Cross-Border Data Transfer from Turkey: KVKK Article 9, Standard Contracts and 5-Day Notice
Cross-border personal-data transfers from Turkey are governed by the amended Article 9 of Personal Data Protection Law No. 6698. Since 1 June 2024, the legal sequence is: first, an Article 5 or Article 6 processing condition plus a Board adequacy decision; if no adequacy decision exists, an Article 5 or 6 condition plus one of the statutory appropriate safeguards; and only where neither route is available, one of the limited incidental-transfer exceptions in Article 9(6). As of 15 September 2026, the Turkish Personal Data Protection Authority states that the Board has not yet designated any adequate country. In practice, private-sector recurring transfers commonly require an Article 9(4) safeguard such as the Board’s standard contract. A signed standard contract must be notified to the Authority within five business days.

1. Article 9 was fundamentally amended in 2024 and the new regime remains the operative rule in 2026
Law No. 7499 amended Article 9 of Personal Data Protection Law No. 6698. The new Article 9 entered into force on 1 June 2024. A transitional overlap kept the former first-paragraph rule in effect alongside the new framework until 1 September 2024. That transition has ended; a 2026 compliance analysis must use the amended Article 9.
The new structure is tiered. A controller or processor cannot start with whichever transfer mechanism is commercially easiest. It must first determine whether the transfer can proceed under an adequacy decision. If no adequacy decision exists, it moves to the appropriate-safeguard route. Only when those safeguards cannot be provided may an incidental transfer rely on one of the exhaustively listed Article 9(6) exceptions.
Article 9 also makes one point that is sometimes missed in foreign-group compliance: the transfer mechanism does not replace the underlying processing condition. The controller or processor must still have one of the Article 5 conditions for ordinary personal data or one of the Article 6 conditions for special-category personal data.
2. Step 1 is an adequacy decision for the destination country, sector or international organisation
Article 9(1) permits transfer where an Article 5 or Article 6 processing condition exists and the Board has issued an adequacy decision concerning the destination country, one or more sectors within that country, or the relevant international organisation.
The Board issues adequacy decisions and publishes them in the Official Gazette. Article 9(2) requires each adequacy decision to be reassessed at least every four years. The Board may also amend, suspend or revoke a decision prospectively where its evaluation requires that result.
Article 9(3) identifies the principal adequacy factors: reciprocity with Turkey, the destination’s data-protection law and practice, an independent and effective supervisory authority and effective administrative/judicial remedies, relevant international commitments and memberships, and international conventions binding on Turkey.
As of the legal-source review date, 15 September 2026, the Authority’s current cross-border-transfer page states that the Board has not yet designated any countries as providing adequate protection. For an ordinary private-company transfer today, that fact makes the appropriate-safeguard analysis especially important.
3. Step 2: Article 9(4) provides four appropriate-safeguard routes
Where no adequacy decision exists, Article 9(4) allows a cross-border transfer if an Article 5 or Article 6 processing condition exists, data subjects retain enforceable rights and effective legal remedies in the destination, and one of four statutory safeguards is provided.
The four routes are: first, a non-treaty agreement between qualifying Turkish public bodies/professional organisations and foreign public bodies or international organisations, together with Board approval; second, binding corporate rules approved by the Board for companies within a group of undertakings engaged in joint economic activities; third, a standard contract published by the Board; or fourth, a written undertaking containing adequate-protection provisions plus Board approval.
For many private businesses using a foreign SaaS provider, cloud vendor, outsourced processor or overseas group company, the published standard contract is the most directly operational mechanism because it does not require case-by-case Board permission once the correct model is validly executed. It does, however, carry a mandatory notification obligation.
Foreign investors should integrate the transfer analysis into their Turkish entity’s compliance architecture. A foreign-owned Turkish company remains subject to Turkish data-protection rules for processing within the scope of Law No. 6698; foreign ownership does not displace Article 9. For the corporate-law ownership framework, see Can a Foreigner Own 100% of a Turkish Company?.
4. The Board’s standard contract is a statutory safeguard, not an ordinary commercial DPA template
Article 9(4)(c) recognises a standard contract published by the Board as an appropriate safeguard. The contract must contain, among other matters, the data categories, transfer purposes, recipients or recipient groups, technical and organisational measures to be applied by the data importer, and additional measures for special-category data.
On 4 June 2024, the Board adopted four standard-contract models and the related binding-corporate-rules documentation through Decision No. 2024/959. The Authority later published English translations of the By-Law and all four contract models. The Turkish version remains legally decisive where there is a conflict with a translation.
The Authority’s current public guidance is explicit that parties may not freely rewrite the prescribed contract. Apart from clauses that the official text itself identifies as optional or alternative, additions, deletions or amendments should not be made because the Board’s published form is the instrument accepted as providing the statutory safeguard.
A separate master services agreement or data-processing agreement can coexist with the standard contract, but it should not contradict the mandatory transfer terms. The Authority’s controller-to-controller template itself contains a conflict rule giving the standard-contract provisions priority where they conflict with other agreements between the parties.
5. The signed standard contract must be notified to the Authority within five business days
Article 9(5) creates a direct statutory deadline: the standard contract must be notified to the Personal Data Protection Authority by the data controller or data processor within five business days following signature.
The Authority accepts notification physically, through registered electronic mail (KEP), and through the Standard Contract Notification Module established under Board Decision No. 2024/1793. The notification mechanism does not convert the standard contract into a prior-approval regime; the transfer safeguard arises from valid execution of the published standard contract, while the five-day notification is a separate mandatory obligation.
The Authority’s current compliance announcement identifies recurring filing errors. Both transfer parties must sign; the signatures must comply with Turkish Code of Obligations signature rules; the signature dates must be stated so that the five-business-day period can be verified; and the persons signing for the parties must have documented representation/signature authority.
If the standard contract is also executed in a foreign language, the Authority requires both exporter and importer signatures on the Turkish contract text. In a bilingual two-column contract, the Authority specifically requires both parties’ signatures in the column containing the Turkish text.
6. Choosing the correct one of the four standard contracts depends on each party’s role
The Board has published four forms: Standard Contract 1 for controller-to-controller transfers; Standard Contract 2 for controller-to-processor transfers; Standard Contract 3 for processor-to-processor transfers; and Standard Contract 4 for processor-to-controller transfers.
The correct form is determined by the parties’ real roles in the specific processing operation, not by what the commercial agreement calls them. A cloud provider that processes only on documented instructions is generally analysed differently from an overseas group company that determines its own purposes and means for the imported data.
The exporter should map each transfer before signing: whose data are transferred, what categories are involved, what the purpose is, what Article 5 or Article 6 processing condition applies, what each party’s controller/processor role is, which recipients exist, and whether onward transfer is contemplated.
A single vendor relationship can contain more than one processing operation. Where roles differ by dataset or service, counsel should confirm whether one standard-contract configuration accurately covers the transfer or whether separate transfer arrangements are necessary.
7. Binding corporate rules and written commitments remain alternatives to the standard contract
Article 9(4)(b) recognises binding corporate rules approved by the Board for companies within a group of undertakings engaged in joint economic activity. The Authority has published separate application forms and minimum-content guidance for controller BCRs and processor BCRs.
BCRs are designed for structured intra-group transfer systems rather than a one-off vendor relationship. They require Board approval and must establish enforceable data-protection obligations across the participating group.
Article 9(4)(ç) separately permits a written commitment containing adequate-protection provisions, but the transfer can proceed under that route only with Board approval. The Authority explains that this mechanism is available where sectoral or regional circumstances make the standard-contract route unsuitable.
The correct safeguard should be selected before live transfer begins. A business should not retrospectively sign a document after months of continuous transfers and describe those earlier transfers as automatically cured.
8. Article 9(6) exceptions are limited to incidental transfers—not a basis for routine cloud or group transfers
Where there is no adequacy decision and an Article 9(4) safeguard cannot be ensured, Article 9(6) allows transfer only in an incidental situation and only where one of the listed circumstances exists.
Those circumstances include informed explicit consent covering the potential transfer risks; necessity for performance of a contract with the data subject or pre-contractual measures requested by that person; necessity for a contract between the controller and another person for the data subject’s benefit; overriding public interest; necessity for establishment, exercise or protection of a right; protection of life or physical integrity where valid consent cannot be given; and a qualifying transfer from a public register accessible under the conditions set by law.
The word “incidental” is decisive. A daily payroll feed to a foreign HR platform, continuous cloud hosting, recurring CRM synchronisation, permanent overseas technical support access or regular parent-company reporting is not properly analysed as an exceptional one-off event simply because an Article 9(6) circumstance can be worded broadly.
Routine transfers should be structured under adequacy or an appropriate safeguard. In 2026, with no adequate countries yet designated by the Board, that frequently means a valid Article 9(4) mechanism.
9. Foreign cloud, SaaS and group-company access can constitute a transfer abroad
A transfer analysis should not be limited to the physical act of emailing a spreadsheet outside Turkey. If personal data are stored on infrastructure abroad, made accessible to a foreign service provider, remotely accessed by an overseas support team or synchronised with a foreign parent/group system, Article 9 can be engaged depending on the processing structure.
Before procuring a foreign cloud or SaaS service, the Turkish controller should identify hosting location, support-access countries, subprocessors, backup locations, disaster-recovery sites and onward transfers. The legal transfer map should correspond to the actual technical architecture.
The vendor contract should identify the parties’ roles, processing instructions, confidentiality, security, breach cooperation, deletion/return obligations, subprocessors and transfer mechanism. The Article 9 standard contract does not eliminate Article 12 data-security obligations.
International groups operating through a Turkish branch should also remember that the branch structure does not remove Turkish compliance. See Foreign Company Branch in Turkey: TCC Article 40 for the corporate structure; data-transfer compliance remains a separate legal layer.
10. Article 9(8) extends the safeguards to onward transfers
Article 9(8) expressly requires controllers and processors to ensure that the safeguards established under the Law and the Article 9 provisions also apply to onward transfers of personal data already transferred abroad and to transfers to international organisations.
This means the importer cannot receive data under a compliant standard contract and then freely send the same data to an unrelated country or subprocessor without examining the onward-transfer conditions. The Board’s standard contracts contain specific provisions addressing subsequent transfers.
Vendor due diligence should therefore ask not only “where do you host?” but also “who can subsequently receive or access the data, in which country, for what purpose, and under what transfer mechanism?” A subprocessor list without country and function information may be inadequate for the legal mapping exercise.
11. Transfer legality and Article 12 data security must be satisfied together
Article 12 requires the data controller to take all necessary technical and organisational measures to prevent unlawful processing, prevent unlawful access and ensure preservation of personal data. Where a processor handles data on the controller’s behalf, the controller is jointly responsible with the processor for the measures in Article 12(1).
The transfer mechanism therefore does not replace encryption, access control, logging, least-privilege design, retention controls, incident response or contractual processor governance. The standard contract itself requires specification of technical and organisational measures and additional measures for special-category data.
The controller should also update its privacy notice and records so that cross-border recipients and transfer purposes are accurately reflected where the law requires disclosure. Article 10 requires information about to whom and for what purpose processed personal data may be transferred.
For privacy disputes involving online publications and foreign elements, see Online Defamation and Privacy Claims in Turkey. That conflicts-of-law issue is separate from the Article 9 transfer-compliance regime addressed here.
12. Failure to notify a standard contract has an express Article 18 administrative-fine consequence
Law No. 7499 added Article 18(1)(d). It provides an administrative fine for failure to fulfil the notification obligation in Article 9(5). The statutory fine band written into the Law is TRY 50,000 to TRY 1,000,000; administrative monetary amounts can be affected by legally applicable annual revaluation rules, so the amount imposed in a specific year must be checked against the current enforcement tariff rather than copied mechanically from the base statute.
Article 18(2) states that the Article 9(5) notification fine can be imposed on the data controller or on natural/legal persons governed by private law that process data. The 2024 amendment also moved appeals against Board administrative fines to the administrative courts.
Separate violations can create separate exposure. An invalid transfer mechanism, failure to satisfy Article 12 security duties, inaccurate Registry information, failure to inform data subjects or non-compliance with a Board decision should be analysed under their own statutory provisions.
Conclusion
Cross-border data transfer from Turkey in 2026 requires a current Article 9 analysis. As of 15 September 2026, the Authority states that no adequate country has yet been designated. For recurring private-sector transfers, the practical focus is therefore on Article 9(4) safeguards—especially the correct Board-published standard contract—rather than trying to force routine processing into the incidental Article 9(6) exceptions.
The compliance sequence is concrete: map the transfer and roles, identify the Article 5/6 processing condition, select the Article 9 safeguard, execute the prescribed Turkish contract correctly, document signatory authority, notify the Authority within five business days, and ensure the same protection for onward transfers and Article 12 security.
Frequently asked questions
Has Turkey designated any adequate countries for KVKK Article 9 as of September 2026?
No. The Authority’s current cross-border-transfer page states that the Board has not yet made such a designation.
Does explicit consent always solve a recurring overseas transfer?
No. Under Article 9(6), informed explicit consent is one of the listed routes only where no adequacy decision or appropriate safeguard can be ensured and the transfer is incidental. It is not the default mechanism for routine continuous transfers.
What are the four standard-contract types?
Controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller.
Does the Board have to approve each standard contract?
No prior individual approval is required for the Board-published standard-contract route, but the signed contract must be notified to the Authority within five business days.
When does the five-business-day period start?
Article 9(5) links the period to signature. The Authority requires signature dates to be stated so timeliness can be verified.
Can the parties rewrite the standard contract?
Only clauses identified by the official form as optional or alternative may be selected/adjusted as permitted. The Authority states that other additions, deletions or modifications should not be made.
Can the contract be signed only in English?
No for the Authority’s standard-contract filing. Current Authority guidance requires both parties’ signatures on the Turkish contract text even where a foreign-language version is also executed.
Does foreign cloud hosting count as an overseas transfer?
It can. Storage abroad or access by a foreign recipient/processor should be mapped and analysed under Article 9 based on the actual technical and processing structure.
Do onward transfers require protection?
Yes. Article 9(8) expressly requires Article 9 safeguards to be maintained for onward transfers.
Is there a specific fine for missing the standard-contract notification?
Yes. Article 18(1)(d) creates an administrative fine for failure to fulfil the Article 9(5) notification obligation.
Official legal sources
Turkish Personal Data Protection Authority — Law No. 6698, current English text
KVKK — Current Cross-Border Transfer Framework
KVKK — Standard Contracts and Binding Corporate Rules
KVKK — Matters to Observe in Standard Contracts
KVKK — Standard Contract Notification Module
Legal-source review date: 15 September 2026.
Mersin office and Türkiye-wide coordination
Bakırcı & Keskin Hukuk Bürosu has one physical office in Mersin. Data-protection and foreign-company matters throughout Türkiye are coordinated from Mersin subject to the competent authority and court rules.
Contact regarding a legal matter
In your first message, you may briefly state the subject, your country or city, and any relevant notification or recent procedural date. Please do not send identity numbers, medical data, or personal documents. Messaging alone does not constitute legal advice or create a lawyer–client relationship.
