A KVKK-compliant website: a practical guide to privacy notices, cookies and forms
Maybe Digital · 8 min read · Updated:
Short answer
Under KVKK (Turkey's Law No. 6698 on the Protection of Personal Data), a website should inform visitors through a privacy notice, not run non-essential cookies without consent, collect only the data a form really needs, and be able to respond to data subjects' requests. This guide is general information, not legal advice.
First, a note: this isn't legal advice
This guide explains, from a technical and practical angle, what to watch for under KVKK when building and running a website. Every business differs in its activities, the types of data it processes and its obligations, and legislation, Personal Data Protection Board decisions and official guidance change over time.
Always consult a lawyer about your own situation and check current information against the official sources of the Personal Data Protection Authority (KVKK). A web agency's job is to implement the requirements your lawyer sets, correctly and completely, on the site.
Privacy notice and explicit consent
A privacy notice (aydınlatma metni) tells people, at the moment their data is collected, who the data controller is, which data is processed for what purpose and on what legal basis, to whom it may be transferred, and what their rights are. It should be easy to find on the site and linked at every point where data is collected (contact forms, newsletter sign-ups, accounts).
Explicit consent (açık rıza) is a separate matter and isn't needed for everything. If another legal basis listed in the law applies, such as entering into or performing a contract or a legal obligation, consent isn't asked separately. Consent may be needed for things like sending marketing messages or using non-essential cookies. Explicit consent must be specific, informed and freely given. Pre-ticked boxes or consent sentences buried inside the privacy notice don't meet that standard.
Cookie banner and cookie policy
The general approach in the Authority's guidance on cookies is this: cookies strictly necessary for the site to work can be used without consent, while non-essential cookies such as analytics, advertising and personalisation should only run after the visitor consents. That means showing a banner isn't enough; the related scripts must technically not load until consent is given.
- "Accept" and "Reject" are equally visible; rejecting isn't made harder.
- Visitors can choose by category and change their mind later.
- Analytics and advertising tags don't load before consent.
- The cookie policy lists the cookies used, their purposes, durations and whose they are.
- The policy and banner are updated whenever a new tool is added to the site.
Forms: collect only what you need
One of KVKK's core principles is that data must be relevant, limited and proportionate to the purpose for which it is processed. A contact form usually needs only a name, contact details and a message. Don't add fields such as ID number, date of birth or address "just in case"; every extra field is both a risk and an obligation.
On the technical side, form data should be sent over an encrypted connection (HTTPS), without creating more copies than needed on the server and in mailboxes, and the form should be protected against spam and abuse. Rules are stricter for special categories of personal data such as health or biometric data; if you need that kind of data, design the process with your lawyer.
Retention and deletion requests
Personal data should be kept only as long as needed for its purpose and as long as the relevant legislation requires, then deleted, destroyed or anonymised. In practice that means deciding upfront how long form entries, newsletter lists and server logs are kept, and putting a routine in place to enforce it.
People have rights such as learning what data is processed about them and asking for it to be corrected or deleted. State clearly on the site how to submit such requests, and set up a process to find and act on the data across every system (form database, e-mail, CRM, newsletter tool) when one arrives. The law sets a response period for these requests; confirm the current period and procedure with your lawyer.
Services abroad and VERBİS
A website usually relies on services running abroad: hosting and CDN, analytics, e-mail services, form and newsletter tools, AI services. Sending personal data to them can fall under the KVKK rules on cross-border transfers, which are regulated separately. A transfer must meet one of the conditions set out in the law, and these rules have been updated in recent years. Listing which service processes data in which country is a good starting point for your lawyer's assessment.
VERBİS is Turkey's Data Controllers' Registry. The registration obligation isn't the same for everyone; it depends on criteria such as headcount, financial size and line of business, and on exemptions granted by Board decisions. Confirm whether your business must register through the Authority's current announcements and your lawyer. Even if you don't have to register, other obligations such as informing people and keeping data secure still apply.
- List every form, cookie and third-party tool on the site.
- For each, note which data goes where and for what purpose.
- Remove unnecessary fields and unused tools.
- Prepare the privacy notice, cookie policy and request procedure with your lawyer.
- Update this list whenever a new tool or form is added to the site.
Frequently asked questions
- My site only has a contact form. Does KVKK apply to me?
- Most likely, yes. The name, e-mail and phone number from a form are personal data. At minimum you need a privacy notice, proportionate form fields and secure storage of that data. Have a lawyer assess your situation.
- Do I need consent to use Google Analytics?
- Analytics cookies generally aren't considered strictly necessary, so under the Authority's general approach they are expected to run only after the visitor consents. The fact that analytics data goes abroad also needs to be assessed. Ask your lawyer for a definitive view.
- Can I use a ready-made privacy notice template?
- A template can be a starting point but isn't enough on its own. The notice must accurately reflect which data you actually process, why, and with which services. A notice that describes things your site doesn't do, or leaves out things it does, solves nothing.
- Can a web agency guarantee KVKK compliance?
- No. Compliance comes from legal assessment, internal processes and technical implementation working together. An agency can set up the technical side correctly, such as cookie management, form security and data retention; the legal assessment is a lawyer's job.