Legislation Categories
Legislative Updates
Here you can access most recent articles on legislative updates regarding Personal Data Protection Law, Social Security Law, Taxation Law, Occupational Health and Safety Law, Code of Obligations, Labor Law, Turkish Commercial Code, Law on Protection of the Value of Turkish Currency, Foreign Exchange Legislation, and Immigration Law in Türkiye.
Bilateral Treaties
You can access the dates of the most recent international bilateral social security and double taxation treaties made between Türkiye and other countries and relevant documents here.
Test
06 March 2026
Author Ecem Kumsal Başyurt, Category KVKK - GDPR
The Personal Data Protection Board's (Kişisel Verileri Koruma Kurulu) Principle Decision No. 2026/266 (In Turkish), published in the Official Gazette dated February 28, 2026 and numbered 33182, has significantly clarified both the legal nature of loyalty card programmes and the obligations incumbent on data controllers.
The core focus of the Decision is as follows:
"Allowing transactions to be carried out without any verification of the data subject, solely on the basis that a third party declares the loyalty card holder's mobile phone number or loyalty card number at the point of sale, gives rise to a risk of non-compliance with personal data security requirements and the general principles."
This assessment demonstrates that loyalty programmes should no longer be regarded merely as marketing tools, but rather as high-risk personal data processing systems.
In its Decision dated July 5, 2019 and numbered 2019/198 (In Turkish), the Board assessed that a loyalty-card-specific discount practice would not be considered as imposing consent as a condition, provided that access to the core product/service is not eliminated.
A similar approach was reaffirmed in the Board's Decision dated May 25, 2023 and numbered 2023/890 (In Turkish). The Board held that participation in the special passenger programme was not mandatory for accessing the core air transport service; the programme merely offered additional benefits, and therefore the "freely given" element of consent was not undermined.
Within this framework, where:
consent may not, in every case, be characterised as "forced".
The Board's Decision dated March 10, 2022 and numbered 2022/229 (In Turkish) set out clear boundaries regarding the use of cookies in the e-commerce sector.
The Board assessed that cookies other than strictly necessary cookies—namely:
are subject to explicit consent, and cannot be activated on the basis of legitimate interests.
Furthermore, the Board explicitly considered an opt-in model—where cookies do not operate by default and are activated through the user's active choice—to be mandatory.
This approach is directly relevant to segmentation, profiling, and re-marketing activities conducted within the scope of loyalty programmes.
The Board also treats errors arising in operational processes as a distinct personal data processing activity.
In its Decision dated January 5, 2023 and numbered 2023/4 (In Turkish), the Board accepted that delivery of a product to the wrong individual due to cross-barcoding constitutes the disclosure of personal data to a third party.
Similarly, in its Decision dated May 18, 2023 and numbered 2023/845 (In Turkish), the Board emphasised that where a courier misuses the recipient's phone number, the data controller's obligations to implement organisational and technical measures remain in force.
In light of these decisions, defences such as "inadvertent mistake" or "isolated employee conduct" do not eliminate liability under Article 12.
In its Decision dated October 7, 2021 and numbered 2021/1021 (In Turkish), the Board expressly stated that even if the breach is alleged to have occurred within the data processor's environment, the data controller's joint responsibility under Article 12/2 continues.
Penetration testing, technical oversight, monitoring of data destruction processes, and contractual security provisions were examined concretely by the Board.
This approach is of critical importance for relationships established in the e-commerce ecosystem with integrators, logistics providers, call centres, and software vendors.
The Board expressly stated that the use of loyalty cards for different transaction types—such as:
may be subject to different verification mechanisms depending on the level of risk.
This approach is aligned with the risk-based security understanding reflected in the e-commerce personal data breach decision dated August 8, 2024 and numbered 2024/1385 (In Turkish), in which:
were assessed as a violation of the data controller's obligations under Article 12.
Accordingly, the Board's message is now clear:
Identity verification and prevention of misuse are no longer optional; they constitute a mandatory design element under Article 12.
The Board stated that transactions carried out by a third party without the loyalty card holder's knowledge and consent cannot be based on any of the legal bases set out under Article 5 of the Law.
The critical points are:
This situation also undermines the "accurate and, where necessary, up-to-date" principle set out in Article 4.
A similar approach is also reflected in the Board's 2023/4 cross-barcoding decision (In Turkish): "even an inadvertent operational error may, as a matter of law, give rise to a new processing/disclosure activity."
Through the Principle Decision, the Board granted data controllers a six-month compliance period.
Upon expiry of this period, it was expressly stated that proceedings may be initiated under Article 18 against data controllers who:
There are significant parallels between Türkiye's KVKK approach and the EU data protection framework.
Under the EU General Data Protection Regulation (GDPR), consent must be:
KVKK adopts a comparable consent standard. Therefore, within loyalty programmes, consents for marketing and additional benefits should be collected separately, in an informative manner, and on a voluntary basis.
The EU e-Privacy Directive requires prior consent (opt-in), particularly for direct marketing conducted through electronic communications. It also protects device privacy in practices such as cookies and device storage/access.
In the context of loyalty programmes, this approach points to principles such as:
The EDPB's guidance on the interplay between the GDPR and the Digital Markets Act (DMA) emphasises that data protection obligations must be incorporated from the outset across all digital design processes ("privacy by design"). This implies that, for loyalty programmes involving multiple processing operations, risk-based verification and security measures should be embedded at the design stage.
Pursuant to the Personal Data Protection Board's Principle Decision No. 2026/266, published in the Official Gazette dated 28 February 2026 and numbered 33182, data controllers operating loyalty card schemes must implement the measures set out below within six months; otherwise, the Board may impose sanctions.
Transaction flows that allow, at the point of sale/online, the following actions solely by stating the loyalty card number or mobile phone number—without obtaining the data subject's approval—must be discontinued:
Use of the loyalty card must not be completed without a verification step that confirms the transaction is carried out with the knowledge and consent of the data subject. Particularly for point spending and discount-triggering transactions, a "no verification, no transaction" approach should be adopted.
In alignment with the Board's approach of providing "alternatives for different groups of data subjects":
In Principle Decision No. 2026/266, the Board stated that loyalty card transactions may be subject to different verification mechanisms depending on transaction type and risk level. While no specific technical solution is mandated, it is emphasised that mechanisms ensuring confirmation of the data subject's knowledge and intent must be implemented.
Accordingly, data controllers may model verification as follows, taking into account the nature of their activities, transaction volume, fraud risk, and technical infrastructure:
In such cases, the data subject's explicit and verified intent should be obtained.
For example:
A minimum verification mechanism may be sufficient.
Access controls ensuring account security (e.g., two-factor authentication) may be implemented; however, these should be technically separated from transaction-generating actions.
It should be emphasised that the Board's approach is not to mandate a specific technology, but to ensure the design of a proportionate and purpose-bound verification architecture that prevents third-party use without the data subject's knowledge.
Therefore, the mechanisms listed above do not constitute a binding technical checklist; they are illustrative design alternatives. Data controllers should determine the appropriate mechanism based on a risk analysis reflecting their operational structure.
For each loyalty transaction, the following records may be retained:
Such logs are critical both for internal audits and for demonstrating compliance in the context of potential breach investigations.
Membership, marketing, and additional service consents should be managed separately, and an easy withdrawal mechanism should be provided.
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.
About The Author
https://www.cottgroup.com
Clarification on the Application Principles of VERBİS Registration Exemptions
Ecem Kumsal Başyurt
13 January 2026
Personal Data Protection Law (PDPL) in Human Resources Processes: Why is It Important?
Civan Güneş, CottGroup Hukuk ve Mevzuat Ekibi
6 October 2023
Evaluation of Personal Data Breaches within the Scope of Turkish Penal Code
CottGroup Hukuk ve Mevzuat Ekibi
11 March 2024
Obligation to Register to the Data Controllers Registry Information System (Verbis)
Semih Er
19 September 2023