Legal position last verified: 1 September 2026.
A foreign company with no subsidiary or branch in Türkiye may still face KVKK obligations where it offers goods or services to individuals in Türkiye, monitors their behaviour, or determines processing that produces effects in Türkiye. Because the KVKK lacks a territorial-scope provision equivalent to GDPR Article 3, the analysis should be grounded in the purpose and effects of the processing, the Board’s treatment of foreign controllers and the actual data flow.1234
This guide is for foreign SaaS, e-commerce, mobile-app and platform companies, group headquarters and employers processing data about users, employees or business contacts in Türkiye.
Core conclusion: KVKK analysis for a foreign company does not end with whether it has an office in Türkiye; targeting, purposes, decision-making, cookies and monitoring, group transfers, representation and VERBIS must be mapped together.
Who is this guide for?
This guide is for foreign SaaS, e-commerce, mobile-app and platform companies, group headquarters and employers processing data about users, employees or business contacts in Türkiye.
Decision summary in one minute
| Question | Potential consequence if yes | Evidence |
|---|---|---|
| Are people in Türkiye targeted? | Stronger KVKK scope case | Language, currency, delivery and advertising |
| Is behaviour monitored? | Cookie/profiling duties | SDK, cookie and analytics map |
| Who determines purposes and means? | Controller/joint-controller role | Decision and contract matrix |
| Is it a foreign controller? | Representative and VERBIS may arise | Registry/representative file |
| Does data leave Türkiye? | Transfer mechanism required | Standard contract/appropriate safeguard |
| Is a Turkish processor used? | DPA and security oversight | Processor contract and audit |
1. Why is the KVKK territorial-scope analysis difficult?
Unlike GDPR Article 3, the KVKK does not codify establishment, targeting and monitoring in one territorial-scope article. The protection of individuals in Türkiye, where decision-making occurs and the real connection between processing and Türkiye remain relevant.56
The uncertainty does not mean that every foreign company is either automatically outside or inside scope. The conclusion should be documented through a reasoned role and territoriality memorandum.78
2. Offering goods or services and monitoring behaviour
A Turkish interface, delivery to Türkiye, TRY pricing, local advertising, a Turkish support channel or targeted campaign may demonstrate deliberate market targeting. Mere global accessibility from Türkiye carries less weight.910
Analytics, advertising technology, location, device fingerprinting and behavioural profiles require separate monitoring and purpose-limitation analysis. A cookie banner that omits SDKs and server-side tracking is not a complete compliance record.1112
3. Controller, processor and joint-controller roles
A foreign group company receiving Turkish data and determining purpose, retention, access or analytics cannot rely on a processor label alone. Actual decision-making may make it a controller or joint controller.131415
Roles should be assessed by activity. The same entity may process payroll on instruction but act as controller for global talent analytics. Intra-group contracts should reflect substance.161718
4. VERBIS and the foreign-controller representative
The Board’s practice treats controllers established abroad as a VERBIS category. A foreign controller appoints a data-controller representative in Türkiye and maintains registry information, subject to any applicable scope or exemption analysis.1920
A controller that becomes subject later should complete registration and notification within thirty days. The representative is not a substitute liable for every substantive duty of the foreign company.2122
5. International transfers and intra-group data
Data transferred from a Turkish company or user to foreign headquarters falls within the Turkish international-transfer regime. In addition to a lawful processing basis, the transfer needs an adequacy, appropriate-safeguard, standard-contract or exceptional route.2324
A global policy is not enough. Categories, recipient, country, purpose, retention and onward transfers should be mapped.2526
6. Transparency, rights requests and incident response
A foreign controller should provide understandable transparency, a workable rights-request channel and identity-verification process. The representative should be operationally capable of routing requests to the correct foreign team.27
Incident procedures should test awareness timing, Board notification, affected-person communication and evidence preservation across headquarters and the Turkish representative.28
Documents and evidence the company should prepare
- Türkiye-targeting and user-journey analysis
- Processing inventory and role matrix
- Cookie, SDK and analytics map
- VERBIS and representative records
- Transparency and rights-request procedure
- Intra-group transfer map
- Standard-contract/appropriate-safeguard file
- Incident and representative escalation process
Contract and governance controls
- Role and instruction boundary
- VERBIS/representative cooperation
- Transfer mechanism and notice
- Subprocessor and location change
- Rights and audit assistance
- Security and breach notice
- Retention and deletion
- Onward transfers and public-authority requests
Red flags and recurring mistakes
- Treating absence of an office as automatic exclusion
- Assuming GDPR compliance equals KVKK compliance
- Appointing a paper-only representative
- Omitting SDK and server-side tracking from notices
- Labelling a group controller as processor
- Confusing transfer safeguards with processing legal basis
Three practical scenarios
1. Foreign SaaS sells directly to Turkish customers
The service uses a Turkish site, TRY pricing and local advertising. The company assesses controller status, VERBIS/representative, cookies, customer-data transfers and incident processes in one scope memorandum.
2. Global headquarters runs workforce analytics
The Turkish subsidiary transfers payroll data and headquarters runs its own performance and talent model. Headquarters is assessed as controller or joint controller rather than processor, and transfer and workforce notices are updated.
3. Advertising SDK in a mobile app
The app discloses only essential cookies while an SDK sends device and behaviour data. Technical inventory, transparency, legal basis and third-party roles are rebuilt.
A 30–60–90-day implementation plan
Days 1–30 — scope and visibility
- Build the foreign-company KVKK scope and role matrix.
- Collect the relevant contracts, permissions, data and decision records.
- Assign owners to urgent gaps and threshold questions.
Days 31–60 — evidence and contracting
- Complete missing permissions, policies, schedules and records.
- Obtain management approval for the decision matrix.
- Test group-company and supplier flows against the chosen model.
Days 61–90 — testing and governance
- Run a practical scenario or tabletop exercise.
- Report open risks with owners and closure dates.
- Establish annual and event-driven review triggers.
Frequently asked questions
Can a foreign company with no Turkish entity be subject to the KVKK?
Yes. Targeting, monitoring, decision-making and effects in Türkiye may create a scope case.
Must a foreign controller register with VERBIS?
Board practice treats controllers established abroad as a registration category, subject to a specific scope and exemption review.
What does the data-controller representative do?
The representative supports registry and communications with individuals and the Authority but does not replace every substantive duty of the foreign company.
Is GDPR compliance sufficient for the KVKK?
No. Legal bases, transfers, registry, rights processes and regulatory practice differ.
Does a Turkish-language website automatically create scope?
Not conclusively; it is assessed with pricing, delivery, advertising, customers and monitoring.
Are cookies subject to the KVKK?
Cookie and SDK data can be personal data where linked to an identified or identifiable person.
Does an intra-group transfer require a contract?
The transfer route and roles should be identified, with standard clauses or another appropriate safeguard where required.
Does VERBIS registration complete compliance?
No. It does not replace transparency, lawful processing, security, transfers or rights handling.
Conclusion
KVKK exposure for a foreign company is understood through data and decision maps, not corporate charts alone. Bringing targeting, roles, VERBIS, representation, cookies and transfers into one scope file reduces both unnecessary filings and invisible non-compliance.
Legal information notice
This article provides general information only. It is not a legal opinion for a particular company, transaction, tax position, licence application or dispute. Applicable sector, tax, employment and regulatory rules require a fact-specific review.
Bibliography
- Kişisel Verilerin Korunması Kanunu No 6698 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf
- KVKK — VERBİS’e Kayıtlar ve Yurt Dışında Yerleşik Veri Sorumluları — https://www.kvkk.gov.tr/Icerik/5290/Veri-Sorumlulari-Icin-VERBIS-e-Kayitlar-Basladi
- EDPB Guidelines 07/2020 on Controller and Processor — https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en
- Controller–Processor Roles in Cloud Computing — https://doi.org/10.1093/idpl/ipad023
- Regulation (EU) 2016/679 (GDPR) — https://eur-lex.europa.eu/eli/reg/2016/679/oj
- KVKK — Sonradan Yükümlü Olan Veri Sorumluları İçin 30 Gün — https://www.kvkk.gov.tr/Icerik/8752/2025-yili-mali-bilanco-toplami-bakimindan-sicile-kayit-yukumlulugu-dogan-kurumlar-vergisi-mukellefi-tuzel-kisi-veri-sorumlularinin-verbis-kayit-suresi-hakkinda-kamuoyu-duyurusu
- Milletlerarası Özel Hukuk ve Usul Hukuku Hakkında Kanun No 5718 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.5718.pdf
- Türk Ticaret Kanunu No 6102 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6102.pdf
Footnotes
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
KVKK — VERBİS’e Kayıtlar ve Yurt Dışında Yerleşik Veri Sorumluları https://www.kvkk.gov.tr/Icerik/5290/Veri-Sorumlulari-Icin-VERBIS-e-Kayitlar-Basladi accessed 1 September 2026. VERBIS registration approach for controllers established outside Türkiye.↩︎
-
EDPB Guidelines 07/2020 on Controller and Processor https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en accessed 1 September 2026. Distinguishing controller, processor and joint-controller roles by their actual functions.↩︎
-
Controller–Processor Roles in Cloud Computing https://doi.org/10.1093/idpl/ipad023 accessed 1 September 2026. Allocation of roles in cloud services and the foreign-controller issue.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Regulation (EU) 2016/679 (GDPR) https://eur-lex.europa.eu/eli/reg/2016/679/oj accessed 1 September 2026. EU data-protection roles, territorial scope, legal bases, transfers and security.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Regulation (EU) 2016/679 (GDPR) https://eur-lex.europa.eu/eli/reg/2016/679/oj accessed 1 September 2026. EU data-protection roles, territorial scope, legal bases, transfers and security.↩︎
-
Regulation (EU) 2016/679 (GDPR) https://eur-lex.europa.eu/eli/reg/2016/679/oj accessed 1 September 2026. EU data-protection roles, territorial scope, legal bases, transfers and security.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Regulation (EU) 2016/679 (GDPR) https://eur-lex.europa.eu/eli/reg/2016/679/oj accessed 1 September 2026. EU data-protection roles, territorial scope, legal bases, transfers and security.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
EDPB Guidelines 07/2020 on Controller and Processor https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en accessed 1 September 2026. Distinguishing controller, processor and joint-controller roles by their actual functions.↩︎
-
Controller–Processor Roles in Cloud Computing https://doi.org/10.1093/idpl/ipad023 accessed 1 September 2026. Allocation of roles in cloud services and the foreign-controller issue.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
EDPB Guidelines 07/2020 on Controller and Processor https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en accessed 1 September 2026. Distinguishing controller, processor and joint-controller roles by their actual functions.↩︎
-
Controller–Processor Roles in Cloud Computing https://doi.org/10.1093/idpl/ipad023 accessed 1 September 2026. Allocation of roles in cloud services and the foreign-controller issue.↩︎
-
KVKK — VERBİS’e Kayıtlar ve Yurt Dışında Yerleşik Veri Sorumluları https://www.kvkk.gov.tr/Icerik/5290/Veri-Sorumlulari-Icin-VERBIS-e-Kayitlar-Basladi accessed 1 September 2026. VERBIS registration approach for controllers established outside Türkiye.↩︎
-
KVKK — Sonradan Yükümlü Olan Veri Sorumluları İçin 30 Gün https://www.kvkk.gov.tr/Icerik/8752/2025-yili-mali-bilanco-toplami-bakimindan-sicile-kayit-yukumlulugu-dogan-kurumlar-vergisi-mukellefi-tuzel-kisi-veri-sorumlularinin-verbis-kayit-suresi-hakkinda-kamuoyu-duyurusu accessed 1 September 2026. Registry registration and notification must be completed within 30 days after the obligation arises.↩︎
-
KVKK — VERBİS’e Kayıtlar ve Yurt Dışında Yerleşik Veri Sorumluları https://www.kvkk.gov.tr/Icerik/5290/Veri-Sorumlulari-Icin-VERBIS-e-Kayitlar-Basladi accessed 1 September 2026. VERBIS registration approach for controllers established outside Türkiye.↩︎
-
KVKK — Sonradan Yükümlü Olan Veri Sorumluları İçin 30 Gün https://www.kvkk.gov.tr/Icerik/8752/2025-yili-mali-bilanco-toplami-bakimindan-sicile-kayit-yukumlulugu-dogan-kurumlar-vergisi-mukellefi-tuzel-kisi-veri-sorumlularinin-verbis-kayit-suresi-hakkinda-kamuoyu-duyurusu accessed 1 September 2026. Registry registration and notification must be completed within 30 days after the obligation arises.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Regulation (EU) 2016/679 (GDPR) https://eur-lex.europa.eu/eli/reg/2016/679/oj accessed 1 September 2026. EU data-protection roles, territorial scope, legal bases, transfers and security.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Regulation (EU) 2016/679 (GDPR) https://eur-lex.europa.eu/eli/reg/2016/679/oj accessed 1 September 2026. EU data-protection roles, territorial scope, legal bases, transfers and security.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
