Türkiye doesn’t have one remote identity verification recipe. A bank, telecom operator, and crypto platform may check the same person against the same Turkish identity card, yet follow different rules for NFC, biometrics, and recordkeeping.
The rules moved again on September 3, 2026. The Capital Markets Board introduced a passport-based remote onboarding route for foreign customers of investment firms, portfolio managers, and crypto asset service providers. The update made NFC passport verification a practical requirement for another group of regulated providers.
In brief: Türkiye uses sector-specific remote identity verification rules rather than a universal KYC process. Turkish customers are generally verified using an electronic identity card, while the 2026 amendments introduced an NFC passport route for eligible foreign customers.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Regulations and regulatory interpretations may change. Organizations should confirm the requirements for their license, use case, and customer population with qualified counsel and the relevant regulator.
How do Turkish privacy laws affect identity and biometric data?
Türkiye’s Personal Data Protection Law No. 6698, commonly known as the KVKK, applies across sectors. It requires personal data to be processed lawfully, for specific and legitimate purposes, and in a way that is relevant, limited, and proportionate to those purposes.
It also defines personal data categories, like general and special (sensitive). Biometric data falls under a special category, which means it’s generally prohibited from being processed unless certain legal conditions are met.
In April 2025, Türkiye’s Personal Data Protection Authority also published guidance on processing Turkish Republic identity numbers. Although an identity number isn’t classified as special-category personal data under the KVKK, it requires particular care because it can facilitate access to other personal information.
The guidance emphasizes necessity and proportionality. Where the same purpose can be achieved with a less intrusive identifier, organizations should use that alternative. For example, if a mobile application can verify a person using a phone number, processing their identity number may be considered unnecessary and disproportionate.
At the same time, this principle doesn’t replace sector-specific rules that expressly require the identity number for customer identification or verification.
KEC-based verification
Türkiye also operates a separate Elektronik Kimlik Doğrulama Sistemi (EKDS), or Electronic Identity Verification System, for authentication with the Turkish identity card. The card is read through a dedicated secure terminal called a Kart Erişim Cihazı (KEC), or Card Access Device.
Government bodies can use it to verify that a Turkish identity card is genuine and that the person presenting it is the legitimate cardholder. For example, Türkiye’s land registry authority uses EKDS to verify identities in title deed transactions.
This is different from the standard NFC chip checks used in many commercial remote onboarding flows, where a mobile device reads identity data from the contactless chip. KEC is designed for institutional EKDS authentication and supports access to protected verification functions that an ordinary NFC check doesn’t.
How do Turkish identity verification requirements vary by industry?
Each regulated industry combines Türkiye’s general privacy and anti-money laundering rules with its own technical and procedural requirements. The table provides a route map, while the following sections explain the relevant processes in more detail.
| Industry | Main authorities | Remote verification baseline |
|---|---|---|
| Banking | Banking Regulation and Supervision Agency (BRSA) and Financial Crimes Investigation Board (MASAK) | Risk assessment, Turkish identity card authentication, biometrics, liveness, and secure video, with a regulated fallback if NFC cannot be completed |
| Payment and electronic money institutions | Central Bank of the Republic of Türkiye (CBRT) and MASAK | NFC or a CBRT-accepted alternative, portrait comparison, liveness, secure real-time communication, and remote contracting controls |
| Crypto asset service providers | Capital Markets Board (CMB) and MASAK | Capital-market remote identification rules, government-database checks, enhanced due diligence, monitoring, and recordkeeping |
| Telecom and internet providers | Information and Communication Technologies Authority (ICTA) | e-Government authentication, NFC- or contact-based electronic ID checks, video verification, and government-assisted routes for some foreign nationals |
MASAK’s anti-money laundering rules cut across several of these sectors, but they do not replace sector-specific requirements. A remote method generally has to satisfy both the AML rules and the legislation governing the organization’s main activity.
What do Turkish banks need for remote customer identification?
Banks can onboard eligible customers remotely, but the process is treated as a critical operation. The BRSA regulation, effective since May 2021 and amended in 2023, combines an application and risk assessment with document authentication, biometric comparison, liveness controls, and a secure video process.
Before the video stage, the applicant submits an electronic form, and the bank assesses the available data. The bank can stop an application before the call if the risk assessment is unfavorable.
During remote identification, the regulation provides for controls including:
-
A real-time, uninterrupted video process with sufficient image quality to inspect the document and the person
-
Verification of identity data from the document chip through NFC, where available
-
Face comparison using the portrait obtained from the chip, or the portrait printed on the card, when chip data cannot be obtained
-
Liveness checks and additional measures addressing deepfake risks
-
Secure communications and records that allow the bank to demonstrate how the decision was made
NFC is the strongest route, but the banking regulation includes a fallback for cases where an NFC check cannot be completed.
Technical providers involved in the remote verification process must be certified under ISO/IEC 27001, a global standard for information security management.
How do payment and electronic money rules differ from banking?
These institutions handle regulated fiat payment services and stored-value balances and use many of the same technical controls as banks. However, they don’t follow the BRSA banking workflow and are supervised by the CBRT under Law No. 6493 and the sector’s information-systems rules.
When a document chip cannot be verified through NFC, the payment-sector fallback can use optical character recognition, a card reader, or another method.
The CBRT framework also allows liveness to be established through online real-time video, real-time moving images, or an online video call. When video or moving images are used instead of an online video call, the system must prevent prerecorded material from entering, issue unpredictable random prompts, perform the required controls using at least three images, and save the records to the institution’s servers in real time.
What is required of Turkish crypto asset service providers?
Crypto asset service providers can onboard customers remotely under the CMB framework used by investment firms and portfolio management companies, together with MASAK’s anti-money laundering rules. This includes (but is not limited to) remote identification and electronic contracting with fraud controls, information security, and recordkeeping.
For Turkish customers, specified data — including name, date of birth, address, and Turkish Republic identity number — must be checked against the government’s Identity Sharing System. The September 2026 amendment also added an NFC-passport route for eligible non-Turkish customers and rules for remotely identifying legal entities, their representatives, and beneficial owners.
Identity verification is only one part of crypto compliance. Providers must also apply enhanced due diligence and ongoing monitoring where the risk warrants it. Documents, videos, and electronic records from remote identification must be retained for ten years. Outsourcing doesn’t remove the provider’s responsibility.
Which Turkish ID documents are required for remote verification?
The Turkish identity card is the main document for domestic identity checks, while passports provide an ICAO-standard electronic document for higher-assurance and cross-border verification. Driver’s licenses can also serve as evidence of identity in some contexts, although regulated remote onboarding may require a specific document.
The current Turkish passport is a biometric and ICAO-compliant document with an RFID chip. The chip stores the holder’s biographic data and facial image, allowing verification systems to compare the physical document, machine-readable data, and electronic chip data rather than relying on a passport photo alone.
A Turkish passport follows international layout and data standards, is available in both Turkish and English, and can be valid for up to 10 years.
The Turkish national identity card is the primary domestic identity document for Turkish citizens and plays a central role in regulated remote onboarding. Its chip stores identity data and the holder’s biometric portrait.
The card also contains the unique 11-digit Turkish Republic identity number, which can be verified by matching it with the barcode on the reverse side or cross-checking with government databases.
The Turkish driver’s license is primarily intended to confirm that the holder is qualified to drive certain vehicles. It can serve as identity evidence in use cases where a driver’s license is accepted, but its regulatory role differs from that of the electronic identity card or passport.
The current Turkish driver’s license version was updated in 2016 to align with EU standards. As a result, its design and security features are now very similar to those found in European driver’s licenses.
Can non-Turkish nationals be verified remotely?
Yes. Since June 27, 2026, eligible non-Turkish natural persons can be verified remotely by institutions within MASAK’s scope using an ICAO Doc 9303-compliant passport with an NFC chip. A September 3, 2026, CMB amendment added the corresponding route for investment firms, portfolio management companies, and crypto asset service providers.
The process requires successful NFC chip verification and a video call with trained personnel; if the chip cannot be verified, the relationship cannot be established remotely under this route. The customer must be classified as high risk, and their address must be verified within three months. Transaction restrictions apply until that check is complete.
How can companies apply Türkiye’s identity verification rules in practice?
A requirements map is the practical bridge between regulation and technology. Because requirements differ by sector, customer type, document, and verification route, it helps define each journey precisely:
-
Which document can be accepted
-
Whether NFC or video is required
-
What fallback is permitted
-
Which data must be checked
-
What evidence needs to be retained
The same map can guide vendor evaluation and proof-of-concept testing. It also helps identify where one technical component can be reused across several journeys and where the workflow needs to branch.
Regula IDV Platform can translate those requirements into configurable verification workflows, with distinct sets of checks and routes tailored to customer types, documents, and regulatory scenarios. Deployment can also be matched to the same requirements, including customer-controlled on-premises infrastructure where needed.
If you are designing or updating an identity verification flow for Türkiye, talk to Regula’s experts about the documents, checks, and deployment model that best suit your use case.
