Platform
Solutions
Resources
Company
Resources
Solutions

KVKK: personal data protection in financial crime analysis

The Law on Protection of Personal Data No. 6698 (KVKK) directly regulates how data used in financial crime and risk analysis must be protected. Two points are decisive: biometric data is classified as special category personal data, and international transfers are subject to an adequacy decision. TruvaLI supports on-premise deployment.

The Law on Protection of Personal Data No. 6698 (KVKK) regulates the procedures and principles for processing personal data. Two of its provisions are directly decisive for financial crime and risk analysis: biometric data is classified as special category personal data, and international transfers are subject to an adequacy decision.

What does the data security obligation require?

Article 12 of the Law obliges the data controller to take all necessary technical and administrative measures for three purposes: preventing unlawful processing of personal data, preventing unlawful access to personal data, and ensuring the preservation of personal data.

The second paragraph of the same article has direct consequences for software vendor relationships: if personal data is processed by another natural or legal person on behalf of the data controller, there is joint liability for taking these measures.

The third paragraph obliges the data controller to carry out or commission the necessary audits within their own institution. The fifth paragraph requires that if processed personal data is obtained by others through unlawful means, the situation must be reported to the data subject and the Board as soon as possible.

Why is biometric data treated separately?

Article 6 of the Law classifies biometric and genetic data as special category personal data and, as a rule, prohibits the processing of special category personal data: processing is only possible under one of the specified conditions.

This has a direct consequence for every institution performing remote identity verification: face matching and liveness checks constitute processing biometric data. Where the data is processed, how long it is stored, and who accesses it is not a technical preference, but a legal matter. The identity verification flow is explained on the customer onboarding page.

Can we transfer data abroad?

Article 9 of the Law was amended by Law No. 7499 dated March 2, 2024. According to its new version, personal data may be transferred abroad if one of the conditions in Articles 5 and 6 is met and an adequacy decision exists regarding the country, sectors within the country, or international organizations to which the transfer will be made.

The adequacy decision is issued by the Board, published in the Official Gazette, and re-evaluated at least once every four years. This makes where a cloud-based solution stores data a legal question.

SubjectLegal basis in the LawPractical result
Technical and administrative measuresArticle 12/1Access, processing, and preservation must be protected separately
Vendor liabilityArticle 12/2Joint liability with the software provider
Audit obligationArticle 12/3The institution must perform or commission its own audits
Breach notificationArticle 12/5Notification to the data subject and the Board as soon as possible
Biometric dataArticle 6Special category, processing is prohibited as a rule
International transferArticle 9 (as amended by 7499)Adequacy decision requirement

How does TruvaLI address this?

Data remains within the institution. In an on-premise deployment, the software runs on the institution's own infrastructure, personal data remains within the institution's information systems, and keys and the audit trail are under the institution's control. The question of international transfer does not arise when there is no transfer. Cloud and private cloud also remain options: which one to choose is the institution's own assessment. Details are on the on-premise deployment page.

Access is subject to authorization, and access is logged. Who accesses personal data is stored in the audit trail. Role and authorization definitions, approval policies, and delegation of authority are logged separately. The obligation to perform or commission the necessary audits required by the Law can be fulfilled through these logs. The audit log can also be exported to a separate destination. Details are on the maker-checker, authorization, and audit trail page.

Biometric data is treated separately. Artifacts collected during the verification session are recorded separately: document image, data read from the chip, selfie, liveness video, and video call recording. When each is collected, which check it is used in, and how long it is stored can be managed individually. Details are on the video customer call page.

Processing employee data establishes a separate legal basis: the employee screening page addresses this distinction. The European Union side is on the GDPR page.

Source

Law on Protection of Personal Data No. 6698, Articles 6, 9, and 12. Article 9 was amended by Article 34 of Law No. 7499 dated 2/3/2024.

This page does not constitute legal advice. The institution's own obligations are evaluated by its own legal department.

Common questions

How does KVKK affect financial crime analysis?
Law No. 6698 regulates the protection of personal data used in analysis. The classification of biometric data as special category and the restriction of international transfers to an adequacy decision are two decisive points.
Is the software vendor also liable?
Yes. The second paragraph of Article 12 of the Law provides for joint liability in taking measures if data is processed by another party on behalf of the data controller.
Do face matching and liveness checks constitute biometric data processing?
Yes. Article 6 of the Law classifies biometric data as special category and, as a rule, prohibits its processing: processing is only possible under one of the specified conditions.
Can we transfer data abroad?
Pursuant to Article 9, data can be transferred if one of the conditions in Articles 5 and 6 is met and an adequacy decision exists regarding the country, sector, or international organization to which the transfer will be made.
Who issues the adequacy decision?
It is issued by the Board, published in the Official Gazette, and re-evaluated at least once every four years.
What needs to be done in the event of a data breach?
The fifth paragraph of Article 12 of the Law requires that if data is obtained through unlawful means, the situation must be reported to the data subject and the Board as soon as possible.
Can we see who has accessed personal data?
Yes. Access is recorded in the audit trail: role and authorization definitions, approval policies, and delegation of authority are logged separately, and the log can be exported to a separate destination.
How is the data collected during identity verification managed?
The document image, data read from the chip, selfie, liveness video, and call recording are recorded separately: the collection time, the check in which it is used, and the retention period of each can be managed individually.

Related