Cookies used on websites often process personal data and fall within the scope of KVKK.
Cookie Types
- Mandatory cookies: Site operation (session, basket)
- Performance cookies: Analytics (Google Analytics)
- Functional cookies: Preferences (language, theme)
- Marketing cookies:Ad tracking (Facebook, Google Ads)
Explicit Consent Requirement
- Mandatory cookies:Explicit consent not required (contractual/legal obligation)
- Other cookies:Explicit consent required
- Pre-signed consent invalid
Cookie Notification (Banner)
- Must be displayed on first visit
- "Accept all" + "Only mandatory" + "Set" options
- Optional cookies should not be activated until the user chooses
- Cookie policy link
KVKK and GDPR Comparison
- GDPR more strict (Cookie Banner example)
- KVKK Board in Türkiye has a similar approach
- Board notification is expected in 2024
KVKK Board Decision
KVKK Board imposes administrative fines on websites that place cookies without cookie notification. In particular, pre-activation of analytical and marketing cookies is considered a violation.
Practical Recommendations
- Use a cookie browser (Cookiebot, OneTrust)
- Publish the cookie policy on a separate page
- Save the preferences (so the user does not need to choose again)
- 3. Minimize party cookies
KVKK expert lawyer recommended.