Worldwide Legal Services
Skip to content

Technology Law, Data Privacy (KVKK) and Cryptocurrency Regulation

Technology Law, Data Privacy (KVKK) and Cryptocurrency Regulation. Serka Law Firm advises international technology companies, platform operators, game publishers and distributors, SaaS providers, fintechs, machine learning teams, and cryptocurrency platforms on Turkish data protection, e-commerce, internet, and capital markets law. We build the compliance structures that let a foreign platform serve Turkish users lawfully, and we defend that platform when a regulator moves against it.

Dated, compulsory, and 1 November 2026. Law No. 7578, published in the Resmi Gazete of 1 May 2026, issue 33240, inserts Additional Article 5 into Internet Law No. 5651 and rewrites Additional Article 4. From 1 November 2026 a foreign-sourced game platform whose daily access from Turkey exceeds one hundred thousand must appoint a representative in Turkey and notify the Authority, with an administrative fine reaching thirty million Turkish lira for a second violation. The duty did not exist before 1 May 2026. The test, the thresholds and what has to be built are set out immediately below.

The 1 November 2026 representative duty for foreign game platforms

From 1 November 2026 a foreign-sourced game platform whose daily access from Turkey exceeds one hundred thousand must designate a representative in Turkey, a real person or a legal person, and notify the Authority of that designation. The platform must also publish the representative’s identity and contact details on its own website, in a form that is easily visible and directly accessible. Content-rating compliance and parental-control functionality attach in the same article. The instrument is Additional Article 5 of Internet Law No. 5651, inserted by article 23 of Law No. 7578, published in the Resmi Gazete of 1 May 2026, issue 33240. Article 27 of that law sets commencement at six months after publication, which is 1 November 2026. The administrative penalty reaches thirty million Turkish lira for a second violation.

Two consequences are worth stating plainly for an in-house legal function. First, the obligation is new, so there is no incumbent adviser running it and no internal precedent to copy. Second, the rating and parental-control architecture is a build rather than a filing: the six months between publication and commencement was the build window, and most of it has already gone.

What the article requires, item by item

  • Designate a representative in Turkey. The article permits a real person or a legal person.
  • Notify the Authority of that designation.
  • Publish the representative’s identity and contact details on the platform’s own website, easily visible and directly accessible.
  • Comply with the content-rating regime and provide parental controls, both of which sit in the same article.

The article designates the notified body as the Authority without naming it further in the published text. We write the Authority for that reason and do not guess at it. Which body it denotes, and the procedure that body will publish, is settled by the implementing secondary legislation or by that body’s own announcement, and we watch the Resmi Gazete for both.

Does the duty reach your platform?

Four conditions decide it. Three are publicly checkable and one is your own figure, which is why the test is set out here for you to apply rather than asserted about anyone from outside. The article itself, its commencement date and its fine ladder are set out in full on the representative requirement for game platforms.

ConditionHow it is decided
The service is a game platformIt falls inside one of the definitions of game, game platform, game developer or game distributor added to article 2 of Law No. 5651 by article 21 of Law No. 7578.
It is foreign-sourcedYurt dışı kaynaklı. A company incorporated in Turkey sits outside the representative rule of this article.
Daily access from Turkey exceeds one hundred thousandYour own access figure, not a public one. The threshold is low enough that a Turkish-language client, Turkish Lira pricing, a Turkish storefront or a Turkish creator program usually means the platform is inside the class and should measure.
No representative has been notifiedOr there is a Turkish entity that handles sales and marketing without a compliance mandate attached to it.

If all four hold, the appointment and the notification are due before 1 November 2026, and the rating and parental-control architecture has to be in place alongside them. After that date the same company is in enforcement rather than in preparation, which is a materially worse position from which to start.

The social network provider regime above ten million daily accesses

Article 22 of Law No. 7578 rewrites Additional Article 4 of Internet Law No. 5651, the provision governing social network providers, and adds a heavier layer for providers whose daily access from Turkey exceeds ten million. It commences on the same date, 1 November 2026. A representative appointed years ago as a formal notification is not the same thing as a legal function capable of running the new layer, so a provider that already holds a notified representative should read the rewritten article against what that appointment actually covers, and against who inside the organization is answerable for it.

Who you are instructing

Serka Law Firm, founded by Av. Serkan Kara, in the legal profession since 2015. Holder of the CCBE Lawyer’s Professional Identity Card. He took a Bachelor of Law (LLB) at Uludağ University Faculty of Law in 2015 and read United States law on the CUSL program at the University of Cologne Faculty of Law, with graded results at vollbefriedigend. The consequence is the one a technology general counsel cares about: this office commands both great legal traditions, the Continental and the Anglo-American, rather than one of them consulting the other across a border. Cross-border work is the ordinary case here and is run as such.

He is also a developer. Software and hardware, hands-on since the MS-DOS era, from the age of eleven, and Premium tier in the Google Developer Program. Machine learning is among this firm’s stated specialisms. What that buys you is narrow and it is the reason this page reads the way it does: your architecture, your data flows, your license file, your model documentation and your terms of service are read by the lawyer instead of being described to him, and your engineers are not asked to translate their own system before it can be advised on.

It also means this firm uses the newest and best technology to its fullest, on its own technological experience and expertise rather than on a supplier’s. That is one of the serious advantages that set it apart anywhere in the world, and the standing above is what it rests on.

What is technology and data privacy law for companies operating in Turkey?

Technology and data privacy law in Turkey governs how a company collects, stores, transfers, and monetizes personal data and digital services. The core statute is the Personal Data Protection Law No. 6698 (KVKK), which mirrors the EU GDPR but imposes stricter conditions on transferring data outside Turkey. A technology company serving Turkish users is bound by these rules regardless of where its servers sit. Alongside KVKK, the Law on the Regulation of Electronic Commerce No. 6563, the Internet Law No. 5651, and the Capital Markets Law No. 6362 (for crypto assets) together form the regulatory perimeter that any foreign platform must respect.

What should a technology or data project review first?

A technology project should begin with a data-flow map: who the data subjects are, what personal data is processed, for what purpose, where it is stored, and which third parties or vendors touch it. From that map, counsel can identify the legal obligations that attach to each flow, including consent or other lawful basis, cross-border transfer controls, security duties, consumer-facing contract terms, and any sector licensing. Resolving these questions during product design, rather than after a regulator inquiry, is what keeps a single commercial decision from becoming a compliance failure later.

What is KVKK and how does it differ from GDPR?

KVKK (Personal Data Protection Law No. 6698) is Turkey’s general data protection statute, structurally close to the GDPR in its principles, data subject rights, and accountability duties. The decisive difference is cross-border data transfer. Where the GDPR permits transfers under adequacy decisions and standardized safeguards, KVKK historically required either the explicit consent of the data subject or that the destination country appear on the Personal Data Protection Board’s list of countries with adequate protection. Because that adequacy list has remained limited in practice, most international companies rely on Board-approved written undertakings or standard contractual safeguards rather than treating a destination as automatically safe.

VERBIS registration and the data controller representative

Companies that meet defined thresholds, or whose core activity is processing sensitive personal data, must register with VERBIS, the public Data Controllers’ Registry maintained by the Personal Data Protection Authority. Registration documents the controller’s data inventory, processing purposes, retention periods, and security measures. A foreign data controller without a Turkish establishment must appoint a Data Controller Representative in Turkey, a role our firm performs for international clients. Failure to register, or registering inaccurate information, exposes the controller to administrative fines.

The Authority states this duty on its own published guidance for the Registry: a data controller that is a legal person resident abroad must appoint a data controller representative in Turkey. That is a test on the status of the controller rather than on the size of any Turkish presence, which is why it reaches a far wider set of foreign technology companies than either platform regime described above. Whether a particular controller also falls inside the registration thresholds is assessed on that controller’s own figures, and it is worth assessing before an inspection rather than after one.

Cross-border data transfer

Under KVKK, personal data of users in Turkey cannot be transferred to servers abroad on convenience alone. Explicit consent is one route, but it is fragile because a user can withdraw it at any time. The more durable route is a written undertaking or standard contractual mechanism approved by the Personal Data Protection Board, supported by genuine technical and organizational security equivalence. We prepare and submit these instruments so that a global company can keep data on its existing cloud infrastructure while remaining lawful under Turkish law.

How does Turkey regulate cryptocurrency and crypto-asset platforms?

Cryptocurrency and crypto-asset service providers in Turkey are regulated under the Capital Markets Law No. 6362, as amended to bring crypto assets within the supervision of the Capital Markets Board (SPK). Crypto asset service providers, including exchanges and custody platforms, must hold an operating authorization from the SPK and comply with capital, governance, custody, and anti-money-laundering obligations. Operating an exchange that targets users in Turkey without that authorization is treated as an unauthorized capital markets activity and can lead to criminal liability for the responsible executives and to access-blocking of the platform.

A personal account blocked after P2P crypto trading is a different question, one of criminal procedure rather than licensing: a bank account blocked in Turkey after P2P is held by one of three measures, each with its own clock and its own way out.

Licensing a crypto exchange

A foreign exchange that solicits Turkish users, advertises in Turkish, or offers Turkish Lira trading pairs generally needs to establish a Turkish joint stock company and obtain SPK authorization. Licensing involves meeting minimum capital requirements, implementing anti-money-laundering and customer identification controls aligned with MASAK (the Financial Crimes Investigation Board), and putting compliant custody arrangements in place. We manage the authorization application end to end and structure the corporate vehicle that holds the license.

Token issuance and Web3 structuring

Token issuance carries securities risk. A token that behaves like a profit-sharing or dividend instrument can be treated as a security, which triggers prospectus and disclosure obligations. We provide legal opinions distinguishing utility tokens from security tokens, structure the issuing entity, and geo-fence retail offerings so founders are not exposed to unauthorized public offering claims in Turkey.

What e-commerce rules apply to foreign online platforms?

Foreign online platforms selling to consumers in Turkey must comply with the Law on the Regulation of Electronic Commerce No. 6563 and the Distance Selling Contracts regulation. Two obligations matter most. First, any business-to-consumer sale must give the consumer a fourteen-day right of withdrawal without penalty, together with a detailed preliminary information form before purchase. Second, commercial electronic messages such as marketing SMS, email, or automated calls require prior approval recorded in the central Message Management System (IYS); a consumer’s opt-out must be honored automatically. Sending unsolicited marketing without IYS approval, or denying a lawful refund, draws administrative fines and consumer complaints that can disrupt local payment processing.

Can Turkish authorities block or throttle a foreign platform?

Yes. Under the Internet Law No. 5651, a foreign social network provider with a large daily Turkish user base must appoint a local representative to receive and respond to legal notices, and from 1 November 2026 the same architecture reaches game platforms above one hundred thousand daily accesses under Additional Article 5. When a court orders content removal on personal-rights or other statutory grounds, the provider must act within the statutory window. Refusal can lead the Information and Communication Technologies Authority (BTK) to impose advertising bans, fines, and progressive bandwidth throttling that degrades the service. We act as the appointed representative, evaluate the validity of each order, file objections where an order is defective, and execute narrowly targeted compliance so that a single dispute does not jeopardize the platform’s overall availability.

What are the main legal risks for technology companies, and the exceptions?

The recurring risks are unlawful cross-border data transfer, missing VERBIS registration, operating a crypto service without SPK authorization, unsolicited marketing without IYS approval, and ignoring content-removal or representative obligations under the Internet Law. Each carries administrative fines, and several carry criminal exposure or access-blocking. The principal exceptions and defenses include lawful bases other than consent under KVKK, genuine anonymization that removes data from the scope of personal data, Board-approved transfer instruments, and structuring crypto or token activity so that it does not target Turkish retail users. Whether an exception applies is fact-specific and should be assessed before, not after, a regulator acts.

Do I need a lawyer for technology and data privacy matters?

A lawyer is necessary whenever a technology product touches Turkish users at scale, processes sensitive or biometric data, transfers data abroad, offers crypto or token services, falls inside a representative obligation, or has received a regulator notice. These matters combine data protection, capital markets, consumer, and internet law, and a misstep in one area can freeze payment gateways or block the entire service. Engaging counsel during product design is far less costly than defending an enforcement action after launch.

Frequently asked questions

We are a game platform with Turkish users. What exactly is due on 1 November 2026?

If your platform is foreign-sourced and daily access from Turkey exceeds one hundred thousand, Additional Article 5 of Law No. 5651 requires a representative designated in Turkey, that designation notified to the Authority, and the representative’s identity and contact details published on your own website in an easily visible and directly accessible form. Content rating and parental controls attach in the same article. The administrative fine reaches thirty million Turkish lira for a second violation.

Our Turkish subsidiary already exists. Does that satisfy the representative duty?

Not by itself. The article requires a representative that is designated and notified, and the identity of that representative published on the platform’s site. A sales or marketing entity that carries no compliance mandate is not a designation, and it does not put anyone in a position to receive and answer what the appointment is there to receive and answer. The right question is which natural or legal person is being named, what the mandate says, and whether the notification has been made.

Does KVKK apply to a company with no office in Turkey?

Yes. KVKK applies based on the processing of personal data of individuals in Turkey, not on where the company is incorporated or where its servers are located. A foreign data controller that processes the data of Turkish users is generally required to register with VERBIS and to appoint a Data Controller Representative in Turkey.

Can we keep customer data on foreign cloud infrastructure outside Turkey?

Often yes, but not automatically. Storing Turkish users’ personal data on foreign cloud infrastructure is a cross-border transfer under KVKK. It must be supported either by valid explicit consent or, more durably, by a Board-approved written undertaking or standard contractual mechanism plus adequate security measures. We prepare and submit the instruments that authorize the transfer.

Is it legal to run a crypto exchange for Turkish users from abroad?

Targeting Turkish users from an unlicensed offshore exchange is treated as an unauthorized capital markets activity under Law No. 6362 and can lead to criminal liability and access-blocking. A platform that wants Turkish users typically must establish a Turkish company and obtain SPK authorization, including MASAK-compliant anti-money-laundering controls.

What happens if we send marketing messages without IYS approval?

Each unapproved commercial electronic message can trigger an administrative fine, and repeated violations attract regulatory and consumer complaints. Marketing SMS, email, and automated calls to Turkish consumers must be registered in the IYS system, and opt-outs must be applied automatically.

A Turkish court ordered us to remove content. What is the deadline?

Under the Internet Law No. 5651, providers must act on a valid content-removal order within the statutory window applicable to the order type. Missing the deadline can lead the BTK to impose advertising bans, fines, and bandwidth throttling. We assess the order’s validity, comply where required, and challenge defective orders.

How quickly should we involve counsel after a regulator inquiry?

Immediately. Early counsel can pause a non-compliant data pipeline, preserve defenses such as anonymization or alternative lawful basis, and open a structured dialog with the regulator before fines and destruction orders are finalized. Delay narrows the available defenses.

What can be checked, and where

Every claim on this page that a reader is entitled to verify is named together with the place to verify it, so that the only remaining act is to type a number.

ClaimWhere you check it
The founding advocate’s bar roll entryAv. Serkan Kara’s page, which links his entry in the Istanbul Bar’s own register
Law No. 7578 and the 1 November 2026 commencementResmi Gazete of 1 May 2026, issue 33240. Articles 21, 22, 23 and 27.
Internet Law No. 5651, consolidated textmevzuat.gov.tr
Personal Data Protection Law No. 6698, consolidated textmevzuat.gov.tr
The data controller representative dutyThe Authority’s own guidance on the Data Controllers’ Registry
Google Developer Program, Premium tierg.dev/serka
CCBE Lawyer’s Professional Identity CardVerified through the issuing bar. There is no public register to link to.
Bachelor of Law (LLB), Uludağ University Faculty of Law, 2015The diploma is produced on request.
United States law, CUSL program, University of CologneThe transcript is sealed and apostilled and is produced on request.

Related legal services

Technology matters frequently connect to other practice areas. Technology and data work is coordinated with establishing companies in Turkey for the corporate vehicle that holds an SPK license or a representative mandate, with corporate and commercial law for SaaS and platform agreements, with foreign direct investment structuring for inbound technology capital, with tax law and customs regulations for digital service taxation, and with criminal defense and jurisdiction where capital markets or cybercrime liability arises.

Tell us about the product and the data flows

If your platform falls inside the 1 November 2026 representative duty, processes Turkish user data, offers crypto or token services to Turkish users, or has received a regulator notice, write to us with the product, the data flows, the access position for Turkish users and any pending order; the obligations that apply follow from those four facts.

Direct: WhatsApp +90 530 127 59 35 or info@serkalaw.com.

Legal disclaimer

This page provides general information about Turkish technology, data protection, and capital markets law and does not constitute legal advice. Reading it does not create an attorney-client relationship. An attorney-client relationship is formed only by a signed engagement. For advice on a specific situation, consult a qualified attorney.