Skip to content
ORSEN
tren

A KVKK compliance checklist for websites

What a website has to do under Turkish data protection law: privacy notices, cookie consent, form permissions, retention periods, and processor lists.

4 min read

This is not legal advice. It is a practical checklist of what a website has to do technically under KVKK, Turkey's personal data protection law. For obligations specific to your sector, consult a lawyer.

1. A privacy notice

If you process personal data, you need a privacy notice. If a form is filled in on your site, you are processing personal data. It has to contain:

  • Who the data controller is, with trade name and contact details.
  • Which data is processed.
  • For what purpose.
  • The legal basis.
  • Who it is transferred to, including hosting, email services, and analytics.
  • How long it is retained.
  • The rights of the data subject and how to exercise them.

The item most often skipped is transfer: if your site is hosted on a server abroad, you have to say so.

2. Explicit consent on forms

A contact form needs a consent checkbox, and it must not be pre-ticked. The wording should not just say "I accept"; it should state clearly what is being consented to.

Poor: "I accept the terms."

Better: "I consent to my contact details being processed so that my enquiry can be assessed and answered."

3. Cookie consent: the critical part

The most common mistake: the cookie banner is displayed, but the analytics script has already loaded with the page. In that case the banner is decorative.

The correct behaviour: the analytics script must not load at all before consent is given. Not blocked, never requested.

Also:

  • Rejecting must be as easy as accepting. The reject button belongs on the same screen with the same prominence.
  • Strictly necessary cookies (language preference, consent record) do not require consent but must still be listed.
  • The user must be able to change their decision later.

4. Third-party embeds

When Google Maps, a YouTube video, or a chat widget loads as the page opens, a request has already gone to a third party and a cookie has been set before the user consented.

The fix is simple: represent the embed with a cover image and load it when the user clicks. The compliance issue disappears and the page gets faster.

5. Retention periods

"We keep it indefinitely" is not an acceptable answer. Decide a reasonable period for contact form records and write it into the privacy notice.

The technical counterpart: old records actually being deleted. The written policy and the implementation have to agree.

6. Security measures

KVKK requires an "appropriate level of security" for the data. For a website, the minimum expectation is:

  • The site is served only over HTTPS.
  • Form data is re-validated on the server.
  • Browser security headers are applied.
  • Access to the admin panel is restricted and logged.

7. List your processors

Every service that touches your site's data is a processor. Most businesses never produce this list, and the privacy notice ends up incomplete.

For a typical corporate site the list looks like this:

  • Hosting provider. Where is the server, in which country?
  • Email service. Who carries the form submissions?
  • Analytics. Who collects visitor behaviour?
  • Chat widget. Where are the conversations stored?
  • Backups. Where do they sit and how long do they stay?

Read each provider's data processing terms and write them into the transfer section of your notice.

8. Can you respond to a data subject request?

What happens when someone says "delete my data"? You have a legal deadline to respond.

What you need technically is to know which systems hold that person's data. Form records sit in a database, in a mailbox, and probably in backups. A deletion that does not cover all three is incomplete.

There has to be a clear channel on the site for such requests. An email address stated in the privacy notice is usually sufficient.

9. Compliance is not a one-time task

As the site changes, so does its compliance position. When a new form is added, a new analytics tool installed, or an embed introduced, the list has to be reviewed again.

A practical habit: after every release, ask "does this change collect any new data?" If the answer is yes, the privacy notice and the cookie list need updating.

Quick check

  • [ ] The privacy notice exists and is current.
  • [ ] The form has a consent checkbox that is not pre-ticked.
  • [ ] Analytics does not load before consent.
  • [ ] Rejecting is as easy as accepting.
  • [ ] Third-party embeds do not load until clicked.
  • [ ] The retention period is written down and applied.
  • [ ] The site is served over HTTPS.
  • [ ] The list of processors has been produced and written into the notice.
  • [ ] There is a clear channel for deletion requests.

We can assess where your site stands against these items. Get in touch.

Related services

If you have a question, let us start there.

Tell us what you are trying to do. On the first call we will tell you whether we are the right fit, roughly how long it takes and how we would approach it. No sales pitch.

orsenyazilim@gmail.com