Turkey
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Turkey — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Turkey lets personal data leave, but only after you build the paperwork yourself. The regulator has never declared a single country safe, so the approved-destination list is empty. Most companies use a government-published standard contract. You must file that contract within five working days. The regulator is busy: it fined 876 organisations in 2025.
Data governance in Turkey
The eight things that decide how you handle data about people in Turkey. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. A company with no office in Turkey is still caught. In fact it is caught harder than a local one. Say you are based outside Turkey and you decide why and how Turkish people's data is used. You must appoint a representative inside Turkey. You must also sign up to Turkey's public data register before you start using the data. That representative has to be a company set up in Turkey, or a Turkish citizen. Turkish small businesses can skip the register if they have fewer than 50 staff and a balance sheet under 100 million lira. There is no such let-off for foreign companies.
- What you have to do here:
- Appoint a representative · Register or notify
Law 6698 has no single article saying it reaches companies with no office in Turkey. Europe's General Data Protection Regulation has one. Turkey does not. The reach is built from the rules on the public data register instead. Those rules define a company's representative as a legal person resident in Turkey, or a citizen of the Republic of Turkey. They set 1 October 2018 as the start date for registration by companies resident abroad, and 31 December 2021 as the deadline. No staff number or balance-sheet threshold is attached to that group. The Board's breach decision points the same way. A company based abroad must report to the Board where the breach affects people in Turkey who use its goods or services. There is a size exemption. It covers businesses with fewer than 50 employees and an annual balance sheet under 100 million lira. Handling sensitive data must not be their main business. It comes from Board Decision 2018/87, as amended by Decision 2023/1154. On its face it applies to everyone. But the registration timetable still lists companies resident abroad as a separate group, with no threshold.
Sources
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
“Veri sorumlusu temsilcisi: Turkiye'de yerlesik olmayan veri sorumlularini bu Yonetmeligin 11 inci maddesinin ucuncu fikrasinda belirtilen konularda asgari temsile yetkili Turkiye'de yerlesik tuzel kisi ya da Turkiye Cumhuriyeti vatandasi gercek kisiyi[ ifade eder]”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
“Turkiye'de yerlesik olmayan veri sorumlulari, veri islemeye baslamadan once veri sorumlusu temsilcisi marifetiyle Sicile kaydolmak zorundadir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“Yurtdisinda yerlesik gercek veya tuzel kisi veri sorumlulari [kayit yukumlulugu baslangic tarihi] 01.10.2018 [son tarih] 31.12.2021”
Link checked 18 August 2026
Where the data is allowed to live
It depends entirely on your industry. That is why Turkey's answer changes from one industry to the next. Under the general privacy law data may leave, but only after you put an approved safeguard in place. That is because the regulator has not yet declared any country safe. In payments and banking the answer flips to no. Systems, backups and data have to sit inside Turkey. Public bodies, critical infrastructure, telecoms networks and health records all carry their own extra restrictions on top.
The general law works in three steps. Step one: has anyone officially decided that the destination country, an industry inside it, or an international organisation protects data well enough? Step two, if not: have the parties put in place one of the approved safeguards listed in the law? Step three, if neither: does one of a short, closed list of one-off exceptions apply? Step one is currently empty. The Authority's own page says plainly that no such decision has been made. Industry rules on top, strongest first. Payment and electronic money institutions: systems, backups and data in Turkey, and cloud only from a named approved list. Banks: the Banking Regulation and Supervision Agency's information systems regulation is the rule that controls this. Public bodies and critical infrastructure: the 2019 information and communication security circular, and the guide issued under it. The Cybersecurity Directorate now oversees both. Telecoms: the Information and Communication Technologies Authority regulates subscriber, traffic and location data separately. Health: Ministry of Health rules and the central health data system. Insurance: the support services and internal systems regulations. The support services one was amended on 23 July 2026.
Sources
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
“Yeterli korumanin bulundugu ulkeler: Bu konuda Kurul tarafindan henuz bir belirleme yapilmamistir.”
Link checked 18 August 2026
- Official sourceTurkiye Cumhuriyet Merkez Bankasi (Central Bank of the Republic of Turkiye)Communique on the Information Systems of Payment and Electronic Money Institutions, Official Gazette 1 December 2021 No 31676, article 21
tcmb.gov.tr
“Kuruluslarin birincil ve ikincil sistemleri ile veri yedekleme merkezlerini yurt icinde bulundurmalari zorunludur.”
Link checked 18 August 2026
- Official sourceBankacilik Duzenleme ve Denetleme Kurumu (Banking Regulation and Supervision Agency)Legislation index of the Banking Regulation and Supervision Agency, listing the Regulation on Banks' Information Systems and Electronic Banking Services
bddk.org.tr
Link checked 18 August 2026
- Official sourceBilgi Teknolojileri ve Iletisim Kurumu (Information and Communication Technologies Authority)Regulations index of the Information and Communication Technologies Authority, listing the Regulation on Processing of Personal Data and Protection of Privacy in the Electronic Communications Sector
btk.gov.tr
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
The model is a list of approved destination countries, and that list is empty. Nobody can rely on their country being approved. So almost everyone uses one of the safeguards instead. The usual route is signing one of four standard contracts the regulator publishes. You then have to tell the regulator within five working days of signing. Group companies can instead get company-wide rules approved. There is also a permission route for one-off written undertakings, but that route almost always fails.
- Ways to send data out:
- Standard contract clauses · Approved group rules · Government sign-off needed · Explicit consent
THE ROUTES. (1) Standard contract. Four versions exist. Which one you use depends on whether each side decides how the data is used, or just handles it for someone else. Board Decision 2024/959 of 4 June 2024 adopted them. You must tell the Authority within five working days of the last signature. That can be on paper or through registered electronic mail. Failing to tell them is itself a fineable offence. Filing is not a formality. In 2025 the Authority received 2,497 standard contracts. It opened 70 investigations of its own off the back of them, finished 21, and fined 3 organisations a total of 150,000 lira. (2) Company-wide rules. The Board approves them once. After that the group transfers data without asking again. Application forms and guides are published. (3) Written undertaking plus Board permission. In 2025, 90 undertakings were submitted and 89 were decided. 13 were allowed and 76 were refused. Treat this route as a last resort. (4) One-off exceptions. These include the person's informed explicit consent, contract necessity, an overriding public interest, and legal claims. The law and the regulation both say these are for occasional, irregular transfers, not routine flows.
Sources
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“standart sozlesmeler, imzalarin tamamlanmasindan itibaren bes is gunu icinde fiziki olarak veya kayitli elektronik posta (KEP) adresi ya da Kurul tarafindan belirlenen diger yontemlerle Kuruma bildirilir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“[Yurtdisina veri aktarim taahhutnameleri 2025] Sunulan Taahhutname 90 / Incelemesi Bitirilen 89 / Aktarima Izin Verilen 13 / Aktarima Izin Verilmeyen 76”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceLink may be brokenResmi Gazete (Official Gazette)Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, Official Gazette 10 July 2024
resmigazete.gov.tr
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Personal Data Protection Authority, and it is fully up and running. In 2025 its board met 42 times, took 2,528 decisions and handled 12,512 complaints. It fined 876 organisations a combined 352.5 million lira, which is roughly 8 million US dollars. It publishes named breach announcements most weeks. Financial, telecoms and insurance regulators enforce their own rules alongside it. A new Cybersecurity Directorate has taken over the national cyber incident centre.
We rate enforcement as active rather than aggressive. The volume is high, but individual fines are modest by European standards. And the biggest single block of penalties is for failing to register, not for mishandling data. The 2025 numbers come from the Authority's own annual report. 876 organisations were fined. Of those, 140 came from complaints and tip-offs, 142 from breach reports and 594 from register failures. Fines totalled 352,510,494 lira. Of that, 216,860,000 lira was register-related. 328 new breach files were opened in 2025, and 32 of them were against companies based outside Turkey. The Authority also asked 42 public bodies to discipline the staff responsible. Its output in 2026 continues. Binding principle decisions came in February, May and July 2026. A compliance guide for public bodies came in July 2026. Named breach announcements were still being published in August 2026. On the security side, Presidential Decree No 177 of 8 January 2025 created the Cybersecurity Directorate. Law No 7545 of 19 March 2025 gave it powers. By 2026 the national cyber incident response centre's services had moved onto the Directorate's site.
Sources
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“2025 yili icerisinde 140'i ihbar ve sikayetler, 142'si veri ihlal bildirimi ve 594'u Veri Sorumlulari Siciline kayit ve bildirim yukumlulugu kapsaminda olmak uzere toplam 876 veri sorumlusu hakkinda uygulanan idari para cezasinin miktari toplam 352.510.494 TL olarak gerceklesmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuAnnouncements page of the Personal Data Protection Authority, showing principle decisions and named breach notices through August 2026
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
“7545 Sayili Siber Guvenlik Kanunu [Kanun] 19.03.2025”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi / USOMNational Cyber Incident Response Centre notice — its functions moved to the Cybersecurity Directorate
usom.gov.tr
“Siber Guvenlik Baskanligi; 177 sayili Cumhurbaskanligi Kararnamesi ve 12.03.2025 tarihli, 7545 sayili Siber Guvenlik Kanunu uyarinca ... kurulmustur.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both directions apply, and the maximum is unusual. Turkey does not give you a fixed number of months to delete by. Instead, once your reason for holding data runs out, you must erase it at your next scheduled clear-out. Any organisation on the public register must publish a written keeping and destruction policy that sets those dates. The minimum comes from ordinary commercial and tax law, which makes you keep books and invoices for years.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep records of how you use data
MAXIMUM. The Regulation on Deletion, Destruction or Anonymisation of Personal Data applies to any organisation that must register. You must have a written policy on keeping and destroying personal data. You must erase, destroy or anonymise data at the first scheduled destruction run after the duty to delete arose. So the gap between destruction runs is the real deadline. You set that gap yourself, in your own policy. There is no single national number. MINIMUM. General Turkish commercial and tax law makes you keep business records for a number of years. Industry regulators impose their own record-keeping periods on banks, payment institutions, insurers and telecoms operators. WHICH RULE WINS. Where the two collide, the keeping duty in the specific law wins and you must keep the data. But you must then lock it down. You may use it only for the purpose that justified keeping it. We did not verify the individual commercial and tax periods against a government source. Treat those numbers as unconfirmed.
Sources
- Official sourceKisisel Verileri Koruma KurumuDeletion, destruction and anonymisation of personal data — the Authority's explainer of the periodic destruction duty
kvkk.gov.tr
“kisisel veri saklama ve imha politikasi hazirlamis olan veri sorumlusu, kisisel verileri silme, yok etme veya anonim hale getirme yukumlulugunun ortaya ciktigi tarihi takip eden ilk periyodik imha isleminde, kisisel verileri siler, yok eder veya anonim hale getirir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are at least three deadlines. The privacy one is 72 hours. From the moment you learn that data has been taken unlawfully, you have three days to tell the Personal Data Protection Board. You must also tell the affected people as soon as you reasonably can. If you miss the 72 hours you must still report, and explain why you were late. Companies based abroad have to report too, if people in Turkey are affected.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
DEADLINE ONE. Board Decision 2019/10 of 24 January 2019 reads the law's phrase 'as soon as possible' as 72 hours from becoming aware. You use the Authority's published breach form. You can supply information in stages if you do not have it all at once. You must tell people directly where you have their contact details. Otherwise use a suitable method, such as a notice on your own website. If a company handling data for you suffers the breach, it must tell you without any delay. A company based abroad must report on the same terms, where the effects hit people in Turkey who use its goods or services. DEADLINE TWO. Cyber incidents go to the Cybersecurity Directorate. Since 2025 it holds the national incident response role. It has taken over the national cyber incident response centre's services. We did not verify a specific number of hours. DEADLINE THREE. Financial regulators run their own incident reporting for banks, payment institutions and electronic money institutions. Overlapping deadlines are where people usually come unstuck. Everyone remembers the 72-hour privacy report. The regulator-specific ones are the ones people miss.
Sources
- Official sourceKisisel Verileri Koruma KurumuBoard Decision 2019/10 of 24 January 2019 on breach notification procedure — the 72-hour clock
kvkk.gov.tr
“veri sorumlusunun bu durumu ogrendigi tarihten itibaren gecikmeksizin ve en gec 72 saat icinde Kurula bildirmesine, ... ilgili kisilere de makul olan en kisa surede ... bildirim yapilmasina”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuBoard Decision 2019/10 of 24 January 2019 on breach notification procedure — the 72-hour clock
kvkk.gov.tr
“Veri ihlalinin yurtdisinda yerlesik veri sorumlusu nezdinde yasanmasi halinde, bu ihlalin sonuclarinin Turkiye'de yerlesik ilgili kisileri etkilemesi ve ilgili kisilerin sunulan urun ve hizmetlerden Turkiye'de faydalanmalari durumunda, bu veri sorumlusu tarafindan da ayni esaslar cercevesinde Kurula bildirimde bulunulmasina”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi / USOMNational Cyber Incident Response Centre notice — its functions moved to the Cybersecurity Directorate
usom.gov.tr
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. One: most fines are for paperwork, not privacy. Two thirds of the organisations fined in 2025 were punished over the public register, not for mishandling anyone's data. Two: the one-off permission route for sending data abroad is close to a dead end. In 2025, 76 of 89 applications were refused. Three: filing your standard contract invites inspection rather than closing the file. Four: your representative in Turkey must be Turkish. Five: no country is on the safe list, so there is no shortcut.
- What you have to do here:
- Register or notify · Appoint a representative · Put a transfer safeguard in place
- What it costs if you get it wrong:
- Criminal liability
(1) In 2025, 594 of the 876 organisations fined were fined over the public data register. That accounted for 216.86 million lira of the 352.5 million lira total. It works out at roughly 365,000 lira each. The Authority says plainly that it keeps taking action against companies resident abroad, as well as Turkish ones. (2) Written undertakings plus Board permission. 90 submitted, 89 decided, 13 allowed, 76 refused. If your transfer plan depends on this route, assume it fails. (3) Standard contracts must be filed within five working days. In 2025 the Authority turned 70 of the 2,497 filings into its own investigations, and fined three organisations. Filing a faulty or unsigned contract triggers a formal review by law. (4) The representative must be a company established in Turkey, or a Turkish citizen. A regional office in another country will not do. (5) No country, industry or international organisation has been declared safe enough. So a European company cannot rely on Turkey treating the European Union as safe. Separately, Turkish law makes some things criminal offences. Those include unlawfully recording personal data, passing it on, and failing to delete it. Those offences can reach individuals, not only the company. We did not verify the current text of those offences.
Sources
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“01.01.2025-31.12.2025 tarihi itibariyle Sicile kayit yukumlulugunu suresinde yerine getirmeyen 594 veri sorumlusu hakkinda toplam 216.860.000 TL idari para cezasi uygulanmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“Kuruma intikal eden standart sozlesme bildirimleri hakkinda yapilan degerlendirme neticesinde 70'i ile ilgili olarak Kanun'un 15'inci maddesinin birinci fikrasi uyarinca resen inceleme baslatilarak 21'i sonuclandirilmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
Link checked 18 August 2026
What's changing next
Two dated items, and one trend. Retailers running loyalty cards have until 28 February 2027 to build a way of checking that the person at the till really owns the card. The regulator extended the original deadline in July 2026. Public bodies are working to a July 2026 ruling on what they may publish online. And the government is pushing openly on keeping data in Turkey. The President chaired a cyber security meeting in May 2026 that treated data as a strategic asset.
- Ways to send data out:
- Official 'this country is safe' decision
DATED. (a) Principle Decision 2026/266, published on 28 February 2026, gave organisations six months to fix loyalty-card checkout processes. Board Decision 2026/1491 of 22 July 2026 pushed that deadline out to 28 February 2027. (b) Principle Decision 2026/1301 of 1 July 2026 governs how public bodies may publish personal data on the internet. A public explainer followed on 27 July 2026, and a compliance guide for public bodies on 28 July 2026. (c) Principle Decision 2026/1095 of 20 May 2026 covers the use of accident victims' personal data. POWERS THAT COULD CHANGE THINGS WITH NO CONSULTATION. The Board can declare a country, an industry within a country, or an international organisation safe enough at any time. It can also suspend or cancel such a decision for the future. It reviews them every four years. The Board can add or remove exemptions from the public register by decision. It did that on 4 September 2025, for very small businesses whose main activity is handling sensitive data. And the central bank has an express power to stop payment institutions sharing data abroad, or to add further limits. It can use that whenever it judges that the payments market is being harmed. More rules under the 2025 Cybersecurity Law are still being issued. Procurement rules came in April 2026.
Sources
- Official sourceKisisel Verileri Koruma KurumuPublic announcement of 13 August 2026 extending the loyalty-card compliance deadline to 28 February 2027 (Board Decision 2026/1491)
kvkk.gov.tr
“uyum suresinin 28.02.2027 tarihine kadar uzatilmasina”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
“Ayrica, veri egemenligi konusu ayri bir baslik altinda ele alinmistir. Verinin yalnizca teknik bir unsur olmanin otesinde, ayni zamanda stratejik bir deger oldugu belirtilmis; bu kapsamda dijital egemenlik yaklasiminin guclendirilmesi yonundeki kararlilik teyit edilmistir.”
Link checked 18 August 2026
- Official sourceTurkiye Cumhuriyet Merkez Bankasi (Central Bank of the Republic of Turkiye)Communique on the Information Systems of Payment and Electronic Money Institutions, Official Gazette 1 December 2021 No 31676, article 21
tcmb.gov.tr
“Banka, yapacagi degerlendirme neticesinde odemeler alaninin gelisimini olumsuz etkileyecegine karar vermesi durumunda, bu fikra uyarinca yapilan paylasimlari durdurabilir veya bunlara iliskin ilave sinirlandirma getirebilir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
Link checked 18 August 2026
What to do: Diarise 28 February 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Payments data needs a copy kept in the country
Official name: Odeme ve Elektronik Para Kuruluslarinin Bilgi Sistemleri ile Odeme Hizmeti Saglayicilarinin Odeme Hizmetleri Alanindaki Veri Paylasim Servislerine Iliskin Teblig · Official Gazette, 1 December 2021, No 31676, article 21; paragraph 4 added 7 October 2023 · Regulator directive
This is the strictest rule in Turkey. Payment and electronic money institutions must keep their main systems, their standby systems and their backups inside the country. Their outsourcing providers must do the same. Since October 2023 a narrow amount of data may be shared abroad for a cross-border payment. But the data itself must still stay stored in Turkey.
Enforced by Central Bank of the Republic of Turkiye
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryPrimary systems, secondary systems and data backup centres must all be inside Turkey. Where an outsourcing provider is used, that provider's systems and backups must be in Turkey too.
- Written vendor contractYou may only use community cloud from outsourcing providers the central bank has assessed as suitable. Six were on the published list as at 10 January 2025.
- Put a transfer safeguard in place — from 7 October 2023Since October 2023 a firm may share only the data a cross-border payment actually needs. The customer must ask for it or instruct it. The data must still be stored in Turkey. And the privacy law's transfer rules must also be met.
- Independent audit
What it costs if you get it wrong
- Loss of your licence: Supervisory action by the central bank under Law No 6493, up to withdrawal of the operating licenceOperating payment systems outside Turkey or using an unapproved cloud provider
Sources
- Official sourceTurkiye Cumhuriyet Merkez Bankasi (Central Bank of the Republic of Turkiye)Communique on the Information Systems of Payment and Electronic Money Institutions, Official Gazette 1 December 2021 No 31676, article 21
tcmb.gov.tr
“Kuruluslarin birincil ve ikincil sistemleri ile veri yedekleme merkezlerini yurt icinde bulundurmalari zorunludur.”
Link checked 18 August 2026
- Official sourceTurkiye Cumhuriyet Merkez Bankasi (Central Bank of the Republic of Turkiye)Communique on the Information Systems of Payment and Electronic Money Institutions, Official Gazette 1 December 2021 No 31676, article 21
tcmb.gov.tr
“Ayni kurulusun musterileri ya da farkli kuruluslarin musterileri arasindaki odeme islemlerinin yurutulmesinde kullanilan tum bilgi sistemleri ve bunlarin yedeklerinin yurt icinde bulunmasi esastir. Bu kapsamda dis hizmet alinmasi halinde, dis hizmet saglayicinin soz konusu hizmete iliskin faaliyetleri yurutmede kullandigi bilgi sistemleri ve bunlarin yedekleri de yurt icinde tutulur.”
Link checked 18 August 2026
- Official sourceTurkiye Cumhuriyet Merkez BankasiList of outsourcing providers approved to supply community cloud services to payment and electronic money institutions, 10 January 2025
tcmb.gov.tr
“Topluluk Bulutu Hizmeti Sunabilmesi Icin Uygunluk Verilen Dis Hizmet Saglayicilar”
Link checked 18 August 2026
Banking data must stay in the country
Official name: Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik · Listed on the Banking Regulation and Supervision Agency's own legislation index; article numbering not verified in this run · Directly binding regulation
Banking is the second strictest area. Three sets of rules decide where a bank's systems and customer data may sit. The agency's information systems regulation, its outsourcing regulation, and its rules on sharing confidential information. The market works on the assumption that the main and standby systems stay in Turkey. Confidence is low, because we could not reach the text itself.
Enforced by Banking Regulation and Supervision Agency
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryBanks are generally understood to have to keep their main and standby information systems in Turkey. Separate rules cover sharing customer secrets. We could not open the article text.
- Extra vendor secrecy termsBanking secrecy sits on top of the privacy law. Customer information is protected by the Banking Law as well. So a standard supplier contract is not enough.
What it costs if you get it wrong
- Loss of your licence: Supervisory measures under the Banking Law, up to restriction or withdrawal of the licencePlacing banking systems or customer secrets outside Turkey without authority
Sources
- Official sourceBankacilik Duzenleme ve Denetleme Kurumu (Banking Regulation and Supervision Agency)Legislation index of the Banking Regulation and Supervision Agency, listing the Regulation on Banks' Information Systems and Electronic Banking Services
bddk.org.tr
Link checked 18 August 2026
Telecoms rules
Official name: Elektronik Haberlesme Sektorunde Kisisel Verilerin Islenmesi ve Gizliligin Korunmasina Iliskin Yonetmelik · Listed on the Information and Communication Technologies Authority's regulations index; consolidated text at the Presidency legislation system, reference 38663 · Directly binding regulation
Telecoms operators answer to their own regulator as well as to the general privacy law. There is a dedicated regulation on personal data and confidentiality in the electronic communications sector. That is the layer covering call records, traffic data and location data.
Enforced by Information and Communication Technologies Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryTelecoms operators are widely reported to have to hold subscriber traffic and location data inside Turkey. We could not open the regulation's text. Treat the duty to store in Turkey as unconfirmed.
- Keep logsTraffic data retention periods are set by telecoms and internet legislation rather than by the privacy law.
- Secure the data
Sources
- Official sourceBilgi Teknolojileri ve Iletisim Kurumu (Information and Communication Technologies Authority)Regulations index of the Information and Communication Technologies Authority, listing the Regulation on Processing of Personal Data and Protection of Privacy in the Electronic Communications Sector
btk.gov.tr
Link checked 18 August 2026
- Official sourceLink may be brokenCumhurbaskanligi Mevzuat Bilgi Sistemi (Presidency Legislation Information System)Regulation on Processing of Personal Data and Protection of Privacy in the Electronic Communications Sector — official consolidated text
mevzuat.gov.tr
Link checked 18 August 2026
- Official sourceBilgi Teknolojileri ve Iletisim KurumuNetwork and information security legislation page — Regulation on Network and Information Security in the Electronic Communications Sector, Official Gazette 13 July 2014 No 29059
btk.gov.tr
“haberlesme ve sebeke guvenligine iliskin hususlar temel olarak 13/07/2014 tarihli 29059 sayili Resmi Gazete'de yayimlanarak yururluge giren Elektronik Haberlesme Sektorunde Sebeke ve Bilgi Guvenligi Yonetmeligi'nde duzenlenmistir”
Link checked 18 August 2026
Cyber security rules
Official name: 7545 sayili Siber Guvenlik Kanunu · Law No 7545, adopted 12 March 2025, Official Gazette 19 March 2025 No 32846 · Act of parliament
A new national cybersecurity law, in force since 19 March 2025. It covers public bodies, professional bodies, private organisations and critical infrastructure. It created a central authority with audit and certification powers. It carries both fines and criminal penalties.
Enforced by Cybersecurity Directorate
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Report cyber incidentsThe Cybersecurity Directorate runs national incident detection and response. It has taken over the national cyber incident response centre's services. We did not verify a specific reporting deadline in hours.
- Hold a security certificateThe law sets up audit, certification, authorisation and standardisation machinery for the cybersecurity market.
- Independent audit
What it costs if you get it wrong
- Criminal liability: The Directorate describes the law as carrying deterrent administrative and criminal sanctions; individual sentence lengths were not verified in this runBreaching duties owed under the Cybersecurity Law
Sources
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
“7545 Sayili Siber Guvenlik Kanunu [Kanun] 19.03.2025”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
“Soz konusu Kanun, 19/03/2025 tarihli ve 32846 sayili Resmi Gazete'de yayimlanarak yururluge girmistir.”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi / USOMNational Cyber Incident Response Centre notice — its functions moved to the Cybersecurity Directorate
usom.gov.tr
Link checked 18 August 2026
- Official sourceLink may be brokenCumhurbaskanligi Mevzuat Bilgi SistemiCybersecurity Law No 7545, Official Gazette 19 March 2025 No 32846 — official consolidated text
mevzuat.gov.tr
Link checked 18 August 2026
Cyber security rules (Government)
Official name: 2019/12 sayili Bilgi ve Iletisim Guvenligi Tedbirleri Genelgesi ve Bilgi ve Iletisim Guvenligi Rehberi · Presidential Circular 2019/12 of 6 July 2019; the implementing guide's current version is dated 1 March 2026 · Regulator directive
If you sell to the Turkish state or run critical infrastructure, this is the rule that decides where the data sits. A 2019 presidential circular and the security guide issued under it require public sector and critical infrastructure data to stay on systems inside Turkey. The Cybersecurity Directorate actively maintains that guide.
Enforced by Cybersecurity Directorate
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryPublic bodies and critical infrastructure operators must keep their data on systems inside Turkey, and under their own control. We could not open the circular's text. We state this duty at medium confidence.
- Prove the data stays under local control
- Independent auditCompliance is checked against the guide, which has its own audit guide, forms and templates, all refreshed in 2026.
- Hold a security certificateThe Directorate publishes a mapping table between the guide's controls and the ISO/IEC 27001 information security standard.
Sources
- Official sourceSiber Guvenlik BaskanligiCybersecurity Directorate document index — Information and Communication Security Guide, version dated 1 March 2026
siberguvenlik.gov.tr
“Bilgi ve Iletisim Guvenligi Rehberi”
Link checked 18 August 2026
- Official sourceSiber Guvenlik BaskanligiCybersecurity Directorate document index — Information and Communication Security Guide, version dated 1 March 2026
siberguvenlik.gov.tr
“Bilgi ve Iletisim Guvenligi Denetim Rehberi”
Link checked 18 August 2026
- Official sourceSiber Guvenlik Baskanligi (Cybersecurity Directorate)Cybersecurity Directorate site data feed — legislation list (Cybersecurity Law No 7545, 19 March 2025) and news, read live on 18 August 2026
cdn.siberguvenlik.gov.tr
Link checked 18 August 2026
Health data rules
Official name: Kisisel Saglik Verileri Hakkinda Yonetmelik · Listed on the Ministry of Health's General Directorate of Health Information Systems regulations page, alongside the Regulation on Health Information Management Systems · Directly binding regulation
Health data carries two layers. It is sensitive data under the general privacy law. And the Ministry of Health runs its own regulation on personal health data, plus a national health data system that providers feed. We could not open that regulation's text. So we make no claim either way about storing health data in Turkey.
Enforced by Ministry of Health, General Directorate of Health Information Systems
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Secure the data
- Get consentHealth data is sensitive data under the general law. That means a stricter list of legal reasons for using it than for ordinary personal data.
- Register or notify
Sources
- Official sourceT.C. Saglik Bakanligi (Ministry of Health)Regulations page of the General Directorate of Health Information Systems, listing the Regulation on Personal Health Data and the Regulation on Health Information Management Systems
sbsgm.saglik.gov.tr
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Sigortacilik Destek Hizmetleri Hakkinda Yonetmelik · Amending regulation published 23 July 2026, per the agency's own legislation index; base regulation text not verified in this run · Directly binding regulation
Insurers and pension companies answer to their own regulator for outsourcing and internal systems. The support services regulation was amended as recently as 23 July 2026. If you are placing insurance data with a supplier, check the current text rather than an older summary.
Enforced by Insurance and Private Pension Regulation and Supervision Agency
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractInsurers' use of outside suppliers, including anyone hosting their systems, is regulated separately from the privacy law.
- Independent audit
Sources
- Official sourceSigortacilik ve Ozel Emeklilik Duzenleme ve Denetleme KurumuInsurance regulations index of the Insurance and Private Pension Regulation and Supervision Agency, showing the Insurance Support Services Regulation amended on 23 July 2026
seddk.gov.tr
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: 6698 sayili Kisisel Verilerin Korunmasi Kanunu · Law No 6698 of 24 March 2016, cross-border transfer article replaced by Law No 7499 of 12 March 2024 · Act of parliament
Turkey's general privacy law. Since 1 June 2024 sending data abroad follows three steps. An official finding that the destination protects data well enough. Or an approved safeguard, such as a standard contract. Or one of a short list of one-off exceptions. No destination has ever been found safe enough. So everyone lives on the safeguards.
Enforced by Personal Data Protection Authority
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life
What you have to do
- Get consentExplicit consent is the default reason for using data. A short list of alternatives exists. Sensitive data has its own, stricter list.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours, from 24 January 2019
- Tell affected people
- Put a transfer safeguard in place — from 1 June 2024The old rule let explicit consent carry routine transfers. It was replaced on 1 June 2024 by the three-step approach: a safe-country finding, then safeguards, then one-off exceptions.
What it costs if you get it wrong
- Fixed maximum fine: Ceilings are set by article 18 and raised every January in line with the official revaluation rate; the 2026 figures were not verified in this run. Across all controllers in 2025 the Board imposed 352,510,494 lira.Failing to give notice, failing to keep data secure, ignoring a Board decision, or failing to register
- Criminal liability: Prison sentences under the Turkish Penal Code for unlawfully recording, transferring or failing to delete personal data; text not verified in this runUnlawful recording, transfer or retention of personal data
Sources
- Official sourceKisisel Verileri Koruma Kurumu (Personal Data Protection Authority)Transferring personal data abroad — the Authority's own explainer of the staged regime introduced on 1 June 2024
kvkk.gov.tr
“Kanunun ... 9 uncu maddesinde degisiklikler yapilmis ve yapilan degisiklikler 01.06.2024 tarihinde yururluge girmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuBoard Decision 2019/10 of 24 January 2019 on breach notification procedure — the 72-hour clock
kvkk.gov.tr
Link checked 18 August 2026
Government data rules
Official name: Kisisel Verilerin Yurt Disina Aktarilmasina Iliskin Usul ve Esaslar Hakkinda Yonetmelik · Official Gazette, 10 July 2024 · Directly binding regulation
The rulebook for sending data abroad. The sharpest part is administrative. Sign one of the government's standard contracts and you must tell the regulator within five working days. That filing gets read, not shelved. In 2025, 2,497 contracts were filed and 70 turned into investigations.
Enforced by Personal Data Protection Authority
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Approved group rules, Government sign-off needed
What you have to do
- Put a transfer safeguard in placeBoard Decision 2024/959 of 4 June 2024 adopted four standard contract templates. It also adopted application forms and guides for company-wide rules.
- Keep records of how you use dataA signed standard contract must be notified to the Authority within five working days of the last signature, on paper or by registered electronic mail.
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine under article 18(1)(d) of Law 6698 for failing to make the notification; three organisations were fined a combined 150,000 lira in 2025Not filing the standard contract, or filing one that is altered or unsigned
Sources
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“standart sozlesmeler, imzalarin tamamlanmasindan itibaren bes is gunu icinde ... Kuruma bildirilir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuThe four published standard contracts for transfers abroad
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuBinding corporate rules application forms and guides
kvkk.gov.tr
Link checked 18 August 2026
- Official sourceLink may be brokenResmi Gazete (Official Gazette)Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, Official Gazette 10 July 2024
resmigazete.gov.tr
Link checked 18 August 2026
Data rules
Official name: Veri Sorumlulari Sicili Hakkinda Yonetmelik · Official Gazette, 30 December 2017, amended 28 April 2019 · Directly binding regulation
Turkey's public data register, and the single biggest source of fines in the country. Foreign companies must appoint a representative based in Turkey. They must register before they start using the data. Unlike Turkish small businesses, they get no size exemption.
Enforced by Personal Data Protection Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — from 1 October 2018You must finish registering before you start using the data. Companies resident abroad had to register by 31 December 2021, with no size threshold.
- Appoint a representativeThe representative must be a legal person established in Turkey or a Turkish citizen.
- Keep records of how you use dataThe register entry lists data categories, purposes, keeping periods, security measures, who receives the data, and what you plan to send abroad.
What it costs if you get it wrong
- Fixed maximum fine: 594 controllers were fined a combined 216,860,000 lira in 2025, an average of about 365,000 lira (roughly 8,000 US dollars) eachNot registering, or not keeping the register entry up to date
Sources
- Official sourceKisisel Verileri Koruma KurumuRegulation on the Registry of Data Controllers (VERBIS), article 11 — non-resident controllers register through a Turkey-based representative
kvkk.gov.tr
“Turkiye'de yerlesik olmayan veri sorumlulari, veri islemeye baslamadan once veri sorumlusu temsilcisi marifetiyle Sicile kaydolmak zorundadir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma Kurumu2025 Annual Activity Report of the Personal Data Protection Authority (enforcement, transfer and registry statistics)
kvkk.gov.tr
“Sicile kayit yukumlulugunu suresinde yerine getirmeyen 594 veri sorumlusu hakkinda toplam 216.860.000 TL idari para cezasi uygulanmistir.”
Link checked 18 August 2026
- Official sourceKisisel Verileri Koruma KurumuExemptions from the duty to register
kvkk.gov.tr
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The article of the Banking Regulation and Supervision Agency's information systems regulation that requires banks' primary and secondary systems to be located in Turkey
We could not confirm which article requires banks to keep their main and standby systems in Turkey. The agency's own legislation index shows the regulation exists. But its document server, the Official Gazette site and the Presidential legislation system were all unreachable, so we could not read the wording. We record the banking rule at low confidence. If you are a bank, get the text from your regulator.
That telecoms operators must hold subscriber traffic and location data inside Turkey
We could not confirm that telecoms operators must hold subscriber traffic and location data inside Turkey. The Information and Communication Technologies Authority's own index lists the relevant regulation. But its text sits on the Presidential legislation system, which we could not open. The duty is widely reported. Check it with the regulator before you rely on it.
The wording of Presidential Circular 2019/12 on information and communication security, including the requirement that public sector and critical infrastructure data stay on systems inside Turkey
We could not confirm the wording of Presidential Circular 2019/12 on information and communication security. That includes the requirement for public sector and critical infrastructure data to stay on systems inside Turkey. The Official Gazette was unreachable, and the Cybersecurity Directorate's document server refused to hand over the guide. We did verify that the guide exists and its current version date, from the Directorate's own site.
The exact administrative fine ceilings under article 18 of Law 6698 for 2026
We could not confirm the exact maximum fines under article 18 of Law 6698 for 2026. They rise each January with the official revaluation rate, and we found no current table on the Authority's site. So we quote only the totals actually imposed in 2025.
Whether any health-sector or insurance-sector rule requires data to stay inside Turkey
We found no health or insurance rule requiring data to stay inside Turkey, checked 18 August 2026. Confidence is medium. The Ministry of Health and the insurance regulators list their rules publicly, but the texts sit on the Presidential legislation system, which we could not open. If you handle health or insurance data, check before you rely on this.
Criminal liability for unlawfully recording, transferring or failing to delete personal data
We could not confirm the criminal penalties for unlawfully recording personal data, passing it on, or failing to delete it. Turkish criminal law is understood to carry prison sentences for these acts, and the privacy law points to them. But we did not open the criminal code text. Assume individuals can be prosecuted and get local advice.
US dollar approximations in this record
We converted at roughly 45 Turkish lira to the dollar, to give you a sense of scale. We did not check that rate against an official source on 18 August 2026. Treat every dollar figure as indicative only.
Whether any official “this country is safe” decision was made between the last update of the Authority's transfer page and 18 August 2026
We could not confirm that no country has been declared safe enough since the Authority last updated its transfer page. That page said on 18 August 2026 that no such decision had been made, and nothing to the contrary appeared in its announcements. Check the page before you plan a transfer.
Draft amendments listed on the banking regulator's site to the information systems regulation and to the rules on sharing confidential information
We could not confirm what draft amendments the banking regulator is working on. Drafts appeared in its legislation index, covering the information systems regulation and the rules on sharing confidential information. We could not date or read them, so we say nothing about what they contain.
Whether securities firms face an information systems localisation rule
We could not confirm whether securities firms must keep their information systems in Turkey. The Capital Markets Board's site is built for browsers and we could not read its legislation pages. We did not research this to a conclusion. Treat the securities industry as unassessed and check with the Board.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.