Turkey's data-protection law (KVKK) is the country's basic law on the processing and storage of personal data. Every institution using cloud services must be compliant with it. A local cloud makes this compliance easier.
01. Data Controller and Data Processor
There are two basic roles: the Data Controller (who makes the decision) and the Data Processor (who processes on their behalf). The cloud provider is usually in the data-processor position. The contract should clarify this.
02. Data Residency
The law doesn't say data can't be transferred outside Turkey, but it requires explicit consent or an undertaking. Using a local cloud makes this step unnecessary.
03. Disclosure Obligation
The data subject must be informed when personal data is collected. If you send data to the cloud, where it's processed and stored is stated in the privacy notice.
04. The Right to Erasure
The data subject has the "forget me" right. Your cloud infrastructure must be able to technically support this deletion request; data must be deletable from backups too.
05. The Right to Audit
The law upholds the data controller's right to audit the data processor. This right must be explicitly stated in the contract; it's easier to apply with a local provider.