What Is Law No. 6698 on the Protection of Personal Data?
Law No. 6698 on the Protection of Personal Data was accepted 24 March 2016 and published in the Official Gazette 7 April 2016. It has been amended several times, most significantly by Law No. 7499 (accepted 2 March 2024, published 12 March 2024), which amended Articles 6, 9, and 18 and added Provisional Article 3 — including a materially new cross-border transfer regime. No enacted amendment to Law No. 6698 after Law No. 7499 has been located; a 2026 amendment proposal exists in the Turkish parliament but remains marked "in committee," not current law. Under the current, post-2024 Article 9, a transfer abroad requires an Article 5/6 processing condition and either a Board adequacy decision for the destination, or — absent adequacy — enforceable rights and effective remedies plus one appropriate safeguard (an approved international agreement, approved binding corporate rules, a Board-published standard contract, or an approved written undertaking). KVKK's current guidance states the Board had not yet designated any adequate-protection country or destination in the 7 September 2026 review — an explicit no-adequacy-decisions-yet finding, not a description of a mature adequacy regime.
At a glance
- Full name
- Law No. 6698 on the Protection of Personal Data
- Short code
- KVKK
- Jurisdiction
- Türkiye
- Enacted
- 2016
- Last major update
- Law No. 7499 (accepted 2 March 2024, published 12 March 2024) amended Articles 6, 9, and 18 and added a new cross-border transfer regime and standard-contract notification offense
- Regulator
- Personal Data Protection Board (KVKK)
- Private right of action
- Yes
Scope, who KVKK covers
Protected data
Data subject rights
Learn whether personal data are processed
Request information about processing
Learn the purpose of processing and whether it is used consistently with that purpose
Know the third parties, domestic or foreign, to whom data is transferred
Request correction of incomplete or inaccurate data
Request deletion or destruction of data under Article 7
Request that correction, deletion, or destruction be notified to third parties who received the data
Object to an adverse result arising from analysis exclusively by automated means
Claim compensation for damage from unlawful processing
Notable features
The controller-first complaint requirement and its precise deadline interactions are a genuine procedural trap: KVKK's own published clarification specifies exactly how the 30-day and 60-day windows run depending on whether and when the controller responds. The Board should conclude within 60 days of a complaint, after which silence is deemed rejection — a real statutory deadline, distinct from many other jurisdictions in this dataset where no such deadline was located.
Enforcement & penalties
Regulator: Personal Data Protection Board (KVKK)
Penalties: Article 18 fine ranges in the current consolidated text: failure to fulfill the information obligation (Art. 10) — TRY 5,000-100,000; failure to fulfill data-security obligations (Art. 12) — TRY 15,000-1,000,000; failure to comply with Board decisions (Art. 15) — TRY 25,000-1,000,000; Data Controllers Registry failures (Art. 16) — TRY 20,000-1,000,000; failure to notify KVKK of a signed standard contract within the required period — TRY 50,000-1,000,000. Law No. 7499 added the specific cross-border standard-contract notification offense (failure to notify within five business days); it did not create a single general "unlawful cross-border transfer" fine.
Private right of action: Article 11's compensation right is preserved even under Article 28(2) partial exemptions. The complaint route is controller-first: apply to the controller under Article 13 (response due within 30 days), then complain to the KVKK Board within 30 days of learning the response, or within 60 days from the controller application if there was no response — a late controller response does not restart the 60-day period, per KVKK's own published interpretation.
Relevance to data brokers
No dedicated data-broker-specific complaint portal, deletion procedure, or statutory route has been located in KVKK legislation, regulation, communiqué, and decision materials. The available route is general: an Article 11(e) deletion request, an Article 13 controller application, an Article 14 Board complaint if unresolved, and possible judicial or compensation remedies. KVKK has handled public-record and search-engine indexing questions through case-by-case Board decisions weighing publication age and purpose against continued public interest, rather than through a general erasure right.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
How do I file a complaint with the KVKK Board?+
You must generally apply to the data controller first under Article 13. If the controller responds within 30 days but you are unsatisfied, you have 30 days from learning that response to complain to the Board. If there is no response, you have 60 days from your original application — a late controller response does not restart that 60-day window.
Does Türkiye currently recognize any country as adequate for data transfers?+
No. In the 7 September 2026 review, KVKK's current guidance states the Board has not yet designated any country, sector, or organization as providing an adequate level of protection under the post-2024 Article 9 regime — transfers instead rely on approved safeguards such as standard contracts or binding corporate rules.
Is there a dedicated way to remove my data from a Turkish data broker or people-search site?+
No dedicated data-broker-specific route has been located. The general route is a deletion request under Article 11(e), followed by a controller application under Article 13 and a Board complaint under Article 14 if unresolved. KVKK has ordered search-result de-indexing in specific cases through ordinary case-by-case complaint analysis, not an automatic right.
Official sources & citations
Other international privacy regimes
KVKK sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
