Cookie Consent in Turkey: KVKK, GDPR and Google Consent Mode v2 — a Practical Guide (2026)

Cerezgo Editör Ekibi
Cerezgo — KVKK Uyumlu Çerez Yönetim Platformu

TL;DR: If your website serves users in Turkey, GDPR compliance alone is not enough. Turkey’s data protection law (KVKK) has its own cookie consent requirements, its own regulator (the KVKK Board), and administrative fines of up to TRY 17,092,242 in 2026. This guide covers what KVKK requires beyond GDPR, how Google Consent Mode v2 fits in, and a step-by-step implementation checklist.

Who needs to comply with KVKK cookie rules?

KVKK (Law No. 6698 on the Protection of Personal Data) applies to any organization processing personal data of individuals in Turkey — regardless of where the company is established. If your site sets analytics or marketing cookies for visitors from Turkey, you fall within scope. This includes foreign e-commerce companies shipping to Turkey, SaaS products with Turkish users, and publishers with Turkish traffic.

KVKK vs GDPR: the five differences that matter for cookies

TopicGDPR / ePrivacyKVKK
Legal basis for tracking cookiesOpt-in consentExplicit consent (açık rıza), opt-in
Information noticePrivacy notice, any official EU languageTurkish-language aydınlatma metni following the DPA’s required content
Regulatory guidanceEDPB guidelines, national DPAsKVKK Board’s Cookie Practices Guideline (2022)
Proof of consentDemonstrable consentDemonstrable, auditable records; burden of proof on the data controller in local audits
2026 finesUp to €20M / 4% global turnoverTRY 85,437 to TRY 17,092,242 per violation type (updated by 25.49% revaluation, effective 1 Jan 2026)

What the KVKK Cookie Guideline actually requires

The Turkish DPA’s Cookie Practices Guideline sets concrete expectations: non-essential cookies must not run before consent; “Accept” and “Reject” must be equally prominent (no dark patterns); cookie walls and pre-ticked boxes are invalid; consent must be as easy to withdraw as to give; and a layered, accessible Turkish information notice must describe each cookie category, purpose and retention period. A KVKK-focused consent setup builds these rules in by default.

Google Consent Mode v2 in the Turkish market

Since March 2024, Google requires ad_user_data and ad_personalization consent signals from advertisers targeting the EEA — and any Turkish advertiser running Google Ads toward European audiences is affected. Even for purely domestic campaigns, Consent Mode v2 is the sustainable way to keep GA4 measurement and remarketing working after consent-based blocking. Without it, conversion tracking degrades silently. See our Consent Mode v2 integration page for signal-by-signal details.

Implementation checklist

  1. Scan and classify: run an automated scan of cookies, localStorage and tags; classify into essential / functional / analytics / marketing. Re-scan on a schedule — tag setups drift.
  2. Block before consent: ensure marketing and analytics tags stay inert until the visitor opts in.
  3. Bilingual banner without dark patterns: Turkish first, equal-weight Accept/Reject, link to the cookie policy and preference center.
  4. Wire Consent Mode v2: map banner choices to Google’s four consent signals; test with Tag Assistant.
  5. IAB TCF 2.2 if you monetize with programmatic: vendor-level consent for publishers — see our TCF 2.2 support.
  6. Keep auditable records: timestamped consent logs, searchable by date/IP/status, exportable for the regulator.
  7. Publish and maintain a cookie policy: inventory table, purposes, retention, withdrawal instructions — kept in sync with your actual tags.

Common mistakes we see in audits

The five most frequent failures: analytics firing before consent (usually GTM misconfiguration), an English-only cookie notice, “by continuing to browse you accept cookies” wording (invalid under both KVKK and GDPR), reject option hidden behind a second layer, and no exportable consent log when the regulator asks for proof.

FAQ

Does GDPR compliance cover KVKK?

No. The frameworks overlap but KVKK has its own notice format, its own guideline on cookies and its own enforcement. A GDPR-configured banner typically fails the Turkish-language and record-keeping requirements.

What are the actual fines in 2026?

Administrative fines range from TRY 85,437 to TRY 17,092,242 depending on the violation type, updated by the 25.49% revaluation rate effective 1 January 2026. Cookie violations are usually assessed as breaches of the information obligation or unlawful processing.

Do I need a Turkey-based CMP?

Not legally mandated, but local hosting, Turkish-language support and a guideline-native banner significantly reduce implementation risk. Compare options in our CMP comparison guide (Turkish).

Does consent management hurt ad performance?

Poorly configured, yes. With a well-designed banner and Consent Mode v2 modelling, most advertisers retain the bulk of their measurement; Cerezgo customers average a 78% consent rate.

How is Cerezgo different?

Cerezgo is built around the KVKK Guideline first: automated scanning, TÜBİTAK trusted-timestamped consent records, Consent Mode v2 and TCF 2.2 support, native iOS/Android SDKs, in-country hosting with an on-premise option, ISO 27001/27701 certification, and 200+ customers including major Turkish banks. Request a demo.

Cerezgo