Sema Tut Arslan Attorney & Legal Counsel TR/EN

Data Protection Law

Structuring your data protection compliance end to end and reducing breach risk.

The protection of personal data is today a priority compliance area for businesses of every size. Within the scope of Law No. 6698 on the Protection of Personal Data — Türkiye's counterpart to the GDPR — I structure the entire process, from the data inventory and privacy notices to VERBİS registration and breach notifications.

I analyse companies' data processing activities, produce a compliance roadmap, and prepare the policy and contract sets required for employee, customer and supplier processes. I carry out periodic audits in line with Board decisions and current case law, and manage the 72-hour notification process in the event of a data breach. For international groups I also advise on the interaction between KVKK and the GDPR in cross-border transfers.

Scope of Services

  • KVKK compliance audit and roadmap
  • Preparation of the personal data processing inventory
  • Privacy notices and explicit consent texts
  • VERBİS registration and updates
  • Data processing and transfer agreements
  • Management of data breach notifications
  • Objections and litigation against Board decisions
  • KVKK awareness training for employees

Data Protection Law in Hatay

I handle data protection law matters from my office in Antakya and appear before the courts of Hatay — principally Antakya and İskenderun — as well as across the province. For clients abroad, meetings can be arranged by telephone or video conference and the file conducted under a power of attorney.

Frequently Asked Questions

Who must register with VERBİS?

Data controllers with more than 50 employees per year or an annual balance sheet total above the threshold value, as well as businesses whose principal activity is the processing of special categories of data, are required to register with VERBİS.

What should be done in the event of a data breach?

Notification must be made to the Personal Data Protection Board within 72 hours of becoming aware of the breach, and affected data subjects must be informed within a reasonable period. A technical and legal analysis establishing the scope of the breach should be carried out in parallel.

How does KVKK relate to the GDPR?

The two regimes are structurally similar but not identical: lawful bases, the rules on cross-border transfers and the registration obligation differ. A group that is GDPR compliant still needs a separate KVKK gap analysis for its Turkish operations.

This page is for general information only and does not constitute legal advice. Please consult an attorney regarding your specific situation.