Buying a Franchise in Türkiye: How to Review Customer Data and KVKK Compliance
Who can access customer records? Before buying a franchise in Türkiye, clarify responsibility for data, sharing with the franchisor and obligations under the KVKK.
Published

A franchise business may use the brand’s systems for orders, reservations and loyalty programmes. However, the fact that the franchisor owns the software does not mean it bears all responsibility for customer data. Before joining a franchise network in Türkiye, examine what data you will collect and why, who will use it and who must act if something goes wrong. This review helps protect customer trust and your business’s legal and operational security.
1. Which rules apply in the absence of specific franchise legislation?
Türkiye has no dedicated law governing franchise relationships. Nor is there a specific requirement to provide a standardised pre-contractual disclosure document for franchise offers or to register franchise agreements in a dedicated register. Nevertheless, general legal duties of good faith and accurate disclosure remain important.
The contractual relationship is governed by the Turkish Code of Obligations No. 6098 and the Turkish Commercial Code No. 6102, with the Law on the Protection of Competition No. 4054 and the Industrial Property Code No. 6769 applying where relevant. For the processing of customer information, the principal legislation is the Personal Data Protection Law No. 6698 (KVKK).
The brand’s assurance that “all branches use the same system” is therefore not enough. Alongside the draft agreement, request customer privacy notices, data-sharing rules and a list of the applications used. These are not components of a mandatory franchise disclosure package; they are due diligence documents you should request. If documents are missing, do not commit to compliance obligations without understanding the data collection processes.
2. Map data flows and the parties’ roles
Start by listing the points at which customers interact with the business: the till, online ordering, Wi-Fi, CCTV, reservation forms and the loyalty app. For each, record what information is collected and where it is sent. Names, telephone numbers, order histories and video recordings are not processed for the same purpose; it is not appropriate to cover them all with a single blanket consent.
Ask the brand to answer these questions in writing:
- Who determines the purpose of data collection and the means of processing?
- Are records held at the outlet, by the franchisor or by an external service provider?
- Does the franchisor provide technical services only, or does it also use the information for its own campaigns?
- Can other franchisees access these records?
- What access permissions are granted to outlet staff?
Under the KVKK, the data controller is the party that determines the purposes and means of processing personal data. A data processor processes data on the controller’s behalf, under its authority. Contractual labels alone are not decisive; what happens in practice matters. The parties’ roles may differ between the outlet’s own reservation list and the franchisor’s loyalty programme.
Set out these distinctions for each processing activity in a schedule to the agreement. This allows you to challenge broad wording such as “the franchisee is responsible for KVKK compliance” before it shifts responsibility for activities controlled by the franchisor onto you.
3. Separate privacy information, marketing and international transfers
The privacy notice provided to customers must explain the controller’s identity, the purposes of processing, details of data transfers, the collection method and legal basis, and the data subject’s rights. Check that the company name in the notice matches the actual controller. Do not simply reuse a template bearing another outlet’s name or only the brand name.
Not every processing activity requires explicit consent; the appropriate legal basis must be established for each activity. However, making a purchase conditional on unnecessary marketing permissions is risky. Providing privacy information and obtaining explicit consent are not interchangeable, either.
For commercial electronic messages, separately assess the requirements of the Law on the Regulation of Electronic Commerce No. 6563 and its related regulations. Explicit consent under the KVKK is not the same as consent to receive commercial messages. Clarify the procedures for Türkiye’s Message Management System (İYS), which business the consents are obtained for and who implements opt-out requests.
Software or support services based abroad may result in personal data being transferred outside Türkiye. Ask about server locations and remote access. Document the mechanism used to comply with the KVKK’s international transfer provisions; do not settle for an assurance that “our global system is secure”.
4. Make data security requirements measurable in the agreement
The schedule to the agreement should contain more than a general confidentiality undertaking. Identify the parties responsible for granting and revoking permissions, staff training, access logs, backups, retention periods and deletion. Even responsibility for closing a departing employee’s account should be clear.
In particular, document the following procedures:
- Where customers should send requests for access, correction or deletion, and how those requests will be routed.
- To whom suspected unauthorised access must be reported, through which channel and within what timeframe.
- Which records the franchisor will provide during a breach investigation.
- How system changes will be communicated to the outlet.
As a general rule, the controller must resolve data subject requests within thirty days at the latest. For breach notifications to the Turkish Personal Data Protection Board, take account of the Board’s requirement to notify it no later than seventy-two hours after becoming aware of the breach. Internal reporting deadlines between the parties must allow statutory obligations to be met on time. Allocating responsibilities does not remove obligations imposed by law.
5. Test the system with a sample transaction before signing
Ask the brand for a demonstration without using real customer information: create a sample record, change a marketing preference, process an access request and demonstrate deletion. Compare what happens on screen with the descriptions in the agreement. Also ask whether the reports the outlet needs can be produced without including personal data.
The agreement should establish how access will be terminated, records returned or deleted, and statutory retention obligations met when the relationship ends. Do not treat a customer list as an asset that can be used without restriction.
Practical takeaway: Before signing, obtain a written data flow map, a clear allocation of the parties’ duties and workable security procedures. Resolve any remaining uncertainty in the agreement with a lawyer experienced in the KVKK.



