KVKK and GDPR are not the same thing. Turkish companies are learning this the hard way.
The compliance assumption that keeps catching teams off guard — and what to actually do about it.
KVKK and GDPR are not the same thing. Turkish companies are learning this the hard way.
The compliance assumption that keeps catching teams off guard — and what to actually do about it.

Three months ago, a client forwarded me a KVKK enforcement notice.
Their cloud setup was reasonable. European provider, GDPR compliant, data stored in Frankfurt. They’d done the work — or thought they had. When I asked about their KVKK compliance specifically, the answer was a version of: “we’re on a GDPR-compliant provider, so we’re covered.”
They weren’t — but not for the reason you might think.
Before I go further: I work at Cloud4U, where we help Turkish and MENA companies with cloud infrastructure decisions. That’s a relevant disclosure for an article about cloud compliance. My view is that regional providers with infrastructure close to Turkey simplify the KVKK picture — but simplify is not the same as required. There are multiple valid paths to compliance, and I’ll cover them all.
GDPR compliance and KVKK compliance overlap significantly. In other places they’re meaningfully different. The gap between them — the part most Turkish startups are missing — is usually not about which cloud provider you use. It’s about whether you’ve actually established a legal basis for your data transfers, documented it, and built the right processes around it.
That’s fixable. But it’s much easier to fix before you’ve built around the wrong assumption than after.
What KVKK actually requires — the short version
KVKK — Kişisel Verilerin Korunması Kanunu — is Turkey’s personal data protection law, in force since 2018. If you’re processing personal data of Turkish citizens, it applies to you. Yes, that means your Turkish startup with Turkish users.
The parts that most cloud infrastructure discussions skip:
Data transfers outside Turkey require a legal basis. Unlike the EU’s GDPR adequacy framework — which maintains a formal public list of countries deemed adequate — KVKK takes a different approach. The KVKK Board assesses adequacy on a case-by-case basis, generally looking for alignment with Convention 108 standards and protections broadly equivalent to GDPR. There’s no simple public checklist to check against.
The legal bases available for international transfers include: explicit and specific user consent; Standard Contractual Clauses (SCCs); Binding Corporate Rules; and certain derogations for specific situations. AWS, Azure, and GCP all offer Data Processing Addendums with SCCs that satisfy KVKK requirements — this is a legitimate and widely used compliance path. Major Turkish tech companies, including some of the largest, run on hyperscalers and are KVKK compliant via exactly these mechanisms.
GDPR compliance in your provider helps, but isn’t sufficient on its own. KVKK has specific requirements around user rights, data subject request handling, DPO registration thresholds, and legal bases for transfers — even when using a provider that’s fully GDPR compliant. The overlap is significant but incomplete.
The client in my opening story wasn’t running afoul of KVKK because of where their data was stored. They were running afoul because they hadn’t established and documented a legal basis for their international transfers, and their privacy notice didn’t meet Turkish requirements. Infrastructure location was the least of their problems.
Two paths to compliance — pick the one that fits your stage
Here’s the practical framing.
Path one: contractual safeguards. Sign a DPA with SCCs with your cloud provider. Ensure your provider has sub-processor transparency and audit-ready documentation. This is the path most Turkish companies on hyperscalers use. It works. It requires a lawyer to review your contracts and ensure the documentation is in order, but the infrastructure itself doesn’t need to change.
Path two: infrastructure location. Choose a provider with infrastructure in or near Turkey, or in a jurisdiction with strong data protection alignment, combined with explicit KVKK compliance documentation. This reduces the complexity of the transfer question — if personal data doesn’t cross a border, the cross-border transfer rules are simpler to navigate. It doesn’t eliminate the need for proper consent flows, privacy notices, and DPO registration if applicable, but it removes one layer of the problem.
Neither path is categorically better. The right choice depends on your stage, your existing infrastructure investment, your risk tolerance, and frankly how much legal complexity you want to manage. A seed-stage startup with five engineers might find path two simpler to reason about. A Series B company already deep in an AWS ecosystem might find path one more practical.
What doesn’t work: assuming that because your provider is GDPR compliant, the KVKK question is answered. That’s the gap.
What KVKK enforcement actually focuses on
Worth being clear about this, because infrastructure location gets more attention in compliance discussions than it probably deserves.
KVKK enforcement actions have primarily focused on:
- Lack of Turkish-language privacy notices
- Inadequate or missing user consent mechanisms
- Failure to report data breaches within the required timeframe
- Missing DPO registration where required
- Responding poorly or not at all to data subject requests
The use of EU-based cloud infrastructure, with proper legal bases in place, has not been a primary driver of enforcement actions. This is useful context. It means that if you’re choosing between spending your compliance budget on getting your privacy notice right versus agonising over server geography, the privacy notice is probably the higher-priority item.
That said — infrastructure decisions are harder to change later than process decisions. Getting the infrastructure picture right early, even if enforcement focus is elsewhere today, is sensible risk management.
The audit that takes an hour and that most teams haven’t done
Regardless of which compliance path you choose, knowing where your data actually lives is the foundation. You can’t establish a legal basis for transfers you don’t know are happening.
Log into your cloud provider. Find every storage resource — not just databases, but object storage buckets, backup destinations, log sinks, data exports. Write down the region for each one.
Then do the same for your third-party tools. Where does your analytics platform store data? Your error tracking tool? Your customer support software? These are often overlooked because they’re not “cloud infrastructure” in the obvious sense, but they process personal data and they have their own storage locations.
Now look at your list. For everything outside Turkey, ask: what’s the legal basis for this transfer? Is there a DPA with SCCs in place? Is there explicit user consent? Is there documentation you could show an auditor?
If the answer to any of those is “I’m not sure,” that’s where to focus.
What to do this week — specifically
Map your data. Where does it live — all of it, including third-party tools. This is the foundation of everything else and it takes about an hour.
Check your DPAs. If you’re on a major cloud provider, find your Data Processing Addendum. Read it. Confirm it includes SCCs for international transfers. If you’re not sure whether it covers KVKK specifically, ask your provider directly — the good ones have documentation for this.
Review your privacy notice. Is it in Turkish? Does it accurately describe your data processing activities, your legal bases, and your transfer mechanisms? This is where most enforcement actions originate.
Look at DPO registration requirements. KVKK has thresholds above which a Data Protection Officer registration is required. If you’re processing data at meaningful scale, check whether you’re above them.
Talk to a lawyer. I’ve given you the infrastructure framing and a map of the compliance landscape. The legal framing — especially for your specific situation, contracts, and consent flows — needs someone qualified to give it.
The infrastructure decisions are yours to make. Make them with the full picture in mind, not just the parts that are easy to google.
메타데이터
- post_id
- 7607c710d2b2
- slug
- kvkk-and-gdpr-are-not-the-same-thing-turkish-companies-are-learning-this-the-hard-way-7607c710d2b2
- url
- https://medium.com/@mehmet.ozturk_72996/kvkk-and-gdpr-are-not-the-same-thing-turkish-companies-are-learning-this-the-hard-way-7607c710d2b2
- canonical_url
- https://medium.com/@mehmet.ozturk_72996/kvkk-and-gdpr-are-not-the-same-thing-turkish-companies-are-learning-this-the-hard-way-7607c710d2b2
- author_url
- https://medium.com/@mehmet.ozturk_72996
- status
- ok
- fetched_at
- 2026-06-09 15:37:30