high but individual fines are modest by European standards, and the biggest single block of penalties is for failing to register rather than for mishandling data. 2025 numbers from the Authority's own annual report: 876 controllers fined, made up of 140 arising from complaints and tip-offs, 142 from breach notifications and 594 from registry failures. Fines totalled 352,510,494 lira, of which 216,860,000 lira was registry-related. 328 new breach files were opened in 2025, 32 of them against controllers based outside Turkey. The Authority also asked 42 public bodies to take disciplinary action against responsible staff. Its output in 2026 continues: binding principle decisions in February, May and July 2026, a compliance guide for public bodies in July 2026, and named breach announcements in August 2026. On the security side, Presidential Decree No 177 of 8 January 2025 created the Cybersecurity Directorate, Law No 7545 of 19 March 2025 gave it powers, and by 2026 the national cyber incident response centre's services had moved onto the Directorate's site.
Sources
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“2025 yili icerisinde 140'i ihbar ve sikayetler, 142'si veri ihlal bildirimi ve 594'u Veri Sorumlulari Siciline kayit ve bildirim yukumlulugu kapsaminda olmak uzere toplam 876 veri sorumlusu hakkinda uygulanan idari para cezasinin miktari toplam 352.510.494 TL olarak gerceklesmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuAnnouncements page of the Personal Data Protection Authority, showing principle decisions and named breach notices through August 2026
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
“7545 Sayili Siber Guvenlik Kanunu [Kanun] 19.03.2025”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi / USOMNational Cyber Incident Response Centre notice — its functions moved to the Cybersecurity Directorate
usom.gov.tr
“Siber Guvenlik Baskanligi; 177 sayili Cumhurbaskanligi Kararnamesi ve 12.03.2025 tarihli, 7545 sayili Siber Guvenlik Kanunu uyarinca ... kurulmustur.”
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply, and the ceiling is unusual. Turkey does not give you a fixed number of months to delete by. Instead, once your reason for holding data runs out, you must erase it at your next scheduled clear-out, and any organisation on the public register has to publish a written retention and destruction policy setting those dates. The floor comes from ordinary commercial and tax law, which forces you to keep books and invoices for years.
Ceiling: the Regulation on Deletion, Destruction or Anonymisation of Personal Data requires controllers that must register to hold a personal data retention and destruction policy, and to erase, destroy or anonymise the data at the first periodic destruction run following the date the duty to delete arose. That makes the interval between destruction runs the real deadline, and it is set in your own policy rather than by a single national number. Floor: general Turkish commercial and tax legislation requires business records to be kept for a period of years, and sector regulators impose their own record-keeping periods on banks, payment institutions, insurers and telecoms operators. Where the two collide, the retention duty in the specific law wins and the data must be kept, but it must then be locked down and used only for the purpose that justified keeping it. We did not verify the individual commercial and tax periods against a government source in this run, so treat those numbers as unconfirmed.
Sources
- Official sourceKisisel Verileri Koruma KurumuDeletion, destruction and anonymisation of personal data — the Authority's explainer of the periodic destruction duty
kvkk.gov.tr
“kisisel veri saklama ve imha politikasi hazirlamis olan veri sorumlusu, kisisel verileri silme, yok etme veya anonim hale getirme yukumlulugunun ortaya ciktigi tarihi takip eden ilk periyodik imha isleminde, kisisel verileri siler, yok eder veya anonim hale getirir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
Link checked 18 August 2026
What happens if there is a breach?
There are at least three clocks. The privacy one is 72 hours: from the moment you learn that data has been taken unlawfully, you have three days to tell the Personal Data Protection Board, and you must tell the affected people as soon as you reasonably can. If you miss the 72 hours you must still report and explain why you were late. Companies based abroad have to report too, if people in Turkey are affected.
Clock one: Board Decision 2019/10 of 24 January 2019 reads the law's phrase 'as soon as possible' as 72 hours from becoming aware, using the Authority's published breach form, with information supplied in stages if it is not all available at once. Individuals must be told directly where contact details exist, otherwise by a suitable method such as a notice on the controller's own website. A processor that suffers the breach must tell its controller without any delay. A controller based abroad must notify on the same terms where the consequences hit people in Turkey who use its goods or services. Clock two: cyber incident reporting to the Cybersecurity Directorate, which since 2025 holds the national incident response role and inherited the national cyber incident response centre's services; we did not verify a specific number of hours in this run. Clock three: financial regulators run their own incident reporting for banks, payment institutions and electronic money institutions. Overlapping clocks are the usual operational failure here: the 72-hour privacy report is the one everyone remembers and the regulator-specific ones are the ones people miss.
Sources
- Official sourceKisisel Verileri Koruma KurumuBoard Decision 2019/10 of 24 January 2019 on breach notification procedure — the 72-hour clock
kvkk.gov.tr
“veri sorumlusunun bu durumu ogrendigi tarihten itibaren gecikmeksizin ve en gec 72 saat icinde Kurula bildirmesine, ... ilgili kisilere de makul olan en kisa surede ... bildirim yapilmasina”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuBoard Decision 2019/10 of 24 January 2019 on breach notification procedure — the 72-hour clock
kvkk.gov.tr
“Veri ihlalinin yurtdisinda yerlesik veri sorumlusu nezdinde yasanmasi halinde, bu ihlalin sonuclarinin Turkiye'de yerlesik ilgili kisileri etkilemesi ve ilgili kisilerin sunulan urun ve hizmetlerden Turkiye'de faydalanmalari durumunda, bu veri sorumlusu tarafindan da ayni esaslar cercevesinde Kurula bildirimde bulunulmasina”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi / USOMNational Cyber Incident Response Centre notice — its functions moved to the Cybersecurity Directorate
usom.gov.tr
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
Link checked 18 August 2026
What trips people up in Turkey?
Five things bite people. One: most fines are for paperwork, not privacy. Two thirds of the organisations fined in 2025 were punished for the public register, not for mishandling anyone's data. Two: the bespoke permission route for sending data abroad is close to a dead end, with 76 of 89 applications refused in 2025. Three: filing your standard contract invites inspection rather than closing the file. Four: your representative in Turkey must be Turkish. Five: no country is on the safe list, so there is no shortcut.
(1) In 2025, 594 of 876 penalised organisations were penalised over the register of data controllers, for 216.86 million lira of the 352.5 million lira total, an average of roughly 365,000 lira each. The Authority states expressly that it continues to take action against controllers resident abroad as well as domestic ones. (2) Written undertakings plus Board permission: 90 submitted, 89 decided, 13 allowed, 76 refused. If your transfer plan depends on this route, assume it fails. (3) Standard contracts must be filed within five working days; in 2025 the Authority turned 70 of the 2,497 filings into own-motion investigations and fined three organisations. Filing a defective or unsigned contract triggers a formal review by law. (4) The representative must be a company established in Turkey or a Turkish citizen, so a regional office in another country will not do. (5) There is no adequacy decision for any country, sector or international organisation, so a European company cannot rely on Turkey treating the European Union as safe. Separately, Turkish law also attaches criminal offences to unlawfully recording, passing on or failing to delete personal data, which can reach individuals rather than only the company; we did not verify the current text of those offences in this run.
Sources
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“01.01.2025-31.12.2025 tarihi itibariyle Sicile kayit yukumlulugunu suresinde yerine getirmeyen 594 veri sorumlusu hakkinda toplam 216.860.000 TL idari para cezasi uygulanmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“Kuruma intikal eden standart sozlesme bildirimleri hakkinda yapilan degerlendirme neticesinde 70'i ile ilgili olarak Kanun'un 15'inci maddesinin birinci fikrasi uyarinca resen inceleme baslatilarak 21'i sonuclandirilmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
Link checked 18 August 2026
What is changing soon in Turkey?
Two dated items and one direction of travel. Retailers running loyalty cards have until 28 February 2027 to build a way of checking that the person at the till really owns the card, after the regulator extended the original deadline in July 2026. Public bodies are working to a July 2026 ruling on what they may publish online. And the government is pushing openly on data sovereignty, with the President chairing a cyber security meeting in May 2026 that treated data as a strategic asset.
Dated: (a) Principle Decision 2026/266, published on 28 February 2026, gave controllers six months to fix loyalty-card checkout processes; Board Decision 2026/1491 of 22 July 2026 pushed that deadline out to 28 February 2027. (b) Principle Decision 2026/1301 of 1 July 2026 governs how public-law controllers may publish personal data on the internet, with a public explainer issued on 27 July 2026, and a compliance guide for public bodies followed on 28 July 2026. (c) Principle Decision 2026/1095 of 20 May 2026 covers processing the personal data of accident victims. Dormant switches that can change the picture without consultation: the Board can declare a country, a sector within a country or an international organisation adequate at any time, and can equally suspend or revoke such a decision looking forward, reviewing every four years; the Board can add or remove exemptions from the register by decision, as it did on 4 September 2025 for micro-businesses whose main activity is processing sensitive data; and the central bank has an express power to stop payment institutions sharing data abroad, or to add further limits, whenever it judges that the payments market is being harmed. Secondary legislation under the 2025 Cybersecurity Law is still being issued, including procurement rules in April 2026.
Sources
- Official sourceKisisel Verileri Koruma KurumuPublic announcement of 13 August 2026 extending the loyalty-card compliance deadline to 28 February 2027 (Board Decision 2026/1491)
kvkk.gov.tr
“uyum suresinin 28.02.2027 tarihine kadar uzatilmasina”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
“Ayrica, veri egemenligi konusu ayri bir baslik altinda ele alinmistir. Verinin yalnizca teknik bir unsur olmanin otesinde, ayni zamanda stratejik bir deger oldugu belirtilmis; bu kapsamda dijital egemenlik yaklasiminin guclendirilmesi yonundeki kararlilik teyit edilmistir.”
Link checked 18 August 2026
- Official sourceTurkiye Cumhuriyet Merkez Bankasi (Central Bank of the Republic of Turkiye)Communique on the Information Systems of Payment and Electronic Money Institutions, Official Gazette 1 December 2021 No 31676, article 21
tcmb.gov.tr
“Banka, yapacagi degerlendirme neticesinde odemeler alaninin gelisimini olumsuz etkileyecegine karar vermesi durumunda, bu fikra uyarinca yapilan paylasimlari durdurabilir veya bunlara iliskin ilave sinirlandirma getirebilir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules3 rules
6698 sayili Kisisel Verilerin Korunmasi Kanunu
Act of parliament · Law No 6698 of 24 March 2016, cross-border transfer article replaced by Law No 7499 of 12 March 2024
Turkey's general privacy law. Since 1 June 2024 sending data abroad follows three steps: an official finding that the destination is adequate, or an approved safeguard such as a standard contract, or one of a short list of one-off exceptions. No destination has ever been found adequate, so in practice everyone lives on the safeguards.
Enforced by Personal Data Protection Authority
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Get consentExplicit consent is the default ground; a short list of alternatives exists, and sensitive data has its own stricter list.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours, from 24 January 2019
- Tell affected people
- Put a transfer safeguard in place — from 1 June 2024The old rule, which let explicit consent carry routine transfers, was replaced on 1 June 2024 by the staged adequacy / safeguard / occasional-exception regime.
What it costs if you get it wrong
- Fixed maximum fine: Ceilings are set by article 18 and raised every January in line with the official revaluation rate; the 2026 figures were not verified in this run. Across all controllers in 2025 the Board imposed 352,510,494 lira.Failing to give notice, failing to keep data secure, ignoring a Board decision, or failing to register
- Criminal liability: Prison sentences under the Turkish Penal Code for unlawfully recording, transferring or failing to delete personal data; text not verified in this runUnlawful recording, transfer or retention of personal data
Sources
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
“Kanunun ... 9 uncu maddesinde degisiklikler yapilmis ve yapilan degisiklikler 01.06.2024 tarihinde yururluge girmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuBoard Decision 2019/10 of 24 January 2019 on breach notification procedure — the 72-hour clock
kvkk.gov.tr
Link checked 18 August 2026
Kisisel Verilerin Yurt Disina Aktarilmasina Iliskin Usul ve Esaslar Hakkinda Yonetmelik
Directly binding regulation · Official Gazette, 10 July 2024
The rulebook for sending data abroad. Its sharpest edge is administrative: sign one of the government's standard contracts and you must tell the regulator within five working days, and that filing is read rather than shelved. In 2025, 2,497 contracts were filed and 70 turned into investigations.
Enforced by Personal Data Protection Authority
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Standard contract clauses, Approved group rules, Government sign-off needed
What it makes you do
- Put a transfer safeguard in placeFour standard contract templates were adopted by Board Decision 2024/959 on 4 June 2024, together with binding corporate rule application forms and guides.
- Keep records of processingA signed standard contract must be notified to the Authority within five working days of the last signature, on paper or by registered electronic mail.
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine under article 18(1)(d) of Law 6698 for failing to make the notification; three organisations were fined a combined 150,000 lira in 2025Not filing the standard contract, or filing one that is altered or unsigned
Sources
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“standart sozlesmeler, imzalarin tamamlanmasindan itibaren bes is gunu icinde ... Kuruma bildirilir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuThe four published standard contracts for transfers abroad
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuBinding corporate rules application forms and guides
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceLink may be brokenResmi Gazete (Official Gazette)Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, Official Gazette 10 July 2024
resmigazete.gov.tr
Link checked 18 August 2026
Veri Sorumlulari Sicili Hakkinda Yonetmelik
Directly binding regulation · Official Gazette, 30 December 2017, amended 28 April 2019
The public register of data controllers, and the single biggest source of fines in Turkey. Foreign companies must appoint a Turkey-based representative and register before processing, and unlike Turkish small businesses they get no size exemption.
Enforced by Personal Data Protection Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — from 1 October 2018Registration must be completed before processing starts. Controllers resident abroad had to register by 31 December 2021 with no size threshold.
- Appoint a local representativeThe representative must be a legal person established in Turkey or a Turkish citizen.
- Keep records of processingThe register entry itself lists data categories, purposes, retention periods, security measures, recipient groups and the data intended to be sent to foreign countries.
What it costs if you get it wrong
- Fixed maximum fine: 594 controllers were fined a combined 216,860,000 lira in 2025, an average of about 365,000 lira (roughly 8,000 US dollars) eachNot registering, or not keeping the register entry up to date
Sources
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
“Turkiye'de yerlesik olmayan veri sorumlulari, veri islemeye baslamadan once veri sorumlusu temsilcisi marifetiyle Sicile kaydolmak zorundadir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“Sicile kayit yukumlulugunu suresinde yerine getirmeyen 594 veri sorumlusu hakkinda toplam 216.860.000 TL idari para cezasi uygulanmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuExemptions from the duty to register
kvkk.gov.tr
Link checked 18 August 2026
Industry rules7 rules
Odeme ve Elektronik Para Kuruluslarinin Bilgi Sistemleri ile Odeme Hizmeti Saglayicilarinin Odeme Hizmetleri Alanindaki Veri Paylasim Servislerine Iliskin Teblig
Regulator directive · Official Gazette, 1 December 2021, No 31676, article 21; paragraph 4 added 7 October 2023 · Payments
The hardest wall in Turkey. Payment and electronic money institutions must keep their main systems, their standby systems and their backups inside the country, and their outsourcing providers must do the same. Since October 2023 a narrow amount of data may be shared abroad for a cross-border payment, but only if the data itself stays stored in Turkey.
Enforced by Central Bank of the Republic of Turkiye
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryPrimary systems, secondary systems and data backup centres must all be inside Turkey. Where an outsourcing provider is used, that provider's systems and backups must be in Turkey too.
- Written vendor contractCommunity cloud may only be taken from outsourcing providers the central bank has assessed as suitable; six were on the published list as at 10 January 2025.
- Put a transfer safeguard in place — from 7 October 2023Since October 2023 a firm may share only the data a cross-border payment actually needs, on the customer's request or instruction, provided the data continues to be stored in Turkey and the privacy law's transfer rules are also met.
- Independent audit
What it costs if you get it wrong
- Loss of your licence: Supervisory action by the central bank under Law No 6493, up to withdrawal of the operating licenceOperating payment systems outside Turkey or using an unapproved cloud provider
Sources
- Official sourceTurkiye Cumhuriyet Merkez Bankasi (Central Bank of the Republic of Turkiye)Communique on the Information Systems of Payment and Electronic Money Institutions, Official Gazette 1 December 2021 No 31676, article 21
tcmb.gov.tr
“Kuruluslarin birincil ve ikincil sistemleri ile veri yedekleme merkezlerini yurt icinde bulundurmalari zorunludur.”
Link checked 18 August 2026
- Official sourceTurkiye Cumhuriyet Merkez Bankasi (Central Bank of the Republic of Turkiye)Communique on the Information Systems of Payment and Electronic Money Institutions, Official Gazette 1 December 2021 No 31676, article 21
tcmb.gov.tr
“Ayni kurulusun musterileri ya da farkli kuruluslarin musterileri arasindaki odeme islemlerinin yurutulmesinde kullanilan tum bilgi sistemleri ve bunlarin yedeklerinin yurt icinde bulunmasi esastir. Bu kapsamda dis hizmet alinmasi halinde, dis hizmet saglayicinin soz konusu hizmete iliskin faaliyetleri yurutmede kullandigi bilgi sistemleri ve bunlarin yedekleri de yurt icinde tutulur.”
Link checked 18 August 2026
- Official sourceTurkiye Cumhuriyet Merkez BankasiList of outsourcing providers approved to supply community cloud services to payment and electronic money institutions, 10 January 2025
tcmb.gov.tr
“Topluluk Bulutu Hizmeti Sunabilmesi Icin Uygunluk Verilen Dis Hizmet Saglayicilar”
Link checked 18 August 2026
Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik
Directly binding regulation · Listed on the Banking Regulation and Supervision Agency's own legislation index; article numbering not verified in this run · Banking
Banking is the second hard wall. The agency's information systems regulation, its outsourcing regulation and its rules on sharing confidential information together decide where a bank's systems and customer data may sit, and the working assumption in the market is that the main and standby systems stay in Turkey. Confidence is low because the text itself was unreachable.
Enforced by Banking Regulation and Supervision Agency
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryBanks are generally understood to have to keep their primary and secondary information systems in Turkey, and separate rules govern the sharing of customer secrets. We could not open the article text from this environment.
- Extra vendor secrecy termsBanking secrecy sits on top of the privacy law: customer information is protected by the Banking Law as well, so a standard processor contract is not enough.
What it costs if you get it wrong
- Loss of your licence: Supervisory measures under the Banking Law, up to restriction or withdrawal of the licencePlacing banking systems or customer secrets outside Turkey without authority
Sources
- Official sourceBankacilik Duzenleme ve Denetleme Kurumu (Banking Regulation and Supervision Agency)Legislation index of the Banking Regulation and Supervision Agency, listing the Regulation on Banks' Information Systems and Electronic Banking Services
bddk.org.tr
Link checked 18 August 2026
Elektronik Haberlesme Sektorunde Kisisel Verilerin Islenmesi ve Gizliligin Korunmasina Iliskin Yonetmelik
Directly binding regulation · Listed on the Information and Communication Technologies Authority's regulations index; consolidated text at the Presidency legislation system, reference 38663 · Telecoms
Telecoms operators are policed by their own regulator on top of the general privacy law, under a dedicated regulation for personal data and confidentiality in the electronic communications sector. This is the layer that governs call records, traffic data and location data.
Enforced by Information and Communication Technologies Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryTelecoms operators are widely reported to have to hold subscriber traffic and location data inside Turkey. We could not open the regulation's text from this environment, so treat the in-country storage duty as unconfirmed.
- Keep logsTraffic data retention periods are set by telecoms and internet legislation rather than by the privacy law.
- Secure the data
Sources
- Official sourceBilgi Teknolojileri ve Iletisim Kurumu (Information and Communication Technologies Authority)Regulations index of the Information and Communication Technologies Authority, listing the Regulation on Processing of Personal Data and Protection of Privacy in the Electronic Communications Sector
btk.gov.tr
Link checked 18 August 2026
- Official sourceLink may be brokenCumhurbaskanligi Mevzuat Bilgi Sistemi (Presidency Legislation Information System)Regulation on Processing of Personal Data and Protection of Privacy in the Electronic Communications Sector — official consolidated text
mevzuat.gov.tr
Link checked 18 August 2026
- Official sourceBilgi Teknolojileri ve Iletisim KurumuNetwork and information security legislation page — Regulation on Network and Information Security in the Electronic Communications Sector, Official Gazette 13 July 2014 No 29059
btk.gov.tr
“haberlesme ve sebeke guvenligine iliskin hususlar temel olarak 13/07/2014 tarihli 29059 sayili Resmi Gazete'de yayimlanarak yururluge giren Elektronik Haberlesme Sektorunde Sebeke ve Bilgi Guvenligi Yonetmeligi'nde duzenlenmistir”
Link checked 18 August 2026
7545 sayili Siber Guvenlik Kanunu
Act of parliament · Law No 7545, adopted 12 March 2025, Official Gazette 19 March 2025 No 32846 · Government
A new national cybersecurity statute, in force since 19 March 2025, covering public bodies, professional bodies, private organisations and critical infrastructure. It created a central authority with audit and certification powers and carries both administrative and criminal sanctions.
Enforced by Cybersecurity Directorate
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Report cyber incidentsThe Cybersecurity Directorate runs national incident detection and response and has absorbed the national cyber incident response centre's services. A specific reporting deadline in hours was not verified in this run.
- Hold a security certificateThe law sets up audit, certification, authorisation and standardisation machinery for the cybersecurity market.
- Independent audit
What it costs if you get it wrong
- Criminal liability: The Directorate describes the law as carrying deterrent administrative and criminal sanctions; individual sentence lengths were not verified in this runBreaching duties owed under the Cybersecurity Law
Sources
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
“7545 Sayili Siber Guvenlik Kanunu [Kanun] 19.03.2025”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
“Soz konusu Kanun, 19/03/2025 tarihli ve 32846 sayili Resmi Gazete'de yayimlanarak yururluge girmistir.”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi / USOMNational Cyber Incident Response Centre notice — its functions moved to the Cybersecurity Directorate
usom.gov.tr
Link checked 18 August 2026
- Official sourceLink may be brokenCumhurbaskanligi Mevzuat Bilgi SistemiCybersecurity Law No 7545, Official Gazette 19 March 2025 No 32846 — official consolidated text
mevzuat.gov.tr
Link checked 18 August 2026
2019/12 sayili Bilgi ve Iletisim Guvenligi Tedbirleri Genelgesi ve Bilgi ve Iletisim Guvenligi Rehberi
Regulator directive · Presidential Circular 2019/12 of 6 July 2019; the implementing guide's current version is dated 1 March 2026 · Government
If you sell to the Turkish state or run critical infrastructure, this is the rule that decides where the data sits. A 2019 presidential circular and the security guide issued under it require public sector and critical infrastructure data to stay on systems inside Turkey, and the guide is actively maintained by the Cybersecurity Directorate.
Enforced by Cybersecurity Directorate
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryPublic bodies and critical infrastructure operators are required to keep their data on systems inside Turkey and under their own control. We could not open the circular's text from this environment; the duty is asserted at medium confidence.
- Prove the data stays under local control
- Independent auditCompliance is checked against the guide, which has its own audit guide, forms and templates, all refreshed in 2026.
- Hold a security certificateThe Directorate publishes a mapping table between the guide's controls and the ISO/IEC 27001 information security standard.
Sources
- Official sourceSiber Guvenlik BaskanligiCybersecurity Directorate document index — Information and Communication Security Guide, version dated 1 March 2026
siberguvenlik.gov.tr
“Bilgi ve Iletisim Guvenligi Rehberi”
Link checked 18 August 2026
- Official sourceSiber Guvenlik BaskanligiCybersecurity Directorate document index — Information and Communication Security Guide, version dated 1 March 2026
siberguvenlik.gov.tr
“Bilgi ve Iletisim Guvenligi Denetim Rehberi”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
Link checked 18 August 2026
Kisisel Saglik Verileri Hakkinda Yonetmelik
Directly binding regulation · Listed on the Ministry of Health's General Directorate of Health Information Systems regulations page, alongside the Regulation on Health Information Management Systems · Health and social care
Health data carries two layers: it is sensitive data under the general privacy law, and the Ministry of Health runs its own regulation on personal health data plus a national health data system that providers feed. We could not open the regulation's text, so no in-country storage duty is asserted here either way.
Enforced by Ministry of Health, General Directorate of Health Information Systems
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Secure the data
- Get consentHealth data is sensitive data under the general law, which sets a stricter list of grounds than for ordinary personal data.
- Register or notify
Sources
- Official sourceT.C. Saglik Bakanligi (Ministry of Health)Regulations page of the General Directorate of Health Information Systems, listing the Regulation on Personal Health Data and the Regulation on Health Information Management Systems
sbsgm.saglik.gov.tr
Link checked 18 August 2026
Sigortacilik Destek Hizmetleri Hakkinda Yonetmelik
Directly binding regulation · Amending regulation published 23 July 2026, per the agency's own legislation index; base regulation text not verified in this run · Insurance
Insurers and pension companies answer to their own regulator for outsourcing and internal systems. The support services regulation was amended as recently as 23 July 2026, so anyone placing insurance data with a supplier should check the current text rather than an older summary.
Enforced by Insurance and Private Pension Regulation and Supervision Agency
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractInsurers' use of outside suppliers, including anyone hosting their systems, is regulated separately from the privacy law.
- Independent audit
Sources
- Official sourceSigortacilik ve Ozel Emeklilik Duzenleme ve Denetleme KurumuInsurance regulations index of the Insurance and Private Pension Regulation and Supervision Agency, showing the Insurance Support Services Regulation amended on 23 July 2026
seddk.gov.tr
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The article of the Banking Regulation and Supervision Agency's information systems regulation that requires banks' primary and secondary systems to be located in Turkey
The agency's own legislation index confirms the regulation exists, but its document server, the Official Gazette site and the Presidency legislation system were all unreachable from this environment, so the operative wording could not be read. The banking rule is therefore recorded at low confidence.
That telecoms operators must hold subscriber traffic and location data inside Turkey
The Information and Communication Technologies Authority's own regulations index lists the relevant regulation, but its text sits on the Presidency legislation system, which could not be opened. The in-country storage duty is widely reported but was not verified against the instrument.
The wording of Presidential Circular 2019/12 on information and communication security, including the requirement that public sector and critical infrastructure data stay on systems inside Turkey
The Official Gazette was unreachable and the Cybersecurity Directorate's document server refused direct downloads of the implementing guide. Existence and the guide's current version date were verified from the Directorate's own site; the wording was not.
The exact administrative fine ceilings under article 18 of Law 6698 for 2026
The ceilings rise each January with the official revaluation rate and no current table was found on the Authority's site. Only the totals actually imposed in 2025 are quoted here.
Whether any health-sector or insurance-sector rule requires data to stay inside Turkey
No such rule was found, checked 18 August 2026, confidence medium. The Ministry of Health and insurance regulators list their instruments publicly but the texts are hosted on the unreachable Presidency legislation system.
Criminal liability for unlawfully recording, transferring or failing to delete personal data
Turkish criminal law is understood to carry prison sentences for these acts and the privacy law cross-refers to them, but the criminal code text was not opened in this run.
US dollar approximations in this record
Converted at roughly 45 Turkish lira to the dollar. The rate was not verified against an official source on 18 August 2026, so treat dollar figures as indicative only.
Whether any adequacy decision was made between the last update of the Authority's transfer page and 18 August 2026
The Authority's page said on 18 August 2026 that no determination had been made, and no announcement to the contrary appeared in its announcements list. A negative cannot be proved beyond that.
Draft amendments listed on the banking regulator's site to the information systems regulation and to the rules on sharing confidential information
Draft versions appeared in the agency's legislation index but could not be dated or read, so nothing is asserted about them.
Whether securities firms face an information systems localisation rule
The Capital Markets Board's site is built for browsers and its legislation pages could not be read from this environment. Not researched to conclusion; treat the securities sector as unassessed.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Turkey versus Argentina
- Turkey versus Armenia
- Turkey versus Australia
- Turkey versus Austria
- Turkey versus Azerbaijan
- Turkey versus Brazil
- Turkey versus Bulgaria
- Turkey versus Cambodia
- Turkey versus Canada
- Turkey versus China
- Turkey versus Croatia
- Turkey versus Cyprus
- Turkey versus Estonia
- Turkey versus France
- Turkey versus Georgia
- Turkey versus Germany
- Turkey versus Greece
- Turkey versus Hong Kong SAR
- Turkey versus Hungary
- Turkey versus Iceland
- Turkey versus India
- Turkey versus Indonesia
- Turkey versus Ireland
- Turkey versus Israel
- Turkey versus Italy
- Turkey versus Japan
- Turkey versus Latvia
- Turkey versus Lithuania
- Turkey versus Luxembourg
- Turkey versus Malta
- Turkey versus Mexico
- Turkey versus Mongolia
- Turkey versus Nepal
- Turkey versus Netherlands
- Turkey versus Poland
- Turkey versus Russia
- Turkey versus Saudi Arabia
- Turkey versus Serbia
- Turkey versus Singapore
- Turkey versus Slovakia
- Turkey versus Slovenia
- Turkey versus South Korea
- Turkey versus Spain
- Turkey versus Sri Lanka
- Turkey versus Sweden
- Turkey versus Switzerland
- Turkey versus Taiwan
- Turkey versus Thailand
- Turkey versus Ukraine
- Turkey versus United Arab Emirates
- Turkey versus United Kingdom
- Turkey versus United States
- Turkey versus Uzbekistan