KVKK (Turkish Personal Data Protection Law)
Definition
KVKK is Turkey's personal data protection law, Law No. 6698, the local counterpart of the EU's GDPR. It requires anyone processing personal data to inform people, obtain consent where needed, keep the data secure, and honour requests to access, correct, or delete it. An online store is a data controller for its customers, and its software provider is a data processor acting on the store's instructions.
Why it matters for your store
Every customer record, address, and order is personal data. KVKK makes the store responsible for it, with administrative fines for failures and a personal data authority that handles complaints. The obligations are concrete: tell people what you collect and why, keep marketing consent separate and unticked by default, protect the data, and answer access and deletion requests within the legal period.
The provider matters too. When your store runs on a platform, that platform processes the data for you, and the law expects a written agreement defining that relationship. Where the data is stored, who the sub-processors are, and what happens when you leave should all be answerable.
This page is general information, not legal advice.
How Kambloo handles it
Consent is collected with separate, unticked boxes at signup and checkout, and every consent is stored with the version of the text shown, a timestamp, and the IP address. Marketing consent is a separate record synchronised with İYS.
Each store's data lives in its own database, physically separate from every other store, which is the basis for both security and clean deletion. A customer's data can be exported on request, and a deletion request anonymises their personal fields while keeping order records in anonymised form for the tax retention period. Deleting a store drops its entire database and purges its files, after a 30-day cooling period.
The data processing agreement with Partnerfy.co, Kambloo's operator, is accepted as a step in the go-live wizard. Data is hosted in the Turkey/EU region, the sub-processor list (Cloudflare, payment providers, email provider) is published, and the incident runbook covers the 72-hour breach notification window.
Questions about KVKK (Turkish Personal Data Protection Law)
What does KVKK require from an online store in practice?
A privacy notice (aydınlatma metni) shown before data is collected, separate consent for marketing, secure storage, a way for customers to request their data or its deletion, and a data processing agreement with any provider that handles the data for you.
Can I delete a customer's data if they ask?
Personal fields, yes. Order and invoice records must be kept for the retention period tax law requires, so they are anonymised rather than deleted: the order stays, the person is removed from it.