Database

Browse Database

TÜRKIYE

Since April 2021

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Regulation on Electric Scooters (Elektrikli Skuter Yönetmeliği)
Art. 8 of the Regulation on Electric Scooters stipulates that the servers hosting databases related to e-scooter operations must be located within the territory of the Republic of Türkiye and must provide unrestricted access to the competent Authority.
Coverage Electric scooter service providers

TÜRKIYE

Since July 2019
Since July 2020

Pillar Cross-border data policies  |  Indicator Local storage requirement
Presidential Circular on Information and Communication Security Measures No. 2019/12 (2019/12 Sayılı Cumhurbaşkanlığı Bilgi ve İletişim Güvenliği Tedbirleri Genelgesi)

Information and Communication Security Guide (Bilgi ve İletişim Güvenliği Rehberi)
According to Art. 1 of Circular 2019/12, critical information and data, including population statistics, health and communication records, as well as genetic and biometric data, must be securely stored within the territory of Türkiye. It is reported that it is generally understood that Art. 1 does not constitute a prohibition on cross-border data transfers; rather, it is interpreted primarily as imposing an obligation to maintain a domestic backup of the relevant data to ensure accessibility. Similarly, Section 4.3.1.1 of the Information and Communication Security Guide underscores the necessity of domestic storage of critical data when utilising cloud services.
Circular 2019/12 and the accompanying Guide are directed at public institutions and providers of critical infrastructure services across a range of sectors, including telecommunications and electronic communications, water management, energy, essential public services such as healthcare, transportation, banking, and finance. The Guide defines critical infrastructure as systems whose compromise, through breaches of confidentiality, integrity, or availability, could result in large-scale harm, national security vulnerabilities, or significant disruption to public order.
Coverage Public sector and critical infrastructure

TÜRKIYE

Since July 2019
Since July 2020

Pillar Cross-border data policies  |  Indicator Local storage requirement
Presidential Circular on Information and Communication Security Measures No. 2019/12 (2019/12 Sayılı Cumhurbaşkanlığı Bilgi ve İletişim Güvenliği Tedbirleri Genelgesi)

Information and Communication Security Guide (Bilgi ve İletişim Güvenliği Rehberi)
Art. 3 of Circular 2019/12 stipulates that data relating to public institutions and organisations may not be stored on cloud services, except where such services are operated by the institution itself or by local service providers under its control. It is reported that it is generally understood that Art. 3 does not constitute a prohibition on cross-border data transfers; rather, it is interpreted primarily as imposing an obligation to maintain a domestic backup of the relevant data to ensure accessibility.
Coverage Public sector

TÜRKIYE

Since July 2014
Since June 2013, as amended in March 2015, last amended in June 2020
Since October 2005, as amended in February 2020

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Regulation on Internal Systems and Internal Capital Adequacy Assessment Process of Banks (Bankaların İç Sistemleri ve İçsel Sermaye Yeterliliği Değerlendirme Süreci hakkında Yönetmelik)

Law No. 6493 on Payments and Security Settlement Systems, Payment Services and Electronic Money Institutions (Ödeme ve Menkul Kıymet Mutabakat Sistemleri, Ödeme Hizmetleri ve Elektronik Para Kuruluşları Hakkında Kanun - Kanun Numarası: 6493)

Banking Law No. 5411 (Bankacilik Kanunu No. 5411)
Certain regulations mandate that financial institutions retain both their primary and secondary systems within the borders of Türkiye, prohibiting the systematic transfer of such data abroad for banks, financial leasing and factoring companies, publicly traded companies, pension investment funds, and other entities regulated by the Capital Markets Board. These regulations include the Regulation on Internal Systems and Internal Capital Adequacy Assessment Process of Banks, whose Art. 11(4) stipulates that Turkish banks must host their primary data systems—comprising the infrastructure, hardware, software, and data necessary for recording and utilising all information required to conduct banking activities and meet legislative obligations—within Türkiye. Likewise, their secondary data systems, which serve as backups, must also be stored domestically. Additionally, Art. 23 of Law No. 6493 requires system operators to maintain information systems and their backups domestically. A system operator is defined as a legal entity responsible for the day-to-day functioning of payment or securities settlement systems, holding the requisite licence for such operations. This provision further compels online payment services, such as PayPal, to retain all data in Türkiye for a minimum of ten years. The law specifies: “The system operator, payment institution, and electronic money institution shall be required to keep all documents and records related to matters within the scope of this Law for at least ten years within the country, in a secure and accessible manner.”
Additionally, under Art. 73 of the Banking Law, the Banking Regulation and Supervision Authority (BRSA) is empowered to prohibit the sharing or transfer of customer data or bank secrets with third parties outside Türkiye. The BRSA may also mandate that banks maintain their information systems and backups within Türkiye, based on assessments related to economic security.
Coverage Financial sector
Sources

TÜRKIYE

Since April 2016, last amended in June 2024
Since July 2024

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Personal Data Protection Law No. 6698 (6698 sayılı Kişisel Verilerin Korunması Kanunu)

Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad No. 32598 (Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelik (Sayı: 32598))
Under Art. 9 of the Turkish Personal Data Protection Law, personal data may be transferred abroad only if the conditions set out in Arts. 5 and 6, which govern the lawful processing of personal data and special categories of personal data respectively, are satisfied. In addition, one of several safeguards must be in place. These include an adequacy decision by the Personal Data Protection Authority (KVKK) concerning the recipient country, sector, or international organisation. In the absence of such a decision, transfers may proceed if the data subject retains enforceable rights and access to effective legal remedies in the destination country, and if mechanisms such as Personal Data Protection Board-approved commitment letters, binding corporate rules (BCRs), or standard contractual clauses (SCCs) are implemented. Transfers may also be authorised through administrative arrangements between public institutions, subject to the Board’s approval. Where neither an adequacy decision nor appropriate safeguards are available, data may still be transferred under specific derogations. These include the data subject’s explicit and informed consent, the necessity of the transfer for the performance of a contract or pre-contractual measures, the conclusion or performance of a contract in the data subject’s interest, reasons of public interest, the establishment or defence of legal claims, situations of physical impossibility, or access to public registers by individuals with a legitimate interest.
The Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad provides the procedural framework for implementing Art. 9.
Coverage Horizontal

TÜRKIYE

Since November 2008, as amended in January 2015

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Electronic Communications Law No. 5809 (5809 sayılı Elektronik Haberleşme Kanununun)
Art. 51 of the Electronic Communications Law stipulates that the transfer of traffic and location data abroad is permitted with the data subject's explicit consent.
Coverage Electronic communications sector

TÜRKIYE

N/A

Pillar Cross-border data policies  |  Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Türkiye has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal

TÜRKIYE

Since April 2016, last amended in June 2024

Pillar Domestic data policies  |  Indicator Framework for data protection
Personal Data Protection Law No. 6698 (6698 sayılı Kişisel Verilerin Korunması Kanunu)
The Personal Data Protection Law establishes a comprehensive data protection regime in Türkiye. It provides for the establishment of the Personal Data Protection Authority (KVKK) and the Data Protection Board as the bodies entrusted with supervisory and enforcement functions. Within the institutional structure of the KVKK, the Board functions as its decision‑making organ, whereas the KVKK itself predominantly fulfils administrative duties. The KVKK is constituted as an independent regulatory authority with institutional and financial autonomy and is mandated both to ensure the protection of personal data and to promote awareness in this area.
Coverage Horizontal

TÜRKIYE

Since June 2013, as amended in March 2015, last amended in June 2020

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Law No. 6493 on Payments and Security Settlement Systems, Payment Services and Electronic Money Institutions (Ödeme ve Menkul Kıymet Mutabakat Sistemleri, Ödeme Hizmetleri ve Elektronik Para Kuruluşları Hakkında Kanun - Kanun Numarası: 6493)
Art. 23 of Law No. 6493 requires that "the system operator, payment institution and electronic money institution shall be required to keep all the documents and records related to the matters within the scope of this Law for at least ten years within the country, in a secure and accessible manner". The article also specifies that "The information systems and their substitutes, which are used by the system operator to carry out its activities shall also be kept within the country".
Coverage E-money institutions and payment services providers

TÜRKIYE

Since November 2008, as amended in December 2020 and entered into force in June 2021

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Electronic Communications Law No. 5809 (5809 sayılı Elektronik Haberleşme Kanununun)
According to Art. 51.10 of the Electronic Communications Law No. 5809:
- Personal data subject to inspection, examination, investigation or dispute shall be retained until the related period has been completed;
- Logs regarding the access of personal data and related other systems are retained for two years;
- Logs that prove the consent of subscribers/users for processing personal data are retained throughout the subscription period;
- Categories of data to be retained and data retention periods, not less than one year and not more than two years from the date of the communication, are determined by secondary law.
Coverage Telecommunications sector

TÜRKIYE

Since January 2018

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Regulation on the Registry of Data Controllers (Veri Sorumluları Sicili Hakkında Yönetmelik)
According to Art. 11 of the Regulation on the Registry of Data Controllers, a contact person must be appointed if the data controller is a legal entity located in Türkiye and is not exempt from registration with the Turkish Personal Data Protection Authority. Additionally, if the data controller is not located in Türkiye, it must appoint a representative who must be either a Turkish legal entity or a Turkish citizen.
The data controller’s contact person or representative is responsible for managing communications with the Turkish Personal Data Protection Authority and data subjects. Data controllers remain liable for compliance with the Protection of Personal Data Law regardless of the appointment of a contact person or a representative.
Coverage Horizontal

TÜRKIYE

Reported in 2022, last reported in 2025

Pillar Public procurement of ICT goods and online services  |  Indicator Other limitations on foreign participation in public procurement
Complaints on public procurement
It is reported that, although Turkish procurement law requires contracting authorities to give due consideration to best value for money, the vast majority of tenders are awarded on the basis of the lowest bid price, a practice which, in the procurement of highly technical goods or services, may exclude firms with the greatest capacity and expertise, including foreign companies that often offer a wider range of services, lower life‑cycle costs, and higher-quality products; moreover, additional features of the Turkish procurement system significantly restrict the participation of foreign firms, as the mandatory use of standardised model contracts limits their ability to submit proposals fully tailored to the specific requirements of procuring authorities, while foreign companies, including those operating through Turkish subsidiaries, have reported persistent difficulties in meeting extensive and onerous documentation requirements imposed by contracting agencies.
Coverage Horizontal

TÜRKIYE

Since November 2008

Pillar Telecom infrastructure & competition  |  Indicator Presence of an independent telecom authority
Electronic Communication Law No. 5809 (Elektroni̇k haberleşme kanunu)
According to Electronic Communication Law No. 5809, the executive authority for the supervision and administration of services in the telecommunications sector in Türkiye is the Information and Communication Technologies Authority. It is reported that the Information and Communication Technologies Authority is independent from the government in the decision-making process.
Coverage Telecommunications sector

TÜRKIYE

N/A

Pillar Public procurement of ICT goods and online services  |  Indicator Signatory of the WTO Agreement on Government Procurement (GPA) with coverage of the most relevant services sectors (CPC 752, 754, 84)
Lack of participation in the WTO Agreement on Government Procurement (GPA)
Türkiye is not a party to the World Trade Organization (WTO) Agreement on Government Procurement (GPA). However, the country has been an observer of the WTO GPA since 1996.
Coverage Horizontal

TÜRKIYE

Since June 2003

Pillar Foreign Direct Investment (FDI) in sectors relevant to digital trade  |  Indicator Maximum foreign equity share
Foreign Direct Investment Law No. 4,875 (4875 Sayılı Doğrudan Yabancı Yatırımlar Kanunu)
According to Art. 3 (a) of the Foreign Direct Investment Law, full foreign ownership is allowed. Unless stipulated by international agreements or other special laws, foreign investors are free to make investments and shall be subject to equal treatment as domestic investors.
Coverage Horizontal

Report issue     Report new measure