Legal preparation text • Not a live notice
Data Subject Request
Preparation guide for sending a secure and proportionate request to the controller under Türkiye's Law No. 6698.
Last content review: 17 July 2026
1. What may be requested?
Article 11 supports requests about whether and how data is processed, purpose and recipients, correction, deletion or destruction where the conditions apply, notice to recipients, objection to solely automated adverse analysis, and compensation for unlawful processing damage.
A request must be clear, specific, and concern the requester. A lawful representation or authority document is needed when acting for another person.
2. Request channels
The written request address [VERİ SORUMLUSU ADRESİ], KEP address [KEP ADRESİ], and privacy email [KVKK BAŞVURU E-POSTASI] will be published after the company and access controls are verified. Until then, the general contact form is not presented as a statutory privacy-request channel.
A request may be submitted in writing, through registered electronic mail, with a secure electronic/mobile signature, or through an email address previously notified to and recorded by the controller, subject to the applicable procedural rules.
3. Information required for a request
A request should include the name; signature for a written application; the identifiers required by the applicable procedure; a service address; an optional notification email or telephone number; and the subject of the request.
Identity verification must remain proportionate to the request. A copy of an identity document is not requested by default; where stronger evidence is necessary, the reason and secure transmission method will be explained.
4. Assessment and response time
The controller must respond as soon as possible and no later than 30 days, normally without charge. Where a separate cost is required, the tariff set by the Board may apply; a fee caused by the controller's fault must be returned.
The request is accepted or refused with reasons, and the response is delivered in writing or electronically. Request records are retained only to administer the request, verify identity, and demonstrate the legal response.
5. Complaint to the Board
Where a request is refused, the answer is insufficient, or no answer arrives within 30 days, a complaint to the Personal Data Protection Board may be available within the periods and procedure set by Law No. 6698. A controller request is required before a complaint to the Board.
This page is not individual legal advice. Current deadlines and methods should be checked against the Personal Data Protection Authority's official materials.