A foreign brand launching a Turkey marketing campaign rarely starts with data protection law. It starts with channel strategy, creative, and budget. But KVKK, Turkey’s Law on the Protection of Personal Data, sits underneath every one of those decisions the moment a campaign collects an email address, a phone number, or a cookie-based tracking identifier from someone in Turkey. Getting this wrong is not a theoretical risk: Turkey’s data protection authority has been actively issuing guidance and enforcement decisions specifically targeting marketing practices in recent periods. This guide walks through what foreign brands actually need to know about KVKK compliance for marketing in Turkey, without assuming a legal background.
Table of Contents
- What KVKK Is and Who It Applies To
- Consent Rules for Marketing
- İYS: The System You Need for Commercial Messages
- VERBIS Registration
- Cross-Border Data Transfer
- Cookie Consent and Behavioral Advertising
- Common Marketing-Specific Pitfalls
- A Practical Compliance Checklist
- Conclusion
- FAQ
What KVKK Is and Who It Applies To
KVKK, formally Law No. 6698 on the Protection of Personal Data, is Turkey’s primary data protection legislation, in force since 2016 and modeled in part on earlier EU data protection frameworks, with amendments in recent years bringing it closer to the current GDPR structure. The law is enforced by the Personal Data Protection Board, generally referred to as the KVKK Authority.
The scope question matters most for foreign brands: KVKK applies to any organization processing the personal data of individuals in Turkey, regardless of where that organization is physically located. This includes local businesses, but it also explicitly includes international service providers and foreign brands that collect data through a website targeting Turkish users, run marketing campaigns aimed at Turkish consumers, or otherwise process the personal data of people in Turkey. A brand does not need a Turkish office or entity to fall within KVKK’s scope; it needs Turkish user data.
Consent Rules for Marketing
For marketing specifically, KVKK requires explicit consent before processing personal data for promotional purposes, unless another valid legal basis applies. That consent has to meet a specific standard, not just exist in some form:
- Specific and informed. Consent must be tied to a clearly stated purpose, with the individual informed about how their data will be used before they agree.
- Freely given. Consent obtained through pressure, bundled agreements, or as a hidden condition of using a service does not qualify.
- Granular, not blanket. A vague consent covering “all data processing activities” is not valid; individuals need meaningful options for different types of processing.
- Verifiable and revocable. The burden of proving valid consent rests with the data controller (your business), and individuals must be able to withdraw consent at any time, with processing stopping as soon as a withdrawal is received.
- Not inferred from silence or inaction. The KVKK Authority has explicitly stated that failing to end a conversation, staying silent, or similar passive conduct cannot be treated as valid explicit consent.
Pre-ticked checkboxes, consent buried in unrelated terms, or “by continuing to scroll you agree” mechanisms do not satisfy KVKK’s standard, even if similar patterns have been used in other markets.
İYS: The System You Need for Commercial Messages
One of the most commonly misunderstood parts of Turkish marketing compliance is that KVKK consent and İYS approval are two separate requirements, arising from different laws, and satisfying one does not automatically satisfy the other.
- İYS (İleti Yönetim Sistemi), the Message Management System, is Turkey’s national registry for commercial electronic messages, covering email, SMS, and marketing calls. Any business sending commercial electronic messages to individuals in Turkey needs to register with İYS before sending, and needs to check recipient numbers or addresses against the İYS consent database.
- Consent recorded through İYS has requirements of its own, including a maximum validity period, and opted-out recipients need to be removed from active marketing lists within a defined window, generally a matter of days, not weeks.
- Message timing rules apply. Commercial SMS messages, for example, are generally restricted to specific daytime hours in Turkey time, and messages sent outside that window risk both delivery blocking and penalties.
- Both layers need to be checked independently for any campaign. A valid KVKK processing basis for holding someone’s contact information does not automatically mean you have İYS approval to message them commercially, and vice versa.
VERBIS Registration
VERBIS (Veri Sorumluları Sicili) is Turkey’s mandatory registry of data controllers, maintained by the KVKK Authority.
- Registration is mandatory for many organizations, including foreign data controllers processing the personal data of Turkish citizens, once certain size or activity thresholds are met (broadly tied to employee count, balance sheet size, or processing of sensitive categories of data, with some exemptions for smaller organizations processing only non-electronic data).
- Foreign brands should not assume exemption by default. The registration obligation is explicitly extended to foreign data controllers under KVKK, meaning a brand with no Turkish office can still be required to register if it processes Turkish personal data at sufficient scale.
- Failure to register carries meaningful financial risk. Administrative fines for VERBIS non-registration can run into significant sums, separate from any fines tied to consent or processing violations.
Cross-Border Data Transfer
Most foreign brands need to move Turkish customer or lead data back to systems outside Turkey — a CRM, an analytics platform, or a global marketing database. This is where KVKK diverges most from what many international marketing teams expect from GDPR-style frameworks.
- Turkey has approved very few countries as offering “adequate” data protection, which means the adequacy-based transfer path that works easily under GDPR for many destinations is far more limited under KVKK.
- Standard contractual clauses, explicit consent, or a formal written commitment to adequate protection are the main practical mechanisms for transferring Turkish personal data abroad in the absence of an adequacy decision.
- Explicit consent for cross-border transfer is a real option but has practical limits for ongoing, automated data flows (like a marketing platform syncing lead data continuously), since relying on consent for every transfer is operationally burdensome at scale.
- Recent amendments have introduced additional notification requirements around cross-border transfers using standard contractual clauses, adding a procedural step that international teams need to track rather than assume is a one-time setup.
Because this is the area where KVKK compliance most directly intersects with how marketing technology actually works — CRM syncing, ad platform integrations, and analytics tools that route data through servers outside Turkey — it is worth building the transfer mechanism into a Turkey campaign’s technical setup early, rather than retrofitting it after a campaign is already live.
Cookie Consent and Behavioral Advertising
Website tracking and behavioral advertising fall squarely under KVKK, even though the law does not contain a dedicated, standalone cookie provision comparable to the EU’s ePrivacy framework.
- Non-essential cookies require prior consent, following guidance the KVKK Authority has published that mirrors the general EU practice of requiring opt-in rather than opt-out for tracking and advertising cookies.
- Cookie banners need to disclose categories and purposes clearly, not bundle analytics, advertising, and functional cookies into a single unexplained consent toggle.
- Third-party marketing and analytics tools need to be checked for compliance too. A brand is responsible for ensuring that tools like ad pixels, analytics scripts, and retargeting platforms embedded on a Turkey-facing website are configured in a way that respects the same consent requirements, not just the brand’s own first-party data collection.
Common Marketing-Specific Pitfalls
- Using SMS verification codes as a backdoor into marketing consent. Turkey’s data protection authority has specifically addressed this pattern, ruling against businesses that collected phone numbers under the guise of transaction verification and then sent unrelated promotional messages without separate, valid consent.
- Assuming referral or “refer a friend” data can be used for marketing without new consent. A public announcement from the authority has drawn a clear line here: contact information obtained from an existing customer’s referral is not, by itself, a valid basis to market to the referred person.
- Treating GDPR compliance as automatically sufficient for Turkey. While KVKK shares structural similarities with GDPR, differences in consent granularity, cross-border transfer mechanisms, and local registration requirements mean an EU compliance program does not transfer directly without a Turkey-specific review.
- Running campaigns in English-only consent language. Consent and privacy notices presented to individuals in Turkey should be in Turkish and written in accessible, non-legal language to meet the “informed” standard KVKK requires.
- Skipping VERBIS because there’s no local office. As noted above, the foreign data controller exemption is narrower than many international teams assume.
A Practical Compliance Checklist
For a foreign brand setting up a Turkey marketing campaign, a practical starting checklist looks like this:
- Confirm whether VERBIS registration applies to your organization’s size and data processing activities, including as a foreign data controller.
- Build KVKK-compliant, Turkish-language consent mechanisms into every data collection point — website forms, cookie banners, app sign-ups, and lead generation ads.
- Register with İYS before sending any commercial email, SMS, or marketing call, and build in a process for checking recipients against the İYS database and honoring opt-outs within the required window.
- Define your cross-border data transfer mechanism for any Turkish personal data flowing into CRM, analytics, or ad platforms hosted outside Turkey, rather than treating this as an afterthought.
- Audit third-party tools embedded on Turkey-facing properties — pixels, analytics scripts, and marketing platforms — for consent-respecting configuration.
- Document your consent records. Since the burden of proving valid consent sits with your business, maintaining clear, timestamped records of what individuals agreed to is essential if compliance is ever questioned.
Building this compliance layer properly also supports the broader marketing infrastructure a foreign brand needs in Turkey — the same data collection points feeding a compliant consent flow are the ones feeding your CRM and campaign targeting, which we cover more broadly in Marketing in Turkey: A Guide for Foreign Brands.
Conclusion
KVKK compliance is not a formality for foreign brands marketing in Turkey — it is an active, evolving enforcement area with real financial and operational consequences. Four points stand out:
- KVKK applies regardless of physical presence — collecting or targeting Turkish personal data is enough to bring a foreign brand into scope.
- KVKK consent and İYS approval are separate requirements — a campaign needs to satisfy both independently, not assume one covers the other.
- Cross-border data transfer needs a defined legal mechanism, since Turkey’s adequacy framework is more restrictive than many international teams expect from GDPR experience.
- Recent enforcement activity specifically targets marketing practices, including SMS verification consent tricks and referral-based contact list building, signaling this is an active area of scrutiny, not a dormant law.
If you’re planning a Turkey marketing campaign and want the consent and data infrastructure built correctly from the start, you can reach out through Medyae.
FAQ
Does KVKK apply to foreign brands that don’t have a physical office in Turkey?
Yes. KVKK applies to any organization processing the personal data of individuals in Turkey, regardless of where the organization is based, including foreign brands that collect data through a website targeting Turkish users, run marketing campaigns aimed at Turkish consumers, or otherwise process Turkish personal data.
What is the difference between KVKK consent and İYS approval for marketing?
They are two separate legal requirements under different laws. KVKK explicit consent makes personal data processing lawful under Turkey’s data protection law, while İYS approval is specifically required to send a commercial electronic message such as email, SMS, or a marketing call under Turkey’s e-commerce communications law. Satisfying one does not automatically satisfy the other.
Can a foreign brand use contact information obtained from a third party for marketing in Turkey?
Not by default. Turkey’s data protection authority has specifically clarified that the fact that contact information was obtained from a third party, referral, or existing customer does not by itself create a valid legal basis to use it for advertising or marketing purposes. A separate, valid processing condition is required.
What are the penalties for KVKK non-compliance?
Administrative fines for KVKK violations can range from several thousand to over a million Turkish lira depending on the nature and severity of the violation, and separate penalties apply for failing to register with VERBIS where required. Beyond fines, the authority can also order the suspension or restriction of data processing activities.
Do privacy notices and consent forms need to be in Turkish?
Yes. Privacy notices and consent forms presented to individuals in Turkey should be in Turkish and use clear, accessible language, since consent obtained through unclear or non-Turkish-language mechanisms is unlikely to meet KVKK’s requirement that consent be specific, informed, and freely given.
This guide is for general informational purposes and does not constitute legal advice. Foreign brands should consult a qualified Turkish data protection lawyer to review their specific data collection and marketing setup.

