KVKK compliant website: privacy notice, explicit consent and cookies in Turkey
A KVKK compliant website informs visitors before it collects personal data, asks for separate and freely given consent where consent is needed, does not load non-essential cookies before the visitor agrees, and stores what it collects securely. KVKK is Turkey's data protection law. It looks like GDPR in many places but differs in registration, consent practice and transfer rules, so ask your legal counsel about your case.
What is a KVKK compliant website?
A KVKK compliant website collects, stores and uses personal data in line with Turkey's Personal Data Protection Law No. 6698, known by its Turkish initials KVKK. In practice that means four things: visitors are informed before data is collected, separate consent is asked where it is needed, non-essential cookies stay off until the visitor agrees, and collected data is kept secure.
This guide is for foreign companies with a Turkish website, a Turkish subsidiary or Turkish customers. We build websites in İzmir and set up the technical side of KVKK on every project. We do not write the legal texts. The law and the guidance of the Personal Data Protection Authority change over time, so check kvkk.gov.tr and ask your legal counsel in Turkey about your specific case.
How is KVKK different from GDPR?
KVKK was modelled on the older EU data protection directive, so the basic ideas will feel familiar to anyone who knows GDPR. The differences are in the details, and the details are where websites go wrong.
| Topic | GDPR | KVKK |
|---|---|---|
| Legal bases | Consent, contract, legal obligation, legitimate interest and others | A similar list, but explicit consent has traditionally been relied on more often in practice |
| Notice and consent | Often combined in one privacy flow | The privacy notice and explicit consent are expected to be separate steps |
| Registration | Records of processing, no public registry | Registration in VERBIS, the data controllers registry, unless an exemption applies |
| Cookies | GDPR plus the ePrivacy rules | No separate cookie law. The Authority has published a cookie guide |
| Transfers abroad | Adequacy, standard contractual clauses and other safeguards | Article 9, amended in 2024: adequacy decisions, safeguards such as standard contracts, and occasional transfers |
| Response to requests | Usually one month | Within thirty days |
The practical lesson: a GDPR cookie banner and privacy policy copied onto a Turkish site are a starting point, not an answer. The notice has to be in Turkish, name the Turkish data controller and describe what the Turkish site actually does.
Which personal data does a website collect?
Even a simple company website collects more personal data than most owners expect. Contact and quote forms collect names, emails and phone numbers. Server logs keep IP addresses. Cookies store session, language, analytics and advertising identifiers. Online stores add addresses and order history. Job application forms collect CVs, which may contain special category data such as health information, where the rules are stricter. Live chat, maps, videos and social media plugins usually set cookies of their own.
Start by writing this down for your own site: which data, on which page, for what purpose, where it is stored and who receives it. This data inventory is what your counsel writes the notices from.
How should the privacy notice appear on forms?
The privacy notice should appear as a short sentence under each form with a link to the full text, not as a tick box. Article 10 of KVKK requires the controller to tell people who it is, why it processes the data, who it may be shared with, how and on which legal basis it is collected, and what rights they have. Informing is a one-way duty. A box saying "I have read and accept the notice" adds nothing and blurs the line with consent.
When is explicit consent needed, and why a separate box?
Explicit consent is needed when none of the other legal bases in the law applies. Answering a quote request usually rests on another basis. Sending marketing messages to the same person usually does not. KVKK defines explicit consent as specific, informed and freely given, which on a form means:
- One box per purpose. Marketing emails and transfer abroad are never bundled.
- Boxes are unticked by default.
- The form can be sent without ticking them. Consent is never a condition of the service.
- The consent text is separate from the privacy notice.
- Consent can be withdrawn as easily as it was given.
We also store proof: who agreed, when, and to which version of the text. Marketing email and SMS in Turkey are also subject to the commercial electronic message rules and the national message management system, İYS. Ask your counsel how the two fit together for you.
What should a cookie banner look like under KVKK?
A cookie banner under KVKK should offer a real choice and keep non-essential cookies switched off until the visitor agrees. The Authority's cookie guide broadly expects consent for everything except cookies that are strictly necessary for the site to work. Accept and reject should be equally easy, categories should be adjustable, and a "Cookie settings" link in the footer should let visitors change their mind.
The most common failure we see is technical, not legal. The banner is on screen, but analytics and ad tags fire the moment the page loads. A correct setup does not add those scripts to the page at all until consent is recorded.
Does a website need VERBİS registration?
VERBİS registration concerns the company, not the website. VERBİS is the data controllers registry. Some controllers are exempt based on criteria such as employee count and balance sheet size, and the thresholds are updated from time to time. Check the current decisions and ask your counsel. An exemption from registration does not remove the duties to inform, obtain consent where needed and keep data secure.
Are analytics and SaaS tools a transfer abroad?
Usually yes, if the tool receives personal data and its servers are outside Turkey. Analytics, newsletter services, live chat, cloud CRMs and hosted form tools are the usual examples. Article 9 was amended in 2024 and now works with adequacy decisions, appropriate safeguards such as standard contracts that must be notified to the Authority, and occasional transfers. Which route applies to which tool is a legal decision.
The technical side is simpler. List every third-party script on the site, remove the ones nobody uses, turn on IP truncation and short retention in analytics, and store form submissions on your own server instead of a third-party form service.
KVKK checklist before launch
- 01 Map the data List which data each page collects, why, where it is stored and who receives it.
- 02 Get the texts written Have your Turkish counsel prepare the privacy notice, cookie policy and any consent texts from that list.
- 03 Check the forms A short notice under every form, separate unticked consent boxes, and the form works without them.
- 04 Test the banner Click reject, then confirm in the browser developer tools that no analytics or ad scripts load.
- 05 Review third-party tools Remove unused scripts and clarify the transfer route for the rest with your counsel.
- 06 Check security HTTPS everywhere, personal admin accounts with two-factor login, private file storage, backups and updates.
- 07 Prepare for requests Publish how people can apply, and make sure you can find and delete one person's data.
What should you ask your web team for?
Ask your web team to make the site behave exactly as your legal texts say. If the notice says analytics runs only with consent, it must. On our projects we map the data with you, build forms with separate consent boxes, log consent, set up a banner that blocks scripts until consent, keep form data on your own server and delete records when the retention period ends. SSL and personal admin accounts are standard. The domain, hosting and code are in your name from day one, so control stays with you as the data controller.
Put these items into the scope from the start. Our guide on how to get a website built explains the process, and pages every company website needs lists the legal pages. See our web design and e-commerce services for scope, and the KVKK glossary entry for a short definition.
Frequently asked questions
We already comply with GDPR. Are we covered for KVKK?
Partly. The principles overlap, but KVKK expects Turkish notices, separate consent, possible VERBİS registration and its own transfer rules. Have local counsel review the gap.
Does KVKK apply to a site with only a contact form?
Yes. A form that collects a name, email or phone number processes personal data. The duty to inform does not depend on the size of the site.
Do we need an "I have read the notice" checkbox?
Usually not. The notice is information, not consent. A short sentence and a link under the form is the common approach. Ask your counsel about your specific form.
Can the cookie banner have only an Accept button?
The Authority's cookie guide broadly expects a real choice, with rejecting as easy as accepting. A single-button banner does not fit that approach.
Can we keep using our global analytics tool?
Usually yes, with consent before it loads and a clear transfer route for data leaving Turkey. Your counsel decides the legal basis. We handle the technical setup.
Do we need a data protection officer?
KVKK does not use the GDPR officer model in the same way. Registered controllers name a contact person in VERBİS. Ask your counsel what applies to your company.
Can you fix an existing site?
Yes. We review forms, cookies and third-party scripts, then send a one-page list of what needs to change. Your counsel prepares the texts and we make the technical changes.
Sources
- 01 Personal Data Protection Authority · Kişisel Verileri Koruma Kurumu
- 02 Law No. 6698 on the Protection of Personal Data (Turkish) · Mevzuat Bilgi Sistemi
- 03 Regulation (EU) 2016/679 (GDPR) · EUR-Lex