We're a B2C e-commerce platform with over 1 million registered users whose identity, contact, and order history are in our database. We've started talking to a SOC provider to step up our internal cybersecurity. In this project, where we've allocated an annual budget of roughly 700,000 TL, we ran into a legal and technical question mark while reviewing the security architecture.
We learned that the central security platform the SOC provider uses is cloud-based, with data centers in Europe and the US. Security analysts will directly examine our server logs, authentication records, and network traffic. However, web and database logs can contain personal data like email addresses, IP info, or order parameters. We don't know whether routing this data to servers abroad puts us under serious risk of KVKK fines.
Should we make it a mandatory condition that logs are kept within Turkish borders? What concrete commitments and retention period guarantees should we demand from the provider under a Data Processing Agreement (DPA) at the proposal stage?