Single Blog Title

This is a single blog caption

STARTING A FINTECH COMPANY

Establishing a Fintech Company in Türkiye: A Lawyer's Guide to Licensing, Capital, and Compliance

Last Updated: January 26, 2026
Author: Attorney Ferhat Küle (Istanbul Bar Association)

Legal Disclaimer: This article is for general informational purposes only. The question of "is licensing required?" in fintech models fund flow, product flow, and contractual role assignments together.


Contents

  1. What is fintech? Why isn't there a "single license" under the law?

  2. Do you need a license for fintech? (Quick quiz + table)

  3. Who regulates fintech in Türkiye? (Central Bank of the Republic of Turkey - Banking Regulation and Supervision Agency - Capital Markets Board - Financial Crimes Investigation Board - Personal Data Protection Authority)

  4. Central Bank of Turkey licenses: Payment institution and Electronic money institution

  5. Minimum equity requirement (2025 Circular – current figures)

  6. MASAK compliance program: KYC + monitoring + SIB

  7. GDPR compliance package: data inventory, disclosure, transfer

  8. Contract set: user-member business-outsourcing

  9. Step-by-step establishment roadmap (checklist)

  10. Frequently Asked Questions (FAQ) + Schema


<a id=”fintech-nedir”></a>

1) What is Fintech? Why isn't there a "single license" under the law?

Fintech (financial technology) is the delivery of financial services through technology; however, the critical legal distinction is this:

  • Are you solely a technology provider? (e.g., technical integration for banks/PSPs, infrastructure software, display/UX services)

  • Or are you involved in financial activities? (e.g., receiving and transferring money from users, creating wallet balances, operating payment accounts, etc.)

In Turkey, the basic framework for the payment/e-money sector in the Central Bank of the Republic of Turkey's "Legislation Regarding Payment Systems" page .

Practical takeaway: “Establishing a fintech company” doesn’t end with registration; it requires establishing the right regulatory framework (Central Bank of Turkey/Banking Regulation and Supervision Agency/Capital Markets Board) licenses, compliance, and contracts .


<a id=”lisans-gerekir-mi”></a>

2) Is a Fintech license required? (Quick quiz + table)

If you answer "yes" to even one of the following questions , proceeding without considering the licensing/compliance risks would be a costly mistake:

  • Are you taking money from the user and then holding onto the account for a while?

  • Do you act as an intermediary in transferring money between a seller and a buyer ?

  • Do you maintain records such as wallet balances (e-money) or payment accounts on behalf of users ?

  • Do you offer open banking services such as "Initiate Payment / Account Information"?

The Central Bank of Turkey's (TCMB) guide on "business models offered in the payments sector" is one of the most valuable references before applying, for correctly establishing this distinction.

2.1. Table for the snippet: "Is a license required?" quick matrix

Business model example Fund flow/money control Licensing risk Typical line
Software only (redirection to PSP) Not with you Low-Medium The word "mediation" in the contract
Virtual POS / collection routing Partially Medium-High Money "passing through you"
Money transfer / payment intermediary You/active role High The misconception that "we are a technology company"
Wallet / balance / redemption You Very high Bypassing e-money obligations

Attorney's note: In practice, licensing risk often arises not from the "product screen," but from the technical design of role assignments and cash flow in contracts


3) Who regulates fintech in Türkiye? (Central Bank of the Republic of Turkey - Banking Regulation and Supervision Agency - Capital Markets Board - Financial Crimes Investigation Board - Personal Data Protection Authority)

3.1. Central Bank of Turkey (TCMB): Payment services and electronic money (axis 6493)

The fundamental framework in the payment/e-money sector is Law No. 6493 and the secondary regulations published by the Central Bank of the Republic of Turkey (TCMB). The TCMB's list of relevant legislation and page 6493 can be found here.

3.2. BDDK: Digital banking and service model banking (BaaS)

If your model approaches the "banking activity" line or has a service model banking structure, the BDDK (Banking Regulation and Supervision Agency) regulations come into play. The BDDK's list of regulations includes the "Operating Principles of Digital Banks and Service Model Banking..." regulation.

3.3. Capital Markets Board (SPK): Crowdfunding platforms

Investment/debt-based “crowdfunding” platforms fall under the regulation of the Capital Markets Board (SPK); the Crowdfunding Regulation (III-35/A.2) has been published as an official PDF.

3.4. MASAK: AML/CFT Obligations

In fintech, due to the triad of identity, transaction, and money, MASAK (Financial Crimes Investigation Board) obligations (KYC, SIB, etc.) should be central to the design. MASAK compiles its obligation headings on its own website.

3.5. GDPR: Compliance between personal data and financial data

Since data processing (identity, communication, transactions, location, etc.) is intensive in fintech, GDPR compliance both reduces risk and plays a critical role in the "due diligence" phase of investment/corporate customer processes. The publications and implementation documents of the GDPR serve as references for this framework.


4) CBRT licenses: Payment institution and Electronic money institution

4.1. Payment institution license (general framework)

A payment institution is defined as an entity authorized by the Central Bank of the Republic of Turkey (TCMB) to provide payment services. The TCMB publishes payment systems legislation and related regulations in its official list.

The main legal headings that typically come to the forefront from the payment institution's perspective are:

  • Business model classification (which payment service?)

  • User agreement and fee transparency

  • Membership agreement (if any)

  • Outsourcing of services (cloud, KYC provider, processor, etc.) and auditing rights

  • Information systems, logging, event management, continuity

4.2. Electronic money institution license (general framework)

Since electronic money carries heavier risk and compliance dimensions such as wallet balance, redemption (conversion to cash), and withdrawals/transfers, the e-money line comes into play when your business model starts generating "balances".

Application tip: The statement "We have the wallet, but we don't have the money" contradicts technical-contractual reality in most models. Be sure to clarify this area using a fund flow diagram and a contractual role matrix.


5) Minimum equity requirement (2025 Circular – current figures)

One of the biggest mistakes fintech founders make is confusing the concepts of "capital" and "minimum equity." In the payment/e-money sector, the minimum equity requirement is determined by the current regulation.

the Communiqué published in the Official Gazette dated January 30, 2025, the minimum equity amounts have been updated as follows (in summary):

  • Exclusively facilitating bill payments: 15,000,000 TL

  • Other payment institutions (with specific exceptions) : 30,000,000 TL

  • Electronic money institutions: 80,000,000 TL.
    the regulation will enter into force on June 30, 2025 .

SEO tip (to increase time spent on the page): Add the subheadings “How to calculate equity?” and “Planning investment rounds” to this section (with 1-2 example scenarios).


6) MASAK compliance program: KYC + monitoring + Suspicious Transaction Reporting (STR) in Fintech

MASAK's "Obligations" page clearly lists the main areas of compliance.
In fintech, MASAK compliance is often more product design.

6.1. Four Pillars of MASAK Compliance for Fintech

  1. KYC / Identity verification: onboarding flow, risk classification

  2. Transaction monitoring: scenarios/rules, alarm management

  3. SIB: decision-reporting-recording process (including non-disclosure)

  4. Training + internal control + audit trail: continuity

Implementation note: When a compliance program is added "after the fact," it disrupts product flows and reduces conversion rates; if designed from the outset, both compliance and growth objectives are preserved.


7) GDPR compliance package: data inventory, disclosure, transfer

The most critical issue in fintech under the Turkish Personal Data Protection Law (KVKK) is this: the purposes of data processing and the division of roles are not clear, the disclosure statement, retention periods, international transfers, and security measures will not be consistent.

The publications of the Personal Data Protection Authority (KVKK) regarding practical application (e.g., the document "KVKK and its Application") are guiding in this context.

7.1. The 5 most common mistakes in Fintech

  • Failure to distinguish between data controller and data processor

  • Mistaking the user agreement and the privacy policy for a "single text"

  • The uncertainty surrounding the transfer configuration in cloud, analytics, and CRM integration

  • Unlimited log keeping without a retention or disposal plan

  • Lack of a breach response plan


<a id=”sozlesmeler”></a>

8) Contract set: User – Merchant – Outsourcing

This is also a strong point from an SEO perspective: Users arrive searching for things like "fintech contract sample" or "merchant agreement." Therefore, keeping the contract set separate and long will rank the page higher.

8.1. “Minimum viable” contract package

  • User agreement / framework agreement

  • Fee and commission information

  • Privacy + GDPR texts (information, explicit consent if required)

  • Membership agreement (if any)

  • Outsourcing contracts (KYC provider, cloud, core infrastructure)

  • SLA + information security addendums (incident reporting, logs, audit rights, subcontractor requirements)

8.2. "Must-have" clauses in an outsourcing contract

  • Right to audit and report

  • Data location / transfer conditions

  • Incident reporting and response times

  • Business continuity and disaster recovery (BCP/DR)

  • Subcontractor terms of use

  • Logging and record keeping obligations


9) Step-by-step fintech startup roadmap (SEO checklist)

A) Pre-establishment (0–4 weeks)

  • Business model + fund flow diagram (license analysis)

  • Determining the line between the Central Bank of Turkey (TCMB), the Banking Regulation and Supervision Agency (BDDK), and the

  • Minimum equity plan and financial sustainability

  • MASAK + KVKK compliance architecture draft

B) Company formation and documentation (2–8 weeks)

  • Articles of association + share structure + investment-compatible frameworks

  • Draft contract sets (user/merchant/outsourcing)

  • KVKK: data inventory + storage-destruction + transfer matrix

C) Licensing file and operation (8–20+ weeks)

  • Application file + internal control/risk/compliance functions

  • Information systems security controls, logging, continuity

  • MASAK: Live setup of KYC-monitoring-SBT processes

D) Postgraduate

  • TÖDEB membership and union processes (payment/e-money line)

  • Periodic reporting, audits, complaint management


10) Frequently Asked Questions (FAQ)

  1. Does every fintech company need to obtain a license?
    No. "Pure technology" models that don't facilitate fund flow may be exempt from licensing; however, if they play an active role in money flow, the Central Bank of Turkey (TCMB) comes into play.

  2. What is the difference between a payment institution and an e-money institution?
    E-money involves heavier obligations such as balance/redemption; if the business model generates "wallet/balance," then the e-money line is debatable.

  3. What are the minimum equity capital requirements?
    The thresholds of 15M/30M/80M TL were determined by the Circular dated 30.01.2025; they came into effect on 30.06.2025.

  4. Is TÖDEB membership mandatory?
    Membership requirements for payment and electronic money institutions operating in Turkey are stated on their statutes and description pages.

  5. When should MASAK compliance be established?
    At the latest during the product onboarding design. MASAK liability headings are for guidance only.

  6. What is the most critical step in the KVKK (Turkish Personal Data Protection Law)?
    Data inventory + role matrix (responsible/operating party) + data transfer framework.

  7. When does the BaaS/service model banking come into play?
    When a "service model" relationship is established with a bank and the activity approaches the banking boundary, the relevant regulation is included in the BDDK (Banking Regulation and Supervision Agency) lists.

  8. I want to do crowdfunding, does that count as fintech?
    Could a crowdfunding platform fall under the scope of the Capital Markets Board (SPK) Regulation?

 

Internal link plan

  • /payment-institution-license/

  • /electronic-money-institution-license/

  • /minimum-equity-payment-e-money/

  • /masak-uyum-fintech-kyc-sib/

  • /kvkk-fintech-data-inventory-transfer/

  • /fintech-outsourcing-sozlesmesi-sla/

  • Digital Bank Service Model Banking/

  • /creating-a-crowdfunding-platform/

Leave a Reply

Call Now Button