KVKK Otomat

Transferring Personal Data Out of Turkey: What Replaced Explicit Consent

September 3, 2026 · 5 min read · Muhammet Çay

Short answer: Law No. 7499 amended Article 9 of Turkey's Law No. 6698 in March 2024, and the implementing Regulation was published on 10 July 2024. Since 1 September 2024, explicit consent is no longer available as a routine basis for transferring personal data abroad. Transfers must instead rest on an adequacy decision, on an appropriate safeguard (standard contractual clauses, binding corporate rules, or an undertaking), or on one of the limited occasional-case exceptions. Turkey has not yet issued adequacy decisions, so standard contractual clauses published by the Authority are the practical mechanism for most transfers — and they must be used without modification and notified to the Authority within five business days of signing.

The price of a late filing. Failure to notify a standard contract carries its own band — TRY 90,308–1,806,377 for 2026 — full fine table.

If your company moves employee, customer or supplier data from Turkey to a parent company, a cloud region or a shared service centre abroad, the legal basis you were using before September 2024 has probably been withdrawn.

This is one of the sharpest divergences between Turkish practice and GDPR practice, and it catches international teams because the old answer — get explicit consent — was simple, and the new answer is not.

This article is general information, not legal advice. Turkish counsel should review your transfer arrangements.

What changed

Law No. 7499 amended Article 9 of Law No. 6698 in March 2024. The implementing regulation, the Regulation on the Procedures and Principles Regarding the Cross-Border Transfer of Personal Data, was published on 10 July 2024.

Before the amendment, most transfers out of Turkey in practice rested on the data subject's explicit consent, because the alternative — a written undertaking approved by the Board — was slow and rarely granted.

Since 1 September 2024 explicit consent is no longer available as a routine transfer basis. It survives only inside the narrow set of occasional-case exceptions.

The three tiers

The framework will look familiar to anyone who works with Chapter V of the GDPR.

Tier 1 — Adequacy decision. The Board may decide that a country, a sector within a country, or an international organisation provides adequate protection. Adequacy decisions are re-evaluated at least every four years.

Tier 2 — Appropriate safeguards. Where there is no adequacy decision, the transfer may proceed on the basis of an appropriate safeguard, provided the data subject can exercise rights and effective remedies remain available in the destination. The instruments are standard contractual clauses, binding corporate rules, an undertaking, or an agreement between public bodies.

Tier 3 — Occasional cases. A narrow list of exceptions for non-routine, one-off transfers. This is not a route for ongoing operational data flows; the word occasional is doing real work.

Why standard contractual clauses are the practical answer

Here is the fact that determines most compliance plans: Turkey has not yet issued adequacy decisions. The Board has been working through country assessments, but no destination is covered.

That removes Tier 1 for everyone. Binding corporate rules are available but are a long project suited to large groups with intra-group transfers. Undertakings still require Board approval.

For most companies, the practical route is the standard contractual clauses published by the Authority.

The three traps in the standard contractual clauses

Use them verbatim. The clauses must be used exactly as published by the Authority. Editing them — even to align wording with your global template or your EU SCCs — undermines their validity. This is stricter than the GDPR practice of adding commercial annexes around an unmodified core.

Turkish is the governing text. A Turkish-language version is required and prevails over foreign-language versions. If your legal team negotiates in English, the English text is not the operative one. Build translation review into the signing process rather than treating it as an afterthought.

Notify within five business days. After signing, the standard contract must be notified to the Authority within five business days. Commentary on the Authority's enforcement practice points to missed notification deadlines as one of the most common triggers for penalties — a purely procedural lapse with real financial consequences.

That third point is where international teams lose. The contract gets signed by a legal entity abroad, sits in a signature workflow for two weeks, and the deadline passes before anyone in Turkey sees it.

A workable sequence

  1. Map every flow that leaves Turkey, including remote access from abroad — access counts, not just copying
  2. For each flow, identify the receiving entity and the country
  3. Discard explicit consent as the basis for anything recurring
  4. Decide the instrument: SCC for most, BCR only if you are a group with the appetite for it
  5. Execute the Authority's clauses unmodified, with the Turkish text as governing
  6. Calendar the five-business-day notification from the signature date, with a named owner
  7. Keep the transfer inventory current — it is the first thing requested in an inspection

Step 1 is the one most often done too narrowly. A support engineer in another country opening a Turkish customer record is a transfer.

How this differs from GDPR

If you already run a GDPR transfer programme, three differences matter:

GDPR Turkey
Adequacy Several decisions in force None issued yet
SCC modification Core unmodified, annexes added commercially Must be used exactly as published
Language Working language acceptable Turkish version prevails
Filing No routine filing of SCCs Notify within five business days

The last row has no GDPR equivalent, which is precisely why it is the one that gets missed.

For the broader comparison see KVKK vs GDPR. If you are also reviewing your Turkish-facing consent forms, note that a separate 2026 decision changed how notices and consent must be presented — Principle Decision 2026/347.

Frequently asked questions

Can we still rely on explicit consent?

Only within the occasional-case exceptions, and those are meant for one-off situations rather than ongoing flows. Building a recurring transfer on consent after September 2024 is not a defensible position.

Does using a European cloud provider solve it?

No. There is no adequacy decision covering the EU, so an EU destination needs the same instrument as any other. A provider's GDPR posture does not substitute for the Turkish requirement.

Is intra-group transfer treated differently?

The same tiers apply. Binding corporate rules exist for groups, but they require preparation and approval; most groups start with standard contractual clauses and consider BCRs later.

What if we transferred data before September 2024?

Arrangements made under the previous regime do not retroactively become lawful under the new one for ongoing transfers. Re-paper recurring flows on a current instrument, and take Turkish advice on the transition for anything historic.

Sources

This article is based on the sources above. Legislation and Board practice change, and the adequacy position in particular may move; rely on the Authority's current publications and Turkish counsel before acting.


The Turkish-language document set: KVKK Otomat generates the privacy notice, consent text, processing inventory and retention policy in Turkish from your process map. Drafts only; Turkish counsel review recommended. See also: VERBIS registration for foreign companies · KVKK compliance checklist.