Globya Information Technologies · Since 2000 0850 432 55 13 info@globya.com.tr
SearchCtrl K Start a project

Data Protection and Security

Your cloud tools may be moving data out of Türkiye

Email, cloud storage, analytics, CRM... Most of the tools a company uses keep data on servers outside Türkiye. We explain the rules that changed in 2024 and the steps to take for these tools in plain language.

Cross-border data transfers under KVKK (Türkiye's Personal Data Protection Law) were for many years one of the hardest topics to handle in practice. The original version of the law required, for transfers without explicit consent, either a list of countries with adequate protection or a written undertaking approved by the Personal Data Protection Board. The list was never published, and the undertaking process took a long time. As a result, many companies effectively based their cross-border transfers on explicit consent. The amendment made by Law No. 7499, published in the Official Gazette on March 12, 2024, took effect on June 1, 2024 and changed this picture significantly. In this article we explain the new framework and what it means for a company's everyday tools.

What counts as a "cross-border transfer"?

Many companies believe they don't transfer data abroad because they have never sent anyone a file. Yet each of the following situations can be considered a transfer:

  • Business email is kept on a service hosted outside Türkiye
  • Files are uploaded to a cloud storage service based abroad
  • Analytics and advertising tags on the website send visitor data abroad
  • The servers of your CRM, support, survey or form tool are outside Türkiye
  • Text containing customer information is sent to AI services
  • A customer list is shared with a group company or business partner abroad

That is why the first step is an inventory: which tool keeps which data, in which country?

The tiered structure introduced by the 2024 amendment

The new framework handles transfers in three tiers. The order matters: you move to a lower tier only when the one above it can't be applied.

TierWhat it meansIn practice
1. Adequacy decisionThe Board decides that a country, sector or international organization offers adequate protectionIf there is a decision and one of the processing conditions is met, the transfer can proceed
2. Appropriate safeguardsIf there is no adequacy decision, safeguards are put in place between the partiesThe standard contract announced by the Board, binding corporate rules or a Board-approved undertaking
3. Incidental transferIf neither of the first two routes is available, for exceptional and non-recurring casesA narrow list of cases such as explicit consent or necessity for performing a contract

The route that will be used most here is the standard contract. The Board has announced the standard contract texts, which the parties sign without modification. Under the regulation, a signed standard contract must be notified to the Personal Data Protection Authority within a set period; failing to make this notification, set in practice as a short deadline, can itself lead to administrative sanctions. Confirm the deadline and the notification procedure with your legal advisor. The details of implementation were set out in a regulation published in 2024.

Explicit consent is no longer the main route for transfers; it is now an exception that can be used only for incidental transfers, meaning those that are not regular or recurring. This means that the "let's get consent for everything" approach no longer works for cross-border transfers either. We covered the general logic of consent in our article on when explicit consent is required.

A practical roadmap for cloud and SaaS tools

  1. Build an inventory. Write down every tool you use, the data it processes and where its servers are.
  2. Ask whether it is really necessary. Some tools can be replaced with a domestic alternative or one hosted in Türkiye. For your website and email, a domestic hosting option simplifies things.
  3. Check the provider's documents. Most large providers offer a data processing agreement and a choice of region. Ask whether they sign Türkiye's standard contract.
  4. Reduce the data. Send only the fields that are needed to tools abroad. Steps such as IP truncation in analytics and removing unnecessary form fields shrink the risk.
  5. Update your privacy notice. If data is transferred abroad, this must be stated clearly in the privacy notice.
  6. Keep a record. Document in a table which safeguard you rely on for which tool.

AI services need special attention

The fastest-growing category of transfers lately is AI services. When an employee pastes a customer email into a chat tool hosted abroad to get a summary, that is also a transfer. For business use, choose contract options under which data is not retained or used for training, and anonymize text containing personal data first whenever possible.

Checklist

  • All tools that process data and their server locations are listed
  • The tier (adequacy, appropriate safeguards, incidental) is defined for each transfer
  • Standard contracts are signed where needed and notified to the Authority
  • Explicit consent is used only for incidental transfers
  • The privacy notice describes the cross-border transfers
  • A short internal rule on the use of AI has been written

How we do it at Globya

On the sites and software we build, we map the data flow at the start of the project and report clearly which component sends data abroad. Where possible, we recommend domestic hosting and business email solutions, and if a tool abroad is unavoidable, we minimize the data sent to it. The contract and notification steps are your legal advisor's job; we give them the technical inventory they need, ready to use. As part of our KVKK compliance approach, this work carries no extra charge.

Frequently asked questions

Are the cross-border transfer consents we collected in the past still valid?

For regular and recurring transfers, you are now expected to rely on appropriate safeguards. We recommend reviewing the status of your existing consents and the transition process together with your legal advisor.

Who signs the standard contract?

It is signed between the party transferring the data (you) and the recipient (the provider). Signing an individual contract with large providers may not always be possible; in that case, alternative tools or data reduction options are considered.

Does a tool with servers in Europe also count as abroad?

Yes. Any location outside Türkiye is abroad. Strong protection in Europe does not on its own make the transfer permissible unless the Board issues a separate adequacy decision.

How can we find out which of our tools send data abroad?

We can review your site and the tools you use together. Reach us at +90 850 432 55 13 or through our contact page.

Anything on your mind about this article?

The Globya assistant is online 24/7; it answers right away and passes your question to the team if needed.

Ask the assistant

The next project could be yours

Let us run your digital work from a single point.

Let us hear your needs in a short phone call and prepare a free preliminary analysis report for your website.