Follow us :
KVKK & Compliance

Privacy Notice or Consent? Türkiye's Most Confused KVKK Rule

The word 'privacy' highlighted in yellow marker on a dictionary page — Xen Bilişim KVKK & Compliance

Publishing a privacy notice and collecting explicit consent are not the same obligation. A privacy notice is something every data controller must provide, full stop. Explicit consent is a narrower mechanism that only kicks in when none of the law’s other legal bases apply. In our compliance work with Turkish SMEs, most companies treat these as interchangeable — either bolting a consent checkbox onto every form they own, or skipping disclosure altogether and leaning on an “I accept” button to cover everything. Both mistakes get penalized differently under an audit.

Article 10: disclosure is always required

Türkiye’s data protection law, KVKK (Law No. 6698), requires five things to be communicated to the data subject whenever personal data is processed:

  • The identity of the data controller (and its representative, if any)
  • The purpose of processing
  • Who the data may be transferred to, and why
  • The method of collection and its legal basis
  • The data subject’s rights under Article 11 (access, correction, deletion, and more)

This notice has nothing to do with consent. It applies whether you’re processing an employee’s payroll record or logging a website visitor’s IP address — because disclosure is a transparency duty, not a permission request. Türkiye’s Data Protection Authority (KVKK Kurumu) expects the wording to be clear, plain, and specific; vague phrases like “may also be used for other purposes in the future” don’t satisfy the requirement. If the purpose isn’t concrete, the notice doesn’t count as valid.

Article 5: consent only when nothing else applies

Article 5 works in the opposite direction. As a default rule, personal data cannot be processed without explicit consent — but the same article lists six exceptions where consent isn’t required at all. If any one of them applies, a signed consent form is unnecessary; disclosure alone is enough.

SituationConsent required?Example
Explicitly provided for by lawNoSocial security filings, tax records
Directly related to forming or performing a contractNoPaying an employee’s salary
A legal obligation of the controllerNoOccupational health records
The data subject has made the data public themselvesNoInformation a person shared openly
Necessary to establish, exercise, or defend a legal claimNoData needed for debt collection
Legitimate interest, without harming fundamental rightsNo (a balancing test is required)In-house security cameras
None of the above applyYesNewsletter sign-up, marketing SMS

The “legitimate interest” row is the one people misread most. The authority doesn’t accept a one-sided justification here — the controller’s interest has to be weighed against the data subject’s fundamental rights, and the controller has to show the purpose couldn’t be reached with a less intrusive method. Security cameras are a good test case: covering entry and exit points is defensible, but pointing a camera at every desk all day for the same stated reason usually isn’t.

Consent itself has to meet three conditions at once: it must be freely given, specific to a defined purpose, and based on prior information. A blanket “I accept the terms of service” doesn’t count as valid consent on its own — it doesn’t say which data is processed, or why.

The three mistakes we see most often

The same patterns keep showing up during audits and compliance reviews:

  1. Adding a consent checkbox to every form. Requesting consent for something mandatory — issuing an invoice, for instance — is pointless and misleading. It implies the customer can opt out, when in practice the invoice gets issued either way.
  2. Burying the privacy notice in a single link at the bottom of the website. Being reachable isn’t enough; the data subject is expected to see it before handing over data — before submitting a form, before registering an account.
  3. Making consent a condition for an unrelated service. Requiring marketing opt-in before a customer can complete a purchase undermines the “freely given” element of consent; Turkish enforcement decisions have repeatedly struck down this kind of bundled consent.
  4. Giving no way to withdraw consent. Consent has to be revocable at any time, without justification. If a newsletter has no unsubscribe link, or a withdrawal request sits unprocessed for weeks, the original consent becomes questionable too.

Frequently asked questions

Is collecting consent enough if we skip the privacy notice? No. Even where consent is obtained, disclosure is a separate, independent obligation — one doesn’t substitute for the other.

We already have signed consent forms from existing customers — do we need to redo them? If the form doesn’t meet all three consent conditions (freely given, specific, informed) — especially if it reads as blanket acceptance — it’s worth renewing.

Where should a small business place its privacy notice? At every point where data is collected: application forms, website contact forms, camera entrances, job interviews. A single central page isn’t enough; the notice needs to be visible at each collection point.

Isn’t one general privacy page on our website sufficient? Being reachable is necessary but not sufficient — the data subject is expected to see the notice before providing data. That’s why it belongs as close as possible to the point of collection, ideally right above or below the form itself.

Getting the line between disclosure and consent right removes unnecessary consent fatigue and makes the real compliance gaps easier to spot. If you’d like a second opinion on your KVKK setup, get in touch.

Share this post
Türkçe oku

Related Posts