Is a Cookie Banner Mandatory in Turkey? The 2026 KVKK Checklist for Websites
Yes for almost every business site: under KVKK, analytics, advertising and social media cookies need explicit consent before they are set. But the banner is one of seven things a compliant website must get right. Privacy notice versus explicit consent, contact form data, VERBİS thresholds after the October 2025 change, cross-border transfers to hosting and analytics providers, İYS for commercial messages, and the 2026 fine amounts, each with its published source and date.
Yes, for almost every business website. Under Turkish data protection rules any cookie that is not strictly necessary for the service the visitor asked for needs explicit consent before it is set, and analytics, advertising and social media pixels sit on the consent side of that line. But the cookie banner is only one of seven things a KVKK-compliant website has to get right: cookie consent, the privacy notice (aydınlatma metni), explicit consent kept separate from that notice, contact form data, VERBİS registration where it applies, cross-border transfers to hosting and analytics providers, and İYS for commercial messages. This guide takes each one with the published rule and its date, as of October 2026. It is a summary of published sources, not legal advice; confirm your specific obligations with a lawyer.
The legal frame is Law No. 6698 on the Protection of Personal Data, known as KVKK, in force since 2016. Article 5 allows processing with explicit consent or under one of the other listed grounds: it is expressly provided for by law, it is necessary to establish or perform a contract with the person, it is needed to fulfil a legal obligation, the person made the data public, it is required to establish or defend a right, or it is necessary for the controller's legitimate interests without harming the person's fundamental rights. The practical lesson for a website is that explicit consent is not the default answer. A quote request runs on the contract ground, order and invoice data run on contract and legal obligation, and consent is the right ground mainly for marketing and for non-essential cookies. Asking for consent you do not need sets a trap: if the person withdraws it, you have told them the processing depended on their choice.
The cookie rules come from the KVKK Authority's Cookie Practices Guide (Çerez Uygulamaları Hakkında Rehber), first published in June 2022 and updated in July 2025. Strictly necessary cookies, such as session, authentication, security and load balancing cookies or the one that remembers a shopping cart, can run without consent because the visitor asked for that service. The guide allows first-party analytics used only to measure your own site to fall inside that exemption in some cases, but published legal commentary on the updated guide reads third-party analytics such as Google Analytics, and every advertising, remarketing and social media cookie, as requiring explicit consent before placement. Entering a site is not consent. Consent must come from an active choice made per purpose, pre-ticked boxes do not count, and a cookie wall that blocks the content until the visitor accepts everything undermines the free will that makes consent valid.
Translated into banner design, that means four rules. Offer 'Accept all', 'Reject all' and 'Manage preferences' with equal visual weight; published commentary on the 2025 update reads the guide as requiring that parity, and a reject option buried on a second screen is the nudge regulators look for. Leave every consent-based category switched off by default. Keep a permanent cookie settings link in the footer so withdrawing consent is as easy as giving it. Record each decision with a timestamp, the banner version and the categories chosen, because proving consent is the controller's job. The failure that matters most is technical rather than textual: a banner with perfect wording while the analytics tag and ad pixels already fired on page load. Test it in a private browser window with the network tab open. Nothing non-essential should load before the visitor chooses.
If you run Google tags, Consent Mode v2 is the switch that connects the banner to the tags. It carries four signals (ad_storage, analytics_storage, ad_user_data and ad_personalization) that should start as denied and change only after the visitor decides. Google offers two implementations. In the basic one, Google tags do not load at all until consent is granted. In the advanced one, tags load and send cookieless pings while consent is denied, and those pings are still a data flow to a provider abroad. Google built Consent Mode around its European Economic Area and UK consent requirements, and nothing in Turkish law names it, but for a site serving Turkish users the basic implementation is the cleanest way to make the banner's promise literally true.
The privacy notice and explicit consent are two different legal acts, and mixing them is one of the most common mistakes on Turkish sites. Article 10 of Law No. 6698 obliges you to inform people at the moment you collect their data: who the controller is (and its representative, if any), why the data is processed, to whom and why it may be transferred, how it is collected and on what legal ground, and what rights the person has under Article 11. That duty applies to every processing activity, whatever the legal ground. Explicit consent is something else: a specific, informed and freely given statement that is only needed when no other ground fits. The Communiqué on the duty to inform, published in the Official Gazette on 10 March 2018, requires that where processing relies on explicit consent, informing and obtaining consent are carried out separately. On a website that means a link to the notice next to every form, and a separate, unticked checkbox only for the purposes that actually need consent.
Contact forms are where most small sites collect the most personal data, and they are easy to get right. Collect only what you need to answer: name, a contact channel and the message. A national ID number or date of birth on a general enquiry form is hard to justify. State a retention period in the notice and enforce it with a scheduled deletion or anonymisation job, because a period written in a document and never executed in the database is not a retention policy. Know where the submission travels: if the form e-mails a provider abroad or writes into a foreign CRM, that is a cross-border transfer. And publish a request channel. Under Article 13 a controller must answer data subject requests free of charge and within 30 days at the latest, with a fee allowed only where the request creates an extra cost under the Board's tariff.
Cross-border transfers changed on 1 June 2024, when Law No. 7499 rewrote Article 9. Transfers abroad now rest on three tiers. First, an adequacy decision for the destination country; according to published legal commentary, the Board had not issued one for any country as of mid-2026. Second, appropriate safeguards: the Board's standard contracts, binding corporate rules, a written undertaking approved by the Board, or agreements between public bodies. Third, occasional transfers, including explicit consent, which the Authority's transfer guide limits to one-off or few transfers that are not continuous and not part of the normal course of business. Hosting, transactional e-mail and analytics are continuous by nature, so explicit consent is not the fix for them. The usual route is the Board's standard contract with the provider, used without changes to its core text and notified to the Authority within 5 business days of signing, which the Authority accepts online through its standard contract notification module. The implementing regulation was published on 10 July 2024.
VERBİS, the data controllers' registry, applies to fewer small businesses than people assume, but the rules moved recently. You are exempt if both of these are true: you employ fewer than 50 people annually and your annual balance sheet total is under 100 million TL, provided your main activity is not processing special category data. Board decision 2025/1572, dated 4 September 2025 and published in the Official Gazette on 1 October 2025, set a tighter test for businesses whose main activity is special category data, such as clinics: they are exempt only with fewer than 10 employees and a balance sheet under 10 million TL. For businesses that do not keep balance-sheet accounts, the Authority's follow-up guidance applies the employee count alone. Controllers based outside Turkey that process data of people in Turkey generally register through a Turkish data controller representative, and published commentary reads the size thresholds as not applying to them. A VERBİS exemption is not a KVKK exemption: notices, security and cookie rules still apply.
Commercial messages run under a second law. Law No. 6563 on e-commerce and its regulation on commercial communication require the recipient's prior approval before you send commercial SMS, e-mail or calls, and senders register with İYS, the Message Management System. Approvals you collect, including newsletter sign-ups on your website, must be uploaded to İYS within 3 business days or they cannot be relied on, and recipients can opt out through İYS at any time. Merchants and tradespeople can be messaged without prior approval, but their addresses still have to be in İYS and checked for an opt-out before sending. Behind every message sits a KVKK question too, since the contact data is personal data. Many sites capture both with one clearly worded, unticked checkbox that links to the notice and writes to İYS through its API; ask your lawyer whether your wording covers both regimes.
Fines are revalued every January by the tax revaluation rate, which was set at 25.49% for 2026 in the general communiqué published on 27 November 2025. The 2026 ranges are: 85,437 to 1,709,200 TL for breaching the duty to inform; 256,357 to 17,092,242 TL for data security failures; 341,809 to 17,092,242 TL for VERBİS registration and notification failures; 427,263 to 17,092,242 TL for not complying with Board decisions; and 90,308 to 1,806,177 TL for failing to notify a standard contract. Separately, under Board decision 2019/10 a data breach must be reported to the Board within 72 hours of the controller learning of it. A website is a common breach surface: an exposed form endpoint, a leaked database backup, or an admin panel without rate limiting.
Here is the checklist we work through on a typical SME site. One: inventory every cookie, tag and pixel and sort it into strictly necessary or consent-based. Two: a banner with equal accept, reject and manage options, categories off by default, scripts blocked until consent, Consent Mode wired if you use Google tags, and consent logs stored. Three: a privacy notice linked at every form, with a separate unticked checkbox only where consent is the real ground. Four: minimal form fields, a stated retention period and a job that enforces it. Five: a data subject request channel answered within 30 days. Six: a list of every provider abroad and the transfer mechanism for each. Seven: a VERBİS threshold check, and İYS integration for any marketing sign-up. Legal texts come from your lawyer. TheCodeVolt's quality and security team builds KVKK and GDPR requirements into the site from the first sprint, so the site behaves exactly the way those texts say it does.
- 01A cookie consent mechanism is effectively mandatory for Turkish-facing sites with analytics, advertising or social media cookies. The KVKK Cookie Practices Guide (June 2022, updated July 2025) exempts only strictly necessary cookies and requires an active, per-purpose choice before anything else is set.
- 02Pre-ticked boxes, consent by simply browsing and cookie walls do not produce valid consent. Published commentary on the 2025 update reads the guide as requiring equally prominent accept, reject and manage options.
- 03The most damaging failure is technical: tags and pixels firing on page load behind a correctly worded banner. With Google tags, the basic Consent Mode v2 implementation keeps tags from loading until consent.
- 04The privacy notice (Article 10) applies to every processing activity; explicit consent is a separate ground only for purposes no other ground covers, and the 10 March 2018 Communiqué requires the two to be obtained separately.
- 05Since 1 June 2024, continuous transfers to hosting, e-mail and analytics providers abroad usually need the Board's standard contract, notified within 5 business days of signing. Explicit consent covers only occasional, non-continuous transfers.
- 06VERBİS exemption requires fewer than 50 employees and a balance sheet under 100 million TL; since decision 2025/1572 (Official Gazette 1 October 2025), businesses whose main activity is special category data are exempt only under 10 employees and 10 million TL.
- 072026 fines range from 85,437 TL (duty to inform) to 17,092,242 TL (security, VERBİS, Board decisions). Commercial SMS and e-mail need prior approval recorded in İYS within 3 business days.
Is a cookie consent banner mandatory in Turkey?
Effectively yes, for any site that uses cookies beyond the strictly necessary ones. The KVKK Authority's Cookie Practices Guide, published in June 2022 and updated in July 2025, lets session, authentication, security and load balancing cookies run without consent, but analytics from third parties such as Google Analytics and all advertising, remarketing and social media cookies need explicit consent before they are set. Consent must come from an active choice per purpose; browsing the site, pre-ticked boxes and cookie walls do not count. A site with only strictly necessary cookies does not need a consent banner, though it still needs a cookie notice. This is a summary of published sources, not legal advice.
What is the difference between a privacy notice (aydınlatma metni) and explicit consent (açık rıza) under KVKK?
The privacy notice is a duty under Article 10 of Law No. 6698 that applies to every processing activity: you tell people who the controller is, why the data is processed, to whom it may be transferred, how and on what legal ground it is collected, and what their rights are. Explicit consent is one of the legal grounds in Article 5, needed only when no other ground such as a contract or legal obligation applies, and it must be specific, informed and freely given. The Communiqué on the duty to inform (Official Gazette, 10 March 2018) requires the two to be handled separately, so on a website the notice is a link and consent is a separate, unticked checkbox.
Who has to register with VERBİS in 2026?
A data controller is exempt from VERBİS only if it employs fewer than 50 people annually and its annual balance sheet total is under 100 million TL, and its main activity is not processing special category data. Board decision 2025/1572, dated 4 September 2025 and published in the Official Gazette on 1 October 2025, exempts businesses whose main activity is special category data, such as health clinics, only if they have fewer than 10 employees and a balance sheet under 10 million TL. Businesses without balance-sheet accounting are assessed on employee count alone. Foreign controllers processing data of people in Turkey generally register through a Turkish representative. Confirm your position with a lawyer.
Can I use Google Analytics on a website for Turkish users under KVKK?
Yes, with two conditions. First, consent: published commentary on the KVKK Cookie Practices Guide reads third-party analytics such as Google Analytics as requiring explicit consent before its cookies are set, so the tag must stay blocked until the visitor opts in; the basic Consent Mode v2 implementation does this. Second, transfer: Google processes the data abroad, and since 1 June 2024 continuous transfers like analytics generally need an appropriate safeguard such as the Board's standard contract, notified to the Authority within 5 business days of signing, because explicit consent only covers occasional transfers. Check which contract terms your Google account offers with your lawyer.
How much are KVKK fines in 2026?
KVKK fines are revalued every year; for 2026 the revaluation rate is 25.49%, set by the general communiqué published in the Official Gazette on 27 November 2025. The 2026 ranges are 85,437 to 1,709,200 TL for breaching the duty to inform, 256,357 to 17,092,242 TL for data security failures, 341,809 to 17,092,242 TL for VERBİS registration and notification failures, 427,263 to 17,092,242 TL for not complying with Board decisions, and 90,308 to 1,806,177 TL for failing to notify a standard contract for cross-border transfers.
Do I need İYS to send newsletters or SMS campaigns from my website?
Yes. Under Law No. 6563 on e-commerce and its regulation on commercial communication, commercial e-mail, SMS and calls need the recipient's prior approval, senders must register with İYS (the Message Management System), and approvals collected on your website must be uploaded to İYS within 3 business days or they cannot be relied on. Recipients can opt out through İYS at any time. Merchants and tradespeople can be messaged without prior approval, but their addresses must still be in İYS and checked for an opt-out before sending. The contact data behind each message is also personal data under KVKK.
Let's apply this to your project.
A free 15-minute call. A technical assessment, not a sales pitch.
Get in touch