Cloud infrastructure has become an essential part of the modern startup ecosystem.
A Turkish startup may use Amazon Web Services, Microsoft Azure, Google Cloud, a foreign CRM provider, an international email platform, an analytics service, an artificial intelligence API or another SaaS provider without ever operating its own physical server.
From a technical perspective, this is often the most practical solution.
From a legal perspective, however, it creates an important question:
Is it legal for a Turkish startup to store customer data on servers located abroad?
The answer is:
Yes, personal data may be stored on servers located outside Turkey, but the transfer must comply with the cross-border data transfer requirements of Law No. 6698 on the Protection of Personal Data (KVKK).
There is no general rule under the KVKK requiring every private company to keep all customer data physically inside Turkey.
However, storing personal data in a foreign data centre will ordinarily constitute a transfer of personal data abroad, meaning that Article 9 of the KVKK must be satisfied.
This distinction is critical.
A startup cannot simply say:
“We are not sending customer data to another company; we are only storing it in the cloud.”
If the cloud infrastructure storing the personal data is located abroad, a cross-border transfer issue may arise.
The Turkish Personal Data Protection Board has expressly considered the use of systems whose servers are located abroad to constitute an international personal data transfer. In a previous enforcement decision involving a technology company using overseas cloud infrastructure, the Board treated the storage of personal data on foreign servers as a transfer abroad for KVKK purposes.
Similarly, the Personal Data Protection Authority has warned that using platforms whose data centres are located abroad creates an international data transfer and therefore requires compliance with Article 9.
The legal framework governing these transfers changed fundamentally in 2024.
As of 2026, Turkish startups must understand the new system based on:
- adequacy decisions;
- appropriate safeguards;
- standard contracts;
- binding corporate rules;
- written undertakings approved by the Board;
- and limited exceptional transfers.
This article explains whether customer data can legally be stored on foreign servers under Turkish law, how the current Article 9 system works, when a standard contract is required, whether explicit consent is sufficient and what startups using international cloud providers should do to comply with the KVKK.
Does Storing Data Abroad Constitute a Cross-Border Data Transfer?
In most cases, yes.
Suppose a Turkish startup collects:
- customer names;
- email addresses;
- telephone numbers;
- purchase history;
- account information;
- IP addresses;
- and customer-support records.
The startup then stores all of this information in a cloud data centre located in Germany.
Even though the startup’s employees remain in Istanbul, personal data are technically transferred to infrastructure located outside Turkey.
This should therefore be analysed under Article 9 of the KVKK.
The same problem can arise where:
- backups are stored abroad;
- databases are replicated to foreign regions;
- customer-support information is sent to a foreign SaaS provider;
- foreign companies access the data remotely;
- emails are hosted abroad;
- logs are stored in foreign analytics infrastructure;
- or customer information is processed by an overseas AI provider.
The issue should therefore be analysed through the entire data architecture rather than simply asking where the startup’s main database is located.
A Foreign Cloud Provider Can Trigger Article 9 Even If the Startup Never “Exports” a File Manually
Many founders imagine international data transfers as situations where someone downloads an Excel spreadsheet and emails it abroad.
Modern data transfers rarely operate that way.
A cross-border transfer can happen automatically.
For example:
A user registers through a Turkish mobile application.
The user’s email address is transmitted directly through an API.
The information is immediately stored in a database located in Ireland or the United States.
No employee manually transfers the information.
Nevertheless, the infrastructure itself causes the personal data to leave Turkey.
The Personal Data Protection Authority’s approach confirms that the location of cloud infrastructure can be sufficient to create an international transfer issue.
Therefore, startups should map technical data flows instead of relying solely on how the process appears to users.
Did the Turkish Rules on International Data Transfers Change?
Yes.
Article 9 of the KVKK was substantially amended in 2024.
The amended system entered into force on 1 June 2024.
The Personal Data Protection Authority describes the current regime as a hierarchical system consisting essentially of:
- transfers based on an adequacy decision;
- transfers based on appropriate safeguards where no adequacy decision exists;
- exceptional transfers where neither an adequacy decision nor an appropriate safeguard is available.
This reform was particularly important for Turkish technology companies because the previous regime made routine use of international cloud services difficult in practice.
Standard contracts are now one of the principal mechanisms enabling regular international data transfers.
First Requirement: There Must Still Be a Lawful Basis for Processing the Data
International transfer rules do not replace the ordinary processing requirements of the KVKK.
Before asking:
“Can we send this data abroad?”
the startup must first ask:
“Are we legally entitled to process this data in the first place?”
Article 9 requires the existence of one of the processing conditions under Articles 5 or 6, depending on whether ordinary or special-category personal data are involved.
For example, a startup may process customer information because:
- it is necessary for performance of a contract;
- it is necessary to comply with a legal obligation;
- it is necessary for establishment, exercise or protection of a right;
- the legitimate interests condition applies without disproportionately interfering with fundamental rights;
- or another statutory processing basis exists.
Special-category personal data require separate analysis under Article 6.
Accordingly, a compliant international transfer requires both:
a lawful processing basis
and
a lawful international transfer mechanism.
The First International Transfer Route: Adequacy Decisions
Under the current Article 9 framework, personal data may be transferred abroad where:
- one of the processing conditions under Articles 5 or 6 exists; and
- the Personal Data Protection Board has adopted an adequacy decision concerning the relevant country, sector within a country or international organisation.
An adequacy decision essentially means that the Board has determined that the relevant destination provides an adequate level of personal data protection.
However, there is an extremely important practical point for startups in 2026.
As of August 2026, the Personal Data Protection Board has not yet designated any country as providing adequate protection under this mechanism.
The Authority’s current official international transfer page expressly states that no such determination has yet been made.
Therefore, a startup currently using a server in:
- Germany,
- Ireland,
- France,
- the Netherlands,
- United Kingdom,
- United States,
- Canada,
- Singapore,
- or another foreign jurisdiction
cannot simply assume that the destination benefits from a Turkish adequacy decision.
This remains true even if that jurisdiction has extensive privacy legislation.
GDPR Compliance Does Not Automatically Mean KVKK Compliance
This is a particularly important misconception.
A Turkish startup may use a European cloud provider and assume:
“The data is stored in the EU, and the provider complies with GDPR, so KVKK is automatically satisfied.”
That conclusion is incorrect.
The EU’s General Data Protection Regulation and the Turkish KVKK are different legal regimes.
A provider’s compliance with GDPR may be relevant when evaluating security and contractual protections, but it does not replace compliance with Turkish Article 9.
As of August 2026, the Board’s official list does not designate EU countries as adequate destinations under the Turkish KVKK framework.
The startup must therefore identify an appropriate Article 9 mechanism.
The Second Route: Appropriate Safeguards
Because there is currently no country-level adequacy decision, appropriate safeguards are the most important route for routine international transfers by Turkish startups.
Article 9 provides several possible safeguards.
These include:
- agreements between qualifying public bodies with Board authorisation;
- Binding Corporate Rules approved by the Board;
- standard contracts published by the Board;
- and written undertakings containing adequate protective provisions and approved by the Board.
For ordinary startup-to-cloud-provider relationships, the most practically important mechanism is generally the standard contract.
What Is the KVKK Standard Contract?
Following the 2024 reform, the Personal Data Protection Board published standard contractual clauses specifically designed for international transfers.
There are four different standard contract structures:
- Controller to Controller;
- Controller to Processor;
- Processor to Processor;
- Processor to Controller.
The correct contract depends on the roles of the parties in relation to the relevant processing activity.
This classification should not be made merely according to the commercial title used in the SaaS contract.
The startup must determine who actually determines:
- processing purposes;
- processing means;
- instructions;
- and other relevant data-processing decisions.
Example: Turkish Startup Using a Foreign Cloud Provider
Consider a Turkish e-commerce startup.
The startup determines:
- what customer information is collected;
- why it is collected;
- how long it is retained;
- and what commercial purposes the information serves.
The startup stores that information with a foreign cloud infrastructure company that processes the information according to the startup’s instructions.
In a typical structure, the startup may operate as the data controller, while the cloud provider operates as a data processor.
The appropriate standard contract may therefore be the:
Controller-to-Processor Standard Contract.
However, actual provider roles and data flows should always be analysed before selecting a template.
Signing the Standard Contract Can Permit Transfer Without Prior Board Approval
One of the major advantages of the new system is that using the Board-published standard contract does not require obtaining separate permission from the Board before every transfer.
The Authority confirms that where the applicable standard contract is properly concluded, international transfer may take place without an additional prior authorisation.
This has made cloud compliance significantly more workable for Turkish businesses.
However, signing the standard contract creates another procedural obligation.
The Standard Contract Must Be Notified to the Authority Within Five Business Days
Article 9 requires the signed standard contract to be notified to the Personal Data Protection Authority within five business days after signature.
The Authority has created an online Standard Contract Notification Module for this purpose.
This means that a startup should not treat the following as the complete compliance process:
“We signed the contract with the cloud company, so we are done.”
The compliance checklist should include:
- identify the transfer;
- determine the parties’ roles;
- select the correct standard contract;
- complete the required schedules and information;
- obtain valid signatures;
- notify the Authority within five business days;
- maintain evidence of the notification;
- update the documentation where the transfer structure changes.
Missing the notification requirement can itself create regulatory risk.
The KVKK Standard Contract Cannot Be Freely Rewritten
This is another area where companies can make mistakes.
A multinational provider may say:
“We already have our own data processing agreement and international transfer clauses.”
Those contractual documents do not automatically replace the Turkish standard contract.
The Personal Data Protection Authority published further guidance in July 2026 emphasising that, except for clauses expressly designed as optional or alternative provisions, the standard contract text should not be amended by adding, deleting or changing terms.
The Authority’s position is based on the fact that the standard text is deemed to provide the appropriate safeguards only in the form published by the Board.
Therefore, startups should not casually merge the Turkish standard contract into a foreign provider’s global DPA and substantially rewrite its wording.
Can the Standard Contract Be Signed in English?
The Authority has published English translations of the international transfer regulation and standard contract forms for practical use.
However, Turkish formal and notification requirements must still be considered.
Where foreign entities and foreign-language corporate documents are involved, the Authority has issued detailed guidance concerning:
- authorised signatories;
- supporting documents;
- apostille or legalisation;
- and notarised Turkish translations.
Its July 2026 announcement also highlights documentary requirements relevant to international parties.
Startups should therefore treat signature formalities as part of the compliance process rather than merely emailing an unsigned template to the foreign provider.
What Information Does the Standard Contract Cover?
The standard contract framework includes matters such as:
- categories of personal data;
- purposes of transfer;
- recipients and recipient groups;
- technical and administrative security measures;
- additional measures for special-category personal data;
- and other terms relevant to protecting data subjects.
This means the contract cannot be completed accurately without understanding the startup’s data flows.
A company cannot properly fill out the schedules if it does not know:
- which customer information is transferred;
- where it goes;
- why it goes there;
- and what security controls apply.
A data inventory should therefore come before the contract.
What Are Binding Corporate Rules?
Binding Corporate Rules, or BCRs, are another appropriate safeguard recognised under Article 9.
They are mainly relevant to multinational corporate groups that regularly transfer personal data between affiliated entities in different jurisdictions.
The rules must provide an adequate level of protection and require approval by the Personal Data Protection Board.
Once approved, BCRs can facilitate intra-group transfers without requiring a separate transfer authorisation for each individual transaction, provided the applicable legal conditions are satisfied.
For a small independent startup using AWS or another unrelated SaaS provider, BCRs will usually not be the most practical solution.
For a startup that has grown into a multinational corporate group, however, they may become relevant.
Can the Parties Use a Special Written Undertaking Instead?
Yes.
Where a standard contract is unsuitable due to sectoral or regional requirements, Article 9 permits a written undertaking containing adequate safeguards.
However, unlike the standard contract mechanism, this route requires approval by the Personal Data Protection Board before the transfer can proceed on that basis.
For ordinary SaaS and cloud arrangements, startups will therefore frequently prefer the standard contract where available.
Is Explicit Consent Sufficient to Store Data Abroad?
This question requires particular care.
Under the old Turkish system, explicit consent was frequently used as the principal practical basis for international transfers.
The 2024 reform changed the architecture significantly.
Under the current Article 9 regime, explicit consent to international transfer appears within the exceptional transfer mechanism where:
- no adequacy decision exists;
- no appropriate safeguard can be provided;
- the data subject is informed about possible risks;
- and the transfer remains occasional rather than regular.
The Authority expressly states that exceptional transfers apply to activities that are:
- incidental;
- not regular;
- not continuous;
- and occurring only rarely.
Therefore, a startup should generally not design a permanent foreign cloud infrastructure on the theory that every customer can simply tick a “consent to overseas transfer” box.
Why Consent Is Usually Unsuitable for Permanent Foreign Cloud Hosting
Suppose a SaaS startup continuously stores every customer’s account information in a US data centre.
Every new registration results in an automatic international transfer.
Customer data remain there continuously.
Backups are also created there.
This is not a rare or incidental transfer.
It is part of the startup’s regular infrastructure.
Accordingly, attempting to rely exclusively on the exceptional explicit-consent route would be difficult to reconcile with the Authority’s position that Article 9 exceptional transfers must remain non-regular and occasional.
For routine cloud hosting, an appropriate safeguard—most commonly the relevant standard contract—should therefore be considered.
What Is an “Incidental” International Transfer?
An incidental transfer is not intended to become the standard infrastructure of the business.
Examples may, depending on circumstances, include an unusual transfer required:
- for a particular legal claim;
- to perform a specific contract;
- for an emergency;
- or in another limited situation listed under Article 9.
The Authority stresses that these exceptions must be interpreted narrowly.
A startup should not attempt to transform an exception into its normal operating model.
Customer Consent and Privacy Notice Are Different Issues
Even when an appropriate safeguard such as a standard contract is used, the startup must still fulfil its Article 10 information obligation.
The privacy notice should accurately describe, where applicable:
- what personal data are transferred abroad;
- for what purpose;
- to which recipient categories;
- and on what legal basis.
The startup should not confuse:
informing users that data are transferred abroad
with
asking users for explicit consent to that transfer.
Where the transfer is lawfully carried out through a statutory processing condition and an appropriate safeguard, explicit consent may not be the relevant legal mechanism.
This distinction is important because unnecessary use of consent can create inconsistent and misleading privacy documentation.
What If the Customer Withdraws Consent?
This is another reason why a startup should not unnecessarily base essential infrastructure on consent.
If the service can operate only because every customer’s information is continuously stored abroad, but the startup claims that international transfer depends entirely on voluntary consent, the question arises:
What happens when the customer withdraws consent?
A consent-based system must respect the characteristics of valid consent.
Using an appropriate statutory transfer mechanism for regular infrastructure is generally more coherent where the underlying processing also has an appropriate legal basis.
Does Encryption Eliminate the International Transfer Issue?
No.
Encryption is an important security measure.
It can substantially reduce the risk of unauthorised access.
However, simply encrypting personal data before sending it to a foreign data centre does not necessarily mean that no international transfer has occurred.
The information remains personal data if it can be connected to an identifiable individual through available means.
Encryption should therefore be treated primarily as a technical security measure, not as a substitute for Article 9 compliance.
What If the Cloud Provider Cannot Read the Data?
This may affect the risk assessment, but it should not automatically be assumed to eliminate Article 9.
For example, a startup may use:
- end-to-end encryption;
- client-side encryption;
- pseudonymisation;
- key separation;
- or another privacy-enhancing architecture.
These controls can significantly improve protection.
However, the startup must still analyse whether the information remains personal data and whether an international transfer is occurring.
True irreversible anonymisation may remove data from the personal-data regime, but pseudonymised and encrypted data generally remain capable of constituting personal data.
Data Localisation Can Sometimes Be the Simplest Option
Some startups choose to keep personal data inside Turkey.
This may reduce international transfer complexity.
For example, a startup might use:
- a Turkish data centre;
- a Turkish cloud region;
- or a local infrastructure provider.
However, data localisation is not necessarily required under the general KVKK framework for every private business.
The decision may depend on:
- security;
- cost;
- scalability;
- availability;
- sector-specific regulation;
- latency;
- customer expectations;
- and international transfer compliance.
In some regulated industries, separate sector-specific data localisation requirements may apply.
Fintech, payment services, banking, telecommunications, health and other regulated businesses should therefore not analyse the matter solely under the KVKK.
Sector-Specific Rules May Require Turkish Servers
A startup should always ask:
“Does another law or regulator impose data localisation requirements on our industry?”
The answer may be particularly important for businesses operating in:
- banking;
- payment services;
- electronic money;
- insurance;
- telecommunications;
- healthcare;
- public-sector contracting;
- critical infrastructure;
- and other regulated fields.
A transfer may theoretically be permissible under Article 9 of the KVKK but still be restricted under sector-specific legislation.
Therefore, KVKK compliance is necessary but may not always be sufficient.
What About Customer Data Stored in the EU?
Storing information in the EU can be commercially attractive because many cloud providers offer European regions.
However, EU location does not automatically resolve the Turkish international transfer issue.
As of August 2026, the Turkish Personal Data Protection Board has not designated any country as adequate under the current Article 9 mechanism.
Therefore:
AWS Frankfurt
Azure Netherlands
or
Google Cloud Belgium
still require Turkish Article 9 analysis.
The fact that the infrastructure is governed by GDPR is not enough by itself.
What About Servers in the United States?
The same principle applies.
A US server may be used lawfully if the Turkish international transfer requirements are satisfied.
There is no blanket provision stating:
“Personal data can never be stored in the United States.”
Nor is there a blanket rule permitting it simply because the provider is a major multinational corporation.
The startup must identify the applicable transfer mechanism and ensure appropriate contractual and security measures are in place.
The Physical Data Centre Is Not the Only Location That Matters
Modern cloud architecture can be complex.
Suppose a provider promises:
“Your primary data are stored in Frankfurt.”
The startup should still investigate:
- backup locations;
- disaster recovery regions;
- support access;
- subprocessors;
- logging systems;
- telemetry;
- security monitoring;
- technical support;
- and administrator access.
Data may technically be stored in Germany while personnel or subprocessors in another jurisdiction can access the information.
Accordingly, a startup should not rely solely on the marketing label:
“EU Data Residency.”
The legal analysis should examine the complete processing chain.
Subprocessors Can Create Hidden International Transfers
A SaaS provider may use another company to provide:
- hosting;
- customer support;
- analytics;
- security;
- email;
- or infrastructure monitoring.
For example:
Turkish Startup → Foreign CRM Provider → US Cloud Provider → Asian Support Provider.
The startup may think it has only one international recipient.
In practice, multiple organisations may receive or access the information.
This creates an important due diligence requirement.
Before adopting a SaaS provider, startups should review:
- processor lists;
- subprocessor lists;
- countries;
- data locations;
- contractual change procedures;
- and security information.
What If a Foreign Employee Merely Accesses Turkish-Hosted Data?
International transfer analysis is not necessarily limited to physically moving a database.
Where personal data hosted in Turkey are made available to persons or entities located abroad, the startup should consider whether this creates an international transfer.
For example:
- an overseas support engineer remotely accesses Turkish customer records;
- a foreign parent company accesses a Turkish subsidiary’s employee database;
- an overseas contractor administers the platform;
- or a foreign cybersecurity provider reviews identifiable logs.
Data-access architecture should therefore be included in the international transfer inventory.
Keeping the physical server in Istanbul does not automatically guarantee that no international transfer occurs.
Customer Support Systems Are Frequently Forgotten
A startup may keep its main customer database in Turkey while using a foreign customer-support platform.
Users then send tickets containing:
- names;
- email addresses;
- telephone numbers;
- account information;
- complaints;
- screenshots;
- and sometimes identity documents.
Those records may be stored abroad.
As a result, the company may still conduct international data transfers even though its core production database is local.
Every system should be mapped.
Email Can Also Cause International Transfers
Corporate email providers can process significant personal data.
Emails may contain:
- customer information;
- employee information;
- attachments;
- commercial contracts;
- legal documents;
- and support records.
If the email infrastructure is hosted abroad, Article 9 should also be considered.
Startups often review their main databases while completely overlooking:
- Google Workspace;
- Microsoft 365;
- Slack;
- Notion;
- HubSpot;
- Zendesk;
- and similar everyday business tools.
Data mapping should include all major SaaS platforms.
AI Tools Are a New Cross-Border Transfer Risk
Artificial intelligence tools create another significant compliance problem.
Suppose employees copy customer information into a foreign generative AI service.
The company may unintentionally transfer:
- customer names;
- contractual information;
- emails;
- support histories;
- personal identifiers;
- and confidential documents
to foreign infrastructure.
The startup may have carefully structured its AWS transfer but fail to regulate employees’ use of AI tools.
An AI usage policy should therefore specify:
- which tools are authorised;
- what customer information may be uploaded;
- whether enterprise privacy settings are required;
- data retention options;
- model-training controls;
- and international transfer compliance.
Cloud Contracts Should Address Security, Not Only Article 9
International transfer compliance does not remove the startup’s Article 12 security obligations.
The data controller remains responsible for implementing appropriate technical and administrative security measures.
A startup should therefore examine whether the cloud provider offers:
- encryption;
- access logging;
- multi-factor authentication;
- backup protection;
- vulnerability management;
- incident notification;
- business continuity;
- certifications;
- subprocessor controls;
- and deletion procedures.
A signed standard contract does not make an insecure processing architecture lawful.
What Happens If the Foreign Cloud Provider Suffers a Data Breach?
Suppose a Turkish startup lawfully transfers customer information to a foreign cloud processor.
The cloud processor suffers a security breach.
The startup may still have obligations under Turkish law.
The company should have contractual procedures addressing:
- how quickly the processor must notify the startup;
- what information must be provided;
- cooperation with investigation;
- mitigation;
- evidence preservation;
- and communication with regulators.
Because KVKK breach notifications may be time-sensitive, the provider cannot wait weeks before telling the Turkish startup what happened.
Processor incident-response provisions should therefore be examined before signing the commercial agreement.
Data Retention Must Also Work in the Foreign Cloud Environment
A startup may establish a policy stating:
“Customer records are deleted two years after account closure.”
But can the cloud provider actually delete:
- active database records;
- backups;
- logs;
- replicated copies;
- archived data;
- and subprocessor copies?
If not, the written retention policy may not correspond to technical reality.
Cloud compliance should therefore include deletion architecture.
The company should understand:
- deletion requests;
- backup cycles;
- restoration procedures;
- retention defaults;
- and account termination processes.
The Privacy Notice Should Match the Real Server Structure
Another frequent compliance mistake is contradiction between technical reality and legal documentation.
For example:
The privacy notice says:
“Your personal data are stored exclusively in Turkey.”
In reality, the startup uses:
- US analytics;
- European cloud storage;
- foreign email;
- and a global customer-support provider.
This discrepancy can create serious regulatory concerns.
The legal team and technical team should therefore regularly compare:
the privacy notice
with
the actual architecture.
Can a Startup Transfer Special-Category Personal Data Abroad?
Potentially yes, but the compliance analysis is more demanding.
The startup must first identify an Article 6 processing condition for the special-category data.
It must then satisfy Article 9 for the international transfer.
Additional technical and administrative safeguards may also be necessary.
This is particularly important for:
- health-tech startups;
- biometric authentication companies;
- employee-management platforms;
- insurance technologies;
- and certain AI products.
A startup processing medical or biometric information should not adopt foreign infrastructure before conducting a specific legal and security assessment.
Example: SaaS Startup Using European Servers
Consider a Turkish B2B SaaS startup.
The startup processes:
- customer administrator names;
- corporate email addresses;
- login logs;
- IP addresses;
- and user-support records.
The production environment is hosted in Germany.
There is no Turkish adequacy decision concerning Germany as of August 2026.
The startup determines that:
- it is controller for its own customer account information;
- the cloud company is processor for that information;
- Article 5 provides the relevant domestic processing grounds;
- and the Controller-to-Processor Standard Contract is the appropriate international safeguard.
The startup then:
- completes the correct standard contract;
- verifies the foreign company’s signatory;
- completes the transfer description and security schedules;
- signs the agreement;
- notifies the Authority within five business days;
- updates its privacy notice;
- documents security measures;
- and monitors subprocessors.
This is substantially stronger than merely asking customers to accept a broad “international data transfer consent” at registration.
Example: Startup Using Ten Foreign SaaS Providers
Now consider another startup.
It uses:
- AWS;
- Google Workspace;
- Slack;
- HubSpot;
- Zendesk;
- Stripe-related services;
- analytics tools;
- an AI API;
- a marketing automation service;
- and a foreign HR application.
The company says:
“We signed a standard contract with AWS, so our international transfers are compliant.”
That conclusion may be wrong.
Each service may involve separate:
- recipients;
- processor/controller roles;
- data categories;
- countries;
- subprocessors;
- and transfer mechanisms.
Cross-border compliance must be mapped across the entire vendor ecosystem.
Example: Foreign Backup That Founders Did Not Know About
A startup operates its main infrastructure in Turkey.
Its technical team uses an automated backup provider.
Backups are stored in the United States.
The founders believe that all customer data stay in Turkey.
From a KVKK perspective, the backup can create an international data transfer issue.
This illustrates why legal review should involve:
- CTO;
- DevOps personnel;
- security team;
- legal counsel;
- and relevant SaaS administrators.
A legal team cannot identify international transfers simply by reading the company’s website.
What Should Be Included in a Cross-Border Data Transfer Inventory?
A startup should create a dedicated inventory showing:
- processing activity;
- data subject group;
- personal data categories;
- special-category information;
- recipient;
- recipient role;
- country;
- transfer purpose;
- frequency;
- transfer mechanism;
- standard contract type;
- signature date;
- notification date;
- security measures;
- subprocessors;
- and retention arrangements.
This document can become extremely valuable during:
- regulatory audits;
- investor due diligence;
- internal compliance reviews;
- and acquisition processes.
International Data Transfers and Venture Capital Due Diligence
Investors increasingly investigate how startups manage international data transfers.
A venture capital fund may ask:
- Where is customer data stored?
- Which cloud provider is used?
- Which server region?
- Are data transferred abroad?
- Which Article 9 mechanism applies?
- Are standard contracts signed?
- Were they notified within five business days?
- Are subprocessors identified?
- Does the privacy notice disclose foreign transfers?
- Has the startup received complaints concerning international transfers?
A startup that cannot answer these questions may face:
- conditions precedent;
- corrective compliance requirements;
- additional warranties;
- indemnification;
- or valuation concerns.
Data architecture has therefore become part of investment readiness.
Cross-Border Data Transfers During Startup Acquisitions
The issue is even more significant during an acquisition.
Suppose an international buyer intends to purchase a Turkish consumer startup with two million users.
During due diligence, it discovers:
- all data have been stored in the United States for four years;
- the privacy notice inaccurately says data are stored in Turkey;
- no Article 9 mechanism was implemented;
- several undisclosed subprocessors exist;
- and the company cannot identify where historical backups are located.
The buyer is not simply purchasing customer information.
It may be acquiring regulatory exposure.
The buyer may therefore require remediation before closing.
Practical Checklist Before Moving Customer Data to Foreign Servers
Before using foreign hosting, a startup should ask:
- What personal data will be stored abroad?
- Are special-category personal data included?
- What is the purpose of processing?
- What Article 5 or Article 6 processing basis applies?
- Which company will receive the data?
- Is the recipient a controller or processor?
- In which country is the primary server located?
- Where are backups stored?
- Where are disaster recovery systems located?
- Can foreign support staff access the data?
- Are subprocessors involved?
- Which countries are subprocessors located in?
- Is there an adequacy decision?
- If not, what appropriate safeguard will be used?
- Which standard contract model applies?
- Has the standard contract been completed without prohibited modifications?
- Are signatories properly authorised?
- Are foreign corporate documents required?
- Are translations or apostilles required?
- Has the contract been notified within five business days?
- Does the privacy notice accurately describe foreign transfers?
- Are security measures sufficient?
- Is encryption used?
- Can data be deleted when required?
- Does the processor provide timely breach notification?
- Are retention and backup periods known?
- Is sector-specific data localisation legislation applicable?
- Are AI tools creating additional transfers?
- Are employee SaaS tools included in the transfer inventory?
- Can the startup produce all this documentation during investor due diligence?
If these questions cannot be answered, moving personal data abroad should not be treated as a routine technical decision.
Frequently Asked Questions About Storing Customer Data Abroad
Is it illegal to store Turkish customer data outside Turkey?
No. The KVKK does not impose a general rule requiring every private company to store all personal data inside Turkey. However, foreign storage generally constitutes an international transfer and Article 9 must be satisfied.
Does using AWS, Azure or Google Cloud automatically violate the KVKK?
No. International cloud services can potentially be used lawfully if the relevant processing and international transfer requirements are met.
Does choosing an EU server automatically make the transfer lawful?
No. As of August 2026, the Personal Data Protection Board states that it has not yet designated any country as an adequate destination under the Article 9 mechanism.
Do I need customer consent to use a foreign cloud server?
Not necessarily. Under the current system, routine transfers may instead rely on a lawful processing condition together with an appropriate safeguard such as the applicable standard contract. Explicit consent under the exceptional transfer mechanism is designed for incidental transfers where the statutory conditions are satisfied, not as the default basis for continuous cloud architecture.
Is storing a backup abroad also a transfer?
Yes, where the backup contains personal data, storing it in a foreign data centre should be analysed as an international data transfer.
What is the most practical Article 9 mechanism for a Turkish startup?
For many routine transfers to unrelated foreign cloud or SaaS processors, the relevant standard contract published by the Board may be the most practical mechanism.
Must the standard contract be approved by the Board first?
The Board’s published standard contract can permit transfer without separate prior approval when properly used. However, the signed contract must be notified to the Authority within five business days.
Can we change the Turkish standard contract to match the cloud provider’s global terms?
Only within the limited optional or alternative provisions allowed by the standard text. The Authority’s July 2026 guidance warns against additions, deletions or modifications to the mandatory clauses.
Does encryption mean Article 9 no longer applies?
Not automatically. Encryption is an important security measure but does not necessarily remove personal information from the KVKK regime.
What if all servers are in Turkey but foreign technical personnel can remotely access customer data?
The company should still analyse whether making data accessible abroad creates an international transfer.
Can special-category personal data be stored abroad?
Potentially, but the startup must satisfy both the relevant Article 6 processing condition and the Article 9 international transfer requirements, together with additional security obligations.
Conclusion: Is It Lawful to Store Customer Data on Foreign Servers Under Turkish Law?
Yes, storing customer personal data on servers outside Turkey can be lawful.
However, foreign cloud storage is not merely a technical hosting choice.
Under the KVKK, it ordinarily creates an international personal data transfer and therefore requires compliance with Article 9.
The Turkish Personal Data Protection Board has already made clear in its enforcement practice that using systems whose servers are located abroad may constitute international data transfer.
The current Article 9 system, effective since 1 June 2024, follows a hierarchical structure.
The first possibility is an adequacy decision.
However, as of August 2026, the Personal Data Protection Board states that it has not yet designated any country as providing adequate protection under the current system.
For most Turkish startups using routine international cloud infrastructure, this means the focus shifts to appropriate safeguards.
These include:
- standard contracts;
- Binding Corporate Rules;
- approved written undertakings;
- and certain arrangements involving public institutions.
For an ordinary startup using an unrelated foreign SaaS or cloud provider, the applicable Board-published standard contract will often be the most practical solution.
The startup must determine whether the transfer is:
- controller to controller;
- controller to processor;
- processor to processor;
- or processor to controller.
The appropriate standard contract should then be signed and notified to the Personal Data Protection Authority within five business days.
Startups should also take account of the Authority’s July 2026 guidance.
The mandatory standard contract text should not be freely rewritten. Except for provisions specifically designated as optional or alternative, additions, deletions and modifications can undermine the standard-contract mechanism.
Perhaps the most important mistake to avoid is relying automatically on explicit consent.
Under the amended Article 9 framework, risk-informed explicit consent appears among the limited exceptional transfer grounds applicable where no adequacy decision or appropriate safeguard exists.
The Authority emphasises that these exceptional transfers must be incidental, irregular, non-continuous and rare.
A startup whose entire customer database is continuously stored on a foreign cloud provider should therefore not assume that a permanent checkbox stating:
“I consent to the transfer of my data abroad”
is the ideal legal architecture.
Regular infrastructure should be structured through a mechanism designed for regular transfers.
The correct compliance analysis should instead ask:
What personal data do we transfer?
Why do we process them?
Which Article 5 or Article 6 legal basis applies?
Where is the primary server?
Where are the backups?
Which company receives the data?
Is the recipient a controller or processor?
Which subprocessors can access the information?
What Article 9 safeguard applies?
Has the correct standard contract been signed?
Was it notified within five business days?
Does our privacy notice accurately describe the transfer?
Can we delete the data when required?
What happens if the cloud provider suffers a breach?
The legal review should also extend beyond the main cloud provider.
A startup may store its main database in Turkey but still transfer personal data abroad through:
- corporate email;
- CRM systems;
- customer-support software;
- analytics tools;
- marketing platforms;
- collaboration software;
- remote technical support;
- and generative AI applications.
For this reason, international data transfer compliance requires a complete data-flow map, not merely a server-location certificate.
Founders should also remember that the KVKK is not always the only relevant legislation.
Startups operating in highly regulated sectors may face additional data localisation or technology infrastructure requirements.
The rules applicable to banking, financial technology, payment services, healthcare, telecommunications or other regulated businesses may impose requirements beyond the general KVKK framework.
The safest approach for a Turkish startup is therefore not to reject international cloud services entirely.
International infrastructure may provide significant benefits in:
- scalability;
- cybersecurity;
- reliability;
- performance;
- disaster recovery;
- AI functionality;
- and global expansion.
The objective should instead be to make the technology architecture legally compliant.
A startup should know:
where its customer data are located,
who can access them,
why they are transferred,
under which contractual mechanism the transfer occurs,
and
how those transfers can be demonstrated to the Personal Data Protection Authority, customers and investors.
When these questions are addressed before migration, using foreign servers can form part of a legally sustainable cloud strategy.
When they are ignored, the same cloud architecture can become a major regulatory, cybersecurity and investment due diligence risk.
For technology startups in Turkey, the key principle is therefore simple:
Customer data do not necessarily have to remain physically in Turkey—but they cannot legally be sent abroad without a compliant legal transfer structure.
No Responses