Legal position last verified: 28 September 2026
Türkiye’s Personal Data Protection Authority — the Kişisel Verileri Koruma Kurumu, commonly referred to in Türkiye as the KVKK Authority — introduced and published a new Practice Guide on the Protection of Personal Data in Lawyers’ Professional Activities on 22 September 2026. The Guide was prepared with the views and contributions of the Union of Turkish Bar Associations (Türkiye Barolar Birliği, or TBB). Its inside cover is dated July 2026, while the public launch and announcement took place in September.1
This Türkiye KVKK guide for lawyers brings together questions that many Turkish lawyers and law firms have been answering in different ways for years. Is an independent lawyer a data controller or a processor? What is the position of substitute counsel appointed under a tevkil arrangement for a hearing or enforcement step? Should every client sign a consent form? Does uploading a pleading to ChatGPT amount to a data transfer? When does a misdirected email, a missing paper file or a stolen phone become a reportable breach?
This is important to state clearly: the Guide concerns Türkiye’s Personal Data Protection Law No. 6698, usually called the KVKK. It is not a general GDPR guide. The Guide does draw on European concepts and comparative materials, but its legal conclusions are framed through Turkish legislation, Turkish Board decisions, the Attorneyship Law and the professional rules applicable in Türkiye.
The Guide does not create a new statute. What it does is make the existing rules much harder to treat as an abstract compliance exercise. Its central message is practical: where a lawyer independently decides why and how personal data should be used in providing legal services, the lawyer will generally be a data controller. A client’s instructions do not, by themselves, turn the lawyer into a processor. Yet the role must still be assessed operation by operation. In some tightly defined and genuinely instruction-bound activities, a lawyer or law partnership may act as a processor.2
In plain terms: professional secrecy remains fundamental, but secrecy alone is not a complete KVKK programme. A law firm should know where its data came from, why it is needed, who may see it, how it leaves the firm, how long it stays, and what happens when something goes wrong.
Twelve answers before opening the Guide
| Issue | The Guide’s central position | What it means inside a law firm |
|---|---|---|
| 1. Scope of the KVKK | Lawyers’ professional activities are not generally outside the KVKK. | Do not assume a blanket exemption merely because the processing relates to litigation. |
| 2. Controller status | An independent lawyer is generally a controller. | The lawyer must manage notices, security, requests and breach response. |
| 3. Functional classification | The label is less important than who decides the “why” and “how”. | Classify each service and data flow separately. |
| 4. Law partnerships | Where work is carried out in the partnership’s name, the partnership will generally be the controller. | A contract calling the partnership a “processor” does not settle the question. |
| 5. Substitution counsel | In a classic, limited tevkil arrangement, the substitute lawyer may act as a processor. | Define the instruction, data scope, purpose, return and deletion duties. |
| 6. Employees and trainees | People working inside the firm’s organisation are not separate processors merely because they handle data. | Use access matrices, training, confidentiality and supervision. |
| 7. Consent | Consent is not the default ground where another statutory condition applies. | Replace blanket consent forms with an activity-based legal-basis matrix. |
| 8. Evidence gathering | Protecting a right can justify processing; it does not justify unlawful collection. | Do not use illicit search tools or data sets of uncertain origin. |
| 9. Generative AI | Uploading a file may involve a domestic or international data transfer. | Review the provider, hosting, subprocessors, retention and training terms. |
| 10. VERBIS exemption | Exemption from registration is not exemption from the rest of the KVKK. | Inventory, notices, retention, security and request handling still matter. |
| 11. Breach reporting | The Board’s 72-hour approach applies where the statutory breach threshold is met. | Plan for lost paper files, wrong emails, compromised accounts and lost devices. |
| 12. Accountability | The lawyer should be able to show where data came from, why it was used and where it went. | Keep source and transfer records and answer data-subject applications within 30 days. |
Why this Guide was needed
A law firm may not describe itself as a data-heavy business. In practice, almost every file that comes through the door is also a personal-data file.
A divorce matter may contain intimate messages, photographs and information about children. An employment dispute may include health, union and payroll data. A criminal file may contain convictions, security measures or witness details. An enforcement file may bring together debt, banking, address and asset information. The firm will often process data not only about its client, but also about opposing parties, witnesses, employees, family members and people who never instructed the firm at all.3
That is why the Guide is more useful than a generic instruction to “prepare a privacy notice”. It separates the grey areas that appear in real legal work:
- the role of an independent lawyer in relation to the client;
- lawyers who share the same office without forming a separate legal entity;
- a law partnership (avukatlık ortaklığı) registered in the Bar’s Law Partnership Registry;
- substitute counsel appointed under a tevkil arrangement for a specific hearing, attachment or inspection;
- employed lawyers, trainees, secretaries and support staff;
- evidence gathering and the use of publicly available information;
- contact with debtors and their relatives;
- domestic and international transfers;
- the use of ChatGPT, Claude, Gemini and similar tools;
- retention, deletion, access requests and breach reporting.
The Guide is not a safe harbour, and it does not promise that a firm following a checklist will be protected in every case. Its value is more grounded: it places Board decisions, the KVKK, the Attorneyship Law and professional duties inside the everyday workflow of a law office.
1. The first misconception: “Legal work is already outside the KVKK”
One of the Guide’s most important corrections is that a lawyer’s role as a constitutive element of the justice system does not make the lawyer a “judicial authority” for the full exemption in Article 28(1)(d) of the KVKK.
Two cumulative conditions are required for that exemption:
- the processing must relate to investigation, prosecution, adjudication or execution; and
- it must be carried out by a judicial authority or an execution authority.
A lawyer is indispensable to the right of defence, but is not a court, prosecution office or execution authority for this purpose. In Decision No. 2020/26, the Board also rejected the idea that sending debt information to the debtor’s sibling could be treated as exempt judicial processing.4
For daily practice, the point is simple. The fact that data appears in litigation or enforcement work does not automatically make every use lawful. The operation should still have:
- a valid processing condition;
- a specific and legitimate purpose;
- necessity and proportionality;
- the correct recipient and channel;
- appropriate security and retention controls.
2. A lawyer will often be a controller — but not for every operation
The Guide uses a functional approach. The real question is:
Who decides why and how the personal data will be processed?
An independent lawyer decides which evidence is relevant, what should appear in a pleading, what must be retained, which authority should be approached and how the matter should be conducted. The lawyer’s primary contractual duty is to provide legal assistance, not to process data as a standalone service. Data processing is an accompanying and protective duty; it does not convert the retainer into a processing agreement.5
A practical role matrix
| Working model | General approach in the Guide | Main point to check |
|---|---|---|
| Independent lawyer | Generally a controller | The lawyer independently determines purposes and essential means. |
| Independent lawyers sharing an office | Each may be a separate controller for their own matters | A shared sign, office and expenses do not automatically create joint controllership. |
| Law partnership (avukatlık ortaklığı) | The partnership is generally the controller for work undertaken in its name | Check in whose name the power of attorney and engagement operate. |
| Substitute counsel under a limited tevkil arrangement | The substitute lawyer may be a processor | Review the actual instruction and degree of independent decision-making. |
| Substitute lawyer acting outside instructions | May become a controller for the new activity | Using the data for the lawyer’s own purpose changes the role. |
| Employed lawyer | Person acting within the employer firm’s organisation | Not a separate processor merely because the lawyer handles personal data. |
| Trainee lawyer | Person acting under the supervising lawyer’s organisation and responsibility | Supervision, training and access boundaries remain essential. |
| Secretary or support staff | Authorised person within the controller’s organisation | Their conduct is treated as part of the controller’s processing. |
| External cloud, archive, software or IT provider | May be a processor depending on the service | Contract, security, subprocessors and incident cooperation must be addressed. |
The contract label is not conclusive
A company and a law partnership may write “processor” into their engagement agreement. That does not settle the legal classification if the partnership, in practice, decides how the work will be handled and how the relevant personal data will be used. In Decision No. 2023/437, the Board looked past the contractual label and treated the law partnership as a controller because it determined the purposes and means of the processing.6
The reverse can also occur. In debt-collection work that is genuinely narrow, rule-bound and performed under detailed instructions, a lawyer or law partnership may be a processor for the specific operation. The Guide refers to Decisions No. 2021/115, 2021/424 and 2023/78 as examples of this narrower possibility.7
What this means for a firm: avoid the one-line assumption that “lawyers are controllers” or “panel law firms are processors”. Build a role matrix by service, data flow and decision-making authority.
3. Professional secrecy matters — but it does not replace data protection
Lawyers’ professional secrecy is broad and continuing. It covers information learned through professional activity, including information received from a person who never became a client. Yet personal data and professional secrets do not fully overlap.
For international readers, Türkiye’s professional-secrecy duty should not be treated as synonymous or necessarily coextensive with attorney-client privilege or legal professional privilege. Those are distinct procedural and evidential concepts whose scope depends on the applicable law.
A person’s name, telephone number or national identity number may not be secret in the ordinary sense. It is still personal data and remains protected under the KVKK. The Guide therefore notes that the personal-data obligation may reach more information than the duty of secrecy.8
The following assumption is unsafe:
“I already protect client confidentiality, so I do not need a separate KVKK process.”
Secrecy principally addresses disclosure and professional trust. The KVKK also asks the firm to address:
- the legal basis for processing;
- transparency and privacy notices;
- data minimisation;
- accuracy and updating;
- retention and deletion;
- data-subject applications;
- technical and organisational security;
- breach assessment and reporting.
4. The file contains data about more than the client
A firm’s data map should not stop at the client. Depending on the matter, data subjects may include:
- current and prospective clients;
- opposing parties, debtors, defendants and suspects;
- witnesses, experts and other third parties;
- spouses, children and other family members;
- company directors, employees and representatives;
- the firm’s own employees and trainees;
- banks, carriers, guarantors and other people connected with the transaction.
The categories may be equally broad: identity and contact details, addresses, financial and asset information, employment records, professional experience, health, genetic data, union membership, political opinions, criminal convictions and security measures.9
This helps explain why a single general privacy notice may not be enough. Client onboarding, conflict checks, employee files, website forms, CCTV, call recordings, external suppliers and generative AI are different data flows and should not be treated as one undifferentiated activity.
5. A blanket consent form is not the answer
One of the Guide’s clearest messages is that explicit consent (açık rıza) is not automatically the “safest” legal basis. Where another condition under the KVKK already applies, requesting consent for the same necessary operation can be misleading and contrary to the principle of fairness.10
In legal practice, the following grounds will often be more relevant:
| Activity | Possible legal basis under the KVKK |
|---|---|
| Taking the client’s identity and contact details | Necessity for entering into or performing the engagement |
| Processing evidence required for litigation | Necessity for the establishment, exercise or protection of a right |
| Issuing a professional receipt | Express provision of law and/or legal obligation |
| Filing documents required by a court or enforcement office | Express provision of law and/or protection of a right |
| Acting under mandatory defence or legal aid | Legal obligation, express statutory basis and protection of a right |
| Basic office security and limited audit logs | Legitimate interests, depending on the balancing exercise |
| Optional sharing without another legal ground | Valid, specific and freely given consent may be required |
Why unnecessary consent can create a problem
If the firm already needs certain data to perform the retainer or protect a right, telling the client “we cannot act unless you consent” calls the freedom of that consent into question. If the client later withdraws consent, the firm may then say that it was actually relying on another ground all along. That undermines transparency.
A better approach is to:
- identify the legal basis for each operation before collecting data;
- use consent only for the activity that genuinely requires it;
- keep the privacy notice separate from a consent request;
- explain accurately what happens if consent is not given.
6. Special-category data and sensitive family files: different concepts, the same care
Family information is not, by itself, a special category of personal data. Family-law matters may nevertheless contain health or sex-life data, genetic or biometric data, or data concerning criminal convictions and security measures.
Medical reports, DNA tests, union membership, political opinions, convictions and biometric information may sit at the centre of an ordinary case. The Guide states that the current conditions in Article 6 of the KVKK and the Board’s Decision No. 2018/10 on additional safeguards should be applied together.11
At a minimum, a law firm should consider:
- a written policy for special categories of personal data;
- restricted access and role-based permissions;
- separate storage or additional encryption;
- secure transfer methods;
- staff training;
- paper-file security;
- reliable deletion or destruction.
“Something in the medical file might become useful” is not enough to justify collecting and retaining the entire file indefinitely. Necessity should be connected to the actual dispute and purpose.
7. Article 2 of the Attorneyship Law is not a blank cheque
Article 2 of Türkiye’s Attorneyship Law requires certain public authorities, banks, notaries, insurers and foundations to assist lawyers and make necessary documents available, subject to special statutory restrictions. The Guide stresses that “needed” does not mean arbitrary or potentially useful at some future point.
There should be:
- a genuine connection with the legal task;
- an explainable need;
- a proportionate scope;
- an appropriate legal basis for the transfer.
The Council of State has also interpreted necessity as a reasoned need linked to the work to be carried out. Special statutes may override the general information-request power. In Board Decision No. 2021/1111, the general rule in the Attorneyship Law did not override the special regime for criminal-record information, and unlawful access led to enforcement action.12
8. Illicit search screens: an easy route with heavy consequences
The Guide repeats a direct warning against software, databases and applications that allow unlawful searches of identity, telephone, address or asset information. Board Principle Decision No. 2019/308 treated the use of such tools as a failure to comply with data-security duties and noted that the matter may also be referred for criminal investigation.13
For a law firm, “the client gave it to us”, “it was online” or “other firms use the same tool” is not enough. A defensible file should record:
- who provided the information;
- when it was obtained;
- why it was necessary for the matter;
- how the lawfulness of the source was assessed;
- where and by whom it was used.
9. Publicly available does not mean free for any purpose
A social-media profile, company website, Trade Registry Gazette entry or public directory may be a source of personal data. Visibility on the internet does not amount to unlimited permission.
According to the Guide, reliance on the “made public by the data subject” condition requires:
- publication by the data subject or a genuine intention to make it public;
- a use consistent with the purpose for which it was made public;
- necessity and proportionality in the new context.14
For example, using a company representative’s published name and authority to pursue a corporate debt may be proportionate. Keeping unrelated photographs or contact details for future marketing or unrelated matters is a different use and needs a different analysis.
10. A text message to the wrong number: a small mistake with serious consequences
A recurring category in Board decisions concerns debt or enforcement information being sent to the wrong number, a relative of the debtor or employees of an unrelated company.
The Guide’s practical lessons are straightforward:
- Do not assume that a relative already knows about the debt.
- Check whether the number is accurate and current before using it.
- Keep the message content to what is genuinely necessary.
- Distinguish a statutory attachment notice from pressure-oriented disclosure to a family member.
- Do not confuse a company’s general number with an individual’s verified contact details.
Where a firm uses automated SMS, bulk calls, call centres or collection software, number verification, template approval, logging and error handling should be separate controls rather than informal habits.
11. Sending a document to a court or mediator is still a data transfer
Sending a file to a court, enforcement office, mediator, expert, client, substitution counsel or service provider may amount to a personal data transfer. Lawful collection does not automatically make every later transfer lawful.
For a domestic transfer, the firm should ask at least:
- What is the purpose of the transfer?
- Which condition under Articles 5 or 6 of the KVKK applies?
- Does a special statute require or limit the transfer?
- Does the recipient need the whole document or only part of it?
- Is the channel secure?
- Is there a second check against the wrong-recipient risk?
Sending only the necessary pages, encrypting an attachment, communicating the password through a separate channel and confirming the recipient are simple examples of proportionality and security working together.
12. Cloud, email and office tools: international transfer is closer than it looks
Article 9 follows three stages: (i) an Article 5 or 6 processing condition plus an adequacy decision; (ii) where no adequacy decision applies, an Article 5 or 6 condition, effective rights and remedies in the destination, and one of the safeguards in Article 9(4); or (iii), absent those, an occasional transfer only within one of the limited situations in Article 9(6). If the parties use the published standard contract, it must be notified to the Authority within five business days of signature.15
For the transfer mechanisms and contract choices, see our study on personal data transfers between Türkiye and the EU.
For a law firm, international transfer does not begin only when someone deliberately emails a foreign client. It may arise through:
- foreign cloud storage;
- international email and office suites;
- matter-management or document-management systems;
- remote backup;
- foreign support-team access;
- translation, transcription or analytics tools;
- generative AI services.
The transfer map should therefore go beyond the provider’s trading name. Hosting locations, support access, subprocessors and onward transfers matter as well.
13. The Guide’s most current warning: uploading a file to ChatGPT
Summarising a pleading, turning an expert report into plain language or generating an interview checklist can now take seconds. The Guide focuses on the blind spot created by that convenience.
When a lawyer uploads a client file, pleading or document containing personal data to ChatGPT, Claude, Gemini or a similar system, the data may be processed within the provider’s infrastructure and, depending on the facts, transferred abroad.16
Saying “I only asked for a summary” or “I used it for legal research” does not remove the data-protection analysis. Before uploading, the firm should understand:
- where the data is processed and stored;
- whether prompts or files may be used for model training;
- whether human review is possible;
- retention periods;
- deletion and opt-out controls;
- subprocessors;
- differences between consumer and enterprise terms;
- access and audit logs;
- the mechanism relied on for an international transfer.
What should a law firm check before using generative AI?
- Use non-personal or genuinely anonymised data wherever possible. Treat redacted or pseudonymised material as personal data unless it can no longer be associated with an identified or identifiable person, even by matching it with other data.
- Make “do not upload special-category data” the default rule.
- Use only the minimum extract rather than the whole file.
- Assess enterprise accounts and data-use restrictions.
- Record the current privacy, retention, training and subprocessor terms.
- Classify use cases as permitted, controlled or prohibited.
- Subject the output to human review and legal verification.
- Adopt a written AI-use policy and staff training.
The Guide also notes that even if the provider is established in Türkiye and the data remains in Türkiye, sending the document to an external provider may still be a domestic transfer under Article 8. The question is therefore wider than “does the data leave the country?”.17
For governance, procurement and internal-use controls, see our enterprise AI compliance playbook.
14. “Related to the case” is not the same as necessary
A valid processing condition is only the first step. The processing must also comply with the principles in Article 4 of the KVKK:
- lawfulness and fairness;
- accuracy and, where necessary, keeping data up to date;
- specified, explicit and legitimate purposes;
- relevance, limitation and proportionality;
- retention only for the period required by law or purpose.
The Guide expects the lawyer to be able to explain why the data processed was necessary for the purpose.18
Risky examples include:
- retaining an entire medical history when two pages are enough;
- sending debt information to a number that has not been checked;
- keeping information indefinitely because it might be useful in another matter;
- placing unrelated family information into a pleading;
- downloading everything found online into the evidence file;
- exposing sensitive information in file names, email subjects or physical covers.
15. A signed privacy notice is not the end of the task
The Article 10 information obligation (aydınlatma yükümlülüğü) is not discharged merely by obtaining a signature under a long privacy notice. The controller lawyer should explain, in an understandable form, who is processing the data, which data is used and why, possible recipients, collection method, legal basis and data-subject rights. Where data is not collected directly from the person, the timing may be a reasonable period after collection, the first contact, or no later than the first transfer, depending on the circumstances.19
The Guide’s telephone example supports a layered notice:
- brief information during the call;
- access to fuller information through the website;
- more detailed explanation before an in-person meeting;
- avoiding unnecessary case detail while the person is only a prospective client.
This is particularly useful for law firms because website forms, WhatsApp, telephone calls, email, physical meetings and online booking systems are different collection points.
16. What does the VERBIS exemption actually mean?
Board Decision No. 2018/32 exempts lawyers practising under the Attorneyship Law from the obligation to register with the Data Controllers’ Registry, known as VERBIS. The Guide is clear that this is only an exemption from the registration and notification duty. It does not remove the rest of the KVKK.20
A lawyer without a VERBIS registration should still be able to answer:
- which data categories are processed;
- from whom they are obtained;
- for which purposes and legal grounds;
- to whom they are transferred;
- how long they are retained;
- which security controls apply;
- where a data-subject request should be sent.
The position of law partnerships and other structures should be checked separately by reference to the legal entity and the current exemption decisions.
17. When should files be deleted? One retention period will not solve every issue
Article 39 requires a lawyer to retain documents entrusted to the lawyer for three years after the mandate ends; if the client is notified in writing to collect them, that duty ends three months after the notice. This is not a single automatic retention period for every category of personal data. The continuing retainer, fee claims, tax and accounting records, limitation periods, evidential needs, special statutes and data-subject requests may all point to different periods.21
A retention and deletion schedule should at least separate:
- prospective-client and conflict-check records;
- active litigation and enforcement files;
- closed files;
- powers of attorney;
- accounting and receipt records;
- employee files;
- CCTV and access logs;
- email and backups;
- data disclosed to AI or other external services;
- records retained despite a deletion request and the reason for refusal.
A deletion request does not have to be granted in every case. It should, however, be accepted or rejected within 30 days, with the legal reason clearly stated.
18. When a person applies, the first question is often: where did this data come from?
The Guide observes that many complaints against lawyers focus on the source of the data. The lawyer should be able to show whether the information came from the client, UYAP, a public authority, a lawful public source or another person.22
A matter-management system should therefore record at least:
- source of the data;
- date of collection;
- legal basis;
- matter and purpose;
- recipient of any transfer;
- retention or deletion date;
- the document or system record that evidences the source.
Keeping contact details on the firm’s website and the bar register current also matters, because data-subject applications must reach someone who can act within the statutory time.
19. Wrong email, missing file, stolen phone: when does the 72-hour clock begin?
“Data breach” often brings ransomware or a compromised mailbox to mind. In a law firm, a breach can begin with something far more ordinary: an email sent to the wrong address, a paper file left in a taxi or an unrestricted shared folder.
Where personal data has been unlawfully obtained by others, the notification duty arises under Article 12(5). The 72-hour period for notifying the Board starts when the controller learns of the breach. Once the affected data subjects have been identified, they should be informed as soon as reasonably possible. Missing information may be supplied to the Board in stages without delay; any justified delay should be explained.23
For incidents involving technology suppliers, see our study on cloud-provider data-breach liability and our first 24 hours cyber-incident guide.
Possible law-firm incidents include:
- loss of a physical case file;
- sending an email to the wrong person;
- posting a document in the wrong WhatsApp group;
- loss of a laptop or telephone;
- compromise of an email account;
- uncontrolled sharing of a cloud folder;
- accidental disclosure of sensitive information in a pleading, file name or cover.
A lost file is not automatically reportable in every case. The firm should investigate promptly whether an unauthorised person obtained, or is likely to have obtained, the data; what categories and individuals are affected; and the probable consequences.
A workable incident plan should answer:
- Who receives the first report?
- Who preserves evidence and secures the system or document?
- Who conducts the legal threshold analysis?
- When does the 72-hour calculation begin?
- Who drafts Board and data-subject notices?
- Which actions, decisions and uncertainties are recorded?
20. Data security is not one expensive product; it is a set of reliable habits
The KVKK requires the controller to prevent unlawful processing and access, protect the data and conduct or commission the necessary audits. The Guide connects these duties directly with the lawyer’s professional responsibility.24
Minimum organisational measures for a law firm
- written privacy and information-security policies;
- role-based access and a permissions matrix;
- confidentiality commitments;
- training for lawyers, trainees and support staff;
- supplier due diligence and data-protection clauses;
- a clean-desk and paper-file procedure;
- visitor and physical archive controls;
- an incident-response team and exercise;
- periodic access, data-flow and retention reviews;
- a generative AI policy;
- records of data sources and transfers;
- a procedure for data-subject requests.
Minimum technical measures for a law firm
- individual accounts rather than shared credentials;
- strong passwords and multi-factor authentication;
- device and storage encryption;
- screen lock and automatic session timeout;
- current operating systems and applications;
- endpoint protection and a firewall;
- regular, tested and isolated backups;
- secure email and file transfer;
- restricted external-media use;
- logging and anomaly monitoring;
- secure deletion and disposal;
- access rights removed immediately when a person leaves.
Many of the Guide’s recommended controls are not expensive products. They are disciplined practices: not reusing passwords, checking the recipient twice, locking paper files, removing former staff access and testing whether a backup can actually be restored.25
A 90-day plan for putting the Guide into practice
First 30 days: make the data visible
- Map controller and processor roles.
- Identify every collection point.
- Separate flows for clients, prospective clients, opposing parties, employees and suppliers.
- Review existing privacy and consent documents.
- List cloud, email, matter-management, translation and AI tools.
- Close obvious security gaps: shared passwords, open folders, dormant accounts and unencrypted devices.
Deliverable: data-flow and role map.
Days 31–60: build the documents and controls
- Prepare the legal-basis matrix.
- Set retention and deletion periods.
- Adopt a data-subject request procedure.
- Revise substitution-counsel, supplier and outsourced-service clauses.
- Validate international-transfer mechanisms.
- Complete staff training and confidentiality documents.
- Put the generative AI policy into effect.
Deliverable: compliance file and remediation plan.
Days 61–90: test whether the system works
- Run a sample data-subject request.
- Conduct a breach tabletop exercise.
- Test a wrong-email and lost-file scenario.
- Review access rights.
- Restore from backup.
- Check a sample of matters for source and legal-basis records.
- Put unresolved issues before the partners or management for a documented decision.
Deliverable: a tested and demonstrable KVKK programme for the firm.
Twelve documents a law firm should have close at hand
- Processing and role inventory
- Client and prospective-client privacy notice
- Employee and trainee privacy notice
- Website and contact-form notice
- Retention and deletion policy
- Data-subject request and response procedure
- Personal data breach response plan
- Employee confidentiality undertaking
- Access-rights matrix
- Data-protection clauses for substitution counsel and external providers
- International-transfer records and safeguard file
- Generative AI use policy
Frequently asked questions
Are lawyers completely exempt from Türkiye’s KVKK?
No. The Guide explains that the judicial-authority exemption in Article 28(1)(d) does not generally cover lawyers’ professional processing. Each operation still requires a legal basis and compliance with the general principles.
Is a lawyer always a data controller?
An independent lawyer is generally a controller, but the classification is activity-specific. A lawyer may act as a processor where the purposes and means are fully determined by another controller and the work is genuinely limited by detailed instructions.
Does the client’s instruction make the lawyer a processor?
Not by itself. If the lawyer independently decides the legal strategy, evidence and manner of handling the data, controller status will generally remain.
What is the role of substitute counsel under a tevkil arrangement?
A lawyer appointed only to attend a hearing, attachment or inspection under the instructing lawyer’s defined directions may, on the facts, be treated as a processor. If the substitute uses the information for a new independent purpose, the lawyer may become a controller for that activity.
Should every client sign a KVKK consent form?
No. Where performance of the engagement, legal obligation, express statutory authority or the establishment, exercise or protection of a right already applies, relying on consent may be unnecessary and misleading.
Does the VERBIS exemption remove the law firm’s other duties?
No. The exemption concerns registration and notification to the registry. Transparency, security, retention, request handling and breach duties continue.
Is uploading a pleading to ChatGPT an international transfer?
It may be, depending on the provider, hosting and subprocessors. Even where the provider and processing are in Türkiye, sending the document to an external service can still be a domestic transfer. The firm should assess necessity, minimisation, provider terms and the applicable transfer mechanism before use.
Can a lawyer freely use a photograph or telephone number found online?
No. Public availability does not create unlimited permission. The person’s intention to make the information public, the original purpose and proportionality must be considered.
How quickly must a data-subject application be answered?
As soon as possible and no later than 30 days, depending on the nature of the request. A refusal should include the reason.
Does a lost case file have to be reported to the Board?
The firm should promptly investigate whether the data was unlawfully obtained by others. If the notification duty arises, the 72-hour period starts when the controller learns of the breach; the Board should be notified without delay and within 72 hours, and identified affected people should be informed as soon as reasonably possible.
Final thought: the Guide asks for a working habit, not another folder on the shelf
KVKK compliance in a law firm is not finished when a privacy notice appears on the website. It means being able to answer, from the first intake call until the file leaves the archive:
- Why did we collect this information?
- Who gave it to us, and can we evidence the source?
- Do we need the whole file?
- Who inside the firm can see it?
- What did we send to the court, client, substitute lawyer or technology provider?
- How long will we keep it?
- Can we give a reasoned answer if the person asks?
- Does everyone know what to do in the first hours after a mistake?
- Where does a document really go when we upload it to an AI or cloud service?
That is the Guide’s real value. It treats data protection as a part of professional practice, not as a separate pile of forms. Checking the recipient twice, recording the source, keeping unnecessary information out of a pleading and redacting a file before using an AI tool are all part of the same discipline.
The sensible starting point is not to redesign every file overnight. It is to identify the highest-risk flows and work through them in a structured order. When the role map, processing inventory, retention schedule, transfer records, AI rules and incident plan operate together, compliance becomes visible in practice rather than only on paper.
A law firm’s roles, data flows, legal bases, transfers, retention, AI use and security arrangements can be reviewed against the Guide through a structured Türkiye KVKK compliance assessment. The resulting work may include a gap analysis, document set, contract amendments and a practical 90-day roadmap.
Legal information notice
This article explains a Guide issued by Türkiye’s Personal Data Protection Authority for lawyers practising under Turkish law. It is intended for general information and does not constitute legal advice on a particular law firm, case file, international transfer, AI tool, data-subject request or security incident. Application of the Guide depends on the firm’s legal structure, activities, data categories, suppliers and the facts of the processing operation.
Explore related publications through our Data, Technology and Digital Regulation practice.
Footnotes
-
Turkish Personal Data Protection Authority, ‘Practice Guide on the Protection of Personal Data in Lawyers’ Professional Activities Published’ (22 September 2026), https://www.kvkk.gov.tr/Icerik/8990/avukatlarin-mesleki-faaliyetlerinde-kisisel-verilerin-korunmasina-iliskin-uygulama-rehberi-yayimlandi; full Turkish Guide: https://www.kvkk.gov.tr/SharedFolderServer/CMSFiles/MTZhYjI0ZTE1NWIwMWM.pdf; Union of Turkish Bar Associations, ‘Practice Guide on the Protection of Personal Data in Lawyers’ Professional Activities Introduced’ (22 September 2026), https://www.barobirlik.org.tr/Haberler/avukatlarin-mesleki-faaliyetlerinde-kisisel-verilerin-korunmasina-iliskin-uygulama-rehberi-tanitildi-86703; Avukatların Mesleki Faaliyetlerinde Kişisel Verilerin Korunmasına İlişkin Uygulama Rehberi (KVKK Publications No 115, July 2026) 1–2.↩︎
-
Guide, 38–49; Turkish Personal Data Protection Board, Decision No 2021/115 (9 February 2021); Decision No 2023/78 (19 January 2023).↩︎
-
Guide, 65–70.↩︎
-
Guide, 20–27; Turkish Personal Data Protection Board, Decision No 2020/26 (14 January 2020) https://kvkk.gov.tr/Icerik/6697/2020-26.↩︎
-
Guide, 35–47.↩︎
-
Turkish Personal Data Protection Board, Decision No 2023/437 (22 March 2023) https://kvkk.gov.tr/Icerik/7600/2023-437.↩︎
-
Turkish Personal Data Protection Board, Decision No 2021/115 https://kvkk.gov.tr/Icerik/6928/2021-115; Decision No 2021/424 https://kvkk.gov.tr/Icerik/7114/2021-424; Decision No 2023/78 https://www.kvkk.gov.tr/Icerik/7596/2023-78.↩︎
-
Guide, 31–33.↩︎
-
Guide, 65–70 and 90–92.↩︎
-
Guide, 72–75.↩︎
-
Guide, 90–92; Turkish Personal Data Protection Board, Decision No 2018/10 (31 January 2018) https://kvkk.gov.tr/Icerik/4110/2018-10.↩︎
-
Guide, 95–105; Turkish Personal Data Protection Board, Decision No 2021/1111 (2 November 2021) https://kvkk.gov.tr/Icerik/7266/2021-1111.↩︎
-
Guide, 106–108 and 139; Turkish Personal Data Protection Board, Principle Decision No 2019/308 (18 October 2019) https://kvkk.gov.tr/Icerik/6568/2019-308.↩︎
-
Guide, 108–110.↩︎
-
Guide, 115–120; Law No 6698, art 9.↩︎
-
Guide, 120–122.↩︎
-
Guide, 121–122.↩︎
-
Guide, 123–128.↩︎
-
Guide, 129–131.↩︎
-
Guide, 132–133; Turkish Personal Data Protection Board, Decision No 2018/32 (2 April 2018) https://www.kvkk.gov.tr/Icerik/4233/2018-32.↩︎
-
Guide, 127–128 and 133–134.↩︎
-
Guide, 134–137.↩︎
-
Guide, 139–141; Turkish Personal Data Protection Board, Decision No 2019/10 (24 January 2019) https://kvkk.gov.tr/Icerik/5362/Veri-Ihlali-Bildirimi.↩︎
-
Guide, 143–144.↩︎
-
Guide, 145–146.↩︎
