Blog01 August 20264 min read923 words

What Is KVKK? A Complete Compliance Guide to Law No. 6698 for Businesses

A practical overview of Türkiye's Personal Data Protection Law (KVKK / Law No. 6698): who it covers, core concepts, processing conditions, controller obligations, and 2026 penalties, plus a 7-step compliance roadmap and how it interacts with Law No. 5651.

#kvkk#law-6698#compliance#data-protection

Law No. 6698 on the Protection of Personal Data (KVKK) was published in the Official Gazette and entered into force on 7 April 2016. It is the primary legislation governing the processing of personal data in Türkiye. The law is largely aligned with the GDPR (the European Union's General Data Protection Regulation) and was updated by amendments made on 6 February 2024 (most notably to the regime governing cross-border data transfers).

Who Does KVKK Cover?

The law applies to every natural person whose personal data is processed and to every natural or legal person who processes personal data. In practice, that means:

  • every business that keeps customer records;
  • every employer that holds HR data about its staff;
  • every organization that collects data through forms on its website;
  • every mass-use provider that offers guest Wi-Fi;
  • every institution that operates security cameras;
  • every call center that records telephone conversations.

Regardless of your sector, size, or whether you operate for profit, if you process personal data you fall within the scope of KVKK.

Key Concepts

  • Personal data: any information relating to an identified or identifiable natural person (name, national ID number, IP address, photograph, e-mail, phone number).
  • Special categories of personal data: data concerning health, biometrics, criminal convictions, religion, political opinion, trade-union membership, sex life, race, and association membership (subject to additional protection).
  • Data controller: the person or organization that determines the purposes and means of processing.
  • Data processor: the party that processes data under the authorization of the data controller.
  • Data subject: the natural person whose personal data is processed.

Conditions for Processing (KVKK Art. 5)

Personal data may be processed only if at least one of the following conditions is met:

  1. Explicit consent: the informed, freely given consent of the data subject.
  2. It is expressly provided for by law.
  3. It is necessary to protect life or physical integrity.
  4. It is necessary for the conclusion or performance of a contract.
  5. It is required to fulfill a legal obligation (e.g., Law No. 5651, the Tax Procedure Law, the Turkish Commercial Code).
  6. The data has been made public by the data subject.
  7. It is necessary for the establishment, exercise, or protection of a right.
  8. It is required for a legitimate interest, provided it does not harm the data subject's fundamental rights and freedoms.

Obligations of the Data Controller

  1. Duty to inform (Art. 10): tell the data subject the purpose of processing, its legal basis, and their rights.
  2. VERBİS registration: required for data controllers that exceed certain thresholds.
  3. Responding to data-subject requests: within 30 days.
  4. Data security measures (Art. 12): technical and administrative measures.
  5. Data breach notification: to the Board and to the affected data subjects within 72 hours.
  6. Data disposal: deletion, destruction, or anonymization once the purpose of processing has ceased.

What Are the Penalties for a Violation?

The administrative fines in force in 2026 (which increase each year through revaluation) are:

  • Breach of the duty to inform: 13,000 – 270,000 TL
  • Breach of data security obligations: 40,000 – 6,000,000 TL
  • Non-compliance with a Board decision: 67,500 – 6,000,000 TL
  • Breach of the VERBİS registration obligation: 54,000 – 2,700,000 TL

For a detailed penalty table, see our article KVKK Penalties 2026.

KVKK Compliance with SignLogger

SignLogger stores user records with electronic signatures and timestamps, hashes passwords with bcrypt, protects access with RBAC and 2FA, and provides automated deletion policies. Through the audit log, you can fulfill data-subject rights in a matter of seconds. Explore the features or review our KVKK disclosure notice.

A KVKK Compliance Roadmap: 7 Steps

  1. Build a data inventory: list which personal data you hold, for what purpose, and where — including network logs and Wi-Fi records.
  2. Map the legal bases: tie each processing activity to a legal basis; logs kept under Law No. 5651 rely on the "legal obligation" basis.
  3. Prepare disclosure notices: for every point where you collect data — including the guest Wi-Fi portal screen; see our Disclosure Notice Guide.
  4. Register with VERBİS if required: for the thresholds, see our VERBİS guide.
  5. Write a retention and disposal policy: define a period and a disposal method for each data category; for logs, see KVKK and Log Management.
  6. Put technical measures in place: access control, encryption, logging, and log integrity (electronic signatures / timestamps) are among the essential technical measures.
  7. Prepare a breach response plan: for the 72-hour rule, see our action plan.

KVKK and Network Logs: The Practical Takeaway for Businesses

For businesses that offer guest Wi-Fi or provide internet access to their staff, KVKK and Law No. 5651 work hand in hand: Law No. 5651 makes logging mandatory, while KVKK governs how you keep those logs (security, access restrictions, disposal at the end of the retention period). For the practical side of striking this balance, read How Do KVKK and Law No. 5651 Work Together?, and for setting up the logging side, see our Law No. 5651 Logging Obligation guide.

Frequently Asked Questions

Does KVKK only concern large companies?

No — every natural and legal person that processes personal data is within scope. Being subject to KVKK and meeting the VERBİS registration threshold are two different things; businesses below the threshold must still comply with all obligations and are only exempt from the requirement to register with the registry.

Is keeping Wi-Fi logs a KVKK violation?

No; logs kept under Law No. 5651 rely on the "legal obligation" legal basis. A violation arises when those logs are kept longer than necessary, left unprotected, or used for purposes other than intended.

Last updated: 01 August 2026

Questions about SignLogger?

Contact us