Follow us :
General

Türkiye's New Loyalty Card Rule: A Retail Compliance Guide

Padlock and keyboard representing data privacy — Xen Bilişim General

A cashier types a customer’s phone number into the loyalty system to apply reward points. Nothing confirms that number actually belongs to the person standing at the register. Türkiye’s Personal Data Protection Board (KVKK) has now decided that gap needs closing. In a decision adopted on 22 July 2026 and published in the Official Gazette on 13 August 2026, real-time identity verification became mandatory for loyalty card and phone-number transactions at checkout. The original deadline was 28 August 2026; the Board granted a six-month extension, pushing full compliance to 28 February 2027. A later deadline is not the same as a shelved rule — it just means retailers have more runway to get it right.

What problem the Board was reacting to

The reasoning behind the original February 2026 policy decision was concrete: when a cashier enters a customer’s phone or card number, nothing verifies that the transaction happens with the real number holder’s knowledge and consent. Anyone who happens to know someone else’s loyalty number can rack up points on their account, redeem accumulated discounts, and in some chains even view purchase history. The Board explicitly rejected the idea that a contract clause shifting “responsibility” onto the customer counts as a technical safeguard. The rule covers loyalty programs in grocery, cosmetics, electronics, home-improvement, and clothing chains — it targets the physical checkout scenario, not e-commerce accounts.

This isn’t actually a new problem. Cashiers at almost every chain running a loyalty program have asked “can I get your number?” for years, then entered whatever answer they got without checking it against anything. What changed isn’t the risk — it’s that the Board finally named it.

What “verification” actually means in practice

The rule is outcome-based rather than prescriptive about the exact mechanism. Whichever method you choose, you need to be able to show that the real number or card holder was aware of, and approved, that specific transaction.

MethodHow it worksImplementation effort
SMS one-time codeAn instant code is sent to the number entered; the cashier asks for itMedium — needs an SMS API integration
Mobile app confirmationThe customer approves the transaction from their own phoneHigh — requires an existing app
QR / physical card scanNumber entry is skipped entirely; a physical card or QR code is scannedLow — usually a POS add-on
Enrollment PINA 4-digit code the customer sets at sign-upLow — software-only, no hardware

For a small chain, QR/card scanning or a PIN is usually the fastest starting point — it can go live within a few weeks even without SMS infrastructure already in place. Forcing an app-confirmation flow on a retailer with no mobile app makes little sense; that’s a separate investment decision entirely.

Cost shouldn’t be the only factor. Checkout speed matters too — waiting on an SMS code during a busy hour lengthens the queue, while a card or QR scan is nearly instant. Across a multi-store chain, that few-second difference adds up to a real customer-experience question by the end of the day.

Rolling it into your POS setup

  • Ask your loyalty platform provider whether a verification API already exists — many local POS and CRM vendors have announced or are about to announce an update for exactly this.
  • If you go with SMS OTP, a 60-second code field on the register screen is usually enough; no separate hardware needed.
  • Retrain cashiers to drop the habit of skipping the step to keep the line moving — a verification step that can be bypassed is, in practice, not implemented, and that shows up in an audit.
  • Update your privacy notice: the new verification step is itself a data-processing activity and needs to be disclosed to customers.
  • Keep logs of which transactions were verified and by which method — that’s the first evidence an auditor will ask for.

Timeline and penalty exposure

28 February 2027 sounds distant, but leaving it to the last few weeks is a common mistake. Coordinating a POS vendor update, cashier retraining, and a privacy-notice revision typically takes two to three months together, and rolling it out store-by-store in a multi-location chain stretches that further. Article 18 of Law No. 6698 ties a missing technical safeguard to an administrative fine, with the amount adjusted annually. Enforcement usually starts with a complaint — one customer reporting “my account was used without permission” can trigger a review across every branch of that chain.

Frequently asked questions

Does this apply if we only track loyalty points by phone number, without a physical card? Yes. The rule isn’t about whether you issue a physical card — it’s about matching a phone or card number to a customer’s identity.

Does our e-commerce membership system fall under this too? The decision primarily targets the physical checkout scenario. Online purchases already go through account login (password, often two-factor), which provides that verification. The gap the Board is addressing is specifically the phone-number entry at a physical register.

We’re a single-location small business — where do we start? Talk to your POS provider first; many local vendors have already added this to their roadmap. If yours hasn’t, a PIN-based approach is typically the quickest software-only option to deploy.

Do we need to review existing loyalty data, or just future transactions? The rule is forward-looking — it doesn’t require deleting historical records. But while you’re setting up verification, it’s worth checking that the phone numbers on file are still accurate; an outdated or mistyped number will keep failing under the new system.

If you’d like help assessing which verification method fits your POS setup with the least disruption and cost, get in touch — we can walk through the options together.

Share this post
Türkçe oku

Related Posts