# Audit KVKK Privacy Compliance

Turkish teams need fast checks for KVKK notices, consent forms, and privacy policies. This skill reviews required elements, flags gaps, and drafts practical compliance text.

## Install

```bash
npx skillstore add cesareth/kvkk-denetim
```

## Metadata

- Status: approved
- Slug: cesareth-kvkk-denetim
- Version: 1.0
- Author version: 1.0
- Skillstore revision: r1
- Version status: invalid
- Tree hash: d9dca90595a94390dd9042ee6dc88b41dc6fb2af635d4c0ba4f0fce24083941e
- Author: cesareth
- GitHub username: cesareth
- License: MIT
- Repository: https://github.com/cesareth/hermes-turkce-skills/tree/main/kvkk-denetim
- Ref: dd4a3ef9f20ddf38830950b4bb713df96b431fd6
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands
- Quality score: 80
- Quality tier: silver
- Public page: https://skillstore.pages.dev/skills/cesareth-kvkk-denetim
- Manifest: https://skillstore.pages.dev/api/skills/cesareth-kvkk-denetim/manifest

## Capabilities

- Guides KVKK audits with checklists for data inventory, legal basis, notices, rights, and security.
- Drafts Turkish aydınlatma metni and explicit consent templates using provided placeholders.
- Reviews privacy text for missing controller, purpose, transfer, retention, contact, and Article 11 rights.
- Uses the included Python script to score text or file inputs against keyword-based KVKK checks.
- References core KVKK articles and common violations from bundled reference material.

## Use Cases

- Review Product Data Flows: Check app signup, support, and analytics data flows before publishing a privacy notice.
- Find Notice Gaps: Identify missing KVKK Article 10 and Article 11 elements in existing customer notices.
- Draft First Policies: Create a first draft of an aydınlatma metni and explicit consent statement.

## Prompt Templates

### Check a Privacy Notice

```
Review this Turkish privacy notice for KVKK Article 10 completeness. List missing elements, risk level, and plain-language fixes: [paste text]
```

### Draft Consent Text

```
Draft a Turkish explicit consent statement for this processing activity. Include data type, purpose, withdrawal right, date, name, and signature fields: [describe activity]
```

### Audit a Service Workflow

```
Audit this service workflow for KVKK compliance. Check data inventory, legal basis, transfers, retention, Article 11 rights, and security controls: [describe workflow]
```

### Prepare Remediation Plan

```
Use the KVKK checklist and reference articles to produce a prioritized remediation plan. Group findings by critical, important, and recommended actions: [paste audit notes]
```

## Limitations

- It is informational and does not replace licensed legal advice.
- Penalty amounts and legal thresholds may become outdated without manual updates.
- The quick-check script is keyword-based and can miss nuanced legal issues.
- It focuses on Turkish KVKK requirements, not full GDPR compliance.

## Best Practices

- Provide the full Turkish text and describe the real data flow before asking for review.
- Validate generated legal text with a qualified Turkish privacy lawyer before publication.
- Keep KVKK penalty amounts, VERBİS thresholds, and regulatory guidance current.

## Anti Patterns

- Do not treat the generated report as binding legal advice.
- Do not use generic GDPR wording without adapting it to KVKK requirements.
- Do not rely only on keyword checks for high-risk or special-category data processing.

## Security Audit

- Audited at: 2026-07-06T06:25:36.698\+00:00
- Summary: All five static findings are false positives caused by Markdown fenced examples in SKILL.md. I found no prompt injection, data exfiltration intent, or business-logic abuse. The bundled Python script performs local text and file analysis only.

## Stats

- Views: 128
- Downloads: 11
- Favorites: 0
- Popularity score: 0
