Skip to content
Kulular Teknoloji, Kulular Bilişim Teknolojileri Limited Şirketi

← Writing

If Your Cloud Provider Is Abroad, You Are Already Transferring Data

11 August 20263 minVersion 1.0

Summary

Transfer of personal data abroad is governed by Article 9 of Turkish Law No. 6698. A transfer is not limited to physically sending data. Hosting data on the server of a provider based abroad, granting a team abroad access to a system, or having data processed abroad all constitute a transfer. This means the data residency of every external service in use has to be identified.

Author

Tarık İsmet Alkan

Organisation

Kulular Bilişim Teknolojileri Limited Şirketi

Ask an organisation "do you transfer data abroad?" and the answer is usually no. Ask which services they use, and a list appears: cloud hosting, email, customer support software, an analytics tool, a payment provider, a backup service.

Most of the services on that list don't have their servers in Türkiye. The real answer was yes, and the organisation didn't know it.

The misunderstanding comes from the word "transfer" itself, which suggests a deliberate act — taking a file and sending it. But holding data on a system abroad, or having it processed there, is a transfer too. No separate act of sending is required.

Seeing where a transfer actually begins

Article 9 of Turkish Law No. 6698 governs transfers abroad. The difficulty in practice isn't the provision itself — it's working out when a transfer has actually occurred.

All three of the following give rise to a transfer: data hosted on a server abroad; a team abroad able to access the system for support purposes; and data being processed abroad with the result sent back. The third is the one most often missed. If you use a text-analysis service and that service is based abroad, the text you send is processed there. Getting the result back doesn't mean no transfer took place.

Our own site has exactly this feature. The free-text field on the home page sends the text entered into it to a provider abroad for analysis. That's why our Data Protection Notice has a section devoted to it, and a visitor can browse the entire rest of the site without ever using that field. Making sure that no transfer occurs at all when the feature isn't used was as much a design decision as the feature itself.

The missing column in the inventory

Most data inventories list category, purpose and retention period. The missing column is: which country does this data physically sit in?

Add that column and the picture changes. Some of the data an organisation assumed was sitting in its own data centre turns out to be abroad. Backups are the most commonly missed item, because the backup service is usually a separate provider and nobody checks where it's located.

When building the inventory, ask the provider directly. If the contract makes a commitment about data residency, get it in writing. If it doesn't, the provider can change the arrangement unilaterally and you won't find out.

The sub-processor chain

The second layer is even less visible. The provider you use may itself rely on other providers for its own infrastructure.

You use a customer-support tool; that tool runs on a cloud provider; it uses a separate service for search; it connects to a third for sending notifications. Your data travels through the whole chain.

You can't fully control that chain, but you can make it visible. The contract should require notice of sub-processor use and give a right to object to a change. Most enterprise providers already offer this — it just has to be asked for.

What to do

The first step is to build a service inventory: the name of every external service used, what it's used for, which categories of personal data it can access, and where its servers are.

Once that table exists, there are three options: replace the service with an alternative hosted in Türkiye, move to the provider's Turkish region if it has one, or put the transfer on a proper legal footing using one of the mechanisms the law provides.

All three carry a cost, and the right choice depends on the nature of the work. But choosing none of them — that is, not noticing the situation at all — is the most expensive option, because it also means your data protection notice is giving inaccurate information, and a single gap ends up breaching two obligations at once.

The rules in this area continue to develop, and Board decisions periodically redraw the framework. Check the current position before choosing a transfer mechanism.

Frequently asked

01Does using a cloud service count as a transfer?
It does, if the provider's servers are abroad. No separate act of sending data out of Türkiye is needed. It's enough that the data is held on, or processed by, a system located abroad.
02Do sub-processors fall within scope too?
Yes. If the service provider you use relies on other providers for its own infrastructure, the whole chain needs to be assessed. This is why it matters that the contract sets out a notification and consent procedure for the use of sub-processors.

Sources

  1. 01Law No. 6698 on the Protection of Personal Data, Art. 9Transfer of personal data abroad — Turkish law, not a GDPR transfer mechanism
  2. 02Personal Data Protection Authority of Türkiye, guidance and Board decisions on cross-border transfer

Suggested citation

Tarık İsmet Alkan. “If Your Cloud Provider Is Abroad, You Are Already Transferring Data”. Kulular Teknoloji, version 1.0, 11 August 2026. https://kulular.com.tr/en/writing/cross-border-data-transfers

  • Data protection
  • Cross-border transfer
  • Cloud
  • Compliance