Get a Quote +90 533 897 82 11
KVKK & Siber Güvenlik 8 August 2026 · 5 min read

Responsibility for Technical and Administrative Measures

How responsibility is allocated in the authority's recent compliance guidance, and what follows.

Data protection Compliance Responsibility Security

One emphasis stands out in the compliance guidance published by Turkey's data protection authority: in a breach, responsibility falls not only on whoever acted but on whoever failed to take the necessary measures.

01. Where Responsibility Sits

The data controller is the organisation itself, not a department or an employee. An employee's mistake doesn't relieve the organisation; instead the question becomes whether the necessary technical and administrative measures were in place.

02. A Protocol Alone Isn't Enough

Data sharing protocols between institutions do not on their own constitute a legal basis. The statutory ground for sharing has to be shown separately. This is a frequent gap in supplier and partner agreements.

03. The Measures List

Access authorisation, logging, encryption, backup, security awareness training and an incident response plan. Their existence matters, and so does a record showing they are operated regularly.

04. A Culture of Evidence

An inspection asks not for the practice but for its record. If the annual permission review happened, there should be minutes; if training was delivered, an attendance list. Good practice without records is treated as absent.

05. The Supplier Chain

Suppliers acting as data processors must be shown to apply the same measures. Writing an audit right into the contract and exercising it at least annually is the expected behaviour.

06. Where to Start

A data inventory, a permission matrix and a retention period table. Without those three documents, every other measure hangs in the air.

KVKK & Siber Güvenlik articles

Other Articles on This Topic

KVKK & Siber Güvenlik

Data Protection Compliance in Enterprise Software

25 June 2026 · 6 min read
KVKK & Siber Güvenlik

The ISO 27001 Certification Process

24 June 2026 · 5 min read
All articles