Implements Turkey KVKK compliance: data controller obligations, VERBIS registration, data subject rights, cross-border transfers, Board decisions, fines.
How this skill is triggered — by the user, by Claude, or both
Slash command
/privacy-skills-complete:turkey-kvkkThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
The Kisisel Verilerin Korunmasi Kanunu (KVKK), Law No. 6698, is Turkey's comprehensive personal data protection law. It was published in the Official Gazette on 7 April 2016 and entered into force on the same date. The KVKK is modelled on the EU Data Protection Directive 95/46/EC and shares structural similarities with the GDPR, though there are significant differences in cross-border transfer ...
The Kisisel Verilerin Korunmasi Kanunu (KVKK), Law No. 6698, is Turkey's comprehensive personal data protection law. It was published in the Official Gazette on 7 April 2016 and entered into force on the same date. The KVKK is modelled on the EU Data Protection Directive 95/46/EC and shares structural similarities with the GDPR, though there are significant differences in cross-border transfer mechanisms, consent requirements, and the role of the Personal Data Protection Authority (Kisisel Verileri Koruma Kurumu, KVKK Authority) and its decision-making body, the Personal Data Protection Board (Kurul).
Turkey applied for EU membership in 1987, and the KVKK was enacted partly to align with EU data protection standards. However, Turkey has not received an adequacy decision from the European Commission under GDPR Article 45, which creates complexity for EU-Turkey data flows.
| Turkish Term | English | GDPR Equivalent |
|---|---|---|
| Kisisel veri | Personal data | Personal data (Art. 4(1)) |
| Ozel nitelikli kisisel veri | Special category personal data | Special category data (Art. 9) |
| Veri sorumlusu | Data controller | Controller (Art. 4(7)) |
| Veri isleyen | Data processor | Processor (Art. 4(8)) |
| Ilgili kisi | Data subject / Relevant person | Data subject |
| Acik riza | Explicit consent | Consent |
| VERBIS | Data Controllers Registry | No direct equivalent (registration system) |
Processing of personal data is prohibited without the explicit consent of the data subject, except where:
Special category data includes: race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, appearance and dressing, association/foundation/union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data.
Processing requires either:
All data controllers meeting the registration threshold must register with VERBIS (Veri Sorumlulari Sicil Bilgi Sistemi). Registration requires disclosure of:
Exemptions from VERBIS: The Board has exempted certain categories including data controllers processing data as required by law, data controllers with fewer than 50 employees and less than TRY 100 million annual turnover (provided core activity is not special category data processing), and notaries.
Transfer of personal data abroad requires:
2024 Amendment: The KVKK was amended in March 2024 to introduce new cross-border transfer mechanisms including standard contractual clauses and adequacy decisions aligned more closely with GDPR Chapter V, with transitional provisions extending to 1 September 2024.
Data subjects have the right to:
The Personal Data Protection Board may impose administrative fines:
Fine amounts are adjusted annually based on the revaluation rate.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin privacy-skills-completeKVKK (Turkish Data Protection Law) use-case triage: classifies new data processing activities, product features, vendor integrations, AI/model training, employee monitoring, or transfer flows as PROCEED, VKED REQUIRED, LEGAL REVIEW, or STOP.
Monitors Turkish regulatory sources (Resmi Gazete, KVKK, SPK, BDDK, etc.), classifies developments by importance, and routes action items to downstream compliance workflows.
Navigates GDPR and CCPA privacy regulations, reviews DPAs, and handles data subject requests. Useful for compliance assessments, vendor agreements, cross-border transfers, and DSAR responses.