Cyber Security

KVKK Technical Measures: Compliance Guide for IT Infrastructure

6 min read 21 June 2025

What Are KVKK Technical Measures?

The Personal Data Protection Law No. 6698 (KVKK) requires that both administrative and technical measures be taken when processing personal data. The Personal Data Security Guide published by the Personal Data Protection Board lists technical measures under specific headings.

Mandatory Technical Measures

1. Access Controls and Authorization

Principle of least privilege: Employees should only be able to access the data required for their duties.

  • Role-based groups should be created in Active Directory
  • Database access should be restricted at the user level
  • Privileged accounts (admin) should not be used for daily operations
  • Upon employee departure, accounts must be disabled immediately

2. Authentication

  • Password policy: Minimum 8 characters, complexity rules, 90-day rotation (enforced via Group Policy)
  • Multi-factor authentication (MFA): Mandatory for remote access, email, and critical systems
  • Account lockout: Automatic lockout after 5 failed login attempts

3. Encryption

Encryption is mandatory for systems containing personal data:

ScenarioEncryption Method
Disk/storageBitLocker (Windows), LUKS (Linux)
DatabaseTDE (Transparent Data Encryption)
Network trafficTLS 1.2+, VPN
EmailS/MIME or encrypted email gateway
BackupsEncrypted backups (AES-256)

4. Log Management and Monitoring

Under KVKK, access logs for personal data must be maintained and retained for a specified period:

  • Who accessed which data, and when?
  • Failed login attempts to systems
  • Data export operations
  • Administrator actions

Recommended retention period: Minimum 2 years (subject to Board decisions)

SIEM (Security Information and Event Management) systems can be used for centralized log management.

5. Network Security

  • Firewall: Systems processing personal data should be kept in a DMZ or isolated segment
  • IPS/IDS: Intrusion detection and prevention
  • DLP (Data Loss Prevention): Preventing personal data from leaving the organization through unauthorized channels
  • Network segmentation: Isolation of sensitive systems using VLANs

6. Vulnerability Management

  • Tracking and applying operating system and software patches
  • Antivirus/EDR solution (endpoint security)
  • Regular vulnerability scans
  • WAF (Web Application Firewall) for web applications

7. Physical Security

  • Access to the server room must be controlled and logged
  • Camera systems and visitor records must be maintained
  • Screen lock policy on workstations (5–10 minutes)

Data Breach Notification Process

KVKK requires that personal data breaches be reported to the Personal Data Protection Authority within 72 hours. To meet this requirement:

  1. Incident detection mechanisms (SIEM, IDS) must be implemented
  2. An Incident Response Plan must be documented in writing
  3. Responsibilities and notification procedures must be defined in advance

The Relationship Between KVKK and ISO 27001

ISO 27001 Annex A controls and KVKK technical measures overlap to a significant degree. An organization holding ISO 27001 certification already satisfies a substantial portion of the KVKK technical measures. For this reason, running both processes together provides efficiency gains.

Conclusion

KVKK technical measures are not abstract legal obligations; they are concrete IT security controls. From access management to encryption, from log records to network segmentation, every measure covers security practices that should already be implemented in today's cyber threat landscape. NRC Sistem provides consulting services for KVKK-scoped IT infrastructure audits, technical measure implementation, and process documentation.

All posts