Legislation Categories
Legislative Updates
Here you can access most recent articles on legislative updates regarding Personal Data Protection Law, Social Security Law, Taxation Law, Occupational Health and Safety Law, Code of Obligations, Labor Law, Turkish Commercial Code, Law on Protection of the Value of Turkish Currency, Foreign Exchange Legislation, and Immigration Law in Türkiye.
Bilateral Treaties
You can access the dates of the most recent international bilateral social security and double taxation treaties made between Türkiye and other countries and relevant documents here.
Test
17 September 2026
Author Ilgım Gerboğa, Category KVKK - GDPR, Work Life
The ISO/IEC 27701:2025 revision has introduced an important transition process for organizations implementing a privacy information management system, requiring existing systems to be reassessed in accordance with the new requirements. The standard was published on October 14, 2025, and the transition process is expected to be completed by October 31, 2028.
In this context, organizations certified according to ISO/IEC 27701:2019 are required to align their existing certificates, processes, documentation, and audit preparations with the requirements of ISO/IEC 27701:2025 within the three-year transition period.
The deadline for the transition process should be monitored according to the existing certification structure and announcements made by certification bodies. However, industry practices indicate that ISO/IEC 27701:2019 certificates will cease to be valid after October 2028 and that all organizations should have completed their transition audits by this date.
Compared with the previous version, ISO/IEC 27701:2025 is not merely an update containing terminological or limited explanatory changes. The new version repositions the privacy information management system from being an extension dependent on ISO/IEC 27001 and ISO/IEC 27002 into a more independent, integrated, and auditable management system standard.
The key differences introduced by the revision include the standard's structure enabling independent certification, the restructuring of management system requirements according to the harmonized structure, a clearer emphasis on privacy risk management, and the restructuring of controls relating to data controller/data processor roles.
ISO/IEC 27701:2019 was implemented as an extension standard built on ISO/IEC 27001 and ISO/IEC 27002. For this reason, certification of the privacy information management system was generally assessed together with an existing information security management system structure.
With ISO/IEC 27701:2025, the standard has gained an independent structure with its own management system requirements. While this change enables organizations to maintain their privacy information management system in an integrated manner with ISO/IEC 27001, it also introduces the option of standalone, i.e. independent, certification.
This approach supports addressing privacy information management not merely as an additional component of information security controls, but independently within the organization's overall management system structure.
The new revision aligns more clearly with the harmonized structure used in ISO management system standards. The areas of context, leadership, planning, support, operation, performance evaluation, and improvement are addressed more holistically in the context of the privacy information management system.
With the ISO/IEC 27701:2025 revision, transition planning is required to adapt existing ISO/IEC 27701:2019 certificates and the related management system practices to the new version.
For this reason, the transition process should not be regarded merely as renewing the existing certificate under the new version. Organizations are expected to review the scope, roles, risk assessment methods, control structures, and audit evidence of their existing privacy information management systems in accordance with the new standard.
As part of the transition process, organizations are required to align with the ISO/IEC 27701:2025 requirements, complete the necessary documentation and process updates, carry out internal audit and management review activities in accordance with the new standard, and plan transition audits with certification bodies in a timely manner.
During the transition to ISO/IEC 27701:2025, it would be beneficial for organizations, as a first step, to compare their existing privacy information management system structure with the requirements of the new standard and identify the changes that need to be implemented.
In this context:
may constitute the key steps of the transition process.
The ISO/IEC 27701:2025 revision supports addressing privacy information management through a more independent, systematic, and auditable management system approach.
The new standard makes the relationship between the scope of the privacy information management system, leadership responsibilities, the risk-based approach, management of data controller and data processor roles, documentation structure, and continual improvement processes more visible.
For this reason, the transition to the new version should not be regarded merely as an update of existing documentation; it should be considered an opportunity to review the organization's privacy information management approach as a whole.
For organizations adopting a privacy information management system approach, the ISO/IEC 27701:2025 revision offers an important opportunity to strengthen organizational maturity in terms of legal compliance, accountability, risk management, and personal data protection.
Closely monitoring the changes introduced by ISO/IEC 27701:2025 and developments relating to the transition process to the new standard is critically important for organizations to manage the transition process in a timely and effective manner.
You can access the announcement on the transition to the ISO/IEC 27701:2025 and ISO/IEC 27706:2025 standards published by the Turkish Accreditation Agency here. (In Turkish)
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.
About The Author
https://www.cottgroup.com
Amendments to the Law on the Protection of Personal Data No. 6698 Within the Scope of the 8. Judicial Package and the Reflections of it
Semih Er
5 August 2024
Processing of Biometric Data in Terms of KVKK and GDPR
CottGroup Hukuk ve Mevzuat Ekibi
13 February 2024
Algorithmic Transparency Within the Scope of GDPR
30 July 2021
Data Transfer within the Scope of KVKK and GDPR
Taylan Ege Günel
4 December 2023