Solution · By goal

KVKK compliance

Plenty of firms in Turkey own a privacy notice, a retention and destruction policy adapted from a template, and perhaps a VERBİS registration. The trouble is that those documents rarely describe what the systems actually do. The policy promises deletion after two years; meanwhile old quotation emails have been sitting on the shared drive for a decade. After a breach, the Personal Data Protection Board expects to hear within 72 hours which data, how many people and what period are involved. If nobody can say what is stored in mailboxes, network folders and industry software, those three days vanish quickly. Apply is not a law firm and gives no legal opinions; that assessment belongs to your own lawyer. Our part is closing the gap between paper and practice, so the software does what the policy says and you can prove it.

72 h
to notify the Board once a personal data breach is discovered
6698
the number of the Turkish data protection law, KVKK
€55
hourly rate plus VAT for work outside a service plan
100%
remote: nobody needs to visit your premises

Where we come in

Responsibilities divide neatly. Legal choices, such as the lawful basis for processing, how long records are kept, or the wording of notices and consent forms, are made by you with your lawyer or KVKK consultant. Whatever is a setting, whether on staff computers, in your cloud office suite or on servers, falls to Apply to inspect and fix.

Arrange an online meeting

Finding the data for real

We search for personal data in Logo, Mikro or Netsis, the CRM, Outlook and Gmail, shared folders, website forms, the online store admin, the courier integration and those payroll spreadsheets emailed to your accountant each month. The findings feed your data inventory and usually correct it. Anything that contradicts what was entered in VERBİS is flagged separately.

Notices and consent built into forms

Your lawyer drafts the wording; we make sure it appears where it should. Contact and sign-up forms link to the privacy notice, marketing permission sits in its own unticked box, and the cookie banner follows the Board's guidance on cookies. Every consent is stored with the person, the time and the version of the text they saw, ready to export on request.

Processors and cross-border transfers

Every outside party handling data for you goes on one list: the accounting firm, payroll software, hosting company, newsletter tool, e-invoicing provider, courier firms and Apply itself. For each we note what they process and the country it is held in. Your lawyer can then see which processor agreements need reviewing and exactly where the rules on transfers abroad kick in.

Retention rules that actually run

Periods written in the policy become settings: retention labels on mailboxes, automatic removal of old job applications, expiry of outdated backup sets, plus a reminder and record template for scheduled destruction. Anything tax rules require you to hold on to is locked down rather than erased. Your lawyer and accountant decide which period wins.

Security controls, applied remotely

A second factor for every login, laptop drives encrypted via Intune, Entra ID roles replacing the single shared administrator password, labelling and leak prevention rules in Microsoft 365, and audit trails retained for the period your policy sets. Our work is guided by ISO 27001 principles; we hold no such certificate and never suggest otherwise.

Incidents and requests from individuals

A written flow showing who alerts whom, and with what facts, so the decision on notifying the Board is made inside the 72 hours. Alongside it sits a technical route for locating one individual's records across all systems, exporting them or deleting them before the reply deadline runs out.

The four stages

No drawn-out audit. Urgent and inexpensive fixes go first: disabling the still-active login of someone who left last spring often does more good than buying a new product.

01

Look, do not touch

We begin by talking online with the person who owns the privacy topic internally. After that we are granted viewing rights only, across your cloud tenant, servers and endpoints, and during this phase not a single setting is altered.

02

A report anyone can read

It maps each data type to its location, names every outside party handling it and lists the gaps, ranked by urgency with the likely effort in hours next to each. Whole sections can be pasted by your lawyer or consultant into the inventory and the VERBİS entries.

03

Quick wins first

Within the opening days we switch on two-step sign-in, remove logins nobody owns and close links that expose files publicly. Disk encryption, labelling, leak prevention and automatic deletion come next on scheduled evenings, so any brief interruption misses the working day.

04

Keep it current

Adopting a new tool, signing a new supplier or losing an employee who had wide permissions are all reasons to refresh the inventory, besides the annual check. An hour of online awareness training for staff fits in at this point. We store screenshots of the settings as proof.

Take an İzmir home textiles brand selling through Trendyol and its own website. Months ago, to sort out a courier problem, someone shared the order list with names, addresses and phone numbers on Google Drive as “anyone with the link”, and then forgot about it. The inventory scan spots that link on day one and closing it takes five minutes. The access logs then show who opened it. Whether this counts as a breach, and whether the Board must be told, is your decision as data controller together with your lawyer, but this time it rests on records rather than guesswork.

Frequently asked questions

No. Choosing a lawful basis, deciding what a notice should say or judging whether an incident is reportable are legal matters, while our expertise is engineering. Instead we partner with whoever advises you: they get an accurate inventory and straight technical answers from us, and we put their decisions into practice. Should nobody fill that role yet, we will point that out and suggest bringing in legal help.

The duty to register and its exemptions are set by decisions of the Board and depend on your circumstances, so your lawyer gives the definitive answer. Registered or not, the KVKK obligations on notices, security and breach reporting still apply in full. Where registration is required, the inventory hands you the technical details it asks for: data categories, recipients and retention periods.

Yes. Anyone administering your systems remotely can see personal data, so Apply is normally your processor. Either side's template can serve as the base; it sets out what we may access, which sub-processors are involved, security measures and how fast Apply informs you about an incident. Because Apply LLP is incorporated outside Turkey, the agreement also deals with the cross-border element; your lawyer chooses the mechanism.

Storing data outside Turkey, or accessing it from there, generally falls under the transfer rules. Picking the route, for instance standard contractual clauses and notifying the Authority about them, is a legal call for your lawyer. Our contribution is concrete: a list showing which service holds which data in which country, which sub-processors the provider relies on, and what moving it to another region would involve.

Email support@apply.tr immediately; contract clients use helpme@apply.tr. On the technical side we can try to pull the message back, cancel any shared links, freeze the mailbox where sensible and reconstruct from audit logs exactly which recipient opened which item at what time. The controller and its lawyer then decide on notifying the Board and the individuals concerned, working from evidence rather than assumptions.

Ideally with a procedure written long before the request lands. It lists every place to search, from the accounting package and customer database to mailboxes, the storefront, marketplace seller panels, mailing lists and backup sets, names the person responsible and says how completion is documented. Invoices and anything else you must legally retain are put beyond everyday reach instead of being wiped, with your lawyer and accountant confirming the specifics. We draft the procedure and try it out on an invented case.

Seldom, at least to begin with. If your company subscribes to the Business Premium tier of Microsoft's suite, device management, sign-in conditions, labelling and leak prevention are included in the licence, yet they often sit unused. The review is charged at €55 per hour plus VAT against a scope fixed in advance, or it runs as part of your Start, Business or Premium plan. Whenever we do recommend buying something, the recommendation points back to a concrete gap we found.

Let us check how KVKK looks inside your systems

Tell us what personal data you handle, which programs hold it and who is responsible for the topic today. We will reply with a review proposal and a short list of questions worth settling with your lawyer first.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.