Focus Area

Legal architecture that protects and leverages data.

From dual KVKK and GDPR compliance to the Data Act: data inventory, cross-border transfer, data contracts, and breach response — legal architecture that both protects data and creates value from it.

Overview

An integrated legal framework for Data

Data is no longer confined to the heading of “personal data protection” alone. A company's customer relationships, employee management, product data, supplier relationships, and use of artificial intelligence depend on data governance; new rules such as the EU Data Act also subject non-personal data to sharing and access obligations.

We treat data both as a risk to be protected and as an asset to be commercialised: we bring KVKK/GDPR compliance, transfer architecture, data-sharing and licensing agreements, the retention-and-destruction regime, and breach response together into a single workable system.

Data strategy / operations
Why Köksal?

A team that reads KVKK, GDPR, and the data economy in a single framework

Data compliance is achieved through working processes, not documents sitting in a folder. We address KVKK and GDPR within a single framework and build data-economy rules such as the Data Act into your contract set; in particular, we set up Germany-related data flows to be compliant with both bodies of legislation and ready for audit.

  • Dual competence in KVKK and GDPR, a single compliance regime
  • Field practice in Türkiye–DACH data transfers
  • Transactional experience in data-sharing, licensing and DPA agreements
  • Early compliance planning for the Data Act and data-economy rules
  • Rapid response at the moment of a breach and Board experience
Data multi-disciplinary team
09

Related Legislation

Data — the legislation that directly affects this focus area, tracked in plain language on our Legislation Radar.

ABAvrupa B.EU Directive & RegulationRecently amendedEU Artificial Intelligence Act (AI Act)Source · ABl. L, 12.7.2024In force · 01.08.2024 (phased)Last amended · Jul 2026 (Digital Omnibus — high-risk timeline deferred; OJ publication pending)

The world’s first comprehensive artificial intelligence regulation: risk-based classification, provider/deployer obligations, and a phased implementation timeline. It may also cover Turkish companies whose output is used in the EU.

RelatedPersonal Data ProtectionIntellectual Property LawLaw of Obligations & Contracts
ABAvrupa B.EU Directive & RegulationIn forceEU General Data Protection Regulation (GDPR)Source · ABl. L 119, 4.5.2016In force · 25.05.2018Last amended · Nov 2025 (Digital Omnibus proposal — Regulation text unchanged)

The framework of the EU data protection regime: it also directly covers Turkish companies that offer goods and services to persons in the EU or monitor their behaviour.

RelatedPersonal Data ProtectionCommercial LawLaw of Obligations & Contracts
TRTürkiyeLawIn forcePersonal Data Protection Law (KVKK, 6698)Source · RG 29677, 07.04.2016In force · 07.04.2016Last amended · Mar 2024 (Law No. 7499) · Jan 2025 (cross-border transfer guide)

Türkiye’s data protection framework: the 2024 amendments re-established the regime for special-category data and cross-border transfers; the standard contract and notification to the Board are at the centre of practice.

RelatedPersonal Data ProtectionEmployment LawCommercial Law
ABAvrupa B.EU Directive & RegulationRecently amendedEU Data ActSource · ABl. L, 22.12.2023In force · 12.09.2025 (application)Last amended · Sep 2025 (application) · next 12.09.2026 (design obligation); Digital Omnibus proposal under negotiation

Rules on access to, sharing of, and cloud switching for connected-product and related-service data: the regulation that re-establishes the contractual order of the data economy has been in application since September 2025.

RelatedPersonal Data ProtectionLaw of Obligations & ContractsCommercial Law
Open the Legislation Radar

Genuinely anonymised data is outside the scope; however, if re-identification is possible, the data is not considered “anonymous.” We verify the adequacy of the anonymisation technique through legal and technical tests and make your data sets safely usable.

The inventory is an internal record of all processing activities and is mandatory for everyone; VERBİS, on the other hand, is the public registry notification of data controllers that meet the criteria. We build the inventory in line with operations and derive VERBİS from it.

Yes, but under the post-2024 regime an appropriate transfer mechanism (most often the Board's standard contract) must be put in place and notification made within the time limit; the privacy notices must also cover the transfer. We build the intra-group flow with a single set of contracts.

The GDPR also covers you if you offer goods/services to individuals in the EU or monitor their behaviour, and it brings additional obligations that differ from the KVKK (a representative, DPIA, a different notification regime). We run your existing compliance through the GDPR threshold and close the gaps.

Both the KVKK and the GDPR require the breach to be notified to the authority within a short time; delay is in itself grounds for sanctions. With a response plan prepared in advance, the detection, containment, notification, and communication steps proceed without panic.

Cookies that run without consent and designs that pressure users to “accept all” are risky under both the KVKK and the GDPR. We turn your cookie layer into one that offers genuine choice and keeps records.

Under the current KVKK regime, the most practical route is usually the standard contract announced by the Board; after signing there are registration obligations, including notification to the Board, and safeguards are also required on the GDPR side. We set up your intra-group transfer structure with a single set of contracts compliant with both regimes.

If you offer connected (IoT) products or related digital services, or use cloud/data services in the EU, you are likely to be affected: provisions on user access to data, sharing with third parties and switching providers must be written into your contracts. We start with a scope analysis and prioritise the necessary revisions.

Focus Area

Let's build a legal strategy in the Data focus area.

Let's assess your needs together with the relevant Practice Areas, Sectors, and Regional Desks.