Back to Blog
Privacy & Security

Executive Privacy in VIP Ground Transport: KVKK, GDPR, and Route Confidentiality

Deniz Arslan May 5, 202618 min readUpdated: 2026-05-24
Executive Privacy in VIP Ground Transport: KVKK, GDPR, and Route Confidentiality

Why privacy in ground transport matters as much as physical security

Six years in the transport department of the Istanbul Chamber of Commerce taught me one thing: procurement teams still too often treat VIP transfer like a "luxury taxi" service. In reality, executive ground transport is a closed data pipeline. Flight number, hotel address, meeting time, and sometimes a not-yet-public M&A destination all land in a single case file with the same service provider.

When that information leaks, physical threat does not have to follow. For market manipulation, press leaks, or competitive intelligence, the schedule of a board member between airport and factory visit is often enough.

At EBA VIP Services, in 287 audited corporate client cases over the last eighteen months, the full route appeared in an assistant's WhatsApp message in roughly one out of every two files. End-to-end encryption does not help when the provider's phone is stolen or the backup policy is unclear. Data protection is an operational discipline — not the logo on the bonnet.

The car as a second soft attack surface

After passport control at Istanbul Airport (IST), the drive to a holding company in Levent is often the only enclosed window in which the guest takes calls, reads email, and sometimes fields press questions. Chauffeur behaviour, dispatch access, and route storage duration belong in the same risk matrix as security staff at the terminal.

Google's YMYL classification (Your Money Your Life) demands higher content care for health, finance, and security topics. VIP ground transport sits at the intersection of executive protection and personal data processing. Marketing copy about "five-star comfort" is not enough for compliance and procurement teams — they need documents, deadlines, and reporting chains.

Risk committees increasingly treat ground transport like flight bookings: formal supplier, traceable processes. ISO 31030 for travel risk management emphasises documentation and auditability. In Istanbul, where traffic peaks can fragment routes, route protection is not only a legal topic but also a scheduling and reputation topic.

When onboarding a new provider in Istanbul as travel manager or chief of staff, apply the same diligence you would to a cloud vendor with access to customer data. Vehicle livery says nothing about access controls, training records, or whether subcontractors see your route on a second screen the same night. In RFPs I still see too often only price per kilometre and vehicle age — no line on VERBİS, deletion periods, or incident SLA.

Which data in the transfer process is personal

Under Turkish KVKK (Law No. 6698), all information relating to an identified or identifiable natural person is personal data. Typical data sets in VIP transfer: name, mobile number, email, flight number, arrival time, pickup point, destination address (hotel, office, plant), intermediate stops, special requests (child seat, escort, protocol), and billing data.

The question "Where did this guest go last month?" is still retrievable in many systems for six to twelve months. On M&A or investor tours that can be a trade secret. KVKK requires data minimisation and purpose limitation — "store indefinitely just in case" is hard to defend before the Kurul.

The guest's mobile number on the chauffeur's private phone is also personal data. In audits I found an informal "regular customer" directory on roughly one in three freelance drivers. The operator remains data controller; the driver becomes an uncontrolled processor.

KVKK, GDPR, and special categories

For EU citizens or persons resident in the EU, GDPR applies additionally. The operator in Turkey must clarify in contract whether it acts as controller or processor. Global corporations often require a data processing agreement under GDPR Article 28.

Special categories (health, biometrics) are rare — except for wheelchair requirements or notes about medical devices. Then consent and safeguards change. An uncategorised free-text field "special request" mixes sensitive details into general route notes.

On group trips (board, delegation) several persons sit in one file. Each data subject needs separate information or a clean group arrangement. One participant's erasure request must not block the others — the file must be segmentable.

Assistant teams often transmit "packages": flight from the app, hotel from the booking tool, route via messenger. Each channel has its own retention and its own subprocessors. An integrated VIP provider reduces the number of places the same address sits — but does not replace the duty to audit that one provider. When the corporation uses a global TMC, the interface between TMC and local chauffeur must be described in the DPA or MSA annex, including deletion after trip end.

Flight numbers and planned arrival times are essential for operations but raise the guest's profile in external feeds. Privacy notices should explain whether the operator uses only public flight status data or deeper GDS-like sources — and how long those fields are stored.

KVKK: obligations of the VIP operator in Turkey

The licensed transfer provider is data controller. VERBİS registration, privacy notice, consent where required, and response to erasure requests under KVKK Article 7 are mandatory — not optional. "We only transport" does not apply once the name appears on the dispatch screen.

Serious Istanbul providers maintain a processing inventory: system, legal basis (contract, legitimate interest, law), access, deletion period. At EBA we update this twice yearly; as subcontractor fleet grows, the access matrix quickly becomes unwieldy.

On personal data breaches the KVKK Kurul can trigger notification duties. The emergency plan must include "unauthorised access to dispatch." In one industry case a former dispatcher reported only after three days that his account was still active — in the meantime fourteen executive routes were visible.

Erasure requests and tax retention

Invoices and tax records often remain archived for ten years under Turkish law; GPS trace and detailed route can be deleted earlier. The difference between "everything deleted" and "everything deleted except legal obligation" builds trust with the compliance officer.

Excessive retention is regularly sanctioned by the Kurul. For global customers KVKK compliance is now often a pass/fail criterion on the supplier list. Without VERBİS, large holdings rarely make the shortlist.

Legitimate interest as legal basis — "we store routes for better service" — holds only if the guest does not object and storage stays proportionate. Written agreement in the MSA with a concrete period is the cleaner basis for procurement teams. On objection the operator must document the balancing test and delete if required.

Data protection impact assessment (DPIA) is required by GDPR in high-risk cases; large corporations pass the question via questionnaire to the Turkish supplier. Who answers structurally — inventory, TOMs, subprocessors, deletion concept — wins tenders. Who answers "we have not done that yet" loses not only the contract but risks internal blocklisting.

GDPR: what European corporations require

For board members from Frankfurt, Amsterdam, or Paris, the Istanbul partner processes data on their behalf. Standard contractual clauses (SCC), DPA, and subprocessor list are on legal's checklist.

Minimisation and storage limitation under GDPR align with KVKK — EU supervision audits the chain more aggressively. "Our drivers are freelance" ignores that the driver sees routes on the operator's behalf. At EBA every active chauffeur signs a processing agreement; routes must not be copied into private apps.

Turkey has no EU adequacy decision. For EU customers SCC or BCR are relevant. Procurement should ask server location and backup region — not only vehicle class.

Most common request: "Delete all routes from the last year and confirm in writing." Without automated deletion jobs manual handling takes fifteen business days — that belongs in the framework contract as SLA.

GDPR Article 17 (right to erasure) and Article 15 (access) reach us parallel to KVKK requests. The response must show which systems were affected: dispatch, CRM, telephony, dashcam, backups. An erasure certificate without a system list looks thin in an EU audit. We deliver tabular confirmation: category, deletion date, exception reason if any.

Transfer to third countries outside EU/Turkey — for example when a dispatch vendor uses US cloud — must be named in contract. Procurement should ask about sub-sub-processors, not only the chauffeur company at the top.

Route confidentiality: need-to-know in practice

Need-to-know means: only the driver on that trip and the responsible dispatcher see the full address. Fleet management, accounting, and marketing have no default access. At EBA we use role-based rights; even admin accounts do not see complete history without reason.

Multi-stop tours — IST → headquarters → confidential plant visit → hotel — carry the highest leak risk. Instead of pushing the day plan once, we open segments sequentially (progressive disclosure). If the phone is lost, the whole day is not readable.

Live tracking for assistants needs separate consent and expiry — the link dies with trip end. Permanent links create historical maps; that is problematic under KVKK.

Private Google Maps use by the driver exports addresses to third parties. We prefer navigation in the dispatch app or corporate navigation with history deletion. Our Istanbul Airport VIP security guide connects terminal procedures with controlled route release.

Multi-day programmes and public perception

On three-day Istanbul programmes the factory address for day two is not released on the evening of day one. When the chauffeur changes, the replacement sees only the current segment — even with a dedicated driver.

"Silent arrival" coordinates chauffeur, hotel, and dispatch: rear entrance, service lift, waiting position without visible plate in front of live cameras. That is the physical side of the same confidentiality logic.

Meet-and-greet with name board at IST terminal helps first-time visitors; for known faces with media interest it is risky. Alternatives: discreet identifier on the sleeve, meeting point in a lounge with access control, or pickup in the underground garage with area clearance. Each variant must be agreed in advance with security and hotel — spontaneous changes by phone without log are forbidden in our Platinum cases.

Shared rides (two executives from one corporation) halve cost but double consent complexity: both parties must know who sees the route. Standard is separate dispatch cases with shared vehicle assignment, not one WhatsApp group with full addresses of all participants.

NDA and contract layer

On non-public M&A visits a mutual non-disclosure agreement is standard. It sits between operator and corporate client; chauffeur and dispatch are bound through the operator. Typical clauses: definition of confidential information, use limits, term, return/destruction, contractual penalty.

Embassies sometimes replace NDA with protocol letters or security briefings — what matters remains: no hotel or meeting address before signing. "Urgent transfer, NDA to follow" often means the address is already out.

In the framework agreement (MSA): retention periods, subprocessors, incident notification deadline (e.g. 72 hours), audit right. About sixty percent of our Fortune 500 clients send annual compliance questionnaires; who does not respond is removed from the panel.

A press leak referencing "transfer driver" led us to a full chain review — the source was later the hotel reception, not the chauffeur. Still the case showed: NDA must be lived in the supply chain, not only archived.

Chauffeur conduct: what must not be documented

Professional VIP chauffeur means unobtrusive — that is trained, not accidental. In the EBA programme the confidentiality module is mandatory. Forbidden: recording phone calls, photos in the passenger compartment, social media hints about guests, copying routes to private phone, sharing "celebrity in the car" with acquaintances.

In-cabin cameras are unsuitable for confidential board conversations. Exterior dashcam for insurance is common — disclose in contract, cabin microphone off. In-cabin camera usually needs explicit consent; in the executive segment it is rarely accepted.

No curious questions about company or appointment. Brief greeting, then silence — unless the guest starts conversation. Dedicated chauffeurs build trust; rotation and replacement drivers must still be governed. On exit all data access ends immediately — details on D2 licence and driver authorisation are in our separate guide.

Dispatch, encryption, and subcontractors

Dispatch is the digital heart of route confidentiality. Minimum standard: TLS for web access, multi-factor authentication, session timeout, access logs, encrypted backups. EBA hosts in Turkey; night backups with AES-256.

WhatsApp routes are fast but hard to audit. For corporate clients we confirm via portal or extranet; phone changes land in the system — without full address in chat.

Subcontractor drivers are used by many licensed operators at peak. The sub must accept KVKK processing contract and same deletion rules. Audit question: "Is the driver listed in your VERBİS as processor tonight?"

Annual penetration test on the dispatch panel — in the last run a weak test account was closed. Small operators skip this; without an RFP question it does not surface.

App versions and TMC interfaces

Outdated chauffeur apps can leave routes in cache. Mandatory updates and remote cache wipe are fleet policy. Three versions behind: no new trips.

Concur, Cytric, and other TMCs feed bookings via API — each hop needs a DPA chain. API keys via WhatsApp is not acceptable practice.

Shift operation in dispatch: night teams must not have permanently elevated admin rights. We quarterly check bulk exports, screenshots in private chats, and logins outside Turkey without ticket. Spot checks compare booked vs driven route — deviation without documented diversion is a discipline matter. Company phone with MDM and remote wipe on loss is standard; loss report within one hour is in the model MSA.

Comparison of typical retention periods in Istanbul VIP ground transport
Data category Industry typical EBA VIP standard Deletion trigger
Guest name and mobile number12–24 months12 months encryptedCustomer request or contract end
Full route (stops, hotels)6–12 months90 days without M&A/embassy riderTrip end + 90 days
GPS traces30–90 days30 days rollingAutomatic purge
Dispatch call recordings12 months6 monthsRetention calendar
Exterior dashcam7–30 days7 days (no cabin audio)Insurance case closure
Invoice and tax records10 years (statutory)10 years (VUK)Statutory period only
Mutual NDA (PDF)Contract + 3 yearsContract + 5 yearsEnd of legal hold

Data retention: carry the table into the contract

The table above contrasts typical market periods with EBA standards. Clients can agree shorter periods in the MSA — e.g. route only 90 days. Except tax archive that is technically feasible when deletion jobs run.

Deleting GPS after 30 days rolling meets minimisation and cuts storage cost. After accident or lost baggage 30 days is sometimes insufficient — then the client agrees a legal hold; the affected case is frozen.

Call recordings six months for quality; guest name can be anonymised. Without M&A or embassy rider: full route gone 90 days after trip end.

Invoices ten years under VUK — but the invoice line stays generic ("transfer Anatolian side Istanbul"), not the house number. Detail route only in dispatch, deleted there; booking receipt remains.

Clients with German or Austrian group headquarters sometimes require retention under twelve months for all non-tax fields. Technically we set this as profile in the MSA: "EU-Strict" with 90-day route, 30-day GPS, 12-month contact only if active contract. After contract end: 30-day grace, then contact deletion.

Backup tapes are the forgotten storage location: deletion in live database is not enough if weekly images still carry the route for eight weeks. Retention on backups must match live policy — otherwise every erasure certificate fails when it matters.

IST and SAW: different profiles

Istanbul Airport and Sabiha Gökçen differ operationally. IST: meet-and-greet, terminal access, and VIP parking depend on airport certificates. Name on the board draws attention — alternatives: code name or company logo.

SAW is more compact; waiting times at the kerb are often shorter. Who chooses SAW for Anatolian side and then drives to a European-side hotel exposes a second route. In our SAW versus IST comparison we match profiles to the right airports.

Flight tracking improves arrival — flight data is also personal. The privacy notice should include one sentence on access to airline feeds.

Night arrivals after 02:00 at IST: quieter terminal, fewer greeters — fewer witnesses, but tired guests and narrower dispatch. 24/7 dispatch and encrypted line belong in the MSA.

Winter fog delays baggage — operational buffer avoids hectic repetition of full addresses at the belt. From November to March we reserve twenty minutes spare for Platinum; backup chauffeurs stay within five kilometres. HGS/OGS transponders reduce cash stops and unnecessary visibility at toll plazas.

M&A, diplomats, and high media exposure

On confidential due diligence runs the operator is bound into the bank's or law firm's NDA chain. Addresses as code ("Project Anatolia — point B Beşiktaş"); the chauffeur sees only the code, company name sits encrypted in dispatch.

Embassies sometimes bring own staff; local partner supplies backup vehicles with minimal data — plate, vehicle type, one contact number. Security departments vet the operator in advance.

Media and culture: paparazzi risk. Rear entrance, service lift, no waiting with visible plate in front of the lobby.

During protests or major events dispatch changes live; old routes are not deleted immediately when security follow-up is needed — legal hold possible.

Incident response and notification

Typical scenarios: dispatch hack, lost chauffeur phone, wrong email with route list, former employee access. The plan should describe customer notification within 24 hours and where required Kurul notification within 72 hours.

Tabletop once yearly: "Admin password leaked — what now?" Kill sessions, rotate passwords, check logs, list affected trips, inform client compliance in writing.

Cyber insurance is rare among small operators; corporations ask coverage limits. Contractual penalty from NDA supplements insurance, does not replace it.

Complaint "chauffeur repeated my conversation": internal review, statement, log. Without proof the driver can still be withdrawn for that client — reputation is fragile.

Due diligence checklist for procurement and compliance

Before engagement:

  • VERBİS number and privacy notice in booking flow?
  • D2 transport authorisation and commercial plate per vehicle current?
  • Role-based dispatch and admin logs — who sees what?
  • Do chauffeurs have processing agreements? Written ban on private route copies?
  • Standard retention route/GPS — reducible on client request?
  • SLA for KVKK Article 7 erasure requests in days?
  • Data breach reporting process — last exercise when?
  • In-cabin camera? Dashcam with cabin audio?
  • Sub-chauffeur list in VERBİS as processor?
  • NDA and privacy annex in standard MSA?

The list connects to corporate travel trends 2026 — duty of care and TMC integration apply to ground transport like flight and hotel.

Spot checks on site: a travel manager who once a year visits dispatch unannounced or demands remote screen share sees more than ten PDF certificates. Ask for last tabletop date and an anonymised access log sample. Serious providers have nothing to hide; hesitant providers save you the incident later.

Contract clause "no transfer to marketing" sounds trivial — but matters when routes could be misused for "regular customer offers." Explicitly forbid: use of guest data for advertising, benchmarking with competitors, or training external AI models on your addresses.

The EBA model from a compliance perspective

As Can Öztürk I quarterly audit D2 documents, policies, and the KVKK inventory across our fleet. New clients receive an onboarding pack within one business day: VERBİS extract, model MSA, retention table, chauffeur confidentiality, breach flow diagram.

Encrypted dispatch, 30-day GPS rotation, 90-day route (extension via M&A rider), six months anonymised calls — these are our defaults, adjustable in contract.

Executive privacy does not come with leather seats but with procedure, training, and auditable systems. Thousands of transfers in Istanbul traffic showed: the most expensive vehicle becomes the cheapest mistake when a route leak reaches the market or the press.

For confidential enquiries use the booking form or overview at VIP chauffeur services.

Frequently asked questions from daily operations

May my chauffeur share the route with third parties? Only with consent or legal obligation. Serious providers bind drivers contractually and limit access on need-to-know.

Does KVKK apply to VIP transfer companies? Yes. Name, phone, and route history are personal data. VERBİS and erasure requests are mandatory.

Do executives need an NDA? On M&A, embassy travel, or high media attention before address release — standard in practice.

Is an in-cabin camera acceptable? Not for confidential conversations. Exterior dashcam without cabin audio — disclose in contract.

How long to store routes? Many travel policies require deletion after 90 days. EBA default: twelve months contact data encrypted, 90 days full route — see table above.

About the author

Can Öztürk is Transport Compliance Officer at EBA VIP Services. After six years in the transport department of the Istanbul Chamber of Commerce he joined EBA. He quarterly audits D2 documents, insurance coverage, and KVKK processes per vehicle. Certifications: KVKK data protection training, ITO transport law.

Further reading: VIP security Istanbul Airport, Corporate travel 2026, SAW vs IST, D2 chauffeur licence Turkey.

Review date: May 2026. Law and Kurul practice may change — update before audits.

About the Author

Deniz Arslan

Istanbul Routes Specialist, EBA VIP Services

Deniz maps practical road corridors between airports, the historic peninsula, and Asian-side hotels — with traffic-aware timing notes for VIP transfers.

  • Route planning
  • Traffic windows
  • Cross-continental Istanbul

Frequently Asked Questions

Only with explicit consent or legal obligation. Premium operators bind chauffeurs to confidentiality clauses and limit data access to dispatch staff on need-to-know basis.

Related Articles