Mevzuat Kategorileri
Hukuksal Düzenlemeler
Türkiye’de Kişisel Verilerin Korunması Kanunu, Sosyal Güvenlik Hukuku, Vergi Hukuku, İş Sağlığı ve Güvenliği Mevzuatı, Borçlar Hukuku, İş Hukuku, Ticaret Hukuku, Türk Parası Kıymetini Koruma Mevzuatı, Kambiyo Mevzuatı ve Vatandaşlık ve Göçmenlik Mevzuatı ile ilgili en güncel bilgilerin yer aldığı makalelere buradan ulaşabilirsiniz.
İkili Anlaşmalar
Türkiye ve diğer ülkeler arasında yapılan en güncel uluslararası ikili sosyal güvenlik ve vergi anlaşmalarının tarihlerine ve dokümanlarına buradan ulaşabilirsiniz.
As it is known, the principles of transfer of personal data abroad are regulated in Article 9 of KVKK. According to this regulation, in transfers to countries that are not counted among adequate countries, with a commitment to be signed between the person to whom the transfer will be made and the person who will make the transfer, permission must be obtained from the Board. However, adequate countries have not yet been announced by the Authority and it is likely that it will take time to identify safe countries, as we see from the "Criteria to be Based on Determining Countries with Sufficient Protection" published by the Authority. Since the adequate countries have not yet been announced, although people go for permission from the Board, there are also some difficulties in this process. Considering these difficulties, the Authority announced the Binding Corporate Rules institution and announced the method to facilitate data transfer for multinational group of companies. In this method announced, the process of obtaining permission from the Board will be carried out, as well. However, it should be noted that although a different alternative has been presented by the Authority, the question marks in transferring abroad have still not been eliminated, since the adequate countries have not been announced yet. Besides, as we will explain below, the announcement that the application of the Binding Corporate Rules will be finalized by the Authority in 1 year and this period will likely to be extended for 6-month periods shows that this process will not be short, as well.
It is the data protection policies that multinational companies determine the rules for transferring personal data to the companies that they are affiliated to, where they operate, have common economic activities or have a common decision mechanism, and that all companies in the group must comply with. Binding Corporate Rules are approved by data protection authority in the country, where the company is to make the data transfer. This institution was originally designed to provide a legal basis for international data transfers in Europe; however, it is obvious that if these rules are fully implemented, since they include the principles regarding data processing, companies will perform data processing management as required.
In order understand the binding corporate rules in the data protection legislation in Türkiye (KVKK), first, it will be useful to handle the regulation of "Binding Corporate Rules" in European data protection law (GDPR). Binding Corporate Rules are regulated under Article 47 of the GDPR and the minimum conditions that must be included in the Binding Corporate Rules text have been set out with this article. According to GDPR, the points that should be included in the text are briefly as follows:
On 10.04.2020, the way of creating Binding Corporate Rules has been announced by the Authority that the way of creating Binding Corporate Rules and Binding Corporate Rules Application Form for Data Controllers and Auxiliary Document Regarding the Main Points to be Included in Binding Corporate Rules for Data Controllers have been published. Details on the application form and the auxiliary document are as follows:
In the auxiliary document published in addition to the announcement of the Authority, the points to be included in the application form and the Binding Corporate Rules text are shown comparatively. In the light of the information included in the application form and the auxiliary document, minimum points to be included in the Binding Corporate Rules are as follows:
Should you require any additional information in regards, please contact your customer representative.
Kategori Personal Data Protection Law
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.
About The Author
Türkiye's National Artificial Intelligence Action Plan 2026–2030: A New Era for the Private Sector
Selma Kıy
21 Ağustos 2026
Five-Year Retention of Employee Emails and Conditions for Access: The Garante's Decision
Ezgi Anasız
KVKK Compliance Period for Loyalty Programs Extended to February 28, 2027: How Should Companies Use the Additional Compliance Period?
17 Ağustos 2026