01/15
Obligations and who owns them
The firm, as data controller, owns every obligation. The software turns the technical-measures part of the list into concrete controls.
| Obligation | Owner | How HukukBis supports it |
|---|---|---|
| Access tied to authority | Firm | Custom roles and fine-grained permissions, two-step verification and closing a removed member's access. |
| Separation of firms' data | Firm | Per-company data isolation keeps each firm's data separate. |
| Document security | Firm | Mandatory malware scanning for every upload and retention periods for documents. |
| Traceability | Firm | A per-case activity log and audit records are kept. |
| Data subject requests | Firm | Data export and deletion-request handling tools, plus automatic backups. |
HukukBis is developed and operated by HukukBis, whose information security management system is ISO/IEC 27001 certified and whose processes are TSE certified. Its cloud infrastructure runs entirely on MTY Cloud.
02/15
How is a data request closed within thirty days?
A fictional client asks for a copy of the data the firm holds about them. The request is followed from arrival to closure; on screen only one thing changes at each step.
- 01/05
Client A asks for a copy of the personal data the firm holds. The date the request reaches the firm starts the thirty-day period.
- 02/05
The request type, the data subject and the date received are recorded; the reply deadline is calculated as 05.11.2026.
- 03/05
The client card, case records, documents and invoice records are gathered in one package. Information about third parties and records with a legal obstacle are left out.
- 04/05
The reply is given in writing or electronically on 12.10.2026, with 24 days of the period left. Had the request been refused, the reasons would have been written in the same reply.
- 05/05
The request moves to Closed; the request, the reply date and the export record are kept together.
A data request arrives from a client
03/15
Who is the data controller, and who is the processor?
If you know the GDPR, the vocabulary will look familiar, though the rules, deadlines and registry differ. Under Article 3 of the KVKK, the data controller is the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system. In a law firm that is the solo lawyer, the partnership or the firm's legal entity. Because you decide why and with which tools a client's data is processed, responsibility sits with you.
A data processor is the person who processes personal data on the controller's behalf, on the authority the controller gives. File-management software, email and cloud providers, and accounting and payment infrastructure are typical examples. The data subject is the individual whose data is processed: clients, opposing parties, witnesses, experts, enquirers, employees and trainees can all be data subjects.
04/15
Inventory: which data, why, and for how long?
The law does not use the word inventory, but privacy notices, retention periods and registry notifications cannot be done without knowing exactly what you process. The content of the registry notification shows it clearly: identity, purpose of processing, data subject groups and data categories, recipient groups for transfers, transfers abroad, security measures and the maximum retention period (Article 16(3)). If you build your inventory under those headings, the same work prepares both your privacy notice and your registry notification.
Start by mapping the firm's data flows: where data comes from, where it sits, who receives it and when it ends. The table below shows typical data groups for a law firm. The basis column is an example; you must assess each processing activity under your own circumstances.
| Data group | Example data | Data subjects | Purpose | Possible basis |
|---|---|---|---|---|
| Identity | Name, Turkish ID or tax number | Client, opposing party | Power of attorney and file record | Conclusion or performance of a contract (5(2)(c)) |
| Contact | Phone, email, address | Client, witness | Updates and service tracking | Performance of a contract (5(2)(c)) |
| Case and file | Docket number, claim, defence, evidence | Parties, witness, expert | Delivering legal services | Establishment, exercise or protection of a right (5(2)(e)) |
| Financial | Invoice, payment, bank details | Client, employee | Billing and collection | Legal obligation (5(2)(ç)) |
| Special categories | Criminal convictions and security measures, health, association or union membership | Client, opposing party | Criminal, employment and family files | Conditions in Article 6(3), plus the measures set by the Board |
| Staff and trainees | Personnel, contact, access logs | Employees, trainees | Employment and security | Legal obligation, legitimate interest |
Special categories need extra care. Article 6 treats data on criminal convictions and security measures, health data, and association or union membership as special-category data; it allows their processing only if one of the listed conditions applies and also requires the adequate measures set by the Board. In a law firm these data appear often in criminal cases and in employment and family disputes.
05/15
When do you need a legal basis and when explicit consent?
Article 4 lists five principles for processing: lawfulness and fairness, accuracy and, where necessary, being up to date, processing for specified, explicit and legitimate purposes, being relevant, limited and proportionate to the purpose, and retention only for the period set by law or needed for the purpose. Every processing activity in the firm must pass these five filters.
Article 5 makes explicit consent the rule and treats the listed conditions as exceptions that allow processing without it. Explicit consent is consent relating to a specific subject, based on information and given freely (Article 3). In a law firm, handling a file usually rests on the power-of-attorney contract, on the establishment, exercise or protection of a right, and on legal obligations. A separate consent form for the engagement itself is therefore mostly unnecessary and invites the argument that consent was not freely given. Keep consent for activities no other basis covers, such as a newsletter.
Professional secrecy is a separate duty. Article 36 of the Attorneyship Law (Law No. 1136) prohibits a lawyer from disclosing what they learn through their work, and the Turkish Bar Association's Professional Rules likewise require professional secrecy to be protected and assistants and trainees to comply with it; check the article number in the current text of the Rules. Finding a KVKK basis for processing never gives you permission to disclose a secret; the two regimes apply together.
06/15
The duty to inform: whom, when and what must you say?
Article 10 requires the controller, or the person it authorises, to inform data subjects on five matters when data is collected: the identity of the controller and its representative, the purpose of processing, to whom and for what purpose data may be transferred, the method and legal basis of collection, and the other rights listed in Article 11. The notice is independent of consent and wider than it; having obtained consent does not mean you have informed.
Firms have three natural points for the notice: signing the power of attorney and engagement letter, the enquiry form on the website, and the first phone call or exchange of messages. Prepare a separate notice for employees and trainees. For data not collected from the data subject, such as the opposing party's or a witness's details, the Authority's notice communiqué sets out separately how and when to inform; decide in advance which exceptions you will rely on and write them down. Failing to inform is a ground for an administrative fine (Article 18(1)(a)).
07/15
Retention and disposal: how long, and why, do you keep a file?
Personal data is kept for the period set in the relevant legislation or needed for the purpose of processing (Article 4). When that period ends, or when the reasons requiring processing disappear, data is deleted, destroyed or anonymised either on the controller's own initiative or at the data subject's request (Article 7). Failing to delete is serious: those who do not delete or anonymise data in breach of Article 7 are punished under Article 138 of the Turkish Penal Code (Article 17(2)).
For a law firm the real difficulty is the tension between deletion and retention duties. Tax, commercial and professional retention requirements and limitation periods can stand in the way of acting on a deletion request at once, and Article 7(2) preserves special provisions in other laws. The answer is to tie a retention period and its legal basis to each data group in a written policy in advance. The Regulation on Deletion, Destruction or Anonymisation of Personal Data sets out what the policy must contain and the principles for periodic disposal.
08/15
Access and authority: the first layer of data security
Article 12 obliges the controller to take all technical and administrative measures needed for an appropriate level of security, with three aims: preventing unlawful processing, preventing unlawful access and ensuring the safekeeping of data. In a firm the most concrete form of this is who can reach which file and which action. A firm where everyone has full authority cannot show that it met this duty.
Paragraph 4 of the same article states that controllers and processors cannot disclose personal data they learn in breach of the Law or use it beyond the purpose of processing, and that this duty continues after they leave their post. Put confidentiality clauses into employee and trainee contracts, and close a departing employee's access the same day. We cover role and permission design in a separate guide.
09/15
Processors, service providers and transfers abroad
If personal data is processed on your behalf by someone else, Article 12(2) makes you jointly responsible with them for taking the security measures. So sign a written data processing agreement with every software and service provider, covering the subject and scope of processing, security measures, approval of sub-processors, confidentiality, and the return or deletion of data when the contract ends.
Transfers abroad are regulated by Article 9, which Law No. 7499 rewrote in 2024. Under the current regime, a transfer needs one of the conditions in Articles 5 and 6 plus, in order, an adequacy decision; if there is none, appropriate safeguards such as a standard contract, binding corporate rules or an undertaking; and failing that, only the exceptional cases listed, and then only occasionally. A standard contract is notified to the Authority within five business days of signature. Cloud and AI services may involve a transfer abroad depending on server location, so ask providers in writing for their server location and sub-processor list.
10/15
Data breach: whom do you notify, and when?
Article 12(5) says that if processed personal data is obtained by others through unlawful means, the controller notifies the data subject and the Board as soon as possible. The Personal Data Protection Board's decision no. 2019/10 of 24 January 2019 makes the timing concrete: the Board is notified without delay and within 72 hours at the latest of learning of the breach, and the data subject within a reasonable time as soon as possible. The decision also provides for use of the breach notification form.
Without a plan, 72 hours is very short. A lost laptop, an email sent to the wrong person, ransomware and a compromised account can each be a breach. Decide in advance who decides, who notifies and how evidence is preserved. Criminal offences concerning personal data fall under Articles 135 to 140 of the Turkish Penal Code (Article 17), so recording the incident matters for both remediation and defence.
11/15
Data subject requests: the thirty-day clock
Article 11 gives data subjects nine rights: to learn whether data is processed, to request information, to learn the purpose, to know the third parties to whom data is transferred, to request correction, to request deletion or destruction, to request that these actions be notified to third parties, to object to an adverse result based solely on automated analysis, and to claim compensation for damage. Requests reach the controller in writing or by other methods the Board sets.
The controller concludes a request free of charge as soon as possible and within thirty days at the latest, depending on its nature; if the action needs a separate cost, the fee in the Board's tariff may be charged (Article 13). The request is accepted, or refused with reasons, and the reply is given in writing or electronically. If the reply is inadequate, the data subject may complain to the Board within thirty days of learning the reply and in any case within sixty days of the request (Article 14).
In a law firm, requests can collide with retention duties, protection of rights and professional secrecy. If a client's deletion request overlaps with a pending case or a tax retention period, you may refuse with reasons; give the reasons in writing. Disclosing one person's data to another remains restricted by the confidentiality duty even when a request gives it as the reason.
12/15
The Data Controllers' Registry (VERBİS)
Article 16 makes it a general rule that natural and legal persons who process personal data must register in the Data Controllers' Registry before they start processing, but the Board may grant exemptions on objective criteria such as the nature and number of data and whether data is transferred. Those criteria, for example staff-count and financial-size thresholds, are set by Board decisions and updated over time. We therefore do not state numbers in this guide: confirm your firm's current position in the Authority's announcements.
If you are subject to registration, you must notify changes to the information in your notification without delay (Article 16(4)). Even if you are exempt, the duties of inventory, privacy notice and retention policy continue; a registry exemption does not remove the compliance duty.
13/15
Seven common mistakes
- 01Having clients sign a consent form without providing a privacy notice.
- 02Giving every employee full rights on every file.
- 03Sharing files through personal email and messaging apps.
- 04Keeping an unlimited archive that never deletes anything.
- 05Having no data processing agreement with software and cloud providers.
- 06Not deciding in advance who does what after a breach.
- 07Leaving a departed employee's access open for weeks.
14/15
Checklist
Tick each item as you finish it. Your ticks are stored only in this browser.
- 01/10
Identify the controller
- Record in writing the firm's identity as data controller (trade name and address).
- List every service provider that processes data on the firm's behalf.
- Appoint a person responsible for KVKK decisions and contact.
- 02/10
- 03/10
Separate legal basis from consent
- Write one primary legal basis for each processing activity.
- Ask for explicit consent only where no other basis exists, and in a separate text.
- Mark the case types that involve special-category data.
- 04/10
Publish the privacy notice
- Link the privacy notice from the engagement letter and the enquiry form.
- Keep the date and version of the notice and archive old versions.
- Prepare a separate notice for employees.
- 05/10
Set retention and disposal rules
- Write the retention period and its basis for every data group in a policy.
- Set a periodic disposal calendar for closed files.
- Record deletion and destruction in minutes.
- 06/10
Tie access to authority
- Define roles on the principle of least privilege.
- Turn on two-step verification for every user.
- Close a leaver's access the same day and record it.
- 07/10
Review providers and transfers
- Keep a signed data processing agreement for every provider.
- Obtain server location and the sub-processor list from each provider in writing.
- Document the Article 9 mechanism and any notification if data goes abroad.
- 08/10
Prepare a breach plan
- Write down who notifies, and in what order, in a written plan.
- Log every incident in a breach register, even if it is not reported.
- Check that access and activity logs are kept and can be reviewed.
- 09/10
Handle data subject requests
- Designate one channel and one responsible person for requests.
- Track the thirty-day period against the request record.
- Keep a written template for reasoned refusals.
- 10/10
Confirm your VERBİS position
- Check the Authority's current exemption criteria and record the result.
- If you must register, notify changes without delay.
- Keep your inventory and policies current even when exempt.
15/15
Frequently asked questions on KVKK for law firms
- 01
Must a law firm register with VERBİS?
Article 16 makes registration the general rule for anyone processing personal data, while the Board may grant exemptions on set criteria. Criteria such as staff count and financial size are set by Board decisions and can change. Check your firm's position in the current announcements of the Personal Data Protection Authority.
- 02
Do I need explicit consent from a client for every action?
No. Article 5 allows processing without consent in cases such as the conclusion or performance of a contract, a legal obligation, and the establishment, exercise or protection of a right. Ask for explicit consent only for activities those conditions do not cover. Professional secrecy applies independently of the KVKK.
- 03
Whom do I notify of a data breach, and how fast?
Under Article 12(5), the data subject and the Board. Board decision 2019/10 provides for notifying the Board without delay and within 72 hours at the latest of learning of the breach, and notifying the data subject within a reasonable time as soon as possible.
- 04
What if a client asks me to delete their file?
Answer in writing or electronically within thirty days at the latest under Article 13. If a retention duty, a limitation period or a pending case stands in the way, you may refuse with reasons. Put the reasons in writing and carry out the deletion once the obstacle lapses.
- 05
Does using cloud software count as a transfer abroad?
It depends on the location of the servers and sub-processors. If any server or processor is abroad, the Article 9 mechanisms apply. Ask the provider in writing for server location and sub-processors; HukukBis publishes this information on its security page.
Sources
The official texts cited in this guide:
- 01Law No. 6698 on the Protection of Personal Data, mevzuat.gov.tr (opens in a new tab)
- 02Law No. 1136 on Attorneyship, mevzuat.gov.tr (opens in a new tab)
- 03Turkish Bar Association Professional Rules of Attorneyship (opens in a new tab)
- 04Personal Data Protection Authority, Board decisions and announcements (opens in a new tab)

