# KVKK Compliance for HR Software: What Foreign Companies Operating in Turkey Need to Know

- [What Is KVKK and How Does It Compare to GDPR?](#what-is-kvkk-and-how-does-it-compare-to-gdpr)
- [VERBIS Registration: Who Must Register and When](#verbis-registration-who-must-register-and-when)
- [What Counts as Personal Data in an HR Context](#what-counts-as-personal-data-in-an-hr-context)
- [The 2026 Enforcement Context: Stricter, Not Softer](#the-2026-enforcement-context-stricter-not-softer)
- [What to Look for in HR Software from a KVKK Compliance Standpoint](#what-to-look-for-in-hr-software-from-a-kvkk-compliance-standpoint)
- [Data Hosting and Localization](#data-hosting-and-localization)
- [Consent Management](#consent-management)
- [Data Minimization](#data-minimization)
- [Access Controls and Role-Based Permissions](#access-controls-and-role-based-permissions)
- [Retention and Erasure Capabilities](#retention-and-erasure-capabilities)
- [Data Processor Agreements](#data-processor-agreements)
- [Breach Notification Support](#breach-notification-support)
- [How HR&Tomorrow Approaches KVKK Compliance](#how-hrtomorrow-approaches-kvkk-compliance)
- [Frequently Asked Questions](#frequently-asked-questions)
- [Take the Compliance Risk Seriously](#take-the-compliance-risk-seriously)
If your company operates in Turkey and processes employee data, Turkish data protection law applies to you — full stop. It doesn't matter whether your headquarters are in Frankfurt, Dubai, or New York. If you have staff in Turkey, you are a data controller under KVKK, and the compliance obligations that come with that status are real, enforceable, and under closer scrutiny than ever in 2026.
This article covers what KVKK requires, where HR software fits into that picture, and what to look for when choosing a platform that keeps you on the right side of Turkish data protection law.
---
## What Is KVKK and How Does It Compare to GDPR?
KVKK — Kişisel Verilerin Korunması Kanunu, Law No. 6698 — is Turkey's personal data protection law, in force since 2016. It was modeled partly on the EU's pre-GDPR framework and shares a recognizable structure: lawful basis for processing, data subject rights, controller and processor obligations, and a supervisory authority (the Personal Data Protection Authority, or KVKK Kurumu).
But the differences matter, especially for foreign companies. Unlike GDPR, KVKK has no lead supervisory authority mechanism. There's no one-stop-shop concept. If you process data in Turkey, Turkish rules apply directly — regardless of where your European DPO is based. Cross-border data transfers require either the recipient country to appear on Turkey's approved list or the parties to execute a binding undertaking approved by the Authority. EU standard contractual clauses don't automatically satisfy Turkish requirements.
KVKK also places particular emphasis on explicit consent for sensitive data categories, including biometric data. That distinction becomes directly relevant for any HR team running attendance systems.
---
## VERBIS Registration: Who Must Register and When
VERBIS (Veri Sorumluları Sicil Bilgi Sistemi) is Turkey's data controller registry, maintained by the Personal Data Protection Authority. Foreign companies that process personal data of individuals in Turkey are required to register if they meet the threshold criteria — and most companies with Turkish operations do.
The general rule: legal entities processing personal data must register before processing begins. For foreign-headquartered companies, this means registering through your Turkish legal entity or representative. Registration requires you to document each processing activity — the categories of data involved, the purposes, retention periods, and whether data is transferred abroad.
Non-registration is a direct violation. Fines for failing to register have increased significantly under the 2026 enforcement cycle, and the Authority has made clear that multinationals are not exempt simply because their data infrastructure sits outside Turkey.
---
## What Counts as Personal Data in an HR Context
Under KVKK, personal data is any information relating to an identified or identifiable natural person. In an HR context, that covers a wide range of everyday data:
- **Payroll data:** salary, bank account details, tax identification numbers, social security numbers, deductions
- **Attendance records:** clock-in/clock-out times, absence records, overtime logs
- **Biometric data:** fingerprint scans, facial recognition data used for attendance tracking
- **Performance records:** appraisal scores, manager feedback, disciplinary notes
- **Health data:** sick leave documentation, disability accommodations
- **Contact and identity data:** national ID numbers, home addresses, emergency contacts
Biometric and health data fall into KVKK's sensitive data category, which requires explicit written consent from the employee and, in some cases, additional safeguards. This isn't a technicality. Processing sensitive data without a valid legal basis is one of the most common violations the Authority investigates.
---
## The 2026 Enforcement Context: Stricter, Not Softer
Enforcement under KVKK has hardened noticeably heading into 2026. The Authority has issued larger fines, conducted more proactive audits, and published sector-specific guidance that signals it is no longer treating non-compliance as a minor administrative matter.
One development HR and operations teams need to know about specifically is İlke Kararı 2026/921, which restricts the use of biometric data for employee attendance tracking. Under this principle decision, employers cannot rely on a general employment contract or workplace policy to justify fingerprint or facial recognition-based attendance systems. Processing biometric attendance data now requires explicit, freely given consent from each employee, a documented legitimate purpose that cannot be achieved by less intrusive means, and appropriate technical and organizational safeguards.
For companies running PDKS (personnel attendance tracking) systems that use biometric inputs, this is not a future concern. It is a present compliance requirement. If your current HR software or attendance system collects biometric data without meeting these conditions, you are already exposed.
---
## What to Look for in HR Software from a KVKK Compliance Standpoint
Choosing HR software isn't just a feature evaluation. For companies operating in Turkey, it's also a compliance decision. Here's a practical checklist:
### Data Hosting and Localization
Where is your employee data stored? Turkey doesn't yet have a blanket data localization law, but cross-border transfers require a legal basis. Software hosted on Turkish servers or within a compliant data residency arrangement removes a layer of transfer risk. Ask vendors explicitly where data is stored and whether they can provide documentation.
### Consent Management
Your HR platform should support capturing, recording, and managing employee consent for data processing activities — particularly for sensitive data categories. Consent records need to be timestamped, attributable to the specific individual, and withdrawable. A system that can't demonstrate consent history is a liability in an audit.
### Data Minimization
KVKK requires that you collect only what is necessary for a stated purpose. HR software that captures broad data sets by default, with no way to configure what's collected, makes data minimization harder to demonstrate. Look for platforms that let you control which data fields are active.
### Access Controls and Role-Based Permissions
Employee data should be accessible only to those who need it for their role. Payroll data shouldn't be visible to line managers. Health information shouldn't appear in a general employee profile. Strong role-based access controls aren't just good practice — they're part of demonstrating appropriate technical measures under KVKK.
### Retention and Erasure Capabilities
KVKK requires that personal data be deleted, destroyed, or anonymized when the purpose for processing no longer exists. Your HR software needs to support configurable retention periods and documented deletion workflows. This matters especially for data belonging to former employees.
### Data Processor Agreements
If your HR software vendor processes data on your behalf, they are a data processor under KVKK. You need a written data processing agreement that meets the Authority's requirements. Vendors who can't provide this — or treat it as an afterthought — represent a compliance gap.
### Breach Notification Support
KVKK requires notification to the Authority within 72 hours of becoming aware of a personal data breach. Your HR software should support audit logs, access history, and incident documentation that make breach detection and reporting manageable rather than chaotic.
---
## How HR&Tomorrow Approaches KVKK Compliance
[HR&Tomorrow](https://hrandtomorrow.com) is built for the Turkish market. KVKK compliance isn't a feature that was added later — the platform's payroll, attendance, and personnel record modules were designed with Turkish data protection requirements as a baseline from the start.
In practice, that means data hosting aligned with Turkish regulatory expectations, configurable access controls across all modules, consent logging within employee records, and retention management built into the system rather than left to manual processes. The attendance module is designed to handle the biometric data restrictions under İlke Kararı 2026/921, giving HR teams the ability to document consent and configure data collection appropriately rather than defaulting to broad data capture.
For foreign companies evaluating HR software for their Turkish operations, the question isn't just whether a platform has KVKK compliance on its feature list. It's whether the platform was built with Turkish legal requirements in mind from the beginning. That distinction matters when the Authority asks questions.
---
## Frequently Asked Questions
**What is KVKK?**
KVKK (Law No. 6698) is Turkey's personal data protection law. It governs how personal data is collected, processed, stored, and transferred, and it applies to any organization that processes data belonging to individuals in Turkey — regardless of where that organization is headquartered.
**Do foreign companies need to register with VERBIS?**
Yes. Foreign companies with Turkish legal entities or representatives that process personal data in Turkey are required to register with VERBIS, Turkey's data controller registry, before processing begins. Non-registration is a direct violation subject to administrative fines.
**What employee data is covered under KVKK?**
Any data that can identify an employee falls under KVKK. This includes payroll information, attendance records, performance evaluations, contact details, and national identification numbers. Biometric data (fingerprints, facial recognition) and health data are classified as sensitive and require explicit consent.
**Can HR software use biometric attendance data under KVKK?**
Yes, but with significant restrictions. İlke Kararı 2026/921 requires explicit, freely given consent from each employee, a documented legitimate purpose, and appropriate safeguards. Employers cannot rely on a general employment contract to justify biometric attendance tracking.
**How does KVKK differ from GDPR for HR purposes?**
The core principles are similar, but KVKK has no lead supervisory authority mechanism — Turkish rules apply directly regardless of where your EU operations are based. Cross-border data transfers also require separate Turkish legal bases and cannot rely solely on EU standard contractual clauses.
**What happens if an HR software vendor processes our employee data without a proper agreement?**
Under KVKK, you remain responsible as the data controller. Processing employee data through a vendor without a compliant data processing agreement exposes you to regulatory action, including fines and potential suspension of processing activities.
**What should we prioritize when evaluating HR software for KVKK compliance?**
Focus on data hosting location, consent management capabilities, access controls, configurable retention and deletion workflows, and whether the vendor can provide a compliant data processing agreement. These are the areas the Authority examines most closely during audits.
---
## Take the Compliance Risk Seriously
KVKK enforcement in 2026 is not theoretical. Foreign companies with Turkish operations are on the Authority's radar, and HR data is one of the most data-intensive areas any employer manages. Payroll records, attendance data, performance files, and potentially biometric inputs — your HR software is directly in scope.
If you're evaluating platforms for your Turkish HR operations and want to see how a Turkey-native system handles these requirements in practice, request a demo at [hrandtomorrow.com](https://hrandtomorrow.com).
HR&Tomorrow Mobil Uygulamasını
Hemen Kullanmaya Başlayın
7/24 destek ekibimiz her sorunuzu yanıtlar. Ayrıca kurulumdan sonra da yanınızda olmaya devam ederiz.