All documentation

Compliance Management

Manage all of KVKK's obligations and the GDPR/AI Act mappings from a single console. The processes are interconnected: scan findings feed ROPA, ROPA feeds VERBİS, and breaches feed DSAR.

Package: ROPA/DPIA Starter (T2); advanced compliance Professional–Premium admin · dpo · auditor

Core records

  • ROPA (Processing Inventory, Art. 16) — legal basis, data categories, measures; drift detection.
  • DPIA & DPIA Wizard — step-by-step impact assessment for high-risk processing.
  • Consent Management — explicit/implicit consent, withdrawal evidence, cookie consent and banner builder.
  • Retention & Erasure (Cascade) — retention schedule, automatic deletion, cascading erasure.

Requests & incidents

  1. 1
    DSAR (Data Subject Request)

    Compliance → DSAR; track access/erasure/portability requests with 30/45-day counters and export the response package.

  2. 2
    Breach Management

    With a 72-hour countdown: detection → investigation → Kurul notification → data-subject notification → closure.

Turkey-specific & frameworks

  • VERBİS Assistant — registry sync and automatic submission.
  • Disclosure Notice v2 — generation of Kurul-precedent disclosure notice text.
  • Kurul Decision Engine — precedent search and penalty prediction.
  • KEP — official notification; Confidence Letter — signed compliance certificate.
  • GDPR ↔ KVKK mapping, ISO 27001 matrix, Compliance Center and Score.
  • AI Act 2026 — system inventory, risk wizard, transparency, conformity and post-market monitoring.

This document is informational. Feature scope may vary by license package, and screen flows may change between releases.

Try this feature live

Test Wyverix with your own data, from a single panel.

Request a Free Demo