What is the duty to inform?
Article 10 of Law No. 6698, known as KVKK (Türkiye's Personal Data Protection Law), requires people to be informed when their personal data is collected. A privacy notice essentially covers:
- The identity of the data controller (your company)
- The purposes for which the data will be processed
- To whom and for what purpose it may be transferred
- The collection method and the legal basis
- The person's rights under the law
No approval is needed for a privacy notice; it is enough that people can reach the text easily. In other words, there is no need for a mandatory "I have read and accept the privacy notice" checkbox — in fact, it invites misunderstanding.
When is explicit consent needed?
The law lists several legal bases on which personal data may be processed, such as entering into or performing a contract, a legal obligation, or legitimate interest. If one of these applies, no separate consent is required. For example, the delivery address on an order form is processed to perform the contract.
Explicit consent comes into play when none of the other bases applies. Typical examples are newsletters and promotional messages, analysis for profiling purposes and, in some cases, transfers to services abroad. Explicit consent must relate to a specific subject, be based on proper information and be given freely.
Designing forms correctly
| Situation | Wrong | Right |
|---|---|---|
| Contact form | Making submission conditional on a consent box | Link to the privacy notice, no checkbox |
| Newsletter | Pre-ticked box | Separate, optional, unticked box |
| Membership | Privacy notice + marketing consent in one box | Privacy notice link + separate marketing consent |
| Withdrawing consent | Request by email only | One click in account settings |
If you plan to send commercial electronic messages (SMS or email campaigns), the permission rules under Law No. 6563 and registration with the Message Management System (İYS) also come into play. We factor this into the form design as well.
How are consent records kept?
The burden of proving that consent was obtained lies with the data controller. That is why we record the following for every consent:
- The date and time consent was given
- The version of the form and text used
- Information identifying the person (email, member number)
- IP address and source page
- The withdrawal date, if consent was withdrawn
When the text is updated, the old version is kept too, so you can always show who agreed to which text.
Checklist
- Is there a link to the privacy notice next to every form?
- Is submitting the form unnecessarily tied to consent?
- Is marketing permission collected through a separate, unticked box?
- Are consent records stored together with the text version?
- Can people withdraw their consent easily?
We work with your lawyer on the legal content of the texts; we map the data flows on your site and make sure the text matches the system exactly. This work is part of our KVKK compliance service and is included at no extra charge in our corporate website and e-commerce projects.
Frequently asked questions
Can we adapt another website's privacy notice?
The notice must describe your actual data flows. Copied texts often mention services you don't use or leave out the ones you do.
Can we refuse service to someone who does not give explicit consent?
Tying a service to consent for processing that isn't truly necessary to provide that service conflicts with the principle that consent must be freely given. We recommend assessing this with your lawyer.
Which languages should the texts be in?
In a language the people your site addresses can understand. On multilingual sites, a separate text is prepared for each language.
For questions, call +90 850 432 55 13 or use the contact page.