PERSONAL DATA COMPLIANCE IN TÜRKİYE'S PAYMENT SECTOR: A SECTOR-SPECIFIC FRAMEWORK UNDER THE KVKK
Türkiye's payment and electronic money sector has grown at a remarkable pace over the past decade. The number of licensed payment institutions and electronic money institutions operating under Law No. 6493 on Payment and Securities Settlement Systems, Payment Services and Electronic Money Institutions ("Law No. 6493") has expanded significantly, and so has the range of services they offer. For foreign fintech businesses looking at Türkiye, this growth has consistently raised a practical question that goes beyond licensing: how does Turkish data protection law apply to the dense, multi-party data flows that payment services generate?
That question now has a more detailed answer. In April 2025, the Personal Data Protection Authority ("KVKK") published its Good Practices Guide on the Protection of Personal Data in the Payment and Electronic Money Sector ("Guide"), prepared jointly with the Turkish Payment and Electronic Money Institutions Association ("TÖDEB[1]”). Running to nearly one hundred pages, the Guide is the first sector-specific data protection instrument of its kind for payment institutions in Türkiye, and it signals a clear expectation: data compliance in this sector will be assessed with a level of granularity that general KVKK guidance has not previously provided.
- Türkiye's Data Protection Framework: The Basics for Payment Institutions
Personal data processing in Türkiye is governed primarily by the Personal Data Protection Law No. 6698 ("KVKK"), which entered into force in 2016 and was modelled in significant part on the European Union's data protection framework. The KVKK establishes processing conditions, data subject rights, and obligations for data controllers that will be recognisable to anyone familiar with the General Data Protection Regulation ("GDPR"), even if the institutional architecture and enforcement mechanisms differ.
Unlike the GDPR, the KVKK does not contain an explicit territorial scope provision. In practice, the KVKK clearly applies to any natural or legal person established in Türkiye that processes personal data. For entities established outside Türkiye, the KVKK Board has, in a number of decisions, taken the position that KVKK obligations apply where a foreign entity processes personal data of individuals located in Türkiye—irrespective of where the processing takes place. Foreign fintechs entering the Turkish market, whether through a locally licensed establishment or a cooperation arrangement under Article 19 of the Payment Services Regulation[2], should therefore proceed on the assumption that the KVKK will apply to their data processing activities from the outset.
Under the KVKK, the key structural distinction is between the Data Controller ("Veri Sorumlusu"), which determines the purposes and means of processing, and the Data Processor ("Veri İşleyen"), which processes data on behalf of the controller. Both carry obligations, but the controller bears primary responsibility for lawful processing and is required to register with the Data Controllers Registry Information System ("VERBİS") where the relevant thresholds are met.
For payment and electronic money institutions, the KVKK does not operate in isolation. Law No. 6493, the Regulation on Payment Services and Electronic Money Issuance and Payment Service Providers ("Payment Services Regulation"), and the Communiqué on Information Systems of Payment and Electronic Money Institutions and Data Sharing Services ("Data Sharing Communiqué") create a dense layer of sector-specific rules that intersect directly with data protection obligations. The Payment Services Regulation explicitly provides that in matters of personal data processing, the KVKK and its secondary legislation take precedence. The sector-specific rules do not displace the KVKK; they operate alongside it, and in several respects they add to it.
- The Good Practices Guide: What It Is and Why It Matters
The Guide's stated purpose is to provide practical guidance to payment institutions and electronic money institutions on how to conduct their data processing activities in compliance with the KVKK and its secondary legislation. It covers five categories of activity: electronic money issuance, money remittance services, point-of-sale ("POS") services, bill payment intermediary services, and mobile payment services. Open banking services were deliberately excluded, as the regulatory framework governing them was still being implemented at the time of drafting and industry-wide practice had not yet consolidated. Further guidance on open banking is anticipated as that framework matures.
A point of practical importance is the Guide's legal status. It does not constitute binding legislation and does not create new obligations beyond those already established under the KVKK and the applicable sector-specific rules. The KVKK has made clear that in any investigation or enforcement action, it will continue to assess matters on the basis of applicable legislation and the specific facts of each case. That said, the Guide represents the KVKK's considered view of how existing obligations should be implemented in the payment sector. Institutions that depart from its recommendations without good reason may face heightened scrutiny in any subsequent regulatory review.
- Data Controller vs. Data Processor: Who Owns the Obligation?
One of the Guide's most practically useful contributions is its service-by-service mapping of data controller and data processor roles across the payment sector. For foreign players trying to understand where their obligations sit, this mapping is an essential reference point.
The Guide identifies the Data Controller for each service type. For electronic money issuance, it is the electronic money institution itself. For money remittance, both the institution serving the sender and the institution serving the recipient are identified as separate Data Controllers. For POS services, the payment institution providing the POS infrastructure, the merchant accepting payment, and the relevant banks may each hold Data Controller status in respect of different elements of the same transaction. For bill payment intermediary services and mobile payment services, the mobile operator and its payment institution affiliate are identified as separate Data Controllers operating in parallel.
The Guide also addresses the position of what it terms the "silent party" — a concept also recognised in European data protection guidance on payment services — a data subject who is not a direct customer of the processing institution but whose personal data must nonetheless be processed in order to execute the transaction[3]. The clearest example is the recipient in a money remittance: their name and identification details are collected from the sender and processed by the sending institution, without any direct relationship having been established between that institution and the recipient. The Guide confirms that silent party data must be handled in strict compliance with the KVKK's purpose limitation and data minimisation principles, and that the legal basis for such processing rests on the necessity of establishing or exercising a right rather than on consent.
- Key Compliance Themes
Several themes in the Guide stand out as particularly significant for institutions operating in the payment sector and for foreign players assessing what compliance in Türkiye demands in practice.
The first concerns the legal basis for processing. The Guide is explicit that consent should not be used as a legal basis where another ground is available. Relying on consent in circumstances where processing could be grounded on a legal obligation, such as customer due diligence (“CDD") requirements under the Law on Prevention of Laundering Proceeds of Crime No. 5549 ("Law No. 5549"), risks misleading data subjects into believing they can halt processing by withdrawing their consent. The Guide treats this misuse of consent as a breach of the KVKK's good faith principle, and institutions should review their consent mechanisms carefully against this benchmark.
Biometric data presents a distinct compliance challenge. Payment and electronic money institutions must process biometric data as part of remote identity verification procedures regulated under the Data Sharing Communiqué. The Communiqué requires that explicit consent be obtained before biometric data is processed in this context, making this one of the few areas where consent is the mandatory legal basis. Institutions must ensure that this consent is obtained as a discrete, informed, and freely given act, and that biometric data is handled in accordance with the additional safeguards prescribed by the KVKK Board's Decision No. 2018/10[4].
Data minimisation runs throughout the Guide as an organising principle, but institutions should be aware that the regulatory direction is not always towards less data — it is towards precisely the right data. A practically significant illustration is the December 2024 amendment to the Financial Crimes Investigation Board ("MASAK") General Communiqué No. 5,[5] which removed simplified customer due diligence (“CDD”)measures previously available for virtual POS services. From 25 December 2024, full CDD procedures apply, meaning that institutions must now collect a wider range of personal data — but that data must align precisely with the requirements of the applicable anti-money laundering regulations and must not be retained or used beyond those purposes.
On retention, the Guide highlights two statutory minimum periods: ten years under Law No. 6493 (applicable to records of payment transactions and related documentation) and eight years under Law No. 5549 (applicable to CDD records and transaction monitoring data). Where both periods apply to the same data, the longer period governs. Once the applicable period expires and no other legal basis for continued storage exists, the data must be deleted, destroyed, or anonymised in accordance with the KVKK Board’s published guidance on these processes.
- Cross-Border Data Flows
Cross-border data transfers present one of the more complex compliance questions for foreign players in Türkiye's payment sector, not least because the applicable rules sit at the intersection of two distinct regulatory regimes.
Under the KVKK as amended by Law No. 7499 in March 2024, personal data may be transferred abroad where the recipient country benefits from an adequacy decision issued by the KVKK Board, or where appropriate safeguards are in place, most commonly through the standard contractual clauses (“SCCs”) published by the KVKK, which must be notified to the Authority within five business days of signing. It should be noted that SCCs alone may not be sufficient where the recipient country’s legal framework does not provide an equivalent level of protection in practice; in such cases, additional safeguards may be required. In the absence of both an adequacy decision and appropriate safeguards, transfers are permitted only on an incidental basis.
Layered on top of this is the sector-specific requirement under Law No. 6493 that payment institutions store all relevant records and data domestically. This obligation is reinforced by the Data Sharing Communiqué, which permits data to be shared with foreign counterparties only to the extent strictly necessary for the execution of a payment transaction involving a cross-border element, and only on the condition that the data continues to be stored within Türkiye. Violations of the domestic storage requirement carry criminal sanctions under Law No. 6493, a point that distinguishes this regime from the predominantly administrative enforcement framework of the KVKK.
For foreign entities receiving personal data from Türkiye-based payment institutions as part of a processing arrangement or a partnership structure, these rules have direct contractual implications. Ensuring that data flows are structured to comply with both the KVKK transfer framework and the sector-specific storage obligations will in practice require careful attention at the contract drafting stage.
- What This Means for Foreign Players
For a foreign fintech assessing its position in the Turkish market, the Guide's practical implications vary depending on the chosen market entry model, but the core data protection obligations are consistent across structures.
A foreign entity that establishes a locally licensed payment institution or electronic money institution in Türkiye will be subject to the full range of KVKK obligations, including VERBİS registration where the relevant thresholds are met, transparency obligations towards data subjects, and the obligation to implement appropriate technical and administrative security measures. The licensed institution will typically be the Data Controller for the services it provides.
A foreign entity providing payment services in Türkiye through a cooperation arrangement with a licensed local institution under Article 19 of the Payment Services Regulation may, depending on the business model, qualify either as a Data Controller in its own right or as a Data Processor acting on behalf of the local institution. This determination cannot be made in the abstract; it requires a careful analysis of how personal data flows between the parties, who determines the purposes and means of processing, and what role each entity plays in the delivery of the service. The cooperation agreement should reflect this analysis precisely, with clear contractual provisions governing data protection responsibilities, the scope of permitted processing, and the treatment of cross-border data transfers. A mismatch between the commercial structure and the data protection framework embedded in the agreement is one of the more common and consequential risks in cross-border payment arrangements.
- Conclusion
The Guide reflects a broader regulatory direction in Türkiye towards sector-specific data protection frameworks that translate general KVKK principles into concrete operational requirements. A similar guide already exists for the banking sector, and the payment sector guide is a natural extension of that approach. Further guidance on open banking services, which was expressly excluded from the current Guide's scope, is anticipated as the regulatory framework in that area matures.
For foreign players, the trajectory is clear: data protection compliance in Türkiye's payment sector is becoming more granular, more enforceable, and more closely aligned with international standards. Engaging with that framework proactively, rather than treating it as an afterthought to licensing and commercial structuring, will be the distinguishing feature of market participants that build durable operations in Türkiye.
[1] Personal Data Protection Authority (KVKK) and Turkish Payment and Electronic Money Institutions Association (TÖDEB), Good Practices Guide on the Protection of Personal Data in the Payment and Electronic Money Sector, KVKK Publication No. 63, March 2025, available at: https://www.kvkk.gov.tr/Icerik/8286/Odeme-ve-Elektronik-Para-Sektorunde-Kisisel-Verilerin-Korunmasina-Iliskin-Iyi-Uygulamalar-Rehberi.
[2] Article 19 of the Payment Services Regulation sets out the conditions under which a foreign-incorporated entity may provide payment services in Türkiye in cooperation with a locally licensed institution, without itself obtaining a separate licence. For a detailed discussion of this model and its practical implications, see our earlier article "Did You Know That Foreign PFs and E-Money Institutions Can Operate in Türkiye Without a Licence?" available at: https://chambers.com/articles/did-you-know-that-foreign-pfs-and-e-money-institutions-can-operate-in-t%C3%BCrkiye-without-license.
[3] European Data Protection Board, Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR, version 2.0, adopted 15 December 2020, available at: https://www.edpb.europa.eu/documents/guideline/guidelines-062020-on-the-interplay-of-the-second-payment-services-directive-and_en.
[4] Personal Data Protection Board Decision dated 31 January 2018, No. 2018/10, on the adequate measures to be taken by data controllers in the processing of special categories of personal data. Available at https://www.kvkk.gov.tr/Icerik/4110/2018-10.
[5] Amendment introduced by MASAK General Communiqué No. 26, published in the Official Gazette dated 25 December 2024, No. 32763.