Single Blog Title

This is a single blog caption

How to Prepare a GDPR Disclosure Statement? The Most Common Mistakes Companies Make

Entrance

For companies, the protection of personal data is no longer just a technical security issue, but a compliance area that directly gives rise to legal responsibility. Every company that registers customers, maintains employee personnel files, uses cookies on its website, conducts camera recordings, carries out email marketing, sends shipments, or stores supplier information may be subject to obligations under the Law No. 6698 on the Protection of Personal Data, either as a data controller or a data processor, depending on the nature of its activity.

The primary obligation the duty to inform . The duty to inform requires that the individual whose personal data is being processed be informed by whom their data is being processed, for what purpose, on what legal grounds, by what method, and to whom it may be transferred. The Personal Data Protection Authority defines the duty to inform as an obligation for data controllers and a right for individuals whose personal data is being processed; it states that this obligation is necessary for the lawful processing of personal data.

In practice, many companies place a general document on their website under the name "KVKK text," using it as a single text for customers, employees, suppliers, and visitors. However, not every personal data processing activity is the same. Obtaining a customer's order address, processing an employee's health report, recording a visitor's camera footage, and using a user's cookie data for advertising purposes cannot be evaluated on the same legal grounds. Therefore, the information text should be prepared in a clear, understandable, and concrete manner, appropriate to the company's actual data processing activities.

What is the KVKK (Personal Data Protection Law) Information Text?

The KVKK (Personal Data Protection Law) disclosure text is a document prepared by the data controller to inform the data subject whose personal data is being processed. This text explains which personal data of the data subject is being processed and for what purpose, how the data is collected, the legal basis for this collection, to whom the data may be transferred, and the data subject's rights under the KVKK.

According to Article 10 of Law No. 6698, the data controller is obligated to provide certain information to data subjects when collecting personal data. This information includes: the identity of the data controller and, if applicable, their representative; the purpose for which the personal data will be processed; to whom and for what purpose the data may be transferred; the method and legal basis for data collection; and the rights of the data subject as set forth in Article 11 of the Law. The Communiqué of the Personal Data Protection Authority on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform also explicitly regulates these minimum elements.

Therefore, the privacy policy is not merely a general statement such as "your personal data is processed under the KVKK (Personal Data Protection Law)." The privacy policy must be clear enough to enable the data subject to make informed decisions about their data. When reading the policy, the individual should be able to understand which of their data is being processed for what purpose, to whom their data may be transferred, and how they can exercise their rights.

Why is Privacy Notice Important?

The data protection notice is one of the fundamental documents ensuring the lawfulness of the personal data processing process. A company's obtaining explicit consent to process personal data, or relying on another legal basis stipulated in the law, does not negate its obligation to inform the data subject. The Authority states that the data subject must be informed regardless of whether the personal data processing activity is based on explicit consent or another processing condition in the law.

The privacy notice also ensures that the company fulfills its transparency obligation. If the data subject does not know how their data is being processed, they cannot effectively exercise their rights under the Personal Data Protection Law (KVKK). For example, a person who does not know which of their data is being processed will have difficulty requesting the correction of erroneous data or the cessation of unlawful processing.

For companies, a well-prepared privacy policy provides significant protection against future complaints, audits, and claims risks. However, this protection is not only possible by having the policy on the website, but also by ensuring that the policy is accurate, up-to-date, accessible, and relevant to the specific business activity.

What information should be included in the Privacy Notice?

A GDPR disclosure statement must first clearly identify the data controller. The company's trade name, address, contact information, and, if applicable, information about its representative should be included. The data subject must be able to clearly see who is processing their personal data and to whom they can apply to exercise their rights.

Secondly, the purpose for which personal data is processed must be stated. These purposes should be specific, not general. Broad statements such as "conducting company operations" or "improving service quality" are insufficient on their own. Instead, purposes directly related to the data processing activity should be indicated, such as "ensuring product delivery," "issuing invoices," "conducting job application processes," "ensuring workplace security," or "resolving customer requests and complaints." According to the Communiqué, the purpose of data processing must be specific, clear, and legitimate; general and vague statements should be avoided.

Thirdly, it should be explained to whom and for what purpose personal data may be transferred. For example, data may be transferred to an accounting consultant, a shipping company, a payment institution, authorized public institutions, an occupational health and safety service provider, or a company providing IT infrastructure services. However, a general statement such as "your data may be shared with third parties" is not sufficient. The purpose of the transfer and the recipient groups must be clearly stated in the text. The institution emphasizes that if a transfer is involved, the purpose of the transfer and the recipient group(s) must be explicitly clarified in the statement.

Fourthly, the method and legal basis for collecting personal data must be explained. Data may be collected through physical forms, websites, call centers, camera systems, email, mobile applications, contracts, job application forms, or cookies. The legal basis refers to which of the processing conditions in Articles 5 and 6 of the Law is relied upon. The Authority specifically states that "legal basis" and "processing purpose" are not the same thing; the legal basis must be clearly stated.

Finally, the data subject's rights under Article 11 of the KVKK (Personal Data Protection Law) should be included. However, this section should not be unnecessarily long and complex. The institution states that long and complex texts should be avoided, and if necessary, a simple phrase such as "Your rights under Article 11 of the Law" can be used.

How should a Privacy Policy be prepared?

The first step in preparing a data privacy policy is to identify the company's data processing activities. The policy should answer questions such as: What personal data does the company collect? From whom does it obtain this data? Which departments have access to this data? In which systems is the data stored? To whom is it transferred? And for how long is it retained? Data privacy policies prepared without this initial assessment will often be incomplete or inaccurate.

The second step is to differentiate between the relevant groups of people. It is not appropriate to use the same information text for customers, employees, job applicants, suppliers, visitors, website users, and business partners. This is because the data collected from these groups, the purposes of data processing, and the legal grounds for processing them differ.

For example, employee information notices might include topics such as personnel files, payroll, social security declarations, occupational health and safety, fringe benefits, performance processes, and workplace safety. Customer information notices, on the other hand, highlight order, payment, invoicing, delivery, customer support, and business communication processes. Visitor information notices explain camera recordings and building entry/exit records, while for website users, cookies, IP address, and contact form data should be managed separately.

The third step is to match the purpose and legal basis for each data processing activity. For example, obtaining a customer's address may be for the purpose of "ensuring product delivery" and based on the legal basis of "performance of a contract." Storing billing information may be for the purpose of "fulfilling accounting and tax obligations" and based on the legal basis of "fulfilling a legal obligation." Sending advertising emails is a different process, and explicit consent or permission mechanisms in relevant legislation must be evaluated separately.

The fourth step is to simplify the text. The information notice should be written in a way that can be understood by non-lawyers as well. The institution requires that clear, concise, and simple language be used when providing information; and that incomplete, misleading, incorrect, or ambiguous statements be avoided.

The fifth step is to provide the data subject with the information notice at the right time and using the right method. The obligation to provide information is not dependent on the data subject's request. The data controller is obliged to provide information at the time of obtaining personal data. According to the Communiqué, if personal data is not obtained from the data subject, information must be provided within a reasonable time from the time the data is obtained; if it will be used for communication purposes, during the first communication; and if it will be transferred, at the latest at the time of the first transfer.

The Information Notice and the Explicit Consent Notice must be separate

One of the most common mistakes companies make is presenting the information notice and the explicit consent notice in the same document with a single checkbox. However, the information notice is for informational purposes only; the explicit consent notice indicates that the data subject consents to a specific data processing activity. These two documents have legally distinct functions.

In its announcement regarding the principle decision dated February 18, 2026, and numbered 2026/347, the Personal Data Protection Board stated that presenting the explicit consent text and the information text together is one of the most frequently encountered legal irregularities in the notifications and complaints received by the Board. The Board explained that the explicit consent and information texts should be prepared under separate headings, and even if they are on the same page, separate declarations should be obtained for each text.

Therefore, single-sentence consent mechanisms such as "I have read the KVKK (Personal Data Protection Law) information text and I give my explicit consent to the processing of my personal data" are risky. For the information text, only feedback confirming that the person has been informed is acceptable. If explicit consent is required, it must be obtained separately and in relation to a specific processing activity.

The Most Common Mistakes Companies Make in GDPR Data Protection Notices

The most common mistake companies make is using a data protection notice copied from another company. Each company has a different field of activity, data processing purpose, employee structure, service providers, customer relations, and technical infrastructure. Therefore, using a text prepared for another company verbatim often does not reflect the company's actual data processing activities. The organization explains that texts prepared by other data controllers should not be used verbatim; instead, each data controller should prepare texts tailored to their own organization and activities.

The second mistake is writing the privacy policy too generally. Statements like "Your personal data may be processed within the scope of company activities" do not provide accurate information to the data subject. The privacy policy should specify which data category is processed and for what purpose. In particular, if the purpose, legal basis, and transfer information are left abstract, the policy will not provide legal protection.

The third mistake is confusing the purpose of processing with the legal basis. "Customer satisfaction" may be a purpose, but it is not a legal basis. Conditions for processing included in the KVKK (Personal Data Protection Law), such as "performance of a contract," "fulfillment of a legal obligation," "establishment, exercise, or protection of a right," "legitimate interest," or "explicit consent," must be specified separately as legal basis. The Authority's announcement dated June 8, 2026, also clearly emphasizes that the legal basis and the purpose of processing are distinct elements.

The fourth mistake is using the privacy policy or data processing policy in place of an information notice. A privacy policy typically describes the company's general approach to data processing. However, an information notice should be specific to a particular data processing activity, directed at a specific group of people, and concrete. The organization states that privacy policies, which are general data processing documents, should not be used as information notices.

The fifth mistake is the inaccessibility of the privacy policy. The privacy policy should not be hidden as an unnoticed link at the bottom of the website; it should be presented in a way that is easily visible to the data subject at the time of data collection. Appropriate information should be provided to the data subject when filling out a job application form, submitting a contact form, creating a membership, entering the camera recording area, or when cookies are used.

The sixth mistake is not keeping the privacy policy up-to-date. The company may have started using a new marketing system, switched to a new software provider, started using overseas servers, or installed a camera system. In this case, the old privacy policy may no longer reflect the company's actual data processing activities. According to the Communiqué, when the purpose of personal data processing changes, a separate privacy policy must be issued for this new purpose before the new processing activity begins.

What is Layered Lighting?

Layered lighting is a method of presenting the user with basic information initially, while providing more detailed information through easily accessible secondary text. Layered lighting can be particularly useful in websites, mobile applications, cookie panels, camera warning signs, and call center processes.

However, the first stage in layered data processing should not be left blank. The institution states that when layered data processing is preferred, basic information should be provided to relevant individuals before they are directed to another channel for detailed information. This basic information should include elements such as the identity of the data controller and the purpose of data processing.

For example, in an area where camera recording is taking place in the workplace, simply stating "camera recording is taking place" may not be sufficient. The sign should include the identity of the data controller, the purpose of the recording, how to access the detailed text, and a brief explanation of fundamental rights; the detailed information text should be accessible via a QR code or an easily accessible link.

When should the Privacy Policy be submitted?

The information notice should be provided at the time of data collection. Providing the notice after the data subject has provided their data, after the process is completed, or after a complaint has been filed does not always remedy past deficiencies. Therefore, the information process should be integrated into the data collection process.

For example, on a website's contact form, individuals should be able to access the privacy policy before entering their name, phone number, and email address. Job applicants should be able to view the privacy policy before submitting their resume. Customers placing orders should be informed that their data will be processed for delivery, billing, and customer service purposes. In areas with camera surveillance, individuals should be able to see an informative sign before entering the recording area.

If the data is not obtained directly from the data subject, the Communiqué also stipulates specific timing rules. Accordingly, if personal data is not obtained directly from the data subject, notification must be provided within a reasonable time; if it is to be used for communication, notification must be given during the first communication; and if it is to be transferred, notification must be given at the latest at the time of the first transfer.

Proof of Obligation to Provide Information

The burden of proof that the obligation to inform has been fulfilled rests with the data controller. Therefore, companies need not only prepare the text but also establish systems that can prove that the information was provided to the data subject. The communiqué explicitly stipulates that the burden of proof for fulfilling the obligation to inform rests with the data controller.

In terms of proof, timestamped records on online forms, access logs to the information text on the membership screen, digital application records in job applications, signed information forms in employee processes, information signs at visitor entrances, and visible warnings in camera systems are important. However, it is important to note that this information should not be transformed into a "consent" mechanism. Information is not consent; the individual is merely informed.

What should a proper privacy notice look like?

A proper privacy policy is simple, concrete, and activity-based. The text should be tailored to the target audience, not cluttered with unnecessary legal quotes, and reflect the company's actual practices. Customer privacy policy and employee privacy policy should not be the same. Cookie and camera privacy policies should be regulated separately.

The text should clearly state "personal data processed," "purposes of processing," "legal grounds," "methods of collection," "persons or organizations to whom data may be transferred," "rights of the data subject," and "method of application." The text should be titled if possible, consist of readable sections rather than long paragraphs, and legal terminology should be simplified.

For example, the following logic could be applied to the customer information text: Your identity and contact information is collected through the website, call center, or store channels for the purpose of processing the order and ensuring product delivery; based on the legal grounds of establishing or performing a contract. Your billing information is processed for the purpose of fulfilling accounting and tax obligations; based on legal obligations. Your delivery information may be shared with the shipping company.

This type of explanation is both understandable to the individual concerned and reveals the legal basis on which the company justifies its data processing activities.

Consequences of Incomplete or Incorrect Privacy Policy

Failure to fulfill the obligation to inform at all, fulfilling it incompletely, or fulfilling it in a misleading manner gives rise to the risk of administrative sanctions under the Personal Data Protection Law (KVKK). The Authority clarifies common errors in information texts through public announcements and emphasizes that this obligation is fundamental to the lawfulness of personal data processing.

Insufficient information can also affect the validity of explicit consent. A person is not considered to have given explicit consent without knowing what they are consenting to. Therefore, in a situation requiring explicit consent, proper information should be provided first, and then explicit consent should be obtained in a separate text and a separate statement.

Inadequate information can pose risks not only in terms of complaints to the Board, but also in terms of compensation and contractual liability. For example, an employer who fails to adequately inform their employees about camera recordings may face controversy if they use these recordings as evidence in disciplinary or termination proceedings. Similarly, a company that fails to provide its customers with clear and accurate information about data processing for marketing purposes may face complaints under both the Personal Data Protection Law (KVKK) and commercial electronic communication regulations.

Applicable Checklist for Companies

Before preparing a GDPR disclosure statement, a company must answer these fundamental questions: What personal data do we collect? To whom does this data belong? For what purpose do we process the data? What is our legal basis for each purpose? By what method do we collect the data? To whom do we transfer the data? What is the purpose of the transfer? How long is the data stored? How can data subjects exercise their rights? If these questions cannot be clearly answered, the disclosure statement will be incomplete.

The company should also regularly review its existing privacy policies. These policies must be updated whenever new software is used, a new service provider is contracted, data is transferred abroad, new marketing channels are created, a camera system is installed, an employee tracking system is implemented, or the cookie infrastructure changes.

The privacy policy should be prepared based on the company's field of activity and practices. A healthcare organization, e-commerce company, law firm, logistics company, educational institution, human resources company, software company, and manufacturing facility cannot use the same policy. Each sector processes different data categories and faces different risks.

Conclusion

The Personal Data Protection Law (KVKK) disclosure statement is a crucial document that ensures transparency in companies' personal data processing activities and forms the basis of legal compliance. However, this statement is not merely a general "KVKK text" posted on a website. A proper disclosure statement should clearly, simply, and concretely indicate the identity of the data controller, the purposes of data processing, the recipient groups to whom the data is transferred, the data collection method, the legal basis, and the rights of the data subject.

The most common mistakes companies make include using texts copied from other companies, confusing the disclosure statement with the explicit consent statement, presenting the processing purpose and the legal basis as the same thing, using the privacy policy instead of the disclosure statement, making the text inaccessible, and failing to keep the text up-to-date. These mistakes can lead to consequences such as administrative sanctions under the Personal Data Protection Law (KVKK), complaints to the Board, claims for compensation, and damage to reputation.

In conclusion, when preparing a GDPR disclosure statement, the company's actual data processing activities should be analyzed, a separate assessment should be made for each data subject group, areas requiring explicit consent should be determined separately, and the texts should be prepared in accordance with the Board's current approach. A legally prepared disclosure statement not only fulfills the legal obligation but also demonstrates that the company has adopted a transparent data management approach that inspires confidence in its customers, employees, and business partners.

Leave a Reply

Call Now Button