Knowledge base
KVKK glossary
Plain definitions of the terms that come up most in compliance conversations. The definitions are general; in a specific case the text of the legislation itself governs.
24 terms in total
- Anonymisation
- Rendering personal data incapable of being associated with an identified or identifiable natural person, even when matched with other data. Anonymous data falls outside the Law.
- Data breach
- Unlawful access to, disclosure of, alteration of, or loss of personal data. It can trigger an obligation to notify the Board and the affected data subjects.
- Data controller
- The party that determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
- Data inventory
- A record showing which personal data is processed in which system, for what purpose, and where it is transferred. This is the foundation of compliance work.
- Data processor
- The party that processes personal data on behalf of the controller, based on the authority the controller grants. Cloud providers, call centres and accounting firms are typical examples.
- Data Protection Officer (DPO)
- Data Protection Officer. The role that monitors data protection compliance within an organisation, advises on it, and acts as the point of contact. Mandatory in certain cases under the GDPR.
- Data subject
- The natural person whose personal data is processed. The rights listed in article 11 of the Law belong to this person.
- Data transfer
- Transmission of personal data to another natural or legal person. Domestic and cross-border transfers are subject to the conditions in articles 8 and 9 of the Law.
- Disposal
- Deletion, destruction or anonymisation of personal data. Required once the retention period expires or the reason for processing disappears.
- DPIA (impact assessment)
- Data protection impact assessment. A systematic evaluation, before a high-risk processing activity begins, of its risks and the measures to be taken.
- Duty to inform
- The controller's obligation, when obtaining personal data, to inform the data subject of its identity, the purpose of processing, the recipients of transfers, the method of collection and their rights (KVKK art. 10).
- Explicit consent
- Consent given on a specific matter, informed, and expressed with free will. Where a service is made conditional on consent, that consent is not considered freely given.
- GDPR
- The European Union General Data Protection Regulation (2016/679). It can apply from Türkiye to organisations offering goods or services to people in the EU or monitoring their behaviour.
- Information security management system
- Information Security Management System. The management framework that is the subject of ISO/IEC 27001, identifying risks and managing them through controls.
- Legal ground
- The legal ground a processing activity rests on. These are listed in KVKK arts. 5 and 6; explicit consent is only one of them and should generally be treated as a last resort.
- Masking
- Hiding part of a value (for example replacing the middle of an ID number with asterisks). This is not anonymisation; reversibility has to be assessed.
- Personal data
- Any information relating to an identified or identifiable natural person. Data that does not identify anyone on its own can become personal data when combined with other data.
- Personal Data Protection Board
- The Personal Data Protection Board. The body that supervises application of the Law, issues principle decisions and resolves complaints.
- Processing activity
- Any operation performed on personal data: obtaining, recording, storing, altering, transferring, classifying, deleting. The inventory is built around these activities.
- Pseudonymisation
- Processing data so it can no longer be attributed to a specific person without additional information. That additional information is kept separately; the data is still personal data.
- Retention period
- How long a data category is kept. The period must have a basis: a statute, a limitation period, or a clearly defined business need.
- Special categories of personal data
- Data on race, ethnic origin, political opinion, philosophical belief, religion, sect, dress, association/foundation/union membership, health, sexual life, criminal convictions and security measures, plus biometric and genetic data. Processing is subject to additional conditions.
- VERBIS
- The Data Controllers' Registry Information System. The public registry where obliged controllers record their processing activities.
- Withdrawal of consent
- A data subject may withdraw explicit consent at any time. Withdrawal takes effect going forward; processing up to that point does not become unlawful, but processing cannot continue afterwards.
These definitions are simplified to explain everyday usage; they do not replace the definitions article of the law. In a concrete case the text of the legislation itself governs.
See where you stand in 20 minutes
The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.
Look at it yourself first
A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.
Start the compliance testLet's look together
We discuss your current state and work out which step comes first and how long it takes.
Request a conversation
