Skip to content
Strategy

What Is KVKK Consultancy? Scope and Compliance Steps

KVKK consultancy covers the technical and administrative work that brings personal data processes in line with Turkey's data protection law.

5 min readMoon Workshop
Contents

KVKK consultancy is the set of technical and administrative work carried out to bring a company’s personal data processing in line with Turkey’s Personal Data Protection Law (KVKK). As the digital world moved to the centre of daily life, the security of our data became one of the most important legal topics. That made regulation of personal data and commercial communication necessary, and KVKK, which came into force in 2016, is among the most comprehensive of those regulations.

This article is general information and is not legal advice. For obligations specific to your organisation, the assessment should be made together with your legal counsel.

What is the purpose of the Personal Data Protection Law?

The law, prepared by taking into account international documents, comparative legal practice and the needs of the country, aims to have personal data processed and protected to contemporary standards. Within that scope, its purpose is to regulate the conditions for processing personal data, the protection of the fundamental rights and freedoms of individuals during that processing, and the obligations, procedures and principles that apply to the real and legal persons who process personal data.

The justification of the law also treats the protection of the individual’s right to privacy and the provision of data security within this scope. In other words, the point is not to complete a set of documents but to build a way of working that genuinely protects the data.

Which concepts do you need to know?

A few core concepts need to be clear before compliance work begins:

  • Personal data: any information relating to an identified or identifiable natural person. Names, phone numbers, email addresses, IP addresses and customer numbers all fall within this scope.
  • Special categories of personal data: more sensitive data types such as health information, biometric data, religion or membership details. These require stricter protective measures.
  • Data controller: the party that determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
  • Data processor: the party that processes data on behalf of the controller under its authorisation, for example a cloud service or a call centre provider.
  • Data subject: the natural person whose data is processed. They have rights such as requesting information, correction and erasure.
  • Disclosure and explicit consent: disclosure means informing the data subject before processing. Explicit consent is consent relating to a specific matter, based on information and expressed with free will. Not every processing activity has to rest on consent; the law provides for other lawful processing conditions as well.

What needs to be done to comply?

The work varies from organisation to organisation, but the core steps can be listed as follows:

  • Ensuring the security functions of all information assets, such as confidentiality, integrity and accessibility, that is, working in line with information security management system standards.
  • Creating strategies to determine which types of data are and will be collected from customers.
  • Building a personal data inventory that records which data is held, for which purpose, where, and for how long.
  • Identifying structured and unstructured data across network systems retrospectively.
  • Classifying recorded personal data according to its characteristics.
  • Reaching out to the people whose data is stored and informing them about the organisation’s processing purposes.
  • Obtaining consent from informed employees and customers through reasonable and demonstrable methods where it is required.
  • Developing technologies, policies and systems that make all of the above sustainable.
  • Carrying out evaluation, review and internal audit activities at defined intervals.
  • Running effective exercises such as penetration testing at regular intervals to verify system security.
  • Feeding the results of internal audits and tests back into the management system so it keeps improving.

Some of these steps are legal in nature, others purely technical. Where website forms, membership systems and customer databases are involved in particular, the web development side has to be planned together with the compliance requirements.

What does a KVKK consultancy engagement cover?

A typical engagement includes:

  • Ensuring that documents required under the law, such as policies and the data inventory, are prepared in a way that fits the company’s actual processes.
  • Creating and updating authorisation and access data as part of the technical measures.
  • Establishing methods to protect personal data moving through the company’s different systems against attacks and losses.
  • Providing regular information about developments within the scope of the law.
  • Keeping processes under control through disaster scenarios, test emails and remote or on-site audit activities.
  • Building and increasing staff awareness through regular training programmes.
  • Standardising a measurable level of knowledge through certified training and online tests.

Why does data compliance matter especially in e-commerce?

Businesses selling online process a large amount of personal data at once: orders, addresses, payment details and communication preferences. Newsletter subscriptions, abandoned cart reminders and remarketing are all data processing activities too. For that reason, handling the marketing setup and data compliance together in e-commerce consulting work prevents mistakes that are hard to undo later.

How is compliance sustained?

KVKK compliance is not a one-off project but an operating programme. When a new piece of software, a new supplier or a new marketing channel comes into play, the data flow changes, and the inventory and policies have to be updated accordingly. Regular internal audits, employee training and periodic technical testing are the three components that keep it running.

If you would like to review your organisation’s digital processes within this framework, you can reach us through our contact page.

Published: · Updated: · Author: Moon Workshop

Share

Frequently Asked Questions

Frequently Asked Questions

What does KVKK consultancy actually include?
It includes analysing the current situation, building the personal data inventory, preparing policies and disclosure texts that fit the company's actual processes, planning technical and administrative measures, training employees and auditing the processes regularly. The aim is to run data processing in line with the procedures and principles the law sets out.
Does a small business need to comply as well?
Every real or legal person who processes personal data falls within the scope of the law. A business that keeps a customer list, stores employee records or collects form submissions through its website is processing personal data. The extent of the obligations can vary with the size of the organisation and the nature of the data, so an assessment specific to the organisation is needed.
Why is the data inventory so important?
The inventory is the foundation of the whole effort. Without knowing which personal data is collected for which purpose, where it is stored, who it is shared with and how long it is kept, neither the disclosure text nor the security measures can be written correctly. Work done without an inventory usually stays incomplete.
Can compliance be completed once and left alone?
No. Deploying a new piece of software, adding a new form or starting to share data with a supplier changes the process. That is why evaluation, review and internal audit activities need to be carried out at regular intervals.
Blog
Free Account Audit

Know exactly where your ad budget goes

We audit your existing Google, Meta or Yandex accounts free of charge and report the waste, the missed opportunities and the growth potential in one document.