KVKK Article 6: Special-Category Health Data
The online appointment form, test result page or patient portal login screen are moments where the visitor comes into contact with health data. On these pages, any analytics or marketing script collected via cookies that runs without explicit consent creates a risk of aggravated penalties under KVKK Article 6. A standard general privacy notice is not considered sufficient.
- Explicit consent: must be separate, freely given, specific and informed
- The consent log must be recorded with a timestamp before appointment confirmation
- The burden of proof lies with the data controller; if the log is deleted, the penalty can double