Mevzuat Kategorileri
Hukuksal Düzenlemeler
Türkiye’de Kişisel Verilerin Korunması Kanunu, Sosyal Güvenlik Hukuku, Vergi Hukuku, İş Sağlığı ve Güvenliği Mevzuatı, Borçlar Hukuku, İş Hukuku, Ticaret Hukuku, Türk Parası Kıymetini Koruma Mevzuatı, Kambiyo Mevzuatı ve Vatandaşlık ve Göçmenlik Mevzuatı ile ilgili en güncel bilgilerin yer aldığı makalelere buradan ulaşabilirsiniz.
İkili Anlaşmalar
Türkiye ve diğer ülkeler arasında yapılan en güncel uluslararası ikili sosyal güvenlik ve vergi anlaşmalarının tarihlerine ve dokümanlarına buradan ulaşabilirsiniz.
18 Kasım 2024
Yazar Ecem Kumsal Başyurt, Kategori KVKK - GDPR
Significant amendments to Law No. 6698 on the Protection of Personal Data ("KVKK") regarding the transfer of personal data abroad were introduced through Law No. 7499, published in the Official Gazette dated March 12, 2024, No. 32487. Additionally, the By-Law on the Procedures and Principles for the Transfer of Personal Data Abroad ("By-Law") was published in the Official Gazette dated July 10, 2024, No. 32598 and entered into force.
These developments establish clear procedures and principles for the transfer of personal data abroad, a topic that has sparked considerable debate. Under Article 9 of the KVKK and the By-Law, standard contracts have become one of the primary tools for data transfers abroad. Previously, transfers based on explicit consent under the KVKK were deemed valid until September 1, 2024, after which such transfers without alternative safeguards would no longer be permissible. As a result, data controllers and processors must ensure compliance with the recent legislation amendments.
Standard contracts outline the obligations of the parties involved in data transfers and are defined by the Personal Data Protection Board. These contracts are intended to provide adequate safeguards between data controllers and data processors.
The standard contracts published by the Board are available on the official website of the Personal Data Protection Authority in both Turkish and English. However, as per the By-Law, the Turkish version will prevail in case of discrepancies. The contracts must specify the categories of personal data transferred, purposes of the transfer, recipient groups, and the technical and administrative measures implemented by the recipient. Additionally, for special categories of personal data (e.g., health data, association membership), further protective measures must be included. Data controllers are expected to identify such data and incorporate relevant details into the standard contracts.
It is important to note that modifications to standard contracts are not permitted. If the Authority determines that changes have been made or the contracts have not been duly signed by authorized representatives, it may initiate an investigation ex officio.
Standard contracts must be submitted to the Authority within 5 (five) business days of signing. Notifications can be made through: (i) physical submission, (ii) KEP (Registered Electronic Mail), or (iii) other methods designated by the Board. On October 25, 2024, the Board announced the launch of the Standard Contract Notification Module, which enables submissions via an online interface.
In conclusion, following these legal amendments, data controllers and processors must comply with the detailed conditions outlined in the By-Law for the transfer of personal data abroad. Non-compliance with the notification requirements for international data transfers may result in administrative fines ranging from 90,308 TRY to 1,806,377 TRY in 2026.
You can access the standard contracts announced by the board here.
You can find frequently asked questions and answers about standard contracts here.
You can access our professional consultancy services here to ensure legal compliance in your company's standard contract processes.
Should you have any queries or need further details, please contact us.
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.
About The Author
https://www.cottgroup.com
Evaluation of Personal Data Breaches within the Scope of Turkish Penal Code
CottGroup Hukuk ve Mevzuat Ekibi
11 Mart 2024
What Is the Right to Erasure? GDPR, Turkish Data Protection Law (KVKK), and Back-Up Compliance in Light of the EDPB Report
Ecem Kumsal Başyurt
23 Mart 2026
Data Controller and Data Processor Within the Scope of KVKK And GDPR
Taylan Ege Günel, Semih Er
8 Kasım 2023
What is Timestamp?
Civan Güneş, CottGroup Hukuk ve Mevzuat Ekibi
16 Ekim 2023