Confidentiality and data protection have become essential components of international arbitration proceedings connected with Turkey.
Commercial arbitrations frequently involve sensitive material such as financial records, customer information, employee files, technical designs, medical documents, pricing formulas, trade secrets, internal investigations, banking data, personal correspondence and commercially valuable digital records.
The arbitration may also involve participants located in several jurisdictions. Parties, arbitrators, lawyers, witnesses, experts, interpreters, arbitral institutions, electronic hearing providers and document-hosting companies may process or access the same information from different countries.
This creates two related but legally distinct questions.
The first concerns confidentiality: who may disclose information concerning the arbitration, its existence, the parties’ submissions, the evidence, hearings and the arbitral award?
The second concerns data protection: on what legal basis may personal data be collected, reviewed, transferred, stored, disclosed and retained throughout the proceedings?
The fact that arbitration is private does not automatically resolve either question.
A hearing conducted outside the public court system may be private, but that does not necessarily create a comprehensive legal obligation preventing every participant from disclosing information. Similarly, a contractual confidentiality clause does not by itself establish compliance with the Turkish Personal Data Protection Law or the European Union General Data Protection Regulation.
International Arbitration Law No. 4686 and the domestic arbitration provisions of the Turkish Code of Civil Procedure regulate the procedure, tribunal powers and judicial supervision of Turkish-seated arbitrations. These statutes provide substantial procedural autonomy but do not contain a complete data-protection code or an express, universally applicable confidentiality regime covering every arbitration participant and every category of information.
Data-processing activities connected with Turkey may instead fall within Personal Data Protection Law No. 6698, commonly referred to as the KVKK, together with its secondary legislation and decisions of the Turkish Personal Data Protection Board.
Where participants, evidence or service providers are connected with the European Economic Area, the GDPR may also apply. The applicable rules must therefore be identified at the beginning of the case rather than after confidential material has already been circulated internationally.
This article explains confidentiality, personal-data processing, cross-border transfers, document production, remote hearings, cybersecurity, data breaches, retention and publication of arbitral awards in international arbitration proceedings connected with Turkey.
Confidentiality and Privacy Are Not the Same
Privacy generally means that arbitration hearings and procedural meetings are not open to the general public.
Confidentiality is broader. It concerns whether a participant is legally prohibited from communicating information obtained through the arbitration to persons outside the proceedings.
A private hearing may still produce information that a party later discloses to:
- A parent company;
- A shareholder;
- An insurer;
- A lender;
- A regulator;
- A court;
- A public authority;
- A potential purchaser;
- The media.
The legal right to make such disclosure depends on the arbitration agreement, institutional rules, procedural orders, professional obligations, applicable legislation and purpose of disclosure.
Data protection concerns another issue entirely. Information may remain confidential between the parties but still be processed unlawfully if personal data is collected without a valid legal basis, transferred abroad without the required safeguard or retained for longer than necessary.
Accordingly, a well-managed arbitration should address privacy, confidentiality, cybersecurity and data protection through separate but coordinated measures.
Is International Arbitration Automatically Confidential under Turkish Law?
International Arbitration Law No. 4686 gives the parties broad authority to determine the procedural rules governing their arbitration. The parties may establish their own procedure or incorporate national, international or institutional arbitration rules. Where no procedure has been agreed, the tribunal may conduct the proceedings subject to the mandatory provisions of the law.
The domestic arbitration provisions of the Code of Civil Procedure adopt a similar party-autonomy structure for Turkish domestic arbitration.
Neither statutory regime, however, establishes a detailed general rule stating that every party, witness, expert, lawyer and service provider in every Turkish-seated arbitration is automatically subject to the same comprehensive confidentiality duty.
The absence of a universal statutory rule does not mean that Turkish arbitrations are public. Arbitration proceedings are ordinarily conducted outside the public court system and institutional arbitration may provide an expressly confidential framework.
ISTAC describes its arbitration services as flexible, confidential and suitable for both domestic and foreign parties. Its institutional framework also imposes confidentiality duties concerning the Arbitration Boards, Secretariat and documents submitted to institutional bodies.
Nevertheless, parties should not rely solely on the general expectation that arbitration is confidential.
A carefully drafted arbitration agreement, institutional rule or procedural order should state:
- Which information is confidential;
- Who is bound;
- Permitted disclosures;
- Security requirements;
- Duration of the obligation;
- Consequences of breach.
Sources of Confidentiality Obligations
Confidentiality in a Turkish arbitration may arise from several overlapping sources.
The Arbitration Agreement
The parties may include a confidentiality clause in the main contract or arbitration agreement.
The clause may protect:
- The existence of the arbitration;
- Pleadings;
- Exhibits;
- Document-production material;
- Witness statements;
- Expert reports;
- Hearing recordings;
- Transcripts;
- Procedural decisions;
- Interim measures;
- Settlement discussions;
- The final award.
The clause should bind not only the companies but also require them to ensure compliance by employees, directors, witnesses, experts and service providers under their control.
Institutional Arbitration Rules
Where the parties choose ISTAC or another arbitral institution, the relevant rules and institutional regulations may create confidentiality obligations for the institution and persons administering the case.
ISTAC’s institutional rules state that Arbitration Board sessions and documents submitted to the Board are confidential. The Secretariat is also required to preserve the confidentiality of statements, documents, pleadings, communications and information learned while performing its duties.
ISTAC additionally presents its arbitration process as a confidential alternative to court litigation.
The precise version of the institutional rules applicable on the commencement date should always be reviewed.
Procedural Orders
The tribunal may adopt a confidentiality and data-protection protocol through a procedural order.
This is often the most effective method because the order can be tailored to the actual case. It may regulate:
- Confidential document categories;
- Access permissions;
- Electronic storage;
- Redaction;
- Data-room use;
- Hearing attendance;
- Recordings;
- Destruction or return of documents;
- Publication of the award.
The tribunal’s procedural authority under Turkish arbitration law provides a foundation for case-specific orders, provided that equality and the right to be heard are respected.
Professional Duties
Lawyers may be subject to professional secrecy and ethical obligations under the laws governing their profession.
Experts, interpreters, tribunal secretaries and technology providers may also have contractual confidentiality obligations.
The existence and scope of these obligations should not be assumed. Each participant should sign an appropriate engagement letter, confidentiality undertaking or data-processing agreement where necessary.
Trade Secret and Contractual Protections
Information may also receive protection as a trade secret, confidential business record or commercially sensitive contractual information.
A party should identify genuinely sensitive material and request proportionate protection rather than marking every document as confidential without distinction.
Who Should Be Bound by the Confidentiality Regime?
A confidentiality protocol should cover every person with meaningful access to the case file.
This may include:
- Parties;
- Directors and employees;
- In-house and external lawyers;
- Arbitrators;
- Tribunal secretaries;
- ISTAC or another institution;
- Witnesses;
- Party-appointed experts;
- Tribunal-appointed experts;
- Interpreters;
- Translators;
- Transcription providers;
- Hearing-platform providers;
- Electronic disclosure vendors;
- Litigation funders;
- Insurers;
- Consultants.
Different participants may require different levels of access.
A technical expert may need access to engineering records but not employee medical files. A damages expert may require financial data but not commercially unrelated correspondence.
Access should therefore be based on the need-to-know principle.
Permitted Disclosures
A confidentiality obligation should contain reasonable exceptions.
Disclosure may be necessary:
- To pursue or defend the arbitration;
- To enforce or challenge the award;
- To obtain interim judicial protection;
- To comply with legislation;
- To answer a regulator;
- To satisfy stock-exchange obligations;
- To inform insurers or funders;
- To obtain professional advice;
- To comply with accounting or audit requirements;
- To protect a legal right.
The disclosing party should ordinarily limit disclosure to what is necessary and, where possible, notify the other party or tribunal.
A confidentiality clause that prohibits every disclosure without exception may become impractical or conflict with mandatory legal obligations.
Turkish Court Proceedings and Loss of Confidentiality
Court support may be required during or after arbitration.
Turkish courts may become involved in:
- Interim injunctions;
- Interim attachment;
- Arbitrator appointment;
- Arbitrator challenges;
- Evidence collection;
- Extension of the arbitration period;
- Setting-aside proceedings;
- Recognition and enforcement.
Court proceedings are governed by procedural rules that are different from the private framework of arbitration. Turkish civil procedure generally recognises the principle of public hearings, subject to legally recognised exceptions.
Documents submitted to a court may therefore face a different level of confidentiality from documents held exclusively within the arbitration.
Parties should consider:
- Whether the full document is necessary;
- Whether irrelevant personal data can be redacted;
- Whether a confidential annex can be used;
- Whether the court can restrict access or close a hearing;
- Whether commercial secrets can be protected through a specific request.
The need to prove an arbitration-related application does not justify submitting an entire unrestricted case file where a smaller document set is sufficient.
Data Protection in International Arbitration
Arbitration proceedings involve extensive processing of personal data.
Under Turkish law, personal data means information relating to an identified or identifiable natural person. The KVKK protects data belonging to real persons rather than data concerning legal entities as such.
Processing is defined broadly and includes:
- Collection;
- Recording;
- Storage;
- Preservation;
- Alteration;
- Organisation;
- Disclosure;
- Transfer;
- Making data accessible;
- Classification;
- Restriction of use.
Sending a witness statement by email, uploading an employee file to an electronic case platform, sharing evidence with a foreign expert or storing hearing recordings in the cloud may each constitute processing.
Personal Data Commonly Found in Arbitration Files
An arbitration record may contain:
- Names and contact information;
- Passport and identity information;
- Signatures;
- Employment records;
- Salaries and bonuses;
- Bank-account details;
- Telephone and location records;
- Performance evaluations;
- Disciplinary records;
- Medical information;
- Trade-union information;
- Criminal allegations;
- Political or religious information;
- Biometric data;
- Photographs;
- Voice and video recordings.
Some of these categories may constitute special-category personal data and require stronger legal and security protections.
The 2024 amendments to the KVKK expanded and reorganised the legal conditions for processing special-category data. The updated regime expressly recognises, among other grounds, processing that is necessary for the establishment, exercise or protection of a right.
This ground may be particularly relevant to evidence in litigation and arbitration, but it should not be treated as permission to process unlimited information.
Necessity, proportionality and the general processing principles must still be satisfied.
Data Controller and Data Processor Roles
A data controller determines why and how personal data will be processed. A data processor processes data on behalf of and under the instructions of a controller.
The correct classification of participants in arbitration is fact-specific.
Depending on their functions:
- A party may act as a controller for its case-related processing;
- A law firm may act as an independent controller for professional and legal-service purposes;
- An arbitral institution may determine certain administrative processing purposes;
- An electronic hosting provider may act as a processor;
- A transcription company may process data under instructions;
- An expert may act as a controller or processor depending on its independence and engagement terms;
- An arbitral tribunal’s status may require a case-specific assessment.
The parties should not label every service provider as a processor without examining who actually determines the purposes and essential means of processing.
The Turkish Personal Data Protection Board has emphasised that controller and processor roles must be determined by examining actual decision-making authority rather than contractual terminology alone.
Legal Grounds for Processing Arbitration Data
Consent is not the only possible ground for processing personal data.
Under Article 5 of the KVKK, personal data may be processed without express consent where one of the statutory conditions exists.
Potentially relevant grounds in arbitration include:
- Performance of a contract;
- Compliance with a legal obligation;
- Establishment, exercise or protection of a right;
- Legitimate interests of the controller, provided that fundamental rights and freedoms are not harmed;
- Data made public by the person for the relevant purpose.
The establishment, exercise or protection of a right is frequently important in dispute resolution. The Turkish authority’s guidance gives the example of using employee data as evidence in proceedings initiated by the employee.
However, this basis requires necessity.
A party should ask:
- Is the data relevant to a disputed issue?
- Is a less intrusive document available?
- Can identifying information be redacted?
- Is the complete employee file needed?
- Is disclosure to every participant necessary?
- Can access be restricted?
A vague possibility that a document may become useful is not a reliable substitute for a documented legal basis.
Processing Special-Category Personal Data
Special-category data can create significant risk.
An arbitration may include medical reports, trade-union membership, criminal allegations, biometric records or information concerning religion, political opinions or sexual life.
Following the amendments that entered into force on 1 June 2024, special-category data may be processed under the revised conditions in Article 6 of the KVKK. These include express consent, cases expressly provided by law and necessity for the establishment, exercise or protection of a right, subject to the applicable safeguards.
Parties should consider additional measures such as:
- Redaction;
- Pseudonymisation;
- Password-protected files;
- Restricted-access folders;
- Separate confidential annexes;
- Prohibition on downloading;
- Limited retention;
- Secure destruction.
The sensitive nature of the data should also be considered when selecting cloud providers and hearing platforms.
Transparency and Privacy Notices
Data subjects should be informed about the processing of their personal data where the KVKK’s transparency requirements apply.
A privacy notice should generally explain:
- The identity of the controller;
- The purposes of processing;
- The recipients;
- The collection method;
- The legal basis;
- The rights of the data subject.
Providing a privacy notice is separate from obtaining consent. The duty to inform applies independently of whether processing is based on consent or another statutory condition.
In a 2026 principle decision, the Turkish Personal Data Protection Board emphasised that privacy notices and consent texts should be prepared separately and that controllers should not request “approval” of a privacy notice as though the notice itself were consent.
Arbitration participants should therefore avoid using one generic form that combines information, consent, confidentiality and procedural acceptance without distinguishing their separate legal functions.
Data Minimisation and Purpose Limitation
The KVKK requires personal data to be:
- Processed lawfully and fairly;
- Accurate and up to date where necessary;
- Processed for specified, explicit and legitimate purposes;
- Relevant, limited and proportionate;
- Retained only as long as required by legislation or the processing purpose.
These principles are directly relevant to arbitration.
A party should not submit 10 years of employee correspondence where only a two-month period concerns the disputed issue.
The tribunal may require:
- Narrowed document requests;
- Redaction of unrelated names;
- Removal of identity numbers;
- Sampling;
- Limitation of custodians;
- Restricted search terms;
- Separate treatment of sensitive documents.
Data minimisation can reduce both legal risk and arbitration costs.
Cross-Border Transfers in International Arbitration
International arbitration inherently creates cross-border data-transfer risks.
A transfer may occur where personal data is:
- Emailed to a foreign arbitrator;
- Uploaded to a server located abroad;
- Reviewed by foreign counsel;
- Shared with an overseas expert;
- Accessed remotely by a foreign institution;
- Stored by an international hearing provider;
- Sent to a translation company in another country.
The Turkish authority’s current framework treats both transmission to a foreign recipient and making data accessible abroad as international transfers.
Article 9 of the KVKK was substantially amended by Law No. 7499, with the new regime taking effect on 1 June 2024. The transitional coexistence of the previous first paragraph ended on 1 September 2024.
The new system follows three principal levels:
- Transfer based on an adequacy decision;
- Transfer based on an appropriate safeguard where no adequacy decision applies;
- Limited exceptional transfer grounds where neither adequacy nor an appropriate safeguard is available.
The appropriate route must be identified before data is uploaded or made accessible abroad.
Adequacy Decisions
The Personal Data Protection Board may issue an adequacy decision concerning:
- A country;
- One or more sectors within a country;
- An international organisation.
The Board must consider matters such as reciprocity, local legislation, the existence of an effective data-protection authority and available administrative or judicial remedies. Adequacy decisions are to be published and periodically reviewed.
Before relying on adequacy, parties should verify whether an applicable and current decision covers the relevant recipient and processing operation.
Appropriate Safeguards
Where no adequacy decision applies, personal data may be transferred if an applicable processing condition exists, data subjects can exercise their rights and obtain effective remedies in the destination, and one of the recognised appropriate safeguards is provided.
The available safeguards include:
- An agreement between qualifying public authorities;
- Binding corporate rules approved by the Board;
- Standard contracts published by the Board;
- A written undertaking approved by the Board.
For many private arbitration participants, the standard contractual mechanism may be the most practical option.
Turkish Standard Contracts
The Turkish authority has published separate standard contracts for different transfer relationships, including controller-to-controller and processor-related transfers.
The official standard contracts regulate matters such as:
- Data categories;
- Processing purposes;
- Data-subject groups;
- Security measures;
- Special-category data safeguards;
- Rights of data subjects;
- Subsequent transfers;
- Breach management;
- Termination.
The contracts are intended to provide an appropriate safeguard under the revised Article 9 regime.
The published text must be used without unauthorised amendment. Where the standard contract is also signed in another language, the Turkish text prevails for the Turkish mechanism.
The completed standard contract must be notified to the Turkish authority within five business days after all signatures have been completed.
An ordinary confidentiality agreement, service agreement or GDPR data-processing addendum does not automatically replace the Turkish standard contract where the KVKK mechanism is required.
Binding Corporate Rules
A multinational group may use binding corporate rules approved by the Turkish Personal Data Protection Board for qualifying intragroup transfers.
The rules must create binding and enforceable data-protection commitments throughout the group and include mechanisms concerning data-subject rights, security, audits, training, subsequent transfers and cooperation with the Turkish authority.
Binding corporate rules may assist groups that regularly manage Turkish litigation and arbitration data through central international platforms.
They are less likely to solve one isolated transfer to an unrelated arbitrator, expert or outside law firm.
Exceptional Transfers
Where there is no adequacy decision and no appropriate safeguard, the revised Turkish regime permits exceptional transfers only in defined circumstances and, as a general feature of the secondary framework, on an occasional rather than continuous basis.
Relevant exceptions may include:
- Explicit consent after information about the risks;
- Necessity for contractual performance in specified circumstances;
- Important public interest;
- Necessity for the establishment, exercise or protection of a right;
- Protection of life or physical integrity;
- Transfer from certain public registers.
The “protection of a right” exception may be relevant to occasional arbitration transfers.
However, it should not be used casually to justify a permanent international case-management platform, systematic overseas storage or repeated routine transfer where an appropriate safeguard can and should be implemented.
Application of the GDPR
The GDPR may apply in addition to the KVKK where the processing falls within its territorial scope.
This may occur, for example, where:
- A party or law firm is established in the European Union;
- An EU-based arbitral institution processes the file;
- An EU business processes the data in the context of its establishment;
- Other territorial criteria under the GDPR are satisfied.
The GDPR regulates lawfulness, transparency, security, data-subject rights, controller-processor relationships, breach notifications and international transfers.
Chapter V requires transfers of personal data from the European Union to third countries to comply with Articles 44 to 50.
Compliance with the Turkish transfer mechanism does not automatically establish GDPR compliance, and compliance with GDPR contractual clauses does not automatically satisfy the KVKK.
Where data moves in both directions, the parties may require parallel Turkish and EU transfer solutions.
Document Production and Data Protection
Data protection should not be used as a blanket excuse to avoid legitimate document production.
At the same time, a tribunal should not order disproportionate disclosure merely because the information may be relevant.
A balanced document-production process may involve:
- Narrowly defined requests;
- Date limits;
- Custodian limits;
- Search terms;
- Redaction;
- Pseudonymisation;
- Confidentiality designations;
- Restricted data-room access;
- Exclusion of irrelevant personal data;
- Clawback procedures for accidental disclosure.
The party producing the material should document its legal basis and security measures.
The requesting party should use the information only for the arbitration and should not reuse employee, customer or witness data for unrelated commercial purposes.
Witnesses and Experts
Witness statements usually contain personal data relating to the witness and third parties.
Before filing a statement, counsel should review whether it includes unnecessary:
- Home addresses;
- Identity numbers;
- Family information;
- Medical information;
- Personal telephone numbers;
- Unrelated allegations;
- Data concerning junior employees.
Experts should receive only the material reasonably necessary for their instructions.
Their engagement terms should address:
- Confidentiality;
- Data-security measures;
- International transfers;
- Subcontractors;
- Storage locations;
- Retention;
- Return or destruction of material;
- Breach notification.
A foreign expert should not be given unrestricted access to the entire case file merely for convenience.
Remote Hearings and Cybersecurity
Remote hearings can expose arbitration material to additional technological risks.
ISTAC’s Online Hearing Rules regulate participation, attendance, technology and the right to be heard. Only notified and permitted participants may attend, and the tribunal must take measures to preserve effective participation.
A remote-hearing protocol should address:
- Approved platform;
- Hosting location;
- Encryption;
- Passwords;
- Waiting rooms;
- Multi-factor authentication;
- Recording;
- Screenshots;
- Attendance verification;
- Use of personal devices;
- Document sharing;
- Interpretation channels;
- Technical support;
- Incident response.
Recording should not be assumed to be permitted merely because the platform contains a recording function.
The tribunal should determine:
- Whether recording is authorised;
- Who controls the recording;
- Where it will be stored;
- Who may access it;
- How long it will be retained;
- Whether copies may be made.
Cloud Storage and Service Providers
International arbitration increasingly depends on cloud storage, electronic bundles, data rooms, transcription platforms and artificial-intelligence tools.
Before using a provider, the responsible participant should examine:
- Server locations;
- Sub-processors;
- Encryption;
- Access controls;
- Backup practices;
- Retention;
- Breach procedures;
- International transfer mechanism;
- Use of uploaded data for product development or model training;
- Deletion after the case.
Consumer-grade platforms may not be appropriate for highly sensitive arbitration records.
The fact that a tool is convenient, popular or offered by a multinational company does not establish compliance with Turkish or EU data-protection rules.
Use of Artificial Intelligence
Artificial-intelligence systems may be used for:
- Document review;
- Translation;
- Chronology preparation;
- Transcription;
- Legal research;
- Drafting;
- Data classification.
Uploading an arbitration record to an AI service may disclose confidential information and transfer personal data to external servers or sub-processors.
Before using such a service, counsel should determine:
- Whether client and tribunal authorisation is required;
- Whether input will be retained;
- Whether input will train the provider’s models;
- Where processing occurs;
- Whether a transfer safeguard exists;
- Whether the output may expose personal data;
- Whether human verification is required.
Highly sensitive documents should not be uploaded to an uncontrolled public service.
Data-Security Obligations
Article 12 of the KVKK requires controllers to take appropriate technical and administrative measures to prevent unlawful processing, prevent unlawful access and ensure the secure preservation of personal data.
Appropriate measures in arbitration may include:
- Encryption in transit and at rest;
- Multi-factor authentication;
- Strong passwords;
- Restricted permissions;
- Access logs;
- Secure file-transfer systems;
- Device encryption;
- Anti-malware protection;
- Secure backups;
- Staff training;
- Incident-response plans;
- Vendor due diligence.
Security should reflect the sensitivity and volume of the information.
A dispute concerning health data, internal investigations or thousands of employee records requires stronger safeguards than an arbitration involving only public corporate documents.
Personal-Data Breaches
A breach may include:
- Sending documents to the wrong recipient;
- Loss of a laptop;
- Compromised email credentials;
- Unauthorised data-room access;
- Publication of an unredacted award;
- Theft of hearing recordings;
- Malware;
- Accidental sharing of a privileged document;
- Disclosure through an insecure AI platform.
Under the Turkish authority’s established breach-notification framework, “as soon as possible” has been interpreted as requiring notification to the Board without delay and no later than 72 hours after the controller becomes aware of the breach. Affected persons must also be informed within a reasonable period where required.
An arbitration data-protection protocol should require participants and processors to notify the responsible controller immediately rather than waiting until the 72-hour period is about to expire.
The tribunal should also consider whether the breach affects:
- Procedural fairness;
- Privilege;
- Confidentiality;
- Authenticity of evidence;
- Hearing timetable;
- Need for interim measures.
Retention and Destruction
The conclusion of arbitration does not necessarily mean that every document must be destroyed immediately.
Material may need to be retained for:
- Setting-aside proceedings;
- Recognition and enforcement;
- Professional obligations;
- Limitation periods;
- Tax or accounting duties;
- Conflict checks;
- Defence against future claims.
However, indefinite retention of the complete file is difficult to reconcile with the principle that data should be stored only for the period required by legislation or the processing purpose.
The retention plan should distinguish between:
- Original client records;
- Working copies;
- Hearing bundles;
- Expert copies;
- Vendor backups;
- Recordings;
- Transcripts;
- Institutional archives.
At the end of the required period, data should be securely deleted, destroyed or anonymised.
Publication of Arbitral Awards
Publication can support consistency and development of arbitration law, but it creates confidentiality and data-protection risks.
Before an award is published, the responsible body should consider removing or anonymising:
- Party names;
- Individual names;
- Addresses;
- Identity numbers;
- Bank details;
- Medical information;
- Trade secrets;
- Sensitive contract terms;
- Information enabling indirect identification.
Removing only the names may be insufficient where the combination of industry, project, dates and positions makes an individual identifiable.
The arbitration agreement or procedural order should determine whether publication is permitted and whether party consent is required.
Drafting a Confidentiality and Data-Protection Protocol
A comprehensive protocol may address:
- Definitions of confidential information and personal data;
- Persons permitted to access the file;
- Legal purposes for which information may be used;
- Confidentiality designations;
- Privacy notices;
- Processing roles;
- Cross-border transfer mechanisms;
- Electronic platform and server locations;
- Security standards;
- Document production and redaction;
- Special-category data;
- Hearing attendance and recordings;
- Remote testimony;
- Use of vendors and subcontractors;
- Use of artificial intelligence;
- Data-breach notification;
- Retention and destruction;
- Publication of decisions;
- Permitted disclosures;
- Remedies for non-compliance.
The protocol should be adopted early, ideally during the first procedural conference.
Sample Confidentiality and Data-Protection Clause
“The parties shall keep confidential the existence of the arbitration, all submissions, evidence, witness statements, expert reports, hearing materials, procedural decisions and awards, except to the extent disclosure is reasonably necessary for the conduct of the arbitration, protection or exercise of a legal right, compliance with law, regulatory reporting, professional advice, financing, insurance, challenge, recognition or enforcement.
Each party shall ensure that its representatives, employees, witnesses, experts, consultants and service providers receiving confidential information are subject to appropriate confidentiality obligations.
The parties, tribunal and administering institution shall process personal data only to the extent necessary for the conduct, administration, challenge, recognition or enforcement of the arbitration and shall implement appropriate technical and administrative safeguards.
No participant shall transfer personal data internationally unless the transfer complies with the data-protection law applicable to that participant and the transfer, including the Turkish Personal Data Protection Law No. 6698 where applicable.
The tribunal may issue further confidentiality, cybersecurity, data-protection, redaction, retention and destruction directions after consulting the parties.”
This sample should be adapted to the parties, institution, seat, evidence and countries involved.
Practical Compliance Checklist
Before or immediately after arbitration begins, the parties should determine:
- What confidentiality rules apply;
- Whether a specific confidentiality clause exists;
- Whether the institutional rules are sufficient;
- Which participants require undertakings;
- What personal data is likely to be processed;
- Whether special-category data is involved;
- Who acts as controller or processor;
- Which processing grounds apply;
- Which privacy notices are required;
- Which countries will receive or access data;
- Whether adequacy or appropriate safeguards exist;
- Whether Turkish standard contracts are required;
- Whether the five-business-day notification obligation applies;
- Whether GDPR transfer requirements also apply;
- Which platform will host documents;
- Where the servers are located;
- Whether artificial-intelligence tools will be used;
- How remote hearings will be secured;
- How breaches will be reported;
- How long files will be retained;
- Whether the award may be published.
Frequently Asked Questions
Is every Turkish arbitration automatically confidential?
No comprehensive statutory rule automatically imposes the same confidentiality duty on every participant in every Turkish arbitration. Confidentiality should be established through the arbitration agreement, institutional rules, procedural orders and participant undertakings. ISTAC presents its institutional proceedings as confidential and imposes confidentiality duties on its Boards and Secretariat.
Is confidentiality the same as data protection?
No. Confidentiality restricts disclosure of arbitration information. Data protection regulates the lawful collection, use, transfer, security and retention of information relating to identifiable natural persons.
Does the KVKK apply to company information?
The KVKK protects personal data relating to natural persons. Purely corporate data concerning a legal entity is not personal data, although documents concerning a company frequently include personal data relating to directors, employees, customers and representatives.
Is consent always required to use personal data as arbitration evidence?
No. Processing may rely on another statutory condition, including necessity for the establishment, exercise or protection of a right. The specific basis and necessity must be documented.
Can medical or criminal information be submitted?
Potentially, where processing satisfies the revised special-category data conditions and is necessary and proportionate. Additional safeguards should be used.
Is sending a document to a foreign arbitrator an international transfer?
It may be. The Turkish framework includes transmitting data to a foreign recipient or otherwise making it accessible abroad.
Can parties rely on a Turkish standard contract?
Yes, where the standard contract is the appropriate safeguard for the relevant controller-processor relationship. The official text must be used correctly and notified to the authority within five business days after signature completion.
Can the right-protection exception justify every arbitration transfer?
No. The exceptional regime is designed for limited circumstances and should not be treated as a substitute for appropriate safeguards for continuous, systematic or routine transfers.
Does GDPR compliance automatically satisfy the KVKK?
No. The laws overlap but are separate. A transfer may require compliance with both Turkish and EU requirements.
Can remote arbitration hearings be recorded?
Only according to the tribunal’s directions, party agreement and applicable law. The platform’s technical ability to record does not itself create permission.
Should witness statements contain home addresses?
Usually only where genuinely necessary. Unnecessary contact, identity and family information should be removed or redacted in accordance with data-minimisation principles.
Can personal data be kept permanently after arbitration?
Not merely for convenience. Retention should be tied to legal, professional and enforcement needs, after which data should be deleted, destroyed or anonymised in accordance with the applicable rules.
What happens if arbitration documents are sent to the wrong person?
The incident should be contained and assessed immediately. Where it constitutes a personal-data breach under Turkish law, notification obligations may arise, including the 72-hour Board notification framework.
Conclusion
Confidentiality and data protection in international arbitration in Turkey require active legal and procedural management.
Arbitration offers a private forum, but privacy alone does not establish a comprehensive confidentiality duty. Parties should define the scope of confidentiality through their arbitration agreement, institutional rules and tribunal orders.
ISTAC provides a confidential institutional setting and imposes confidentiality obligations on its administrative bodies and Secretariat. Nevertheless, a case-specific protocol remains valuable where witnesses, experts, insurers, funders, vendors and foreign service providers will access the record.
Data protection presents a separate layer of legal obligations.
Arbitration files may contain significant quantities of ordinary and special-category personal data. Every participant should identify its processing role, legal basis, security obligations, transparency duties and retention period.
The establishment, exercise or protection of a right may provide an important legal basis for processing arbitration evidence. It does not remove the requirements of necessity, proportionality, purpose limitation and security.
Cross-border transfer compliance is particularly important.
Since the reformed Article 9 regime entered into force in 2024, Turkish transfers operate through adequacy decisions, appropriate safeguards and limited exceptional grounds. Standard contracts, binding corporate rules and approved undertakings may be required depending on the relationship and frequency of transfer.
International cases may also require simultaneous GDPR compliance.
Remote hearings, cloud storage, electronic disclosure and artificial-intelligence tools create efficiency but also increase the risk of unauthorised access, uncontrolled international transfers and data breaches.
The strongest approach is to address these questions at the first procedural conference.
A detailed confidentiality and data-protection protocol can protect commercial secrets, personal data, procedural fairness and the enforceability of the eventual award.
Confidentiality and data protection should therefore not be treated as administrative formalities. They are central elements of effective international arbitration practice in Turkey.
Legal Disclaimer: This article is provided for general informational purposes only and does not constitute legal advice. Confidentiality and data-protection obligations depend on the arbitration agreement, institutional rules, seat, participants, categories of data, processing purposes, transfer destinations and applicable national or international legislation. Case-specific advice should be obtained before processing or transferring personal data in international arbitration proceedings.
Yanıt yok