Skip to the content
Global Data RulesData governance rules, country by country

Turkey

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Turkey lets personal data leave, but only after you build the paperwork yourself. The regulator has never declared a single country safe, so the approved-destination list is empty. Most companies use a government-published standard contract and must file it within five working days. The regulator is busy: it fined 876 organisations in 2025.

Eight questions about Turkey

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Turkey's rules apply to my company?

Yes. A company with no office in Turkey is still caught, and it is caught harder than a local one. Any organisation based outside Turkey that decides why and how Turkish people's data is used must appoint a representative inside Turkey and sign up to the public register of data controllers before it starts processing. That representative has to be a company set up in Turkey or a Turkish citizen. Turkish small businesses can escape the register if they have fewer than 50 staff and a balance sheet under 100 million lira, but there is no such let-off for foreign companies.

High confidenceNational rulesAppoint a local representativeRegister or notify

Can I store my users' data outside Turkey?

It depends entirely on your industry, which is why Turkey is rated 'sectoral'. Under the general privacy law data may leave, but only after you put an approved safeguard in place, because the regulator has not yet declared any country safe. In payments and banking the answer flips to no: systems, backups and data have to sit inside Turkey. Public bodies, critical infrastructure, telecoms networks and health records all carry their own extra restrictions on top.

High confidenceDepends on your industryAllowlist

What do I need in place before data leaves Turkey?

The model is an approved-destination list, and the list is empty. Nobody can rely on their country being blessed, so almost everyone uses one of the safeguards instead. The usual route is signing one of four standard contracts the regulator publishes, then telling the regulator within five working days of signing. Group companies can instead get binding corporate rules approved, and there is a permission route for bespoke undertakings, but that route almost always fails.

High confidenceAllowlistStandard contract clausesApproved group rulesGovernment sign-off neededExplicit consent

Who enforces the rules in Turkey, and what can they do?

The Personal Data Protection Authority, and it is fully up and running. In 2025 its board met 42 times, took 2,528 decisions, handled 12,512 complaints and fined 876 organisations a combined 352.5 million lira, which is roughly 8 million US dollars. It publishes named breach announcements most weeks. Financial, telecoms and insurance regulators enforce their own rules alongside it, and a new Cybersecurity Directorate has taken over the national cyber incident centre.

High confidenceActive

How long do I have to keep the data?

Both directions apply, and the ceiling is unusual. Turkey does not give you a fixed number of months to delete by. Instead, once your reason for holding data runs out, you must erase it at your next scheduled clear-out, and any organisation on the public register has to publish a written retention and destruction policy setting those dates. The floor comes from ordinary commercial and tax law, which forces you to keep books and invoices for years.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep records of processing

What happens if there is a breach?

There are at least three clocks. The privacy one is 72 hours: from the moment you learn that data has been taken unlawfully, you have three days to tell the Personal Data Protection Board, and you must tell the affected people as soon as you reasonably can. If you miss the 72 hours you must still report and explain why you were late. Companies based abroad have to report too, if people in Turkey are affected.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Turkey?

Five things bite people. One: most fines are for paperwork, not privacy. Two thirds of the organisations fined in 2025 were punished for the public register, not for mishandling anyone's data. Two: the bespoke permission route for sending data abroad is close to a dead end, with 76 of 89 applications refused in 2025. Three: filing your standard contract invites inspection rather than closing the file. Four: your representative in Turkey must be Turkish. Five: no country is on the safe list, so there is no shortcut.

High confidenceRegister or notifyAppoint a local representativePut a transfer safeguard in placeCriminal liability

What is changing soon in Turkey?

Two dated items and one direction of travel. Retailers running loyalty cards have until 28 February 2027 to build a way of checking that the person at the till really owns the card, after the regulator extended the original deadline in July 2026. Public bodies are working to a July 2026 ruling on what they may publish online. And the government is pushing openly on data sovereignty, with the President chairing a cyber security meeting in May 2026 that treated data as a strategic asset.

High confidenceIn forceOfficial 'this country is safe' decision

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

6698 sayili Kisisel Verilerin Korunmasi Kanunu

Act of parliament · Law No 6698 of 24 March 2016, cross-border transfer article replaced by Law No 7499 of 12 March 2024

In forceYes, with paperwork

Turkey's general privacy law. Since 1 June 2024 sending data abroad follows three steps: an official finding that the destination is adequate, or an approved safeguard such as a standard contract, or one of a short list of one-off exceptions. No destination has ever been found adequate, so in practice everyone lives on the safeguards.

In force since 7 April 2016But only enforceable from 1 June 2024

Enforced by Personal Data Protection Authority

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk

High confidence

Kisisel Verilerin Yurt Disina Aktarilmasina Iliskin Usul ve Esaslar Hakkinda Yonetmelik

Directly binding regulation · Official Gazette, 10 July 2024

In forceYes, with paperwork

The rulebook for sending data abroad. Its sharpest edge is administrative: sign one of the government's standard contracts and you must tell the regulator within five working days, and that filing is read rather than shelved. In 2025, 2,497 contracts were filed and 70 turned into investigations.

In force since 10 July 2024

Enforced by Personal Data Protection Authority

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Standard contract clauses, Approved group rules, Government sign-off needed

High confidence

Veri Sorumlulari Sicili Hakkinda Yonetmelik

Directly binding regulation · Official Gazette, 30 December 2017, amended 28 April 2019

In forceYes — store it anywhere

The public register of data controllers, and the single biggest source of fines in Turkey. Foreign companies must appoint a Turkey-based representative and register before processing, and unlike Turkish small businesses they get no size exemption.

In force since 1 January 2018But only enforceable from 31 December 2021

Enforced by Personal Data Protection Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules7 rules

Odeme ve Elektronik Para Kuruluslarinin Bilgi Sistemleri ile Odeme Hizmeti Saglayicilarinin Odeme Hizmetleri Alanindaki Veri Paylasim Servislerine Iliskin Teblig

Regulator directive · Official Gazette, 1 December 2021, No 31676, article 21; paragraph 4 added 7 October 2023 · Payments

In forceA copy must stay

The hardest wall in Turkey. Payment and electronic money institutions must keep their main systems, their standby systems and their backups inside the country, and their outsourcing providers must do the same. Since October 2023 a narrow amount of data may be shared abroad for a cross-border payment, but only if the data itself stays stored in Turkey.

In force since 1 December 2021

Enforced by Central Bank of the Republic of Turkiye

Transfer model: Allowlist · Accepted routes: Government sign-off needed

High confidence

Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik

Directly binding regulation · Listed on the Banking Regulation and Supervision Agency's own legislation index; article numbering not verified in this run · Banking

In forceNo — it stays put

Banking is the second hard wall. The agency's information systems regulation, its outsourcing regulation and its rules on sharing confidential information together decide where a bank's systems and customer data may sit, and the working assumption in the market is that the main and standby systems stay in Turkey. Confidence is low because the text itself was unreachable.

Enforced by Banking Regulation and Supervision Agency

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Low confidence

Elektronik Haberlesme Sektorunde Kisisel Verilerin Islenmesi ve Gizliligin Korunmasina Iliskin Yonetmelik

Directly binding regulation · Listed on the Information and Communication Technologies Authority's regulations index; consolidated text at the Presidency legislation system, reference 38663 · Telecoms

In forceYes, with paperwork

Telecoms operators are policed by their own regulator on top of the general privacy law, under a dedicated regulation for personal data and confidentiality in the electronic communications sector. This is the layer that governs call records, traffic data and location data.

Enforced by Information and Communication Technologies Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

  • Kisisel Verileri Koruma Kurumu

    General privacy law, cross-border transfers, breach notification, the controller register

    Fully operational. In 2025 the board held 42 meetings, took 2,528 decisions, processed 12,512 complaints, opened 328 breach files and fined 876 organisations a total of 352,510,494 lira. It issued binding principle decisions in February, May and July 2026 and was publishing named breach notices in August 2026.

  • Turkiye Cumhuriyet Merkez Bankasi

    Payment services, electronic money, payment system data localisation

    Licenses and supervises payment and electronic money institutions, maintains the approved community cloud provider list and updates the sector's minimum capital figures annually, most recently in January 2026.

  • Bankacilik Duzenleme ve Denetleme Kurumu

    Banks' information systems, outsourcing and banking secrecy

    Active supervisor. Its site was reachable only intermittently from this environment, so its rules are cited at lower confidence than the central bank's.

  • Bilgi Teknolojileri ve Iletisim Kurumu

    Telecoms operators, subscriber and traffic data, network security, internet legislation

    Publishing sector bulletins and market analyses through 2026.

  • Sigortacilik ve Ozel Emeklilik Duzenleme ve Denetleme Kurumu

    Insurance and private pension companies, their outsourcing and internal systems

    Issuing regulations and circulars through July 2026.

  • Sermaye Piyasasi Kurulu

    Investment firms, exchanges and their information systems

    Active; publishing decisions and press notices through August 2026. Its information systems rules were not verified in this run.

  • Siber Guvenlik Baskanligi

    National cybersecurity, critical infrastructure, incident response, certification

    Created by Presidential Decree No 177 on 8 January 2025 and empowered by Law No 7545 on 19 March 2025. By 2026 it had absorbed the national cyber incident response centre's services, published a refreshed security guide dated 1 March 2026 and issued its own procurement rules in April 2026.

  • T.C. Saglik Bakanligi Saglik Bilgi Sistemleri Genel Mudurlugu

    Personal health data, hospital information systems, the national health record system

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The article of the Banking Regulation and Supervision Agency's information systems regulation that requires banks' primary and secondary systems to be located in Turkey

    The agency's own legislation index confirms the regulation exists, but its document server, the Official Gazette site and the Presidency legislation system were all unreachable from this environment, so the operative wording could not be read. The banking rule is therefore recorded at low confidence.

  • That telecoms operators must hold subscriber traffic and location data inside Turkey

    The Information and Communication Technologies Authority's own regulations index lists the relevant regulation, but its text sits on the Presidency legislation system, which could not be opened. The in-country storage duty is widely reported but was not verified against the instrument.

  • The wording of Presidential Circular 2019/12 on information and communication security, including the requirement that public sector and critical infrastructure data stay on systems inside Turkey

    The Official Gazette was unreachable and the Cybersecurity Directorate's document server refused direct downloads of the implementing guide. Existence and the guide's current version date were verified from the Directorate's own site; the wording was not.

  • The exact administrative fine ceilings under article 18 of Law 6698 for 2026

    The ceilings rise each January with the official revaluation rate and no current table was found on the Authority's site. Only the totals actually imposed in 2025 are quoted here.

  • Whether any health-sector or insurance-sector rule requires data to stay inside Turkey

    No such rule was found, checked 18 August 2026, confidence medium. The Ministry of Health and insurance regulators list their instruments publicly but the texts are hosted on the unreachable Presidency legislation system.

  • Criminal liability for unlawfully recording, transferring or failing to delete personal data

    Turkish criminal law is understood to carry prison sentences for these acts and the privacy law cross-refers to them, but the criminal code text was not opened in this run.

  • US dollar approximations in this record

    Converted at roughly 45 Turkish lira to the dollar. The rate was not verified against an official source on 18 August 2026, so treat dollar figures as indicative only.

  • Whether any adequacy decision was made between the last update of the Authority's transfer page and 18 August 2026

    The Authority's page said on 18 August 2026 that no determination had been made, and no announcement to the contrary appeared in its announcements list. A negative cannot be proved beyond that.

  • Draft amendments listed on the banking regulator's site to the information systems regulation and to the rules on sharing confidential information

    Draft versions appeared in the agency's legislation index but could not be dated or read, so nothing is asserted about them.

  • Whether securities firms face an information systems localisation rule

    The Capital Markets Board's site is built for browsers and its legislation pages could not be read from this environment. Not researched to conclusion; treat the securities sector as unassessed.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.