Follow us :
KVKK & Compliance

KVKK Staff Training: How Often, and What Should It Cover?

Corporate training session in an office setting — Xen Bilişim KVKK & Compliance

In decision 2021/407, Türkiye’s Personal Data Protection Board (KVKK) fined a data controller 600,000 TL. One of the reasons cited: the company had assigned KVKK awareness training to its staff but never made sure it was completed, and the content that was delivered barely covered the basics, things like not disclosing or sharing personal data with unauthorized parties. This wasn’t a firewall gap or a missing encryption policy. It was a gap on the human side, and it became part of the fine’s own reasoning.

Most SMEs think of KVKK compliance as a technical checklist: firewalls, encryption, backups. The Board’s own Personal Data Security Guide puts staff awareness first on the list — because most breaches don’t start with a hacked server. They start with an employee emailing a file to the wrong address, copying a customer list onto a USB stick, or walking away from an unlocked screen.

Who needs training, and how often

Turkish law (Article 12 of Law No. 6698) doesn’t specify a fixed interval — “once a year” or “every six months” isn’t written anywhere. It puts the burden on the data controller to take “necessary measures,” leaving frequency to a risk-based judgment call. What actually works on the ground looks like this:

GroupFrequencyWhy
New hiresWithin the first 30 daysAwareness before access is granted
All staffAnnual refresherKeeps up with current threats and procedures
Staff with direct access to personal data (HR, finance, sales)Twice a yearHigher exposure, higher risk
Team involved in an incidentWithin 30 days of the eventTargeted, root-cause-specific training

An HR specialist has access to the CV database. An accountant has access to bank details. A salesperson has access to every phone number in the CRM. Running all three through the same generic slide deck once, and checking a box, won’t hold up as a defense in an audit — in decision 2021/407 the problem wasn’t that training had been assigned, it was that completion was never enforced.

What the content should — and shouldn’t — cover

The Board’s own guidance is blunt about this: training that turns into a law lecture on “what is KVKK, how many articles does it have” doesn’t work. It has to walk through scenes employees actually run into during the workday.

  • What to check before sending a document with personal data to an email address
  • Physical document handling — not leaving files on a desk, printer tray, or in an open bin, and how to properly destroy them
  • How to respond to an “urgent, can you send me that list” request from outside the company (social engineering)
  • Who to notify, and how fast, when a possible data breach is spotted (the internal window has to be much shorter than the 72-hour regulatory notification deadline, or that deadline can’t be met)
  • Limits on keeping company data on personal devices or backing it up to a personal cloud account
  • Basic hygiene: screen locking, strong passwords, unauthorized USB use

Training that blends legal obligations with everyday security habits is the kind employees actually remember. Handing out a PDF and collecting a signature doesn’t build a defense after an incident — it just adds a piece of paper to the file.

Documentation matters as much as the training itself

A pattern repeats across Board decisions: the gap between claiming training happened and proving it. Saying “we train our staff” isn’t enough. What needs to be on file:

  1. Training content (slides, video, or document) — dated and versioned
  2. Attendance and completion records (name, date, completion percentage)
  3. A short assessment or quiz result — proof of comprehension, not just “viewed”
  4. A refresher schedule with the next training date already set

These records should match what your VERBİS registration declares about technical and administrative measures. If your registry states “staff awareness training is provided” and there isn’t a single record to back it up, that mismatch between declaration and reality becomes its own item on an auditor’s list.

Frequently asked questions

Do we have to hire an outside training provider? No. An in-house program is fine as long as it’s current and scenario-based. What matters is content quality and documentation, not who delivered it.

Does a 5-person office really need this? Yes. Article 12’s threshold is the nature and risk of the personal data being processed, not headcount. In a small office, one person often handles HR, finance, and sales data all at once — which concentrates the risk rather than reducing it.

Is a one-time training session enough if we archive the record? No. In decision 2021/407, the fact that most of the assigned training was never completed was itself an aggravating factor. A one-off assignment that nobody tracks is functionally the same as an untracked to-do list.

How long should we keep training records? There’s no fixed retention period in the regulation. As a general evidentiary principle, records should be kept for the duration of the employee’s tenure and for a reasonable period afterward.

This month’s checklist

Pull the numbers on how many employees completed KVKK training over the past year, and what the completion rate actually was. Check whether the 30-day rule is being applied to new hires. List the teams with direct access to personal data — HR, finance, sales, customer service — and move them to a twice-a-year schedule. Look honestly at whether your training content is generic information or built around real scenarios.

If you’d like to review your training program alongside your KVKK technical and administrative measures checklist, get in touch.

Share this post
Türkçe oku

Related Posts