A comprehensive examination of the regime for the cross-border transfer of personal data under Article 9 of the Turkish Data Protection Law as amended by Law No. 7499. The three-tier structure of adequacy decisions, appropriate safeguards and occasional cases, the four modules of standard contracts, the five-business-day notification obligation, binding corporate rules, the undertaking, comparison with the GDPR and administrative fines are addressed.
The cross-border transfer of personal data is one of the most frequently encountered compliance problems of an increasingly digital and globalised commercial life. The use of a cloud server located abroad, the sharing of human resources data within a multinational group of companies, or benefiting from the services of a software provider abroad all constitute, in legal terms, a transfer of personal data abroad. In this field, Turkish law has undergone a fundamental change through Law No. 7499. The amendment to Article 9 of the Data Protection Law, which entered into force on 1 June 2024, abandoned the previous rigid structure centred on explicit consent and introduced a graduated and more flexible system compatible with the European Union General Data Protection Regulation. This article comprehensively examines the new regime for cross-border data transfers, its three-tier structure, standard contracts, notification obligations and practical compliance steps.
1. The Importance of Cross-Border Transfer and the Position Before the Reform
Before the reform, Article 9 of the Law subjected the transfer of personal data abroad to rather strict conditions. As a rule, data could not be transferred abroad without the explicit consent of the data subject. Where there was no explicit consent, a transfer could only be made to countries with adequate protection, or was possible where the data controllers gave a written undertaking and the permission of the Board was obtained. However, the fact that the Board never announced any list of countries with adequate protection led to the system becoming locked, in practice, around explicit consent. This situation made continuous commercial data transfers dependent on explicit consent, and since explicit consent is always revocable, it created serious legal uncertainty for companies. This impasse in practice gave rise to the need to restructure the system by bringing it closer to the European Union model.
2. The Reform Introduced by Law No. 7499 and the Three-Tier System
By Article 34 of Law No. 7499, published in the Official Gazette of 12 March 2024, Article 9 of the Data Protection Law was reorganised, and the amendment entered into force on 1 June 2024. Following this, by decision of the Personal Data Protection Board No. 2024/959 of 4 June 2024, the standard contract texts and the documents relating to binding corporate rules were adopted, and the details of the implementation were determined by the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, published in the Official Gazette of 10 July 2024. The new system was established on the basis of the relevant provisions of the European Union General Data Protection Regulation and provides for a three-tier structure. Accordingly, in order for a transfer to be lawful, there must first be one of the general processing conditions set out in Articles 5 and 6 of the Law, followed by one of the following three options in turn. At the first tier, it is examined whether an adequacy decision exists. If there is no adequacy decision, at the second tier it is assessed whether one of the appropriate safeguards can be provided. If an appropriate safeguard cannot be provided either, at the third tier the existence of occasional cases is sought. This graduated structure requires the legal basis on which the transfer rests to be carefully determined in each concrete case.
3. The First Tier: The Existence of an Adequacy Decision
The first and strongest basis for transfer under the new system is the adequacy decision. An adequacy decision is a decision rendered by the Board concerning a country, sectors within that country or international organisations, determining that the country or organisation in question provides an adequate level of protection. An important innovation introduced by the reform is that the adequacy decision no longer has to relate to the whole of a country. As stated in the preamble to the Law, an adequacy decision may also be rendered in respect of a particular sector within a country, for example the automotive or finance sector of a particular country, rather than the country as a whole. Moreover, it is also possible to obtain an adequacy decision in respect of international organisations. Where an adequacy decision exists, the transfer may be carried out without the need for any additional safeguard or permission. Adequacy decisions are reviewed by the Board at least once every two years and may be amended or revoked where necessary. In practice, the first check to be made before a transfer is to investigate whether there is a current adequacy decision concerning the country or organisation to which the transfer is to be made.
4. The Second Tier: Appropriate Safeguards
If there is no adequacy decision concerning the country, sector or organisation to which the transfer is to be made, one proceeds to the second tier and assesses whether one of the appropriate safeguards can be provided. An important common condition at this tier is that the data subject must have the possibility of exercising their rights and of having recourse to effective legal remedies in the country to which the transfer is made. The Law provides for four ways of providing an appropriate safeguard. These are the existence of an agreement, not of the nature of an international treaty, between public institutions or international organisations abroad and public institutions or professional organisations having the status of a public institution in Türkiye, together with the permission of the Board; binding corporate rules; standard contracts announced by the Board; and a written undertaking together with the permission of the Board. Among these four ways, the most practical and most frequently used method is standard contracts, since some of the other methods, being subject to the permission of the Board, require a longer process. The choice of the appropriate safeguard method must be made according to the parties and the nature of the transfer.
5. Standard Contracts and the Four Modules
Standard contracts are template contracts announced by the Board whose content is predetermined. The most important advantage of these contracts is that, where they are used, there is no need to obtain any separate permission from the Board. Standard contracts are drawn up in four different modules according to the legal capacity of the parties to the transfer. The first module concerns transfers made from a data controller to a data controller; for example, a company in Türkiye sending customer data to a business partner abroad that is able to take independent decisions falls within this scope. The second module regulates transfers made from a data controller to a data processor and is the most common scenario in practice; a company in Türkiye storing its data on a cloud server abroad is an example. The third module concerns transfers made from a data processor to a data processor, and the fourth module concerns transfers made from a data processor to a data controller. The selection of the correct module is of critical importance, since the choice of the wrong module may render the contract invalid. For this reason, the correct identification of whether the parties are data controllers or data processors in respect of the activity subject to the transfer is the most important step of the process. In standard contracts, only clauses granting an optional right may be amended; revision of the body of the text is not possible. The details of the transfer are set out in the annexes, which form an integral part of the contract.
6. The Notification Obligation for the Standard Contract and the Five-Business-Day Rule
One of the most striking procedural innovations introduced by the reform is the notification obligation concerning the standard contract. In transfers made using a standard contract, the signed contract must be notified to the Board by the data controller or data processor within five business days of the date of signature. This notification does not mean that the transfer is subject to prior permission; the standard contract in itself provides an appropriate safeguard, and the transfer may be carried out independently of the notification. However, the failure to fulfil the notification obligation within the time limit constitutes in itself a misdemeanour and is subject to an administrative fine. For this reason, companies that sign a standard contract must carefully monitor the five-business-day period and incorporate the notification process into their internal compliance procedures. The details concerning the procedure for notification have been regulated by the Regulation, and it is expected to be made through the channels provided by the Authority.
7. Binding Corporate Rules
Binding corporate rules are an appropriate safeguard method designed specifically for multinational groups of companies. They are a set of binding rules, prepared by companies within the same group engaged in a joint economic activity for intra-group transfers of data abroad and approved by the Board. This method is particularly suitable for holdings and multinational companies that have subsidiaries in a large number of countries and where there is a continuous flow of data within the group. For binding corporate rules to enter into force, the approval of the Board is required; for this reason they require a longer and more comprehensive preparation process compared to standard contracts. The Board has published application forms and auxiliary guides concerning the essential matters that must be contained in binding corporate rules. For structures that carry out intra-group data transfers systematically and continuously, although the initial preparation burden is heavy, binding corporate rules offer the most stable solution in the long term.
8. The Undertaking and the Permission of the Board
Another way of providing an appropriate safeguard is for the data exporter and the recipient abroad to undertake in writing to provide adequate protection, and for this undertaking to be permitted by the Board. Although the undertaking method is a mechanism known from the pre-reform system, it has retained its place as an option among the appropriate safeguards in the new system. The most distinctive feature of this method is that it is subject to the separate permission of the Board for each concrete transfer. This makes the undertaking method slower and, in terms of administrative process, more burdensome compared to standard contracts. For this reason the undertaking stands out as a method preferred where the standard contract modules are not suitable, or where the concrete transfer carries its own particular circumstances. The content of the undertaking must be drawn up in such a way as to legally guarantee that protection equivalent to that of the Law will be provided to the transferred data abroad as well.
9. Agreement Not of the Nature of an International Treaty
Another of the appropriate safeguard methods is the existence of an agreement, not of the nature of an international treaty, between public institutions or international organisations abroad and public institutions or professional organisations having the status of a public institution in Türkiye, together with permission for the transfer being granted by the Board. By its nature, this method finds application in respect of public institutions and professional organisations having the status of a public institution. Although it is not a route to which private sector actors may resort directly, it is significant in data transfers connected with the public sector. In transfers made on the basis of such agreements, the condition of the permission of the Board is also sought. Accordingly, this method has a limited scope of application peculiar to data transfers originating from and directed at the public sector.
10. The Third Tier: Occasional Cases
Where there is no adequacy decision and none of the appropriate safeguards can be provided, occasional cases may be resorted to as a last resort. However, the word occasional must be underlined with care. Occasional cases are valid only for transfers that are not continuous, that are one-off or that occur infrequently. Transfers that are continuous, that recur, or that have become an ordinary part of the workflow are not deemed occasional and cannot be based on these exceptions. Among the occasional cases enumerated in a limited manner in the Law are the following. The data subject giving explicit consent to the transfer, the transfer being necessary for the performance of a contract or for the implementation of pre-contractual measures, the existence of an overriding public interest, the transfer being necessary for the establishment, exercise or protection of a right, the protection of the life or physical integrity of a person who is unable to give consent owing to actual impossibility, and transfers made from registers open to the public fall within this scope. For example, the sharing of the health data of an employee who has had an accident abroad with a hospital there, or the sharing of data in order to submit evidence in an action brought abroad, may be given as examples of occasional cases. The narrow interpretation of these exceptions is essential.
11. Comparison with and Harmonisation to the GDPR
The new system has to a large extent taken as its model the cross-border transfer architecture of the European Union General Data Protection Regulation. The adequacy decision, standard contractual clauses and binding corporate rules mechanisms in the Regulation are reflected in the new Article 9 of the Data Protection Law in a similar manner. This harmonisation provides an important convenience for companies conducting data flows between Türkiye and the European Union, since the use of similar instruments on both sides simplifies compliance processes. Nevertheless, there are also differences between the two systems. The obligation in the Turkish system to notify the standard contract to the Board within five business days is a procedural requirement not found in the Regulation. There are also differences in terms of the scope of adequacy decisions, the enumeration of occasional cases and the structure of administrative sanctions. In transfers made from the European Union to Türkiye, on the other hand, the standard contractual clauses of the Regulation come into play. For this reason, companies conducting two-way data flows must assess both regimes together.
12. The Transfer of Special Categories of Personal Data
Special categories of personal data are sensitive data such as data relating to health, sexual life, race, ethnic origin, political opinion, philosophical belief, religion, sect, association and trade union membership, biometric and genetic data, and data relating to criminal convictions and security measures. The new three-tier structure applies to the transfer of these data abroad as well; however, additional measures must be taken for special categories of data. Standard contracts contain special provisions concerning the additional technical and administrative measures to be taken in respect of special categories of personal data. As regards the processing and transfer of these data, the Law applies a stricter protection regime compared to general personal data. Law No. 7499 also reorganised the conditions for the processing of special categories of personal data and enumerated in an expanded manner the cases in which such data may be processed. Companies transferring special categories of data abroad must carefully implement the additional measures at the level of the contract annexes and the technical infrastructure.
13. Administrative Fines and Sanctions
Non-compliance with the rules on the cross-border transfer of data is subject to serious administrative sanctions. Law No. 7499 provides for a specific misdemeanour in respect of data controllers and data processors who fail to notify the standard contract to the Board within five business days of its signature; an administrative fine of between fifty thousand Turkish liras and one million Turkish liras applies to this misdemeanour. In addition, the unlawful transfer of data abroad, that is, without any basis for transfer, is assessed within the scope of the general sanction provisions of the Law concerning the unlawful processing of personal data and may give rise to more serious consequences. An important procedural change introduced by the reform is that the administrative courts are now competent in respect of administrative fines imposed by the Board. Whereas under the previous system the criminal judgeships of the peace were competent in respect of these fines, the administrative judicial route has been adopted by the new regulation. This change is intended to allow the expertise of the administrative judiciary to be drawn upon in the review of administrative fines.
14. Practical Compliance Steps
Companies transferring data abroad must follow a systematic course in order to comply with the new regime. The first step is to draw up an inventory of all the cross-border data transfers the company carries out; it must be determined which data is transferred, for what purpose, and to which recipient in which country. At the second step, the three-tier structure is applied in turn for each transfer, and first an adequacy decision, failing that an appropriate safeguard, and failing that an occasional case is assessed. At the third step, if a standard contract is to be used as an appropriate safeguard, the correct module must be selected and it must be correctly determined whether the parties are data controllers or data processors. At the fourth step, the annexes of the standard contract are prepared carefully and the five-business-day notification period following signature is entered in the calendar. At the fifth step, it is assessed whether it would be appropriate to prepare binding corporate rules for continuous intra-group transfers. Finally, the privacy notices, the data processing inventory and the retention policies are updated in accordance with the new regime. Committing these steps to a written compliance procedure both reduces the legal risk and enables the company to document its compliance effort in the event of an audit.
15. Conclusion and Recommendations
The new cross-border transfer regime introduced by Law No. 7499 has replaced the previous explicit-consent-centred and, in practice, locked system with a structure close to the European Union model, graduated and workable. The practical considerations to be observed in this field are as follows. The three-tier structure must be applied in turn before each transfer, and the legal basis of the transfer must be clearly determined. If a standard contract is used, the correct module must be selected, the capacity of the parties correctly determined and the annexes drawn up without omission. The five-business-day notification period for the standard contract must never be neglected, since a breach of this obligation gives rise in itself to an administrative fine. Binding corporate rules must be assessed for continuous intra-group transfers, and it must not be forgotten that continuous transfers cannot be based on occasional cases. Additional measures must be taken for special categories of data, and privacy notices and the data inventory must be updated in accordance with the new regime. A properly structured cross-border transfer compliance both reduces the company's legal risk and enables it to maintain its global commercial relations without interruption.
For support on the cross-border transfer of personal data, the preparation and notification of standard contracts to the Board, the establishment of binding corporate rules, DPL and GDPR compliance processes and data protection advisory services, you may contact us at info@guzeloglu.legal.