An Azure service that provides streamlined full-stack web app development.
Hello @Fatih Akşener
Your understanding of the regulatory mechanism is generally correct. Türkiye’s Personal Data Protection Authority (KVKK) publishes four standard contracts for international transfers, including Standard Contract 2 - Controller to Processor, which is the relevant template where the Turkish exporting organization acts as controller and the overseas recipient acts as processor.
However, the questions you're asking about which Microsoft entity should be named, whether Microsoft will countersign SS-2, who has authority to sign it, and what Microsoft-specific annexes should contain can't safely be determined from the Azure or Microsoft 365 product configuration alone.
Those are Microsoft contractual/legal-entity questions and need confirmation from Microsoft's commercial/privacy contracting team.
Microsoft does publish the Microsoft Products and Services Data Protection Addendum (DPA), including a Turkish version. The current DPA defines Microsoft's data-processing and security commitments for Microsoft products and online services and forms part of Microsoft's commercial licensing terms.
Importantly, don't independently insert a Microsoft corporate entity from the DPA into SS-2 or modify the mandatory SS-2 wording. The appropriate Microsoft contracting entity can depend on the customer's commercial agreement and purchasing channel, and Microsoft needs to confirm which entity is the data importer for this specific relationship.
Likewise, I don't see a published Microsoft procedure that authoritatively says that a customer can submit the Turkish SS-2 through Azure Portal support and have it countersigned there. Microsoft Q&A also isn't a contracting channel, so nobody here can execute the agreement or confirm that.
Therefore, handle this through the customer's Microsoft account/commercial channel. If MIZAN purchases through a CSP/reseller, ask the partner to escalate the request to their Microsoft commercial contact. If the organization has a Microsoft account team, ask that team to route a request specifically for:
“Türkiye KVKK Article 9 international data transfer – execution of Standard Contract 2 (Controller-to-Processor) for Microsoft Online Services.”
Make clear that you're not requesting interpretation of Turkish law. You're requesting Microsoft's contracting instructions.
Don't assume that Microsoft Graph needs a separate SS-2 simply because it is a separate API. Graph is an access/API layer across Microsoft cloud services; the relevant contractual analysis should instead follow the Microsoft products/services, customer agreement, and processing relationship involved. Whether those workloads can be placed under a single SS-2 is something Microsoft's contracting team should confirm, not something we should infer here.
So, from the community side, "Yes, SS-2 is an official KVKK transfer mechanism for a controller-to-processor relationship, but the Microsoft entity, scope, annex contents, countersignature process, and execution channel need written confirmation from Microsoft contracting/privacy personnel."
I don't recommend changing any Azure or Microsoft 365 configuration, signing an SS-2 with an assumed Microsoft entity, or treating the existing Microsoft DPA alone as confirmation that the Turkish SS-2 execution requirement has been met.
References:
KVKK – Announcement and Standard Contract Texts
Microsoft Products and Services Data Protection Addendum
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.