Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul

Devin Law & IP · Practice Areas

Our Services

Comprehensive legal services combining sector expertise with strategic legal insight: clear, practical and result-oriented solutions for businesses and individuals. Eight dedicated practice groups cover intellectual property, media and advertising, data protection, technology, corporate matters, dispute resolution and maritime law, for multinational groups and early-stage ventures alike.

04Data Protection, Privacy & CybersecurityDefensible governance under KVKK and the GDPR, data mapping, cross-border transfers, breach response and defence before the Authority.

Data Protection, Privacy & Cybersecurity

Data protection is not a document set — it is the way an organisation actually collects, stores, shares and deletes information, tested against what the Personal Data Protection Board expects to see. We act as external privacy counsel to Turkish and multinational businesses: building compliance programmes that survive an audit, structuring lawful cross-border transfers, standing in as local representative for foreign controllers, and running the response when a breach or an investigation arrives.

Most enforcement in Türkiye does not begin with a hacker. It begins with a complaint from an employee, a customer or a competitor — and the Board then asks for the inventory, the privacy notice, the consent record and the retention policy. Where those documents describe a process the company does not actually follow, the gap itself becomes the finding. Our work therefore starts with data mapping rather than with templates.

The practice supports clients continuously rather than project by project. Product and marketing teams get answers before a feature ships, not after; new tools are assessed before procurement; and privacy by design is applied while a decision is still cheap to change. That retainer relationship is what keeps a compliance programme aligned with a business that keeps moving.

Cross-border operations add a second layer. A company subject to both the GDPR and the KVKK faces two regimes that overlap without matching — different lawful bases, different transfer mechanisms, different notification clocks. We build a single control framework that satisfies both, so that the organisation runs one process rather than two competing ones.

When an incident occurs the timetable is unforgiving: the Board expects notification without undue delay and in any event within 72 hours of the controller becoming aware. We work alongside forensic and communications teams from the first hour — preserving evidence, scoping the affected data, drafting the notification and the subject communications, and building the defence file that will be needed months later if an investigation follows.

A compliance file is only useful if it describes what the organisation actually does. We begin with data mapping, then write the inventory, notices and policies from that map — so that when the Board asks for documentation, the documents and the practice tell the same story.

Day-to-Day Counsel
  • External privacy counsel to product, marketing, HR and IT teams
  • Privacy by design and by default review of new features, apps and business models
  • Vendor and tool assessments before procurement decisions are made
  • Role-specific training for executives, HR and marketing teams
Programme Build
  • Departmental data mapping and identification of complex data flows
  • Personal Data Processing Inventory creation and restructuring
  • Privacy notices, explicit consent forms, retention and destruction policies
  • Internal governance protocols, approval chains and record-keeping
Assessments & Requests
  • Data Protection Impact Assessments for high-risk processing
  • Automated decision-making and profiling risk reviews
  • Data subject access, rectification and erasure request handling
  • VERBİS registration, continuous updating and deletion processes
Day-to-Day Privacy CounselProviding continuous, strategic, and operational legal consultancy to corporate clients acting as their external privacy counsel. Advising product, marketing, and IT teams on a daily basis to integrate “Privacy by Design” and “Privacy by Default” principles into new software, apps, and business models before they launch.
Data Protection Impact Assessments (DPIAs)Conducting rigorous risk assessments for high-risk data processing activities, new technology deployments, and automated decision-making systems to mitigate legal liabilities preemptively.
Data Subject Access Requests (DSAR) ManagementFormulating legally sound, timely, and strategic responses to complex requests from data subjects regarding their rights to access, rectify, or erase their personal data.
Corporate Privacy TrainingDesigning and delivering customized, role-specific data protection training programs for C-level executives, HR departments, and marketing teams to cultivate an internal culture of data privacy.
End-to-End Audits & ImplementationConducting exhaustive departmental data mapping, identifying complex data flows, and creating or restructuring statutory Personal Data Processing Inventories (Kişisel Veri İşleme Envanteri).
Policy & Documentation ArchitectureDrafting precise and operational Privacy Notices (Aydınlatma Metni), Explicit Consent Forms (Açık Rıza), Data Retention and Destruction Policies, and internal data governance protocols tailored strictly to the client’s sector.
VERBİS ManagementManaging the mandatory registration, continuous updating, and deletion processes before the Data Controllers Registry (VERBİS) for both domestic and foreign data controllers, ensuring the registry perfectly mirrors actual data processing activities.
Retention Schedules & Destruction AuditsSetting defensible retention periods per data category, documenting periodic destruction cycles, and verifying that deletion actually occurs across backups, archives and vendor systems.

For a group operating under both the GDPR and the KVKK, the danger is running two parallel programmes that drift apart. We build one framework mapped to both regimes, and where transfers out of Türkiye are required we choose the mechanism that will actually clear — rather than the one that is quickest to sign.

Dual Regimes
  • GDPR and KVKK gap analysis and harmonisation for multinational groups
  • Single control framework satisfying both regimes without duplicate processes
  • Lawful basis mapping across jurisdictions and processing purposes
  • Group-wide policies adapted to local Turkish requirements
Transfer Mechanisms
  • Letters of undertaking (taahhütname) and Board approval processes
  • Standard contractual clauses and their Turkish notification requirements
  • Binding corporate rules for intra-group transfers
  • Transfer impact assessments and supplementary safeguards
Local Presence
  • Acting as designated data controller representative in Türkiye
  • Correspondence and filings with the Authority on behalf of foreign controllers
  • Local complaint handling and data subject communication
  • Monitoring regulatory developments affecting the client's sector
GDPR & KVKK Dual Compliance MatrixProviding strategic gap analysis and harmonization consultancy for multinational corporations, e-commerce platforms, and tech startups operating simultaneously under the EU General Data Protection Regulation (GDPR) and the Turkish KVKK framework.
Lawful Cross-Border Data TransfersStructuring legally robust international data transfer mechanisms. Drafting and executing Letters of Undertaking (Taahhütname), Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and navigating the complex approval processes of the Turkish Data Protection Authority.
Local Representation for Foreign EntitiesServing as the designated Data Controller Representative in Turkey for global companies processing the personal data of Turkish residents, ensuring a seamless, compliant, and responsive legal bridge with the local Authority.
Data Localisation & Sector RulesAdvising on sector-specific localisation and hosting requirements — banking, payments, health and public procurement — where general transfer mechanisms are not sufficient on their own.

Two areas produce most of the exposure that companies do not see coming: what vendors are permitted to do with data once it leaves the building, and what employers do with employee data inside it. Both are contractual and policy problems before they are enforcement problems, which is where we prefer to solve them.

Vendor & Partner
  • Data processing agreements and joint controller arrangements
  • Cloud service provider terms (AWS, Azure, Google Cloud) and addenda
  • Secure data-sharing protocols with partners and affiliates
  • Sub-processor chains, audit rights and breach-notification obligations
Transactions
  • Privacy due diligence in mergers, acquisitions and joint ventures
  • Valuation of data assets and identification of hidden non-compliance
  • Post-merger integration of disparate data silos and legacy systems
  • Data transfer and migration structuring on carve-outs and divestments
Workplace
  • Corporate email monitoring, GPS tracking and CCTV policies
  • Bring Your Own Device (BYOD) frameworks and device separation
  • Biometric access systems — fingerprint and facial recognition
  • Employee health, disability and occupational safety records
  • Candidate screening, background checks and recruitment data
Data Processing Agreements (DPAs)Drafting and aggressively negotiating complex DPAs, Joint Controller Agreements, and secure data-sharing protocols with third-party vendors, cloud service providers (AWS, Azure, Google Cloud), and strategic business partners.
M&A Privacy Due DiligenceConducting rigorous, deep-dive data privacy audits during mergers, acquisitions, and joint ventures to identify hidden non-compliance risks, assess the actual value of data assets, and plan post-merger integration strategies for disparate data silos.
Workplace Surveillance & BYODNavigating the delicate balance between an employer's legitimate management interests and employee privacy rights. Drafting legally compliant policies for corporate email monitoring, GPS tracking in company vehicles, CCTV usage, and Bring Your Own Device (BYOD) frameworks.
Biometric & Health Data ProcessingAdvising on the exceptionally strict legal requirements for processing special categories of personal data in the workplace, particularly biometric access systems (fingerprint, facial recognition) and employee health or disability records.
Vendor Audit & Sub-Processor ChainsEstablishing audit rights, approval procedures and notification duties down the sub-processor chain, so that responsibility remains traceable when data passes through several providers.

An incident is judged twice — once on how it happened, and once on how it was handled. The second judgement is the one the organisation controls. We work from the first hour to preserve evidence, meet the notification clock and build the file that will answer the questions an investigation asks months later.

Breach Response
  • Notification to the Authority within the statutory 72-hour window
  • Communications to affected data subjects and internal stakeholders
  • 24/7 crisis coordination during ransomware, phishing and intrusion events
  • Insider data theft investigations and evidence preservation
  • Coordination with forensic IT specialists and communications advisers
Regulatory Defence
  • Written defence submissions in Authority investigations and audits
  • Sector-specific audit preparation and document production management
  • Communication strategy with the regulator throughout a file
  • Appeals against administrative fines before the Criminal Courts of Peace
Civil & Remediation
  • Defence of material and moral compensation claims arising from data incidents
  • Group and consumer-organisation claims following large-scale leaks
  • Incident response plans, tabletop exercises and post-breach remediation
  • Root-cause documentation supporting mitigation arguments on penalty
Rapid Breach Notification ProceduresManaging the critical and mandatory 72-hour breach notification process to the Turkish Data Protection Authority (KVKK Kurulu) and drafting sensitive communications for affected data subjects.
Incident Response CoordinationProviding urgent, 24/7 legal crisis management during cyber-attacks (ransomware, phishing, malicious hacking) or insider data theft. Coordinating seamlessly with forensic IT experts and PR teams to assess and contain the legal impact of the breach.
Post-Breach Remediation & DefenseDrafting internal incident response plans, building regulatory defense files, and mitigating the long-term legal and reputational fallout of a corporate data security failure.
Authority Investigations & AuditsRepresenting corporate clients in formal investigations, sector-specific audits, and written defense requests initiated by the Turkish Data Protection Authority, effectively managing the communication strategy with the regulators.
Penalty AppealsChallenging and appealing administrative fines (idari para cezaları) issued by the Authority before the Criminal Courts of Peace (Sulh Ceza Hakimlikleri) through meticulous procedural and substantive defense strategies.
Civil Privacy LitigationDefending data controllers against material and moral compensation claims (tazminat davaları) filed by individuals or consumer groups in general civil courts due to alleged privacy violations or data leaks.
Ransomware & Extortion ResponseAdvising on the legal boundaries of negotiation and payment demands, sanctions exposure, evidence preservation, and the parallel notification duties that arise alongside the technical recovery effort.

Marketing technology is where privacy law meets a stack nobody has fully inventoried. We start from what the site and app actually load — tags, pixels, SDKs — and align the cookie policy, the consent platform and the İYS records to that reality rather than to an idealised description of it.

Cookies & Consent
  • Cookie policies drafted against the actual technical inventory
  • Consent management platform (CMP) implementation review
  • Consent validity, granularity, withdrawal and record-keeping
  • Tracking pixels, SDKs and mobile identifier assessments
Commercial Messaging
  • Compliance with the Electronic Commerce Law (ETK) and KVKK together
  • Commercial Electronic Message Management System (İYS) management
  • Newsletter, SMS and push notification consent architecture
  • Opt-out handling, suppression lists and complaint response
Ad-Tech
  • Programmatic advertising and real-time bidding data flows
  • Audience segmentation, lookalike modelling and enrichment practices
  • Affiliate networks, attribution tools and shared identifiers
  • Dark pattern review of consent and subscription interfaces
Cookie Compliance & CMP IntegrationDrafting complex, technically accurate Cookie Policies and advising on the legal implementation of valid consent management platforms (CMPs) for corporate websites and mobile applications.
Direct Marketing & E-Commerce RegulationsEnsuring commercial marketing campaigns, newsletters, and SMS activities strictly comply with both the Law on the Regulation of Electronic Commerce (ETK) and KVKK, including the legal management of the Commercial Electronic Message Management System (İYS).
Ad-Tech & Programmatic Data FlowsReviewing real-time bidding, audience segmentation and enrichment practices, mapping which parties receive which identifiers, and allocating controller and processor roles accurately across the chain.
Dark Pattern & Interface ReviewAssessing consent banners, subscription flows and cancellation journeys against consumer protection and privacy expectations, so that design choices do not become regulatory findings.