Role-based access — not everyone needs to see everything
Article 12 of Law No. 6698, known as KVKK (Türkiye's Personal Data Protection Law), requires the data controller to take the technical and administrative measures needed for data security. On the software side, the first measure is making sure each user can access only the data their job requires.
For example, in a CRM a sales representative sees only their own customers, the accounting team can access invoice details but not customer notes, and a dealer user sees only their own current account. Risky actions such as bulk data export (downloading to Excel) are tied to a separate permission.
Authentication
- Strong password rules and a limit on failed login attempts
- Two-factor authentication for administrator accounts
- Personal accounts instead of shared ones
- Same-day removal of access for employees who leave
- Automatic logout for sessions left idle for a long time
Access logs (logging)
A log is a record of who did what in the system and when. A good access log answers these questions: which user viewed, changed, deleted or exported which record, when, and from which IP address.
The logs themselves must be protected too: users must not be able to alter them, they must be kept for a defined period and reviewed regularly. Alerts can be set up for unusual activity, such as a bulk export at midnight or a large number of failed logins.
Data breach readiness
When a data breach is detected, you are required to notify the Personal Data Protection Board and the affected people; under a decision of the Board, it must be notified without delay and within 72 hours at the latest from the time the breach is discovered. Meeting that deadline is only possible with solid logs: you need to be able to quickly pull out what was affected, when and to what extent. We recommend preparing a short incident plan showing who calls whom.
Data subject requests
Article 11 of the law gives people rights such as learning whether their data is processed, requesting information, and asking for correction or deletion. Article 13 requires requests to be answered within thirty days at the latest. The methods for submitting requests are set out in the Personal Data Protection Authority's communiqué; we recommend deciding with your lawyer which channels you will accept.
On the software side, we make requests easier to handle with:
- A simple tracking screen where requests are recorded and deadlines are monitored
- A tool that finds a person's data across all systems in a single query
- A process that applies a deletion or correction request to every relevant table
- A record of the response given and its date
Checklist
- Does each user access only the data their job requires?
- Is two-factor authentication enabled for administrator accounts?
- Are viewing, editing and exporting logged?
- Are accounts of departing employees closed?
- Is the thirty-day deadline for requests tracked?
- Is the incident plan written down?
This work is part of our KVKK compliance service and comes as standard in the custom software and B2B dealer portal projects we develop.
Frequently asked questions
Are logs personal data too?
Often, yes — they contain usernames and IP addresses. That is why logs are also subject to retention periods and access rules.
Do requests require identity verification?
You need to make sure the requester really is the data subject; otherwise someone else's data could end up with the wrong person.
For questions, call +90 850 432 55 13 or use the contact page.