GDPR compliance and international data transfers across the EU, Türkiye and the Gulf
GDPR programmes for European entities — and, less commonly available, the ability to handle the Turkish, UAE and Qatari side of the same data flows. We cover both the legal and the technical requirement, which is where most single-discipline advisers stop short.
What does GDPR compliance involve?
The General Data Protection Regulation — Regulation (EU) 2016/679 — requires controllers and processors to process personal data lawfully and to be able to demonstrate it. In practice that means records of processing, a lawful basis for each activity, transparent notices, data subject rights procedures, DPIAs for high-risk processing, Article 28 processor agreements, breach notification to the supervisory authority within 72 hours (Article 33), and a valid mechanism for every transfer outside the EEA. For Türkiye, which has no EU adequacy decision, that mechanism is standard contractual clauses plus a transfer impact assessment and supplementary measures.
Four regimes, one data flow
Combined coverage of these four regimes is uncommon and directly relevant to groups operating across Europe, Türkiye and the Gulf.
EU — GDPR
Regulation (EU) 2016/679: accountability, Article 28 processor agreements, 72-hour breach notification, and Chapter V rules for transfers outside the EEA.
Türkiye — KVKK
Law No. 6698 on the Protection of Personal Data. Law No. 7499 reshaped the transfer rules from 1 June 2024: adequacy, appropriate safeguards (including standard contracts notified within five business days) and incidental transfers. VERBIS registration applies.
UAE — PDPL
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, for groups with operations or service providers in the United Arab Emirates.
Qatar — PDPPL
Law No. 13 of 2016 on Personal Data Privacy Protection, for groups with operations or service providers in Qatar.
A data protection programme in seven steps
Legal and technical requirements handled together, so the documents describe what the systems actually do.
Compliance analysis
Existing processes reviewed, personal data inventory produced, gap analysis against the regulation.
Roadmap
Risk assessment report, compliance strategy and corporate data processing policies.
Process and documentation
Privacy notices, consent mechanisms, processing and retention policies, data subject rights and breach procedures.
Technical and organisational measures
Encryption, access control, logging, backup and recovery specified concretely, not as a list of aspirations.
Transfers
Transfer mapping, SCCs, transfer impact assessments and supplementary measures; KVKK alignment on the Turkish side.
Training and awareness
All-staff awareness, in-depth training for management and data owners, periodic refreshers.
Ongoing compliance and audit
Periodic compliance audits, legislative update support and breach scenario exercises.
Engagement summary
- Track record
- 15+ completed data protection compliance projects
- Jurisdictions
- EU GDPR, Türkiye KVKK, UAE PDPL, Qatar PDPPL
- Delivered as
- Word and Excel; version-controlled, metadata cleaned, document IDs applied
- Certification route
- ISO/IEC 27701 where third-party assurance is wanted
Our approach
- One adviser covering both EU and Turkish requirements on the same data flow
- Technical measures specified concretely
- Breach procedures that meet the 72-hour clock and interlock with NIS2 reporting
- Records of processing designed to be maintainable by the client
- SCCs used in unaltered official form
The compliance programme
- Data inventory and records of processing activities
- Lawful basis analysis and legitimate interest assessments
- Privacy notices and consent mechanisms
- Data subject rights procedure
- DPIAs for high-risk processing
- Processor register and Article 28 agreements
- Breach detection, assessment and 72-hour notification procedure
- Retention and deletion schedule
- Transfer map, SCC package and transfer impact assessments
- KVKK transfer alignment and VERBIS support
- Staff and management training records
- Compliance audit report and action plan
We work both ends of the transfer
Most European organisations can find a GDPR adviser. Far fewer can advise on what happens when personal data leaves the EEA for a group company or service provider in Türkiye — and on the Turkish rules that apply at the other end of the same flow.
EU side — GDPR Chapter V
- Transfer mapping across group entities and suppliers
- Standard contractual clauses, attached in unaltered official form
- Transfer impact assessments written for the actual data flow
- Supplementary technical and organisational measures
- Article 28 processor terms aligned with the transfer package
Türkiye side — KVKK Law No. 6698
- Transfers abroad under Article 9 as amended by Law No. 7499, in force since 1 June 2024
- Adequacy decisions, appropriate safeguards and incidental transfers as the three routes
- Standard contracts notified to the Personal Data Protection Authority within five business days of signature
- Binding corporate rules and other safeguards where they fit the group
- VERBIS registration and alignment with the EU-side contract
No adequacy decision for Türkiye
The European Commission has not adopted an adequacy decision for Türkiye. Every transfer from the EEA to a Turkish group company or supplier therefore needs the full package — SCCs, a transfer impact assessment and supplementary measures — built correctly. It is one of the reasons European groups with Turkish operations come to us. See also the Türkiye–EU supply chain bridge.
completed data protection compliance projects
jurisdictions covered: EU, Türkiye, UAE, Qatar
GDPR breach notification clock, interlocked with NIS2 reporting
Questions we are asked
Can we transfer personal data from the EU to a group company in Türkiye?
Yes, but not on the basis of adequacy — there is no EU adequacy decision for Türkiye. The transfer needs standard contractual clauses, a transfer impact assessment for the actual data flow, and supplementary measures where the assessment calls for them. On the Turkish side, KVKK has its own transfer rules that must be aligned with the EU-side contract.
What changed in Turkish KVKK transfer rules in 2024?
Law No. 7499, in force since 1 June 2024, amended Article 9 of Law No. 6698. Transfers abroad now rest on an adequacy decision, appropriate safeguards — such as standard contracts, which must be notified to the Personal Data Protection Authority within five business days of signature, or binding corporate rules — or, in limited cases, incidental transfer conditions.
Do you replace our lawyers?
No. We deliver the compliance programme — inventory, records, procedures, technical measures, transfer packages and training — and work alongside your legal counsel where a legal opinion or representation is needed. Many clients value having one adviser who covers both the legal documents and the technical measures behind them.
How does GDPR breach notification relate to NIS2?
A single incident can trigger both: GDPR Article 33 requires notification to the data protection authority within 72 hours of becoming aware of a personal data breach, while NIS2 Article 23 requires an early warning within 24 hours and an incident notification within 72 hours to the cybersecurity authority. We design one incident procedure that makes both decisions in time.
Is ISO/IEC 27701 worth adding?
Where customers or partners want independent assurance, yes. ISO/IEC 27701:2025 is a standalone, certifiable privacy management standard, and a certificate is strong evidence of accountability across GDPR and KVKK.
Let us start with a scoping conversation
Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.