Compliance with Turkish data protection law is not a one-off document exercise. The process begins by identifying processing activities and becomes a cycle that must be revisited as the organisation changes.
1. Building the Data Inventory
The foundation of any compliance project is establishing what personal data the company processes, for what purpose, on what legal basis, and for how long it is retained. Privacy notices drafted without an inventory do not reflect the actual position and therefore offer no protection.
2. Identifying the Legal Basis
Each processing activity must rely on one of the conditions in Article 5 of the Law. Explicit consent is not the first basis to reach for; it is the option that arises where none of the other conditions apply. The provision of a service may not be made conditional on explicit consent.
3. The Document and Policy Set
- Privacy notices, prepared separately for each category of data subject (employees, customers, visitors, candidates)
- Explicit consent statements, only where genuinely required
- A retention and destruction policy with a periodic destruction schedule
- Agreements between the data controller and data processors
- An internal procedure for responding to data subject requests
4. VERBİS Registration
Data controllers meeting the criteria set by the Authority must register with VERBİS. Registration means entering a summary of the inventory into the system, and it must be updated whenever the inventory changes.
5. Breach Response Plan
In the event of a breach, the data controller must notify the Authority without delay and in any event within seventy-two hours of becoming aware of it. Because that window is short, a written response plan setting out who takes which step must be prepared in advance.
Notification to affected data subjects must be made within the shortest reasonable time and in plain language.