mindora
BlogPractice Management

KVKK Guide for Therapists: How to Protect Your Client Data

Learn how to achieve KVKK compliance in therapy practice: special category data processing, privacy notice obligations, client rights, data security measures, and WhatsApp risks under Turkish data protection law.

Mindora
2026-06-02
18 min
KVKK Guide for Therapists: How to Protect Your Client Data

Under KVKK (Turkey's Law No. 6698 on the Protection of Personal Data), therapists are individual data controllers processing client data, and therapy data such as session notes, diagnoses, and risk assessments falls into the law's highest-protection special category personal data. This guide addresses the privacy notice obligation, the difference between explicit consent and the confidentiality exception, client rights, digital and physical security measures, and the data breach process specifically for therapy practice.

An Obligation That Cannot Be Ignored

Consider a clinical psychologist who stores session notes in a cloud app, communicates with clients via WhatsApp, and presents no privacy notice at the first session. Everything seems fine until a client asks: "Where are my notes stored? Who can access my session records?" The therapist cannot answer, because the topic has never crossed their mind.

This scenario is not hypothetical. The Personal Data Protection Authority (KVKK) has been auditing and sanctioning data controllers under Law No. 6698 since 2016. Therapists, as individual data controllers who process client data, fall directly within the scope of this law. The attitude of "I just do therapy, I don't deal with technology" is not a legal defense but a risk factor.

In this post, we examine the therapy-specific dimensions of KVKK: which data qualifies as "special category," what distinguishes explicit consent from the professional secrecy exception, what the privacy notice obligation requires, what rights clients have, what digital and physical security measures are necessary, and what to do in the event of a data breach. Each section is supported by current legal provisions and 2026 penalty amounts.

Why It Matters: Personal Liability, Severe Penalties

Therapy data falls under the "special category personal data" classification in KVKK Article 6. This is a fundamentally different legal status from ordinary personal data such as a name or phone number. Psychological diagnoses, session notes, medication information, sexual health data, suicide risk assessments, and trauma histories are among the data types that the law places under its highest level of protection.

In KVKK terminology, the therapist holds the status of "data controller." This means personal liability for how client data is collected, processed, stored, and deleted. Even if you work within a clinic, responsibility is shared if you have access to clinical records. Therapists in independent practice bear direct and sole responsibility.

The penalty amounts are substantial. As of 2026, administrative fines under KVKK range from 85,437 TL to 17,092,242 TL. Beyond this, Turkish Penal Code Article 136 prescribes 1 to 4 years of imprisonment for unlawfully disseminating personal data; this sentence is increased by half when committed through professional access. A therapist who inadvertently discloses client information faces both administrative and criminal sanction risk.

Tip
Administrative fines under KVKK range from 85,437 TL to 17,092,242 TL in 2026. Under TPC Article 136, unlawful data sharing carries 1-4 years imprisonment; the sentence is increased by half when committed through professional access.

Which Data Qualifies as Special Category?

KVKK Article 6 defines health data and data related to sexual life as "special category personal data." In therapy practice, this definition covers an extremely broad scope. Psychological diagnoses and assessment results, session notes and clinical observations, medication information, mental health history, addiction information, sexual orientation and sexual health data, suicide risk assessments, domestic violence and abuse information, and trauma histories all fall into this category.

An important point to note is that even demographic data that is not "special category" on its own becomes sensitive when combined with the therapy context. A person's name and phone number constitute ordinary personal data, but when combined with the information that this person is a "psychotherapy client," it acquires the character of health data. Even a client list contains special category data from this perspective.

This broad scope means that therapists must evaluate not only session notes but also appointment records, communication history, and even information kept in the waiting room from a KVKK perspective.

Legal Basis: Explicit Consent or Professional Secrecy Exception?

There are two primary pathways for processing special category personal data. The first is explicit consent: the client freely, informedly, and for a specific purpose gives approval for their data to be processed. Three conditions must be met for valid explicit consent: it must relate to a specific matter, it must be based on adequate information, and it must be given by free will. General statements like "all my data may be processed for any purpose" are legally invalid.

The second pathway is the exceptions under KVKK Article 6/3. Health professionals who are bound by a duty of confidentiality may process health data without explicit consent for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment, and care services. Clinical psychologists and psychotherapists can be evaluated within this exception.

What does this mean in practice? You do not need separate explicit consent for keeping session notes, conducting clinical assessments, and creating treatment plans for treatment purposes; the professional secrecy exception covers these activities. However, non-treatment purposes are different: if you wish to use client data for research, statistics, or marketing, explicit consent is mandatory. Clients can withdraw their explicit consent at any time, and in that case you must cease the relevant data processing activity.

Privacy Notice Obligation: Mandatory Regardless of Consent

The privacy notice obligation is one of KVKK's most frequently overlooked yet most fundamental requirements. Whether you obtain explicit consent or process data under the professional secrecy exception, informing the client about how their data is processed is mandatory. The privacy notice and consent are entirely separate obligations.

The Communique on Procedures and Principles for Fulfilling the Privacy Notice Obligation, published in the Official Gazette on March 10, 2018, specifies the elements that the privacy notice must contain: the identity of the data controller, data processing purposes, to whom and for what purposes data may be transferred, the data collection method and legal basis, and the client's rights under KVKK Article 11. A privacy notice lacking any of these elements is considered incomplete.

The penalty for non-compliance with the privacy notice obligation ranges from 85,437 TL to 1,709,200 TL in 2026. What needs to be done in practice is straightforward: present the client with a clear and understandable privacy notice before the first session. This text must be a separate document; it should not be embedded within the informed consent form or combined with the consent form. Board decisions have found the combination of privacy notice and consent in a single document to be unlawful.

Client Rights: KVKK Article 11

KVKK Article 11 grants comprehensive rights to data subjects. Your client may at any time make the following requests: to learn whether their data is processed, to request information about processing if it has been, to learn the purpose of processing and whether data is used in accordance with its purpose, to know the third parties to whom data is transferred, to request correction of incomplete or inaccurate data, and to request deletion of data.

The right to deletion creates a particular tension point in therapy practice. The client can request the deletion of their data, but clinical record retention obligations impose limits. Ministry of Health regulations and professional standards recommend that clinical records be kept for at least 5 years; many experts recommend 15-20 years. In this conflict, the therapist can refuse the deletion request citing the legal retention obligation, but must notify the client in writing with stated reasons.

There is a mandatory 30-day deadline for responding to client requests. If the response is deemed insufficient, the client can file a complaint with the Personal Data Protection Board. For this reason, taking client requests seriously, documenting them, and responding within the deadline is both a legal and professional necessity.

Data Security: Digital and Physical Measures

Board Decision No. 2018/10 of the Personal Data Protection Board specifies in detail the adequate measures that data controllers must take when processing special category personal data. This decision serves as a checklist for therapists.

Digital security measures include encryption (data encrypted both in transit and at rest), two-factor authentication (2FA), access control (only authorized persons accessing data), and the use of separate encryption keys for special category data. Cloud storage is permitted but with specific conditions: data must be encrypted, 2FA must be active, the service provider's security practices must be audited, and destruction of encryption keys at the end of service must be guaranteed.

Physical security measures must not be neglected either. Printed client files should be stored in locked cabinets with protection against fire and flood. When leaving the office, computers should be locked and client information should not be left visible on screens.

Regarding VERBiS (Data Controllers Registry Information System) registration, an exemption exists: data controllers with fewer than 10 employees and annual financial balance sheets below 10 million TL are exempt from VERBiS registration. Many individual therapists benefit from this exemption. However, VERBiS registration exemption does not mean exemption from other KVKK obligations; privacy notice, security measures, and client rights obligations continue in full.

WhatsApp and Communication Risks

WhatsApp is one of the most commonly used tools for therapist-client communication in Turkey, but it carries serious risks from a KVKK perspective. WhatsApp servers are located outside Turkey, meaning every message technically constitutes a cross-border data transfer. The Personal Data Protection Board has opened an investigation into WhatsApp and found the platform's data processing practices to be problematic.

Sharing session content via WhatsApp means processing special category health data on an uncontrolled platform. A client's message saying "I was very anxious this week, I had a panic attack" is legally health data and is stored on WhatsApp servers. This situation is problematic from both KVKK and professional ethics perspectives.

The practical recommendation is: use WhatsApp only for appointment reminders and change notifications, never share any clinical content. Prefer encrypted and secure channels for clinical communication. For more detailed information on platform security and online therapy infrastructure, see our online therapy practice guide.

Cross-Border Data Transfer

For therapists using online therapy platforms (Zoom, Google Meet) and cloud software, cross-border data transfer is an unavoidable reality. KVKK Article 9 provides specific mechanisms for cross-border data transfer: transfer to countries for which the Board has issued an adequacy decision (none have been issued yet), standard contractual clauses (available since July 2024), binding corporate rules, and explicit consent.

When standard contractual clauses are used, notification to the Board within 5 business days is mandatory. In case of violation of cross-border data transfer rules, administrative fines ranging from 90,308 TL to 1,806,377 TL may be imposed in 2026.

What does this mean in practice? You need to know where your online therapy platform and cloud storage service store your data, apply the necessary legal mechanisms, and inform your clients about this matter.

What to Do in Case of a Data Breach

A data breach means the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. For a therapist, this covers situations such as a laptop being stolen, a cloud account being compromised, an email sent to the wrong person, or files being exposed in an unencrypted environment.

Once a breach is detected, notification to the Personal Data Protection Board within 72 hours is mandatory. Affected clients must also be notified "as soon as reasonably possible." The notification must include: what happened, when it occurred, which data was affected, how many people were affected, and the measures taken. A data breach notification form is available on the Board's website (kvkk.gov.tr).

The most effective way to prevent data breaches is to implement security measures proactively. However, no system is one hundred percent secure; therefore, having a breach response plan prepared in advance ensures systematic action rather than panic when a breach occurs.

Clinical Example: Deniz, 32, Structuring Her Digital Practice

Deniz is a clinical psychologist who opened her own private practice after working at a university hospital for 5 years. She accepts both in-person and online clients. When setting up her practice, she decided to structure KVKK compliance from the start.

Privacy Notice: She prepared a clear privacy notice containing the data controller's identity, data processing purposes (treatment, appointment management, legal retention), to whom data may be transferred (accountant, official authorities when required), collection method (sessions, forms, digital communication), and client rights. It is presented to the client before the first session.

Consent Form: No separate consent is obtained for treatment-purpose data processing (professional secrecy exception). However, she prepared a separate explicit consent form for use in anonymous statistics and research purposes. The privacy notice and consent form are two separate documents.

Data Security: Client records are stored in encrypted cloud storage (AES-256), two-factor authentication is active. Printed documents are in a locked cabinet. Full disk encryption (FileVault/BitLocker) is enabled on the laptop.

Communication Rules: WhatsApp is used only for appointment reminders and changes. No clinical content is shared whatsoever. Online sessions are conducted via an encrypted platform.

Retention Period: Clinical records are retained for 15 years. When the period expires, they are irreversibly deleted. The retention policy has been documented in writing.

Breach Protocol: She prepared a written protocol including steps for notifying the Board within 72 hours, informing affected clients, and maintaining an incident log in the event of a data breach.

Annual Review: She conducts a KVKK compliance check every January: is the privacy notice current, are security measures adequate, are retention periods being applied.

5 Core Principles for KVKK Compliance

1

Keep Privacy Notice and Consent Forms Separate

According to Board decisions, the privacy notice and explicit consent form must not be combined in a single document. The privacy notice is for informational purposes and is independent of consent; consent represents approval given for a specific processing activity. Prepare two separate documents and present them to the client separately.

2

Apply Data Minimization

Collect only the data necessary for treatment. Collecting unnecessary data with a "might need it later" approach violates the proportionality principle, one of KVKK's fundamental principles. For every data collection activity, ask yourself: "Does this data serve the treatment purpose?"

3

Restrict Access Permissions

If you have an assistant or secretary, they should not have access to session notes. Information needed for appointment management and clinical records should be maintained at different access levels. The "everyone can see everything" approach violates both KVKK and professional ethics.

4

Define and Enforce Retention Periods

Set a retention period between 5 and 20 years for clinical records and formalize it as a written policy. When the period expires, irreversibly destroy the data. Indefinite retention violates KVKK; the "I keep everything forever" approach carries legal risk.

5

Conduct an Annual KVKK Compliance Review

Legislation changes, penalty amounts are updated, and technological risks evolve. Review your privacy notice, security measures, retention periods, and communication practices at least once a year. This review also forms the basis for a "I exercised due diligence" defense in the event of a Board audit.

Common Mistakes

Combining Privacy Notice and Consent in One Document

This is a practice the Board has explicitly found to be unlawful. Having the client sign a single document stating "your information will be processed for these purposes, I agree" invalidates the privacy notice obligation. The privacy notice is a one-sided disclosure; consent is a two-sided transaction. They must be in separate documents.

Applying the "Treatment Purpose" Exception to Everything

The professional secrecy exception covers only direct treatment activities. Using client data in a research project, generating statistics, processing for marketing purposes, or using it in a supervision presentation is not treatment. Separate explicit consent is required for these purposes. The "I'm a therapist, everything I do falls under treatment" approach is not legally valid.

Sharing Clinical Content on WhatsApp

Sharing session content, emotional states, or clinical assessments with clients via WhatsApp means transferring special category health data to servers outside Turkey. Appointment reminders are acceptable, but messages like "about the homework we discussed last session" carry clinical content and are risky.

Not Having Defined a Data Retention Period

KVKK requires that data be deleted or anonymized once the purpose of processing ceases. The "I don't know when to delete it, so I never delete anything" approach violates the law. Set a reasonable retention period for clinical records (legal minimum 5 years, recommended 15-20 years), formalize the policy in writing, and enforce it when the period expires.

KVKK-Compliant Data Management with Mindora

Meeting the requirements discussed in this article, such as privacy notice obligations, secure storage, access control, and retention period management, becomes much easier with the right tools in a digital environment. Mindora supports your therapy practice's data management needs with a security-focused infrastructure:

  • Encrypted Cloud Storage: Client records and session notes are stored in encrypted infrastructure. Your data is protected both in transit and at rest.
  • Account Security and Data Isolation: Two-factor authentication (2FA) ensures account security. Each therapist's data is completely isolated from others; database-level separation makes it technically impossible to access another user's data.
  • Audit Trail: Who accessed which data, and when? All access and modification records are automatically maintained.
  • Client Consent Tracking: Privacy notice delivery status and explicit consent records can be tracked through the client profile.

All this data is managed in an integrated manner with other client records (session notes, treatment plans, formulations) within the clinical documentation system.

For detailed information about our encryption infrastructure, data isolation, input validation, and infrastructure security, visit our security page.

Tip
KVKK compliance is a legal responsibility, and the final decision always rests with the therapist as the data controller. Digital tools facilitate the compliance process but do not replace legal counsel.

Frequently Asked Questions

This Article is Part of the Practice Management Series

This article is one of the deep-dive posts in the practice management series. You can explore the other articles in the series below.

References

  • Law No. 6698 on the Protection of Personal Data (2016). Official Gazette of the Republic of Turkey, No. 29677.
  • Personal Data Protection Authority (2018). Adequate Measures to be Taken by Data Controllers in the Processing of Special Category Personal Data (Board Decision 2018/10).
  • Personal Data Protection Authority (2019). Personal Data Security Guide. KVKK Publications.
  • Turkish Psychologists' Association (2004). Ethical Guidelines for the Professional Practice of Psychology.
  • Regulation on Personal Health Data (2019). Official Gazette of the Republic of Turkey, No. 30808.