Skip to content

Blog

Managing Customer Data Under KVKK: A Practical Checklist for Sales and Support Teams

Practical steps sales and support teams can follow to keep customer and lead data in order under KVKK, Turkey’s data protection law: inventory, consent, access, deletion and email permissions.

CRModular 3 min read

Note: This article is general information, not legal advice. Consult a lawyer about your organisation’s specific obligations.

Law No. 6698 on the Protection of Personal Data — KVKK, Turkey’s data protection law, broadly similar in spirit to the EU’s GDPR — affects almost every company that keeps customer and lead data about people in Turkey. Sales and support teams handle this data most often, so compliance depends on daily working habits as much as on the legal team. This checklist makes those habits concrete.

1. Know what you hold: a data inventory

List which personal data you process, for what purpose, for how long and on what legal basis. Typical categories for sales and support:

Data category Example Purpose
Identity Name, surname, job title Managing the customer relationship
Contact Email, phone Quotes, support, notifications
Customer transactions Quotes, orders, case history Performing the contract, support
Marketing Consent status, campaign engagement Commercial messages (consent-based)

Do not collect data you do not need: every field added “just in case” is one more thing to protect.

For marketing email or SMS permissions, record four things: who consented, when, through which channel (web form, trade fair form, contract) and to what. When consent is withdrawn, record that date too. A permission you cannot show a record for cannot be proven when it matters.

The most common mistake: someone unsubscribes but keeps receiving bulk email from another list. Withdrawn consents and unsubscribes must act as a suppression list across all bulk emails and automated follow-up sequences, and every commercial email needs a working unsubscribe link.

4. Not everyone needs to see everything

A sales rep may not need the whole customer base, and a support agent may not need financial details. With role- and profile-based permissions:

  • restrict read, edit and delete rights per object;
  • set record-level visibility by team and hierarchy;
  • grant bulk export only to those who need it;
  • use a strong password policy and two-factor authentication for sign-in.

5. Be ready for deletion and access requests

When a data subject asks for deletion, you must find every copy: the CRM, email lists, spreadsheets. With data in one system this takes minutes instead of days. Anonymisation instead of hard deletion makes the person unidentifiable without breaking your sales statistics.

6. Reduce scattered copies

Customer lists emailed around, spreadsheets on desktops and contacts on personal phones are the hardest places to control. Keeping master data in one system and limiting exports removes much of the risk.

7. Who changed what?

Being able to trace who changed a record and when matters for internal audits and for clarifying what happened if a complaint arrives.

Quick checklist

  • [ ] Data inventory written down and up to date
  • [ ] Marketing permissions recorded with source and date
  • [ ] Withdrawn consent suppressed in every send
  • [ ] Unsubscribe link in every commercial email
  • [ ] Role-based permissions, restricted exports
  • [ ] Deletion request procedure defined and tested
  • [ ] Change history kept

In CRModular

CRModular records consent with source, date and IP address; withdrawn consent and unsubscribes are suppressed in all bulk emails and cadences; executing a deletion request anonymises matching contact and lead records; and record-level access is set with profiles, a role hierarchy and sharing rules. Details: KVKK-ready CRM and Security.

Blog

Related content

Bring your sales and service teams onto one platform

Try every module free for 14 days, no credit card required. Our team helps you get set up.