dqagent
← Blog

How to Validate a Turkish ID Number (TCKN) in Your Database

· 5 min read

A Turkish Republic ID number (TCKN, T.C. Kimlik Numarası) is an 11-digit identifier. Banks, insurers and fintechs store it in customer tables, and a malformed value usually means a data entry error, a broken migration or a test record that leaked into production. Because the last two digits are check digits, you can catch many of these errors with a simple calculation, without calling any external service.

The rules

  • The value has exactly 11 digits and contains nothing else.
  • The first digit is never 0.
  • The 10th digit equals ((sum of digits 1, 3, 5, 7, 9) × 7 − (sum of digits 2, 4, 6, 8)) mod 10.
  • The 11th digit equals the sum of the first 10 digits, mod 10.

Note that the first rule produces a negative number for some inputs. In SQL Server, JavaScript, Java and C#, the % operator can return a negative result in that case, so normalize the value before comparing it to the digit. Python's % operator already returns a non-negative result for a positive divisor.

A tested implementation

def is_valid_tckn(value: str) -> bool:
    if len(value) != 11 or not value.isdigit() or value[0] == "0":
        return False
    d = [int(c) for c in value]
    odd = sum(d[0:9:2])    # 1st, 3rd, 5th, 7th, 9th digits
    even = sum(d[1:8:2])   # 2nd, 4th, 6th, 8th digits
    return d[9] == (odd * 7 - even) % 10 and d[10] == sum(d[:10]) % 10

is_valid_tckn("10000000146")  # True  (widely used test number)
is_valid_tckn("10000000147")  # False (last digit changed)

What a valid checksum does not prove

Passing the algorithm only shows that the number is well-formed. Roughly one in a hundred random 11-digit strings that start with a non-zero digit passes it, and a well-formed number can still belong to nobody, to someone else, or to a person who has died. Confirming that a TCKN matches a real person's name and date of birth requires the official identity verification service, which is outside the scope of a database quality check.

Using it for data quality and KVKK work

In a profiling run, count how many values in each TCKN column fail the format check and track that count over time. A sudden jump usually points to a new source system or a changed import job. Also look for the same value repeated across many customers, which often indicates a placeholder such as 11111111110. Under KVKK, the TCKN is personal data, so run these checks where the data already lives and avoid exporting it to external tools.

DQ-Agent treats a TCKN format violation (11 digits plus the check algorithm) as a critical validity anomaly and runs it as part of its on-premise anomaly detection phase, so the data never leaves your server.

30-minute live demo against your own schema

Not a slideshow — a live install. We profile your SQL Server connection in minutes.