KVKK and Foreign Patients: How Are Medical Records Protected in Turkey?
Foreign patients receiving medical treatment in Turkey inevitably provide some of their most sensitive personal information to hospitals, doctors, laboratories and medical tourism providers.
A patient undergoing surgery may provide:
- passport details;
- medical history;
- current medications;
- allergy information;
- laboratory results;
- radiological images;
- photographs;
- operative reports;
- anaesthesia records;
- genetic information;
- billing information.
A cancer patient may have pathology reports and genetic-testing data.
An IVF patient may have fertility, reproductive and embryology records.
A cosmetic surgery patient may have detailed photographs showing the face or body.
A bariatric surgery patient may have extensive laboratory, imaging and postoperative monitoring information.
For international patients, those records may later need to be transferred to doctors in another country.
This raises several important legal questions:
Who owns or controls the medical file?
Can the patient obtain a copy?
Can a Turkish hospital send records to the Ministry of Health?
Can the clinic share them with a medical tourism agency?
Can the records be transferred abroad?
Can the patient ask for correction or deletion?
What happens if the hospital database is hacked or medical information is sent to the wrong person?
Turkey regulates these issues through several overlapping legal regimes.
The most important are:
Law No. 6698 on the Protection of Personal Data — commonly referred to as the KVKK;
the Patient Rights Regulation;
the Basic Health Services Law;
and, where the patient travels to Turkey specifically for healthcare, the International Health Tourism and Tourist Health Regulation.
Foreign nationality does not exclude a patient from these protections.
The Patient Rights Regulation expressly covers official and private healthcare institutions and the individuals entitled to receive healthcare services.
For international medical tourists, the 2025 International Health Tourism Regulation additionally requires healthcare providers to process recorded personal health information in compliance with the KVKK and the health-data provisions of Turkish healthcare law.
Accordingly, a foreign patient who receives treatment in Turkey should not assume that his or her medical record becomes the unrestricted property of the clinic.
The hospital may have important legal reasons to create, process, preserve and transmit medical records.
But those powers are not unlimited.
What Counts as Personal Health Data Under the KVKK?
Under Turkish data-protection law, health data belongs to the category of special-category personal data — özel nitelikli kişisel veri.
The Personal Data Protection Authority explains that health, genetic and biometric information receive enhanced protection because disclosure can expose individuals to discrimination, unfair treatment or serious privacy harm.
Medical information can therefore include much more than a formal hospital diagnosis.
Depending on the case, protected health information can include:
- diagnosis;
- blood tests;
- pathology reports;
- prescriptions;
- medical history;
- allergy records;
- pregnancy information;
- fertility treatment;
- genetic results;
- psychiatric information;
- radiological images;
- surgical photographs;
- disability information;
- medication records.
Even a document showing that a person visited a particular specialist can reveal health-related information.
For example, identifying a patient as receiving treatment from an oncology, fertility or psychiatric clinic may itself expose sensitive information about that person.
Why Does Turkish Law Treat Medical Data More Strictly?
Health information can affect almost every aspect of a person’s private life.
Unauthorised disclosure could reveal that a person:
- has cancer;
- is undergoing fertility treatment;
- has a genetic condition;
- has undergone cosmetic surgery;
- has a psychiatric diagnosis;
- is receiving treatment for a chronic disease.
Such information can potentially affect employment, insurance, reputation, family relationships and personal dignity.
For that reason, Article 6 of the KVKK creates specific rules for processing special-category personal data.
Turkey amended Article 6 in 2024.
The current version no longer treats explicit consent as the only possible route for processing sensitive information. It permits processing under several defined legal conditions, including where processing by persons under confidentiality duties or authorised institutions is necessary for public health, preventive medicine, medical diagnosis, treatment and care, or healthcare planning, management and financing.
This is particularly important for patients.
A hospital does not need to ask:
“Do you consent to us recording your blood pressure?”
every time a medically necessary observation is entered into the patient file.
There may already be a statutory legal basis for that healthcare processing.
But the same rule cannot automatically justify using those medical records for unrelated purposes.
Can a Turkish Hospital Process Medical Records Without Explicit Consent?
Yes, potentially.
This is often misunderstood.
Healthcare providers may have a lawful basis to process medical information even without relying on explicit consent.
A major statutory development occurred in January 2025.
Law No. 7538 added Additional Article 19 to the Basic Health Services Law No. 3359.
The provision states that personal data which individuals must provide when applying to public or private healthcare institutions or healthcare professionals, together with data relating to the healthcare provided to them, may be processed as required for healthcare services.
It further permits the Ministry of Health to process such information for purposes including:
- healthcare provision;
- protection of public health;
- preventive medicine;
- medical diagnosis;
- treatment and care;
- healthcare planning;
- healthcare cost calculations.
The provision also states that these data cannot be transferred outside the conditions permitted by the KVKK.
This means that lawful medical-record processing does not necessarily depend on a broad signed consent form.
The relevant legal basis may instead arise directly from healthcare law and Article 6 KVKK.
Does This Mean the Hospital Can Do Whatever It Wants With the Records?
No.
A legal basis for treatment-related processing is not a blank cheque.
The healthcare provider must still comply with fundamental data-protection principles.
For example, processing should have:
- a lawful purpose;
- an appropriate legal basis;
- a defined scope;
- necessary security measures.
The Personal Data Protection Authority’s current guidance emphasises that special-category data must be processed on the correct legal basis and with adequate protective measures.
A hospital may legitimately need a CT scan for treatment.
That does not automatically mean the hospital can:
- publish it publicly;
- send it to unrelated businesses;
- give it to a hotel;
- use it for advertising.
The legal basis must correspond to the actual processing activity.
Is the Medical Record Confidential?
Yes.
KVKK protection exists alongside a separate medical-confidentiality regime.
Article 21 of the Patient Rights Regulation states that respect for patient privacy is essential and requires medical evaluations, examinations and treatment to take place with appropriate confidentiality. Persons unrelated to treatment should generally not be present during medical interventions.
Article 23 provides an even clearer rule:
information obtained because healthcare has been provided may not be disclosed except where disclosure is permitted by law.
The Regulation also states that disclosure without a legally and ethically justified basis may lead to legal and criminal responsibility, and that identifying patient information may not be disclosed during research or education without consent.
Accordingly, medical confidentiality is not merely a hospital policy.
It is a legal obligation.
Who Inside the Hospital Can Access the Medical File?
Not every hospital employee should automatically have unrestricted access to every patient’s complete medical history.
Access should correspond to legitimate healthcare or administrative functions.
A surgeon may need access to relevant laboratory and imaging records.
An anaesthesiologist may need information about:
- allergies;
- medication;
- comorbidities.
Nursing staff may need access to treatment instructions and monitoring information.
A billing department may require financial and limited treatment information necessary to prepare the bill.
These are very different from an unrelated employee opening the patient’s file merely out of curiosity.
The healthcare provider must organise access and security in a manner consistent with confidentiality and KVKK obligations.
The 2025 Additional Article 19 also requires the Ministry to create systems capable of monitoring which authorised personnel use healthcare information and for what purpose, illustrating the importance Turkish law places on traceability of access.
Can a Foreign Patient Obtain the Complete Medical Record?
Yes.
Article 16 of the Patient Rights Regulation gives patients a clear right to inspect the file and records containing information about their health.
The patient may inspect the records:
- directly;
- through an attorney;
- through a legal representative.
The patient may also obtain copies.
This right is extremely important for foreign patients after returning home.
A patient may need the Turkish records for:
- continuation of treatment;
- revision surgery;
- a second medical opinion;
- insurance;
- a malpractice investigation.
For example, a foreign patient investigating a surgical complication may need much more than the hospital discharge summary.
Relevant records may include:
- operative report;
- anaesthesia chart;
- laboratory results;
- radiology;
- nursing observations;
- vital-sign monitoring;
- informed-consent forms.
A request should therefore describe the records required as specifically as possible.
Can a Turkish Lawyer Obtain the Medical File for a Foreign Patient?
Potentially, yes.
Article 16 expressly permits access through the patient’s attorney.
The hospital may request evidence demonstrating the representative’s authority.
This is particularly useful for patients who have already returned abroad.
An appropriately authorised Turkish lawyer may therefore be able to request the medical records without the patient having to travel personally to the hospital.
The exact power-of-attorney formalities should be checked according to the patient’s country and the authority required.
What If the Medical Record Contains an Error?
Patients also have a right to seek correction.
Article 17 of the Patient Rights Regulation permits patients to request:
- completion of incomplete information;
- explanation of unclear information;
- correction of inaccurate medical or personal data.
This right should be distinguished from rewriting medical history simply because the patient disagrees with a physician’s professional opinion.
For example, a patient can legitimately challenge factual errors such as:
“The record states that I smoke, but I have never smoked.”
“The hospital recorded the wrong date of birth.”
“The record says I have a penicillin allergy, but that information belongs to another patient.”
Corrections can be particularly important because incorrect records may affect future medical treatment.
The KVKK independently gives data subjects the right to request correction of incomplete or inaccurately processed personal data.
What Rights Does Article 11 KVKK Give a Foreign Patient?
Article 11 provides a powerful set of rights.
A data subject may apply to the data controller and request information concerning personal data processed about him or her.
These rights include the ability to:
- learn whether personal data is processed;
- request information about processing;
- learn the purposes of processing;
- determine whether data is used consistently with those purposes;
- learn third parties in Turkey or abroad to whom data has been transferred;
- request correction of incomplete or inaccurate data;
- request deletion or destruction where statutory conditions apply;
- request notification of correction or deletion to recipients;
- object to certain adverse results created solely through automated processing;
- request compensation where unlawful data processing has caused damage.
For foreign patients, the right to identify who received the data can be particularly useful.
Can a Patient Find Out Whether Records Were Shared With a Medical Tourism Company?
Potentially, yes.
Suppose the patient arranged surgery through an international health tourism intermediary.
The patient may want to know whether the hospital sent that company:
- operative reports;
- passport copies;
- photographs;
- laboratory results;
- diagnosis information.
Article 11 allows the patient to request information about third parties to whom personal data has been transferred.
A properly structured KVKK request can therefore ask:
What categories of my personal data were transferred?
To whom?
For what purpose?
On what legal basis?
This can be highly valuable where the medical tourism provider appears to have received more medical information than necessary for its role.
Can a Medical Tourism Agency Have Access to the Whole File?
Not automatically.
Some international health tourism intermediaries may genuinely require certain information to coordinate the healthcare service.
However, the amount of medical information provided should correspond to the actual purpose.
For example, a company arranging:
- airport transfer;
- hotel accommodation
would not automatically need complete oncology or genetic records merely to organise those logistical services.
The data-protection principle of purpose limitation and proportionality remains important.
A foreign patient should therefore distinguish:
healthcare provider, from
medical tourism intermediary.
They can have different roles and different lawful reasons for processing data.
What Records Are International Health Tourism Providers Required to Keep?
The International Health Tourism and Tourist Health Regulation published on 26 April 2025 contains specific record obligations.
Article 8 requires healthcare facilities providing international health-tourism services to use a health information management system registered within the Ministry’s registration system for recording and archiving healthcare services.
It expressly requires personal health data recorded by the facility to be processed in accordance with:
- the KVKK;
- Additional Article 19 of Law No. 3359.
The data is also transferred to the Ministry’s central health data system according to Ministry procedures.
This is particularly important because patients sometimes assume:
“I only gave the information to the private clinic.”
In reality, Turkish healthcare regulations can require certain information to be reported or transferred to authorised public health systems.
A legally mandated transfer to the Ministry is not automatically a privacy violation.
Why Does the Ministry of Health Receive Patient Information?
Turkey’s healthcare system relies on central health information systems for functions including:
- healthcare provision;
- public-health management;
- treatment planning;
- healthcare administration.
The 2025 statutory framework specifically authorises the Ministry to process healthcare information for defined health-related purposes while requiring security measures and compliance with KVKK transfer conditions.
Therefore:
hospital → Ministry
is legally different from:
hospital → unrelated commercial company.
The legal purpose and statutory authority matter.
Does a Foreign Patient’s Passport Number Also Fall Under the KVKK?
Yes, where it identifies or can identify the individual.
Medical tourism providers commonly process both:
ordinary personal data, such as:
- name;
- passport number;
- telephone;
- address;
and
special-category health data, such as:
- diagnosis;
- medical images;
- laboratory results.
The categories may therefore have different sensitivity but remain within the personal-data framework.
A clinic must protect the entire patient identity ecosystem, not merely the clinical diagnosis.
What About Medical Photographs?
Medical photographs can constitute personal data where the patient is identifiable.
If the photograph reveals healthcare information or treatment status, it may also reveal sensitive medical information.
Clinical photographs may legitimately be used as part of treatment documentation.
But treatment documentation and public publication are separate purposes.
The fact that the patient permitted the hospital to take a photograph does not automatically mean the patient authorised:
- social-media publication;
- clinic advertising;
- the individual doctor’s personal account.
The KVKK Board has previously sanctioned healthcare-related unlawful disclosure of special-category medical information on the internet and social media, emphasising the data controller’s duty to maintain adequate security.
Can a Patient Demand That All Medical Records Be Deleted?
Not automatically.
This is another common misunderstanding.
Article 11 KVKK provides a right to request deletion or destruction in accordance with the statutory conditions.
However, hospitals can have independent legal duties to retain medical records.
Therefore, the patient does not necessarily have an absolute right to say:
“Delete everything immediately.”
A more legally accurate question is:
Does the hospital still have a lawful reason or retention obligation for keeping this particular information?
If the statutory processing conditions have ceased and there is no other lawful retention requirement, deletion or destruction rights may become relevant.
But where healthcare legislation still requires preservation of the record, immediate deletion may not be legally required.
Can a Patient Request Removal of Unnecessary Copies?
Potentially.
The existence of legitimate medical-record retention does not necessarily justify retaining every duplicate copy everywhere indefinitely.
For example, there may be a difference between:
the official medical record that must be retained, and
an optional copy stored by a marketing department.
The legal basis for each processing environment should be considered separately.
This is why a well-drafted KVKK request should identify the disputed category rather than simply demanding deletion of the whole hospital file.
International Transfer: Can Turkish Medical Records Be Sent Abroad?
Yes, potentially, but the transfer must comply with the current KVKK international-transfer framework.
This issue is especially common for foreign patients.
A Turkish hospital may need to send records to:
- the patient’s doctor in London;
- a German pathology specialist;
- an international insurer;
- an overseas laboratory.
Turkey substantially revised Article 9 KVKK in 2024.
The new international-transfer framework entered into force on 1 June 2024.
The regime provides mechanisms based on:
- adequacy decisions;
- appropriate safeguards;
- defined exceptional transfer circumstances.
Appropriate safeguards can include standard contractual clauses and binding corporate rules.
The Authority has published four categories of standard contracts depending on whether the transfer is:
- controller to controller;
- controller to processor;
- processor to processor;
- processor to controller.
Important 2026 Development on Standard Contracts
International data-transfer compliance remains an actively developing area.
On 27 July 2026, the Personal Data Protection Authority published additional guidance on standard contracts.
Among other matters, the Authority emphasised:
- signatures must be valid;
- authorised signatories must be documented;
- Turkish versions must satisfy signature requirements;
- supporting foreign documents can require authentication and Turkish translation;
- standard contractual clauses should not be altered outside the permitted options.
This is relevant to international hospital groups and foreign cloud-service providers storing Turkish patient data.
A Turkish provider should therefore not treat overseas storage as legally irrelevant simply because the patient is foreign.
Does a Foreign Patient Automatically Consent to International Transfer?
No.
A patient’s nationality is not itself a universal international-transfer mechanism.
For example:
“The patient is British, so we can automatically upload all records to a UK server.”
is not a legally sufficient explanation by itself.
The data controller should identify the applicable legal basis and transfer mechanism under Article 9.
Similarly, a foreign patient asking the hospital to send records to his or her own physician abroad may create a different legal situation from the hospital routinely transferring all patient data to an overseas commercial platform.
The context matters.
Can the Hospital Use a Foreign Cloud Provider?
Potentially, provided that the applicable data-processing and international-transfer requirements are met.
Cloud storage may involve an overseas data transfer even where the hospital staff remain physically in Turkey.
The healthcare provider should therefore understand:
- where data is stored;
- which provider has access;
- whether Article 9 applies;
- what safeguard mechanism is used.
This is increasingly relevant as hospitals use international software platforms for imaging, appointments, CRM systems and medical-tourism communication.
What Must a Hospital Tell the Patient About Data Processing?
Under Article 10 KVKK, the data controller has an obligation to provide certain information about the processing activity.
The Personal Data Protection Authority published a particularly relevant public announcement on 27 August 2026.
The Authority emphasised that privacy notices should use:
- understandable;
- clear;
- simple
language.
It warned against vague, incomplete or misleading information.
The notice should separately explain:
- the purpose of processing;
- the legal basis;
- recipient groups;
- transfer purposes.
The Authority also emphasised that general privacy policies should not simply be used as substitutes for processing-specific information notices.
This is particularly important for foreign patients confronted with a long generic “KVKK Consent Form” at hospital admission.
A Privacy Notice and Explicit Consent Are Not the Same Thing
A hospital’s duty to inform the patient should not be confused with asking the patient for consent.
The hospital may have to provide a privacy notice even where the medical processing relies on a statutory healthcare basis rather than explicit consent.
A document saying:
“I have been informed under the KVKK”
does not necessarily mean:
“I consent to every use of my data.”
Likewise, the healthcare provider should not attempt to create a misleading impression that refusal to consent to optional commercial processing means the patient cannot receive medically necessary care.
The correct legal basis must be identified for each processing purpose.
What If the Hospital Refuses to Give the Medical Records?
The patient has several possible legal tools.
The first route may be a direct patient-rights request based on Article 16.
In addition, the patient can use the KVKK application mechanism where the issue concerns personal-data processing.
A formal application can request:
- confirmation that records are processed;
- access to information about processing;
- correction;
- transfer information.
The data controller must generally respond as soon as possible and in any event within 30 days.
Foreign patients should consider making formal, traceable requests rather than relying indefinitely on WhatsApp messages.
How Can a KVKK Application Be Made?
The application should be addressed to the data controller.
Official KVKK guidance recognises methods including:
- written application;
- registered electronic mail — KEP;
- secure electronic signature;
- mobile signature;
- certain registered email methods;
- designated application systems.
Where an attorney submits the application, appropriate authority documentation is required.
The request should clearly identify:
- the patient;
- the requested information;
- the specific Article 11 right being exercised.
For a foreign patient, a lawyer can help avoid procedural problems involving identity verification and representation.
How Long Does the Hospital Have to Reply?
Generally, no later than 30 days.
The data controller may:
- accept the request;
- reject it with reasons.
Where the request is accepted, the necessary action should be taken.
The process is normally free unless the request generates specific additional costs within the permitted tariff framework.
Can the Patient Complain to the Personal Data Protection Board?
Yes, but there is a procedural sequence.
A patient generally must first apply to the data controller before complaining to the Personal Data Protection Board.
If the data controller:
- rejects the application;
- gives an inadequate answer;
- fails to respond within 30 days,
the patient may potentially complain to the Board.
The complaint deadlines are strict.
Where a response is received in time, the patient generally has 30 days from learning of the response to complain.
Where no answer is given, the overall complaint period generally runs 60 days from the initial application.
Foreign patients should not allow these periods to expire while repeatedly sending informal reminders to the clinic.
Can the KVKK Board Award Compensation to the Patient?
A Board proceeding and a compensation claim are not the same thing.
The Board can investigate compliance and impose regulatory measures or administrative sanctions within its powers.
An administrative fine imposed on a hospital is not automatically paid to the patient.
Article 11 separately preserves the data subject’s right to request compensation where unlawful processing causes damage.
The Authority also explains that where personality rights have been violated, general judicial compensation remedies remain available and can exist separately from the Board complaint process.
Therefore:
KVKK complaint = regulatory remedy.
Compensation action = judicial remedy.
They should not be confused.
What Happens if a Hospital Suffers a Data Breach?
A healthcare data breach can be especially serious because the compromised information may include:
- passport data;
- medical diagnosis;
- photographs;
- laboratory results;
- financial information;
- genetic information.
Article 12 KVKK imposes security obligations on data controllers.
Where processed personal information is unlawfully obtained by others, the controller must notify the affected individuals and the Personal Data Protection Authority.
The Board interprets the statutory phrase “as soon as possible” as requiring notification to the Authority without delay and no later than 72 hours after learning of the breach.
Affected data subjects must also be informed within a reasonably prompt period after they are identified.
What Should a Foreign Patient Do After Receiving a Data Breach Notice?
The patient should determine exactly what information was exposed.
Ask whether the breach involved:
- identity documents;
- passport number;
- payment information;
- treatment history;
- diagnosis;
- medical photographs;
- genetic information.
The practical response will depend on the data involved.
For example, theft of a passport copy may create different risks from disclosure of a psychiatric or genetic record.
The patient should preserve the hospital’s breach notification and any later correspondence.
If actual loss occurs, independent compensation issues may also arise.
Can a Hospital Be Responsible if an Employee Leaks the Information?
Potentially.
The data controller’s responsibilities are not necessarily eliminated because an employee or another person physically performed the unauthorised disclosure.
The Personal Data Protection Authority has previously imposed sanctions where healthcare-related special-category data was exposed on social media and the data controller failed to ensure appropriate data security.
Data controllers must take adequate:
- technical measures;
- administrative measures
to protect the information.
This can include:
- access controls;
- staff training;
- system logs;
- confidentiality measures;
- appropriate security architecture.
The patient should therefore consider both the individual disclosure and the healthcare institution’s system-level responsibilities.
What If Medical Records Are Sent to the Wrong Patient?
This is a classic data breach scenario.
For example:
Patient A asks for his medical file.
The hospital accidentally emails him Patient B’s pathology report.
Patient B’s sensitive health information has now been disclosed to an unauthorised third person.
The healthcare institution should treat this as a data-security incident rather than simply saying:
“It was an email mistake.”
The legal importance depends on:
- data exposed;
- number of people affected;
- response by the hospital;
- compliance with notification obligations.
Can Medical Records Be Shared With Family Members?
Not simply because they are relatives.
Patient Rights Regulation Article 20 permits a patient, subject to statutory exceptions, to request that information about his or her health not be given to:
- relatives;
- anyone else.
The decision can be recorded in writing and later changed.
Therefore, a foreign patient’s spouse or parent does not automatically have unlimited rights to the medical file.
Legal representation, patient authorisation and applicable statutory exceptions must be considered.
Can an Insurance Company Obtain the Medical File?
Potentially, where a valid legal basis exists and the information is genuinely necessary for the insurance process.
But the fact that an insurer is paying for treatment should not automatically be understood as unlimited access to every medical record indefinitely.
The nature of the insurance arrangement, applicable law and necessity of the requested information should be evaluated.
Foreign patients should review both:
- insurance authorisations;
- hospital data-transfer notices.
What About WhatsApp and Medical Tourism Communication?
Medical tourism in Turkey frequently relies on WhatsApp.
Patients send:
- photographs;
- pathology reports;
- passports;
- radiology;
- laboratory results.
Convenience does not eliminate data-protection requirements.
The clinic still has to consider:
- who can access the account;
- whether data is sent to the correct person;
- whether retention is necessary;
- whether international data-transfer issues arise.
Patients should also be careful about sending large amounts of sensitive material to unknown numbers before confirming the identity of the healthcare provider or intermediary.
Does the GDPR Replace the KVKK for European Patients?
No.
A French, German or Dutch patient does not automatically fall outside Turkish data law merely because he or she is an EU citizen.
Where a Turkish healthcare provider processes the patient’s information within the Turkish healthcare relationship, the Turkish KVKK framework can apply.
The GDPR may separately apply to a European entity depending on its role and territorial scope.
But nationality alone does not replace KVKK with GDPR.
The practical question is:
Which organisation is processing the information, and under which legal regime?
What Evidence Should a Foreign Patient Preserve in a Medical Data Dispute?
A patient considering a privacy or KVKK claim should keep:
- Hospital treatment contract.
- KVKK privacy notice.
- Explicit-consent forms.
- Medical record requests.
- Hospital responses.
- Screenshots of unlawful publications.
- Emails showing accidental disclosure.
- Data breach notifications.
- Correspondence with medical tourism intermediaries.
- Evidence showing actual financial or non-financial harm.
Where information appeared online, preserve evidence before asking for removal.
Once the hospital deletes the page, proving what was published may become more difficult.
Practical Example 1: Clinic Refuses to Provide Medical Records
A British patient undergoes surgery in Istanbul.
After returning home, complications develop.
The UK surgeon asks for the Turkish operative report.
The clinic ignores several WhatsApp messages.
The patient can rely on Article 16 Patient Rights Regulation to request the record and may additionally use the formal KVKK process concerning personal-data access and processing information.
A formal application also starts the statutory response timetable.
Practical Example 2: Wrong Information in the Hospital File
A German patient discovers that the Turkish hospital record incorrectly states:
“Patient has no drug allergies.”
The patient had actually informed staff of a serious allergy.
Because inaccurate information could affect future treatment, the patient may request correction under both Article 17 Patient Rights Regulation and Article 11 KVKK.
Practical Example 3: Records Shared With a Medical Tourism Agency
A patient purchased surgery through an intermediary.
After treatment, the patient discovers that the intermediary possesses the entire medical file, including photographs and operative records.
The patient may request information concerning:
- what the hospital transferred;
- the recipient;
- purpose;
- legal basis.
Article 11 expressly provides the right to learn third parties in Turkey or abroad to whom personal data has been transferred.
Practical Example 4: Turkish Hospital Sends Records to a Foreign Specialist
A Turkish hospital asks a European specialist to provide a second opinion and transfers medical images abroad.
This may be a legitimate healthcare purpose.
However, the transfer should still comply with the current Article 9 international-transfer rules.
Foreign destination does not eliminate Turkish transfer requirements.
Practical Example 5: Hospital Database Is Hacked
A hospital suffers a cyberattack.
The leaked information includes:
- foreign patient passports;
- diagnoses;
- operative reports.
The institution must evaluate its duties under Article 12 and the Board’s breach-notification framework.
Where unlawful access is established, notification to the Authority must generally occur no later than 72 hours after the controller learns of the breach.
Frequently Asked Questions
Are foreign patients protected by the KVKK?
Foreign nationality does not exclude a patient from the Turkish medical-record protection framework where personal data is being processed by Turkish healthcare providers under Turkish law. The Patient Rights Regulation also broadly covers persons entitled to healthcare in official and private institutions.
Are medical records sensitive personal data?
Health data is expressly classified as special-category personal data under KVKK Article 6. Genetic and biometric data are also specially protected.
Can the hospital legally store my medical records without explicit consent?
Potentially, yes. Current Article 6 KVKK and the 2025 Additional Article 19 of the Basic Health Services Law provide healthcare-related statutory processing bases.
Does that allow the hospital to use my records for advertising?
No automatic right follows. Treatment-related processing and marketing are different purposes requiring separate legal analysis.
Can I obtain a copy of my medical records?
Yes. Article 16 of the Patient Rights Regulation expressly permits a patient to inspect the medical file and obtain copies personally or through an attorney or legal representative.
Can I request correction of inaccurate records?
Yes. Both patient-rights rules and Article 11 KVKK recognise correction rights concerning incorrect or incomplete data.
Can I ask who my medical records were shared with?
Yes. Article 11 includes the right to learn the third parties in Turkey or abroad to whom personal data was transferred.
Can my medical tourism agency receive the file?
Potentially where there is an appropriate lawful basis and the data is necessary for its legitimate role. Being an intermediary does not automatically justify access to the entire medical record.
Are international health tourism records sent to the Ministry of Health?
The 2025 International Health Tourism Regulation requires healthcare facilities to record and archive relevant information through authorised systems and transfer personal health data to the Ministry’s central health data system according to Ministry procedures, subject to KVKK and health-law requirements.
Can my Turkish medical records be transferred abroad?
Potentially, yes, but the transfer must comply with KVKK Article 9. The current framework includes adequacy mechanisms, appropriate safeguards such as standard contracts and limited statutory exceptions.
Did the international-transfer rules change recently?
Yes. The revised Article 9 regime entered into force on 1 June 2024, and the Authority issued additional guidance on standard-contract requirements in July 2026.
Does being a foreign citizen automatically allow overseas transfer?
No. The patient’s foreign nationality is not by itself a universal legal basis for international data transfer.
Can I ask the hospital to delete all records?
Not automatically. Hospitals may have legal obligations requiring medical records to be retained. Deletion rights depend on whether the legal conditions for continuing processing still exist.
How long does a hospital have to respond to a KVKK request?
Generally no more than 30 days.
Can I complain directly to the KVKK Board?
Normally, the patient must first apply to the data controller. If the application is rejected, inadequately answered or unanswered, the patient can consider a Board complaint within the statutory periods.
What are the KVKK complaint deadlines?
Depending on the response, the relevant complaint period is generally 30 days from learning of a timely answer and in appropriate no-response situations no later than 60 days from the original data-controller application.
Can the KVKK Board award compensation?
A Board sanction is not the same as damages paid to the patient. Article 11 preserves the patient’s right to seek compensation where unlawful processing causes damage, and judicial remedies may be available separately.
What happens after a medical data breach?
Where personal data has been unlawfully obtained by others, the data controller must notify the Authority and affected persons under Article 12. The Board interprets notification to the Authority as requiring action no later than 72 hours after learning of the breach.
Can my family access my medical information automatically?
No. Patient-rights legislation permits patients, subject to legal exceptions, to restrict disclosure of their health information to relatives or others.
Does patient confidentiality continue after death?
Yes. Article 21 of the Patient Rights Regulation expressly states that death does not justify violation of medical privacy.
Can a Turkish lawyer request my records while I remain abroad?
Potentially, yes. Article 16 allows access through an attorney, subject to proving the required authority.
Conclusion: Foreign Patients Have Extensive Rights Over Medical Records in Turkey
Medical records are essential to modern healthcare.
Doctors need them to make diagnoses.
Surgeons need them to plan treatment.
Hospitals need them to monitor patients.
The Ministry of Health may lawfully process defined categories of health information for authorised healthcare purposes.
For that reason, Turkish law does not operate on the simplistic principle:
“A hospital cannot process any medical data unless the patient signs an explicit-consent form.”
The current legal framework is more sophisticated.
After the 2024 amendments to Article 6 KVKK, healthcare-related special-category data can be processed under several defined legal conditions, including where necessary for medical diagnosis, treatment and care by authorised institutions or persons subject to confidentiality obligations.
The 2025 amendment to the Basic Health Services Law strengthened that healthcare-specific framework further.
Additional Article 19 now expressly permits processing of information patients must provide when applying for healthcare and information relating to services supplied to them.
The Ministry can also process that information for defined public-health and healthcare purposes, but transfers must remain within KVKK conditions and the Ministry must maintain security and access-control systems.
Foreign medical tourists are incorporated directly into this structure.
The 26 April 2025 International Health Tourism Regulation requires participating healthcare facilities to use registered information systems, archive healthcare-service data and process foreign patients’ personal health information according to KVKK and Additional Article 19.
Relevant data is also transmitted to the Ministry’s central health data system according to applicable procedures.
Therefore, an international patient should understand that some authorised healthcare data processing and public-system reporting can occur even without separate consent for each individual processing step.
But that does not eliminate patient privacy.
The Patient Rights Regulation provides an independent layer of protection.
Patients have the right to confidentiality during medical evaluation and treatment.
Article 23 provides that information acquired because healthcare has been supplied cannot be disclosed outside circumstances permitted by law.
Foreign patients also have strong rights over the medical record itself.
Article 16 allows a patient—or an appropriately authorised lawyer or representative—to inspect the file and obtain copies.
Article 11 KVKK adds an even wider set of information rights.
A patient can ask:
Do you process my personal data?
Why are you processing it?
Who received it?
Was it transferred outside Turkey?
Is the information accurate?
Can any information lawfully be corrected or deleted?
Has unlawful processing caused me damage?
These rights are particularly useful for international patients.
A patient may leave Turkey believing that all medical information remained with one clinic, then discover that:
- a medical tourism agency has copies;
- an overseas company stores the information;
- another specialist received the records.
Article 11 allows the patient to investigate that processing structure.
Cross-border transfers require additional attention.
Turkey fundamentally changed the international-transfer system on 1 June 2024.
The revised Article 9 framework now includes adequacy mechanisms and structured safeguards such as standard contractual clauses and binding corporate rules.
The Authority’s July 2026 guidance demonstrates that compliance remains highly formalised, including rules concerning signatures, foreign supporting documents, translations and alteration of standard clauses.
For a foreign patient, this creates an important principle:
being foreign does not make the medical record legally “international” in a way that allows unrestricted transfer abroad.
A Turkish healthcare provider must still identify the legal mechanism supporting its transfer.
Transparency is equally important.
The Personal Data Protection Authority’s 27 August 2026 announcement expressly warns data controllers to avoid vague privacy notices.
The patient should receive clear and understandable information about:
- processing purposes;
- legal grounds;
- recipients;
- transfer purposes.
A generic hospital privacy policy cannot simply replace activity-specific disclosure.
If a dispute arises, the KVKK provides a practical enforcement mechanism.
The patient may first make an Article 13 application to the data controller.
The healthcare provider generally has no more than 30 days to respond.
If the response is inadequate or absent, the patient may consider a complaint to the Personal Data Protection Board within the applicable statutory deadlines.
However, the patient should remember that a Board proceeding is not the same as a compensation lawsuit.
The Authority itself confirms that judicial compensation rights for personal-rights violations remain available independently of the regulatory complaint mechanism.
Data breaches create yet another layer of protection.
If personal information is unlawfully obtained by third parties, the controller must comply with Article 12.
The Board’s current rule interprets notification to the Authority as requiring action without delay and within a maximum of 72 hours after becoming aware of the breach.
This is especially significant for hospitals because medical databases can contain extraordinarily sensitive combinations of:
identity,
passport,
diagnosis,
genetic,
photographic,
and
financial data.
Ultimately, foreign patients receiving treatment in Turkey should understand one central distinction.
A hospital has legitimate and sometimes mandatory reasons to create and process medical records.
But the existence of those healthcare obligations does not convert medical data into unrestricted commercial information.
Necessary healthcare processing, authorised Ministry reporting, medical confidentiality, patient access rights, international transfer rules and data-security obligations all operate simultaneously.
A foreign patient who wants to protect his or her medical information should therefore keep:
- copies of treatment documents;
- privacy notices;
- KVKK forms;
- medical tourism agreements;
- record requests;
- hospital responses.
Where malpractice is suspected, request the complete medical file early.
Where privacy is suspected to have been breached, preserve evidence before asking for deletion.
Where information may have been transferred to another company or abroad, use Article 11 rights to identify the recipients and legal basis.
And where a healthcare provider refuses to respond, do not overlook the 30-day data-controller response period and the subsequent KVKK Board complaint deadlines.
Foreign patients in Turkey have both a right to receive healthcare and a right to have the medical information created during that healthcare handled lawfully, securely and confidentially.
Legal Disclaimer
This article provides general information concerning KVKK, foreign patients and medical-record protection under Turkish law as of September 2026. It does not constitute individual legal advice.
Whether specific processing, storage, disclosure, deletion or international transfer of medical information is lawful depends on the type of information, identity and role of the data controller, processing purpose, statutory healthcare obligations, applicable KVKK legal basis, retention duties, transfer mechanism and factual circumstances.
Hospitals may be legally required to preserve certain healthcare records despite a patient’s request for deletion.
International transfers should be assessed under the current Article 9 framework, including the amendments effective from 1 June 2024 and subsequent Personal Data Protection Authority guidance.
Foreign patients who believe their medical records have been unlawfully accessed, disclosed, transferred, altered or withheld should preserve the available evidence and obtain case-specific advice concerning patient-rights applications, KVKK requests, Board complaints and judicial remedies.
No Responses