GDPR Compliance on E-Commerce Websites: Customer Data, Marketing Permissions, and Cookies
Entrance
E-commerce websites are among the digital spaces where personal data is processed most intensively. When a user accesses a site, data such as IP address, device information, cookie data, browsing behavior, and product viewing history may be processed. When creating an account, information such as name, surname, phone number, email address, date of birth, and password is required. During the ordering process, delivery address, billing information, payment information, shopping cart contents, purchase history, and customer transaction records are processed. After product delivery, new data processing activities arise within the scope of returns, exchanges, customer support, campaigns, satisfaction surveys, and marketing processes.
Therefore, GDPR compliance on e-commerce sites is not simply about placing a "GDP text" on the website. E-commerce businesses must clearly state the purpose for which they collect customer data, the legal basis for doing so, which data they are obligated to collect, which data they use for marketing purposes, with whom they share data, which data they process using cookies, whether they transfer data abroad, and how customers can exercise their rights.
Marketing permissions and cookies are among the most frequently complained about areas in the e-commerce sector. The phone number required to offer a product or service to a user is not the same as the communication permission required to send advertising and campaign messages. Similarly, obtaining a customer's address information to deliver their order and creating an advertising profile based on that customer's behavior cannot be evaluated on the same legal grounds. In its decision numbered 2022/229 concerning the e-commerce sector, the Personal Data Protection Board imposed an administrative fine of 800,000 TL on the data controller for processing personal data with absolutely unnecessary cookies and transferring data abroad due to the lack of a legal basis.
For e-commerce businesses, the correct GDPR compliance process requires addressing a combination of factors including data inventory, information text, explicit consent management, permissions for commercial electronic communications, IYS (Electronic Communication System) registrations, cookie management panel, data security measures, retention and destruction policy, and third-party service provider agreements.
What Personal Data is Processed on E-Commerce Websites?
The personal data processed on e-commerce websites varies depending on the site's field of activity and business model. However, generally, customer identification data, contact data, address data, financial data, transaction security data, customer transaction data, marketing data, and cookie data are processed.
Identity data may include name, surname, username, membership number, billing information, and in some cases, Turkish national identity number. Contact data consists of phone number, email address, and delivery/billing address. Customer transaction data includes order history, shopping cart contents, return requests, exchange records, customer support correspondence, product reviews, and complaint records. Transaction security data may include IP address, log records, device information, session information, and security verification records.
Marketing data is different. Information such as which products a user views, which campaigns they click on, which products they add to their cart, which categories they are interested in, email open and click data, segmentation information, and ad targeting data can all be considered marketing data. Behavioral data collected through cookies and similar technologies can also fall into this category.
E-commerce businesses should not disclose all this data collectively under the same text and legal basis. The purpose and legal basis must be determined separately for each data processing activity. For example, delivery addresses may be processed within the scope of contractual performance for the purpose of shipping the product. Billing information may be processed within the scope of tax and accounting obligations. However, sending campaign SMS messages, conducting remarketing, or tracking users with advertising cookies require different legal assessments.
The Obligation to Inform in E-Commerce
One of the most fundamental obligations of an e-commerce site under the Turkish Personal Data Protection Law (KVKK) is the obligation to inform. Informing the data subject means explaining to the data subject who is processing their data, for what purpose, on what legal grounds, to whom it may be transferred, the methods used to collect it, and their rights under the KVKK. Information must be provided when personal data is collected; only in this way should the user be able to understand how their data is being processed.
The privacy policy should reflect the actual data processing activities of the e-commerce site. General statements such as "Your personal data is processed under the KVKK (Turkish Personal Data Protection Law)" are insufficient. The policy should explain each process separately: membership creation, order taking, payment, delivery, invoicing, customer support, returns, marketing, cookies, and legal dispute resolution.
For example, it should be clearly stated that customer name, surname, and contact information are processed for the purposes of managing the order process, delivering products, and providing customer support services; that the delivery address may be shared with the shipping company; that billing information is stored for accounting and tax purposes; and that separate permission will be obtained for campaign and advertising communications.
The terms "information notice" and "explicit consent" should not be confused. The Personal Data Protection Board's principle decision numbered 2025/1072 emphasizes that the obligation to inform and the process of obtaining explicit consent must be carried out separately. Therefore, attempting to obtain a membership agreement, a KVKK (Personal Data Protection Law) information notice, explicit consent, and permission for commercial electronic communications all in a single box on an e-commerce site creates serious legal risks.
How is the legal basis for processing customer data determined?
Under the Turkish Personal Data Protection Law (KVKK), there must be a legal basis for any personal data processing activity. The most frequently used legal grounds for e-commerce sites are: establishment or performance of a contract, fulfillment of a legal obligation, establishment, exercise or protection of a right, legitimate interest, and explicit consent.
Obtaining the customer's name, surname, delivery address, and telephone number is often necessary for the fulfillment of the distance selling contract. Processing billing information may be based on legal obligations arising from tax and accounting regulations. Return and exchange records may be processed within the scope of consumer legislation and contractual obligations. Customer support records may be processed for the purpose of resolving requests and complaints.
In contrast, marketing, advertising, behavioral analysis, retargeting, custom campaign segmentation, and commercial email delivery generally require different assessments. A customer's purchase does not automatically mean they can receive unlimited advertising messages. Similarly, a customer providing their phone number for delivery does not automatically mean that number can be used for advertising SMS messages.
This distinction is particularly crucial for e-commerce sites. E-commerce companies often want to use phone and email information collected during the sales process for later purposes such as campaigns, discounts, shopping cart reminders, and special offers. Both the Personal Data Protection Law (KVKK) and the legislation on commercial electronic communications must be considered together for this use.
Marketing Permissions and Commercial Electronic Communication
One of the most important areas for e-commerce sites to pay attention to is sending commercial electronic communications. SMS, email, automated calls, campaign notifications, discount announcements, shopping cart reminders, remarketing messages, and similar communications can be considered commercial electronic communications.
Regarding the sending of commercial electronic messages, not only the Personal Data Protection Law (KVKK) but also Law No. 6563 on the Regulation of Electronic Commerce and the Regulation on Commercial Communication and Commercial Electronic Messages must be considered. In this area, the Message Management System (İYS) is used as a centralized permission management system. The Ministry of Trade states that with İYS, citizens can view, control, and exercise their right to refuse message consents from a single point; and that it provides legal security in terms of proof for service providers in managing permission processes.
Therefore, when an e-commerce site obtains marketing permission from a customer, it must clearly specify which channel this permission applies to. SMS, email, and call permissions should be managed separately. A customer may only want to receive emails and not SMS messages. They may only want to receive order notifications and not campaign messages. These preferences must be recorded in a clear and verifiable manner.
Furthermore, customers should always be able to exercise their right to refuse. The IYS (Electronic Communications System) also offers recipients the ability to manage, approve, and exercise their right to refuse commercial electronic communications from a single point. E-commerce sites should not send marketing messages to customers who have exercised their right to refuse and should ensure consistency between their own systems and IYS records.
Is it possible to obtain marketing consent using an SMS verification code?
One of the most debated practices in e-commerce websites and retail sales processes in recent years is obtaining permission via SMS verification codes. During transactions such as payment, membership registration, invoice creation, or information updates, a code is sent to the customer's phone; when the customer enters this code, it is sometimes interpreted as obtaining permission for commercial electronic communication or consent for personal data processing. This practice carries serious risks under the Turkish Personal Data Protection Law (KVKK).
In its principle decision dated June 10, 2025, numbered 2025/1072, the Personal Data Protection Board thoroughly evaluated the processing of personal data through the sending of SMS verification codes during the provision of products and services. The Board stated that individuals must be clearly and understandably informed about the purpose of the SMS code sent during processes such as payment, registration, membership creation, or offer generation; and that practices involving the completion of different activities—such as membership agreement approval, personal data processing consent, and commercial electronic communication consent—with a single action should be terminated.
This decision is directly important for e-commerce sites. If a customer is told to "enter the code to complete your order," and it is then claimed that this code also constitutes marketing consent, the elements of informed and freely given consent may be undermined. The Board's decision also explicitly states that explicit consent to the processing of personal data for the purpose of sending commercial electronic communications should not be presented as a mandatory element for the completion of the product or service delivery.
Therefore, the most effective approach for an e-commerce site is to manage mandatory processes for orders and membership, as well as marketing consent, on separate screens, with separate texts and separate checkboxes. Customers should be able to complete their orders even without granting marketing consent. Marketing consent should be requested later, as an explicit and separate option.
How to Obtain Explicit Consent?
Explicit consent is informed and freely given consent regarding a specific matter. In e-commerce sites, explicit consent may be relevant particularly in marketing, commercial electronic communications, certain cookies, behavioral advertising, some international data transfers, and data processing activities where there is no legal basis other than explicit consent.
Explicit consent should not be general and unlimited. Statements such as "I consent to the processing of all my personal data for any purpose" are legally risky. Instead, it should be clearly stated which data will be processed, for what purpose, and through which channel. For example, specific statements such as "I consent to the processing of my phone number for the purpose of sending campaign and advertising SMS messages" or "I consent to receiving commercial electronic messages with discounts and promotions to my email address" should be used.
Consent boxes should not be pre-checked. A user's silence, continued use of the site, or purchase should not constitute explicit consent. Furthermore, explicit consent should not be made a mandatory condition for the service. The Board's principle decision numbered 2025/1072 clearly states that presenting explicit consent as a prerequisite for the provision of a product or service undermines the element of free will.
The explicit consent processes on an e-commerce site must also be verifiable. Which user gave permission, on what date, via what text, and for which channel? From which IP address was the permission given? Was it later withdrawn? Is it compliant with the IYS (Information System for Users) record? Answers to these questions must be provided.
Cookies and E-commerce Websites
Cookies are widely used on e-commerce websites. Some cookies may be necessary for shopping cart protection, session security, user login, language preference, payment security, and site performance. However, analytical cookies, advertising/marketing cookies, behavioral targeting cookies, remarketing pixels, and third-party tracking technologies often require explicit consent and detailed information.
In its decision numbered 2022/229, the Personal Data Protection Board examined the cookies used on the website and mobile applications of a company operating in the e-commerce sector; an administrative fine was imposed due to the lack of an explicit consent mechanism for non-essential cookies, failure to adhere to personal data processing conditions, and inappropriate international data transfer processes. The Board also stated that for functional, performance-analytical, and advertising/marketing cookies (excluding strictly essential cookies), if there is no data processing condition other than explicit consent, an "opt-in" mechanism should be implemented. This mechanism ensures the user's active consent upon logging into the site and, by default, disables the cookies.
This decision demonstrates the importance of cookie management for e-commerce sites. Passive notifications such as "We use cookies, click here for details" are often insufficient. Users should be informed about cookie categories, non-essential cookies should be disabled by default, and users should be able to make a genuine choice between "accept," "reject," or "manage my preferences.".
The cookie policy should also be simple and concrete. Which cookies are used, who is the provider, what is their purpose, how long are they stored, are they first-party or third-party, do they transfer data abroad, and how can users change their preferences? This information should be clearly stated.
What should a cookie management panel look like?
A cookie management panel compliant with the Turkish Personal Data Protection Law (KVKK) must enable users to make genuine and free choices. Simply having an "accept all" button is insufficient; "reject" and "preferences" options must also be clearly visible. Except for mandatory cookies, cookies should not be executed without the user's active consent.
One of the common mistakes made on e-commerce sites is that advertising and analytical cookies are automatically activated as soon as a user enters the site. Even if the user is later directed to disable cookies through their browser settings, data processing may have already begun. The Board's e-commerce decision also indicates that simply directing users to disable cookies through browser settings is not considered sufficient; an active consent mechanism is crucial for cookies that are not absolutely necessary.
The cookie panel should clearly distinguish between categories. Essential cookies, functional cookies, performance/analytical cookies, and advertising/marketing cookies should be displayed under separate headings. Users should be able to accept analytical cookies and reject advertising cookies. Furthermore, users should be able to change their preferences later.
Sharing Customer Data with Third Parties
E-commerce websites often have to share customer data with third parties. This includes shipping companies, payment institutions, banks and virtual POS providers, accounting software, invoice integration companies, call center providers, advertising agencies, email marketing platforms, software providers, and cloud service companies.
However, sharing customer data with third parties cannot be unlimited and uncontrolled. The data protection notice should clearly state which recipient groups may receive data and for what purpose. For example, processes such as sharing name, surname, phone number, and address information with a shipping company for delivery; sharing transaction information with a payment institution for payment; or providing information to a financial advisor or e-invoice service provider for invoicing should be clearly defined.
E-commerce companies must include data security clauses in their contracts with data processors. If a shipping company, call center, software company, or email marketing platform accesses customer data, it must be specified for what purpose these parties process the data, how long they store it, whether they use subcontractors, whether they transfer data internationally, and how they will notify in case of a breach.
If advertising, analytics, CRM, or email marketing tools, especially those based abroad, are being used, the provisions of the KVKK (Turkish Personal Data Protection Law) regarding data transfer abroad should be evaluated separately. The Board's decision numbered 2022/229 also specifically states that the transfer of personal data abroad via cookies must be brought into compliance with Article 9 of the Law.
Payment Information and Data Security
Payment information is of particular importance on e-commerce websites. Credit card information, payment transaction records, installment details, payment approvals, and return records can be considered financial data. The secure processing of this data is crucial for both GDPR compliance and payment system security.
E-commerce sites should, if possible, avoid storing card information in their own systems and instead process transactions through reliable payment institutions and virtual POS infrastructures. If card storage services are offered, the technical and legal framework for these services should be examined separately. Unauthorized access, data leaks, or system vulnerabilities may lead to both GDPR data breach notifications and industry-specific obligations.
Data security measures should include strong password policies, two-factor authentication, SSL/TLS usage, access authorization, logging, encryption, backups, firewalls, regular penetration testing, software updates, and employee training. Only personnel whose duties require access to customer data should be allowed to do so. System privileges for former employees should be immediately revoked.
Membership Agreement, Distance Sales Agreement and GDPR Texts Should Be Separate
One common mistake on e-commerce sites is grouping all legal texts under a single checkbox. Membership agreements, distance selling agreements, pre-information forms, GDPR disclosure texts, explicit consent texts, cookie policies, and permission for commercial electronic communications all have different legal functions.
The user may agree to the distance selling agreement while shopping; however, this agreement does not automatically imply consent to marketing or cookie usage. The user may read the information text; however, this does not constitute explicit consent. The user may create a membership; however, this membership does not mean that they consent to receiving advertising SMS messages.
Therefore, e-commerce sites should organize their legal texts in a simple, accessible, and functionally distinct manner. Mandatory contractual approvals for order completion should be clearly separated from optional marketing permissions. Users who do not consent to marketing should be able to make purchases. Users who reject non-essential cookies in their cookie preferences should be able to use the site's basic functions.
How long can customer data be stored?
According to the Turkish Personal Data Protection Law (KVKK), personal data must be stored for as long as is necessary for the purpose for which it was processed. E-commerce sites cannot retain customer data indefinitely. However, the storage of certain data may be necessary for specific periods due to legal obligations and the possibility of disputes.
Invoice and accounting records may be kept in accordance with tax regulations. Order and delivery records may be retained for specific periods for consumer disputes, returns, warranties, defective product claims, and legal defense purposes. Customer support records may be kept to support the resolution of requests and as evidence in potential disputes. Marketing permissions may be retained for as long as necessary to prove the existence of permission and to exercise the right to refuse.
However, cookie data from non-purchasing visitors, inactive accounts of former members, unused campaign lists, and unnecessary segmentation data should not be stored uncontrollably. A retention and destruction policy should be established; data should be deleted, destroyed, or anonymized when the retention periods expire.
Data Subject Applications and Customer Rights
E-commerce customers are considered data subjects under the Turkish Personal Data Protection Law (KVKK). Customers can contact the e-commerce company to inquire whether their personal data is being processed, request information if it is, ask about the purpose of processing, find out who their data has been transferred to, request correction of inaccurate or incomplete data, request the deletion or destruction of data if the conditions are met, and claim compensation for any damages incurred.
The e-commerce site must have a clear channel for these applications. A GDPR application form, email address, registered electronic mail address, or physical application address must be provided. The customer service team must be able to distinguish between GDPR applications and ordinary customer complaints. Applications must be answered promptly and with justification.
Furthermore, in terms of marketing permissions, the customer's right to opt out must be effectively exercised. The process should be easy when the customer wishes to unsubscribe, stop receiving SMS messages, or leave the email list. Making the opt-out process difficult, forcing the user through multi-step procedures, or continuing to send messages despite unsubscribing poses risks under both the Personal Data Protection Law (KVKK) and commercial electronic communication legislation.
The Most Common GDPR Mistakes Made by E-commerce Websites
The most common mistake e-commerce sites make is assuming they can freely use contact information collected for orders for marketing purposes. However, a phone number collected for delivery does not automatically mean permission to receive promotional SMS messages.
The second mistake is trying to gather all consents in a single box. Membership, distance selling, GDPR information, explicit consent, permission for commercial electronic communications, and cookie consent should be managed separately.
The third mistake is running cookies without user consent. An active consent mechanism should be established, especially for advertising and marketing cookies, behavioral targeting, and third-party tracking tools.
The fourth mistake is not keeping the IYS (Electronic Communication System) records up-to-date. Commercial electronic communication permissions must be consistent with the consents given or withdrawn by the customer. As stated by the Ministry of Trade, IYS is a system established for the centralized management of consents and the exercise of the right to refuse.
The fifth mistake is overlooking foreign service providers. Data transfer abroad may occur in email marketing, advertising, analytics, CRM, cloud, and payment infrastructures. This situation should be evaluated separately under Article 9 of the Turkish Personal Data Protection Law (KVKK).
The sixth mistake is inadequate data security measures. Weak passwords, unauthorized panel access, leaving old employee accounts open, sharing customer data in Excel lists, uncontrolled use of shipping labels, and failure to maintain log records all create a serious risk of breaches.
The seventh mistake is using copy-paste GDPR texts. Every e-commerce site has different data processing processes. If text taken from another site does not reflect the actual data flow, the obligation to inform remains incomplete.
GDPR Compliance Checklist for E-Commerce Websites
E-commerce businesses should first prepare a data inventory. What data is processed during membership registration, orders, payments, deliveries, returns, customer support, marketing, and through cookies? For what purpose, on what legal basis, and for how long is this data processed? To whom is it transferred? Is any data transferred abroad?
Secondly, the privacy policy should be updated. Separate privacy policies can be prepared for customers, members, visitors, and cookies. The texts should be simple, clear, and concrete.
Thirdly, explicit consent and permissions for commercial electronic communications should be separated. Marketing permissions should not be made a mandatory condition of the order; customers should be given a genuine choice. SMS, email, and call permissions should be managed separately.
Fourthly, the IYS (Information Management System) processes should be monitored. Permission records, rejection records, and system integrations should be maintained regularly.
Fifth, a cookie management panel must be installed. Non-essential cookies should be disabled by default; the user must actively consent to this setting.
Sixth, data processing agreements should be made with third-party service providers. Data security obligations should be clarified with shipping, payment, software, advertising, email, and cloud providers.
Seventh, data security must be improved. Panel access should be restricted, log records should be maintained, encryption and backups should be implemented, employees should be trained, and a data breach response plan should be prepared.
Conclusion
GDPR compliance is an integral part of the sales process for e-commerce websites. Customer data, membership, order, payment, delivery, return, customer support, marketing, and cookie processes must be considered together; the correct legal basis must be determined for each data processing activity. E-commerce businesses should differentiate between data processing activities that are mandatory for a customer to make a purchase and optional activities such as marketing, advertising, and behavioral tracking.
In terms of marketing permissions, IYS (Information System for Electronic Communications) records, commercial electronic communication legislation, and the Personal Data Protection Law (KVKK) must be applied together. A customer providing their phone number or email address for delivery does not automatically mean they will receive campaign messages. The Board's principle decision numbered 2025/1072 serves as a clear warning to e-commerce businesses regarding obtaining different approvals in a single transaction via SMS verification code and presenting commercial electronic communication permission as a mandatory condition of the service.
Regarding cookies, it is absolutely essential to differentiate between necessary cookies and advertising, marketing, analytical, and behavioral tracking cookies. The Board's decision No. 2022/229 concerning the e-commerce sector indicates that an active consent mechanism for non-essential cookies, updating of the cookie policy, and compliance of international data transfer processes with the Personal Data Protection Law (KVKK) are necessary.
In conclusion, simply publishing legal texts is not enough to establish an e-commerce site compliant with the Turkish Personal Data Protection Law (KVKK). A data inventory must be prepared, information texts must be concretized, explicit consent and marketing permissions must be managed separately, CMS processes must be kept up-to-date, a cookie management panel must be established, third-party service providers must be monitored, and data security measures must be implemented. When this process is carried out correctly, the e-commerce business reduces the risk of administrative fines and complaints, and offers its customers a trustworthy, transparent, and legally compliant digital shopping experience.