Sistem Patent
Management Systems

ISO 27001 and KVKK: Mapping Your ISMS to Turkish Data-Protection Law

A control-mapping diagram linking ISO 27001 Annex A control groups to KVKK data-protection obligations

A Turkish exporter passes its ISO 27001 surveillance audit cleanly, then receives a data-subject access request and a question from a customer's legal team: does the certificate prove KVKK compliance? The honest answer is no, and the gap between the two is exactly where most security teams get caught. An information security management system and a data-protection law overlap heavily, but they are not the same instrument, and treating the certificate as a compliance receipt is how organisations end up exposed on the controls the standard never asked for.

This is a crosswalk, not a primer. The aim is to show, control area by control area, where ISO 27001:2022 Annex A already carries the weight of a KVKK (Turkey's Personal Data Protection Law, No. 6698) obligation, and where the law demands something the standard simply does not cover. If you run an ISMS and you process personal data, this is the map that tells you what your certificate is doing for you and what it leaves on the table.

Why the two instruments only partly overlap

ISO 27001 protects information assets against loss of confidentiality, integrity and availability, whatever those assets contain. KVKK protects natural persons, specifically their personal data, and it imposes duties that have nothing to do with whether your security controls work: a lawful basis for every processing activity, transparency to the individual, limits on how long you keep data, and a defined route for someone to exercise their rights. The standard is risk-driven and asset-centric. The law is rights-driven and person-centric.

That difference is the whole story. Annex A control 5.34, privacy and protection of personally identifiable information, explicitly tells you to identify and meet the requirements of applicable legislation, which in Turkey means KVKK. So the standard points at the law without containing it. Certifying your information security management system gives you the machinery to operate data protection well. It does not, on its own, discharge the legal obligations that machinery is supposed to serve.

Where Annex A genuinely satisfies KVKK

For the security limb of KVKK, the data controller's duty under Article 12 to take adequate technical and organisational measures, a certified ISMS does real and demonstrable work. This is the strongest part of the overlap, and it is where your certificate earns its keep.

Article 12 technical and organisational measures. KVKK requires the controller to prevent unlawful access and unlawful processing and to ensure data is preserved. Annex A answers this directly: access control (5.15 through 5.18), cryptography (8.24), logging and monitoring (8.15, 8.16), secure development (8.25 through 8.28), and supplier security (5.19 through 5.22). The Turkish Data Protection Authority's own technical-measures guidance reads as a near-subset of Annex A, which is why an accredited 27001 certificate is persuasive evidence that the security half of Article 12 is met.

Breach handling, on the technical side. Annex A 5.24 through 5.28 build an incident-management capability: detection, response, evidence collection, learning. KVKK obliges the controller to notify the Authority and affected individuals of a breach within the shortest possible time, which the regulator has framed as 72 hours. The ISMS gives you the detection and assessment pipeline that makes a 72-hour clock realistic. Hold that thought, because the notification duty itself is not an Annex A control.

Asset inventory and classification. Annex A 5.9 through 5.13 require you to know what information you hold and how sensitive it is. That inventory is the raw material for a KVKK record of processing, even though the two artefacts are not identical.

Internal accountability machinery. The management-system clauses, leadership, competence, internal audit, management review, give KVKK accountability somewhere to live. A law that says "be accountable" needs a system that produces evidence on a schedule, and that is precisely what an ISO 27001 system does.

ISO 27001 and KVKK: Mapping Your ISMS to Turkish Data-Protection Law figure

Where the certificate runs out: KVKK duties Annex A never asks for

Here is the part security teams underestimate. A significant share of KVKK is not a security requirement at all, and no amount of Annex A maturity will produce it. These are the controls a privacy assessment finds missing in an otherwise well-run ISMS.

Lawful basis and explicit consent

KVKK Articles 5 and 6 require a lawful ground for every processing activity, and for special categories of personal data, often explicit consent. Annex A has no concept of a processing ground. Your encryption can be flawless while the processing it protects is unlawful, because you never established a basis for it. This is the single most common blind spot.

Transparency and the disclosure obligation

Article 10 obliges the controller to inform individuals, at the point of collection, who is processing their data, why, to whom it may be transferred and on what legal ground. This is the aydınlatma yükümlülüğü, the disclosure obligation. It is a communication duty to the data subject. Annex A protects data once you hold it but says nothing about telling people you hold it.

Data-subject rights and the response route

Article 11 gives individuals rights to learn whether their data is processed, to request correction or erasure, and to object. The controller must operate a route to receive and answer these requests within 30 days. An ISMS secures the data behind that request but does not build the intake-and-response process the law mandates.

Retention limits and erasure

KVKK requires that personal data be kept only as long as the purpose requires, then deleted, destroyed or anonymised under a retention-and-disposal policy. Annex A 8.10 covers information deletion as a security control, but the legal trigger, purpose exhaustion rather than risk, comes from the law, and the documented retention policy is a KVKK artefact the standard does not demand.

VERBIS registration and cross-border transfer

Many controllers must register with VERBIS, the Authority's data-controllers registry, and KVKK Article 9 sets specific conditions for transferring personal data abroad. For a Turkish firm serving EU customers, this is where the law bites hardest, and it is purely a legal and administrative duty. Annex A has nothing equivalent. This is why dedicated KVKK work sits alongside, not inside, your security certification.

Cross-border transfer is also where a recent change to the law matters. The 2024 amendment to Article 9 introduced standard contractual clauses, binding corporate rules and adequacy-style routes as bases for sending data abroad, moving Turkey closer to the GDPR model. Annex A 5.14, information transfer, asks you to protect data in transit and to agree transfer rules with the receiving party. That control will make you encrypt the channel and sign a security schedule, but it will not tell you whether the transfer has a lawful KVKK ground, nor produce the standard contractual clauses the amended Article 9 now expects. The security mechanics and the legal authorisation are two separate questions, and your certificate answers only the first.

How to read your certificate after this mapping

The practical conclusion is that ISO 27001 covers the technical and organisational security obligations of KVKK convincingly, and the legal-basis, transparency, rights and registration obligations barely at all. A mature ISMS gets you perhaps two-thirds of the way on the controls that matter for an audit and a fraction of the way on the duties that matter for a regulator's inspection.

The efficient move is to run the two as one programme rather than two. Use the Annex A statement of applicability as the spine, then bolt on the KVKK-only artefacts: the record of processing, the lawful-basis register, the disclosure texts, the data-subject-request procedure, the retention schedule and the VERBIS filing. Your internal audit and management review, already required by the standard, then cover both. That is the integration that turns a security certificate into genuine data-protection assurance, and it is the work to scope before your next audit cycle rather than after a complaint lands.