KVKK and PCI DSS are two separate frameworks that define how customer and payment data is collected, stored and protected in B2B trade. KVKK governs the processing of personal data, meaning the name, phone, email and current account activity of the dealer's authorized contact. PCI DSS, on the other hand, describes how information such as the card number, expiry date and CVV must be handled in every environment where card data is processed. Unless you set up both together, a gap remains in your collections flow.
The practical summary is this: do not store card data in your own system, run your virtual POS and payment link flows through a PCI DSS certified payment institution, restrict access to customer data on a role basis, and make 3D Secure verification mandatory on every collection. In this article we will set up these steps one by one through a real dealer collection scenario.
If you adapt the checklist below to your own B2B collections process, you both meet your legal obligation and limit your liability in the event of a data breach. On platforms such as B2BPro that bring current account, collections and payment link modules together, most of these controls come ready at the infrastructure level, yet there are still points you need to verify on your own side.
1. Map out what data you hold: the data inventory comes first
Before you start protecting anything, you need to know what you have. Open a table and write down every data type that circulates in your B2B process: dealer title and tax number, the authorized contact's full name, phone and email, current account balance and activity, billing addresses, payment method details. Separate which of these is personal data under KVKK and which is card data under PCI DSS. The title of Demir Ticaret, a legal entity, is not personal data, but the mobile phone number of Ayşe Yılmaz, that firm's accounting manager, is personal data.
For each data type, answer three questions: where is it stored, who can access it, how long is it kept. In this exercise most businesses find card details sitting in an Excel file, old collection records in unpurged emails, or in WhatsApp threads. Even a partial card number kept in a notebook is a PCI DSS violation.
Once you have built this inventory, your goal is clear: card data must not sit in any environment under your control, and personal data must remain only where the work requires it and only for as long as it requires. The inventory also gives you a starting point for processing personal data properly.
2. Do not store card data: tokenization and the virtual POS flow
The shortest path to PCI DSS compliance is never storing card data at all. When you collect a dealer payment through a virtual POS or payment link, the card number, expiry date and CVV must never touch your server, they should be entered directly on the page of the PCI DSS certified payment institution. The only thing returned to your system is a token for that transaction and a reference number. Because you do not hold card data in this setup, the bulk of your PCI DSS burden shifts to the payment institution.
In practice it works like this: you send a payment link to Yıldız Bayi for a 18.500 TL collection, the dealer clicks the link, enters the card details on the bank's secure page, the payment is approved, and on your side only the transaction-successful status, the amount and the token appear. For recurring collections, instead of asking for the card again, this token is used, so card data again never sits with you. The same logic applies in direct debit system (DBS) flows, where instead of a card the limit and reconciliation defined on the bank side do the work.
The critical rule here is that you never write the card number into a database, a log file or a support record, even for your own convenience. Never store the CVV under any circumstances, not even at the moment of the transaction; PCI DSS strictly prohibits this. B2BPro's payment link and virtual POS modules are designed to work on tokenization logic, meaning card data is not held on the platform and the collection result is posted to the current account automatically.
3. Make 3D Secure mandatory on every collection
3D Secure is the layer where the cardholder verifies the transaction with an extra step on the bank side. The bank sends the person entering the card details an SMS code or an app confirmation, and the transaction is not completed without verification. Because amounts are high in B2B collections, rather than leaving this layer optional, run it as mandatory. In transactions made with 3D Secure, if a claim arises that the card was used fraudulently, liability largely shifts to the card-issuing bank.
Set up the flow like this: after the card is entered on the payment link or virtual POS screen, the system should automatically route to 3D Secure verification; if verification fails the transaction should be rejected and no collection should be posted to the current account. Log failed verification attempts, because failed attempts repeated within a short window may be a sign of a card-testing attack.
When verification is complete, report the transaction result to the dealer and to your own accounting at the same time. When Yıldız Bayi approves the payment, a notification should reach the dealer's phone and the current account balance should update instantly. This both reduces reconciliation errors and makes the process transparent in the dealer's eyes.
4. Restrict access on a role basis: who can see what
One of KVKK's core expectations is that only those who need to access personal data for their work do so. Set this up with role-based authorization. The field sales rep should see only the current account balance and order history of dealers in their own region, and not be able to access a dealer in another region or the full customer list. Accounting should be able to enter the collection and reconciliation screens but not drill into a dealer's card transaction detail, because there should be no card data stored there in the first place.
Give every user their own account, do not share a common username. So that you can trace who performed a transaction, every access and every change must be logged. The answer to the question of who raised Demir Ticaret's credit limit, and when, from 250.000 TL to 400.000 TL must sit in the system. These records serve you both in a KVKK audit and in your own internal controls.
When a staff member leaves or changes role, remove or update their access the same day. Lingering old accounts are the most frequent cause of data breaches. On platforms such as B2BPro, because role definitions, region-based dealer access and transaction history can be set at the module level, these controls run systematically rather than through manual tracking.
5. Set up consent flows and the privacy notice
KVKK requires you to inform the data subject when you process their personal data. If you are collecting the phone and email of your dealer's authorized contact, you need to present a privacy notice explaining for what purpose this data is processed and with whom it may be shared. While explicit consent is not separately required for data processed within the scope of performing the contract, if you are going to send marketing SMS or email, you are expected to obtain a separate consent for it. Do not confuse these two cases.
Place the consent flow within the natural flow of the work. The privacy notice should be shown when the dealer record is created, and marketing consent should be presented as a separate checkbox that is unchecked by default. A pre-checked box is not considered valid explicit consent under KVKK. Also leave a path for a dealer who wants to withdraw the consent they gave, for example so they can keep receiving collection notifications while stopping marketing communication.
Keep a record of when and with which text the consents were obtained. If an objection comes later, you need to be able to show which text Yıldız Bayi approved on 12 March to give marketing consent. The same traceability is expected for data shared in processes such as offsetting, reconciliation or quotes.
6. Plan retention, deletion and breach response
Keeping data indefinitely is contrary to KVKK. Define a retention period for each data type and automate the deletion or anonymization step when the period expires. Commercial and tax records are kept for the legal retention period, but old marketing lists that exceed that period or the unnecessary personal data of a dealer you no longer work with should be purged. Put your retention policy in writing so you can show it in an audit.
Encrypt your backups and your data transfers. When sharing a current account report with a dealer or moving data to accounting, use an access-controlled method instead of an open email attachment. Encrypted communication and encrypted storage keep the data unreadable in the event of a breach, which eases both your risk and the consequences of your notification obligation.
Finally, write a breach response plan. When you suspect a data breach, who will be notified, how the affected records will be identified, and within what time the notification to the Personal Data Protection Board will be made should be decided in advance. KVKK expects you to notify the Board as soon as possible from the moment you learn of the breach, as a rule within 72 hours. Running the plan once as a drill earns back, in advance, the time you would lose during a real incident.
Key takeaways
- Do not store card data in your own system; run virtual POS and the payment link through a PCI DSS certified payment institution with tokenization, and never keep the CVV under any circumstances.
- Make 3D Secure mandatory in B2B collections; if verification fails the transaction should be rejected and no collection posted to the current account.
- Restrict access to customer data on a role basis, do not use shared accounts, log every access and change, and remove authorization the same day a staff member leaves.
- Separate the privacy notice from marketing explicit consent; a pre-checked consent box is invalid, and keep obtained consents with their date and text.
- Define a retention period for each data type, delete or anonymize data once it expires, and have a pre-written breach response plan in place.
Frequently asked questions
Can I store card data in my own database in B2B?
No. Storing the card number, expiry date or CVV in your own system aggravates your PCI DSS obligations, and storing the CVV is prohibited in every case. The safest path is to take the payment on the virtual POS or payment link page of a PCI DSS certified payment institution and keep only the transaction token and reference number on your own side.
Is the data of a dealer that is a legal entity also within KVKK scope?
The firm's title or tax number is not personal data, but the full name, phone and email of that firm's authorized contact are within KVKK scope because they belong to a real person. So even if the dealer is a legal entity, you must process the data of the real persons you communicate with according to KVKK rules.
Why is it important to make 3D Secure mandatory rather than optional?
3D Secure verifies the transaction on the cardholder's bank side. When it is mandatory, in an objection claiming the card was used fraudulently, liability largely shifts to the card-issuing bank. In high-value B2B collections this reduces both fraud risk and chargeback-driven losses.
Is the consent in the contract enough for marketing?
No. The data processing required to perform the contract and the explicit consent required for marketing communication rest on different grounds. If you want to send marketing SMS or email, you need to present a separate consent box that is unchecked by default; a pre-checked box is not considered valid explicit consent.
What should I do if I experience a data breach?
The moment you suspect a breach, activate the response plan you prepared in advance: identify the affected records, restrict access, and notify the Personal Data Protection Board as a rule as soon as possible, within 72 hours. Having stored the data encrypted keeps the information unreadable at the time of the breach and eases the consequences.
Does B2BPro provide these compliance steps automatically?
B2BPro's payment link and virtual POS modules are designed to work with tokenization without storing card data on the platform and to support 3D Secure verification; role-based access, region-based dealer authorization and transaction history are also defined at the module level. Even so, decisions belonging to your own processes, such as the privacy notice, retention periods and the breach plan, are for you to configure.