Turkish HR glossary

What counts as personal data under Turkey's KVKK?

Kişisel veri — personal data — means any information relating to an identified or identifiable natural person under Turkey's Personal Data Protection Law No. 6698 (KVKK), Article 3. The definition tracks the GDPR's, but KVKK is a separate regime with its own lawful bases, privacy-notice duty and cross-border transfer rules — GDPR compliance alone does not satisfy it.

Turkey's KVKK in brief — and how it maps to GDPR

The Personal Data Protection Law No. 6698 (KVKK), in force since 2016, is Turkey's general data protection statute, enforced by the Personal Data Protection Authority and its Board. It was modeled on the EU framework, and an amendment by Law No. 7499 — effective 1 June 2024 — moved it visibly closer to the GDPR on special-category processing and international transfers. It remains a distinct regime all the same: the definitions and principles feel familiar, but the lawful bases are narrower in places, the paperwork is Turkish, and enforcement is domestic. An employer hiring in Turkey therefore complies with KVKK directly rather than mapping a GDPR program onto it one-to-one.

Two differences matter most in practice. First, adequacy is not assumed in either direction: Turkey is not covered by an EU adequacy decision, and transfers out of Turkey run through KVKK's own Article 9 regime rather than through GDPR mechanisms. Second, KVKK historically leaned harder on açık rıza (explicit consent) than the GDPR does. The 2024 amendment widened the alternative grounds — notably for employment data — but documented lawful bases, Turkish-language notices and carefully separated consent wording still carry more weight in Turkish practice than many foreign employers expect.

Lawful grounds and special categories

Processing is lawful when it rests on one of the Article 5 grounds: explicit consent, clear authorization by law, necessity for forming or performing a contract, the controller's legal obligation, data made public by the person concerned, establishing or protecting a legal claim, or the controller's legitimate interest balanced against fundamental rights. For HR the contract and legal-obligation grounds carry most payroll and personnel processing, so consent is the fallback rather than the default — and asking for consent where another ground already applies muddies the record instead of strengthening it.

Special categories under Article 6 — health, biometric and genetic data, criminal convictions, union membership, religion, race and similar — start from a prohibition and may be processed only in the cases the article lists. Since the 2024 amendment they may be processed without explicit consent where necessary to meet legal obligations in employment, occupational health and safety, social security or social services: the ground that covers mandatory pre-employment health reports, disability records and similar items in a Turkish personnel file.

Cross-border transfers: the strict part

Sending employee data from Turkey to a foreign headquarters, a group HRIS or a cloud tool is a regulated transfer under Article 9. Since 1 June 2024 the lawful paths mirror the GDPR's architecture: first, an adequacy decision issued by the Turkish Board for a country, sector or international organization, then appropriate safeguards such as Board-approved standard contractual clauses or binding corporate rules, and finally narrow, occasional exceptions. The Turkish standard contract carries a hard procedural edge of its own — it must be notified to the Authority within five business days of signature, and skipping that notification is a separately punishable administrative offence even where the transfer itself is otherwise sound.

Data subject rights and the response clock

Article 11 gives every data subject nine rights against a controller: to learn whether their data is processed, to request information about that processing, to learn its purpose and whether the data is used accordingly, to know the third parties the data is transferred to, in Turkey or abroad, to have incomplete or inaccurate data corrected, to request erasure or destruction under the Article 7 conditions, to require corrections and erasures to be notified to the third parties the data went to, to object to a decision produced solely by automated analysis that works against them, and to claim compensation for damage caused by unlawful processing.

The procedure runs in two steps and on a fixed clock. The data subject applies to the controller first, and the controller must conclude the request as soon as possible and within 30 days at the latest, free of charge — a fee from the Board's tariff is allowed only where the operation itself carries a cost (Article 13). If the request is refused, the answer is inadequate, or no answer arrives in time, the person may complain to the Board within 30 days of learning the response and in any case within 60 days of the original application (Article 14). Going straight to the Board without applying to the controller is not available, so an employer in Turkey needs a named intake channel for employee and candidate requests and a 30-day answering routine behind it.

Breach notification, destruction duties and fines

Article 12 requires appropriate technical and organizational measures against unlawful processing and unlawful access, and against loss of the data. Where data is obtained by others, Article 12(5) requires notification to the data subject and to the Board "as soon as possible", and Board decision 2019/10 of 24 January 2019 fixed that as no later than 72 hours from the moment the controller becomes aware of the breach. The clock runs from awareness, not from the incident itself, and notification to affected individuals follows within a reasonable time once they have been identified.

Erasure has its own regulation. A controller that maintains a personal data retention and destruction policy runs periodic destruction at the interval set in that policy, and the interval may not exceed six months. A controller under no such obligation must erase, destroy or anonymize within three months of the duty arising. Records of destruction operations are kept for at least three years. Turkish workplace record-keeping rules run alongside this — social security records for 10 years, employee health files for 15 years after exit — so retention periods and destruction cycles are reconciled per data category rather than set once for the whole file.

Article 18 sets the administrative fines, and the amounts are revalued annually. On the Authority's published 2026 figures the bands are TRY 85,437 to TRY 1,709,200 for failing the privacy-notice duty, TRY 256,357 to TRY 17,092,242 for failing data-security obligations, TRY 427,263 to TRY 17,092,242 for not complying with a Board decision, TRY 341,809 to TRY 17,092,242 for breaching the VERBİS registration and notification duty, and TRY 90,308 to TRY 1,806,177 for not notifying a signed standard contract in time. These are administrative penalties. Unlawfully recording or obtaining personal data, or failing to destroy it, is separately a criminal offence under Articles 135–140 of the Turkish Penal Code (KVKK Article 17).

What KVKK means for HR data

Employee and candidate data is personal data from the first CV onward: identity and contact details, payroll and bank information, leave and attendance records, performance notes — and health reports or criminal-record extracts as special categories. Employers owe a privacy notice (aydınlatma metni) at the moment of collection, covering the controller's identity, the purposes, the recipients, the collection method, the legal ground and the data subject's rights (Article 10). Controllers above the registration thresholds — currently an annual headcount of 50 or more, or an annual balance sheet above TRY 100 million — must also register with VERBİS, the public registry of controllers, and Turkish retention rules keep workplace records for years after an employee exits.

Legal basisPersonal Data Protection Law No. 6698 (KVKK), amended by Law No. 7499 (in force 1 June 2024)
DefinitionAny information relating to an identified or identifiable natural person (Art. 3)
Special categoriesHealth, biometric, genetic, criminal-record, union, religious, racial and similar data (Art. 6)
Privacy noticeDue at collection: controller, purpose, recipients, method, legal ground, rights (Art. 10)
Cross-border transfersAdequacy decision, safeguards such as a standard contract notified within 5 business days, or exceptions (Art. 9)
EU adequacyTurkey holds no EU adequacy decision. KVKK applies in its own right
Response clockController answers within 30 days (Art. 13). Complaint to the Board within 30 days, and 60 days at the outside (Art. 14)
Breach notificationTo the Board within 72 hours of becoming aware (Art. 12(5), Board decision 2019/10 of 24 Jan 2019)
Periodic destructionAt most every 6 months under a retention and destruction policy, otherwise within 3 months. Destruction records kept 3 years
Administrative fines (2026)Privacy notice TRY 85,437–1,709,200. Data security TRY 256,357–17,092,242. VERBİS TRY 341,809–17,092,242 (Art. 18)

Frequently asked

Turkey's KVKK (Law No. 6698) is a separate data protection regime, not a local copy of the GDPR. It was modeled on the EU framework, and a 2024 amendment aligned special-category processing and cross-border transfers more closely with GDPR concepts — yet lawful bases, registration duties and enforcement remain distinct, and Turkey is not covered by an EU adequacy decision. A company compliant with the GDPR still has to satisfy KVKK separately for its Turkish employees and candidates.

An aydınlatma metni is the privacy notice Turkish law requires a data controller to provide when personal data is collected (KVKK Article 10). It must state the controller's identity, the processing purposes, to whom and why data may be transferred, the collection method and legal ground, and the data subject's rights. It is owed regardless of the lawful basis — it is an information duty, not a consent form — and belongs on job application forms and hiring paperwork as much as on websites.

Transferring personal data out of Turkey is lawful only through the Article 9 paths: an adequacy decision by the Turkish Data Protection Board, appropriate safeguards — most commonly the Board's standard contractual clauses, which must be notified to the Authority within five business days of signature, or binding corporate rules — or narrow occasional exceptions. Routing Turkish payroll or personnel records to a foreign HQ or a global HRIS falls squarely within this regime, so the safeguard has to be in place first.

In an employment file the usual special categories are health data (medical reports, disability records), biometric data used for access or attendance, criminal-conviction records, and union membership. Religion or blood type appearing on old-format documents also qualifies. These start from a processing prohibition, though since the 2024 amendment they may be processed without explicit consent where necessary for legal obligations in employment, occupational health and safety or social security. Stricter security measures apply either way.

VERBİS is Turkey's public registry of data controllers. Registration turns on thresholds set by Board decisions: controllers with an annual headcount of 50 or more, or an annual balance sheet above TRY 100 million, must register, as must those whose main activity is processing special-category data — that group has its own, much lower thresholds. Smaller employers outside these lines are exempt, but the duty revives in the year a threshold is crossed, so the figures belong in an annual compliance check.

Article 11 of Law No. 6698 gives a data subject nine rights: to learn whether their personal data is processed, to request information about the processing, to learn its purpose and whether the data is used accordingly, to know the third parties it has been transferred to in Turkey or abroad, to have incomplete or inaccurate data corrected, to request erasure or destruction under the Article 7 conditions, to have corrections and erasures notified to those recipients, to object to a decision produced solely by automated analysis that works against them, and to claim compensation for damage from unlawful processing.

A controller must notify the Personal Data Protection Board no later than 72 hours after becoming aware of the breach. Article 12(5) of Law No. 6698 says "as soon as possible", and Board decision 2019/10 of 24 January 2019 fixed that phrase at 72 hours. The clock starts when the controller learns of the breach, not when the incident occurred — an intrusion discovered weeks later still gets a fresh 72 hours. Affected data subjects are notified within a reasonable time once they have been identified.

The Article 18 administrative fines are revalued each year. For 2026 the Authority's published bands are TRY 85,437 to TRY 1,709,200 for failing the privacy-notice duty, TRY 256,357 to TRY 17,092,242 for failing data-security obligations, TRY 427,263 to TRY 17,092,242 for not complying with a Board decision, TRY 341,809 to TRY 17,092,242 for breaching VERBİS registration and notification duties, and TRY 90,308 to TRY 1,806,177 for failing to notify a signed standard contract within five business days.

Only as long as the processing purpose lasts: Article 7 requires personal data to be erased, destroyed or anonymized once the reason for processing disappears, and Turkish statutory retention periods are read alongside it — social security workplace records for 10 years, employee health files for 15 years after exit. The separate destruction regulation sets the rhythm: controllers with a retention and destruction policy run periodic destruction at most every six months, controllers without one act within three months of the duty arising, and destruction records are kept for at least three years.