Law / Turkey

Personal Data Protection Law (KVKK), enforcement and compensation

Law No. 6698, Arts. 11(1)(g), 18

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 7 April 2016.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • An app processing the personal data of a person in Turkey must be prepared to answer to the KVKK Board for its lawful basis and safeguards, facing tiered administrative fines for a violation, and an individual harmed by unlawful processing may claim compensation in court, but only on proof of the damage suffered.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

KVKK Art. 17(1) cross-references Turkish Penal Code (Law No. 5237) Arts. 135 to 140 for crimes involving personal data. Unlawfully recording personal data (Art. 135) carries imprisonment from one to three years, increased by half, up to four and a half years, where the data concerns political, philosophical or religious opinion, racial origin, or, unlawfully, moral tendency, sexual life, health, or trade-union affiliation. Unlawfully giving, disseminating, or obtaining personal data (Art. 136) carries imprisonment from two to four years, the highest base tier of the group. A public official who abuses the authority of office, or a person who exploits a professional facility, in committing one of these offenses faces a further one-half increase (Art. 137). Failing to destroy data after the statutory retention period has expired, contrary to KVKK Art. 7, is separately punished under Art. 138 with imprisonment from one to two years (KVKK Art. 17(2)). Prosecution of the Art. 135, 136, and 138 offenses proceeds without a victim complaint (Art. 139), and a legal person faces security measures for these offenses under Turkish law (Art. 140).

Penalty structure

Art. 18(1) sets five fixed-range administrative-fine tiers: (a) 5,000 to 100,000 TL for failing the Art. 10 notice obligation; (b) 15,000 to 1,000,000 TL for failing the Art. 12 data-security obligations; (c) 25,000 to 1,000,000 TL for noncompliance with a Board decision issued under Art. 15; (ç) 20,000 to 1,000,000 TL for violating the Data Controllers' Registry registration and notification obligations under Art. 16; and (d), added by Law No. 7499 (2 March 2024), 50,000 to 1,000,000 TL for failing the Art. 9(5) cross-border transfer-notification obligation. fixed_cap records the ceiling shared by tiers (b), (c), (ç) and (d). These are the amounts stated in the Act's own text. Kabahatler Kanunu (Misdemeanors Law No. 5326) Art. 17(7) requires fixed-range administrative fines generally to be increased each calendar year by the revaluation rate announced under Tax Procedure Law No. 213's repeated Art. 298, so the amount actually collectible in a given year runs above these statutory base figures; no KVKK announcement stating the currently applicable revalued amounts was reachable through the primary-source channel used for this research, so the statutory base figures are recorded here.

Rule
Fixed only
As of
2 September 2026
Currency
TRY
Fixed cap
1,000,000

Who enforces it

Enforcement body

Kisisel Verileri Koruma Kurulu (Personal Data Protection Board)

Enforcement record

KVKK 2025 Yılı Faaliyet Raporu (2025 Annual Activity Report), Table 18: in 2025 the Board imposed Art. 18 administrative fines on 876 data controllers in total (140 for complaint/report matters, 142 for data breach notifications, 594 for Data Controllers' Registry and notification-obligation violations), totalling 352,510,494 TL. The prior year's total was 551,139,817 TL (2024), so the latest year-over-year figure fell, though the five-year series (2021: 31,746,000 TL; 2022: 85,483,000 TL; 2023: 240,912,000 TL) still shows a longer-run rise. Counts KVKK Board-imposed administrative fines only; the report does not separately track private civil compensation claims filed under Art. 11(1).

As of
2 September 2026
Trend
Falling
Currency
TRY
Source link
https://www.kvkk.gov.tr/SharedFolderServer/CMSFiles/MTY5ZjMxYTVlZGY0Y2Y.pdf
Fines per year
352,510,494
Actions per year
876

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Personal Data Protection Board (KVKK) enforces the Act with tiered administrative fines under Art. 18: 5,000 to 100,000 TL for notice failures, 15,000 to 1,000,000 TL for security failures, 25,000 to 1,000,000 TL for noncompliance with a Board decision, 20,000 to 1,000,000 TL for registry failures, and, added by Law No. 7499 in 2024, 50,000 to 1,000,000 TL for Art. 9(5) transfer-notification failures; fines are now appealable to administrative courts under Art. 18(3), also added in 2024.

Art. 11(1)(g) lets a data subject claim compensation for the damage arising from the unlawful processing, which requires proof of damage, unlike a no-proof-of-damage statutory-damages tort found elsewhere in this region.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official statute text, KVKK Kurumu consolidated English translation

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app