Cookie consent is the explicit permission a website obtains from a visitor before placing non-essential cookies in their browser. It sounds simple, yet on a large share of the sites we see in the field, the situation is this: analytics and advertising code starts running as soon as the page opens, and at the bottom sits a bar that just says "Got it." That setup does not match the Guide on Cookie Practices published in 2022 by the Personal Data Protection Authority, the regulator behind KVKK (Türkiye's Personal Data Protection Law). In this article we explain step by step how to obtain cookie consent and what should and should not be in the banner.
First, sort cookies into three groups
A cookie is a small text file that a site leaves in the browser. It is used to keep you logged in, remember your cart, collect visit statistics or target ads. Not all cookies are treated the same when it comes to consent. In practice, three buckets are enough:
| Group | What it does | Is consent required? |
|---|---|---|
| Essential | Session, cart, security, language preference, the consent preference itself | Usually no, but visitors must be informed |
| Analytics / performance | Number of visits, which pages are read | Yes, under the Authority's guide |
| Marketing / targeting | Ad pixels, remarketing, social media plugins | Yes |
Interpreting "essential" too broadly is a common mistake. There is no such category as "essential for our ad campaign"; an essential cookie is one required for the service the visitor explicitly asked for to work.
What does a good cookie banner look like?
The spirit of the guide is this: visitors should be able to choose freely, knowingly and easily. Here is how that translates to the screen:
- Accept and reject on equal footing. Both belong on the first layer, at a similar size and with similar visibility. Requiring three clicks to reject and one to accept invalidates the consent.
- No pre-ticked boxes. Analytics and marketing toggles start switched off.
- No cookie wall. "If you don't accept cookies, you can't see the site" means making consent a condition of the service.
- Scrolling or browsing is not consent. Consent is given through a positive action, in other words by pressing a button.
- Preferences can be changed later. There should be a "Cookie preferences" link at the bottom of every page, and withdrawing consent should be as easy as giving it.
- Layered information. A short explanation on the first layer; category-level details and a link to the cookie policy on the second.
The real work is technical: tying code to consent
Putting up the banner is the visible part. The real work is making sure analytics and advertising code does not run at all until consent is given. The most common problem we see in the field is a banner that is pure decoration; even if the visitor clicks "Reject," the tags have already loaded.
What needs to be done:
- Build an inventory of all third-party code on the site (analytics, ad pixels, maps, video, chat tools).
- Assign each piece of code to a category and hold it back until a consent decision arrives.
- If you use Google tags, pass consent status to the tags with Consent Mode. We cover the measurement side in detail in our article on setting up conversion tracking.
- Show embedded content such as YouTube videos or maps as a placeholder box when there is no consent.
- Keep a record of consent: when it was given, for which categories, and with which banner version.
A cookie policy and a privacy notice are different things
Behind the banner there should be a cookie policy page: which cookies are used, by whom (first party or third party), how long they are kept and for what purpose. This page does not replace your general privacy notice; it complements it. We cover what a privacy notice must include separately in our article on the website privacy notice.
Most advertising and analytics tools move data to servers abroad. That brings the rules on cross-border data transfers into play as well; we cover that topic in our article on international data transfers.
Checklist
- All cookies and third-party code running on the site are listed
- Each one is classified as essential, analytics or marketing
- Analytics and marketing code does not load before consent
- "Accept" and "Reject" carry equal weight in the banner
- There are no pre-selected options
- A "Cookie preferences" link is accessible on every page
- The cookie policy is up to date and linked from the banner
- Consent records are kept
- Someone is responsible for updating the list when a new tool is added
The last item looks minor, but it is where things break most often. One day the marketing team adds a new pixel, nobody updates the banner, and the site quietly falls out of compliance.
How we do it at Globya
On every site we build, we take a cookie inventory at the start of the project, connect code to consent management by category, and separately test the "Reject" scenario in the browser. We prepare the cookie policy and privacy notice according to how the site is actually used, and submit them to your legal advisor for a final check. KVKK requirements are never left out of a project, and we do not charge extra for them. You can find our general approach on our KVKK compliance page.
Frequently asked questions
We only use Google Analytics. Do we still need a banner?
Yes. Because analytics cookies are not considered essential, the Authority's guide calls for explicit consent. The analytics code should not run until consent is given.
If most visitors reject cookies, are our statistics wasted?
You will lose some data; that is to be expected. Tools like Consent Mode can model visitors who do not consent using cookieless, aggregated signals. Still, the decision always belongs to the visitor.
Is installing a ready-made cookie plugin enough?
A plugin is a tool, not compliance itself. You need to test whether the code is really tied to consent and whether the categories are set correctly. We recommend confirming the final wording of the texts with your legal advisor.
How can we find out the cookie status of our current site?
As part of our free preliminary analysis, we report which code runs on your site before consent. You can reach us at +90 850 432 55 13 or via our contact page.
The Globya assistant is online 24/7; it answers right away and passes your question to the team if needed.