Certification planner / KVKK

How do you get KVKK certification?

Compliance file for Türkiye's Personal Data Protection Law No. 6698: data inventory, privacy notices, retention and destruction. Answer the questions, and we'll map out the stages, timeline and documents you need to prepare for your business, with the reasoning behind each one.

3–6 monthstypical preparation time 13documents in the library 7stage

Your personal roadmap

Free · no sign-up required · about 2 minutes

Describe your main products and services, your customers and how you work in a few sentences.
E.g. metal processing, software, logistics, food production, consulting
Office, factory, warehouse, construction site — all addresses to be included in the certification scope.
Accreditation bodies and legal requirements vary by country.
Employees, customers, visitors, health data, CCTV footage…
Are you registered with VERBİS?

Your answers are processed with AI solely to prepare your roadmap.

KVKK certification steps

  1. Scope and gap analysisDefine the certification scope and locations, and identify the gaps between your current practices and the standard.
  2. Leadership, policy and objectivesTop management commitment, policy, roles and measurable objectives.
  3. Risks and standard-specific analysesRisks and opportunities; depending on the standard, environmental aspects, information security risks or business impact analysis.
  4. DocumentationPrepare, approve and publish procedures, work instructions, forms and lists tailored to your business.
  5. Implementation and recordsOperate the system; build up records such as training, calibration, suppliers and corrective actions.
  6. Internal audit and management reviewAudit the system yourself, close the findings and conduct the management review.
  7. Certification auditStage 1 (documentation) and Stage 2 (implementation) audits by an accredited body, followed by the certificate.

Documents required for KVKK

The mandatory set from the KaliteGO library. Each one is generated as docx/xlsx, filled in with your company details.

  • FR.13Destruction Report
  • FR.45Data Subject Application Form
  • FR.46Employee Privacy Notice
  • FR.72Customer, Visitor and Website Privacy Notice
  • FR.74Explicit Consent Statement and Withdrawal Form
  • LS.26Personal Data Processing Inventory
  • LS.27Personal Data Transfer and Third-Party Disclosure Record List
  • PO.26Personal Data Protection and Processing Policy
  • PO.27Personal Data Retention and Destruction Policy
  • PR.35Data Subject Request Response Procedure
  • PR.36Personal Data Breach Response Procedure
  • PR.63Consent Management Procedure
  • SOZ.2Data Processor Agreement (Personal Data Processing and Transfer Contract Annex)

Frequently asked questions

How long does KVKK certification take?

For most SMEs, 3–6 months. The timeline depends on your headcount, locations and current practices. The system needs to run long enough to generate records (usually 2–3 months), followed by an internal audit, a management review and the certification body's Stage 1 and Stage 2 audits.

Which documents are required for KVKK?

The standard explicitly requires certain documented information: scope, policy, objectives, procedures and records. The KaliteGO library has 13 document templates for KVKK; the planner explains which of them your business needs, and why.

Does KaliteGO issue the certificate?

No. The certificate is issued by an accredited certification body following the audit. KaliteGO gets you ready for the audit: documents, records, internal audit and management review.

Can I prepare without a consultant?

Yes. Most small and medium-sized businesses can prepare with a guided roadmap and ready-made templates. Consultants also use KaliteGO to manage multiple clients.