Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

Turkey Personal Data Protection Law (KVKK) Compliance

Pandectes GDPR Compliance helps Shopify stores meet KVKK requirements by blocking non-essential cookies until visitors consent, scanning and classifying cookies, and keeping consent records.

Start Free
KVKK Turkey

The #1 cookie consent app for Shopify, trusted by 185k stores

  • Nike Strength
  • Reebok
  • Ted Baker
  • Juicy Couture
  • Aje
  • Casely
  • Oracle Red Bull Racing
  • KFC
  • Flying Tiger Copenhagen
  • Sennheiser
  • Susanne Kaufmann
  • Aldo
  • Victoria Beckham
  • Scalpers
  • UGREEN

What is KVKK?

KVKK is Turkey’s Law No. 6698 on the Protection of Personal Data (Kişisel Verilerin Korunması Kanunu), often called the PDPL in English. It was published in the Official Gazette on 7 April 2016 and sets the rules for how personal data of individuals may be collected, used, stored, and transferred. It is enforced by the Personal Data Protection Authority and its decision-making body, the Personal Data Protection Board.

KVKK was modeled on EU data protection law and shares many ideas with the GDPR. Its main principles include:

  • Processing personal data only on a legal basis, with explicit consent as the central one. Explicit consent must be freely given, specific, and informed.
  • Informing people, at the time their data is collected, who the data controller is, why the data is processed, who it is shared with, and what their rights are.
  • Giving individuals the right to learn whether their data is processed, to access it, to have it corrected or erased, and to object to certain results of automated analysis.
  • Keeping personal data secure and reporting data breaches to the Board and to the people affected.
  • Transferring personal data abroad only under the conditions set by the law.

Law No. 7499 amended KVKK from 1 June 2024, bringing its cross-border transfer rules closer to the GDPR. Transfers can now rely on an adequacy decision, on appropriate safeguards such as the Board’s standard contracts (which must be notified to the Authority within five business days of signing) or binding corporate rules, or on limited occasional exceptions. The amendments also widened the legal grounds for processing sensitive data.

Who does the KVKK apply to?

KVKK applies to individuals and organizations that process the personal data of natural persons, whether by automated means or as part of a filing system. The law has no explicit extraterritorial clause, but the Authority applies it to the processing of personal data of people in Turkey, and data controllers based abroad may need to appoint a representative in Turkey and register with the Data Controllers’ Registry (VERBIS).

What happens if I don’t comply with the KVKK?

Breaches of KVKK can lead to:

  • Administrative fines: The fines in Article 18 are revalued every year. For 2026, the highest fines reach TRY 17,092,242, for example for failing to meet data security obligations, ignoring Board decisions, or not registering with VERBIS.
  • Fines for transparency failures: Failing to meet the obligation to inform people can be fined up to TRY 1,709,200 in 2026.
  • Fines for unreported transfers: Since the 2024 amendments, failing to notify the Authority of a standard contract used for a cross-border transfer is also subject to a fine.
  • Board decisions: The Board can order a controller to remedy a violation or stop unlawful processing.
  • Criminal liability: Unlawfully recording, disclosing, or failing to delete personal data can be prosecuted under the Turkish Penal Code.

When did the KVKK go into effect?

KVKK came into force on 7 April 2016, the day it was published. The provisions on transfers, data subject rights, complaints, the registry, and penalties applied from 7 October 2016, six months later. The 2024 amendments took effect on 1 June 2024.

Complying with the KVKK

If your online store sells to customers in Turkey, KVKK can apply to the personal data you collect from them, including data collected by cookies and tracking tools.

For cookies and tracking, the main points are:

  • Consent: The Authority’s 2022 guideline on cookies expects explicit consent before using cookies for purposes such as advertising, marketing, and behavioral tracking. Strictly necessary cookies, such as those that keep a shopping cart working, can be used without consent. Consent should be an active choice, so pre-ticked boxes or continued browsing do not count.
  • Notice: Tell visitors which cookies you use, what each one does, how long it lasts, and whether it is set by you or a third party.
  • Cross-border transfers: Many analytics and advertising tools send data to servers outside Turkey. Check how each provider handles transfers under the amended Article 9, for example through standard contracts.
  • Data subject requests: Be ready to answer requests to access, correct, or erase personal data. The law requires controllers to respond within 30 days.

To make this manageable, consider using a Consent Management Platform (CMP) like Pandectes GDPR Compliance. It shows a cookie banner that blocks non-essential cookies until the visitor consents, scans your store to detect and classify cookies automatically, and generates a cookie declaration for your policy page. It keeps consent logs as proof of each visitor’s choice, helps you handle data subject requests, and uses geolocation to show region-specific banner settings to visitors from different countries. Pandectes GDPR Compliance is designed specifically for Shopify stores.

KVKK has its own definitions and procedures, so review your setup with legal counsel where appropriate, especially for cross-border transfers and VERBIS registration.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free