If your organisation collects personal data from people in Turkey, the form you are using is probably no longer compliant.
On 18 February 2026 the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) issued Principle Decision No. 2026/347, published in the Official Gazette on 24 March 2026. It addresses a practice that had become near-universal in the Turkish market: merging the Article 10 privacy notice and the explicit consent text into a single block of copy with a single tick-box.
That structure is now expressly unlawful.
This article is general information, not legal advice. Turkish counsel should review your remediated texts.
Why the Board intervened
Turkish law treats the two instruments as fundamentally different, and GDPR practitioners will recognise the distinction.
The privacy notice under Article 10 of Law No. 6698 is a unilateral obligation of the controller. It must be provided whether or not consent is the legal basis, and its validity does not depend on the data subject agreeing to anything.
Explicit consent under Article 3(1)(a) is a declaration of the data subject's will. It must be freely given, related to a specific subject, and based on information. Crucially, it must be capable of being withheld.
When both are compressed into one tick-box, each loses its character: the notice becomes something to be "accepted", and consent becomes a gate you must pass to use the service. The Board's decision restores the separation.
What the decision prohibits
The Board's public announcement lists the practices it found unlawful:
- Presenting the consent text and the privacy notice intertwined as a single text
- Requesting approval or consent for the fact that the privacy notice was given — the familiar "I have read and accept the privacy notice" formulation
- Using verbatim copies of another controller's texts
- Failing to use "clear, plain and simple language"; vague, incomplete or misleading wording
- Excessively long, detailed and complex texts
The last point is worth dwelling on. Length is treated as a compliance criterion, not a style preference. A notice nobody can read does not discharge the duty to inform.
What the decision requires
| # | Requirement |
|---|---|
| 1 | The privacy notice is given before processing begins, regardless of whether consent is the basis |
| 2 | Where consent is the basis, the two texts are drafted separately, under different headings |
| 3 | If shown on the same page, they appear stacked, with two separate declarations |
| 4 | Where another legal basis applies, no consent text is presented at all |
| 5 | From the data subject, only an acknowledgement that the notice was read and understood is collected |
| 6 | Texts are not copied; each controller drafts for its own organisation and activities |
| 7 | Clear wording; rights may be summarised as "your rights under Article 11 of the Law" rather than reproduced at length |
Requirement 4 is the one most often missed by international teams. Payroll reporting, invoicing and social security filings rest on a legal obligation, not consent. Asking for consent there is not merely redundant — the Board treats it as a bad practice, and it undermines the consent you do rely on, because a data subject who cannot meaningfully refuse is not consenting freely.
Before and after
Non-compliant — one text, one declaration:
Your personal data is processed for the purposes of ... Do you accept the processing of your personal data?
[ ]I have read and accept the privacy notice.
Compliant — two texts, two declarations:
1. Privacy Notice Identity of the controller, purposes, legal bases, transfers, rights...
[ ]I have read and understood the privacy notice.
2. Explicit Consent For the purpose of sending commercial electronic messages, I consent to the processing of my name and contact details:
[ ]I consent[ ]I do not consent
Three things to note in the second block: the scope is limited to the purpose that genuinely needs consent, the data listed is the minimum that purpose requires, and the negative option is visible.
Scope of the remediation
The decision is not limited to website forms. In practice the following all need review for Turkish-facing operations:
- Website sign-up, account and contact forms
- E-commerce checkout and membership terms
- Job application and candidate forms
- Paper forms used at branches or reception
- Call centre disclosure and consent scripts
- Mobile app onboarding screens
- Visitor logs and CCTV signage
Paper forms are the most frequently overlooked. "Stacked with two separate declarations" usually means the form has to be redesigned, not edited.
How this compares with GDPR practice
If your organisation is already GDPR-compliant, much of this will feel familiar — GDPR's transparency obligation under Articles 13–14 is likewise independent of consent, and EDPB guidance has long criticised bundled consent.
The difference is that Turkey has now made the document architecture itself an enforceable requirement, and named specific presentation defects. A GDPR-shaped notice that bundles acknowledgement and consent into one action may satisfy your European reviewers and still fail in Turkey.
Two further Turkey-specific points, covered in more depth in our KVKK vs GDPR comparison: Turkish law requires consent more often than GDPR does, and the VERBIS registry is a separate obligation with its own thresholds — see VERBIS registration for foreign companies.
Enforcement
The Board's announcement states that where non-compliance is established, action will be taken under Article 18 of Law No. 6698, which provides for administrative fines.
The practical exposure is that the privacy notice is the first document a Board reviewer asks for in a complaint or ex officio investigation. An intertwined single text is visible in the first minute of that review.
Remediation checklist
- Inventory every Turkish-facing collection point, including paper and telephone
- For each, identify the actual legal basis of each processing purpose
- Remove consent requests wherever another legal basis applies
- Split the remaining forms into two headed texts with two declarations
- Replace "I have read and accept" with "I have read and understood"
- Narrow consent scope to the data the consent-based purpose actually needs
- Rewrite anything copied from another controller so it describes your operations
- Have Turkish counsel review before deployment
Steps 3 and 6 are the two that most often reduce risk rather than add work: in most remediations the consent text gets substantially shorter.
Sources
- Public announcement on Principle Decision No. 2026/347 of 18.02.2026 — Turkish Personal Data Protection Authority (KVKK)
- Law No. 6698 on the Protection of Personal Data (full text, Turkish)
- Turkish Personal Data Protection Authority
This article is based on the official sources above. Legislation and Board decisions change; rely on the primary sources for the current text.
Generating the Turkish texts: KVKK Otomat produces the privacy notice and the explicit consent text as separate documents, limits consent scope to purposes that genuinely require it, and includes the "I consent / I do not consent" options the decision calls for. Output is a draft; Turkish counsel review is recommended. Starting point: KVKK compliance checklist · Turkish data protection law guide.


