Cybersecurity

KVKK Technical Measures: Putting Them into Practice on Your IT Infrastructure

KVKK compliance does not end with a folder of policy documents. If the policy says access is limited by role, Active Directory has to say the same. That is the side of the work we take on: making sure the technical measures are actually in place on your infrastructure.

CybUP TeamLast updated: 7 min read

In short

KVKK technical measures are the safeguards an organisation builds into its IT infrastructure under Article 12 of KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698), to prevent unlawful processing of and access to personal data and to keep it safe: access control, logging, firewalls, encryption, backup and vulnerability management. CybUp implements and documents these measures; it does not give legal advice.

What are KVKK technical measures?

KVKK technical measures are the technological safeguards applied to systems that process personal data, to prevent unauthorised access, data loss and unlawful processing. KVKK is Türkiye’s Personal Data Protection Law (Law No. 6698), and the legal basis is Article 12 of the Law: the data controller must take “all necessary technical and administrative measures to ensure an appropriate level of security” in order to prevent unlawful processing of and access to personal data and to keep it safe.

The Law does not list the measures one by one. The practical framework comes from the Personal Data Protection Authority’s Personal Data Security Guide (Technical and Administrative Measures), whose current edition is dated April 2025. The technical measures in the guide’s summary table are: an authorisation matrix, authorisation control, access logs, user account management, network security, application security, encryption, penetration testing, intrusion detection and prevention systems, log records, data masking, data loss prevention software, backup, firewalls, up-to-date antivirus, deletion, destruction or anonymisation, and key management.

“Veri sorumlusu; a) Kişisel verilerin hukuka aykırı olarak işlenmesini önlemek, b) Kişisel verilere hukuka aykırı olarak erişilmesini önlemek, c) Kişisel verilerin muhafazasını sağlamak, amacıyla uygun güvenlik düzeyini temin etmeye yönelik gerekli her türlü teknik ve idari tedbirleri almak zorundadır.”

The data controller shall take all necessary technical and administrative measures to ensure an appropriate level of security in order to: a) prevent the unlawful processing of personal data, b) prevent unlawful access to personal data, c) ensure the safekeeping of personal data.

— Law No. 6698 (KVKK), Article 12(1) — mevzuat.gov.tr

What does CybUp do in a KVKK compliance project, and what does it not do?

To be clear: we are not a law firm or a KVKK consultancy. The personal data inventory, privacy notices, explicit consent processes, registration with VERBİS (the Data Controllers’ Registry) and the retention and destruction policy are legal and administrative work. For those you need your lawyer or KVKK consultant.

Our job is to make what those documents say true in your infrastructure. When your consultant says only the accounts team should open the accounting folder, we build the permission group. When they say logs must be kept, we set up log collection. When they say backups must be kept off the network, we design the backup architecture. We are happy to work alongside your consultant.

Which IT tasks do the guide’s technical measures map to?

Most items in the guide are familiar IT tasks described in KVKK terms. The mapping below shows how each measure is put into practice in the infrastructure.

  • Firewalls and network security: firewall installation, rule clean-up and VLAN segmentation.
  • Authorisation matrix, authorisation control and user account management: Active Directory group structure, least privilege, and disabling the accounts of staff who leave.
  • Vulnerability management: regular vulnerability scanning; penetration testing is carried out by authorised firms.
  • Application security: a web application firewall and SSL/TLS configuration for web applications.
  • Backup: backup with Veeam, with off-network, immutable copies.
  • Log records and access logs: central collection and retention of firewall, server and file access logs.

What does the guide expect for logging and monitoring?

The guide asks organisations to check which software and services are running on their networks, to determine whether there has been an intrusion or any activity that should not be there, to keep regular records of all users’ actions through methods such as logs, and to report security problems quickly. It also lists regular checks of security software alerts and access records, and regular vulnerability scans and penetration tests against known vulnerabilities.

In practice, this means Windows event logs, file server access auditing, and firewall and VPN logs are collected in one place, kept for a set period and protected against tampering. Alerts are defined for critical events. When a breach is suspected, these logs are what let you answer “who opened which file, and when?”

That question may have to be answered against the clock. Under decision no. 2019/10 of the Personal Data Protection Board, a data controller must notify the Board without delay and within 72 hours at the latest of becoming aware of a breach. A company without logs will struggle to establish the scope of a breach in that time.

“İşlenen kişisel verilerin kanuni olmayan yollarla başkaları tarafından elde edilmesi hâlinde, veri sorumlusu bu durumu en kısa sürede ilgilisine ve Kurula bildirir.”

Where the processed personal data are obtained by others through unlawful means, the data controller shall notify the data subject and the Board of this as soon as possible.

— Law No. 6698 (KVKK), Article 12(5) — mevzuat.gov.tr

What does the guide say about backup and encryption?

The guide names ransomware explicitly. It asks that backed-up personal data be accessible only to the system administrator and that dataset backups always be kept outside the network. A backup on the same network, reachable with the same admin account, is not a backup as far as ransomware is concerned. That is why our backup designs use separate credentials, immutable storage and an off-network copy; we cover the details on our disaster recovery page.

On encryption, the guide recommends encrypting devices that hold personal data to protect against loss and theft, using internationally accepted methods. Typical work here includes full-disk encryption with BitLocker on laptops, storing recovery keys in Active Directory or Microsoft Entra ID, TLS on web forms, and two-factor authentication for data stored in the cloud.

Example scenario: a 40-person healthcare clinic

Say there is a clinic with two branches and 40 staff. Patient records sit in an application on one server and lab results on a file share. Everyone has full access to the same share, the guest Wi-Fi and the server are on the same network, the nightly backup goes to a USB disk plugged into that same server, and the branches are connected through port forwarding. Health data is special category personal data, which makes the picture more serious still.

In an environment like this, the technical measures become concrete steps: shares are reorganised with role-based permissions, the guest network and cameras move to a separate VLAN, an encrypted site-to-site VPN tunnel links the branches, port forwards are closed, the backup gains an off-network immutable copy, file access auditing is switched on and logs are stored centrally. Finally, every measure is documented in a form your consultant, and any future audit, can follow.

Why are email and endpoints in scope?

The guide separately stresses adequate measures when personal data is sent by email, and security controls for employees’ personal devices that connect to the company network. A spoofed From address used to ask for personal data or payment details is a common scenario here; protecting your domain with DMARC, SPF and DKIM reduces that risk considerably.

On endpoints, the basic measures are up-to-date antivirus, central patch management, removing local admin rights and restricting USB storage. The guide also notes that removing unused software and services may be preferable to keeping them updated, which is why trimming the software inventory is security work in its own right.

What you receive

  • Current-state assessment (gap analysis) against the technical measures in the guide
  • Prioritised technical improvement plan
  • Measures implemented: permission structure, segmentation, log collection, backup, encryption
  • Vulnerability scan and verification report
  • A technical measures document showing what was done for each measure
  • A summary table you can share with your legal or KVKK consultant

How we work

  1. 1

    Free initial call

    We talk about which systems process personal data and what your infrastructure looks like, review any documents your consultant has prepared and send a written quote.

  2. 2

    Gap analysis

    Your infrastructure is compared with the technical measures in the guide, and the gaps are listed in order of risk.

  3. 3

    Plan

    We agree which measure is applied in what order, in which maintenance window, and how it will affect day-to-day work.

  4. 4

    Implementation

    Permission changes, segmentation, log collection, backup and encryption work are carried out as planned.

  5. 5

    Documentation and follow-up

    Every measure is documented, and regular vulnerability scans and log checks keep it that way.

Frequently asked questions

Are technical measures enough for KVKK compliance?

No. The Law requires technical and administrative measures together. For administrative and legal work such as the data inventory, policies, contracts and privacy notices, you need a legal or KVKK consultant. We take on the technical side.

Do you give legal advice on KVKK?

No. We do not give legal opinions or prepare VERBİS registrations, privacy notices or consent forms. We implement and document the technical measures, and we can work alongside your consultant.

Does KVKK require penetration testing?

The Authority’s guide lists regular vulnerability scans and penetration tests against known vulnerabilities among the technical measures. We do vulnerability scanning; we do not carry out penetration tests, which are done by authorised firms.

How long should we keep logs?

The retention period depends on your sector and the other regulations you are subject to, so you should set it with your legal adviser. We build storage and protection that match the period you decide on.

We are a small company. Do these measures apply to us?

The obligation in the Law does not depend on company size; the scope of the measures scales with the nature of the data you process and the risk involved. In a small office, a properly configured firewall, sensible permission groups and an off-network backup cover most of the work.

How would you help if we had a data breach?

On the technical side we help establish the scope of the breach from the logs, cut off the attacker’s access and restore systems from backup. Notifying the Board and the legal process remain the responsibility of you and your legal adviser.

Do you work remotely or on site?

Most of the gap analysis and implementation is done over secure remote access anywhere in Türkiye. For work that involves installing physical equipment or cabling, we work on site in Istanbul.

How is pricing worked out?

It depends on the number of systems and branches, and on the gap between where you are now and where you need to be. Once the initial call has set the scope of the gap analysis, we send a written quote; the first review is free.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Cybersecurity

Services in this area

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.