Practice area

Compliance, Ethics and Data Protection

Building a demonstrable system that assures the company operates in line with the law, data protection rules and its own ethical principles.

What does this mean, in short?

Building a demonstrable system that assures the company operates in line with the law, data protection rules and its own ethical principles.

A compliance program isn't a file signed to avoid a fine — it's the company writing down in advance how it will manage each risk. When an audit arrives, the first question isn't 'what did you do about this,' it's 'can you document it.'

Under Turkish data protection law, the obligation has three stages: knowing where and why personal data is held (inventory), informing the data subject (privacy notice), and protecting the data with technical and administrative measures. In the event of a data breach, there's a 72-hour window to notify the Board.

SBP Legal builds data-protection compliance and the company's ethics infrastructure as a single program, then keeps it alive through periodic audits.

What we do in this area

Data protection compliance program

Building a data inventory, tying processing purposes to lawful grounds, and preparing a retention and destruction policy.

Document and record set

Privacy notices, explicit consent forms, cookie policy, VERBİS registration and data-processor agreements.

Data breach response

Managing the 72-hour notification process after a breach is detected, notifying affected individuals, and handling correspondence with the Board.

Cross-border data transfer

Assessing standard contractual clauses, binding corporate rules and undertaking letters; compliance for cloud services.

Code of ethics and whistleblowing

Codes of conduct, conflict-of-interest policy, gift and hospitality limits, and setting up a whistleblower hotline.

Anti-bribery and anti-corruption

Third-party due diligence, supplier compliance undertakings and internal investigation management.

Does this page speak to your situation?

If any of the following applies to you, now is the time to talk:

  • You've received a letter or complaint notice from the Turkish Data Protection Board.
  • You suspect a data leak has occurred at your company.
  • You share employee data with a group company abroad.
  • A corporate client has asked you for a compliance policy and code of ethics.

Frequently asked questions

I run a small company — does data protection law still apply to me?

Yes. The obligation depends on whether you process personal data, not on company size. If you have an employee, a customer, or a website visitor, you're processing personal data. VERBİS registration thresholds are based on staff numbers and financial statements, but falling below that threshold doesn't remove the other obligations.

Are a privacy notice and explicit consent the same thing?

No, and the distinction is critical. A privacy notice is a one-way disclosure explaining why data is processed, and it's always required. Explicit consent is only obtained when no other lawful ground exists — such as a contract, a legal obligation, or legitimate interest. Trying to get consent for everything is a common mistake; because consent can be withdrawn at any time, it makes the company more fragile, not less.

How quickly must I report a data breach?

The data controller must notify the Turkish Data Protection Board without delay and no later than 72 hours after becoming aware of the breach. Affected individuals must also be informed as soon as reasonably possible. That's why a breach-response plan needs to be ready before an incident happens, not after.

This page was last updated on 20.07.2026. Content is for general informational purposes and does not substitute for legal advice.

Every sentence has a consequence. Whoever writes the contract writes the outcome.

Compliance, Ethics and Data Protection

Other areas

Other topics you might look at

Corporate Law

The area of law that governs a company from formation to dissolution — ownership structure, capital, general assembly, share transfers — at every step along the way.

Learn more

Mergers and Acquisitions (M&A)

The end-to-end legal management of buying, selling, or merging all or part of a company with another.

Learn more

Corporate Governance and Restructuring

Building the order that defines who decides what within a company, who answers to whom, and how group companies connect to one another.

Learn more

Commercial Contracts and International Trade Law

Putting every relationship that earns your business money — sales, supply, distribution, exports — on a written, enforceable footing.

Learn more

Energy Law

The field governing the licensing, permitting and contractual dimensions of electricity generation, renewable energy investment and energy trading.

Learn more

Healthcare Law

The field covering licensing, patient rights, physician liability and advertising rules for hospitals, clinics and health technology companies.

Learn more
Call Now WhatsApp