Service · Cybersecurity

KVKK and personal data protection

Ask a Turkish SME how it complies with KVKK and the answer is usually a privacy notice written by a lawyer. That notice matters, but Law No. 6698 on the Protection of Personal Data also expects the data controller to keep information secure through suitable technical and administrative safeguards, and those live in your IT rather than in a PDF. The gap tends to show at the worst possible time. A patient from two years ago files a request to see her records. A clerk sends the payroll sheet to an outside address by mistake. The Board writes after a complaint and wants to know how access is controlled. If nobody can point to the systems involved or name the people with access, the notice alone will not carry you. This service covers the technical half. We locate personal data across your systems, restructure permissions, turn on logging and give your staff a clear routine for a breach. We are not lawyers, and we say so plainly: legal opinions, final notice wording and contracts remain with your counsel or KVKK consultant. What we hand them is solid, dated evidence of how your systems behave, produced entirely over remote sessions.

72 hours
window for reporting a breach to the Board
30 days
latest point to reply to a data subject request
One login per person
no more generic “frontdesk” users
Remote only
your staff keep working throughout

What the work covers in practice

Protection should match what is at stake. Marketing email addresses for a web shop are one thing; patient files at a dental practice are special category data under KVKK and call for stricter handling. We scale the effort to your data and do not sell you controls your risk does not need.

Agree the scope with the engineer who will do the work

Data location map

Customer cards in Logo or Mikro, the payroll tool, CRM, booking software, SharePoint, OneDrive, file shares, inboxes and that exported spreadsheet sitting on a sales laptop. We record each location, the categories of data it holds and who can reach it, which is exactly what your KVKK inventory needs.

Notice versus reality

Your website forms, cookie banner and booking pages collect data every day. We check what they gather, whether explicit consent is a genuine separate tick box and where proof of that consent is stored, then report the mismatches to the person who drafts your notices.

Processor access review

Accountants, payroll bureaus, software vendors and shipping integrators often connect with accounts nobody remembers creating. We catalogue those connections, shut the stale ones and describe the safeguards your data processing agreements should reference.

Permissions by job role

Payroll figures are for HR, medical notes are for clinicians. Access is assigned to groups in Entra ID or Google Workspace, so when someone joins, moves or leaves, their rights follow the role rather than lingering.

Audit trails

Microsoft 365 auditing and file server access logs are switched on and retained long enough that, weeks later, you can still see which account opened a given document.

Retention in practice

If your retention and destruction policy promises a deletion period, mail and document retention rules should enforce it. We configure those rules and decide how proof of each periodic deletion gets recorded.

Breach routine

A single page covering the opening hours of an incident: the person who triages, the logs that must be frozen, the facts the Board notification will require and the way affected individuals will be told.

How we approach the job, from first call to handover

Cheap, high-impact fixes come first. Deeper restructuring waits until those are done.

01

Initial review

One video meeting with your KVKK contact and a remote look at your tenant and servers. Output: a list of personal data systems and the protection each currently has.

02

Immediate clean-up

Dormant accounts of former staff, shared usernames and logins protected only by a password are dealt with during week one.

03

Safeguards

Encrypted laptop drives, logging, a role-based access model and restrictions on sharing with outsiders, introduced in stages so that no department suddenly loses access to its work.

04

Evidence pack

Each safeguard is written up with its date and owner, in wording you can paste into the inventory, a VERBİS entry or a response to the Board.

Regulators care less about which products you own and more about what you can demonstrate. Following a complaint or incident, the useful questions are factual: which accounts could open the data, from what date, what record confirms it and when the setup was last checked. An undocumented control is very hard to defend, which is why everything we change is logged with a date.

Frequently asked questions

Board decisions set out who must register and who is exempt, taking into account things like staff numbers, financial thresholds and the nature of the data. That is a legal question for your adviser. Where registration is required, we extract the categories, retention periods and safeguards from the inventory so the entry can be completed quickly.

Start from the inventory: booking tool, patient software, mailboxes, shared folders and backups. A Microsoft 365 eDiscovery query will pull up messages and files mentioning her name or ID number in minutes. You have thirty days at most to respond, and counsel should see the answer before it is sent.

Write to support@apply.tr immediately, or helpme@apply.tr if you have a contract with us. We attempt a message recall, secure the relevant logs and pin down what data left the building. Your legal adviser then decides whether a Board notification is needed; the 72 hours run from the moment you learned of the incident.

KVKK treats that as an international transfer and attaches conditions to it. Choosing the right legal basis, for example standard contracts, is your lawyer's job. Ours is to confirm in which countries your mail, backups and apps physically reside and to record it for the inventory, which also helps with GDPR if you sell to EU customers.

No, that is legal work. We test whether your systems behave as the notice claims. Suppose the notice promises deletion after two years: we look for a retention rule in the mail system and CRM that actually does that, and flag it if there is none.

Get a clear picture of your personal data

List the systems where customer and staff records are kept. We will send back a first assessment and suggested priorities.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.