ARTICLE
14 November 2025

First DPA Permission Granted For Cross Border Transfer In Türkiye Under Non-International Mechanism

KST LAW

Contributor

KST LAW is an independent Istanbul based full service corporate law firm in cooperation with Kinstellar.

We provide legal services relevant to all aspects of business in a wide variety of sectors. We operate to the highest international standards in managing cross border transactions or investments and providing practical and creative solutions to legal or regulatory issues.

KST LAW is proud to have an exceptional client base consisting some of the largest Turkish conglomerates, sector leaders in Turkey, multi-nationals, investment or private equity funds and financial institutions.

On 11 November 2025, the Turkish Personal Data Protection Board (the "Board") announced on its official website that on 21 October 2025 it granted permission for a cross-border personal...
Turkey Privacy
Ceren Ceyhan’s articles from KST LAW are most popular:
  • within Privacy topic(s)
  • in United Kingdom
KST LAW are most popular:
  • within Privacy, Employment and HR, Litigation and Mediation & Arbitration topic(s)

November 2025 – On 11 November 2025, the Turkish Personal Data Protection Board (the “Board”) announced on its official website that on 21 October 2025 it granted permission for a cross-border personal data transfer based on a non-international agreement concluded between Türkiye's Directorate General of Migration Management (under the Ministry of Interior) and the United Nations High Commissioner for Refugees (“UNHCR”).

Background: A New Transfer Mechanism in Practice

Following the amendment to the Personal Data Protection Law on 12 March 2024, Turkish data privacy legislation contains a new cross-border data transfer mechanism. This mechanism allows transfers between (i) Turkish public institutions, organisations, or professional organisations having the status of public institution, and (ii) foreign public institutions, organisations, or international organisations, where appropriate safeguards may be ensured through a non-international agreement containing personal data protection clauses.

Under this framework, the Board's opinion must be sought during the negotiation of the agreement. Once the text is finalised, the Board's permission is required before any transfer takes place.

With this recent decision, the UNHCR-Directorate General of Migration Management agreement has become first approved example of a non-international agreement providing “appropriate safeguards” for cross-border data transfers.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More