Skip to content
Questa e una traduzione di cortesia. La versione inglese e la versione ufficiale e giuridicamente vincolante. Visualizza versione inglese
EuropeMEDIUM coverage

Turkey Personal Data Protection Law (KVKK No. 6698) + AI Strategy 2021-2025: AI Compliance Requirements

Turkey's KVKK (Kişisel Verileri Koruma Kanunu, Law No. 6698) is Turkey's GDPR-equivalent, administered by the Personal Data Protection Authority (KVKK Board). While Turkey is not in the EU, KVKK aligns closely with GDPR principles and is a prerequisite for Turkish market access. Turkey's National AI Strategy 2021-2025 adds sector-specific AI obligations across finance (BRSA/BDDK), healthcare, and transportation. CYCLE 20 CORRECTION (2026-08-22): the prior "Turkey processed for EU adequacy decision as of 2026" framing was misleadingly incomplete — verified via Marpatas and KVKK's own public page that the European Commission already found Turkey's framework NOT adequate (decision of 2023-12-13), and KVKK's own site confirms no adequacy determination existed as of 2026-08-03; cross-border transfers instead run on the Law No. 7499 three-tier mechanism (adequacy/SCCs-BCRs/derogations) described in scopeDefinition. There is no pending positive EU adequacy process to be "processed for."

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

April 7, 2016

Enforcement Begins

October 1, 2018

Maximum Penalty

KVKK fine band, revalued ANNUALLY (2026 figures, effective 2026-01-01): disclosure-obligation failures TRY 85,437-1,709,200; data-security-obligation failures TRY 256,357-17,092,242; failure to comply with Board decisions TRY 427,263-17,092,242; VERBİS registration/notification violations TRY 341,809-17,092,242. Top of band ≈ $356,000 USD at 2026-08-22's ~48 TRY/USD rate — NOT a fixed figure; re-check annually. Plus criminal sanctions under Turkish Penal Code (TPC Art. 135-140); KVKK Board can suspend processing.

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Explicit Consent and Processing Conditions

Critical

KVKK Article 5 permits personal data processing only under explicit consent or specific lawful grounds (statutory obligation, contract, vital interests, legitimate interest). AI systems processing Turkish residents' data must obtain affirmative, specific consent for each processing purpose and maintain timestamped consent records.

KVKK (Law No. 6698), Art. 5

Data Controller Registry (VERBİS) Registration

Critical

KVKK Article 16 requires data controllers processing personal data to register in VERBİS (Veri Sorumluları Sicili Bilgi Sistemi) before commencing processing. Foreign companies processing Turkish resident data must also register. AI system data processing activities must be accurately declared in VERBİS.

KVKK (Law No. 6698), Art. 16

Data Subject Rights and Response Obligations

High Priority

KVKK Article 11 grants Turkish residents rights to access, correct, delete, and object to processing. Controllers must respond within 30 days (or 60 days in complex cases). AI decisions must be explainable and subject to human review on request. Healthcare and financial AI must provide enhanced explainability under KVKK Board guidance.

KVKK (Law No. 6698), Art. 11

Turkey National AI Strategy 2021-2025 Compliance

Medium Priority

Turkey's National AI Strategy sets requirements for public-sector AI transparency, algorithmic accountability, and human oversight. BDDK/BRSA-regulated entities using AI in credit, fraud, or customer segmentation must conduct model risk assessments. KVKK Board has issued sector-specific guidance on AI profiling and automated decisions.

Turkey National AI Strategy 2021-2025 (Presidency Digital Transformation Office); KVKK Board sector-specific AI guidance (non-binding policy layer, distinct from KVKK's own binding Arts. 5/11/16 duties above)

Who Does This Apply To?

Applies to any organisation — established in Turkey or outside it — that processes the personal data of individuals in Turkey, including via AI profiling and automated-decision systems; KVKK (Law No. 6698) has no general small-business exemption, and a controller (including a foreign one) must register in the VERBİS controller registry under Art. 16 before processing Turkish-resident data. Cross-border AI data flows changed materially under Law No. 7499 (Official Gazette, 12 March 2024), which restructured Art. 9 into a three-tier transfer mechanism — adequacy decisions, appropriate safeguards (standard contractual clauses, binding corporate rules), and narrow derogations; from 1 September 2024 explicit consent is no longer a valid basis for regular or repeated international transfers, so AI pipelines moving Turkish-resident data abroad must rely on an adequacy decision, SCCs/BCRs filed with the Board, or a derogation. Core duties: purpose-specific explicit consent or another Art. 5 lawful ground, accurate VERBİS declaration of AI processing, and Art. 11 data-subject rights (access, correction, deletion, objection) answered within 30 days, with explainability and human review for consequential automated decisions. Enforced by the Personal Data Protection Authority (KVKK Board): administrative fines up to the KVKK statutory maximum (revalued annually) plus criminal sanctions under Turkish Penal Code Arts. 135-140, and Board power to suspend processing.

Recent Regulatory Guidance

guidance2021-09

KVKK — Recommendations on the Protection of Personal Data in the Field of Artificial Intelligence (2021); Law No. 6698

KVKK's guidance on AI is its 2021 Recommendations on the Protection of Personal Data in the Field of Artificial Intelligence; binding obligations derive from Personal Data Protection Law No. 6698: explicit, purpose-specific consent for behavioural profiling (consent bundled into general terms of service is insufficient); VERBİS registry declarations must accurately reflect AI processing activities; data subjects may object to decisions based on solely-automated processing and request human review within the Article 11 response timeframes. Sector regulators (e.g. BDDK/BRSA for credit scoring and fraud detection) may impose additional model-risk expectations.

guidance2026-01

Draft Law Amending KVKK — Platform Liability for Unauthorised AI-Generated Content (submitted 2026-01-09, NOT YET LAW)

A Draft Law submitted to the Grand National Assembly on 2026-01-09 would amend Law No. 6698 to impose administrative fines on social media services/digital platforms that permit sharing of AI-generated audio, visual, or written content depicting a real person without that person's consent, addressing deepfake/generative-AI risks to personal data and personality rights. Runs alongside a related, separate proposal to amend Law No. 5651 (internet publications) requiring AI-generated-content labelling, with non-compliance triggering criminal liability under Turkish Criminal Code Art. 217/A. Neither bill is enacted as of this cycle — monitoring item, not a current obligation.

guidance2026-01

KVKK Guidance for Parents on Children's Use of AI Tools

On 2026-01-12 KVKK released guidance addressed to parents on children's use of AI technologies in education, gaming, communication, and social activities — covering age-appropriate consent, data-minimisation, and supervision expectations. Non-binding guidance, not a new statutory duty.

guidance2026-04

KVKK Guidance on Agentic AI and Data Protection

In April 2026 KVKK issued guidance addressing agentic AI systems (AI agents that act autonomously on a user's behalf) and their data-protection implications under Law No. 6698 — emphasising that autonomous data collection/action by an agent does not relieve the deploying organisation of its Art. 5 lawful-basis and Art. 11 data-subject-rights obligations. Guidance-level, not a new statutory instrument.

Frequently Asked Questions

Does Turkey Personal Data Protection Law (KVKK No. 6698) + AI Strategy 2021-2025 apply to my business?

Turkey's KVKK (Kişisel Verileri Koruma Kanunu, Law No. 6698) is Turkey's GDPR-equivalent, administered by the Personal Data Protection Authority (KVKK Board). While Turkey is not in the EU, KVKK aligns closely with GDPR principles and is a… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Turkey Personal Data Protection Law (KVKK No. 6698) + AI Strategy 2021-2025 is: KVKK fine band, revalued ANNUALLY (2026 figures, effective 2026-01-01): disclosure-obligation failures TRY 85,437-1,709,200; data-security-obligation failures TRY 256,357-17,092,242; failure to comply with Board decisions TRY 427,263-17,092,242; VERBİS registration/notification violations TRY 341,809-17,092,242. Top of band ≈ $356,000 USD at 2026-08-22's ~48 TRY/USD rate — NOT a fixed figure; re-check annually. Plus criminal sanctions under Turkish Penal Code (TPC Art. 135-140); KVKK Board can suspend processing.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Turkey Personal Data Protection Law (KVKK No. 6698) + AI Strategy 2021-2025?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://kvkk.gov.tr/en/

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan