forumNew topic

Where are our logs and customer data stored in a SOC service — do I need to ask from a KVKK standpoint?

İİbrahim T***MemberCommunity member
Joined
Aug 2023
Message
279
#1

We're a B2C e-commerce platform with over 1 million registered users whose identity, contact, and order history are in our database. We've started talking to a SOC provider to step up our internal cybersecurity. In this project, where we've allocated an annual budget of roughly 700,000 TL, we ran into a legal and technical question mark while reviewing the security architecture.

We learned that the central security platform the SOC provider uses is cloud-based, with data centers in Europe and the US. Security analysts will directly examine our server logs, authentication records, and network traffic. However, web and database logs can contain personal data like email addresses, IP info, or order parameters. We don't know whether routing this data to servers abroad puts us under serious risk of KVKK fines.

Should we make it a mandatory condition that logs are kept within Turkish borders? What concrete commitments and retention period guarantees should we demand from the provider under a Data Processing Agreement (DPA) at the proposal stage?

VVeli T***Member
Job title
Human Resources Specialist
Sector
Agriculture
Organization type
120-person company
Joined
Apr 2023
Message
1
Most Helpful#2

Short answer: IP addresses, usernames, and URL parameters found in log records qualify directly as personal data under KVKK; transferring this data to a foreign-based cloud platform clearly violates regulations unless statutory transfer conditions are met. Therefore, the contract must either commit to storing data in data centers within Turkey, or irreversible masking must be performed on a local collector before transfer.

On e-commerce sites, web server logs often contain sensitive parameters in GET requests, like email addresses, names, or even payment reference numbers. While recent amendments to the law introduced mechanisms such as Standard Contractual Clauses approved by the Personal Data Protection Board or binding corporate rules for cross-border data transfers, choosing infrastructure hosted directly in Turkey fully protects you from this bureaucratic and punitive risk.

When evaluating the SOC proposal, you should mandate the technical architecture as follows: Personal data must be masked or pseudonymized using regex filters on a log collector installed within your corporate network. What analysts see on their screens should not be usernames or customer details, but strictly system events.

On the legal front, a comprehensive Data Processing Agreement must be signed. This text should explicitly stipulate, backed by penalty clauses, that data will only be stored in designated locations within Turkey, securely destroyed at the end of the retention period, and not shared with any third party abroad.

UUmut Ş***Expert
Job title
DevOps
Organization type
boutique agency
Joined
Aug 2023
Message
231
#3

Get log scrubbing done before it leaves your network. Have the agent or collector installed on your own server hash or star out email and identity data in the logs using SHA-256. Only scrubbed security telemetry should leave, eliminating the risk of data leaks.

YYavuzExpert
Job title
Information Security Manager
Joined
Jul 2023
Message
168
#4

Under Article 9 of KVKK, the transfer of personal data abroad is bound by strict rules. Unless standard contracts are drafted with your service provider and notified to the Board, storing data on foreign servers will result in administrative fines against your company as the data controller.

SSelmaMember
Job title
Online store
Joined
Jul 2024
Message
94
#5

Add this exact sentence to the RFP: 'All log data and analytical outputs shall be stored in data centers within the borders of the Republic of Turkey.' Drop any provider who can't commit to this right from the start, or you'll have massive headaches later.

FFiliz P***Member
Job title
Production Manager
Sector
E-commerce
Organization type
300-person organization
Joined
Jun 2025
Message
166
#6

We faced the exact same dilemma. The provider quoted 120,000 TL more per year for the locally hosted solution in Turkey. We ran the numbers with our legal counsel; that price gap was negligible compared to the fines and brand damage from a potential data breach notification, so we went local.

AAleyna S***Member
Job title
Export manager
Sector
E-commerce
Organization type
medium-sized business
Joined
Aug 2024
Message
3
#7

Is the provider only collecting SIEM logs, or are they sniffing all packet traffic (PCAP) on the network too? If they're doing packet analysis, they could see all form data in HTTP traffic in clear text except credit cards—have you checked that?

AAycan K***Member
Job title
Store Manager
Sector
Catering
Organization type
20-person company
Joined
Mar 2024
Message
132
#8

Some vendors who claim 'our data center is in Turkey' only keep the database here and send the analytics to AI engines abroad. Unless you get it in writing as 'all systems, including data processing and analytics engines,' they'll find a loophole.

HHüseyin Ş***Member
Job title
Network Administrator
Sector
Packaging
Organization type
a company within a holding
Joined
Jul 2023
Message
81

Doki · Brand identity · 2025

#9

at our old company we had a system that sent logs to the us and during an audit the inspector caught a customers national id in a url inside a log file we barely survived writing justifications definitely get them maasked imo.

edit: fixed a few typos.

ZZübeyde D***Member
Job title
Marketing director
Sector
Freight
Organization type
300-person organization
Joined
Mar 2024
Message
174
#10

Ultimately, you have two paths: either implement strict masking on the log collector so personal data never leaves the premises, or sign with a locally hosted SOC model whose entire infrastructure is within Turkey.

IIrmak Ş***VeteranCommunity member
Joined
Sep 2022
Message
32
#11

im in the same situation thats why Im asking.. then tbh an automated scan report is not the same as a penetration test.

if you post the result here it will help others too.

MMert K***Member
Job title
Store associate
Sector
Energy
Organization type
sole proprietorship
Joined
Dec 2024
Message
304
#12

Saved.

AAli T***Member
Job title
Board member
Sector
Chemistry
Organization type
8-person team
Joined
Jun 2025
Message
334
#13

my perspective changed after experiencing that then like solutions that work at a small scale collapse when you grow; I learned this late.

paayment information changes are never verified through the channel they came from then if you post the result here it will help others too.

NNazlı G***MemberCommunity member
Joined
Oct 2025
Message
253
#14

This thread is archived. Processes without records never improve, because you don't know what to fix.

AAhmet O***MemberCommunity member
Joined
Feb 2025
Message
142
#15

The cheap-looking path usually ends up costing more later. If permission and scope aren't in writing, don't start that test.

When we decide without measuring, we always end up in the same place.

RRecep T***Member
Job title
Sales Manager
Sector
Accounting & advisory
Organization type
cooperative
Joined
Dec 2023
Message
2

Doki · SEO consulting · 2023

#16

correct.

GGülMember
Job title
Fashion brand
Organization type
40-person manufacturing company
Joined
Nov 2023
Message
128
#17

i'm a small business let me explain from my side and mistakes made on the where is soc data stored side are usually reversible but expensive.

BBaranMember
Job title
Game developer
Organization type
120-person company
Joined
Jun 2024
Message
98
#18

I didn't know that.

AAhmet Ç***Member
Job title
Warehouse Manager
Sector
Jewelry
Organization type
workshop
Joined
Jan 2026
Message
399
#19

noted thanks.

MMehmet A***Member
Job title
Sales Manager
Sector
Insurance
Organization type
two-branch business
Joined
Mar 2026
Message
251
#20

Generally correct, but one part is missing. If you don't write this down from the start, it leads to arguments later.

Proven by experience.

Reply