Short answer: A cookie banner built for GDPR is not automatically valid under Turkey's data protection law, KVKK (Law No. 6698). KVKK treats explicit consent as the default legal basis for non-essential cookies, and the Turkish Data Protection Authority's 2022 Cookie Guideline leaves far less room for the legitimate-interest arguments some sites rely on in the EU. Cross-border transfers also work differently: KVKK Article 9 has its own list of transfer mechanisms, so US-hosted analytics and advertising tags need a separate review for Turkish traffic. If your website serves both markets, the practical answer is one geo-aware banner that applies KVKK behavior to visitors from Turkey and GDPR behavior to visitors from the EU.
Turkey is one of the largest online markets in Europe's neighborhood, and many international teams assume their existing GDPR setup covers it. It usually does not. Below we compare the two regimes point by point: legal basis, banner UX, cross-border transfers, consent records and enforcement, and close with an architecture that handles both without running two separate tools.
Note: This article is general information, not legal advice. For decisions about your specific situation, consult a qualified lawyer.
Table of contents
- Why GDPR compliance is not automatically KVKK compliance
- Legal basis: explicit consent under KVKK vs the GDPR landscape
- Banner UX differences: granularity, reject buttons and language
- Cross-border transfers: KVKK Article 9 and US-hosted tags
- Consent logging and record keeping on both sides
- Enforcement snapshot: what regulators sanction
- Side-by-side comparison table
- Practical architecture: one geo-aware banner, two behaviors
- Frequently Asked Questions
- Sources
Why GDPR compliance is not automatically KVKK compliance
KVKK (Kişisel Verilerin Korunması Kanunu, Law No. 6698) was enacted in 2016 and modeled largely on the EU's Directive 95/46/EC, the framework that preceded GDPR. The two laws share DNA, which is exactly why the differences are easy to miss: the vocabulary looks familiar, but the details diverge in ways that matter for cookies.
Three structural facts drive the gap:
- Different legal-basis menu. KVKK's processing conditions in Article 5 are not a copy of GDPR Article 6, and Turkish Board practice reads the flexible bases much more narrowly for tracking technologies.
- Different transfer regime. KVKK Article 9 governs transfers out of Turkey with its own mechanisms and notification duties. An EU transfer file (SCCs, transfer assessments) does not satisfy it by itself.
- Different regulator. The Turkish Personal Data Protection Board (KVKK Kurulu) publishes its own guidance and decisions and is not bound by EDPB positions.
Both laws can apply to the same website at the same time: a store in Berlin selling to Istanbul falls under GDPR for its EU visitors and under KVKK for its Turkish audience. Treating Turkey as "just another GDPR country" is the single most common mistake we see in international consent setups.
Legal basis: explicit consent under KVKK vs the GDPR landscape
The EU side
In the EU, cookies are governed by two layers. The ePrivacy Directive (2002/58/EC, Article 5(3)) requires consent before storing or reading anything on a user's device, unless the cookie is strictly necessary for the service the user requested. GDPR then supplies the consent standard: freely given, specific, informed and unambiguous (Articles 4(11) and 7). Pre-ticked boxes and "by continuing you accept" banners are invalid.
Legitimate interest (GDPR Article 6(1)(f)) exists for processing in general, but it cannot replace ePrivacy consent for placing non-essential cookies. A few national regulators accept narrow audience-measurement exemptions under strict conditions, and those exemptions are national, not EU-wide.
The Turkish side
KVKK Article 5 lists the lawful processing conditions, and Article 3 defines explicit consent (açık rıza) as consent that relates to a specific matter, is based on information, and is expressed with free will. The Turkish DPA's 2022 Guideline on Cookie Applications (Çerez Uygulamaları Hakkında Rehber) applies this to cookies directly: analytics, advertising and social-media cookies require explicit consent before they are set, while strictly necessary cookies (session, cart, security, language preference) can rely on other Article 5 conditions. Scrolling, continued browsing or silence is not consent.
The practical difference
Under KVKK, plan on explicit opt-in for every analytics and marketing cookie; legitimate interest is not a workable shortcut for tracking in Board practice. Since ePrivacy also demands consent for non-essential cookies in the EU, consent-first is the safe common denominator for both markets. For a deeper walkthrough of each regime, see our KVKK cookie guide and the GDPR guide.
Banner UX differences: granularity, reject buttons and language
The good news: a well-built banner satisfies most of both regimes at once. The requirements overlap heavily.
Shared expectations:
- Prior blocking. Non-essential scripts must not fire before the visitor chooses.
- Granular categories. "Accept all" alone is not enough; visitors need per-category choices (necessary, analytics, advertising, and so on).
- Easy withdrawal. Withdrawing consent must be as easy as giving it, which in practice means a persistent preferences link or widget.
Where Turkey adds emphasis:
- Equal-prominence reject. The Turkish Board treats hidden or hard-to-find reject options as a dark pattern, and its published decisions repeatedly flag this. Rejecting must be as easy and as visible as accepting.
- Turkish language for Turkish visitors. KVKK Article 10 requires informing the data subject in a clear and intelligible way. The law does not literally say "in Turkish", but for an audience in Turkey a disclosure they cannot read does not meet that bar, so Turkish banner text and a Turkish cookie notice are the practical expectation.
- Cookie walls. Blocking site access until the visitor consents is viewed as undermining free will in Turkish guidance, mirroring the skeptical position most EU regulators take.
Where the EU adds emphasis: several EU authorities now expect a reject option on the first layer of the banner, not buried behind a "settings" click, and design tricks such as color-weighted buttons have featured in enforcement on both sides.
Cross-border transfers: KVKK Article 9 and US-hosted tags
Cookie consent and transfer rules are usually discussed separately, but third-party tags merge them: when a page loads an analytics or advertising script, the visitor's IP address, identifiers and behavioral data typically flow to servers abroad, often in the United States. That is a cross-border transfer on both sides of the comparison.
Under KVKK, Article 9 originally allowed transfers abroad mainly on explicit consent or a Board-authorized written undertaking, which made US-hosted tooling awkward for years. The article was overhauled by Law No. 7499, published in March 2024 and in force since June 2024. The current regime resembles GDPR Chapter V in structure: adequacy decisions by the Board, appropriate safeguards such as standard contracts (which must be notified to the Authority within five business days of signing), binding corporate rules and Board-approved undertakings, plus narrow derogations for occasional transfers. Explicit consent moved from the default mechanism to an exception.
Under GDPR, Chapter V requires an adequacy decision (the EU-US Data Privacy Framework covers certified US companies), or appropriate safeguards such as SCCs combined with a transfer impact assessment following the Schrems II judgment. Several EU authorities have assessed Google Analytics configurations as problematic under Schrems II, which is why analytics setups deserve extra scrutiny in transfer reviews.
The practical takeaway: you cannot document transfers you do not know about. Start with an inventory of every third-party tag and where it sends data; a free cookie scanner can list the cookies and third-party providers your pages actually load. Then confirm each US-hosted vendor is covered by a valid mechanism on both the KVKK and the GDPR side, and say so in your cookie notice.
Consent logging and record keeping on both sides
Both regimes put the burden of proof on the website operator.
- GDPR: Article 7(1) requires the controller to be able to demonstrate that consent was given, and Article 5(2) makes accountability a standing principle. If a regulator asks, "show me this visitor consented to advertising cookies on this date", you need an answer.
- KVKK: Article 12 imposes data-security and demonstrability obligations, and Board practice expects the controller to prove that valid explicit consent existed before non-essential cookies were set.
A defensible consent record typically captures: a timestamp, a pseudonymous visitor identifier, the banner version and the exact text shown, the language, the per-category choices, the consent method, and any later withdrawal events.
Neither law fixes a single statutory retention period for consent logs. Keep them long enough to demonstrate valid consent for the processing they cover, document that period in your published cookie policy, and delete them when they no longer serve the purpose. Your policy should also match what the banner actually does; a cookie policy generator helps keep the published text and the real cookie inventory in sync.
Enforcement snapshot: what regulators sanction
We deliberately keep this section general: fine amounts change, get indexed annually, and are frequently quoted out of context. What is stable is the pattern of behavior that draws sanctions.
In Turkey, the Board's administrative fine ceilings are updated every year with the official revaluation rate, and published decisions repeatedly target the same failures: loading third-party advertising or analytics cookies without explicit consent, reject options that are hidden or harder to use than accept (dark patterns), inadequate or unintelligible disclosure texts, and transfers abroad without a valid Article 9 mechanism. Current decisions are published at kvkk.gov.tr.
In the EU, GDPR sets statutory maxima of up to 20 million EUR or 4% of worldwide annual turnover, and cookie enforcement is handled by national authorities, often under national ePrivacy implementations. Recurring themes mirror the Turkish list: no first-layer reject, pre-ticked boxes, tracking that starts before any choice, and misleading banner design.
On both sides, the cheapest insurance is the same: block before consent, offer a real reject, and keep records.
Side-by-side comparison table
| Topic | KVKK (Turkey) | GDPR + ePrivacy (EU) |
|---|---|---|
| Core law | Law No. 6698 (2016), modeled on Directive 95/46/EC | Regulation (EU) 2016/679 + ePrivacy Directive 2002/58/EC |
| Cookie-specific guidance | Turkish DPA Guideline on Cookie Applications (2022) | EDPB guidelines + national DPA guidance |
| Consent standard | Explicit consent: specific, informed, freely given | Freely given, specific, informed, unambiguous |
| Legitimate interest for analytics | Not accepted in Board practice for analytics/ads cookies | Consent required under ePrivacy; only narrow national audience-measurement exemptions |
| Reject option | As easy and visible as accept; dark patterns sanctioned | First-layer reject increasingly expected by DPAs |
| Language of disclosure | Turkish for visitors in Turkey in practice (Article 10) | Language of the targeted audience (Article 12 transparency) |
| Cross-border transfers | Article 9 (amended 2024): adequacy, standard contracts notified to the Authority, BCRs, limited derogations | Chapter V: adequacy (incl. EU-US DPF), SCCs + transfer impact assessments |
| Consent records | Article 12 + controller burden of proof | Articles 5(2) and 7(1) accountability |
| Fine framework | Administrative fines, ceilings updated annually | Up to 20 million EUR or 4% of worldwide turnover |
| Regulator | Personal Data Protection Board (KVKK Kurulu) | National DPAs, coordinated by the EDPB |
Practical architecture: one geo-aware banner, two behaviors
You do not need two consent tools for two laws. You need one banner with region-specific behavior and one consent log behind it:
- Detect the visitor's region at page load, before any non-essential tag runs.
- Turkish visitors get KVKK behavior: Turkish banner text, explicit opt-in per category, a reject button with the same prominence as accept, and a cookie notice that names third-party recipients and transfers abroad.
- EU visitors get GDPR behavior: banner text in their language, a first-layer reject, granular categories, and Google Consent Mode v2 signals that default to denied until the visitor makes a choice.
- Everyone gets the fundamentals: non-essential scripts blocked until a choice is made, every consent event written to a single log with region, language and banner version, and periodic rescans so new tags never bypass the banner.
This is the model cerez.io implements: a geo-aware cookie consent banner that applies KVKK defaults to Turkish traffic and GDPR defaults to EU traffic, automatic cookie scanning and categorization, Google Consent Mode v2 integration, and timestamped per-domain consent logs. It helps you implement, measure and document consent; it does not replace legal review of your specific setup.
Frequently Asked Questions
Does KVKK require a cookie banner?
Short answer: KVKK never uses the word "banner", but a banner is how its requirements are met in practice. Non-essential cookies need explicit consent before they are set, and Article 10 requires informing visitors about the processing. The Turkish DPA's 2022 Cookie Guideline describes consent that is informed, specific and freely given, and a banner with granular categories plus an equally visible reject option is the standard way to collect and prove it.
Is GDPR compliance enough for a website targeting Turkey?
Short answer: No. A solid GDPR setup is a strong starting point because both laws demand informed, freely given consent, but KVKK differs on how narrowly the flexible legal bases are read, on cross-border transfer mechanics under Article 9, and on the practical expectation of Turkish-language disclosure. Review your banner text, your tag inventory and your transfer documentation separately for Turkish traffic.
Can I use legitimate interest for analytics cookies under KVKK?
Short answer: Do not plan on it. Turkish guidance and decision practice treat analytics and advertising cookies as requiring explicit consent, and the legitimate-interest condition in Article 5/2(f) is read narrowly, essentially for cases like fraud prevention and security. Since the EU's ePrivacy rules also require consent for non-essential cookies, consent-based analytics is the safer common denominator in both markets.
Do I need separate consent flows for Turkish and EU visitors?
Short answer: You need separate behaviors, not separate infrastructure. A single geo-aware banner can show Turkish text with KVKK defaults to visitors from Turkey and local-language GDPR behavior to EU visitors, while writing every consent event into one log with region and banner-version metadata. Running two unrelated consent tools on one site usually creates gaps instead of closing them.
How long should cookie consent records be kept?
Short answer: Neither KVKK nor GDPR sets one fixed retention period for consent logs. Keep them long enough to demonstrate valid consent for the processing they cover, state that period in your cookie policy, and delete them when they no longer serve the purpose. In practice retention commonly ranges from about one year to a few years depending on risk profile and local limitation periods; ask your counsel what fits your situation.
Sources
- Turkish DPA, Guideline on Cookie Applications (2022)
- Turkish Personal Data Protection Authority (KVKK)
- Regulation (EU) 2016/679 (GDPR), full text
- ePrivacy Directive 2002/58/EC, full text
- Google Consent Mode developer documentation
Serving visitors in both Turkey and the EU? Start free and set up one geo-aware banner with KVKK and GDPR behaviors in about 15 minutes, no credit card required. Plan details are on the pricing page.