Knowledge Base / Security

Data Protection & Hosting: Where Should My Server Be?

Last updated: 23 September 2026

"Because of KVKK, does my server have to be in Turkey?" — a question every owner of a site that processes personal data asks. Short answer: not mandatory for a general website, but you must follow the rules for cross-border data transfer. This guide summarises the picture after the 2024 changes, plus practical advice.

This content is general information, not legal advice. In regulated sectors (health, finance, public sector) or for large-scale data processing, always consult a KVKK expert/lawyer.

What does KVKK say about server location?

KVKK does not impose a general localisation requirement on where data must physically reside. That is, the server of a commercial website, an e-commerce store or a SaaS can be in Germany, the Netherlands or the US. The requirement is that the cross-border transfer of data rests on a lawful basis.

Sector-specific legislation is separate: in areas like banking (BDDK), payment institutions, electronic communications, e-invoicing/e-ledger and health (e-Nabız), keeping data in Turkey may be required by their own regulations. This comes not from KVKK but from that sector's own rules.

Cross-border transfer (post-2024)

With the March 2024 amendment, the cross-border transfer regime was brought closer to GDPR. Transfer is possible in the following order:

  1. Adequacy decision: if the Board has declared a country/sector to have "adequate protection", data can be transferred freely. (The list is updated over time; check it.)
  2. Appropriate safeguards: if there is no adequacy decision — a standard contract between the parties (an SCC-like text published by the Board, notified to the Board after signing), binding corporate rules, undertakings, etc.
  3. Exceptions (incidental): narrow exceptions such as explicit consent or necessity for the performance of a contract — not a basis for ongoing transfers.
In practice: if your server is in the EU (e.g. Germany) and you have signed a standard contract/DPA with your provider, transfer rests on a legitimate basis for a typical website. The EU has a strong protection framework due to GDPR.

Where should you host? A practical decision

ScenarioRecommendation
Corporate brochure site, blog (little personal data: contact form)An EU location (Frankfurt/Amsterdam) is enough; low latency + strong protection
E-commerce (customer name, address, order)EU location + DPA/standard contract with the provider; payment data is already with a PCI-DSS payment institution
Heavy Turkish audience, performance criticalA Turkey location (Istanbul) cuts latency by 40–60 ms — a performance, not a legal, reason
Public sector, health, finance, regulated sectorCheck the sector legislation; usually hosting in Turkey + an expert opinion
Serving a government agency / public tenderThe specification usually requires hosting in Turkey and a domestic provider

What is required beyond server location

KVKK compliance is far broader than the server address:

  • Privacy notice: on the site, at every point where data is collected (form, membership, cookies).
  • Explicit consent where required — separate, freely-given consent (marketing email, the cross-border transfer exception, etc.).
  • VERBİS registration: mandatory for data controllers above certain thresholds.
  • Cookie management: a consent banner for non-essential cookies; rejecting must be as easy as accepting.
  • Data processor agreement: the hosting provider, email provider, analytics, CRM — all are "data processors"; there must be a written contract/DPA between you.
  • Security measures: encryption, access control, logging, server hardening, backups — technical measures directly affect liability in the event of a breach.
  • Breach notification: the obligation to notify the Board within 72 hours of detecting a data breach.
  • Retention and destruction policy: you cannot keep data indefinitely; periodic destruction.

Questions to ask when choosing a provider

  • Which country is the data centre in, and what certifications does it hold (ISO 27001, SOC 2)?
  • Do you sign a standard contract / DPA?
  • Who are the sub-contractors (sub-processors), and where are they?
  • Where are backups kept?
  • What is your notification process in the event of a breach?
At Arcnar: Our infrastructure is located in Europe (the GDPR framework); a data processing agreement (DPA) is provided on request. If you need a Turkey location, get in touch via a support ticket. Privacy/consent texts and VERBİS registration are your responsibility — we recommend working with a KVKK expert.

Frequently asked questions

Does KVKK require my server to be in Turkey?
No. KVKK does not impose a general data localisation requirement; a typical website's server can be in the EU or another country. The requirement is that any cross-border transfer of data rests on a lawful basis (adequacy decision, standard contract, etc.). Regulated sectors such as banking, payments and health may separately require hosting in Turkey.
My server is in Germany — what should I do for KVKK?
Sign a data processing agreement (DPA) / standard contract with your hosting provider. Since the EU has a strong protection framework due to GDPR, transfer rests on a legitimate basis for a typical website with that safeguard in place.
What else is required for KVKK besides server location?
A privacy notice, explicit consent where required, VERBIS registration if applicable, cookie consent, written contracts with data processors (hosting, email, analytics, CRM), technical security measures, breach notification within 72 hours, and a periodic data destruction policy.
Where should the server be for a site serving a government agency?
Public tenders and agency specifications usually require data to be hosted in Turkey and a domestic provider to be used. Read the specification carefully before signing a contract.

Was this article helpful?