All documentation
Compliance Management
Manage all of KVKK's obligations and the GDPR/AI Act mappings from a single console. The processes are interconnected: scan findings feed ROPA, ROPA feeds VERBİS, and breaches feed DSAR.
Package: ROPA/DPIA Starter (T2); advanced compliance Professional–Premium admin · dpo · auditor
Core records
- ROPA (Processing Inventory, Art. 16) — legal basis, data categories, measures; drift detection.
- DPIA & DPIA Wizard — step-by-step impact assessment for high-risk processing.
- Consent Management — explicit/implicit consent, withdrawal evidence, cookie consent and banner builder.
- Retention & Erasure (Cascade) — retention schedule, automatic deletion, cascading erasure.
Requests & incidents
- 1DSAR (Data Subject Request)
Compliance → DSAR; track access/erasure/portability requests with 30/45-day counters and export the response package.
- 2Breach Management
With a 72-hour countdown: detection → investigation → Kurul notification → data-subject notification → closure.
Turkey-specific & frameworks
- VERBİS Assistant — registry sync and automatic submission.
- Disclosure Notice v2 — generation of Kurul-precedent disclosure notice text.
- Kurul Decision Engine — precedent search and penalty prediction.
- KEP — official notification; Confidence Letter — signed compliance certificate.
- GDPR ↔ KVKK mapping, ISO 27001 matrix, Compliance Center and Score.
- AI Act 2026 — system inventory, risk wizard, transparency, conformity and post-market monitoring.
This document is informational. Feature scope may vary by license package, and screen flows may change between releases.