Erdem & Erdem Law Office

Erdem & Erdem Law Office

Turkey

News and developments

Cross-Border Transfers of Personal Data and Direct Collection: An Assessment within the Framework of EU and Turkish Law

Introduction

Driven by an increasingly globalized world economy, the rapid pace of digitalization, the widening prevalence of multinational corporate structures, and the deepening integration of technological tools into business operations, the cross-border flowof personal data has come to constitute an inescapable and ongoing feature of contemporary commerce. The regulatory framework governing such transfers ought not, however, to be regarded as a mere technical adjunct to data protection law. On the contrary, the rules applicable to cross-border flow of personal data discharge a pivotal and strategic function in relation to economic growth, the investment climate, the facilitation of international trade, and competitiveness within digital markets — since the commercial exploitation of personal data underpins the expansion of digital trade and materially contributes to broader economic growth.[i]

To address the imperatives arising from cross-border data flows, substantial amendments were made to the Personal Data Protection Law No. 6698 ('Law') by Law No. 7499, published in the Official Gazette on 12 March 2024, encompassing provisions on the cross-border transfer of personal data ('Amendment Law').[ii] Through these amendments, a framework broadly aligned with the international data transfer regime under the European Union's ('EU') General Data Protection Regulation 2016/679 ('GDPR') was put in place. As noted in the Guideline on the Transfer of Personal Data Abroad ('Guideline')[iii] published by the Personal Data Protection Authority ('Authority') in January 2025, the preamble to Amendment Law acknowledges that, following the entry into force of the GDPR, the alignment of the Law with the GDPR was incorporated into various governmental action plans and that, in this context, the provisions governing cross-border transfers of personal data were identified as a legislative priority.

It does not follow that every data flow involving a foreign element is automatically to be characterized as a cross-border transfer of personal data. Where a controller established abroad directly collects personal data from a data subject located in Türkiye, it must be emphasized that such collection does not, in itself constitute a cross-border transfer of personal data. Notwithstanding this, in practice, a substantial number of processing activities involving a foreign dimension continue to be treated as falling within the ambit of cross-border transfers, and the conceptual demarcation between the direct collection of personal data and the cross-border transfer thereof is frequently drawn inaccurately.

This article analyses two distinct legal categories — the cross-border transfer of personal data and its direct collection — which are frequently conflated in practice, within the Turkish and EU data protection regulatory framework.

The Regulatory Framework Governing Cross-Border Personal Data Transfers under the GDPR and the Law

The procedures and principles governing the cross-border transfer of personal data, as introduced by the Amendment Law, are laid down in Article 9 of the Law, in parallel with the tiered compliance structure adopted under the GDPR, whilst the detailed provisions governing such transfers are set out in the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad[iv] ('Regulation').

Pursuant to the Regulation, the cross-border transfer of personal data is defined as 'the transmission of personal data from a data controller or data processor subject to Law to a data controller or data processor established abroad, or making such data accessible to them by any other means'. The Guideline elaborates upon this definition and, in so doing, clarifies the ambit of the concept and espouses a broad interpretation of what is to be regarded as constituting a transfer.

The Guideline stipulates that three cumulative conditions must be met for an activity to be characterized as a cross-border transfer of personal data: (i) the data exporter must be subject to the Law with respect to the relevant personal data processing activity; (ii) the personal data processed by the data exporter must be transmitted to, or otherwise made accessible by, the recipient; and (iii) the data controller or data processor to whom the personal data is transferred must be established in a third country, irrespective of whether that recipient is itself subject to the Law. The Guideline further furnishes concrete examples of circumstances that may be regarded as constituting such transfers. To this end, the Guideline identifies operations such as creating an account for systems situated in Türkiye, granting access rights to an existing account, approving or accepting a valid request for remote access, inserting a storage device, or disclosing a file password, as well as providing remote access from a third country to a system situated in Türkiye — even where the personal data is merely viewed on screen — as falling within the category of cross-border transfers of personal data.

The expansive interpretive approach adopted in the Guideline with respect to the concept of cross-border data transfers finds a clear parallel in EU supervisory practice. In this regard, the European Data Protection Board's ('EDPB') Guidelines on the Interplay between the Application of Article 3 of the GDPR and the Provisions on International Transfers under Chapter V of the GDPR[v] ('EDPB Guidelines') provide that a cross-border transfer occurs where the data exporter transmits personal data to a recipient outside the EU or otherwise makes such data accessible from outside the EU. The EDPB equally adopts a broad interpretation of the concept of making personal data accessible; accordingly, remote access from outside the EU in the context of IT support or troubleshooting activities may fall within this concept, even where the personal data is merely viewed on screen. The interpretive stance articulated in the Guideline may therefore be regarded as substantially consistent with the supervisory position and interpretive practice developed by the EDPB.

Where a cross-border transfer of personal data exists in the sense described above, the rules governing such transfers will apply under both Turkish legislation and the GDPR. In such circumstances, the transfer must be assessed within the tiered compliance framework established under Article 9 of the Law and Chapter V of the GDPR. Subject to the presence of a legal basis for processing, personal data may be transferred abroad in the first instance on the basis of an adequacy decision — issued by the Personal Data Protection Board ('Board') in respect of transfers from Türkiye, or by the European Commission ('Commission') in respect of transfers from the EU — covering the relevant country, international organisation, or sectors within a country. In the absence of an adequacy decision, transfers from Türkiye require that the data subject is able to exercise their rights and access effective remedies in the destination country, and that one of the appropriate safeguards under Article 9 of the Law is put in place — such as the conclusion of standard contractual clauses or the adoption of binding corporate rules — whereas transfers from the EU must be founded upon one of the appropriate safeguards provided for under Article 46 et seq. of the GDPR. Where these conditions cannot be satisfied, the transfer may only be affected based on one of the derogatory grounds for exceptional and occasional transfers exhaustively provided for under the Law.

Distinguishing Direct Collection of Personal Data by Controllers Established Abroad fromCross-Border Transfers under the GDPR and the Law

As set out in the preceding section, where a cross-border transfer of personal data is engaged, the specific rules and obligations governing such transfers become operative. It is accordingly of fundamental importance to draw a clear legal distinction between cross-border transfers, properly characterized, and situations that may superficially resemble such transfers in practice but do not attract that legal characterization.

In practice, scenarios involving the direct collection of personal data are frequently mischaracterized as cross-border transfers, with the consequence that the transfer mechanisms applicable to the latter are applied erroneously. The Guideline, however, expressly provides that instances in which data controllers or data processors established abroad collect personal data directly from data subjects are not to be regarded as cross-border transfers of personal data within the meaning of Article 9 of the Law. By way of illustration, the Authority treats data subjects situated in Türkiye directly submitting their name, surname, and e-mail address via a form on an online retail website operated by a company established abroad that directs its activities at the Turkish market as constituting direct collection of personal data, confirming that the cross-border transfer rules under Article 9 of the Law would not be engaged in such a scenario. The Guideline further clarifies, however, that where the party that directly collected the data subsequently transmits such data to a processor situated outside Türkiye, that subsequent activity will be characterized as a cross-border transfer under the Law and the rules governing  cross-border transfers of personal data will accordingly apply. In respect of such subsequent transfers effected by the party established outside Türkiye that directly collected the personal data, one of the appropriate safeguards prescribed under Article 9/4 of the Law must be put in place — such as the conclusion of standard contractual clauses or, in the case of intra-group transfers, the adoption of binding corporate rules.

The position established under Turkish law with respect to the direct collection of personal data from data subjects by a data controller established abroad is equally recognised under EU law. The EDPB Guidelines confirm that cases involving the direct collection of personal data from the data subject fall outside the rules and procedures on international transfers prescribed under Chapter V of the GDPR. It should be borne in mind, however, that a data controller established abroad nonetheless remains bound by the GDPR and continues to be accountable for its processing activities, irrespective of where those activities are carried out. In the illustrative online retail example provided in the EDPB Guidelines, a data subject residing in Italy directly submitting her name, surname, and postal address via a form on a website operated by a third-country company that has no establishment in the EU but directs its activities at the EU market does not constitute an international transfer within the meaning of Chapter V of the GDPR, since the personal data is not transmitted by a data exporter but is directly collected from the data subject by the controller established in a third country. Notwithstanding this, as the processing activities of that company fall within the territorial scope of the GDPR by virtue of Article 3(2), the company remains subject to all obligations arising under the GDPR.

Conclusion

In summary, the accurate demarcation between the cross-border transfer of personal data and the direct collection of personal data from data subjects by a controller established abroad carries considerable practical significance for determining the applicable compliance mechanisms. In practice, the erroneous characterization of direct collection scenarios as cross-border transfers may result in the unnecessary deployment of transfer safeguards. This may, in turn, generate additional compliance burdens and risks — most notably in relation to standard contractual clauses, in view of the associated notification obligation owed to the Authority. In this respect, the Turkish and EU data protection regulatory frameworks and their respective supervisory practices are substantially aligned. Under both regimes, cases in which personal data is directly collected from data subjects by controllers established abroad are not treated as cross-border transfers, assessed by reference to comparable criteria, whilst this treatment does not discharge the relevant controller from its obligations under the applicable data protection legislation.

Author: Ozan Akman, Erdem & Erdem Senior Associate

[i] Yakovleva, S. “Personal Data Transfers in International Trade and EU Law: A Tale of Two “Necessities”, Journal of World Investment & Trade (2020) 1-39, p.2-3.

[ii] Law No. 6698 on the Amendment of the Code of Criminal Procedure and Certain Laws, including provisions on the Law on the Protection of Personal Data, was published in the Official Gazette dated 12.03.2024 and numbered 32487. The amendments entered into force on 01.06.2024 and existing first paragraph of Article 9, which regulates the procedures and principles regarding the transfer of personal data abroad, continued to be applied until 01.09.2024 with the amended version of the article.

[iii] Personal Data Protection Authority, “Kişisel Verilerin Yurt Dışına Aktarılması Rehberi” (Date of Access: 20.04.2026).

[iv] Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad published on the Official Gazette No. 32598 dated 10.07.2024

[v] European Data Protection Board, Guidelines 05/2021 on the Interplay Between the Application of Article 3 and the Provisions on International Transfers as per Chapter V of the GDPR (Date of Access: 20.04.2026)