KVKK·7 min read·
How to write a privacy notice under Turkey's KVKK
The five mandatory elements, the drafting rules the regulation sets out, and a practical checklist for a website operating in Turkey.
Dilay Emre·Founder
Anyone processing personal data in Turkey has to inform the data subject at the moment the data is collected. The written form of that duty is the aydinlatma metni, the privacy notice. For a company running a website it starts the moment a visitor's name, email, IP address or cookie data is taken.
The common problem is not a missing notice. It is a notice copied from another site that never describes what the company actually does. Below are both the mandatory elements and the rules on how the text has to be written.
Creating a privacy notice is often the first thing a company asks a lawyer about. Yet the skeleton is defined in the regulation; the real work is establishing what data the company actually processes and why. Once that inventory is right, the text largely writes itself.
A privacy notice is not consent
This distinction underpins everything else. The notice informs; consent permits. They serve different legal functions and must not be merged.
The duty to inform applies in every case, whatever legal ground you rely on. Explicit consent only comes into play when no other ground is available.
The practical consequence: putting a checkbox under the notice saying "I have read and accept" is the wrong construction. A notice is not something to accept. Where consent is required it must be taken separately and optionally.
Is a privacy notice the same as a privacy policy?
Not quite, though they overlap. KVKK's own term is aydınlatma metni, the notice; privacy policy is the broader document familiar from international practice.
Both approaches appear in practice. Some companies write a single privacy policy and place the required elements inside it. Others prepare short, focused notices per context and link out to the fuller policy.
The second works better. A job applicant and a newsletter subscriber do not need to see the same information. Showing everyone the same long text weakens the clarity the regulation asks for.
The five mandatory elements
The communique governing how the duty is met lists what the text must contain. If one is missing, the notice does not satisfy the obligation.
- The identity of the data controller and its representative, if any
- The purposes for which the personal data will be processed
- To whom and for what purpose the processed data may be transferred
- The method and legal ground of collection
- The rights of the data subject set out in the law
The identity part is often thin. Company name, address and a contact route should be explicit; the visitor needs to know who to approach.
Transfers are the most commonly skipped section. Every external service you use may amount to a transfer: an analytics tool, an email sender, a payment provider, a support widget. Some of them sit outside Turkey, which has to be stated separately.
The transfer section needs two separate answers: who receives the data, and in which country it is processed. Where a service is headquartered and where the data physically sits are not always the same place.
Most widely used tools fall into scope. Analytics tools, advertising pixels, embedded video, live chat widgets, payment providers and email senders are typical examples.
You can pull the list of third-party services running on your site, and the country each one sits in, with an automated scan. Writing the transfer section against that list beats writing it from memory.
Avoid vague purpose statements
The communique explicitly rules out general and indefinite wording. A line such as "to improve our services" does not describe a purpose on its own.
The more concrete the purpose, the sturdier the text. "To create the order record and enable shipment tracking" or "to measure site usage statistics" are both understandable and defensible.
Plain, clear and simple language is essential when the duty to inform is carried out.
Communique on the Procedures and Principles for Fulfilling the Duty to Inform
Think per collection channel
The duty is not limited to the website. Wherever data is collected, the notice belongs there.
- Contact and signup forms on the website
- Cookies and on-site tracking tools
- Call centre conversations
- Job application forms
- CCTV recordings on physical premises
CCTV is the one most often forgotten. If there is a camera at a shop, office or warehouse entrance, a short notice has to be visible there. A small sign pointing to the full text does the job.
Where it goes on the site
The text has to be reachable from wherever data is collected. A single footer link, with no mention at the form itself, is a weak setup.
- Every form should carry a link to the notice
- The cookie banner should reach both the cookie policy and the notice
- The text should live on its own permanent URL
- The effective date and version should be visible
Version information is missing from most sites but it matters. In a dispute, the question is which text was shown to the visitor on that date.
Should retention periods appear in the text?
Although not listed as a separate mandatory element, stating retention serves both transparency and the person's ability to exercise their rights. Someone who does not know how long data is kept cannot judge whether to ask for erasure.
You do not have to give a figure in days. Where a statutory retention duty applies, referring to it is enough; otherwise tying it to the purpose ceasing to exist works.
- The statutory period for invoices and accounting records
- For the duration of the contract and the limitation period after it
- Until a newsletter subscription ends
- For cookie data, the lifetime of the cookie itself
The last one is missing from most texts. Presenting cookie lifetimes as a table in the cookie policy both completes the disclosure and gives the visitor something concrete.
Five frequent mistakes
- A text copied from another site that does not describe the real business
- Merging the notice and consent into a single checkbox
- Never naming the third-party services in use
- Saying nothing about transfers abroad
- Writing the text once and leaving it for years
The last is the quietest. The text can be accurate the day it is written, then marketing adds a tag, engineering connects a service, and it ages without anyone noticing.
The copied-text problem is more widespread than it looks. The same sentences can be found repeated word for word across dozens of sites. When an audit shows the text does not match the company's actual activity, having a text provides no defence.
So a privacy notice is not a one-off task. Following what actually runs on the site through scheduled scans and change monitoring also tells you when the text needs updating.
When to update it
The text changes when your processing changes. In practice these are the triggers:
- A new analytics, advertising or support tool is added
- The payment, email or hosting provider changes
- A new form or collection point opens
- The company name, address or contact details change
- The country where data is stored changes
Template or from scratch?
Using a template is not wrong, and it is sensible. The required elements are fixed, so composing every text from nothing serves no one. The problem is not the template but using it unfilled.
Most ready-made texts circulating online describe another company's business. Their purposes, transfers and retention periods are not yours. Such a text sits in a folder but does not meet the obligation.
The right construction: the skeleton comes from a template, the content from your actual processing. That requires the inventory first. Which forms exist, which tools run, where the data goes.
DILAYS combines those two steps. It scans your site to establish which third-party services run on it, then drafts policies and notices against your business type and chosen framework. The KVKK notice is produced from a Turkish-language template.
What comes out is a draft, and legal responsibility stays with the data controller in every case. But there is a real difference between starting from a blank page and reviewing a draft built on a known inventory.
Checklist
- Are all five mandatory elements present?
- Are the purposes concrete rather than general?
- Are the third-party services you use named?
- Are transfers abroad stated where they occur?
- Are the notice and consent kept apart?
- Is the text reachable from every collection point?
- Are the effective date and version shown?
- Has a new service appeared on the site since the last update?
Most of these are not done once. We wrote up how we process and store data on our own infrastructure in the Trust Center; asking yourself the same questions is a reasonable place to start.
Which third-party services run on your site?
Enter your domain, we scan your home page and email you the report. Free.
Scan for free