What are cookies, and which ones need permission?
A cookie is a small data file a website stores in your browser. Cookies are used to remember your cart, keep you logged in, count visits or show you ads. The Personal Data Protection Authority's guidance on cookie practices, issued under KVKK (Türkiye's Personal Data Protection Law), groups cookies by purpose and requires the user's explicit consent for everything other than strictly necessary cookies.
| Type | Example | Permission |
|---|---|---|
| Strictly necessary | Session, cart, security, the cookie preference itself | Not required, information is enough |
| Preference / functional | Language selection, live chat tool | Required |
| Analytics | Google Analytics, heatmap tools | Required |
| Marketing | Meta pixel, Google Ads, retargeting | Required |
Mistakes we often see
- The banner only has an "OK" button, with no option to reject
- "Reject" is hidden in a submenu while "Accept" is large and colorful
- Analytics and ad code loads before the banner even appears
- The code keeps running even after the user rejects it
- There is no way to change the choice later
- The cookie policy doesn't match the tools actually used on the site
The third one is the most serious. If tracking starts before the user is even asked, the banner is just decoration.
What does a correct setup look like?
- Scan: We list every cookie and third-party script your site loads.
- Classify: We sort each one into strictly necessary, functional, analytics or marketing.
- Block: We wire the scripts that need permission so they don't run at all until consent is given. For Google tools, we configure Consent Mode.
- Panel: We offer accept, reject and customize settings with equal visibility.
- Record: We store the date and version of each choice.
- Policy: We write the cookie policy based on the tools you actually use.
Do we lose measurement when users reject cookies?
Partly, yes. Visitors who reject cookies won't fully show up in analytics reports. That is a natural consequence of compliance. The gap can be narrowed to some extent with basic server-side measurement and tools such as Google's Consent Mode, but the goal should never be to track people who haven't given permission anyway. We work with our digital advertising team to plan campaign measurement around this reality.
Checklist
- Does any code that needs permission run before consent? (Test with the browser's developer tools)
- Is the Reject button as easy to use as Accept?
- Can the choice be changed later?
- Does the cookie policy include an up-to-date list of tools?
- Is the panel updated when a new tool is added?
The last point is often forgotten: when the marketing team adds a new tag to the site, the cookie panel needs updating too. On sites under our maintenance, we check this regularly.
Frequently asked questions
Is an off-the-shelf cookie plugin enough?
It works when configured correctly. But installing a plugin doesn't mean the scripts are actually blocked; you need to test that the blocking really works.
We only use Google Analytics — do we still need permission?
Yes. Analytics cookies are not considered strictly necessary.
How long should a cookie preference be stored?
The choice can be asked again after a reasonable period; that period should be stated in your cookie policy.
This work is part of our KVKK compliance service. For our general approach, see the our approach to KVKK page, and for questions, write to us through the contact page.