Single Blog Title

This is a single blog caption

How to Prepare a Cookie Policy Under the Personal Data Protection Law (KVKK)? Legal Guide for Websites

Entrance

Websites are no longer just digital storefronts for advertising. E-commerce sites, law firms, clinics, software companies, hotels, educational institutions, news sites, membership platforms, and mobile applications can process a wide range of data, including visitors' IP addresses, device information, location data, session information, user preferences, shopping behavior, pages visited, and advertising interactions. A significant portion of this data is collected through cookies and similar technologies.

Cookies can facilitate the operation of a website, remember users' language preferences, protect items added to the cart, enable secure login, or analyze site traffic. However, cookies can also be used to track user behavior, create advertising profiles, conduct remarketing, transfer data to third-party advertising networks, and track users across different sites. Therefore, a cookie policy is not just a technical document, but a legal document that is directly part of the GDPR compliance process.

The Personal Data Protection Board's decisions state that explicit consent may not always be required for cookies that are essential for the proper functioning of a website; however, cookies used for advertising, marketing, and performance purposes may be subject to explicit consent. Furthermore, it is accepted that for non-essential cookies, an "opt-in" mechanism may be implemented, requiring the user to actively consent upon entering the website and setting the default to disable these cookies.

Therefore, the answer to the question "How to prepare a cookie policy under the KVKK (Personal Data Protection Law)?" is not simply adding a sample text to the website. First, it requires identifying the cookies used, determining the purpose and legal basis of each cookie, differentiating between mandatory and non-mandatory cookies, establishing a proper consent management mechanism for cookies requiring explicit consent, and providing the user with clear and understandable information.

What are cookies?

Cookies are small data files placed on a user's device or browser when they visit a website. These files allow the website to remember the user's preferences, session information, shopping cart information, language selection, or previous visits. Cookies can enhance the user experience, but they can also be used to measure user behavior and target advertising.

The important point from the perspective of the Turkish Personal Data Protection Law (KVKK) is this: While not all data processed through cookies is automatically considered personal data, information that directly or indirectly identifies the user may be considered personal data. IP addresses, user IDs, device identifiers, session tokens, advertising IDs, behavioral tracking data, and cookie data associated with an account can be considered within this scope.

Therefore, stating on a website that "we only use cookies, we don't process personal data" is often inaccurate. Especially if cookies are associated with user accounts, IP addresses, advertising IDs, device information, or third-party tracking tools, personal data processing activities may be considered under the Personal Data Protection Law (KVKK). In the Board's decision regarding the e-commerce sector, the lack of a clear statement in the cookie policy specifying which personal data is associated with which processing purpose and legal basis was deemed a deficiency.

What is the Cookie Policy?

The cookie policy is a document that explains the purposes for which cookies are used on the website or mobile application, the types of cookies available, what data is processed through cookies, the legal basis for this data processing, how long cookies are stored, whether they are first-party or third-party cookies, and how users can manage their cookie preferences.

The cookie policy differs from the general privacy policy. While the privacy policy may describe the company's general personal data processing processes, the cookie policy should specifically focus on the use of cookies on the website and mobile application. Board decisions state that information regarding cookies should be easily accessible and that the cookie policy should be updated in accordance with Article 10 of the Law and the Communiqué on the Obligation to Inform.

A well-designed cookie policy should not only inform the user that "this site uses cookies." The user should clearly see which cookies are being used and why, whether they are mandatory, whether they are used for advertising or analytics purposes, whether data is being transferred to third parties, and how to disable unwanted cookies.

What are the different types of cookies?

Cookies can be classified according to different criteria. Based on storage duration, they can be called session cookies and persistent cookies; based on their source, they can be called first-party and third-party cookies; and based on their purpose, they can be classified as essential cookies, functional cookies, performance-analytical cookies, and advertising-marketing cookies.

Mandatory cookiesare cookies that are necessary for the website to perform its basic functions. Session security, user login, protection of shopping cart information, payment security, load balancing, or the provision of a service explicitly requested by the user can be considered within this scope. The site may not function properly without these cookies.

Functional cookiesare cookies that remember user preferences. Examples include language selection, region preference, font preference, theme preference, or user interface preferences. However, not every functional cookie is automatically considered mandatory. Whether it is truly necessary for the service explicitly requested by the user must be evaluated separately.

Performance and analytical cookiesmay be used to measure how the website is used, analyze visitor numbers, see which pages are visited most frequently, or improve the user experience. However, the likelihood of explicit consent increases if these cookies track the user, collect data through third-party service providers, or are combined with an advertising profile.

Advertising and marketing cookies are used to display ads based on user interests, perform remarketing, track movement between different sites, and measure advertising performance. Because these types of cookies interfere more with user privacy, they are evaluated more strictly under the Turkish Personal Data Protection Law (KVKK).

The Board's decisions emphasize that, with the exception of absolutely necessary cookies, for functional, performance-analytical, and advertising/marketing cookies, explicit consent must be obtained from the user via the "opt-in" method if there is no other data processing requirement.

Which cookies require explicit consent?

Whether explicit consent is required under the KVKK (Turkish Personal Data Protection Law) is determined not by the name of the cookie, but by its purpose and legal basis. Simply labeling a cookie as "analytical" or "functional" is not sufficient. It must be examined what data it actually collects, whether it tracks the user, whether it transfers data to third parties, whether it is related to advertising profiling, and whether it is truly necessary for the website to function.

Regarding cookies that are essential for the proper functioning of the website, explicit consent may not be required if one of the data processing conditions other than explicit consent in Article 5 of the KVKK (Law on Protection of Personal Data) is met. For example, essential cookies may be used for user login, shopping cart protection, or security checks. However, explicit consent is much more likely for cookies used for advertising, marketing, user behavior tracking, and performance purposes. The summary of the Board's decision numbered 2022/1358 shows that administrative fines were imposed for processing personal data without any processing conditions through non-essential cookies, such as those used for advertising and marketing purposes.

The most important point to consider when obtaining explicit consent is that it must be based on active behavior. A user cannot be considered to have accepted the use of cookies simply by entering the site. Passive behaviors such as pre-checking boxes, remaining silent, scrolling the page, or continuing to use the site are risky in terms of explicit consent. In the Board's decision regarding online gaming platforms, it is seen that the approach in the cookie policy stating "visiting the site means consent to the use of cookies" was the subject of a complaint, and the importance of an "opt-in" mechanism based on active consent in cookie management was emphasized.

What should a cookie management panel look like?

Publishing a cookie policy compliant with the KVKK (Turkish Personal Data Protection Law) solely as text is insufficient. If non-essential cookies are used, a cookie management panel that provides the user with real choices must be established. This panel should be visible upon first visit to the site and should easily guide the user.

As a good practice, the "accept," "reject," and "preferences" options should be presented with equal visibility in the panel. The Board's decision summary (Decision No. 2023/1645) states that presenting the "accept," "reject," and "preferences" buttons in the cookie management panel with equal color, size, and font could be considered a good practice example. The same decision also states that options should be provided for each type of cookie requiring explicit consent, and that a collective consent approach such as "allow all cookies" could undermine the elements of explicit consent being specific to a particular matter and given freely.

Therefore, offering only an "accept all" option to the user in the cookie panel is incorrect. Users should be able to accept analytical cookies and reject advertising cookies, excluding mandatory cookies. Similarly, there should be an easily accessible "cookie preferences" link on the website so that users can change their preferences later.

Is Cookie Wall Usable?

A cookie wall is a practice that conditions the use of a website or service on the acceptance of non-essential cookies. For example, if a user cannot access the site or use the basic service without accepting advertising cookies, it becomes debatable whether explicit consent is based on free will.

Making explicit consent a condition of service in the application of the Personal Data Protection Law (KVKK) is risky. The Board has assessed that imposing explicit consent as a condition of membership or service in personal data processing activities that are not necessary for the provision of the service may invalidate explicit consent and constitute a violation of the law, the rules of good faith, and the principle of proportionality.

Therefore, website owners should not design their cookie panel in a way that forces users to choose. Users should be given a genuine choice; even if they reject non-essential cookies, they should still be able to use the site's basic services. This is especially important for e-commerce sites, membership platforms, and service providers, as it reduces the risk of administrative sanctions.

What information should be included in the Cookie Policy?

A cookie policy compliant with the Turkish Personal Data Protection Law (KVKK) must first identify the data controller. The trade name, address, and contact information of the company operating the website must be clearly stated. The user must know who is processing their data and against whom they can exercise their rights.

Secondly, the purposes for which cookies are used should be explained. General statements such as "improving user experience" may not be sufficient on their own. It should be specified separately which cookie is used for session security, language preference, traffic analysis, advertising targeting, social media integration, or remarketing.

Thirdly, the legal basis for each cookie must be stated. For mandatory cookies, reasons such as contractual performance, legal obligation, legitimate interest, or necessity for a service explicitly requested by the user may be considered. For non-mandatory advertising, marketing, and some analytical cookies, explicit consent may be required. Here, "processing purpose" and "legal basis" should not be confused. The Communiqué on the Obligation to Inform stipulates that the data controller must inform the data subject about the method and legal basis for collecting personal data.

Fourthly, the storage duration of cookies should be specified. Session cookies may expire when the browser is closed; persistent cookies may remain on the device for a specific period. The user should know how long each cookie is stored.

Fifthly, it should be clarified whether the cookie is first-party or third-party. First-party cookies are placed directly by the website being visited. Third-party cookies, on the other hand, may be placed by advertising networks, social media platforms, analytics tools, or external service providers. The Board's decision summary numbered 2023/1645 states that, in the case of third-party cookies, both the website owner and the third party must clearly inform users about the cookies and obtain the necessary consents; and if data is transferred abroad, the conditions of Article 9 of the Law must be complied with.

Sixth, the user should be informed how to change their cookie preferences. Information on managing cookies through browser settings can be provided; however, this alone should not be considered sufficient. Because if non-essential cookies are activated the moment the user enters the site, redirecting them to browser settings later does not provide real control. Therefore, a preference management mechanism that works within the site is a more secure method.

Are the Cookie Disclosure Statement and the Explicit Consent Statement the Same Thing?

No. A cookie policy is an informational text that explains to the user which personal data is processed through cookies. Explicit consent, on the other hand, is the user's free will to approve a specific category of cookies or a particular data processing activity.

In its announcement regarding the principle decision dated February 18, 2026, and numbered 2026/347, the Personal Data Protection Board stated that presenting the explicit consent text and the information text intertwined is one of the frequently observed legal irregularities in the notifications and complaints received by the Board. The announcement also listed requesting approval or consent from the data subjects regarding the information provided, and the verbatim use of texts from other data controllers, as problematic practices.

Therefore, using a single checkbox in the cookie policy that reads "I have read the cookie policy and I give my explicit consent to all cookies" is risky. Information and explicit consent should be separated; if explicit consent is required, a separate option should be offered for each category.

Third-Party Cookies and Data Transfer Abroad

Websites often utilize third-party services for analytics, advertising, maps, social media plugins, live support, payment infrastructure, or performance measurement. Some of these services are provided by companies based abroad. In this case, the transfer of personal data collected through cookies to foreign countries may be a concern.

Data transfer abroad is a sensitive issue that needs to be evaluated separately under the Personal Data Protection Law (KVKK). It is not sufficient for a website's cookie policy to simply state that "third-party cookies may be used." It must be explained which third-party provider placed which cookie, for what purpose the data is collected, whether the data is transferred abroad, and what legal mechanism underlies this transfer.

In its decision regarding the e-commerce sector, the Board imposed an administrative fine on the data controller for processing data through cookies that are not strictly necessary, without relying on any of the conditions set forth in Articles 5 and 6 of the Law, and for transferring personal data without relying on any of the transfer methods in Article 9 of the Law.

Therefore, cookie inventory and international data transfer analysis should be performed together, especially when using tools such as Google Analytics, Meta Pixel, advertising networks, social media plugins, map services, and similar applications. Otherwise, even if a cookie policy formally exists, actual use may be contrary to the Personal Data Protection Law (KVKK).

Steps to Prepare a Cookie Policy in Compliance with the KVKK (Turkish Personal Data Protection Law)

The first step in preparing a cookie policy compliant with the Turkish Personal Data Protection Law (KVKK) is to technically identify all cookies on the website. This process cannot be done simply by writing a legal statement. The site must be scanned, and the cookies, pixel codes, third-party scripts, analytics tools, advertising tools, and social media plugins used must be identified.

The second step is to categorize cookies. It's essential to determine which cookies are mandatory, which are functional, which are analytical, and which are used for advertising or marketing purposes. This distinction should be made based on the cookie's actual function, not just the cookie provider's claims.

The third step is to determine the legal basis for each cookie. For mandatory cookies, processing conditions other than explicit consent can be evaluated. For non-mandatory cookies, the applicability of explicit consent, legitimate interest, or another legal basis should be examined on a case-by-case basis. For advertising, behavioral tracking, and third-party tracking cookies, the explicit consent approach is considered more secure.

The fourth step is to set up a cookie management panel. The panel should present the user with equally clear and understandable options for accept, reject, and preferences. Non-essential cookies should be disabled by default; they should not function unless the user actively makes a choice.

The fifth step is to publish the cookie policy. The policy should be easily accessible on the website, with a direct link from the cookie panel. Users should always be able to access this text and change their preferences.

The sixth step is to perform regular checks. New advertising code may have been added to the website, a new analytics tool may have been installed, live support may have been integrated, or a social media pixel may have been placed. In this case, the cookie policy and cookie panel should be updated. Otherwise, there will be a discrepancy between the published text and the actual use of cookies.

The Most Common Mistakes Companies Make

The most common mistake companies make is thinking they're done simply by posting a general "privacy and cookie policy" on their website. However, a document that doesn't identify individual cookies, specify their storage duration, mention third-party providers, and establish explicit consent management is often insufficient.

The second mistake is automatically enabling non-essential cookies upon login to the site. Activating advertising and analytical cookies without the user making a choice in the cookie panel is risky under the GDPR. The Board's decisions particularly emphasize the "opt-in" mechanism, which stipulates that non-essential cookies should not be activated by default.

The third mistake is the approach of "by continuing to use the site, you agree to the use of cookies." Explicit consent must be specific, informed, and given freely. Substituting passive behavior for explicit consent is legally risky.

The fourth mistake is offering the user an "accept all" option while hiding the "reject" option. Making the reject button small, faded, difficult to find, or multi-step can influence user decision-making. A healthier practice is to present the accept, reject, and preferences options with equal visibility in the cookie management panel.

The fifth mistake is ignoring third-party cookies. A website owner cannot evade responsibility by saying, "These cookies are placed by an advertising company, I'm not responsible." If third-party cookies are placed on the site, the user must be informed and the necessary consents obtained.

The sixth mistake is using a cookie policy copied from another website. Each site has different infrastructure, advertising tools, analytics systems, third-party providers, and storage periods. Because the copied text may not reflect the actual use of cookies, it could fail to fulfill the obligation to inform users.

What are the rights of users?

Users whose personal data is processed through cookies are considered data subjects under the KVKK (Turkish Personal Data Protection Law). The user can contact the data controller to inquire whether their personal data is being processed, request information regarding this processing if applicable, learn the purpose of processing, ask to whom their data has been transferred, request the deletion or destruction of unlawfully processed data, and claim compensation for any damages incurred.

Therefore, website owners must clearly state the application method in their cookie policy. Users should know which email address, registered email address, physical address, or application channel to use. Additionally, there should be an easily accessible preference management area on the site for users who wish to change their cookie preferences.

Conclusion

Under the Turkish Personal Data Protection Law (KVKK), a cookie policy is an indispensable legal compliance document for websites and mobile applications. However, this document should not be viewed merely as a standard text. A proper cookie policy should be based on a technical inventory of the cookies used on the site, and should clearly indicate the purpose, provider, storage duration, first-party or third-party nature, legal basis, and user preference management of each cookie.

Mandatory cookies should be distinguished from advertising, marketing, analytics, and behavioral tracking cookies. If explicit consent is required for non-mandatory cookies, a cookie management panel should be established that gives the user an active choice, keeps these cookies disabled by default, and offers a balanced selection of accept, reject, and preferences options.

The biggest risk for website owners is that while a cookie policy exists on paper, the actual use of cookies is inconsistent with the text. Third-party advertising and analytics tools, data transfer abroad, automated marketing cookies, and the failure to provide users with a genuine option to refuse can lead to GDPR complaints and administrative sanctions.

In conclusion, preparing a cookie policy compliant with the Turkish Personal Data Protection Law (KVKK) requires a combination of legal and technical analysis. The website's cookies must be identified, the legal basis for each cookie must be determined, the appropriate consent management infrastructure must be established for cookies requiring explicit consent, and the user must be provided with clear, understandable, and accessible information. A cookie policy prepared in this way will both increase user trust and significantly reduce the company's risk of administrative fines, complaints, and compensation claims under the KVKK.

Leave a Reply

Call Now Button