Data Protection & Hosting: Where Should My Server Be?
Last updated: 23 September 2026
"Because of KVKK, does my server have to be in Turkey?" — a question every owner of a site that processes personal data asks. Short answer: not mandatory for a general website, but you must follow the rules for cross-border data transfer. This guide summarises the picture after the 2024 changes, plus practical advice.
What does KVKK say about server location?
KVKK does not impose a general localisation requirement on where data must physically reside. That is, the server of a commercial website, an e-commerce store or a SaaS can be in Germany, the Netherlands or the US. The requirement is that the cross-border transfer of data rests on a lawful basis.
Sector-specific legislation is separate: in areas like banking (BDDK), payment institutions, electronic communications, e-invoicing/e-ledger and health (e-Nabız), keeping data in Turkey may be required by their own regulations. This comes not from KVKK but from that sector's own rules.
Cross-border transfer (post-2024)
With the March 2024 amendment, the cross-border transfer regime was brought closer to GDPR. Transfer is possible in the following order:
- Adequacy decision: if the Board has declared a country/sector to have "adequate protection", data can be transferred freely. (The list is updated over time; check it.)
- Appropriate safeguards: if there is no adequacy decision — a standard contract between the parties (an SCC-like text published by the Board, notified to the Board after signing), binding corporate rules, undertakings, etc.
- Exceptions (incidental): narrow exceptions such as explicit consent or necessity for the performance of a contract — not a basis for ongoing transfers.
Where should you host? A practical decision
| Scenario | Recommendation |
|---|---|
| Corporate brochure site, blog (little personal data: contact form) | An EU location (Frankfurt/Amsterdam) is enough; low latency + strong protection |
| E-commerce (customer name, address, order) | EU location + DPA/standard contract with the provider; payment data is already with a PCI-DSS payment institution |
| Heavy Turkish audience, performance critical | A Turkey location (Istanbul) cuts latency by 40–60 ms — a performance, not a legal, reason |
| Public sector, health, finance, regulated sector | Check the sector legislation; usually hosting in Turkey + an expert opinion |
| Serving a government agency / public tender | The specification usually requires hosting in Turkey and a domestic provider |
What is required beyond server location
KVKK compliance is far broader than the server address:
- Privacy notice: on the site, at every point where data is collected (form, membership, cookies).
- Explicit consent where required — separate, freely-given consent (marketing email, the cross-border transfer exception, etc.).
- VERBİS registration: mandatory for data controllers above certain thresholds.
- Cookie management: a consent banner for non-essential cookies; rejecting must be as easy as accepting.
- Data processor agreement: the hosting provider, email provider, analytics, CRM — all are "data processors"; there must be a written contract/DPA between you.
- Security measures: encryption, access control, logging, server hardening, backups — technical measures directly affect liability in the event of a breach.
- Breach notification: the obligation to notify the Board within 72 hours of detecting a data breach.
- Retention and destruction policy: you cannot keep data indefinitely; periodic destruction.
Questions to ask when choosing a provider
- Which country is the data centre in, and what certifications does it hold (ISO 27001, SOC 2)?
- Do you sign a standard contract / DPA?
- Who are the sub-contractors (sub-processors), and where are they?
- Where are backups kept?
- What is your notification process in the event of a breach?