Skip to content
HEM Bilişim
Resources

Checklists

Simplified versions of the checklists we use in the field. No sign-up wall: the lists are on the page, ready to read or print.

Each list collects what to look at in the first pass of a piece of work. Where we have a step-by-step guide on the topic, it is linked below the list.

KVKK starter checklist

What an organisation new to compliance should look at on the first pass.

Items · 15

  • Have the units that process personal data been listed?
  • Has it been written which data categories each unit processes?
  • Has a purpose been written for every processing activity?
  • Has a legal ground been identified for every purpose?
  • Has it been established whether special category data is processed?
  • Have transfers outside the organisation been listed?
  • Do contracts with processors contain data processing terms?
  • Has a retention period and its basis been written for every data category?
  • Has the privacy notice been prepared and published?
  • Has processing that relies on explicit consent been separated out?
  • Has a channel been defined for data subject requests?
  • Has the VERBIS obligation been assessed?
  • Is it written down what happens in a data breach?
  • Are access rights recorded?
  • Have employees been briefed?

The first hours of a breach

What to check, in order, once a breach is discovered.

Items · 15

  • Has the moment of discovery been recorded?
  • Have the response team and roles been activated?
  • Has the spread been stopped (account closure, access removal, isolation)?
  • Has evidence been preserved — were logs and disks left untouched?
  • Has it been established which data categories were affected?
  • Has the number of affected data subjects been determined?
  • Was special category data affected?
  • Did data leave the organisation?
  • Has the impact assessment been made in writing?
  • Has a decision been made on whether to notify the Authority?
  • Has a decision been made on whether to inform the data subjects?
  • Have the notification texts been prepared?
  • Has the root cause been identified?
  • Has a corrective action been defined and given an owner?
  • Has a review been held and the procedure updated?

Supplier assessment questions

What to ask before working with a service provider that will reach your data.

Items · 11

  • Which personal data will they reach?
  • Where do they host the data (country and infrastructure)?
  • Do they use sub-processors, and if so which?
  • How long do they retain the data, and what happens at contract end?
  • Is a contract signed with them as a data processor?
  • How do they manage access rights, and do they keep records?
  • Do they encrypt data in transit and at rest?
  • How quickly do they notify us in a breach?
  • Do they hold security certifications, and what is the scope?
  • Does the contract give us a right to audit or to ask questions?
  • How are return and disposal of data handled when the service ends?

Pre-AI checklist

What to answer before putting an AI-assisted system into operation.

Items · 12

  • Which data will reach the model and which will not — is it written down?
  • Is that restriction technically enforced, or is it only a warning?
  • How long does the provider retain the data, and is it used for training?
  • Are those terms written into the contract?
  • Is the output a decision or a suggestion — is there human approval at the consequential step?
  • Is the approval recorded?
  • Are calls logged (input summary, model, output, timestamp)?
  • Is unnecessary personal data accumulating in those logs?
  • Is it defined what the model will not answer?
  • Is the user informed that AI is being used?
  • Has a measurable benefit been defined (time, errors, capacity)?
  • Has this use been entered in the AI inventory?

Use your browser's print function to print a checklist.

Fillable template versions of these lists are in preparation. If you would like one now, write to us and we will send the version we have.

Request the fillable template

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation