Turkey runs its own data protection regime rather than applying the GDPR directly, built around the KVKK — Law No. 6698 on the Protection of Personal Data. The structure is recognisably similar to the GDPR, but the terminology, the registration duty and the transfer rules are distinctly Turkish. This page sets out that framework, what Turkish and international buyers typically expect, and how lead.box is set up for it.
At a glance
- Framework
- KVKK — Law No. 6698 on the Protection of Personal Data
- Supervision
- Kişisel Verileri Koruma Kurumu (KVKK Authority) and its Board (Kurul)
- Usual legal basis
- Legitimate interest of the data controller, comparable to Art. 6(1)(f) GDPR
- Processing location
- ISO-certified EU data centres
The legal framework in Turkey
Regulation at a glance
- FrameworkKVKK — Law No. 6698 on the Protection of Personal Data
- SupervisionKişisel Verileri Koruma Kurumu (KVKK Authority) and its Board (Kurul)
- Usual legal basisLegitimate interest of the data controller, comparable to Art. 6(1)(f) GDPR
- Processing locationISO-certified EU data centres
Turkey is not an EU or EEA member, and the GDPR does not apply there directly. Instead, Turkey has its own comprehensive data protection statute, KVKK — Law No. 6698 on the Protection of Personal Data (Kişisel Verilerin Korunması Kanunu), in force since 2016 and closely modelled on earlier European data protection law. The structure will look familiar to anyone who knows the GDPR — a lawful basis is required for processing, data subjects have rights of access and objection, and processors act on the instructions of a data controller — but the KVKK uses its own vocabulary and its own procedural requirements, and treating it as a translation of the GDPR understates the differences that actually matter in practice.
Enforcement sits with the Kişisel Verileri Koruma Kurumu, generally referred to as the KVKK Authority, and its decision-making body, the Kurul (Board). The Kurul issues binding decisions, guidance and administrative fines, and its published decisions function similarly to the way GDPR case law and guidance from European supervisory authorities shape practice — they are the reference point a Turkish legal team will consult when assessing a vendor.
The KVKK also establishes VERBIS, the data controllers' registry (Veri Sorumluları Sicil Bilgi Sistemi), which certain data controllers operating in Turkey are required to register with, describing categories of data processed and purposes at a general level. Whether a given company falls under this registration duty depends on criteria set by the Kurul and is assessed case by case; this page does not state thresholds or claim that any particular company is or is not obliged to register, since that determination belongs to the controller itself. Separately, the KVKK sets its own conditions for transferring personal data outside Turkey, distinct from the GDPR's adequacy and standard-clause mechanisms, and a Turkish controller sending data to a processor abroad is expected to satisfy those conditions on its own assessment.
What the Turkish market expects
Turkish exporters and manufacturers sell heavily into European and international buyers, and that orientation shows up in how they evaluate vendors: a request for a data processing agreement, a clear statement of where data is processed, and a plain description of what is collected are treated as ordinary supplier diligence rather than an exceptional demand. A vendor that can answer these points directly, without vague reassurance, tends to move through review faster.
Because the KVKK's international transfer conditions are separate from the GDPR's, a careful buyer will ask specifically how data leaving Turkey is handled rather than assuming a European vendor's usual answer covers it. Being explicit that data is processed in ISO-certified EU data centres, and that the classification of any transfer under the KVKK's own rules remains a decision for the controller, tends to be more useful than a general compliance statement.
The KVKK registration question also comes up in procurement conversations, particularly with larger industrial buyers and public-sector-adjacent projects. The realistic answer here is not a certification claim but a description of what the product does — company-level identification, no advertising identifiers, no device fingerprints — that lets the Turkish controller make its own VERBIS assessment rather than relying on a vendor's characterisation of it.
Start free
Install the snippet and see the first named companies on your own traffic.
What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
Where identification pays off here
Turkey's export-oriented industries — textiles, automotive components, construction and heavy equipment — sell into long, relationship-driven procurement cycles where a foreign buyer's engineering or purchasing team can spend weeks comparing suppliers' technical pages before making contact. Seeing which international company is researching a product page, before an inquiry is sent, gives a Turkish exporter a real opening to reach out with the right technical contact instead of waiting for a generic request for quotation.
The same logic applies to Turkish contractors bidding on construction and infrastructure projects abroad, where a handful of named companies from a specific region or sector matter far more than overall traffic volume. A site with modest weekly visits can still surface a short, workable list of international buyers worth a direct, well-timed call.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Turkey is neither an EU nor an EEA member, so the GDPR does not apply there directly; instead Turkey runs its own comprehensive statute, the KVKK — Law No. 6698 on the Protection of Personal Data — in force since 2016 and closely modelled on earlier European data protection law. The structure will look familiar to anyone who has worked with the GDPR: a lawful basis is required before processing, data subjects hold rights of access and objection, and a processor acts strictly on the controller's documented instructions. Treating the KVKK as a direct translation of the GDPR understates real differences, particularly around the registration duty and cross-border transfer conditions, which follow their own Turkish procedural rules rather than the GDPR's adequacy and standard-clause mechanisms. For company-level website visitor identification, the practical starting point in Turkey is the same question as anywhere else — is personal data of an identifiable individual involved — but the answer has to be documented against KVKK vocabulary and KVKK Board guidance specifically, not against GDPR case law, if it is going to hold up in a Turkish legal review.
Enforcement sits with the Kişisel Verileri Koruma Kurumu, commonly called the KVKK Authority, and its decision-making body, the Kurul, which issues binding decisions, published guidance and administrative fines for non-compliance. The Kurul's decisions function similarly to how GDPR case law and European supervisory guidance shape practice elsewhere: a Turkish legal or compliance team consulted on a new vendor will typically check the vendor's stated positions against specific Kurul decisions on legitimate interest, cross-border transfer or registration duty rather than against the bare statute. That habit means a vendor able to point to how its processing activity maps onto a relevant Kurul decision, rather than offering a generic compliance statement, tends to move through a Turkish review with fewer follow-up questions. The Kurul does not pre-certify vendors or products, and no seal or badge substitutes for the controller's own documented assessment; lead.box supports that assessment with a data processing agreement and technical documentation rather than making the KVKK determination on the customer's behalf.
The KVKK establishes VERBİS, the Data Controllers' Registry, and certain data controllers operating in Turkey are obliged to register there and describe, at a general level, the categories of personal data they process and the purposes behind that processing. Whether a specific organisation falls under this duty depends on criteria the Kurul has set, including factors such as headcount, annual data volume and whether special category data is processed, and that determination is made case by case rather than by a fixed universal threshold. This page deliberately does not state a threshold or claim that any customer is, or is not, obliged to register, because that assessment belongs to the controller and depends on facts about the controller's own organisation that lead.box does not hold. What lead.box can describe is the processing itself: company-level identification, without advertising identifiers or device fingerprints, so that whoever runs your VERBİS assessment has an accurate, specific description of this particular activity to work from rather than a vague vendor characterisation.
The KVKK sets its own conditions for transferring personal data abroad, separate from the GDPR's adequacy decisions and standard contractual clauses, and those conditions were substantially revised by amendments that took effect in September 2024, replacing the earlier permission-based regime with a structure closer to, though still distinct from, the GDPR's own transfer mechanisms. Under the amended rules a transfer abroad can rely on an adequacy decision for the destination country, on Kurul-approved safeguards such as standard contractual clauses adapted to Turkish requirements, or on binding corporate rules, with notification duties to the Kurul depending on the mechanism used. lead.box processes data concerning the EU in ISO-certified EU data centres, which keeps that data within a defined, documented location, but classifying any particular flow out of Turkey under the amended KVKK transfer rules, and choosing the correct safeguard mechanism for it, remains an assessment the Turkish data controller has to make for its own processing activities rather than something a vendor can pre-clear on the controller's behalf.
The KVKK recognises a legitimate interest basis for the data controller that is structurally comparable to Art. 6(1)(f) GDPR, and it is the basis most Turkish organisations rely on for company-level website visitor identification, since the processing serves a clear business purpose — recognising which organisations are researching a supplier — without imposing a disproportionate burden on any individual, because no individual is actually identified. As with the GDPR-based frameworks in neighbouring markets, relying on this basis is expected to be documented rather than asserted: a short written note explaining the purpose, the categories of data involved and why the interest is not overridden by an individual's rights is the kind of record a Turkish compliance reviewer or, in an audit, the Kurul itself would expect to see. Because identification here resolves a company rather than a person, that balancing exercise is comparatively straightforward, but skipping the documentation step and only relying on a vendor's general assurance is the gap that most often draws follow-up questions in a Turkish procurement review.
lead.box resolves an anonymous website visit to the name of the visiting organisation using network-level signals, principally the IP address range associated with a business connection, matched against a maintained company-to-network database; the process does not create or store a cookie, a device fingerprint, an advertising identifier or a cross-site profile, and it does not attempt to identify the individual employee behind a visit. The output delivered to a customer is limited to the company name, an approximate location and the pages viewed during that visit, not a person's name, role or contact details, which is the distinction that keeps this processing activity at the company level rather than the individual level under KVKK terminology. A meaningful share of visits, particularly from residential or mobile connections and from organisations without a dedicated business IP range, cannot be resolved to a company at all, and lead.box does not substitute an estimate or a guess for those visits; unresolved traffic is simply left unidentified rather than presented as a match.
Turkish exporters and manufacturers commonly run a compact commercial team tracking a defined set of named international accounts rather than a large inbound funnel, and CRM discipline ranges from structured Salesforce or HubSpot deployments to lighter spreadsheet-based tracking maintained by the sales office itself. lead.box exports identified companies as CSV or Excel files for that kind of manual review, or pushes matches by webhook into whichever CRM a team already relies on, so the identification layer slots into existing habits rather than requiring the business to adopt a new platform. For teams working export accounts largely by phone, email and in-person visits, a simple weekly export naming which international companies viewed which product or technical pages is often more actionable than a live dashboard, particularly where the buying committee on the other side is a foreign engineering or procurement team evaluating suppliers before making direct contact.
Getting started requires adding a single JavaScript snippet to the site, after which identified companies typically begin appearing within the first days of traffic, without any waiting period tied to a contract term or involvement from a hosting provider beyond a code or tag-manager edit. Accuracy follows the same underlying constraint everywhere the product runs: identification depends on a visit originating from a network range that can be matched to a specific organisation, and traffic from mobile networks, home connections or organisations sharing infrastructure will frequently not resolve to a named company, a limitation that is stated plainly rather than minimised. Teams can add colleagues as additional seats, export lists as CSV, Excel or JSON at any point, and connect a webhook to hand qualified companies to a CRM without manual re-entry; if the tool does not prove useful, cancellation is handled through self-service account settings rather than a notice period or a retention call, which matches the lower-commitment way many Turkish exporters prefer to trial new software before scaling it up.
See which international companies are already on your site
Install a first-party snippet, watch the first companies appear, and hand your compliance contact the documents in the same week.