Blog · SIEM

Minimum SIEM and Log Architecture for KVKK in Turkey

Published: 8 min read

What a small or mid-sized Turkish entity needs to meet KVKK's logging and monitoring measures: log sources, layers, who runs it and what evidence to keep.

A minimum SIEM architecture for KVKK is the smallest set of components that collects access and activity logs from systems holding personal data in Turkey (Türkiye), keeps clocks aligned, detects unusual activity with rules, routes alerts to a named owner, protects integrity and destroys records on schedule. This guide sizes it for a small or mid-sized Turkish entity.

Written for IT and security leads of foreign-owned companies with a Turkish subsidiary or branch; English quotations of Turkish texts are unofficial. This page is for information only and is not legal advice; consult your legal and information-security advisers on how the measures apply to your organisation.

The Guide's logging expectations are summarised in our article on KVKK technical measures for logs and access security. The follow-up here: if your Turkish office has 50 to 250 people and the group runs security tooling elsewhere, what must the Turkish entity itself have in place?

Does KVKK require a SIEM?

No. The law names no products. Article 12/1 of Law No. 6698 requires the data controller (veri sorumlusu) to take "all necessary technical and administrative measures to ensure the appropriate level of security". The Personal Data Security Guide (Kişisel Veri Güvenliği Rehberi, January 2018), prepared by the Personal Data Protection Board, describes what those measures need to achieve: keep records of all users' actions, detect intrusions or movements that should not happen, report security problems as quickly as possible, and regularly check records and act on alerts.

The Guide also warns that the view that full security can be achieved with a single cyber-security product "is not always correct", so buying a SIEM does not meet the measure by itself. What counts is that the functions work and can be shown to work; a SIEM is the usual way to put them in one place.

Which architecture component answers which KVKK measure?

Guide or Board wording (unofficial translation) Component Our suggested minimum
"Regularly keeping records of all users' actions (such as log records)" Collection A list of systems holding personal data, each sending logs to a central point
"Determining whether there is an intrusion or a movement that should not happen in the IT networks" Correlation rules A small, tested rule set over directory, VPN and firewall events
"Reporting security problems as quickly as possible" Alert routing An owner, a channel and a response time for each alert type
"Regularly checking … access control records and other reporting tools, and acting on alerts" Monitoring and case records A record of who looked, when, and what they did
"Evidence should be collected and stored securely" Integrity-protected archive A separately administered central archive that can show records were not altered
Board decision No. 2018/10 (special categories of data): "secure logging of the transaction records of all actions performed on the data" Application and database audit logs Record-level audit trails where health, biometric or similar data is held

The third column is our recommendation, not a requirement listed by the Guide or the Board.

Which log sources does a Turkish entity need first?

Start with where personal data lives and the paths to it:

  1. Directory service (e.g. Active Directory, Entra ID): sign-ins, failed attempts, account and group changes.
  2. VPN and firewall: remote-access sessions, management-interface logins, allowed and blocked connections.
  3. Applications and databases holding personal data: HR, payroll, CRM or customer portals — who accessed which record, and when.
  4. File server, e-mail and Microsoft 365: shared-folder access, bulk downloads, external forwarding rules.
  5. Endpoint protection: malware detections and quarantine events.

In a group, the cloud directory, e-mail and endpoint console are often run centrally, so their logs may already sit outside Turkey. Record where each source's logs are held today.

If the Turkish office network gives staff or guests internet access, access records under Law 5651 must also be kept for two years under the Regulation on Internet Collective-Use Providers (art. 4/1-b). They can pass through the same collector but follow their own retention rules; our 5651 logging service (in Turkish) covers that scope.

What layers should the minimum architecture have?

  • Collection: agents on servers, syslog from network devices; a local collector at each site with its own firewall or servers, forwarding over an encrypted, buffered channel.
  • Time: every source synchronised to the same time source. Records with drifting clocks cannot be correlated and make weak evidence.
  • Integrity-protected archive: a central archive administered separately from the systems that produce the logs, able to show records were not altered.
  • Correlation rules: a few rules that work rather than many that do not. For KVKK the most telling one is unusual bulk access to a system holding personal data; identity rules complement it.
  • Alerting and cases: a written route for each alert and a short case record for each one handled.
  • Retention and destruction: a documented period per log type (in the retention and destruction policy, saklama ve imha politikası, if the entity must register with VERBİS); expired records are destroyed at periodic destruction, or within three months without a policy obligation.

Each layer can stay small, but skip one and the others lose their value. Clock synchronisation and alert ownership are the two most easily forgotten.

Who should operate it — the group, the Turkish entity or a provider?

Any of them can operate it, but responsibility is not transferred with the work: under art. 12/2 the controller is jointly responsible with those processing data on its behalf. Put in writing where logs are held, who can access them and how they are destroyed.

For groups: forwarding logs that contain personal data to a SIEM or SOC outside Turkey brings in KVKK's cross-border transfer rules (art. 9, amended in 2024), and in practice a global SOC still needs a Turkish counterpart who can act locally. If you prefer collection, correlation and 24/7 monitoring under one contract, with logs kept on infrastructure in Türkiye, our managed SIEM service (in Turkish) is built for that model.

How do you show the architecture works?

Auditors and breach investigators look for evidence of operation, not just a policy:

  • a log source inventory with each source's last event time;
  • a record of clock synchronisation checks;
  • the rule list and when each rule was last tested;
  • alert and case records: who looked, what was done, when closed;
  • archive integrity checks and periodic destruction records.

This evidence pays off in a breach. In decision No. 2019/10 of 24 January 2019, the Board read "as soon as possible" in art. 12/5 as no later than 72 hours from becoming aware of the breach for notifying the Board, and the shortest reasonable time for affected individuals; information can be provided in stages. The inventory shows which systems to examine, case records when the incident was detected, integrity checks that the records can be trusted.

Frequently asked questions

Are open-source or free logging tools enough for KVKK?

The law and the Guide prescribe no products or licence models. What matters is that records are kept and checked, alerts are acted on and evidence is stored securely, and that you can show it.

Does decision No. 2018/10 apply if we do not process special categories of data?

Check before concluding that: health data, such as medical reports kept in HR files, is a special category under art. 6/1. If you truly process no such data, the decision does not apply directly, but the general security obligation in art. 12/1 covers all personal data.

Should logs be collected at each Turkish site or sent straight to a central platform?

A local collector is usually simpler at sites with their own firewall or servers: it buffers events when the link drops. Cloud services can often forward directly. Either way, check that every source keeps sending and clocks stay synchronised.

How many days of logs should stay online and searchable?

Turkish law gives no number. The total period comes from the relevant legislation or your purpose; how much stays quickly searchable is an operational choice based on investigation needs and budget.

Sources

The official texts are in Turkish. English renderings in this article are unofficial.

This article is for general information and does not constitute legal advice. Article numbers and periods reflect the consolidated texts on mevzuat.gov.tr on the date of publication; verify the current text there. The official texts are in Turkish; where this page and the official text differ, the official text prevails.

← All articles