Eurocert
Management Systems

ISO 27001 and data-protection law: linking information security to legal compliance

Diagram linking KVKK and GDPR duties to ISO 27001 information security controls

Two compliance projects, one set of evidence

Walk into most mid-sized companies and you will find two separate teams solving the same problem without talking to each other. The legal or compliance function is busy with KVKK paperwork: privacy notices, consent records, the VERBIS registration. Meanwhile IT runs its own security programme, patching servers and tightening access. When a data-protection authority asks the one question that matters, can you demonstrate the technical and organisational measures you took to protect personal data, neither team has the full answer on its own.

This is the gap an information security management system is built to close. ISO 27001 does not replace data-protection law, and it will never make you compliant on paper by itself. What it does is turn a vague legal duty into a documented, audited, repeatable set of controls that you can put in front of a regulator, a customer, or a court. The smart move is to stop running security and privacy as rival projects and wire them into a single management system.

The law asks for measures it never lists

Article 12 of Turkey's Personal Data Protection Law (KVKK) requires data controllers to take all necessary technical and organisational measures to keep personal data safe. Article 32 of the GDPR uses almost identical language and adds the test of measures appropriate to the risk. Neither text tells you what those measures actually are. That silence is deliberate, because the right controls depend on your data, your threats, and your size.

An ISO 27001 information security management system fills exactly that space. Its Annex A turns that legal silence into 93 concrete controls covering everything from access management to incident response, the implementation detail the law itself leaves blank. When a regulator opens a file, saying you follow ISO 27001 and handing over your Statement of Applicability is a far stronger position than a folder of ad hoc memos.

Mapping legal duties to ISMS controls

The value of integration shows up when you place each legal obligation next to the part of the ISMS that satisfies it. The duties are not abstract. Each one has a home in the standard, and treating them as one programme removes the duplicated effort of documenting the same control twice.

ISO 27001 and data-protection law: linking information security to legal compliance figure

Security of processing

The headline duty under both KVKK Article 12 and GDPR Article 32 is to secure personal data against loss, unauthorised access, and alteration. In the ISMS this is the whole engine: a risk assessment that identifies where personal data lives and what threatens it, followed by a risk treatment plan that selects Annex A controls in proportion to that risk. The standard forces you to justify each control in the Statement of Applicability, which is precisely the reasoning a regulator expects when it asks why you judged your measures adequate.

Knowing what data you hold

You cannot protect, or lawfully report on, data you have not mapped. KVKK obliges most controllers to register their processing inventory with VERBIS, and GDPR Article 30 requires records of processing activities. ISO 27001 control A.5.9, the inventory of information and associated assets, builds the same picture from the security side. Run one data-mapping exercise and feed both the legal register and the asset inventory from it, rather than maintaining two drifting spreadsheets.

Breach notification against the clock

When something goes wrong, the law starts a timer. The Turkish data-protection board expects notification of a personal-data breach within 72 hours of the controller becoming aware of it, and GDPR Articles 33 and 34 set the same window for notifying the authority and, where the risk is high, the affected individuals. A breach is discovered through the ISMS incident-management controls (A.5.24 to A.5.28), so the detection, assessment, and escalation path that the standard requires is the same path that produces a timely, defensible notification. Build the 72-hour decision into the incident procedure and the legal deadline stops being a scramble.

Controlling processors and the supply chain

Most data leaves your walls. KVKK Articles 8 and 9 govern transfers to third parties, GDPR Article 28 demands a binding contract with every processor, and both expect you to check that the recipient is safe. The ISMS supplier-security controls (A.5.19 to A.5.23, including cloud services) give you the due-diligence questionnaire, the contractual security clauses, and the monitoring that turn that legal expectation into evidence you actually hold a file on each vendor.

Answering data subject requests

KVKK Article 11 and Chapter 3 of the GDPR give individuals the right to ask what data you hold, to correct it, and in defined cases to have it erased. You can only answer within the legal time limit if you can find every copy of that person's data quickly, which again rests on the asset and data inventory and on the access controls that show who can reach each record. A right that looks purely legal turns out to depend on the same housekeeping the ISMS already demands.

Privacy by design

GDPR Article 25 asks for data protection by design and by default, meaning privacy is engineered in rather than bolted on. The ISMS secure-development and change-management controls (A.8.25 to A.8.28) put that discipline into your projects: threat assessment before a system ships, security requirements in the specification, and testing before release. The legal principle and the engineering control are two views of the same habit.

Where ISO 27001 stops and the law continues

Honesty matters here, because overselling the certificate is how firms get caught out. ISO 27001 secures personal data well, but it says little about the lawfulness of processing it. Whether you have a valid legal basis or consent, whether your privacy notice is adequate, whether you respect purpose limitation and data minimisation, whether a cross-border transfer has a lawful mechanism, and whether you have appointed the contact person KVKK expects: these are legal determinations the standard does not make for you.

This is the point where a dedicated privacy management system earns its place. A standard such as BS 10012 for personal information management extends the security backbone toward privacy specifically, adding controls for lawful basis, data subject rights, retention, and consent that ISO 27001 leaves to one side. Run on top of an existing ISMS, it closes the privacy half of the picture without rebuilding the management system from scratch.

Running them as one system

The integration is practical, not theoretical. A handful of shared mechanisms carry both the security and the legal load:

  • One inventory. A single data and asset map serves VERBIS, the GDPR record of processing, and the ISMS asset register.
  • One risk assessment. Fold privacy risk, including data protection impact assessments, into the same methodology that drives information-security risk treatment.
  • One Statement of Applicability. Add a column that names the legal duty each control supports, so the document doubles as your evidence of accountability.
  • One incident procedure. Detection, severity assessment, and the 72-hour notification decision live in a single playbook.
  • One audit calendar. Internal audit and management review already exist under ISO 27001, so widen their scope to test legal compliance at the same time.

The accountability principle in both regimes asks you to demonstrate compliance, not merely to claim it. An ISMS is, in effect, a machine for producing that demonstration: documented decisions, audit trails, corrective actions, and management sign-off. When the KVKK board or a major customer asks for proof, you are handing over records you already keep rather than assembling a defence after the fact.

Start from the system you may already have

If you already hold ISO 27001, you are closer to defensible data-protection compliance than you probably think, and the work is to map your existing controls to legal duties and fill the privacy-specific gaps. If you are starting fresh, build the ISMS with the legal mapping in mind from day one so you never document the same control twice. Either way, treat security and data protection as one obligation with one body of evidence. Our teams support both the ISO 27001 certification and the privacy-management side, so the system you build answers the auditor and the regulator with the same set of records.