Personal Data Protection Law (KVKK), enforcement and compensation
Law No. 6698, Arts. 11(1)(g), 18
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 7 April 2016.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- An app processing the personal data of a person in Turkey must be prepared to answer to the KVKK Board for its lawful basis and safeguards, facing tiered administrative fines for a violation, and an individual harmed by unlawful processing may claim compensation in court, but only on proof of the damage suffered.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
KVKK Art. 17(1) cross-references Turkish Penal Code (Law No. 5237) Arts. 135 to 140 for crimes involving personal data. Unlawfully recording personal data (Art. 135) carries imprisonment from one to three years, increased by half, up to four and a half years, where the data concerns political, philosophical or religious opinion, racial origin, or, unlawfully, moral tendency, sexual life, health, or trade-union affiliation. Unlawfully giving, disseminating, or obtaining personal data (Art. 136) carries imprisonment from two to four years, the highest base tier of the group. A public official who abuses the authority of office, or a person who exploits a professional facility, in committing one of these offenses faces a further one-half increase (Art. 137). Failing to destroy data after the statutory retention period has expired, contrary to KVKK Art. 7, is separately punished under Art. 138 with imprisonment from one to two years (KVKK Art. 17(2)). Prosecution of the Art. 135, 136, and 138 offenses proceeds without a victim complaint (Art. 139), and a legal person faces security measures for these offenses under Turkish law (Art. 140).
Penalty structure
Art. 18(1) sets five fixed-range administrative-fine tiers: (a) 5,000 to 100,000 TL for failing the Art. 10 notice obligation; (b) 15,000 to 1,000,000 TL for failing the Art. 12 data-security obligations; (c) 25,000 to 1,000,000 TL for noncompliance with a Board decision issued under Art. 15; (ç) 20,000 to 1,000,000 TL for violating the Data Controllers' Registry registration and notification obligations under Art. 16; and (d), added by Law No. 7499 (2 March 2024), 50,000 to 1,000,000 TL for failing the Art. 9(5) cross-border transfer-notification obligation. fixed_cap records the ceiling shared by tiers (b), (c), (ç) and (d). These are the amounts stated in the Act's own text. Kabahatler Kanunu (Misdemeanors Law No. 5326) Art. 17(7) requires fixed-range administrative fines generally to be increased each calendar year by the revaluation rate announced under Tax Procedure Law No. 213's repeated Art. 298, so the amount actually collectible in a given year runs above these statutory base figures; no KVKK announcement stating the currently applicable revalued amounts was reachable through the primary-source channel used for this research, so the statutory base figures are recorded here.
- Rule
- Fixed only
- As of
- 2 September 2026
- Currency
- TRY
- Fixed cap
- 1,000,000
Who enforces it
Enforcement body
Kisisel Verileri Koruma Kurulu (Personal Data Protection Board)
Enforcement record
KVKK 2025 Yılı Faaliyet Raporu (2025 Annual Activity Report), Table 18: in 2025 the Board imposed Art. 18 administrative fines on 876 data controllers in total (140 for complaint/report matters, 142 for data breach notifications, 594 for Data Controllers' Registry and notification-obligation violations), totalling 352,510,494 TL. The prior year's total was 551,139,817 TL (2024), so the latest year-over-year figure fell, though the five-year series (2021: 31,746,000 TL; 2022: 85,483,000 TL; 2023: 240,912,000 TL) still shows a longer-run rise. Counts KVKK Board-imposed administrative fines only; the report does not separately track private civil compensation claims filed under Art. 11(1).
- As of
- 2 September 2026
- Trend
- Falling
- Currency
- TRY
- Source link
- https://www.kvkk.gov.tr/SharedFolderServer/CMSFiles/MTY5ZjMxYTVlZGY0Y2Y.pdf
- Fines per year
- 352,510,494
- Actions per year
- 876
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Personal Data Protection Board (KVKK) enforces the Act with tiered administrative fines under Art. 18: 5,000 to 100,000 TL for notice failures, 15,000 to 1,000,000 TL for security failures, 25,000 to 1,000,000 TL for noncompliance with a Board decision, 20,000 to 1,000,000 TL for registry failures, and, added by Law No. 7499 in 2024, 50,000 to 1,000,000 TL for Art. 9(5) transfer-notification failures; fines are now appealable to administrative courts under Art. 18(3), also added in 2024.
Art. 11(1)(g) lets a data subject claim compensation for the damage arising from the unlawful processing, which requires proof of damage, unlike a no-proof-of-damage statutory-damages tort found elsewhere in this region.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official statute text, KVKK Kurumu consolidated English translation
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.