Skip to the content
Global Data RulesData governance rules, country by country

Turkey

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Turkey — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Turkey lets personal data leave, but only after you build the paperwork yourself. The regulator has never declared a single country safe, so the approved-destination list is empty. Most companies use a government-published standard contract. You must file that contract within five working days. The regulator is busy: it fined 876 organisations in 2025.

Data governance in Turkey

The eight things that decide how you handle data about people in Turkey. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. A company with no office in Turkey is still caught. In fact it is caught harder than a local one. Say you are based outside Turkey and you decide why and how Turkish people's data is used. You must appoint a representative inside Turkey. You must also sign up to Turkey's public data register before you start using the data. That representative has to be a company set up in Turkey, or a Turkish citizen. Turkish small businesses can skip the register if they have fewer than 50 staff and a balance sheet under 100 million lira. There is no such let-off for foreign companies.

What you have to do here:
Appoint a representative · Register or notify

Where the data is allowed to live

It depends entirely on your industry. That is why Turkey's answer changes from one industry to the next. Under the general privacy law data may leave, but only after you put an approved safeguard in place. That is because the regulator has not yet declared any country safe. In payments and banking the answer flips to no. Systems, backups and data have to sit inside Turkey. Public bodies, critical infrastructure, telecoms networks and health records all carry their own extra restrictions on top.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

The model is a list of approved destination countries, and that list is empty. Nobody can rely on their country being approved. So almost everyone uses one of the safeguards instead. The usual route is signing one of four standard contracts the regulator publishes. You then have to tell the regulator within five working days of signing. Group companies can instead get company-wide rules approved. There is also a permission route for one-off written undertakings, but that route almost always fails.

Ways to send data out:
Standard contract clauses · Approved group rules · Government sign-off needed · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Personal Data Protection Authority, and it is fully up and running. In 2025 its board met 42 times, took 2,528 decisions and handled 12,512 complaints. It fined 876 organisations a combined 352.5 million lira, which is roughly 8 million US dollars. It publishes named breach announcements most weeks. Financial, telecoms and insurance regulators enforce their own rules alongside it. A new Cybersecurity Directorate has taken over the national cyber incident centre.

How long you must keep it — and when to delete it

Both directions apply, and the maximum is unusual. Turkey does not give you a fixed number of months to delete by. Instead, once your reason for holding data runs out, you must erase it at your next scheduled clear-out. Any organisation on the public register must publish a written keeping and destruction policy that sets those dates. The minimum comes from ordinary commercial and tax law, which makes you keep books and invoices for years.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are at least three deadlines. The privacy one is 72 hours. From the moment you learn that data has been taken unlawfully, you have three days to tell the Personal Data Protection Board. You must also tell the affected people as soon as you reasonably can. If you miss the 72 hours you must still report, and explain why you were late. Companies based abroad have to report too, if people in Turkey are affected.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. One: most fines are for paperwork, not privacy. Two thirds of the organisations fined in 2025 were punished over the public register, not for mishandling anyone's data. Two: the one-off permission route for sending data abroad is close to a dead end. In 2025, 76 of 89 applications were refused. Three: filing your standard contract invites inspection rather than closing the file. Four: your representative in Turkey must be Turkish. Five: no country is on the safe list, so there is no shortcut.

What you have to do here:
Register or notify · Appoint a representative · Put a transfer safeguard in place
What it costs if you get it wrong:
Criminal liability

What's changing next

Two dated items, and one trend. Retailers running loyalty cards have until 28 February 2027 to build a way of checking that the person at the till really owns the card. The regulator extended the original deadline in July 2026. Public bodies are working to a July 2026 ruling on what they may publish online. And the government is pushing openly on keeping data in Turkey. The President chaired a cyber security meeting in May 2026 that treated data as a strategic asset.

Ways to send data out:
Official 'this country is safe' decision

What to do: Diarise 28 February 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Payments

Payments data needs a copy kept in the country

Official name: Odeme ve Elektronik Para Kuruluslarinin Bilgi Sistemleri ile Odeme Hizmeti Saglayicilarinin Odeme Hizmetleri Alanindaki Veri Paylasim Servislerine Iliskin Teblig · Official Gazette, 1 December 2021, No 31676, article 21; paragraph 4 added 7 October 2023 · Regulator directive

In forceA copy must stay

This is the strictest rule in Turkey. Payment and electronic money institutions must keep their main systems, their standby systems and their backups inside the country. Their outsourcing providers must do the same. Since October 2023 a narrow amount of data may be shared abroad for a cross-border payment. But the data itself must still stay stored in Turkey.

In force since 1 December 2021

Enforced by Central Bank of the Republic of Turkiye

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Banking

Banking data must stay in the country

Official name: Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik · Listed on the Banking Regulation and Supervision Agency's own legislation index; article numbering not verified in this run · Directly binding regulation

In forceNo — it stays put

Banking is the second strictest area. Three sets of rules decide where a bank's systems and customer data may sit. The agency's information systems regulation, its outsourcing regulation, and its rules on sharing confidential information. The market works on the assumption that the main and standby systems stay in Turkey. Confidence is low, because we could not reach the text itself.

Enforced by Banking Regulation and Supervision Agency

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Telecoms

Telecoms rules

Official name: Elektronik Haberlesme Sektorunde Kisisel Verilerin Islenmesi ve Gizliligin Korunmasina Iliskin Yonetmelik · Listed on the Information and Communication Technologies Authority's regulations index; consolidated text at the Presidency legislation system, reference 38663 · Directly binding regulation

In forceYes, with paperwork

Telecoms operators answer to their own regulator as well as to the general privacy law. There is a dedicated regulation on personal data and confidentiality in the electronic communications sector. That is the layer covering call records, traffic data and location data.

Enforced by Information and Communication Technologies Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: 6698 sayili Kisisel Verilerin Korunmasi Kanunu · Law No 6698 of 24 March 2016, cross-border transfer article replaced by Law No 7499 of 12 March 2024 · Act of parliament

In forceYes, with paperwork

Turkey's general privacy law. Since 1 June 2024 sending data abroad follows three steps. An official finding that the destination protects data well enough. Or an approved safeguard, such as a standard contract. Or one of a short list of one-off exceptions. No destination has ever been found safe enough. So everyone lives on the safeguards.

In force since 7 April 2016Enforced from 1 June 2024

Enforced by Personal Data Protection Authority

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life

Government data rules

Official name: Kisisel Verilerin Yurt Disina Aktarilmasina Iliskin Usul ve Esaslar Hakkinda Yonetmelik · Official Gazette, 10 July 2024 · Directly binding regulation

In forceYes, with paperwork

The rulebook for sending data abroad. The sharpest part is administrative. Sign one of the government's standard contracts and you must tell the regulator within five working days. That filing gets read, not shelved. In 2025, 2,497 contracts were filed and 70 turned into investigations.

In force since 10 July 2024

Enforced by Personal Data Protection Authority

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Approved group rules, Government sign-off needed

Data rules

Official name: Veri Sorumlulari Sicili Hakkinda Yonetmelik · Official Gazette, 30 December 2017, amended 28 April 2019 · Directly binding regulation

In forceYes — store it anywhere

Turkey's public data register, and the single biggest source of fines in the country. Foreign companies must appoint a representative based in Turkey. They must register before they start using the data. Unlike Turkish small businesses, they get no size exemption.

In force since 1 January 2018Enforced from 31 December 2021

Enforced by Personal Data Protection Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Kisisel Verileri Koruma Kurumu

    General privacy law, cross-border transfers, breach notification, the controller register

    Fully operational. In 2025 the board held 42 meetings, took 2,528 decisions and handled 12,512 complaints. It opened 328 breach files and fined 876 organisations a total of 352,510,494 lira. It issued binding principle decisions in February, May and July 2026. It was still publishing named breach notices in August 2026.

  • Turkiye Cumhuriyet Merkez Bankasi

    Payment services, electronic money, payment system keeping data in the country

    It licenses and supervises payment and electronic money institutions. It maintains the approved community cloud provider list. It updates the industry's minimum capital figures every year, most recently in January 2026.

  • Bankacilik Duzenleme ve Denetleme Kurumu

    Banks' information systems, outsourcing and banking secrecy

    Active supervisor. We could reach its site only now and then. So we cite its rules at lower confidence than the central bank's.

  • Bilgi Teknolojileri ve Iletisim Kurumu

    Telecoms operators, subscriber and traffic data, network security, internet legislation

    Publishing sector bulletins and market analyses through 2026.

  • Sigortacilik ve Ozel Emeklilik Duzenleme ve Denetleme Kurumu

    Insurance and private pension companies, their outsourcing and internal systems

    Issuing regulations and circulars through July 2026.

  • Sermaye Piyasasi Kurulu

    Investment firms, exchanges and their information systems

    Active. It published decisions and press notices through August 2026. We did not verify its information systems rules.

  • Siber Guvenlik Baskanligi

    National cybersecurity, critical infrastructure, incident response, certification

    Created by Presidential Decree No 177 on 8 January 2025 and given powers by Law No 7545 on 19 March 2025. By 2026 it had taken over the national cyber incident response centre's services. It published a refreshed security guide dated 1 March 2026, and its own procurement rules in April 2026.

  • T.C. Saglik Bakanligi Saglik Bilgi Sistemleri Genel Mudurlugu

    Personal health data, hospital information systems, the national health record system

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The article of the Banking Regulation and Supervision Agency's information systems regulation that requires banks' primary and secondary systems to be located in Turkey

    We could not confirm which article requires banks to keep their main and standby systems in Turkey. The agency's own legislation index shows the regulation exists. But its document server, the Official Gazette site and the Presidential legislation system were all unreachable, so we could not read the wording. We record the banking rule at low confidence. If you are a bank, get the text from your regulator.

  • That telecoms operators must hold subscriber traffic and location data inside Turkey

    We could not confirm that telecoms operators must hold subscriber traffic and location data inside Turkey. The Information and Communication Technologies Authority's own index lists the relevant regulation. But its text sits on the Presidential legislation system, which we could not open. The duty is widely reported. Check it with the regulator before you rely on it.

  • The wording of Presidential Circular 2019/12 on information and communication security, including the requirement that public sector and critical infrastructure data stay on systems inside Turkey

    We could not confirm the wording of Presidential Circular 2019/12 on information and communication security. That includes the requirement for public sector and critical infrastructure data to stay on systems inside Turkey. The Official Gazette was unreachable, and the Cybersecurity Directorate's document server refused to hand over the guide. We did verify that the guide exists and its current version date, from the Directorate's own site.

  • The exact administrative fine ceilings under article 18 of Law 6698 for 2026

    We could not confirm the exact maximum fines under article 18 of Law 6698 for 2026. They rise each January with the official revaluation rate, and we found no current table on the Authority's site. So we quote only the totals actually imposed in 2025.

  • Whether any health-sector or insurance-sector rule requires data to stay inside Turkey

    We found no health or insurance rule requiring data to stay inside Turkey, checked 18 August 2026. Confidence is medium. The Ministry of Health and the insurance regulators list their rules publicly, but the texts sit on the Presidential legislation system, which we could not open. If you handle health or insurance data, check before you rely on this.

  • Criminal liability for unlawfully recording, transferring or failing to delete personal data

    We could not confirm the criminal penalties for unlawfully recording personal data, passing it on, or failing to delete it. Turkish criminal law is understood to carry prison sentences for these acts, and the privacy law points to them. But we did not open the criminal code text. Assume individuals can be prosecuted and get local advice.

  • US dollar approximations in this record

    We converted at roughly 45 Turkish lira to the dollar, to give you a sense of scale. We did not check that rate against an official source on 18 August 2026. Treat every dollar figure as indicative only.

  • Whether any official “this country is safe” decision was made between the last update of the Authority's transfer page and 18 August 2026

    We could not confirm that no country has been declared safe enough since the Authority last updated its transfer page. That page said on 18 August 2026 that no such decision had been made, and nothing to the contrary appeared in its announcements. Check the page before you plan a transfer.

  • Draft amendments listed on the banking regulator's site to the information systems regulation and to the rules on sharing confidential information

    We could not confirm what draft amendments the banking regulator is working on. Drafts appeared in its legislation index, covering the information systems regulation and the rules on sharing confidential information. We could not date or read them, so we say nothing about what they contain.

  • Whether securities firms face an information systems localisation rule

    We could not confirm whether securities firms must keep their information systems in Turkey. The Capital Markets Board's site is built for browsers and we could not read its legislation pages. We did not research this to a conclusion. Treat the securities industry as unassessed and check with the Board.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.