KVKK Compliance Period for Loyalty Programs Extended to February 28, 2027: How Should Companies Use the Additional Compliance Period?

The Personal Data Protection Board's ("Board") Principle Decision dated February 10, 2026 and numbered 2026/266 regarding the processing of personal data within the scope of loyalty programs was published in the Official Gazette dated February 28, 2026 and numbered 33182. The six-month compliance period granted to data controllers under the Principle Decision for the purpose of implementing the necessary technical and organizational measures will be expired on February 28, 2026.
However, this period has been extended until February 28, 2027 by the decision of the Board published in the Official Gazette dated August 13, 2026 and numbered 33339.
In our previously published article titled "KVKK's New Principle Decision on Loyalty Programs: A Six-Month Compliance Period for Data Controllers," we addressed the scope of the Principle Decision, the Board's assessments and the compliance process envisaged for data controllers.
Taking into account that the need to extend the compliance period had arisen in line with requests from the sector, the Board changed the deadline, previously set as August 28, 2026, to February 28, 2027.
Accordingly, the key issue for companies is no longer what the regulation entails, but rather ensuring that the additional time granted is used effectively to align their existing technical and operational systems with the Principle Decision.
The Board's Findings
In the operation of loyalty programs, a customer's declaration of a telephone number or card number at the checkout stage may be sufficient for locating the relevant loyalty account and associating the transaction with that account. This structure may also enable third parties who know another person's telephone number or card number to carry out transactions through the relevant loyalty account without any additional authentication.
This is one of the fundamental issues emphasized by the Board in the Principle Decision. The ability of third parties to carry out transactions by using the loyalty card holder's mobile telephone number or card number without any authentication mechanism does not merely create a commercial risk regarding the unauthorized use of loyalty points or discounts. Such a practice may also result in personal data being associated with the wrong person and data being processed without the knowledge of the relevant person.
For example, if Person A provides Person B's telephone number during a purchase and the system records the transaction in B's loyalty account without carrying out any authentication, the products purchased by A, the transaction date, the transaction amount and information regarding the use of campaigns may be associated with B's customer profile.
This is also significant in terms of the principle of being "accurate and, where necessary, kept up to date" regulated under Article 4 of the KVKK. The recording of transactions that were not carried out by the relevant person in that person's customer profile may result in the personal data held by the company not reflecting the actual circumstances.
The New Compliance Approach Introduced by the Principle Decision
Following the Principle Decision, it will not be sufficient for companies merely to ensure the accuracy of the basic customer information recorded in the loyalty program. Companies should also assess measures that will ensure that transactions carried out through a customer account are actually associated with the relevant person.
Within this scope, it is important for companies first to identify which transactions a third party can carry out through the relevant account merely by knowing the customer's telephone number or loyalty card number.
The addition of points to an account, the redemption of accumulated points, benefiting from a campaign, changing account information or using an advantage with monetary value may involve different levels of risk. Therefore, authentication measures should also be determined according to the nature of the transaction and the risk it creates.
The Board's approach should not be interpreted as a framework requiring a single technical authentication method to be applied to all loyalty programs. Methods such as a one-time code sent via SMS, approval through a mobile application or a user-specific dynamic QR code are technical solutions that may be considered according to the characteristics of the specific system. The essential point is to establish an authentication mechanism that can prevent third-party use without the knowledge of the relevant person, is proportionate to the risk and is appropriate for the intended purpose.
Maintaining the Balance Between Data Security and Proportionality
It should be borne in mind that strengthening authentication mechanisms does not provide companies with an unlimited ability to collect additional personal data. When determining security measures, companies should also take into account the principle under Article 4 of the KVKK that personal data must be relevant, limited and proportionate to the purposes for which they are processed.
Requesting more personal data than necessary from customers for a low-risk loyalty program practice or carrying out extensive personal data processing where the same level of security can be achieved through a less intrusive method, may also require assessment in terms of proportionality. Accordingly, the objective is not to establish the most stringent authentication mechanism possible, but rather to establish a security mechanism that is necessary, appropriate and proportionate in view of the specific risk.
Separating the Loyalty Program from Marketing Processes
When assessing the compliance process within the company, it is also important to distinguish the operation of the loyalty program from marketing and commercial communication activities.
Processing a customer's telephone number for the purpose of creating or authenticating a loyalty account and using the same number for sending advertising and campaign messages constitute different personal data processing activities. Similarly, retaining purchase history for the purpose of calculating loyalty points should not be considered within the same scope as using such history to analyze the customer's consumption habits or create a marketing profile.
For this reason, companies should separately assess the legal bases for loyalty program membership, operation of the account, points and benefits systems, profiling, personalized marketing and commercial electronic communication processes.
The Use of Service Providers Does Not Eliminate Companies' Obligations
In loyalty programs, various processes such as POS systems, CRM infrastructures, mobile applications, cloud services, campaign management and call centers may be carried out through third-party service providers.
Nevertheless, the fact that the technical infrastructure of the loyalty program is provided by a third party does not eliminate the data controller's data security obligations arising from Article 12 of the KVKK.
For this reason, companies should include within their compliance work the access authorizations of service providers, data security obligations, logging systems, data breach processes, use of subprocessors, and data retention-destruction processes.
Compliance Actions to Be Completed by Companies by February 28, 2027
It is important to conduct an end-to-end review of the existing loyalty program and identify points within POS, CRM, mobile applications, websites, call centers, campaign management systems and third-party integrations that may enable unauthorized account use.
Companies will particularly need to review account creation and matching methods, point earning and redemption processes, account changes, authentication mechanisms, records of unsuccessful or unusual transactions, access authorizations and customer notification mechanisms.
On the other hand, it is important that the compliance process is not limited to the legal/KVKK department and that information technology, information security, CRM, marketing, customer services and operations teams are also included in the process.
The extension of the compliance period until February 28, 2027 should not be interpreted as meaning that the work in question may be postponed. On the contrary, it is important that the additional time granted be used to complete technical developments, test verification mechanisms, review third-party integrations, and align internal company processes with the Principle Decision.
Conclusion
By the Board's Decision No. 2026/1491, the compliance period granted to data controllers under Principle Decision No. 2026/266 has been extended until February 28, 2027. The new Decision does not alter the obligations set out in the Principle Decision; it merely provides companies with additional time to reflect these obligations in their technical and operational systems.
In our previous article, we addressed the legal framework of the Decision. At the current stage, companies should prioritize determining whether the requirements of the Principle Decision have actually been incorporated into technical systems, operational processes and internal control mechanisms.
Therefore, it is important that the additional period granted until February 28, 2027 be regarded not as a postponement period, but as an additional implementation period intended for the completion of ongoing compliance efforts.
In this context, the fundamental control question remains unchanged: If a third party knows only the customer's telephone number or loyalty card number, what transactions can they carry out on that person's account without the knowledge of relevant person?
The answer to this question constitutes an important starting point for companies in identifying the aspects of their existing loyalty programs that need to be reconsidered within the scope of the Principle Decision.
Click here to access the relevant announcement. (In Turkish)
-
-
Notification!



