Building a demonstrable system that assures the company operates in line with the law, data protection rules and its own ethical principles.
A compliance program isn't a file signed to avoid a fine — it's the company writing down in advance how it will manage each risk. When an audit arrives, the first question isn't 'what did you do about this,' it's 'can you document it.'
Under Turkish data protection law, the obligation has three stages: knowing where and why personal data is held (inventory), informing the data subject (privacy notice), and protecting the data with technical and administrative measures. In the event of a data breach, there's a 72-hour window to notify the Board.
SBP Legal builds data-protection compliance and the company's ethics infrastructure as a single program, then keeps it alive through periodic audits.
What we do in this area
Data protection compliance program
Building a data inventory, tying processing purposes to lawful grounds, and preparing a retention and destruction policy.
Document and record set
Privacy notices, explicit consent forms, cookie policy, VERBİS registration and data-processor agreements.
Data breach response
Managing the 72-hour notification process after a breach is detected, notifying affected individuals, and handling correspondence with the Board.
Cross-border data transfer
Assessing standard contractual clauses, binding corporate rules and undertaking letters; compliance for cloud services.
Code of ethics and whistleblowing
Codes of conduct, conflict-of-interest policy, gift and hospitality limits, and setting up a whistleblower hotline.
Anti-bribery and anti-corruption
Third-party due diligence, supplier compliance undertakings and internal investigation management.
Does this page speak to your situation?
If any of the following applies to you, now is the time to talk:
- You've received a letter or complaint notice from the Turkish Data Protection Board.
- You suspect a data leak has occurred at your company.
- You share employee data with a group company abroad.
- A corporate client has asked you for a compliance policy and code of ethics.
Frequently asked questions
I run a small company — does data protection law still apply to me?
Yes. The obligation depends on whether you process personal data, not on company size. If you have an employee, a customer, or a website visitor, you're processing personal data. VERBİS registration thresholds are based on staff numbers and financial statements, but falling below that threshold doesn't remove the other obligations.
Are a privacy notice and explicit consent the same thing?
No, and the distinction is critical. A privacy notice is a one-way disclosure explaining why data is processed, and it's always required. Explicit consent is only obtained when no other lawful ground exists — such as a contract, a legal obligation, or legitimate interest. Trying to get consent for everything is a common mistake; because consent can be withdrawn at any time, it makes the company more fragile, not less.
How quickly must I report a data breach?
The data controller must notify the Turkish Data Protection Board without delay and no later than 72 hours after becoming aware of the breach. Affected individuals must also be informed as soon as reasonably possible. That's why a breach-response plan needs to be ready before an incident happens, not after.
This page was last updated on 20.07.2026. Content is for general informational purposes and does not substitute for legal advice.