KVKK Cookie Consent Guide: Turkish Data Protection Compliance
Understand KVKK Law 6698 cookie consent requirements: explicit consent (açık rıza), cookie policy obligations, aydınlatma metni (privacy notice), and how to set up a compliant consent banner for Turkish websites.
Disclaimer: This guide is for informational purposes only and does not constitute legal advice (hukuki tavsiye değildir). KVKK compliance depends on your specific circumstances, the nature of the personal data you process, and how Turkish regulatory guidance evolves. You should consult qualified Turkish legal counsel before relying on any information presented here.
Turkey's Law on the Protection of Personal Data (Kişisel Verileri Koruma Kanunu, Law 6698) — commonly referred to as KVKK — is the primary data protection framework governing how websites and online services handle personal data in Turkey. Published in the Official Gazette in April 2016, KVKK is closely modelled on the pre-GDPR EU Data Protection Directive 95/46/EC, but it has evolved through secondary regulations and guidance from the Turkish Personal Data Protection Authority (KVKK Kurumu) to introduce uniquely Turkish obligations, including the aydınlatma metni (clarification notice) and specific rules around explicit consent (açık rıza). For any website serving Turkish users — whether your company is based in Istanbul or you are an international SaaS with Turkish customers — understanding KVKK cookie consent requirements is essential. The KVKK Kurumu has been increasingly active in enforcement, issuing public announcements and fines for non-compliant cookie practices. This guide walks you through the legal landscape: what KVKK requires for cookie consent, how those requirements compare to GDPR, what practical steps Turkish websites must take, and how a consent management platform like Nuvo Consent fits into your compliance strategy.
KVKK explicit consent (açık rıza) and how it compares to GDPR
Under KVKK Article 3, explicit consent (açık rıza) is defined as consent that relates to a specified subject, is based on information, and is declared with free will. While this echoes GDPR's freely given, specific, informed, and unambiguous standard, KVKK applies a more formalistic approach in practice. The KVKK Kurumu has consistently emphasised that consent must be obtained through an affirmative action — pre-ticked boxes, implied consent through continued browsing, and cookie walls are all disfavoured under Turkish regulatory guidance. One important distinction from GDPR is the central role of the aydınlatma metni (clarification text or privacy notice), which must be provided separately from the consent request itself. Under Article 10 of KVKK and the Communiqué on Principles and Procedures to be Followed in Fulfilment of the Obligation to Inform, data controllers must provide a detailed written notice covering the identity of the data controller, the purposes of processing, to whom and for what purposes data may be transferred, the method and legal basis of collection, and the rights enumerated in Article 11 — all before obtaining consent. This two-step obligation (inform first, then request consent) is more demanding than the typical single-screen GDPR cookie banner. KVKK also does not recognise 'legitimate interest' as broadly as GDPR. While GDPR allows certain processing under legitimate interest without consent, the KVKK Kurumu has taken a narrower view, meaning that for cookie-based tracking — especially analytics, marketing, and advertising cookies — explicit consent is the safest and most commonly expected legal basis. Websites targeting Turkish users should default to explicit opt-in consent for all non-essential cookies.
What Turkish websites must watch for: practical do's and don'ts
Operating a compliant Turkish website under KVKK requires attention to several practical details that differ from EU-centric compliance checklists. Do: provide a separate, easily accessible aydınlatma metni page that covers all Article 10 elements — this cannot be buried inside a generic privacy policy. Do: implement a consent banner that clearly distinguishes between necessary and non-necessary cookies, with non-necessary categories defaulting to off until the user takes affirmative action. Do: ensure the 'reject all' option is visually and functionally equivalent to 'accept all' — a common enforcement focus. Do: log every consent action (accept, reject, partial selection, withdrawal) with timestamp and scope, as the KVKK Kurumu expects controllers to be able to demonstrate compliance. Do: register with the VERBIS (Data Controllers Registry Information System) if you meet the registration thresholds — this is a separate KVKK obligation distinct from cookie consent but part of the same compliance framework. Don't: pre-load analytics or marketing scripts before the user has made a choice — this is the functional equivalent of a pre-ticked box and has been explicitly called out in KVKK Kurumu guidance. Don't: use cookie walls that condition access to content on accepting tracking, as this undermines the 'free will' element of açık rıza. Don't: treat KVKK compliance as a one-time setup — the obligation to inform is ongoing, and if you add new third-party trackers or change data processing purposes, you must update your aydınlatma metni and re-obtain consent where necessary. Don't: assume GDPR compliance automatically covers KVKK — while the frameworks share DNA, the Turkish regulator applies its own interpretation and secondary legislation.
Cookie policy (çerez politikası) and aydınlatma metni obligations
KVKK does not use the word 'cookie policy' in the text of Law 6698 itself, but the KVKK Kurumu has made it clear through guidance and enforcement that websites using cookies must maintain a publicly accessible cookie disclosure. In practice, this means Turkish websites should publish both a çerez politikası (cookie policy) and an aydınlatma metni (clarification/privacy notice). The cookie policy should list every cookie and tracking technology in use — first-party and third-party — along with each cookie's name, provider, purpose, duration, and whether it is strictly necessary or requires consent. The aydınlatma metni is the broader mandatory privacy notice required by Article 10 and must cover: the identity of the data controller (your company name, address, and contact details), the purposes for which personal data will be processed, the categories of recipients to whom data may be transferred (including any third-party analytics or ad providers), the method and legal basis of data collection (e.g. 'automatically via cookies when you visit our website'), and the data subject rights under Article 11 — including the right to access, rectify, delete, and object to processing. The aydınlatma metni must be made available before consent is collected, and it must be written in clear, plain Turkish (or a language the data subject understands). It is common practice for Turkish websites to link to both the aydınlatma metni and the çerez politikası from the consent banner itself. The KVKK Kurumu has also indicated that cookie consent preferences should be revocable — users must be able to change their choices through a persistent mechanism such as a floating preferences button or a footer link, consistent with the principle that withdrawal should be as easy as giving consent.
Nuvo Consent and KVKK: what we do and what we don't guarantee
Transparency note: Nuvo Consent's KVKK legal review is currently pending_counsel. We have not yet completed a formal legal review of our platform against KVKK requirements with qualified Turkish data protection counsel, and we do not currently guarantee or certify that using Nuvo Consent alone satisfies all KVKK obligations. Here is what Nuvo Consent does today: our scanner detects the trackers, cookies, and third-party vendors on your domain so you have a complete inventory for your çerez politikası disclosure. Our AI classification engine maps findings into regulation-aligned categories, including a KVKK-focused classification scheme that flags marketing, analytics, and advertising cookies as consent-required. Our consent SDK blocks all non-necessary scripts until the user takes affirmative action — supporting the KVKK açık rıza requirement. Every consent action is logged to a tamper-evident audit trail with timestamps and category-level granularity, giving you a record of who consented to what and when — useful for demonstrating compliance to the KVKK Kurumu. Users can update or revoke their preferences at any time through a persistent preferences widget. What Nuvo Consent does not currently do: we do not generate or host your aydınlatma metni — you remain responsible for drafting and publishing a compliant Article 10 notice. We do not handle VERBIS registration. We do not provide legal advice or guarantee that your specific KVKK compliance posture would survive a regulatory audit. If you operate a Turkish website and need KVKK-specific assurances, we recommend engaging qualified Turkish counsel to review your full compliance setup — and we welcome the opportunity to work with your legal team to address any platform gaps identified during their review.
Setting up a KVKK-compliant consent banner
KVKK cookie consent compliance is achievable with the right preparation: understand the explicit consent (açık rıza) standard, draft a thorough aydınlatma metni that meets Article 10 requirements, publish a clear çerez politikası listing every tracker on your site, deploy a consent banner that blocks non-necessary scripts by default and offers equally prominent accept and reject options, and maintain records of every consent action. Nuvo Consent handles the technical heavy lifting — scanning, classification, blocking, banner delivery, and audit trail — so you can focus on the legal and editorial work of drafting your Turkish-language disclosures. If you are ready to set up a KVKK-compliant consent banner, start with a free scan of your domain to identify every tracker that needs disclosure, then work through the consent setup workflow step by step. As our KVKK legal review progresses, we will update our platform documentation and compliance statements to reflect the outcome.