Skip to main content
HukukBis logo: Hukuk Bilgi İletişim Sistemi (legal information and communication system)

By HukukBis Editorial Team

Updated:

11 min read

Law No. 6698

art.4 · art.10 · art.11 · art.12 · art.16

The firm is the controller of the data.

Turkey's Law No. 6698 (KVKK) makes every lawyer and firm that handles client files a data controller. The provisions that matter to a firm are gathered into ten checklist items.

KVKK retention and archive review in a law firm

Office manager and lawyer checking document retention records on a tablet in front of archive cabinets; editorial photograph for the GDPR/KVKK compliance guide

01/15

Obligations and who owns them

The firm, as data controller, owns every obligation. The software turns the technical-measures part of the list into concrete controls.

Obligations and who owns them
ObligationOwnerHow HukukBis supports it
Access tied to authorityFirmCustom roles and fine-grained permissions, two-step verification and closing a removed member's access.
Separation of firms' dataFirmPer-company data isolation keeps each firm's data separate.
Document securityFirmMandatory malware scanning for every upload and retention periods for documents.
TraceabilityFirmA per-case activity log and audit records are kept.
Data subject requestsFirmData export and deletion-request handling tools, plus automatic backups.

HukukBis is developed and operated by HukukBis, whose information security management system is ISO/IEC 27001 certified and whose processes are TSE certified. Its cloud infrastructure runs entirely on MTY Cloud.

Read our KVKK privacy notice

02/15

How is a data request closed within thirty days?

A fictional client asks for a copy of the data the firm holds about them. The request is followed from arrival to closure; on screen only one thing changes at each step.

  1. 01/05

    Client A asks for a copy of the personal data the firm holds. The date the request reaches the firm starts the thirty-day period.

  2. 02/05

    The request type, the data subject and the date received are recorded; the reply deadline is calculated as 05.11.2026.

  3. 03/05

    The client card, case records, documents and invoice records are gathered in one package. Information about third parties and records with a legal obstacle are left out.

  4. 04/05

    The reply is given in writing or electronically on 12.10.2026, with 24 days of the period left. Had the request been refused, the reasons would have been written in the same reply.

  5. 05/05

    The request moves to Closed; the request, the reply date and the export record are kept together.

A data request arrives from a client

03/15

Who is the data controller, and who is the processor?

If you know the GDPR, the vocabulary will look familiar, though the rules, deadlines and registry differ. Under Article 3 of the KVKK, the data controller is the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system. In a law firm that is the solo lawyer, the partnership or the firm's legal entity. Because you decide why and with which tools a client's data is processed, responsibility sits with you.

A data processor is the person who processes personal data on the controller's behalf, on the authority the controller gives. File-management software, email and cloud providers, and accounting and payment infrastructure are typical examples. The data subject is the individual whose data is processed: clients, opposing parties, witnesses, experts, enquirers, employees and trainees can all be data subjects.

04/15

Inventory: which data, why, and for how long?

The law does not use the word inventory, but privacy notices, retention periods and registry notifications cannot be done without knowing exactly what you process. The content of the registry notification shows it clearly: identity, purpose of processing, data subject groups and data categories, recipient groups for transfers, transfers abroad, security measures and the maximum retention period (Article 16(3)). If you build your inventory under those headings, the same work prepares both your privacy notice and your registry notification.

Start by mapping the firm's data flows: where data comes from, where it sits, who receives it and when it ends. The table below shows typical data groups for a law firm. The basis column is an example; you must assess each processing activity under your own circumstances.

Sample personal data inventory for a law firm
Data groupExample dataData subjectsPurposePossible basis
IdentityName, Turkish ID or tax numberClient, opposing partyPower of attorney and file recordConclusion or performance of a contract (5(2)(c))
ContactPhone, email, addressClient, witnessUpdates and service trackingPerformance of a contract (5(2)(c))
Case and fileDocket number, claim, defence, evidenceParties, witness, expertDelivering legal servicesEstablishment, exercise or protection of a right (5(2)(e))
FinancialInvoice, payment, bank detailsClient, employeeBilling and collectionLegal obligation (5(2)(ç))
Special categoriesCriminal convictions and security measures, health, association or union membershipClient, opposing partyCriminal, employment and family filesConditions in Article 6(3), plus the measures set by the Board
Staff and traineesPersonnel, contact, access logsEmployees, traineesEmployment and securityLegal obligation, legitimate interest

Special categories need extra care. Article 6 treats data on criminal convictions and security measures, health data, and association or union membership as special-category data; it allows their processing only if one of the listed conditions applies and also requires the adequate measures set by the Board. In a law firm these data appear often in criminal cases and in employment and family disputes.

06/15

The duty to inform: whom, when and what must you say?

Article 10 requires the controller, or the person it authorises, to inform data subjects on five matters when data is collected: the identity of the controller and its representative, the purpose of processing, to whom and for what purpose data may be transferred, the method and legal basis of collection, and the other rights listed in Article 11. The notice is independent of consent and wider than it; having obtained consent does not mean you have informed.

Firms have three natural points for the notice: signing the power of attorney and engagement letter, the enquiry form on the website, and the first phone call or exchange of messages. Prepare a separate notice for employees and trainees. For data not collected from the data subject, such as the opposing party's or a witness's details, the Authority's notice communiqué sets out separately how and when to inform; decide in advance which exceptions you will rely on and write them down. Failing to inform is a ground for an administrative fine (Article 18(1)(a)).

07/15

Retention and disposal: how long, and why, do you keep a file?

Personal data is kept for the period set in the relevant legislation or needed for the purpose of processing (Article 4). When that period ends, or when the reasons requiring processing disappear, data is deleted, destroyed or anonymised either on the controller's own initiative or at the data subject's request (Article 7). Failing to delete is serious: those who do not delete or anonymise data in breach of Article 7 are punished under Article 138 of the Turkish Penal Code (Article 17(2)).

For a law firm the real difficulty is the tension between deletion and retention duties. Tax, commercial and professional retention requirements and limitation periods can stand in the way of acting on a deletion request at once, and Article 7(2) preserves special provisions in other laws. The answer is to tie a retention period and its legal basis to each data group in a written policy in advance. The Regulation on Deletion, Destruction or Anonymisation of Personal Data sets out what the policy must contain and the principles for periodic disposal.

08/15

Access and authority: the first layer of data security

Article 12 obliges the controller to take all technical and administrative measures needed for an appropriate level of security, with three aims: preventing unlawful processing, preventing unlawful access and ensuring the safekeeping of data. In a firm the most concrete form of this is who can reach which file and which action. A firm where everyone has full authority cannot show that it met this duty.

Paragraph 4 of the same article states that controllers and processors cannot disclose personal data they learn in breach of the Law or use it beyond the purpose of processing, and that this duty continues after they leave their post. Put confidentiality clauses into employee and trainee contracts, and close a departing employee's access the same day. We cover role and permission design in a separate guide.

09/15

Processors, service providers and transfers abroad

If personal data is processed on your behalf by someone else, Article 12(2) makes you jointly responsible with them for taking the security measures. So sign a written data processing agreement with every software and service provider, covering the subject and scope of processing, security measures, approval of sub-processors, confidentiality, and the return or deletion of data when the contract ends.

Transfers abroad are regulated by Article 9, which Law No. 7499 rewrote in 2024. Under the current regime, a transfer needs one of the conditions in Articles 5 and 6 plus, in order, an adequacy decision; if there is none, appropriate safeguards such as a standard contract, binding corporate rules or an undertaking; and failing that, only the exceptional cases listed, and then only occasionally. A standard contract is notified to the Authority within five business days of signature. Cloud and AI services may involve a transfer abroad depending on server location, so ask providers in writing for their server location and sub-processor list.

10/15

Data breach: whom do you notify, and when?

Article 12(5) says that if processed personal data is obtained by others through unlawful means, the controller notifies the data subject and the Board as soon as possible. The Personal Data Protection Board's decision no. 2019/10 of 24 January 2019 makes the timing concrete: the Board is notified without delay and within 72 hours at the latest of learning of the breach, and the data subject within a reasonable time as soon as possible. The decision also provides for use of the breach notification form.

Without a plan, 72 hours is very short. A lost laptop, an email sent to the wrong person, ransomware and a compromised account can each be a breach. Decide in advance who decides, who notifies and how evidence is preserved. Criminal offences concerning personal data fall under Articles 135 to 140 of the Turkish Penal Code (Article 17), so recording the incident matters for both remediation and defence.

11/15

Data subject requests: the thirty-day clock

Article 11 gives data subjects nine rights: to learn whether data is processed, to request information, to learn the purpose, to know the third parties to whom data is transferred, to request correction, to request deletion or destruction, to request that these actions be notified to third parties, to object to an adverse result based solely on automated analysis, and to claim compensation for damage. Requests reach the controller in writing or by other methods the Board sets.

The controller concludes a request free of charge as soon as possible and within thirty days at the latest, depending on its nature; if the action needs a separate cost, the fee in the Board's tariff may be charged (Article 13). The request is accepted, or refused with reasons, and the reply is given in writing or electronically. If the reply is inadequate, the data subject may complain to the Board within thirty days of learning the reply and in any case within sixty days of the request (Article 14).

In a law firm, requests can collide with retention duties, protection of rights and professional secrecy. If a client's deletion request overlaps with a pending case or a tax retention period, you may refuse with reasons; give the reasons in writing. Disclosing one person's data to another remains restricted by the confidentiality duty even when a request gives it as the reason.

12/15

The Data Controllers' Registry (VERBİS)

Article 16 makes it a general rule that natural and legal persons who process personal data must register in the Data Controllers' Registry before they start processing, but the Board may grant exemptions on objective criteria such as the nature and number of data and whether data is transferred. Those criteria, for example staff-count and financial-size thresholds, are set by Board decisions and updated over time. We therefore do not state numbers in this guide: confirm your firm's current position in the Authority's announcements.

If you are subject to registration, you must notify changes to the information in your notification without delay (Article 16(4)). Even if you are exempt, the duties of inventory, privacy notice and retention policy continue; a registry exemption does not remove the compliance duty.

13/15

Seven common mistakes

  1. 01Having clients sign a consent form without providing a privacy notice.
  2. 02Giving every employee full rights on every file.
  3. 03Sharing files through personal email and messaging apps.
  4. 04Keeping an unlimited archive that never deletes anything.
  5. 05Having no data processing agreement with software and cloud providers.
  6. 06Not deciding in advance who does what after a breach.
  7. 07Leaving a departed employee's access open for weeks.

14/15

Checklist

Tick each item as you finish it. Your ticks are stored only in this browser.

Progress: 0/10
  1. 01/10

    Identify the controller

    • Record in writing the firm's identity as data controller (trade name and address).
    • List every service provider that processes data on the firm's behalf.
    • Appoint a person responsible for KVKK decisions and contact.
  2. 02/10
  3. 03/10

    Separate legal basis from consent

    • Write one primary legal basis for each processing activity.
    • Ask for explicit consent only where no other basis exists, and in a separate text.
    • Mark the case types that involve special-category data.
  4. 04/10

    Publish the privacy notice

    • Link the privacy notice from the engagement letter and the enquiry form.
    • Keep the date and version of the notice and archive old versions.
    • Prepare a separate notice for employees.
  5. 05/10

    Set retention and disposal rules

    • Write the retention period and its basis for every data group in a policy.
    • Set a periodic disposal calendar for closed files.
    • Record deletion and destruction in minutes.
  6. 06/10

    Tie access to authority

    • Define roles on the principle of least privilege.
    • Turn on two-step verification for every user.
    • Close a leaver's access the same day and record it.
  7. 07/10

    Review providers and transfers

    • Keep a signed data processing agreement for every provider.
    • Obtain server location and the sub-processor list from each provider in writing.
    • Document the Article 9 mechanism and any notification if data goes abroad.
  8. 08/10

    Prepare a breach plan

    • Write down who notifies, and in what order, in a written plan.
    • Log every incident in a breach register, even if it is not reported.
    • Check that access and activity logs are kept and can be reviewed.
  9. 09/10

    Handle data subject requests

    • Designate one channel and one responsible person for requests.
    • Track the thirty-day period against the request record.
    • Keep a written template for reasoned refusals.
  10. 10/10

    Confirm your VERBİS position

    • Check the Authority's current exemption criteria and record the result.
    • If you must register, notify changes without delay.
    • Keep your inventory and policies current even when exempt.

15/15

Frequently asked questions on KVKK for law firms

  1. 01

    Must a law firm register with VERBİS?

    Article 16 makes registration the general rule for anyone processing personal data, while the Board may grant exemptions on set criteria. Criteria such as staff count and financial size are set by Board decisions and can change. Check your firm's position in the current announcements of the Personal Data Protection Authority.

  2. 02

    Do I need explicit consent from a client for every action?

    No. Article 5 allows processing without consent in cases such as the conclusion or performance of a contract, a legal obligation, and the establishment, exercise or protection of a right. Ask for explicit consent only for activities those conditions do not cover. Professional secrecy applies independently of the KVKK.

  3. 03

    Whom do I notify of a data breach, and how fast?

    Under Article 12(5), the data subject and the Board. Board decision 2019/10 provides for notifying the Board without delay and within 72 hours at the latest of learning of the breach, and notifying the data subject within a reasonable time as soon as possible.

  4. 04

    What if a client asks me to delete their file?

    Answer in writing or electronically within thirty days at the latest under Article 13. If a retention duty, a limitation period or a pending case stands in the way, you may refuse with reasons. Put the reasons in writing and carry out the deletion once the obstacle lapses.

  5. 05

    Does using cloud software count as a transfer abroad?

    It depends on the location of the servers and sub-processors. If any server or processor is abroad, the Article 9 mechanisms apply. Ask the provider in writing for server location and sub-processors; HukukBis publishes this information on its security page.

Sources

The official texts cited in this guide:

  1. 01Law No. 6698 on the Protection of Personal Data, mevzuat.gov.tr (opens in a new tab)
  2. 02Law No. 1136 on Attorneyship, mevzuat.gov.tr (opens in a new tab)
  3. 03Turkish Bar Association Professional Rules of Attorneyship (opens in a new tab)
  4. 04Personal Data Protection Authority, Board decisions and announcements (opens in a new tab)

Make the technical side of compliance easier with HukukBis

7 days · no card