Why is KVKK compliance a technical job too?
Law No. 6698 on the Protection of Personal Data, known as KVKK (Türkiye's Personal Data Protection Law), requires every organization that processes personal data to collect it lawfully, use it only for its stated purpose, store it securely and destroy it once the retention period ends. A large share of these obligations is met directly inside your digital systems: website forms, cookies, e-commerce accounts, CRM records, B2B dealer portal users and employee apps.
At many companies, KVKK is considered "done" once a law firm's documents have been pasted onto the website. But if the text says "we don't use cookies without your consent" while the site loads advertising cookies on the very first visit, or if it says "your data is deleted after two years" while the database still holds ten years of records, the text and the system contradict each other. Our job is to make those two sides match.
In every website, e-commerce, portal and software project Globya delivers, KVKK requirements are never left out, and there is no separate charge for them.
Privacy notice and explicit consent
At every point where personal data is collected, people must be told who is processing which data, for what purpose, on what legal basis, and what their rights are. This is the duty to inform. Explicit consent is a separate matter and is only needed when none of the other legal bases listed in the law applies — for example, sending marketing messages or transferring data to a service abroad.
A common mistake is to merge the privacy notice and explicit consent into a single checkbox, or to make submitting the form conditional on consent. We build your forms around this distinction and record when consent was given and with which text. Details are on the privacy notice and explicit consent page.
Cookie management
Apart from strictly necessary cookies, analytics, advertising and personalization cookies require the user's prior consent. The Personal Data Protection Authority's guidance on cookie practices takes the same approach. With properly configured cookie management, these cookies are not loaded before consent, "accept" and "reject" are offered with equal ease, and users can change their choice later.
We connect Google Analytics, the Meta pixel and advertising tags to the consent mechanism. We explain how it is set up on the cookie management page.
Data inventory, retention and destruction
You cannot protect or delete personal data without knowing which system holds it. A data inventory lists each data category, the purpose of processing, the retention period, who has access and where the data is transferred. A retention and destruction policy defines how those periods are actually enforced.
We handle the software side of this work: we map the personal data fields in your systems and set up scheduled jobs that automatically delete or anonymize records whose retention period has expired. Details are on the data inventory and retention page.
Access rights, logs and data requests
The law requires administrative and technical measures for data security. On the software side, that means role-based permissions, strong passwords and two-factor authentication, access logs that record who viewed or changed which record and when, encrypted connections and regular backups.
Data subjects can also ask for information about their data and request correction or deletion; the law expects these requests to be answered within thirty days at the latest. We set up a simple process in which requests are recorded and tracked. Details are on the access, logging and data requests page.
Notice and Consent
How a KVKK privacy notice differs from explicit consent on web forms, sign-up and e-commerce pages, where each belongs and how to keep consent records.
02Cookie Management
KVKK-compliant cookie management for your website — separating necessary and optional cookies, a consent panel, and tying Google Analytics and ad tags to it.
03Data Inventory and Retention
We map the software side of your KVKK data inventory, build retention periods into your systems and set up automatic deletion of data whose time has expired.
04Access and Requests
KVKK technical measures in your software — role-based access, two-factor authentication, access logs, data breach readiness and tracking data subject requests.
How this relates to legal advice
To be clear: Globya is not a law firm, and this service does not replace legal advice. Questions such as which data is processed on which legal basis, your registration obligation in VERBIS (Türkiye's data controller registry), and employee and supplier contracts are for your lawyer to decide.
Our role is technical implementation. If you have a lawyer, we work alongside them and reflect the rules they set correctly in your systems. If you don't, we clarify what you need and clearly flag the points that require a legal assessment. We also describe our general approach on the our approach to KVKK page.
Who needs this most?
Every company processes personal data, but in some industries the data is more sensitive. Health data counts as a special category of personal data and is subject to stricter conditions, so we take extra care in healthcare and clinics projects. E-commerce sites, membership systems, dealer portals and mobile apps that track employee location also process large amounts of data. In a new e-commerce or corporate website project, these requirements are part of the design from day one.
If you'd like to see where your current system stands, we can do a short preliminary review. For systems built by other providers, the scope and price of the compliance work are set in a written proposal after the discovery call. Call +90 850 432 55 13 or write to us through the contact page.
Frequently asked questions
Our website only has a contact form — does KVKK apply to us?
Yes. If your form collects a name, email address or phone number, you are processing personal data. At a minimum you need a privacy notice, cookie management and secure storage.
Will we pay extra for KVKK compliance?
In projects Globya delivers, KVKK requirements are part of the scope and there is no extra charge. Systems built by other companies may need a separate piece of work.
Do you write our privacy notice?
We prepare a draft based on the data flows on your website. We recommend having your lawyer review the final text.
What are the penalties for violating KVKK?
The law provides for administrative fines and, for certain acts, criminal penalties; the amounts are revalued every year. For current figures, we recommend checking Law No. 6698 and the announcements of the Personal Data Protection Authority.