Ecommerce Growth
KVKK compliance for online stores in Turkey

In short
KVKK compliance for an online store in Turkey rests on three pillars: a privacy notice that meets Article 10 of Law No. 6698 when data is collected, explicit consent only where needed and collected separately from the notice, and consent management for non-essential cookies. The authority's July 2025 cookie guide treats equally weighted accept and reject buttons as good practice.
Contents
- What does KVKK compliance require from an online store?
- Which legal basis applies to which data?
- What must a privacy notice include?
- How should explicit consent be collected?
- What should a cookie banner look like under KVKK?
- Does an online store need to register with VERBİS?
- What about transferring data to tools abroad?
- Step-by-step KVKK roadmap
- Key takeaways
What does KVKK compliance require from an online store?
Under Turkey's Law No. 6698 on the Protection of Personal Data (KVKK), an online store must give a privacy notice meeting Article 10 when it collects data, rely on a legal basis from Article 5 for each processing activity, ask for explicit consent only where needed and separately from the notice, manage consent for non-essential cookies and secure data under Article 12.
Note: This article explains Turkish data protection rules for brands selling to customers in Turkey. KVKK is similar to the GDPR in places but not identical. This is general information, not legal advice, based on texts on mevzuat.gov.tr and kvkk.gov.tr as of October 2026 (last updated: October 2026).
Ecommerce processes personal data at almost every step: accounts, orders, delivery addresses, payments, customer service, email lists and ad pixels. Each needs its own legal basis and its own disclosure.
Which legal basis applies to which data?
Article 5 of Law No. 6698 says personal data may in principle not be processed without explicit consent, then lists bases that do not require consent. The ones ecommerce relies on most:
| Processing activity (example) | Possible legal basis | Explicit consent needed? |
|---|---|---|
| Orders, delivery address, invoicing | Formation or performance of a contract (Art. 5/2-c) | No |
| Keeping invoices and records | Legal obligation (Art. 5/2-ç) | No |
| Fraud prevention, site security | Legitimate interest (Art. 5/2-f), provided fundamental rights are not harmed | Usually no |
| Advertising and targeting cookies, pixels | Explicit consent per the cookie guide | Yes |
| Special category data (for example health) | Limited conditions in Art. 6 | Mostly yes |
The table does not settle every case; you need a data inventory and a decision per activity. One warning: asking for consent "for everything" when another basis such as contract performance applies undermines the freely given element of consent and is not good practice.
What must a privacy notice include?
Under Article 10, when personal data is obtained the data subject must be told:
- The identity of the data controller and any representative,
- The purposes of processing,
- To whom and for what purposes data may be transferred,
- The method of collection and the legal basis,
- The rights listed in Article 11 (access, rectification, erasure, objection, compensation and more).
The authority's March 2025 guide on the information obligation, citing Article 5 of the Communiqué on the information obligation, stresses one rule: where processing relies on explicit consent, the notice and the consent must be handled separately. A single checkbox reading "I have read and accept the privacy notice" tries to do both jobs and is risky.
In practice, link a short notice at every collection point: account sign-up, checkout, newsletter forms and contact forms.
How should explicit consent be collected?
Article 3 defines explicit consent as consent "on a specific subject, based on information and given with free will". For ecommerce that translates into:
- Specific: Separate consent per purpose (do not bundle ad cookies and cross-border transfer in one box).
- Informed: A short, clear explanation before the consent.
- Free: Do not make consent a condition of ordering or signing up, and never pre-tick boxes.
- Provable: Log who consented, when and to which version of the text.
Commercial electronic messages (email, SMS) follow a separate regime under Article 6 of Law No. 6563. Keep that distinction when you build marketing flows; our ecommerce email automations guide covers the automation side.
What should a cookie banner look like under KVKK?
The authority's Guide on Cookie Practices (July 2025, KVKK Publications No. 69) is the most concrete reference for online stores. Key points:
- Strictly necessary cookies (session, cart, security, remembering consent choices) can rely on bases other than consent, but must not be used for marketing.
- Advertising and behavioural targeting cookies and social network tracking cookies require explicit consent.
- First-party analytics cookies limited to running and measuring the site may, according to the guide, be assessed under non-consent bases, with measures such as IP masking recommended. Assess third-party analytics tools separately.
- A panel shown on entry with "accept", "reject" and "preferences" buttons equal in colour, size and font is cited as good practice.
- The cookie notice should be separate from the consent panel and easy to reach.
Rejected cookies must genuinely not load, which means your tag manager has to fire based on consent state. To reduce the measurement gap left by users who decline, our server-side tracking and Conversions API guide helps, but server-side setups must respect the same consent decisions.
Does an online store need to register with VERBİS?
Article 16 governs registration in the Data Controllers' Registry (VERBİS), but the Board has set exemptions. Under Board decision 2023/1154 of 6 July 2023, data controllers with fewer than 50 employees and an annual balance sheet total below TRY 100 million, whose main activity is not processing special category data, are exempt. Board decision 2025/1572 of 4 September 2025 added an exemption for controllers whose main activity is processing special category data but who have fewer than 10 employees and a balance sheet below TRY 10 million. Above those thresholds, VERBİS registration is required.
What about transferring data to tools abroad?
Most stores use hosting, email and ad tools located outside Turkey. Article 9 was rewritten in 2024 by Law No. 7499. Transfers now require a basis from Article 5 or 6 plus an adequacy decision, or, without one, appropriate safeguards such as standard contracts. A signed standard contract must be notified to the authority within five business days; failing to do so is a separate fine under Article 18.
Step-by-step KVKK roadmap
- Build a data inventory: which data, which purpose, which legal basis, stored where.
- Update privacy notices for each collection point.
- Separate consent-based activities and give each its own consent flow.
- Audit cookies and configure your consent platform with equal buttons.
- Test that tags fire according to consent state.
- List transfers abroad, sign standard contracts and notify them on time.
- Check the VERBİS thresholds and register if required.
- Document access controls, encryption and logging under Article 12.
A compliant measurement setup does not have to cost you ad performance. If you want to plan it together, request a free growth analysis via our contact page and the Performetic team will review the tracking and advertising side with you.
Key takeaways
- Assign a legal basis from Article 5 or 6 of Law No. 6698 to every processing activity.
- Privacy notices need the five Article 10 elements; for consent-based processing, notice and consent are separate.
- Explicit consent must be specific, informed and free; no pre-ticked boxes.
- July 2025 cookie guide: consent for ad cookies and equally weighted accept and reject buttons.
- VERBİS exemption: under 50 employees and under TRY 100 million balance sheet (if special category data is not the main activity).
- Standard contracts for transfers abroad must be notified within five business days.
Frequently asked questions
Can the privacy notice and the consent form be one document?
The Turkish authority's guide, citing Article 5 of the Communiqué on the information obligation, says that where processing relies on explicit consent, the notice and the consent must be handled separately. The notice informs and needs no acceptance; consent is a separate expression of will on a specific subject. Do not merge them into one checkbox.
Is KVKK the same as the GDPR?
No. KVKK shares concepts with the GDPR, such as legal bases for processing and data subject rights, but it has its own rules, for example the VERBİS registry, the 2024 cross-border transfer regime under Article 9 and the Turkish authority's own cookie guide. GDPR compliance alone does not guarantee KVKK compliance.
Do analytics cookies need consent in Turkey?
The KVKK cookie guide says first-party analytics cookies limited to running and measuring the site may rely on bases other than consent. If a third-party analytics tool also serves advertising purposes or transfers data, the assessment may differ. Review your setup with a specialist and lean towards consent when in doubt.
What are the penalties for ignoring the information obligation?
Article 18 of Law No. 6698 sets separate administrative fines for failing the information obligation, failing data security duties, breaching VERBİS duties and not notifying standard contracts for transfers abroad. The amounts in the law are updated periodically, so check the current figures before relying on them.
Sources
- Law No. 6698 on the Protection of Personal Data (Turkish)
- KVKK: Guide on Cookie Practices, July 2025 (Turkish)
- KVKK: Guide on Fulfilling the Information Obligation, March 2025 (Turkish)
- KVKK: VERBİS exemption threshold update, decision 2023/1154 (Turkish)
- KVKK: VERBİS exemption for special category processors, decision 2025/1572 (Turkish)