Data Protection Atlas

Türkiye

Tier 3 Comprehensive law Europe

Principal framework: Law 6698 (KVKK, amended 2024) (2016). Regulator: KVKK Authority. Law 6698 follows the pre-GDPR 1995 Directive model; the 2024 amendments modernised special-category processing and added GDPR-style transfer routes (SCCs, BCRs).

At a glance

Principal law
Law 6698 (KVKK, amended 2024)
Regulator
KVKK Authority
Breach notification
72 hours to the KVKK Authority; affected persons without undue delay
Maximum penalty
Administrative fines updated annually (into the millions of lira)
DPO required
No DPO mandate; controllers register with the VERBIS registry
Digital consent age
No specific age — general capacity rules
Extraterritorial reach
Applies to processing affecting persons in Türkiye

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
TR

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.