KVKK & Cross-Border Data Transfer Position Paper

KVKK & Cross-Border Data Transfer Position Paper

KVKK & Cross-Border Data Transfer Position

Effective starting: September 24, 2025 · Last updated: September 14, 2026

Purpose: Compliance positioning for customers subject to KVKK (Law No. 6698) and cross-border data transfer requirements


1. Purpose and Scope

This document outlines how ProcessMind positions itself with respect to:

  • The Turkish Personal Data Protection Law (KVKK – Law No. 6698)
  • Cross-border data transfer mechanisms under KVKK — in particular the Standard Contract published by the KVKK
  • EU Standard Contractual Clauses (SCCs) for transfers from the EEA, the United Kingdom and Switzerland

It is intended to support customer compliance assessments, procurement processes, and regulatory discussions, particularly in regulated industries such as banking and financial services.


2. Roles and Responsibilities under KVKK

In a typical deployment:

  • Customer acts as the Data Controller under KVKK
  • ProcessMind acts as the Data Processor

ProcessMind processes personal data solely on documented customer instructions and does not determine the purposes or means of processing. Details on our processing activities are set out in our Data Processing Addendum.

This role allocation aligns with KVKK Articles 3, 10, and 12, and mirrors the processor obligations under GDPR Article 28.


3. Alignment with KVKK Principles

KVKK is largely aligned with GDPR in terms of its core data protection principles. ProcessMind is designed in accordance with these principles, including:

  • Lawfulness and purpose limitation
  • Data minimization and proportionality
  • Accuracy and retention limitation
  • Confidentiality and security of processing

ProcessMind does not require directly identifiable personal data to deliver process mining insights. Customers retain full control over which data attributes are ingested, masked, pseudonymized, or excluded.


4. Technical and Organizational Measures (TOMs)

ProcessMind implements appropriate technical and organizational measures to protect personal data, including but not limited to:

  • Encryption of data in transit and at rest
  • Role-based access control and least-privilege principles
  • Audit logging and traceability of access
  • Secure tenant isolation
  • Data retention and deletion mechanisms, including organization and dataset deletion features

These measures are designed to support compliance with KVKK Article 12 and SCC security requirements. For more details, see our Privacy Policy and security measures documentation.


5. Sensitive Data and Regulated Environments

ProcessMind is suitable for use in regulated environments, including banking, where event logs may contain employee or customer-related identifiers.

The platform supports:

  • Pseudonymized identifiers in event logs
  • Attribute-level data exclusion or masking
  • Customer-controlled ingestion pipelines

Customers remain responsible for ensuring a lawful processing basis and for determining whether explicit consent or other legal grounds apply under KVKK.


6. Cross-Border Data Transfers

6.1 Transfers from Türkiye (KVKK)

Following the 2024 amendment to Article 9 of KVKK (Law No. 7499), a transfer of personal data from Türkiye to another country requires one of the following:

  • an adequacy decision by the KVKK Board covering the recipient country, a sector within that country, or an international organisation;
  • an appropriate safeguard — in particular the Standard Contract published by the KVKK, which must be notified to the KVKK within five (5) business days of signing; a written undertaking approved by the KVKK; or Binding Corporate Rules approved by the KVKK; or
  • a derogation for limited, occasional situations — for example, where the data subject has given explicit consent after being informed of the risks, or where the transfer is necessary for the performance of a contract.

The previous general route based on explicit consent ended on 1 September 2024; explicit consent now operates only as one of these limited derogations.

For customers subject to KVKK, ProcessMind supports the execution of the KVKK Standard Contract for Controller-to-Processor transfers alongside the Data Processing Addendum. Where ProcessMind acts as the data importer, the parties complete the Standard Contract and ProcessMind provides the information required for the notification to the KVKK.

Where a transfer is subject to both the GDPR and KVKK, the EU SCCs do not by themselves satisfy the Turkish transfer requirements: the KVKK Standard Contract (and its notification) is a separate mechanism that can be put in place in parallel with the SCCs.

6.2 Transfers from the EEA, the United Kingdom and Switzerland (SCCs)

Where personal data is transferred from the EEA, the United Kingdom or Switzerland to a country without an adequacy decision, ProcessMind applies the EU Standard Contractual Clauses as part of its Data Processing Addendum, supplemented by the UK Addendum or the equivalent Swiss provisions where applicable.

Key points:

  • the SCCs are executed between the data exporter (Customer) and ProcessMind as data importer
  • the SCCs apply only where a cross-border transfer occurs, together with the UK Addendum or the equivalent Swiss provisions where applicable
  • the SCCs are supplemented by ProcessMind’s technical and organizational safeguards

Upon request, ProcessMind can provide information required to support transfer impact assessments.


7. Shared Responsibility Model

KVKK compliance is a shared responsibility:

  • Customers are responsible for the lawful basis, transparency obligations, data subject rights, and for determining which transfer mechanism under KVKK Article 9 applies to their cross-border transfers
  • ProcessMind is responsible for secure processing, confidentiality, and adherence to customer instructions

This shared model ensures regulatory clarity and operational accountability.


8. Conclusion

ProcessMind positions itself as a GDPR-first, KVKK-compatible process intelligence platform that supports regulated customers through:

  • Clear processor role definition
  • Strong technical and organizational safeguards
  • Support for KVKK-compliant cross-border transfers (the KVKK Standard Contract) and, where applicable, the EU SCCs
  • Customer-controlled data governance

ProcessMind does not claim KVKK certification but enables customers to deploy the platform in a KVKK-compliant manner.

For additional information, please review our Privacy Policy and Data Processing Addendum.


ProcessMind B.V.
Willem Sandbergstraat 33, 7425RC Deventer, The Netherlands
Email: privacy@processmind.com · Phone: +31 85 060 68 09

Integrated Process Intelligence, designed for clarity, security, and trust.