Our Services

Personal Data Protection

The Law on the Protection of Personal Data No. 6698, which entered into force in 2016, introduced a new regime in the field of personal data and additional obligations for companies. These obligations include preparing data inventories, complying with the duty to inform, obtaining explicit consent where required, ensuring data security, responding to applications, complying with the decisions of the Personal Data Protection Board and registering with the Data Controllers Registry. In this respect, Aksan Law Firm has been advising clients in their compliance with personal data protection legislation since the law came into force.

  • Identifying (and, where necessary, establishing) the company departments involved in KVKK compliance, holding KVKK-focused meetings with them, identifying needs and gaps and shaping compliance actions accordingly;
  • Training company personnel on the obligations brought by KVKK and arranging refresher trainings for new joiners at regular intervals;
  • Preparing a data inventory by department for personal data already stored or to be stored, and updating it on a regular basis;
  • Building, on the basis of the data inventory, a systematic data management framework within the company and producing the related compliance set (information notices, data processing policies, privacy policy, cookie policy, explicit consent texts, e-commerce communication consents, etc.) and updating these documents regularly;
  • Reviewing all contracts to which the company is or will be a party from a KVKK perspective and, where necessary, negotiating and revising them;
  • Carrying out the company's registration with the Data Controllers' Registry ("VERBİS");
  • Active support in responding to KVKK and GDPR-related applications from third parties;
  • Communicating Personal Data Protection Authority decisions and announcements to the company team in real time, defining new corporate policies in the event of legislative changes and ensuring necessary actions are implemented.
Oktay Şener
Oktay Şener
Managing Partner
Ecem Akyiğit
Ecem Akyiğit
Senior Associate
Bengisu Uğraş
Bengisu Uğraş
Associate
Serra Delibalta
Serra Delibalta
Associate
Fatma Subaşı
Fatma Subaşı
Counsel

Personal Data Protection

Verimlilik mi, Veri Güvenliği mi? KVKK Bakımından İş Yerlerinde Yapay Zekâ Denklemi

March 11, 2026
Kişisel Verileri Koruma Kurumu ("Kurum"), 05.03.2026 tarihinde yayınladığı "İş Yerlerinde Üretken Yapay Zekâ Araçlarının Kullanımı” başlıklı doküman...

Sadakat Kart Üyeliği Bulunan Bir Kişinin Cep Telefonu Numarasının veya Sadakat Kart Numarasının Üçüncü Bir Kişi Tarafından Alışveriş Esnasında Kullanılması Hakkında İlke Kararı (11.02.2026 – 2026/266 sayılı karar)

March 4, 2026
Kişisel Verileri Koruma Kurulu ("Kurul") tarafından alınan ve 28 Şubat 2026 tarihli Resmî Gazete'de yayımlanarak yürürlüğe giren "Sadakat Kart Üyeliği...

Kişisel Verileri Koruma Kurulu Bir SMS ile Birden Fazla İşleme İlişkin Toplu Onay Alınmasını KVKK’ya Aykırı Buldu!

July 4, 2025
Kişisel Verileri Koruma Kurulu (“Kurul”), ürün ve hizmet sunumlarına ilişkin süreçlerde ilgili kişilerin iletişim bilgilerinin talep edilmesi ve SMS i...

Kişisel Verilerin Korunması Kurumu Tarafından Özel Nitelikli Kişisel Veriler Rehberi Yayımlandı

March 7, 2025
Kişisel Verileri Koruma Kurumu (“KVKK”) tarafından, 26 Şubat 2025 tarihinde, 6698 sayılı Kişisel Verilerin Korunması Kanunu (“Kanun”) kapsamında özel ...

ChatGPT ve Kişisel Verilerin Korunması İlkeleri Çelişkisi

August 7, 2024
Kişisel Verileri Koruma Kurum’u (“Kurum”) tarafından 2 Temmuz 2024 tarihinde yayınlanan Kişisel Verileri Koruma Dergisi’nin yeni sayısı ile “ChatGPT’n...

Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelik Yayınlandı!

July 12, 2024
Kişisel Verileri Koruma Kurumu'nun (“Kurum”) 09.05.2024 tarihinde yayımlamış olduğu "Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esasl...

Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelik Taslağı Yayınlandı!

June 3, 2024
Kişisel Verileri Koruma Kurumu'nun 09.05.2024 tarihinde yayımlamış olduğu "Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkınd...

2024 yılı KVKK Yazı Dizisi 1 | Kişisel Verileri Koruma Kurumu Ocak 2024 Duyuruları

April 1, 2024
2024 yılı ocak ayında Kişisel Verileri Koruma Kurumu (“Kurum”) tarafından yayınlanan duyuruları derledik. 1. Köy Tüzel Kişiliklerinin Veri Sorumlular...

Frequently Asked Questions

Data controllers processing personal data must register with the Data Controllers Registry (VERBIS) where they meet the criteria set by the Personal Data Protection Board. The Board defines scope and exemptions by reference to headcount, annual balance sheet total and the nature of the data processed. Different thresholds apply to controllers whose principal activity involves special categories of personal data.
The duty to inform is an obligation to notify the data subject and must be met in every case, regardless of the legal basis relied upon. Explicit consent, by contrast, is only one of the lawful bases for processing. Where another statutory basis applies — performance of a contract, a legal obligation or legitimate interest — separate consent is not required.
The data controller must notify the Personal Data Protection Authority within the period set by the Board from the moment it becomes aware of the breach, and must inform the affected data subjects. Late notification constitutes a separate breach in itself. A predefined internal incident response procedure is therefore important.
Yes, provided the transfer relies on one of the mechanisms set out in the legislation. These include transfers to jurisdictions covered by an adequacy decision, appropriate safeguards such as standard contractual clauses or binding corporate rules, and the exceptional grounds listed in the law. The legal basis of every transfer, including intra-group transfers, should be documented.
This is permitted only within narrow limits. Decisions of the Constitutional Court and the Court of Cassation require that the employee has been clearly informed in advance, that the review pursues a legitimate aim, that it is proportionate, and that the least intrusive method available has been chosen.