Cross-Border Personal Data Transfers under Turkish KVKK: A Practical Guide for International Businesses

Data Protection & International Transfers 12 min read

Key takeaway: Cross-border personal data transfers from Türkiye are not governed by a simple consent-only rule. Businesses must identify the actual data flow, confirm the underlying processing condition under Articles 5 or 6 of the KVKK, and select the correct Article 9 transfer mechanism.

Who should read this: International businesses, Turkish companies, foreign parent companies, cloud and SaaS providers, global HR teams, CRM providers, marketplaces and service providers with data connected to Türkiye.

Cross-Border Personal Data Transfers in Türkiye at a Glance

Primary ruleArticle 9 of Law No. 6698 on the Protection of Personal Data (KVKK)
First questionDoes a controller or processor subject to the KVKK transmit data or make it accessible to a recipient abroad?
Main transfer routesAdequacy decision, appropriate safeguard, or a narrow exceptional transfer
Private-sector safeguardsStandard contracts, Binding Corporate Rules and authorised written undertakings
Operational deadlineFive business days to notify a signed standard contract after completion of signatures

The Turkish Personal Data Protection Authority (KVKK) has published an official English overview of transfers of personal data abroad and a detailed Guide on the Transfer of Personal Data Abroad. This guide explains the practical implications for businesses operating between Türkiye and other countries.

What Is a Cross-Border Personal Data Transfer under Turkish Law?

Turkish data protection law treats a transfer abroad as the transmission of personal data by a controller or processor subject to the KVKK to a controller or processor located abroad, or otherwise making that data accessible to such a recipient.

The concept is broad. A transfer does not necessarily require a spreadsheet or database to be physically moved from Türkiye. Making personal data remotely accessible to an overseas recipient may also constitute an international transfer.

Examples include:

  • storing personal data on servers located abroad;
  • allowing a foreign parent company to access employee records;
  • giving an overseas service provider remote access to a Turkish customer database;
  • transferring customer information to a foreign call centre;
  • using an overseas processor for payroll, CRM, support or analytics;
  • allowing a foreign subcontractor to process personal data; and
  • transmitting customer details from a Turkish platform to a hotel or service provider abroad.

The Authority explains that remote access from a third country may amount to a transfer even when personal data is only viewed on a screen for troubleshooting, administration or support. Cloud storage abroad may also constitute an international transfer where the criteria are satisfied. For a focused example, see our guide on storing Turkish customer data abroad under KVKK.

When Does an International Transfer Exist?

Companies mapping cross-border data flows should test three elements:

  1. The person transferring the data is a controller or processor subject to the KVKK in relation to the relevant processing activity.
  2. That controller or processor transmits the personal data or otherwise makes it accessible.
  3. The recipient controller or processor is located outside Türkiye.

These elements are relevant to international SaaS, cloud, HR, CRM, support, infrastructure and group-company arrangements. A transfer assessment should focus on the actual technical access model, not only the wording of a privacy notice.

Does a Foreign Company Collecting Data Directly from Turkish Users Receive a “Transfer”?

Not necessarily. If an individual in Türkiye directly enters their name and email address into the website of a company established abroad, the individual is directly providing the information to that foreign company. There may be no separate controller or processor transmitting the information to the foreign recipient for Article 9 purposes.

This does not necessarily place the underlying processing outside the KVKK. Foreign e-commerce businesses, SaaS platforms, marketplaces, mobile applications and subscription services targeting users in Türkiye should separately assess whether Turkish data protection requirements apply to their processing activities.

If the foreign company subsequently sends the data to another processor located abroad, that subsequent disclosure may be an international transfer subject to the Article 9 framework.

Can the KVKK Apply to Companies Located Outside Türkiye?

The KVKK does not contain a territorial-scope provision identical to Article 3 of the GDPR. However, the Authority takes a broad approach to effective protection in cross-border digital environments.

Foreign businesses should not assume that having no subsidiary or office in Türkiye automatically places them outside Turkish data protection law. The Authority has also considered that data breaches at overseas controllers affecting individuals in Türkiye may potentially trigger Turkish notification obligations depending on the circumstances.

How Can Personal Data Be Legally Transferred Abroad?

Revised Article 9 establishes a structured hierarchy. In practice, businesses should analyse international transfers in this order:

  1. Check whether an international treaty or another Turkish law contains a specific transfer rule.
  2. Confirm that the underlying processing satisfies the applicable condition under Articles 5 or 6 of the KVKK.
  3. Determine whether an adequacy decision exists.
  4. If there is no adequacy decision, determine whether an appropriate safeguard can be used.
  5. Only where these mechanisms are unavailable should an exceptional transfer mechanism be considered; exceptional transfers must generally be occasional rather than systematic.

A company should not move directly to explicit consent simply because data is transferred abroad. The transfer mechanism must reflect the actual flow and the frequency of the operation.

First Route: Transfers Based on an Adequacy Decision

Where the Turkish Data Protection Board determines that a foreign country, a particular sector within that country or an international organisation provides an adequate level of protection, personal data may be transferred there if the applicable Article 5 or Article 6 processing conditions are also satisfied.

When evaluating adequacy, the Board may consider:

  • reciprocity regarding personal data transfers with Türkiye;
  • the foreign country’s data protection legislation and practice;
  • rules applicable to the relevant international organisation;
  • the existence and effectiveness of an independent data protection authority;
  • available administrative and judicial remedies;
  • participation in international data protection conventions;
  • membership in international or regional organisations; and
  • Türkiye’s international treaty obligations.

Adequacy decisions must be reviewed at least every four years, and the Board may amend, suspend or withdraw a decision prospectively. Businesses relying on adequacy should therefore monitor the status of the relevant jurisdiction, sector or organisation.

Second Route: Appropriate Safeguards

Where no adequacy decision applies, Article 9 allows transfers based on appropriate safeguards, provided the necessary processing conditions are satisfied and individuals can exercise their rights and access effective legal remedies in the destination country.

The principal safeguards are:

  • agreements between qualifying public bodies that are not international treaties;
  • Binding Corporate Rules;
  • standard contracts; and
  • written undertakings approved by the Board.

For most private international businesses, standard contracts and Binding Corporate Rules are likely to be the most commercially relevant mechanisms.

KVKK Standard Contracts

Standard contracts provide a contractual mechanism for establishing appropriate safeguards without separate prior authorisation from the Board for each transfer. The Turkish Data Protection Board has adopted four models covering the principal controller and processor combinations:

SS-1: Controller to Controller

Used where both the data exporter and overseas recipient act as controllers.

SS-2: Controller to Processor

Used where the exporter is a controller and the overseas recipient processes personal data on its behalf. This may apply to cloud, hosting, payroll, CRM, customer support and external technology providers. These role distinctions should also be reflected in any data processing agreement used with the processor.

SS-3: Processor to Processor

Used where both parties act as processors, including situations where a Turkish processor engages a foreign sub-processor.

SS-4: Processor to Controller

Used where the Turkish exporter acts as processor while the overseas recipient acts as controller.

Correctly identifying the parties’ roles is essential before selecting a standard contract. The Authority’s English standard-contract materials provide the official controller/processor models.

Can Companies Amend the KVKK Standard Contract?

Only to a limited extent. The approved wording is intended to provide the safeguards required by the Turkish framework. Parties should not make additions, deletions or amendments except where the relevant clause expressly provides optional or alternative wording.

Separate commercial terms may exist between the parties, but they should not undermine the operation of the approved standard contract. Businesses should avoid treating the KVKK model as an ordinary commercial agreement that can be freely negotiated.

What Information Must Be Included in the Standard Contract Annexes?

The annexes are a central part of the compliance exercise. The transfer documentation may need to specify:

  • the activities of the exporter and recipient;
  • categories of data subjects;
  • personal data categories;
  • special categories of personal data, where applicable;
  • the legal basis for the transfer;
  • transfer frequency;
  • the nature and purpose of processing;
  • purposes of subsequent processing;
  • data-retention periods;
  • recipients and recipient groups;
  • sub-processing arrangements; and
  • technical and administrative security measures.

Generic descriptions create compliance risk. “Customer data is transferred for business purposes” is less useful than identifying the specific data, why it is transferred, who receives it, how long it is retained and what processing takes place abroad.

Five-Business-Day Standard Contract Notification Requirement

A signed standard contract must generally be notified to the Turkish Personal Data Protection Authority within five business days after completion of the signatures.

The parties may decide in the contract whether the exporter or recipient will make the notification. If they do not, the exporter is responsible. Processors may also be responsible in certain circumstances and may need to fulfil the obligation without a separate instruction from the controller.

Failure to comply may lead to an administrative fine under the KVKK. Businesses using standard contracts frequently should build the five-business-day deadline into their contract-management and compliance workflow.

How Is the Standard Contract Submitted?

According to the Authority’s guide, notification may be made through available methods including physical submission, post, registered electronic mail (KEP) and other mechanisms designated by the Authority, including an electronic notification module where available.

The submission should include the completed and signed standard contract and supporting documentation showing the signatories’ authority. Foreign-language supporting documents may require notarised Turkish translations. Official documents issued abroad may require authentication or an apostille depending on the relevant international framework.

Turkish Language Requirement and Changes after Notification

Standard contracts may be executed in more than one language, but the Turkish text is controlling for the purposes of the Turkish international transfer framework. Multinational contract systems should ensure that the Turkish version accurately reflects the approved model.

Compliance does not end with the first notification. If information in the contract changes or the standard contract terminates, further notification may be required, including changes concerning subsequent recipients, recipient groups and sub-processors.

Binding Corporate Rules in Türkiye

Binding Corporate Rules (BCRs) are an appropriate safeguard for international corporate groups that regularly transfer personal data between group companies in different jurisdictions.

Approved BCRs can facilitate transfers between a Turkish group member and foreign group members. Two broad structures are recognised:

  • Binding Corporate Rules for controllers; and
  • Binding Corporate Rules for processors.

BCRs may suit shared systems involving central HR databases, global CRM infrastructure, group-wide customer management, cybersecurity, accounting, reporting and central compliance or IT operations.

What Must Binding Corporate Rules Contain?

The Authority identifies a substantial set of elements, including:

  • organisational structure and contact information;
  • descriptions of personal data flows;
  • legally binding commitments for relevant group members;
  • compliance with Turkish data protection principles;
  • security measures and safeguards for special categories of data;
  • restrictions on onward transfers;
  • data-subject rights and remedies;
  • responsibility for breaches by foreign group members;
  • accessibility of the BCRs to data subjects;
  • staff training, compliance monitoring and internal audits;
  • mechanisms for recording amendments;
  • cooperation with the Turkish Data Protection Authority; and
  • mechanisms addressing foreign laws that may adversely affect the safeguards.

BCRs require Board approval before they can be relied upon. Approval does not mean that every processing activity carried out by the group automatically complies with the KVKK; each transfer and processing activity must still satisfy the applicable legal requirements.

Written Undertakings

Where there is no adequacy decision, parties may prepare a written undertaking containing sufficient safeguards and submit it to the Board for authorisation.

An undertaking should address the purpose and scope of the transfer, legal basis, data-protection principles, transparency, data-subject rights, security measures, special categories of personal data, onward transfers, remedies, changes in foreign law, suspension or termination, deletion or return of data, and Turkish law and jurisdiction.

Unlike a standard contract, signing an undertaking does not by itself authorise the transfer. The parties must wait for Board authorisation. Starting the transfer while the application is under review may result in an unlawful international transfer.

Third Route: Exceptional Transfers

Where there is no adequacy decision and no appropriate safeguard can be used, certain transfers may occur under the exceptional transfer provisions. These exceptions must be interpreted narrowly and the transfer must generally be occasional.

An occasional transfer is not regular, does not have continuity and does not form part of the ordinary course of business. Permanent access to a foreign database, recurring payroll processing abroad and continuous cloud processing would ordinarily be difficult to characterise as occasional.

Exceptional Transfer Grounds under the KVKK

Explicit consent

An individual may explicitly consent to an occasional transfer after being informed about the possible risks arising from the absence of an adequacy decision or appropriate safeguards. Consent must be specific, informed and freely given.

Performance of a contract with the individual

An occasional transfer may be possible where necessary for a contract between the individual and the controller, or for pre-contractual measures requested by the individual. Necessity requires a close and objective connection with the contract, such as sending traveller details abroad to arrange an overseas hotel reservation.

Contract concluded in the interest of the individual

A transfer may be possible where necessary for a contract between the controller and another person for the benefit of the individual, subject to necessity and the occasional nature of the transfer.

Overriding public interest

An occasional transfer may be made where necessary for an overriding public interest, including areas such as crime prevention, national security, public health, competition, taxation, customs and financial supervision.

Establishment, exercise or protection of a right

Personal data may be transferred where necessary for legal proceedings before a foreign court or authority. Data minimisation remains important: anonymise where possible and transfer only what is genuinely required.

Protection of life or physical integrity

An exceptional transfer may be permitted where the individual cannot give valid consent and the transfer is necessary to protect that person’s or another person’s life or physical integrity.

Transfers from certain public registers

Transfers from registers open to the public or persons with a legitimate interest may be possible where statutory access requirements are satisfied. This does not permit indiscriminate transfer of an entire public register.

Why Routine Business Transfers Should Not Rely on Exceptions

Exceptional transfers are a last-resort mechanism. They should not normally justify routine international infrastructure such as:

  • continuous cloud storage;
  • global HR systems;
  • international CRM systems;
  • routine group reporting;
  • regular payroll processing;
  • recurring international support access;
  • permanent remote access; or
  • systematic transfers to overseas processors.

Businesses operating these models should normally consider an adequacy decision or an appropriate safeguard, particularly a standard contract or approved BCRs.

What About Onward Transfers?

A lawful first transfer does not end the analysis. Article 9 also applies to subsequent international transfers. Controllers and processors must ensure that the protection required by Turkish law continues when the original foreign recipient transfers information onwards.

This is especially relevant to cloud and SaaS structures involving multiple sub-processors. Companies should map affiliates, sub-processors, hosting providers, support vendors, backup providers and other downstream recipients, not only the first overseas recipient.

Practical KVKK Cross-Border Transfer Compliance Checklist

This workflow should form part of a broader KVKK compliance programme, rather than being treated as a standalone contract task.

  1. Map international data flows. Identify what data leaves Türkiye or becomes accessible abroad.
  2. Identify the parties. Determine which entity is controller, processor or sub-processor.
  3. Identify the processing condition. Confirm the applicable Article 5 or Article 6 condition where required.
  4. Check special legislation and treaties. Sector-specific rules may affect the analysis.
  5. Check adequacy. Confirm whether an adequacy decision applies to the destination country, sector or organisation.
  6. Select the safeguard. Consider standard contracts, BCRs or an undertaking depending on the structure.
  7. Use the correct standard contract. Match controller/processor roles accurately.
  8. Complete the annexes. Describe the actual data flow, categories, purposes, recipients, retention and security measures.
  9. Meet the five-business-day deadline. Assign responsibility for notification and retain evidence of submission.
  10. Review onward transfers. Include sub-processors and downstream recipients.
  11. Update privacy notices and inventories. Reflect the actual systems and international access arrangements.
  12. Monitor changes. New processors, recipients, purposes or foreign-law risks may require further action.

Frequently Asked Questions (FAQs)

Is explicit consent always required to transfer personal data outside Türkiye?

No. Article 9 provides mechanisms including adequacy decisions, standard contracts, BCRs and authorised undertakings. Explicit consent is mainly relevant to exceptional and generally occasional transfers.

Can a Turkish company store personal data on foreign cloud servers?

Potentially yes, but foreign cloud storage may constitute an international transfer. The company must assess the underlying processing and select an appropriate Article 9 mechanism.

Does foreign remote access to data stored in Türkiye count as an international transfer?

It may. Allowing a person abroad to access or view personal data can make that data accessible to an overseas controller or processor.

Does using a foreign SaaS provider trigger KVKK international transfer rules?

It can. If a Turkish controller or processor makes personal data accessible to an overseas SaaS provider acting as controller or processor, Article 9 should be assessed.

Can employee information be transferred to a foreign parent company?

Yes, if the applicable KVKK requirements are satisfied. Regular intra-group transfers should generally use a sustainable safeguard such as a standard contract or approved BCRs.

What are KVKK standard contracts?

They are model contracts adopted by the Turkish Data Protection Board to provide appropriate safeguards where no adequacy decision applies.

How many types of KVKK standard contracts exist?

Four: controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller.

Does a KVKK standard contract require prior Board approval?

No separate prior approval is required merely because the parties use the approved model. The signed contract must generally be notified within five business days after signature completion.

When must a KVKK standard contract be notified?

Within five business days after the parties complete the signatures.

Can a company change the wording of the KVKK standard contract?

Generally no, except where the approved contract expressly provides optional or alternative provisions.

What are Binding Corporate Rules?

BCRs are binding internal data-protection rules used by members of the same corporate group to establish safeguards for recurring international intra-group transfers.

Do BCRs require approval in Türkiye?

Yes. BCRs must be approved by the Turkish Personal Data Protection Board before being relied upon as the relevant safeguard.

Can companies use explicit consent for regular cloud transfers?

This is generally problematic. Exceptional transfers are intended for occasional transfers, while ongoing cloud operations are usually systematic and continuous.

Does a foreign company with Turkish customers automatically fall outside the KVKK?

No. Foreign businesses processing data connected with individuals and services in Türkiye may still be subject to Turkish data-protection requirements depending on the circumstances.

Does collecting information directly from a Turkish customer constitute a cross-border transfer?

Where the individual directly provides information to a foreign company, that collection itself may not constitute an Article 9 transfer. The underlying processing may still fall within the KVKK.

Are onward transfers covered by the KVKK?

Yes. Safeguards must also be maintained for subsequent transfers to affiliates, sub-processors, hosting providers and other downstream recipients.

Key Takeaway for International Businesses

The revised Turkish international data-transfer regime is not built around a simple question of whether the data subject has consented. Companies should identify what data leaves Türkiye or becomes accessible abroad, who exports it, who receives it, why it is transferred, whether the processing is lawful, whether adequacy is available and which safeguard applies.

This is particularly important for international cloud infrastructure, foreign processors, global HR systems, overseas CRM platforms, centralised customer support and multinational corporate structures. A transfer mechanism should reflect the actual technical and commercial data flow, not merely broad wording in a privacy policy.

For recurring business operations, a properly documented standard contract or approved BCR framework is generally more sustainable than relying on exceptional transfers or broad consent wording.

Turkish Trade Lawyers

Expert legal counsel for KVKK, international data transfers, technology contracts and regulatory compliance in Türkiye.

Need Assistance with a KVKK International Data Transfer?

Our team can help map Türkiye-related data flows, assess Article 9 mechanisms, prepare standard-contract annexes, review BCRs and manage notification requirements.

Contact Our Experts

Sources & Authorities

Primary legislation and official guidance referenced for accuracy and transparency.