Globya Information Technologies · Since 2000 0850 432 55 13 info@globya.com.tr
SearchCtrl K Start a project

Data Protection and Security

Is the padlock in the address bar enough?

HTTPS is no longer optional; it's the bare minimum. But the padlock doesn't say the site is secure, only that the connection is encrypted. We explain the difference and the details of a correct setup.

An SSL certificate is a digital document that encrypts the traffic between your website and a visitor's browser and verifies that the site really belongs to your domain. HTTPS is the name for that encrypted connection. Although the protocol in use today is technically called TLS, the industry still says "SSL." For any site whose forms collect names, phone numbers or email addresses, HTTPS is the most basic part of the technical safeguards expected for data security under KVKK (Türkiye's Personal Data Protection Law). But it isn't the only part. In this article we explain what HTTPS solves, what it doesn't, and the checkpoints for a correct setup.

What does HTTPS protect?

On an unencrypted (HTTP) site, when a form is submitted the information travels over the network as plain text. Someone on the same café Wi-Fi, the internet provider or any device in between can read or alter it. HTTPS provides three things:

  • Confidentiality: No one in between can read the content.
  • Integrity: The page can't be altered in transit; for example, ads or malicious code can't be injected.
  • Authentication: The browser checks that the server it connects to really belongs to that domain.

Browsers flag form fields on HTTP sites with a "Not secure" warning. Google also announced in 2014 that it would use HTTPS as a light ranking signal in search. So a site without HTTPS loses both trust and visibility.

What doesn't HTTPS protect?

The padlock doesn't mean the site is secure. A fake site can also get a free certificate and show a padlock. HTTPS does not protect against:

  • Software vulnerabilities on the site (old plugins, an unpatched platform)
  • Weak administrator passwords
  • Form data being stored unencrypted on the server or in a publicly accessible folder
  • Fake (phishing) sites
  • Form data being forwarded by unencrypted email

So treat HTTPS as a starting line. We covered the other safeguards on the form side in our article on web form security, and the password side in password policy and 2FA.

The difference between certificate types

TypeWhat it verifiesWho it suits
DV (Domain Validated)That the domain belongs to youCorporate sites, blogs, most e-commerce
OV (Organization Validated)The domain + that the company existsThose who want company details to appear in the certificate
EV (Extended Validation)A more thorough organization checkThose with special requirements; browsers no longer show a separate visual indicator

There is no difference between the types in terms of encryption strength. For most corporate sites, an automatically renewed DV certificate is enough. Buying a paid certificate doesn't make a site more secure.

Certificate lifetimes are shrinking, so automation is a must

Certificate validity periods have shortened over the years. In 2025, the CA/Browser Forum, formed by browser makers and certificate authorities, decided to shorten them further in stages over the coming years. The practical consequence: a certificate renewed by hand will inevitably be forgotten one day. An expired certificate shows visitors a full-page security warning, and forms stop working. Renewal should be automatic, and the expiry date should be monitored separately.

Checklist for a correct setup

  • All pages open over HTTPS; HTTP addresses go to HTTPS with a permanent (301) redirect
  • Both the "www" and non-"www" versions are covered by the certificate
  • No mixed content on pages (images, scripts or fonts loaded over HTTP inside an HTTPS page)
  • Old protocols (SSL, TLS 1.0 and 1.1) are disabled; TLS 1.2 and 1.3 are enabled
  • The HSTS header is enabled; it tells the browser to come to this site only over HTTPS
  • Certificate renewal is automatic, and an expiry alert is in place
  • Subdomains (panel, portal, store) also run over HTTPS
  • Form data is protected on the server too; email notifications don't carry sensitive data in plain text

Mixed content is the item most often overlooked. A single HTTP image link on an old page can cause the browser to drop the padlock or block the content.

Where HTTPS fits under KVKK

KVKK requires data controllers to take appropriate technical and administrative measures to protect personal data against unlawful access. The data security guide published by the Personal Data Protection Authority also lists encryption and secure communication among the expected technical measures. A form that collects personal data without HTTPS is a clear sign, in a breach investigation, that measures were not taken. Conversely, HTTPS alone isn't enough to say "we took measures"; it is assessed together with server security, updates and access management.

How we do it at Globya

All sites under our hosting and maintenance service are published with automatically renewed certificates, HTTP-to-HTTPS redirects and current protocol settings. Before delivering a new site, we separately check for mixed content and review the subdomains. Certificate expiry dates are monitored; if renewal fails, the problem reaches us before it reaches your visitors. We don't charge extra for the technical requirements under KVKK.

Frequently asked questions

Is there a security difference between a free certificate and a paid one?

Not in terms of encryption. The difference lies in the level of validation and, in some cases, in extra services offered by the provider. For most corporate sites, an automatically renewed free DV certificate is enough.

Our site has no forms. Do we still need HTTPS?

Yes. Browsers mark HTTP sites as not secure, and HTTPS also prevents the page from being altered in transit. Even without forms, the integrity of the content your visitors see matters.

What happens if the certificate expires?

Visitors are met with a full-page security warning before they can enter the site, and most turn back. That's why automatic renewal and expiry monitoring matter.

Can you check our site's HTTPS setup?

Yes. Reach us at +90 850 432 55 13 or through the contact page, and we'll send you the checkpoints in a short report.

Anything on your mind about this article?

The Globya assistant is online 24/7; it answers right away and passes your question to the team if needed.

Ask the assistant

The next project could be yours

Let us run your digital work from a single point.

Let us hear your needs in a short phone call and prepare a free preliminary analysis report for your website.