Türkiye Regulation
10 entries · 10 credit someone else by name · 0 running here
Türkiye's identity rules are written across MASAK circulars, KVKK, the e-Devlet gateway, BTK's SIM registration regime and the crypto-exchange licensing framework, and almost nowhere are they set out together in one place. This section does that: what each rule obliges you to do, who enforces it, and which of them bite at onboarding rather than later.
That gap matters more than usual, because Türkiye is the one market where Solidus content converts. Search data shows Turkish readers clicking at roughly 19.8% where the global average sits near zero. The audience that actually reads us is in the jurisdiction whose rules we have not built for. Naming that gap is more useful than papering over it.
Why the Turkish regime deserves its own section
Because it is not a translation of the EU's. Treating KVKK as "Turkish GDPR" or MASAK as "the Turkish AMLD" produces advice that is wrong in the specifics that matter, different authorities, different reporting thresholds, different retention periods, different lawful bases.
- MASAK, the Financial Crimes Investigation Board, under the Ministry of Treasury and Finance. The AML supervisor, whose obligations flow from Law No. 5549. A Turkish crypto exchange's KYC programme exists because MASAK requires it.
- KVKK, the Personal Data Protection Law (No. 6698) and the authority enforcing it. Overlaps GDPR in shape and diverges in detail; explicit consent, data-transfer rules and the registry obligation all work differently.
- TCKN, the Turkish national identity number. Eleven digits with a checksum, present on every Turkish ID document, and the join key for most identity processes in the country. A checksum can be validated arithmetically; whether a TCKN belongs to a real living person can only be answered by a state system, and we do not query one.
- e-Devlet, the national e-government gateway. The channel through which a Turkish citizen already proves identity to the state, and therefore the benchmark any private verification flow is implicitly compared against.
- Turkish crypto-exchange licensing, the Capital Markets Board regime that brought crypto asset service providers under formal supervision. This is why exchange compliance teams are buying identity infrastructure now rather than later.
- BTK SIM registration: the telecoms regulator's identity requirement before a line is activated, and the legal basis of the SIM-registration vertical.
- Law 6222, the sports-events law behind stadium entry identity requirements, and the legal root of the venue-access vertical.
What is honest to say
These entries are the buyer's regulatory context, defined, not features. A compliance officer at a Turkish exchange or bank reads them and recognises their own obligations described accurately; that is the entire intent. Solidus's KYC engine runs on a public testnet, has no audit, and has no paying customer in Türkiye or anywhere else.
Turkish-language versions of these entries are the obvious next step and are on hold pending a decision about the Turkish content lane, because a machine translation of a legal-vocabulary page is worse than no page, and these are the ones a native reader would judge hardest.
Where this category ends
The EU regime is separate and does not transfer. The compliance processes themselves, CDD,
PEP, sanctions screening, are the identity section, also not-built. The verticals these laws
create demand in are the vertical section.
What Solidus has built against these rules
Nothing. No MASAK reporting, no KVKK compliance tooling, no e-Devlet integration, no TCKN
validation against a state register. Every entry here says not-built, and nothing on this page is a
compliance claim.