[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cms-entry-blog-managing-customer-data-under-kvkk-en":3},{"message":4,"data":5,"success":42},"OK",{"id":6,"entry_type":7,"locale":8,"slug":9,"title":10,"summary":11,"body":12,"blocks":13,"author_name":14,"published_at":15,"updated_at":15,"data":16,"category":17,"tags":18,"related":19,"alternates":32,"seo":37,"cover":17,"media":41,"preview":40},4,"blog","en","managing-customer-data-under-kvkk","Managing Customer Data Under KVKK: A Practical Checklist for Sales and Support Teams","Practical steps sales and support teams can follow to keep customer and lead data in order under KVKK, Turkey’s data protection law: inventory, consent, access, deletion and email permissions.","> **Note:** This article is general information, not legal advice. Consult a lawyer about your organisation's specific obligations.\n\nLaw No. 6698 on the Protection of Personal Data — **KVKK**, Turkey's data protection law, broadly similar in spirit to the EU's GDPR — affects almost every company that keeps customer and lead data about people in Turkey. Sales and support teams handle this data most often, so compliance depends on daily working habits as much as on the legal team. This checklist makes those habits concrete.\n\n## 1. Know what you hold: a data inventory\n\nList which personal data you process, for what purpose, for how long and on what legal basis. Typical categories for sales and support:\n\n| Data category | Example | Purpose |\n|---|---|---|\n| Identity | Name, surname, job title | Managing the customer relationship |\n| Contact | Email, phone | Quotes, support, notifications |\n| Customer transactions | Quotes, orders, case history | Performing the contract, support |\n| Marketing | Consent status, campaign engagement | Commercial messages (consent-based) |\n\nDo not collect data you do not need: every field added “just in case” is one more thing to protect.\n\n## 2. Record consent in a way you can prove\n\nFor marketing email or SMS permissions, record four things: **who** consented, **when**, **through which channel** (web form, trade fair form, contract) and **to what**. When consent is withdrawn, record that date too. A permission you cannot show a record for cannot be proven when it matters.\n\n## 3. Actually honour withdrawn consent\n\nThe most common mistake: someone unsubscribes but keeps receiving bulk email from another list. Withdrawn consents and unsubscribes must act as a suppression list across **all** bulk emails and automated follow-up sequences, and every commercial email needs a working unsubscribe link.\n\n## 4. Not everyone needs to see everything\n\nA sales rep may not need the whole customer base, and a support agent may not need financial details. With role- and profile-based permissions:\n\n- restrict read, edit and delete rights per object;\n- set record-level visibility by team and hierarchy;\n- grant bulk export only to those who need it;\n- use a strong password policy and two-factor authentication for sign-in.\n\n## 5. Be ready for deletion and access requests\n\nWhen a data subject asks for deletion, you must find every copy: the CRM, email lists, spreadsheets. With data in one system this takes minutes instead of days. Anonymisation instead of hard deletion makes the person unidentifiable without breaking your sales statistics.\n\n## 6. Reduce scattered copies\n\nCustomer lists emailed around, spreadsheets on desktops and contacts on personal phones are the hardest places to control. Keeping master data in one system and limiting exports removes much of the risk.\n\n## 7. Who changed what?\n\nBeing able to trace who changed a record and when matters for internal audits and for clarifying what happened if a complaint arrives.\n\n## Quick checklist\n\n- [ ] Data inventory written down and up to date\n- [ ] Marketing permissions recorded with source and date\n- [ ] Withdrawn consent suppressed in every send\n- [ ] Unsubscribe link in every commercial email\n- [ ] Role-based permissions, restricted exports\n- [ ] Deletion request procedure defined and tested\n- [ ] Change history kept\n\n## In CRModular\n\nCRModular records consent with source, date and IP address; withdrawn consent and unsubscribes are suppressed in all bulk emails and cadences; executing a deletion request anonymises matching contact and lead records; and record-level access is set with profiles, a role hierarchy and sharing rules. Details: [KVKK-ready CRM](\u002Fen\u002Ffeatures\u002Fkvkk-compliant-crm) and [Security](\u002Fen\u002Fsecurity).\n",[],"CRModular","2026-10-03T20:39:07.548Z",{},null,[],[20,24,28],{"slug":21,"title":22,"summary":23,"entry_type":7},"what-is-crm-for-small-businesses","What Is CRM and What Does It Do for a Small Business? A Realistic Guide","What a CRM is, which problems it solves for a small or mid-sized company, when it is too early, and how to plan the switch — without the hype.",{"slug":25,"title":26,"summary":27,"entry_type":7},"how-to-set-slas-for-service-teams","How to Set SLAs for Service Teams: Priorities, Targets and Measurement","A step-by-step way for technical service and support teams to set realistic SLA targets, define priorities and measure compliance.",{"slug":29,"title":30,"summary":31,"entry_type":7},"how-to-follow-up-on-sales-quotes","How to Follow Up on Sales Quotes: 7 Steps to Stop Losing Deals After the Proposal","Many quotes are forgotten simply because the customer did not reply. Here are seven steps that turn quote follow-up into a repeatable team process — and what to measure at each step.",[33,36],{"locale":34,"slug":35},"tr","kvkk-uygun-musteri-verisi-nasil-tutulur",{"locale":8,"slug":9},{"title":38,"description":39,"canonical_url":17,"noindex":40,"og_image":17},"Managing Customer Data Under KVKK (Turkey): A Checklist | CRModular","A practical checklist for keeping customer and lead data in line with KVKK, Turkey’s personal data protection law: data inventory, consent records, access control, deletion requests and email permissions.",false,{},true]