Turkish administrative fines are set in nominal Turkish lira and re-indexed every year, which means figures found in older articles are almost always wrong. These are the amounts in force for 2026.
This article is general information, not legal advice.
The 2026 bands
Article 18 of Law No. 6698 sets the violation categories; the amounts below reflect the 25.49% revaluation rate applied for 2026, published in the Official Gazette of 27 November 2025 (General Communiqué No. 585 on the Tax Procedure Law).
| Violation (Art. 18) | Lower | Upper |
|---|---|---|
| Failure to fulfil the obligation to inform (privacy notice) | TRY 85,437 | TRY 1,709,200 |
| Failure to fulfil data security obligations | TRY 256,357 | TRY 17,092,242 |
| Failure to comply with Board decisions | TRY 427,263 | TRY 17,092,242 |
| Breach of VERBIS registration and notification obligations | TRY 341,809 | TRY 17,092,242 |
A separate band applies to failure to notify a standard contract used for cross-border transfers: TRY 90,308 – 1,806,377.
That last row deserves attention out of proportion to its size. It penalises a purely administrative omission — the contract exists, the safeguard is in place, but the filing was late. Commentary on the Authority's enforcement practice points to missed notification deadlines as a recurring trigger. The deadline is five business days from signature; see cross-border transfers and standard contractual clauses.
How the amounts move
The bands are not fixed in the Law as spendable numbers; they are re-indexed annually under Article 17 of the Misdemeanours Law (No. 5326) using the revaluation rate set by the Ministry of Treasury and Finance for the preceding year.
Two practical consequences:
Budget in the current year's figures. A compliance budget built on last year's table understates exposure by the revaluation rate.
Distrust undated sources. Any article quoting KVKK fines without naming a year and a revaluation rate is stale. The 25 million TRY threshold for VERBIS, for instance, still circulates widely even though the balance-sheet threshold is now 100 million TRY — see who must register with VERBIS.
Why these are not GDPR fines
International teams routinely mis-model Turkish exposure by analogy to GDPR. Three structural differences:
No turnover-based tier. GDPR's upper tier is the greater of a fixed amount or 4% of global annual turnover. Turkish fines are absolute amounts with no turnover multiplier. For a large multinational this makes the nominal exposure materially lower.
Nominal lira, annual indexation. The bands are lira amounts adjusted yearly, so their value in euro or dollar terms moves with both indexation and the exchange rate.
Different violation taxonomy. The categories are drawn around Turkish obligations — the VERBIS registry and the standard-contract notification have no GDPR counterpart at all.
The conclusion many teams draw from the first point — that Turkish exposure is negligible — misses where the real cost sits. The operational consequence of a Board decision (suspending a processing activity, unwinding a transfer arrangement, re-papering forms across every channel) is usually larger than the fine, and the fine for not complying with a Board decision is in the highest band.
What actually gets penalised
Looking at the categories rather than individual cases, the pattern is that procedural and documentary failures dominate. The privacy notice is the first document requested in a complaint or an ex officio review, and defects there are visible immediately — which is why the 2026 principle decision on notice and consent structure matters practically as well as legally: see Decision 2026/347.
Three low-cost items that remove a disproportionate share of exposure:
- A privacy notice that is actually given before processing begins, in the required structure
- VERBIS registration if any threshold is met — the thresholds are alternatives, not cumulative
- A calendared owner for the five-business-day standard contract notification
None of these requires a large budget. All three sit in the categories the Authority acts on.
Frequently asked questions
Are fines per violation or per data subject?
Fines are imposed per violation of the relevant obligation, not multiplied by the number of data subjects. The number of people affected is, however, relevant to where within the band the amount falls.
Can a foreign company be fined?
The Law applies to processing of personal data of individuals in Turkey; being established abroad does not by itself remove the obligations. Foreign controllers with Turkish operations, employees or customers should assume they are in scope and take Turkish advice.
Do fines apply to individuals or only companies?
Article 18 addresses data controllers, which may be natural or legal persons. Separately, the Law contains criminal provisions handled under the Turkish Penal Code, which are a different track from administrative fines.
Where do I find the current figures?
The Authority publishes the annual amounts; the underlying revaluation rate comes from the Ministry's General Communiqué each November. Check both rather than a secondary source.
Sources
- Law No. 6698 on the Protection of Personal Data (full text, Turkish)
- Misdemeanours Law No. 5326, Article 17 (annual indexation of amounts)
- General Communiqué No. 585 on the Tax Procedure Law — Official Gazette, 27.11.2025, No. 33090 (revaluation rate 25.49%)
- Turkish Personal Data Protection Authority
Amounts are re-indexed annually; verify against the Authority's current publication before relying on them.
Reducing the documentary exposure: KVKK Otomat generates the Turkish privacy notice, consent text, processing inventory and retention policy from your process map — drafts, with Turkish counsel review recommended. Start with the KVKK compliance checklist or the Turkish data protection law guide.


