If it is genuinely anonymous, it falls outside the scope of KVKK/GDPR; however, the re-identification risk must be tested technically. The claim of being “anonymous” is the assumption that fails most often.
One more gate sits before resale even when anonymisation genuinely holds: your customer contracts and platform terms may still bar using or selling the data, whatever its legal status under KVKK/GDPR. Check those restrictions alongside the re-identification test — a dataset can be lawfully anonymous and still contractually off-limits to monetise.
Shall we apply this matter to your situation?
Tell us your specific situation in a few sentences; we'll assess it with the right team.