What KVKK says about fingerprinting
Turkiye's Kisisel Verilerin Korunmasi Kanunu - Law No. 6698 on the Protection of Personal Data - has been in force since 7 April 2016. It was modelled closely on the EU Data Protection Directive (95/46/EC) that preceded GDPR, and the 1 June 2024 amendments (Law No. 7499) pushed the statute substantially further toward GDPR-level alignment.
KVKK Article 3 defines personal data as 'any information relating to an identified or identifiable natural person'. Online identifiers fall squarely inside that definition. A browser fingerprint - the hash of a device's screen resolution, fonts, GPU renderer, audio stack, time zone, and installed plugins - constitutes personal data the moment it is used to recognise the same browser or device across sessions, even without a name or email address attached.
The statute does not use the word 'fingerprinting'. It does not need to: the Article 3 definition is technology-neutral and follows the same logic as Recital 30 of the EU GDPR. The KVKK Authority has, in its published decisions, treated device-derived online identifiers as personal data subject to the full processing conditions of the law.
Lawful basis for fingerprinting under KVKK
KVKK Article 5 sets out the lawful bases for processing personal data. In priority order for fingerprinting deployments: explicit consent of the data subject; a statutory obligation; necessity for the performance of a contract to which the data subject is party; protection of the life or physical integrity of the person where consent cannot be obtained; processing of data made public by the data subject; necessity for the establishment, exercise, or defence of a legal right; and the legitimate interest of the controller - provided those interests do not override the fundamental rights of the data subject.
For most commercial fingerprinting purposes - analytics, personalisation, advertising, session continuity - explicit consent is the only workable basis. The legitimate-interest ground is narrow and the KVKK Authority has interpreted it strictly in published decisions. There is no GDPR-equivalent 'strictly necessary for communication transmission' exception that is broadly recognised in Turkish administrative practice for fingerprinting.
The anti-fraud carve-out is the most legally defensible non-consent basis. A narrowly scoped fingerprint used solely to detect or prevent fraud or unauthorised access may rest on the 'necessity for establishing, exercising or protecting a right' ground under Article 5(2)(e), or on legitimate interest under Article 5(2)(f), provided the controller has documented the proportionality assessment and informed data subjects in the privacy notice.
Special-category data: biometric signals in fingerprinting
KVKK Article 6 enumerates special categories of personal data that carry elevated protection: racial or ethnic origin, political opinions, philosophical or religious beliefs, appearance and attire, trade union membership, health data, sexual life, criminal records and security measures, biometric data, and genetic data. Explicit consent is required to process any of these categories, and even then, additional security measures specified by the KVKK Board apply.
For fingerprinting, the biometric data category is the operative concern. When a fingerprinting system collects signals that qualify as behavioural biometrics - such as keystroke dynamics, mouse movement entropy, touch pressure patterns, or gait characteristics - the KVKK Authority's position is that those signals fall within the Article 6 biometric data category if they can be used to verify or authenticate the identity of a natural person.
Standard browser fingerprinting signals (canvas hash, WebGL renderer, font list, screen resolution, time zone) are not biometric data under KVKK and are processed as ordinary personal data under Article 5. But a fingerprinting deployment that combines standard signals with behavioural biometric measurement must treat the combined dataset as special-category data for Article 6 purposes.
VERBİS registration and fingerprinting deployments
The VERBİS obligation is one of the most frequently missed KVKK requirements in cross-border deployments. Non-Turkish companies deploying fingerprinting SDKs that process the personal data of persons in Turkiye must assess whether they meet the controller-registration thresholds, and if so, register through the KVKK's electronic system before going live.
The registration entry for a fingerprinting deployment should identify: the purpose of processing (e.g. fraud prevention, analytics, personalisation); the legal basis under Article 5 or Article 6; the categories of personal data processed (online identifiers, device characteristics, and, if applicable, biometric data); retention periods; and the identities of all third-party recipients or transfer destinations, including the country to which data is transferred.
Failure to register with VERBİS when required is itself an administrative violation, independent of any substantive processing error, and can result in a separate fine. The KVKK has issued decisions against both Turkish and international organisations for VERBİS non-compliance.
The 2024 amendments: what changed operationally
Law No. 7499 introduced four operationally significant changes that directly affect fingerprinting deployments.
First, the cross-border transfer regime under Article 9 was restructured. Transfers to a third country now require one of: (a) an adequacy decision by the KVKK Board covering the destination country; (b) appropriate safeguards, including standard contractual clauses approved by the KVKK, binding corporate rules, or other instruments approved by the Board; (c) explicit consent of the data subject for the specific transfer; or (d) specific exceptions applicable to vital interests, public interests, or legal claims. India, where Benny the Doorman is hosted, does not have a KVKK adequacy decision as of the date of this page.
Second, controllers must notify the KVKK and affected data subjects of personal data breaches within 72 hours of becoming aware of the breach. This applies to fingerprint data if it is compromised.
Third, Data Protection Impact Assessments (DPIAs, called 'data protection impact assessment' in the Turkish implementing guidance) are mandatory before undertaking processing that is likely to result in a high risk to the rights and freedoms of natural persons. Large-scale fingerprinting for advertising or profiling purposes would ordinarily trigger this requirement.
Fourth, the 2024 amendments formalised DPO obligations for controllers designated by the KVKK Board. Covered organisations must appoint a data protection officer and notify the Authority.
What explicit consent for fingerprinting must look like under KVKK
- Informed: the data subject must be told what data is collected (device signals, identifiers), the purpose of collection, the legal basis, and the identity of recipients including cross-border transfer destinations.
- Freely given: consent cannot be bundled with terms of service or conditioned on access to a service when fingerprinting is not strictly necessary for that service.
- Specific: a single blanket consent covering all processing is insufficient. Consent for fingerprinting must be purpose-specific - separate from consent for email marketing, analytics, or other unrelated processing.
- Unambiguous: pre-ticked boxes, silence, or continued browsing do not constitute consent. A clear affirmative action is required.
- Withdrawable: the data subject must be able to withdraw consent at any time without detriment, and the withdrawal mechanism must be as easy as the consent mechanism.
- For special-category biometric data under Article 6: explicit consent is always required regardless of any other basis, and the KVKK Board's additional security measures must be implemented.
Common fingerprinting purposes under KVKK
| Purpose | Personal data? | Special-category (Art 6)? | Consent required? | VERBİS entry needed? | DPIA likely needed? |
|---|---|---|---|---|---|
| Anti-fraud at login or payment (device binding) | Yes | No (standard signals) | Often no - legitimate interest or legal-right defence, with documented assessment | Yes, if threshold met | No, if narrowly scoped |
| Account-takeover detection | Yes | No | Usually no - legitimate interest, scoped and documented | Yes, if threshold met | No |
| Bot mitigation on a public-facing form | Yes | No | Usually no - legitimate interest | Yes, if threshold met | No |
| Behavioural biometrics (keystroke, mouse dynamics) | Yes | Yes - biometric data under Article 6 | Yes - explicit consent mandatory | Yes, if threshold met | Yes |
| Cross-site behavioural advertising / retargeting | Yes | No | Yes - explicit consent | Yes, if threshold met | Yes |
| Personalisation and A/B testing | Yes | No | Yes - explicit consent | Yes, if threshold met | No (unless large-scale) |
| Product analytics (page views, session replay) | Yes | No | Yes - explicit consent unless purely internal and non-identifying | Yes, if threshold met | No |
| KYC / identity verification using device signals | Yes | Possibly - if biometric inference involved | Yes - explicit consent; legal obligation may apply in regulated sectors | Yes, if threshold met | Yes |
| Fraud intelligence sharing with third parties | Yes | No | Yes, or appropriate safeguards - transfer rules apply | Yes, if threshold met | Yes |
Cross-border transfer of fingerprint data
The 2024 amendments significantly tightened Article 9. Fingerprint data transferred outside Turkiye must follow one of the approved routes: adequacy decision, appropriate safeguards (KVKK-approved contractual clauses, binding corporate rules, or other Board-approved instruments), explicit consent, or the narrow statutory exceptions.
As of June 2026, the KVKK has not published an adequacy list comparable to the EU Commission's list. Controllers must therefore rely on KVKK-approved contractual clauses or obtain explicit consent covering the specific cross-border transfer. The KVKK has published model contractual clauses, though as of the time of this writing the finalised post-2024 clause templates were still under Board review. Controllers should check the official KVKK website for the current status of approved transfer instruments.
Practical consequence: a Turkish e-commerce operator sending fingerprint hashes to a US or Indian cloud vendor for fraud-scoring must either execute KVKK-approved contractual clauses with that vendor, obtain explicit per-transfer consent from each data subject (impractical at scale), or wait for a bilateral adequacy decision that does not yet exist.
Annual fine indexing: the 2026 penalty landscape
KVKK administrative fines are not fixed in the statute. They are set as ranges and indexed annually by the KVKK Board to the previous year's Producer Price Index. This means the maximum and minimum thresholds change every January. In 2025 the upper cap was approximately TRY 5.4 million per violation. For 2026 the cap rose to approximately TRY 9.4 million per violation. Fines double for repeat violations of the same provision.
Beyond the administrative fines, KVKK Article 17 provides for criminal liability - imprisonment for between one and three years - for persons who unlawfully obtain, transfer, or destroy personal data, or who fail to destroy data when required. A fingerprinting deployment that collects data without consent and retains it beyond the declared retention period could give rise to both administrative and criminal exposure for the individuals responsible.
Controllers should verify the current fine schedule on the KVKK's official website each January, since the indexed amounts cited in any published article (including this one) will be superseded by new figures for the following calendar year.
Enforcement examples
The KVKK publishes its formal decisions on its website (kvkk.gov.tr) in anonymised form for most private-sector decisions, with the full decision text available for significant public-interest cases. Several decisions bear directly on fingerprinting-adjacent processing:
- Amazon Turkey (2022): The KVKK fined Amazon Turkey Operations Logistics for failure to adequately protect customer personal data and for non-compliant processing of online identifiers, citing absence of adequate technical and organisational measures. The decision is among the KVKK's highest-profile e-commerce enforcement actions and has been cited in subsequent decisions as establishing the standard for online identifier security requirements.
- Meta (Facebook) Turkiye (2022): The KVKK issued a fine against the Turkish data controller associated with Meta platforms for processing personal data including device identifiers without a lawful basis and failing to meet cross-border transfer requirements under the then-applicable Article 9. The decision reinforced the Authority's position that device-level identifiers, including those used for ad targeting, are personal data subject to the full consent and transfer framework.
- Google Turkiye (2022): The KVKK issued an administrative fine against Google's Turkish representative for processing personal data in connection with Google's advertising ecosystem without meeting consent and transparency requirements. The decision specifically referenced the use of unique identifiers tied to users' devices as regulated personal data requiring a documented lawful basis.
- Multiple unnamed controllers (2023-2024): The KVKK's 2023 and 2024 annual reports document a pattern of VERBİS non-compliance enforcement, with fines issued to dozens of medium and large controllers - including several operating in e-commerce and fintech - for failing to register processing activities including online identifier collection before beginning processing.
Transparency obligations: the privacy notice
KVKK Article 10 requires controllers to provide data subjects with a defined set of information at the time of data collection or, where not possible, without undue delay. For a fingerprinting deployment, the privacy notice must identify: the identity of the controller and, if applicable, the DPO; the purpose of processing; the legal basis; whether the data will be transferred abroad and to which countries; the data subject's rights under Article 11; and the retention period.
The KVKK has issued guidance specifying that 'online identifiers' collected for advertising, analytics, or fraud-prevention purposes must be called out by category in the privacy notice. A generic 'we collect technical information' clause has been found insufficient in several Board decisions. Where biometric data is processed, the Article 6 status and the explicit-consent mechanism must be disclosed separately.
For cross-border transfers under the post-2024 regime, the privacy notice must additionally disclose the transfer destination country, the safeguard mechanism relied upon (e.g. contractual clauses), and the data subject's right to obtain a copy of or reference to the relevant safeguard.
Children's data and fingerprinting
KVKK does not set a specific digital-services age threshold equivalent to GDPR's 16-year default or the UK's 13-year AADC threshold, but the consent provisions of Article 5 require that consent be given by a person with legal capacity to consent. For minors under 18, Turkish civil law generally requires parental or guardian consent for legal acts. The KVKK has taken the position that processing the personal data of children requires parental consent and that controllers who cannot verify whether a visitor is a minor must implement age-assurance measures appropriate to the risk.
For fingerprinting deployments that serve audiences including minors - particularly in gaming, e-learning, or consumer retail contexts - the standard approach is to implement age gates and to obtain verifiable parental consent before any fingerprinting data collection occurs.
How Benny the Doorman fits into a KVKK-aware deployment
Benny is a fingerprinting SDK and hosted API, not a consent management platform or VERBİS filing service. The KVKK compliance obligations - consent collection, VERBİS registration, DPIA completion, privacy notice, cross-border transfer safeguards - all sit on the controller's side of the relationship, not on Benny's.
Three integration steps are specific to the KVKK context. First, gate the call to Benny's fingerprint API behind a consent signal for each declared purpose. For purposes that require explicit consent under Article 5 or the Article 6 biometric data provisions, the user must have affirmatively and specifically consented before any fingerprinting signal is collected. Second, if your organisation meets the VERBİS registration threshold, register the fingerprinting activity in VERBİS before going live, listing Benny as a data processor and specifying the transfer destination as India. Third, complete a DPIA if the deployment involves large-scale fingerprinting for advertising or profiling, and retain the documented assessment as evidence of compliance for any KVKK inspection.
Critically, India does not have a KVKK adequacy decision. Fingerprint data transferred to Benny's infrastructure in Chennai must be covered by KVKK-approved contractual clauses between your organisation and Benny, or by explicit per-transfer consent from each data subject - the latter being impractical for most deployments. Benny's standard Data Processing Agreement includes contractual safeguard provisions; controllers should verify that those provisions satisfy the current KVKK requirements for cross-border transfer documentation, including the post-2024 clause format.
Frequently asked questions
Is browser fingerprinting illegal under the Turkiye KVKK?
No. Browser fingerprinting is not banned under KVKK. It is regulated as personal data under Article 3. You can use fingerprinting lawfully by establishing a valid legal basis under Article 5 - most commonly explicit consent for commercial purposes, or legitimate interest for narrowly-scoped anti-fraud use. Deploying fingerprinting without a lawful basis, without VERBİS registration if your organisation meets the threshold, or transferring data abroad without the required safeguards is where enforcement exposure arises.
What did the 1 June 2024 amendments (Law No. 7499) change for fingerprinting?
Four material changes. First, cross-border transfers now require an adequacy decision, KVKK-approved contractual clauses, binding corporate rules, or explicit consent - the previous 'undertaking' mechanism was replaced. Second, 72-hour breach notification to the KVKK and affected data subjects is now mandatory. Third, Data Protection Impact Assessments are required for high-risk processing, including large-scale fingerprinting for advertising or profiling. Fourth, DPO obligations were formalised for designated controllers. Any KVKK compliance programme that was last reviewed before June 2024 should be treated as incomplete.
What is VERBİS and when do fingerprinting controllers need to register?
VERBİS (Data Controllers Registry Information System) is a mandatory pre-processing registry operated by the KVKK Authority. Controllers with more than 50 employees or annual financial turnover above TRY 25 million - and all public institutions - must register their processing activities in VERBİS before any processing begins. For a fingerprinting deployment, this means registering the specific activity, listing the data categories (online identifiers, device characteristics, or biometric data if applicable), the legal basis, retention periods, and transfer destinations including any cross-border transfers. Failure to register when required is itself an administrative violation with a separate fine.
Does fingerprinting count as biometric data under KVKK Article 6?
Standard browser fingerprinting signals - canvas hash, GPU renderer, font list, screen resolution, time zone - are ordinary personal data under KVKK Article 3 and are processed under Article 5. They are not biometric data. Behavioural biometric signals - keystroke dynamics, mouse movement entropy, touch pressure patterns - qualify as Article 6 biometric data if they are used to verify or authenticate a person's identity, requiring explicit consent and additional Board-specified security measures. A combined deployment that mixes both types must treat the dataset as a whole as special-category data.
What are the KVKK fines for non-compliant fingerprinting in 2026?
The KVKK indexes administrative fines annually to the Producer Price Index. For 2026 the maximum administrative fine is approximately TRY 9.4 million per violation, up from approximately TRY 5.4 million in 2025. Fines double for repeat violations. Separately, KVKK Article 17 provides for criminal penalties - one to three years imprisonment - for individuals who unlawfully obtain, transfer, or destroy personal data. Controllers should check the KVKK's official website each January for the updated indexed amounts.
Can I rely on legitimate interest for anti-fraud fingerprinting under KVKK?
Yes, for narrowly scoped anti-fraud use, but with significant caveats. KVKK Article 5(2)(f) permits processing where necessary for the legitimate interests of the controller, provided those interests do not override the data subject's fundamental rights. For this to hold, the fingerprint must be used solely for fraud or abuse detection and not repurposed for analytics or marketing; retention must be tied to the fraud-detection lifecycle; and the controller must document a proportionality assessment. The KVKK Authority has interpreted the legitimate-interest ground strictly and the absence of a documented assessment has been cited in enforcement decisions.
How do cross-border transfer rules apply when using an Indian-hosted fingerprinting vendor?
India does not have a KVKK adequacy decision. Transferring fingerprint data to an Indian-hosted vendor therefore requires one of the approved alternative safeguards under the post-2024 Article 9: KVKK-approved standard contractual clauses, binding corporate rules, or explicit consent from each data subject for the specific transfer. Explicit consent at scale is impractical for most deployments, so the contractual-clause route is the standard approach. Controllers should confirm with their vendor that the Data Processing Agreement includes clause provisions that meet the current KVKK Board format requirements.
Does KVKK apply to companies based outside Turkiye?
Yes. KVKK applies to controllers that process the personal data of individuals in Turkiye, regardless of where the controller is located, when the processing is connected to offering goods or services to or monitoring the behaviour of persons in Turkiye. A US or EU company deploying a fingerprinting SDK that processes data from Turkiye-based visitors falls inside KVKK's scope and must meet all applicable obligations, including VERBİS registration if the threshold is met and cross-border transfer safeguards for any data transferred outside the country.
Tooling
Benny the Doorman is built for this compliance posture.
Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.
Last reviewed 2026-06-06

