Ask a company operating in Turkey “do you transfer personal data abroad?” and the most common answer is “no, we don’t do any business abroad.” Then you start listing the tools they use: corporate e-mail and office suite, CRM, customer support software, e-mail marketing service, web analytics, video conferencing, HR platform, cloud hosting — and, added in the last two years, the AI assistant that half the team pastes customer correspondence into every day.
If the servers behind those tools are outside Turkey, every one of them is a cross-border data transfer under the KVKK — Turkey’s Personal Data Protection Law No. 6698. You don’t need to trade internationally; a SaaS subscription is enough.
In 2024, Article 9 of the law was rewritten from scratch, and the rules became both clearer and stricter. This post explains the new regime and what a company using cloud, SaaS and AI tools actually has to do about it.
This post is for general information purposes and is not legal advice. We recommend getting legal support for choosing a transfer mechanism and preparing the contracts.
What Changed?
Under the old regime, transfers abroad were effectively squeezed into a single path: explicit consent (açık rıza). The list of countries with adequate protection was never published, and only a handful of companies managed to obtain permission from the Personal Data Protection Board (Kurul — “the Board”) by way of a written undertaking. The result: thousands of companies put an “I consent to my data being transferred abroad” checkbox on their sign-up screen and assumed the problem was solved.
The amendment introduced by Law No. 7499 entered into force on 1 June 2024; the transition period for the old provision ended on 1 September 2024. The details of implementation were set out in the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, published on 10 July 2024. The new system has three tiers.
The Three-Tier System
1. Adequacy decision
The Board may issue an adequacy decision (yeterlilik kararı) for a country, a sector within a country, or an international organization. Where a decision exists, the transfer can take place without any additional safeguard. As of the date this post is published, no adequacy decision has been issued; so in practice everyone has to look at the second tier.
2. Appropriate safeguards
Where there is no adequacy decision, one of the following appropriate safeguards (uygun güvenceler) must be in place, on the condition that data subjects are able to exercise their rights and have access to effective legal remedies:
| Mechanism | Suitable for | Board process |
|---|---|---|
| Standard contract (standart sözleşme) — Turkey’s equivalent of the EU SCCs, but a separate text | Almost everyone — including SaaS and cloud vendors | Notification within 5 business days of signature |
| Binding corporate rules (bağlayıcı şirket kuralları) | Intra-group transfers within multinational groups | Board approval |
| Written undertaking (taahhütname) | Special cases where the standard contract does not fit | Board permission |
| Agreement that is not an international treaty | Public institutions and professional organizations with public-institution status | Board permission |
3. Incidental transfers
If neither of the first two tiers can be met, there are limited exceptions only for incidental (arızi) transfers — that is, transfers that are non-recurring and not continuous: for example, the data subject giving explicit consent after being informed of the possible risks, or the transfer being necessary for the performance of a contract with the data subject.
The critical word here is “incidental.” Customer data flowing into your CRM every day is not incidental.
Standard Contracts: The Main Route in Practice
The Board has published four standard contract texts; the right one is chosen according to the roles of the parties:
- Data controller to data controller
- Data controller to data processor — the typical SaaS and cloud scenario
- Data processor to data processor
- Data processor to data controller
What you need to know:
- The text cannot be changed. The standard contract must be used exactly as published by the Board, with nothing added and nothing removed. Only the fields in the annexes are filled in (the parties, data categories, purposes, technical and organizational measures, etc.).
- It must be signed by authorized persons. Documents evidencing signing authority are part of the notification.
- 5 business days. Within five business days of the signatures being completed, the contract must be notified to the Personal Data Protection Authority (Kurum — “the Authority”) — physically, by registered e-mail (KEP), or through the Authority’s Standard Contract Notification Module.
- Notification is not approval. You don’t have to wait for a response from the Authority; but failing to notify is an administrative offence in its own right. For 2026 the fine ranges from 90,308 TL to 1,806,377 TL.
- EU standard contractual clauses (SCCs) are not a substitute. The GDPR-compliant data processing addendum you signed with your vendor is not a standard contract for KVKK purposes.
”We Collect Explicit Consent — Isn’t That Enough?”
Not anymore. Under the new system, explicit consent is a valid route only for incidental transfers, and only if the person has been informed of the possible risks. Systematic transfers — which means almost all cloud and SaaS usage — cannot be based on consent.
If your sign-up screen still has an “I consent to my data being transferred abroad” checkbox, that checkbox is not protecting you; it only shows that you are stuck on an outdated compliance model. For the broader problems with consent checkboxes, see our post on privacy notices and explicit consent.
A Roadmap for Companies Using Cloud and SaaS
1. Build an inventory of your tools. Don’t stop at the subscriptions finance pays for; include the accounts teams opened on their own cards and the free plans. For each tool: which personal data goes into it, in which country is the data held, and is the vendor a data processor or a data controller?
2. Look at your vendor’s sub-processors. You may be using a SaaS company based in Turkey, but if its infrastructure runs on a cloud abroad, one link of the chain is still outside the country.
3. Tie every transfer to a mechanism. In most cases the answer is the controller-to-processor standard contract. Ask your vendor plainly whether it will sign the Board’s standard contract. A vendor that refuses to sign is a vendor you need to make a risk decision about.
4. Put the notifications on a calendar. Five business days is short; run the signing process and the notification preparation in parallel.
5. Reduce the data you transfer. This is the least discussed and most effective step:
- Hosting in Turkey. Keeping the layer where personal data lives inside the country removes the transfer question for that data. We described what moving from a public cloud to infrastructure under your own control looks like in practice in our self-hosted PaaS migration post.
- Pseudonymization and masking. If you send data to a tool abroad for analytics or reporting, strip the identifying fields before sending, or transform them irreversibly.
- Data minimization. Does the customer’s Turkish national ID number really need to go to your support tool? Most integrations carry more fields than they need.
6. Update your documents. Your privacy notices and your registration in VERBİS, the Data Controllers’ Registry, must accurately reflect your transfers abroad.
AI Tools: The New and Growing Gap
When an employee pastes a customer complaint into an AI assistant to get it summarized, when a developer shares a log containing real user records while debugging, or when HR uploads a résumé to have it evaluated, personal data has been transferred to a provider abroad. In most companies these transfers appear nowhere — not in the inventory, not in the privacy notice, not in any contract.
In its Guide on Generative AI and the Protection of Personal Data, published on 24 November 2025, the Authority addressed the conditions for processing data throughout the lifecycle of these systems, data subject rights, and the cross-border transfer dimension. The message is clear: AI use is not a KVKK-exempt zone.
Banning it is not a solution; teams keep using it through their personal accounts and you lose visibility entirely. The approach that works is layered:
- Enterprise agreement. Instead of individual accounts, enterprise plans with defined data processing terms, where inputs are not used for model training — and an appropriate transfer mechanism for them.
- Usage policy. Short, understandable rules that say which class of data may go into which tool. A clear ban for special categories of personal data.
- Sanitization layer. An intermediate layer that detects and masks personal data before the request goes to the provider, and puts it back when the response returns. You get the power of the model, but personal data never leaves your perimeter. We covered this architecture in detail in our Synthesis Wall post.
- Locally run models. For highly sensitive workloads, open models running on your own infrastructure remove the transfer question altogether.
Where to Start?
Cross-border transfer is the part of KVKK compliance where law and architecture are most tightly intertwined. The contract side is necessary but not sufficient on its own; the real leverage is knowing which data goes where, and not sending what doesn’t need to go.
Three questions to start with: Do you have an up-to-date list of every SaaS and AI tool used in your company? Which of those tools receive personal data? For how many of them do you have a valid transfer mechanism?
As part of our KVKK consulting, IWWOMI maps your data flows and tool inventory, helps you determine the appropriate mechanism for each transfer, and — the part that is specific to us — reduces the transferred data at the architecture level: in-country hosting, masking, and AI sanitization layers. If you’d like to assess where you stand together, get in touch.
Sources: Standard Contracts — KVKK · Guide on the Transfer of Personal Data Abroad — KVKK · Announcement on the Standard Contract Notification Module · Guide on Generative AI and the Protection of Personal Data