KVKK and Cookie Compliance: Website Obligations

Every business with a website processes its visitors' personal data in some way: contact form, cookies, server logs. From the moment this data is processed it falls under Law No. 6698, and the obligation does not change with the size of the site.
Do I have to get cookie consent on my site?
No consent is needed for necessary cookies; session and security cookies essential for the site to work are in this group. But for analytics, marketing and third-party tracking cookies you need prior explicit consent. The critical detail here is the order: these cookies must not load before consent is given. Running the analytics code as soon as the page opens and showing a banner at the bottom does not count as compliance.
A privacy notice and explicit consent are not the same thing
This is the most commonly confused topic.
A privacy notice is information: you explain which data you process, for what purpose, on which legal basis, and the person's rights. It doesn't require approval, but it must be presented before the data is collected.
Explicit consent is permission: relating to a specific matter, based on information and given freely. A pre-ticked box, a phrase like "by continuing you are deemed to have accepted", or making the service conditional on consent does not count as explicit consent.
In practice make this distinction: the data needed to fulfil the request in a contact form rests on a contractual basis; you don't need to ask for consent separately. If you want to send marketing emails after the same form, you must obtain that consent with a separate checkbox.
What the cookie banner must contain
- The reject option must be as easily accessible as accept. A banner with only an "Accept" button does not produce valid consent.
- A choice by category must be offered: necessary, analytics, marketing.
- Consent given must be revocable, and this route must be permanently available on the site.
- When and with which choices consent was given must be recorded; the burden of proof is on you.
The four most common mistakes
- Copying the texts. Copying another site's privacy policy provides no protection because it doesn't match the data you actually process; on the contrary, it makes your statement false.
- Not updating the privacy notice. When you add a new analytics tool or CRM, the parties you transfer to change; the text must change too.
- Vague data retention periods. "As long as necessary" is not a period. A concrete period for each data type and what happens at the end of it must be written.
- Form data scattered around. If messages from the contact form sit in email, in the panel and in the team chat at the same time, nobody knows who has access to which data.
A small checklist
Does your site have: a privacy policy, a KVKK privacy notice, a cookie policy, terms of use. Is there a link to the relevant text next to the forms? Does the cookie banner stop tracking code before consent? Are consent records kept?
Starting advertising or email marketing before these four are complete is the gap that costs the most in a future audit. Preparing the texts is a few days' work; correcting retroactively is not possible.
The matter of transfers abroad
If the servers of the analytics, form, email or hosting service you use are abroad, personal data is being transferred abroad. This alone is not prohibited, but the safeguards the law requires must be in place or explicit consent obtained.
In practice the job is to list the third-party services you use: form provider, analytics, chat tool, email sending service, cloud storage. This list must both appear in the privacy notice and match exactly what you actually use.
If a data subject request comes in
When a visitor writes "delete my data" or "which of my data do you process", you have a legal time limit; leaving it unanswered is not an option. Three things are enough to be prepared:
- Define a single address where requests will arrive and write it in the texts.
- Keep a simple list showing which personal data sits in which system. Searching where to look when a request arrives wastes time.
- Record the response given and the action taken.
The parties you work with under contract
The agency maintaining the site, the server provider and the email service process data on your behalf. This relationship must have a written basis: who has access to what, where the data is kept, what happens when the relationship ends. This is the point where most problems arise in an agency change; the old agency still being able to access the panel is a common and easily preventable gap.
Three checks you can do today
If the texts are in place and current, what remains is this: is tracking code running before consent, is rejecting as easy as accepting, are consent records kept. If these three are in order, you have no serious gap on the compliance side.
A practical setup for the contact form
The place that collects the most personal data is the contact form, and it is also where compliance breaks most easily. A healthy setup is built like this:
- Ask only for the fields you need. If name, email and message are enough for a quote, don't ask for date of birth or address. Data you don't collect is data you don't have to protect.
- Put the link to the privacy notice next to the form. Right under the send button, clickable.
- Get marketing consent with a separate checkbox and don't pre-tick it.
- Gather incoming messages in one place. The same message sitting separately in email, the panel and the team chat makes finding them all impossible when a deletion request arrives.
- Clean up old records. If keeping a quote request from three years ago has no business value, delete it when the retention period ends.
Compliance is not a one-off job
Preparing and publishing the texts starts the process; it doesn't finish it. When you add a new tool, open a new form or change a supplier you work with, the data processed and the parties transferred to change; the texts must change too. Reviewing once a year is a sufficient rhythm for most businesses.
A realistic risk picture
The cost of non-compliance works differently from what most businesses assume. Board audits usually start with a complaint: a visitor asks for their data to be deleted, gets no answer and files an application. From that point the investigation spreads to the whole site.
So the highest-risk gap is not a technical detail but not responding to a request. A site with missing texts usually gets off with a warning when it handles the incoming request properly; a site that leaves the request unanswered makes the process heavier even if its texts are complete.
Administrative fines vary with the size of the business, but the real cost is usually on the reputation side: the sales process of a business known to have failed to protect customer data is directly affected.
Additional obligations for e-commerce sites
A site that sells must also have identifying information, a distance-selling contract, a pre-information form, delivery and return terms. These rest on legislation separate from KVKK but are managed on the same page infrastructure.
Card details collected at the payment stage must never touch your server; redirecting to the payment institution's page or using their component is the standard method. Keeping card data in your own database, even if technically possible, is a responsibility that should not be taken on.
What to do when changing agency
When you start working with a new agency or leave one, three things must be done: the old team's panel and server access closed, shared passwords changed, the list of parties with access to data updated.
When these steps are skipped the picture is this: a panel where a team that left months ago can still read customer messages. From both a compliance and a security point of view, this is the door that is easiest to close and most often left open.
If you want to run the process at a corporate level, KVKK process management is among our services.