Skip to content
Symmetric Metro Internet: equal download and upload up to 10 Gbps
Erbe Bilişim
KVKK & Compliance

How to Prepare a KVKK Privacy Notice: Elements and Checklist

Learn how to prepare a KVKK privacy notice under Turkey's Article 10: mandatory elements, seven common mistakes, and a ready-to-use checklist.

  • Erbe Bilişim Uzman Ekibi
  • 7 min read
KVKK & Compliance category cover — a sealed document icon on a dark navy background

If your company collects personal data from anyone in Turkey, a single document decides whether that collection is lawful from the very first second: the privacy notice. Picture a prospective client filling in your contact form on a Thursday afternoon, then noticing that nothing explains what data you gather or why. They file a complaint with the data protection authority. Thirty days later, an information request lands on your desk. This guide helps foreign and local companies operating in Turkey build a privacy notice that survives that scrutiny, without learning the rules the hard way.

What a Privacy Notice Is Under KVKK Article 10

KVKK is Turkey's Personal Data Protection Law (Law No. 6698). A privacy notice, or aydınlatma metni, is the document through which a data controller informs the data subject at the moment personal data is collected. Article 10 makes this disclosure mandatory. In plain terms: it is the first and non-negotiable step of any lawful data processing in Turkey.

The obligation is triggered at the point of collection. When someone completes a form, signs a contract, or calls a support line, they must learn who the controller is and why the data is being processed. This is independent of consent; it happens in every case.

For foreign companies, two points often cause surprises. First, the notice is required across every channel, not just the website: job applications, CCTV recording, delivery logistics, and loyalty sign-ups all fall under the same rule. Second, the burden of proof sits with the controller. Saying "we informed them" is not enough; you must be able to show when and how the notice was presented. Time-stamped records for web forms and signed copies for physical processes are practical safeguards.

A frequent confusion is between the disclosure obligation and explicit consent. The privacy notice is always required. Explicit consent is needed only when no other legal basis applies. That distinction is the most critical point of the whole process. We map the wider framework step by step in our KVKK compliance roadmap. The full text of Article 10 is available through the Turkish Legislation Information System.

Mandatory Elements Your Notice Must Contain

A privacy notice is not free-form text. The law lists the elements it must include. If even one is missing, the notice may exist on paper yet still fail to meet the obligation.

Mandatory elementWhat the notice must state
Identity of the data controllerCompany name and, where relevant, its representative
Purpose of processingThe specific purpose the data is used for
Transfer informationTo whom and for what purpose data is shared
Collection method and legal basisHow and under which legal basis data is gathered
Rights of the data subjectApplication rights under KVKK Article 11

The data controller is the natural or legal person who determines the purposes and methods of processing. This identity must be clearly visible so the data subject knows whom to contact. When special categories of data are involved (health, religion, or biometric data), the notice must be written with even greater care, showing the purpose and legal basis explicitly.

Keep the language plain. Replace dense legal phrasing with wording an average reader understands, and keep the notice separate from any explicit-consent form. The official Personal Data Protection Authority publishes decisions and sector guidance worth reviewing.

Seven Common Mistakes

Across compliance projects, most privacy notices contain at least one of the following errors. Their common thread is treating the notice as a formality, when it is in fact one of the first documents examined during an audit or complaint.

  1. Merging notice and consent. Combining two distinct documents into one weakens both.
  2. Using a generic template. A copy-paste notice from the web never reflects your real processes.
  3. Omitting transfer recipients. Failing to name the vendors and bodies receiving data is a frequent gap.
  4. Leaving purposes vague. Phrases like "as required by business processes" do not count as concrete purposes.
  5. Presenting the notice too late. Disclosure must appear at the moment of collection, not afterward.
  6. Writing in unreadable language. Overly technical, long sentences defeat the purpose of informing.
  7. Never updating the notice. When a process changes, an outdated notice invalidates compliance.

Most of these are human rather than technical. If the employee running a form does not know when to show the notice, even the best document is useless. For that reason, our security awareness training is designed to cover KVKK processes as well, so the team that presents the notice is prepared alongside the notice itself.

Websites, Cookies, and Mobile Apps

The website is where the disclosure obligation is most often overlooked. Contact forms, membership sign-ups, and newsletter subscriptions all collect personal data, and each needs an accessible notice link at the relevant point. A single text buried on one page, which nobody reaches, is not enough.

Cookies are a separate dimension. Analytics and marketing cookies can process personal data, so the site should carry a cookie policy and a consent mechanism for non-essential cookies. A cookie banner offering only an "accept" button is a commonly criticised practice.

Mobile apps follow the same rule. On first launch, the user should learn which data is collected and under which permissions. Providing separate notices for location, contacts, and device identifiers prevents later complaints. The most frequent gap we find during setup projects is a missing notice link right next to the form. A small link prevents a large risk, and the technical security of the site hosting those forms is part of the same picture, as we detail in our website security guide.

A Pre-Publication Checklist

Run through this list before publishing any privacy notice. If you can answer "yes" to every item, the notice meets the core obligation.

  • Is the controller's identity and contact information clearly stated?
  • Is each processing purpose concrete and understandable?
  • Are the transfer recipients and transfer purpose shown?
  • Are the collection method and legal basis explained?
  • Are all rights under KVKK Article 11 listed in full?
  • Is the notice presented at the exact time and point of collection?
  • Is the language plain enough to grasp on first read?
  • Is someone responsible for updating the notice when processes change?

Once these are complete, the registry obligation may follow. We walk through it screen by screen in our VERBİS registration guide. Revisiting the checklist at regular intervals keeps the notice current in practice, not just on paper.

Conclusion

A privacy notice is a small but decisive part of KVKK compliance. Its mandatory elements must be complete, its language plain, its timing correct, and its content refreshed as processes evolve. Treat it not as an isolated file but as a living output fed by your data inventory: as the inventory updates, the notice stays current on its own. Avoiding the seven common mistakes and following the checklist removes most of the risk from the start. To place your notices inside a proper compliance framework, explore our KVKK & ISO 27001 compliance consulting and begin with a gap analysis.

Frequently Asked Questions

Is the privacy notice the same document as an explicit-consent form?

No, they are different documents and should never be merged. The privacy notice is always mandatory and exists to inform the data subject. Explicit consent is an approval collected only when no other legal basis applies. Combining them into one text leaves both the disclosure and the consent legally fragile, so preparing them separately is the most robust approach.

Where on my website should the privacy notice appear?

The notice must be accessible at every point where personal data is collected. Place a notice link right next to the contact form, membership sign-up, and newsletter subscription. A dedicated privacy or KVKK page collecting all notices helps too. A single link buried in the footer is usually insufficient, because it is not shown at the moment of collection.

What is the penalty for not preparing a privacy notice?

Failing to meet the disclosure obligation is a separate violation subject to administrative fines under KVKK. Fine amounts are revised each year according to the official revaluation rate. Beyond the monetary penalty, an incomplete notice causes reputational harm during a complaint or audit. Follow the current thresholds through the Personal Data Protection Authority's announcements.

Tags

  • privacy notice
  • kvkk
  • data controller