Website Obligations Under the Personal Data Protection Law (KVKK)
Entrance
Websites are today the most important digital assets for companies, e-commerce businesses, law firms, healthcare organizations, educational institutions, associations, platforms, and individual ventures. A website is not only a promotional tool; it is also a digital touchpoint where various personal data is collected from visitors, customers, members, subscribers, applicants, and users.
The presence of a contact form on a website, newsletter subscriptions, user account creation, order placement, payment processing, use of cookies, operation of advertising and analytics tools, provision of live support services, or tracking user behavior may constitute personal data processing activities. Therefore, website owners must be aware of and fulfill their obligations under the Law No. 6698 on the Protection of Personal Data
The primary purpose of the Personal Data Protection Law (KVKK) is to protect the fundamental rights and freedoms of individuals, primarily the right to privacy, in the processing of personal data, and to regulate the obligations of natural or legal persons who process personal data. The law applies to natural and legal persons who process personal data through automated means or through non-automated means as part of a data recording system. Therefore, companies, e-commerce businesses, professional service providers, and platform owners that collect data through websites are, in most cases, legally liable as data controllers or data processors under the KVKK.
What Personal Data is Processed on Websites?
According to the Turkish Personal Data Protection Law (KVKK), personal data is any information relating to an identified or identifiable natural person. Personal data processed on websites is not limited to name, surname, telephone number, and email address. IP address, device information, user activity, cookie records, location data, order history, payment information, message content, application form information, username, password, customer number, comments, product preferences, and live support records can also be considered personal data.
For example, a law firm's website's "contact us" form collecting name, surname, phone number, email address, and subject description constitutes personal data processing. An e-commerce site collecting address, order, invoice, and payment information from a customer is also a personal data processing activity. A health clinic's website accepting appointment requests may create a risk of processing health data or special categories of personal data related to health. A website's tracking of visitor behavior with advertising, analytics, or targeting cookies should also be evaluated within the scope of the Personal Data Protection Law (KVKK).
Therefore, the idea that it's "just a promotional site" is often wrong. If the website includes any forms, cookies, analytics tools, newsletter subscriptions, live support, membership systems, or third-party tracking tools, its compliance with the GDPR (General Data Protection Regulation) must be evaluated.
Is the website owner the data controller?
According to the Turkish Personal Data Protection Law (KVKK), the data controller is the person who determines the purposes and means of processing personal data. If the website owner decides which data will be collected, for what purpose, where the data will be stored, with whom it will be shared, and for how long, the website owner is considered the data controller in most cases.
For example, a company is a data controller if it has created a contact form on its website and transfers the applications received through this form to its own customer management system. An e-commerce site is a data controller if it manages membership and order processes. A clinic is a data controller if it collects information from prospective patients through an appointment form.
Conversely, a hosting company, software developer, agency, CRM service provider, email marketing platform, payment infrastructure provider, or live support software company may be considered a data processor, depending on the specific circumstances. However, this distinction is made based on the actual situation, not on the title stated in the contract. Whoever determines the purpose of data processing and whoever has the authority to make decisions regarding the data is considered the data controller.
Obligation to Prepare a Privacy Policy
One of the most fundamental obligations under the Personal Data Protection Law (KVKK) for websites is the obligation to inform. The obligation to inform means that the person whose personal data is being processed must be notified of who is processing their data, for what purpose, on what legal basis, to whom their data may be transferred, and what their rights are.
As emphasized in the Personal Data Protection Authority's announcement dated 2026, the obligation to inform is not dependent on the request or consent of the data subject. The data controller must fulfill the obligation to inform whether or not explicit consent is obtained when processing personal data. Furthermore, clear, simple, and understandable language should be used in the information texts; vague, incomplete, misleading, or general statements should be avoided.
Therefore, simply placing a long and general text under the heading "Privacy Policy" on a website is not always sufficient. The information text should be appropriate to the processing activity. Separate or layered information may be required for contact forms, membership systems, cookie usage, e-newsletter and commercial electronic communication processes.
For example, a brief informational text can be provided at the bottom of the contact form, linking to a detailed privacy policy. However, when making this connection, the individual should be able to understand from the outset who the data controller is and for what purpose their data is being processed. Simply placing a small, printed link to a "KVKK (Personal Data Protection Law) text" at the bottom of the page may not be considered a sufficient or effective method of providing information in practice.
What information should be included in the Privacy Notice?
A website's privacy policy should fundamentally include the following elements: the identity of the data controller, the categories of personal data processed, the purposes for which personal data is processed, the legal grounds on which personal data is processed, to whom and for what purposes data may be transferred, the data collection method, and the data subject's rights under the Personal Data Protection Law (KVKK).
It is particularly important not to confuse "processing purpose" with "legal basis" here. For example, "your personal data is processed for the purpose of receiving applications" is a processing purpose. In contrast, "legitimate interest under Article 5/2-f of the KVKK" or "establishment or performance of a contract under Article 5/2-c of the KVKK" may be a legal basis. The Authority's statement dated 2026 also clarifies that processing purpose and legal basis are separate elements in the information texts, and that the term "legal basis" should be understood to indicate which of the processing conditions specified in Articles 5 and 6 of the Law is being relied upon.
Therefore, general statements such as "your personal data is processed in accordance with the KVKK (Personal Data Protection Law)" or "your personal data is processed for legal reasons" are insufficient. The website must clearly indicate which data category it processes and for what reason.
The Explicit Consent and Information Text Should Be Separate
One of the most common mistakes on websites is confusing the explicit consent statement with the information disclosure statement within the same document. Information disclosure is the obligation of the data controller to provide information. Explicit consent, on the other hand, is the free will of the data subject to consent for specific data processing activities. These two concepts are different.
In its announcement regarding the Principle Decision No. 2026/347 dated February 18, 2026, the Personal Data Protection Board specifically emphasized that data controllers must prepare separate consent and information texts. The same announcement stated that these texts should use clear, understandable, and simple language, avoid ambiguous expressions, and clearly state the data being processed, the purpose of processing, and the legal basis.
Therefore, single-checkbox applications on website forms that state "I have read the KVKK (Personal Data Protection Law) text and I give my explicit consent" are risky. The individual should first be informed; if explicit consent is required, it should be given for a specific and clear matter. The explicit consent box should not be pre-checked; the user should give their consent through active behavior.
Obligation to Prepare a Cookie Policy
One of the most important obligations of websites under the Turkish Personal Data Protection Law (KVKK) is cookie management. Cookies can be used for purposes such as session management, security, language preference, shopping cart information, performance measurement, user behavior analysis, advertising targeting, and remarketing.
If personal data is processed through cookies, users must be informed about this. The cookie policy should clearly state the name of the cookie, its purpose, provider, duration, whether it is a first-party or third-party cookie, and the legal basis for its use. The Personal Data Protection Board's decisions regarding cookies also emphasize that cookie tables must be consistent, understandable, and comply with the obligation to inform users.
For mandatory cookies, explicit consent may not always be required. For example, cookies necessary for the secure operation of the site, the protection of the user's shopping cart, or the continuation of the session may be essential for the provision of the service. However, explicit consent is required for analytics, advertising, marketing, targeting, profiling, or third-party tracking cookies.
How to Obtain Explicit Consent for Cookies?
When obtaining explicit consent for cookies, users should be given a genuine choice. Simply having an "accept" button, stating "by continuing to use the site you accept the cookies," or hiding a reject option on the site is legally risky.
The Personal Data Protection Board's decision summaries state that for non-essential cookies, the "opt-in" method, based on the user's active action, is the primary approach, and offering a balanced selection of "accept," "reject," and "preferences" options could be considered a good practice. Furthermore, obtaining collective explicit consent for cookies other than necessary, without providing users with category-based preferences, may compromise the elements of explicit consent being "related to a specific matter" and "given freely.".
Therefore, a good cookie panel should allow users to see mandatory cookies and manage performance/analytical cookies, advertising/marketing cookies, and functional cookies separately. The opt-out option should be easily accessible, and the user should be able to withdraw their consent later.
Third-Party Tools and Data Transfer Abroad
Websites often utilize third-party services. Examples include analytics tools, ad pixels, social media plugins, map services, live support software, email marketing platforms, payment infrastructure, CDN services, cloud storage systems, and CRM tools.
A significant portion of these tools are provided by companies based abroad. In this case, personal data collected through the website may be transferred abroad. In particular, third-party advertising and analytics cookies may transfer IP addresses, device information, and behavioral data to service providers located abroad.
The KVKK's (Turkish Personal Data Protection Law) regime for data transfer abroad changed significantly in 2024. The amendments to Article 9 of the KVKK, introduced by Law No. 7499, entered into force on June 1, 2024; standard contracts and binding company rules were regulated as appropriate safeguard methods that can be used for the transfer of personal data abroad. The Authority announced that standard contracts must be notified to the Authority within five business days of their signing, and that these notifications can be made through the Standard Contract Notification Module.
Therefore, when website owners say "we use Google Analytics," "we've added Meta Pixel," "we use a foreign live support application," or "data is stored in the cloud," they are not only performing technical integration; they may also be required to conduct data transfer analysis abroad in accordance with Article 9 of the Turkish Personal Data Protection Law (KVKK).
Contact Forms and Application Forms
Contact forms on websites are one of the simplest yet most neglected areas in terms of the Turkish Personal Data Protection Law (KVKK). The information requested in the form should be appropriate. Name, surname, email, phone number, and message fields may not be necessary in all cases. For example, requesting a Turkish national identity number when only an information request is being received might be excessive. In sensitive areas such as law firms or healthcare institutions, individuals may enter sensitive personal information in the message box. In such cases, the data controller needs to design the form more carefully.
A brief informational text should be provided next to or below the contact form, linking to a more detailed informational text. The purpose of the form should be clearly stated. A concrete statement such as, "Your data is processed for the purpose of receiving your request, contacting you, and managing communication processes," should be used. Furthermore, it should be specified who can view the form data, whether it will be transferred to the CRM system, who will receive it via email, and how long it will be stored.
If an option such as "I want to be informed about advertisements and campaigns" is added to the contact form, this should be evaluated separately from commercial electronic communication and explicit consent processes. If the person only wants a response to their application, separate consent should be obtained for receiving marketing messages.
E-Newsletter and Commercial Electronic Communication Obligations
One of the frequently used practices on websites is e-newsletter subscription. Subscribing to a newsletter by entering your email address constitutes personal data processing. Furthermore, if the newsletter's content is advertising, a campaign, a promotion, or a commercial communication, the Law No. 6563 on the Regulation of Electronic Commerce and the legislation concerning commercial electronic communications also come into play.
According to the Ministry of Trade, a Message Management System has been established that allows recipients to obtain consent for commercial electronic messages and exercise their right to refuse; the aim of this system is to enable recipients to view and control their given consents and exercise their right to refuse from a single point.
Therefore, when obtaining e-newsletter, campaign notification, SMS consent, or marketing permission on a website, the Personal Data Protection Law (KVKK) and commercial electronic communication legislation must be considered together. The legal basis for processing personal data under the KVKK is separate from the consent required for sending commercial electronic communications. The user must be given the option to refuse, and the time and channel through which consent was obtained must be recorded in a verifiable manner.
GDPR Obligations of E-Commerce Websites
E-commerce websites are among the internet sites that process the most personal data in terms of the Turkish Personal Data Protection Law (KVKK). Numerous data processing activities occur due to membership, orders, payments, shipping, invoicing, returns, customer service, product reviews, campaign notifications, cookies, and marketplace integrations.
Data collected from users on e-commerce sites should be limited solely to the sales transaction. Information not necessary for the order should not be made mandatory. Payment information should be processed using secure payment infrastructures; unnecessary storage of card information should be avoided. If data is shared with shipping companies, payment institutions, billing/accounting service providers, call centers, marketplaces, and advertising providers, these transfers should be specified in the privacy policy.
The Ministry of Trade's current legislation page states that Law No. 6563 establishes the legal framework for electronic commerce and includes secondary regulations regarding the information disclosure and other obligations of e-commerce service providers and intermediary service providers. Therefore, e-commerce website owners must ensure compliance with the Personal Data Protection Law (KVKK) in conjunction with consumer law, electronic commerce legislation, and commercial electronic communication rules.
Data Security Obligation
Compliance with the Personal Data Protection Law (KVKK) is not just about preparing text. Website owners are obliged to take the necessary technical and administrative measures to prevent the unlawful processing and unlawful access to personal data, and to ensure the preservation of data. The Authority's statements regarding data security indicate that the data controller is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security.
Key technical security measures for websites include the use of SSL certificates, a strong password policy, multi-factor authentication in the admin panel, regular security updates, access authorization, logging, database security, secure backups, malware scanning, firewalls, penetration testing, and monitoring unauthorized access.
Administrative measures include employee confidentiality commitments, data processor agreements, retention and destruction policies, authorization matrices, data inventory, data breach response plans, employee training, and supplier audits. Especially when working with third parties such as web development agencies, hosting companies, advertising agencies, and CRM providers, their data security responsibilities should be clearly defined in the contract.
Notification Obligation in Case of Data Breach
Website hacking, database leaks, user account information being stolen, applications being sent to the wrong people through forms, unauthorized access to the admin panel, or customer data being obtained by third parties can all constitute a data breach.
According to Article 12/5 of the Personal Data Protection Law (KVKK), if personal data processed is obtained by others through unlawful means, the data controller is obliged to notify the data subject and the Board as soon as possible. In its announcement regarding the Personal Data Protection Board's decision dated January 24, 2019, numbered 2019/10, the phrase "as soon as possible" was interpreted as 72 hours; it was stated that the data controller must notify the Board without delay and within a maximum of 72 hours from the date they become aware of the breach.
Therefore, website owners should not simply tell the technical team to "fix the site" when a data breach occurs. They must quickly assess which data is affected, how many people are affected, whether the breach is ongoing, what measures are being taken, whether notification to relevant individuals is necessary, and whether a notification needs to be made to the Board.
Storage and Destruction Obligation
Personal data collected through websites cannot be stored indefinitely. Personal data must be deleted, destroyed, or anonymized when the purpose requiring its processing no longer exists. For example, a simple information request received through a contact form should not be kept in a database for years. Continuing to keep a person on a marketing list after they have unsubscribed from an e-newsletter may also constitute a legal violation.
The institution's statements regarding the deletion, destruction, or anonymization of personal data indicate that for data to be considered anonymized, it must become impossible to link it to an identified or identifiable natural person; and that the data controller is obligated to take the necessary technical and administrative measures in this regard.
Therefore, website owners must determine in advance how long each type of data will be stored. Application forms, membership data, order records, billing information, cookie records, log records, and marketing consents may be subject to different retention periods. These periods should be determined taking into account legislation, statutes of limitations, contractual relationships, and the purpose of data processing.
Managing Data Subject Applications
Under the Personal Data Protection Law (KVKK), individuals have the right to learn whether their data is being processed, to request information if it is being processed, to learn the purpose of the processing, to know the persons to whom it has been transferred, to request correction if it has been processed incompletely or incorrectly, and to request its deletion or destruction if the conditions are met.
Website owners must clearly demonstrate how these applications should be submitted. The information notice should specify the application method; methods such as email, registered electronic mail (KEP), written application, or secure electronic signature should be clearly defined. Incoming applications should be recorded and responded to in a timely manner.
One of the mistakes made in practice is putting a general statement like "Contact us for GDPR applications" on the website but not establishing a process to manage applications internally. However, it should be determined in advance who will receive the applications, how they will be reviewed, which departments will gather information, and how the response will be given.
VERBİS, Inventory and Policy Obligations
Not every website is automatically required to register with VERBİS. However, the VERBİS obligation should be assessed separately, taking into account the data controller's field of activity, number of employees, total financial balance, the special categories of data processed, and relevant exceptions.
The institution's statement regarding the KVKK (Personal Data Protection Law) compliance process indicates that data controllers have obligations such as lawful data processing, registration with VERBİS (Personal Data Protection Information System), preparation of a personal data processing inventory, storage and destruction policy, and taking technical and administrative measures regarding data security.
Therefore, a company that owns a website cannot be considered to have completed its GDPR compliance simply by placing text on its website. The company's overall data processing activities, along with website processes, must be documented; it must be determined which data was collected from where, for what purpose it was processed, to whom it was transferred, whether it was transferred abroad, and for how long it was stored.
Conclusion
Under the Personal Data Protection Law (KVKK), the obligations of websites are not limited to simply adding a "KVKK text" and a "cookie policy" to the site. Every data controller that collects personal data through a website must fulfill its obligation to inform, obtain separate and valid explicit consent where explicit consent is required, manage cookies in accordance with the law, analyze third-party tools and data transfers abroad, design appropriate contact forms, conduct e-newsletter and commercial electronic communication processes in accordance with the legislation, take data security measures, and make the necessary notifications in case of a data breach.
To ensure a website complies with the Turkish Personal Data Protection Law (KVKK), it is first necessary to identify all data processing activities taking place on the site. Contact forms, membership forms, order forms, payment forms, cookies, live support, social media plugins, advertising pixels, analytical tools, e-newsletters, and application forms should be examined separately. For each activity, the data processed, the purpose of processing, the legal basis, the parties involved, the retention period, and security measures must be determined.
There are significant risks in practice, particularly regarding cookies and third-party tools. A genuine preference mechanism should be established for non-essential cookies; users should be given the option to accept, reject, and manage their preferences; and the cookie policy should be up-to-date, consistent, and understandable. If service providers based abroad are used, the conditions for transferring data abroad under Article 9 of the KVKK (Personal Data Protection Law) should be evaluated separately.
In conclusion, website compliance with the Turkish Data Protection Law (KVKK) is a holistic undertaking requiring legal text, technical infrastructure, and administrative processes. Websites lacking properly prepared privacy notices, valid explicit consent mechanisms, a compliant cookie panel, a secure data infrastructure, a principle of proportionate data collection, application management, and a data breach response plan may face administrative sanctions, reputational damage, loss of customer trust, and compensation claims. Therefore, it is crucial for website owners to consider KVKK compliance from the design phase and update their websites regularly.