A public announcement published on 21 July 2026 by Turkey’s Personal Data Protection Authority (KVKK) targets a habit that has become standard practice in marketing: adding contact details collected through referral, recommendation or brand ambassador programs to a marketing list without ever asking their owner. Any company selling through call centers or running “refer a friend” campaigns for the Turkish market should put this announcement on this week’s agenda.
What the Authority said
The complaints reaching the Authority share a pattern: companies obtain phone numbers and email addresses from existing customers or third parties, then use them for marketing calls and SMS without informing the individuals or obtaining their explicit consent. The Board draws a clear line: the fact that data was obtained from a third party is not, by itself, a legal basis for processing it for advertising or marketing.
At the same time, the Board reminds data controllers that the legal basis must be assessed case by case; Article 5 of Law No. 6698 recognizes processing grounds beyond explicit consent. The right question is therefore not “did we get consent” but “which legal ground does this campaign rely on, and can we show that assessment in writing”.
The real break: silence is not consent
The most consequential part of the announcement is its explicit rejection of implied consent. According to the Board, the fact that a person keeps listening to a sales pitch, does not hang up, asks questions, or fails to reply “STOP” to an SMS does not amount to valid explicit consent. Explicit consent must be an affirmative declaration: specific to a defined matter, based on prior information, and freely given. Passivity does not meet that definition.
In practical terms, the “they didn’t object, so they agreed” logic that call center operations have relied on for years is no longer defensible in Türkiye.
What to do now
- Assess and document the legal basis per campaign. Do not reduce the analysis to explicit consent by default; for each campaign, record which Article 5 ground you rely on. That written assessment is your first line of defense in an investigation.
- Document the source of every contact record. For each entry on a marketing list, record where the data came from (referral program, recommendation form, brand ambassador scheme). Possession of the data is not permission to process it.
- Deliver the privacy notice on time and in full. Where data is not collected directly from the individual, the implementing communiqué on the duty to inform requires notice within a reasonable period after obtaining the data, at first contact if the person will be contacted, and at the latest at first transfer if the data will be shared. The notice must cover the controller’s identity, the purpose of processing, the recipients and purposes of any transfer, the collection method and legal ground, and the individual’s rights. This is precisely the step call centers skip in practice by opening with the pitch.
- Never log passive behavior as consent in your CRM. Update call scripts and CRM fields so that continuing to listen or failing to opt out is never recorded as consent. Explicit consent should be logged only on a separate, affirmative statement.
- Run notice and consent as separate processes. Under the communiqué these are independent obligations: notice first, then, where required, explicit consent through a distinct declaration. The Board’s February 2026 principle decision already mandated this separation; the announcement restates it for marketing.
- Test your opt-out channels regularly. Verify periodically that channels such as replying “RET” (stop) by SMS or making a verbal request during a call actually work, and that requests are actioned immediately.
The three documents an investigation asks for first
In complaints of this kind, the Board typically requests three things first: the record showing the source of the data, proof of when the privacy notice was delivered, and the record showing whether consent was obtained through a separate affirmative statement or inferred from passive behavior. If any of the three is missing, the defense is weak regardless of how solid the technical setup is. Written procedures and regular training for call center staff, accessible privacy notices, and consent logs capturing date, time, channel and the content of the declaration are what carry the burden of proof.
Sanction exposure
The announcement creates no new obligation; it clarifies how the duties already present in Articles 5 and 10 of Law No. 6698 and the implementing communiqué apply to marketing built on referred data. But the Board’s unambiguous rejection of implied consent signals a stricter review posture for complaints in this area. Violations carry administrative fines of up to TRY 17,092,242 for 2026 under Article 18.
How Vircon Legal can help
If you run referral or recommendation campaigns touching the Turkish market, we can run a rapid health check of your campaign mechanics, call scripts and CRM consent logs against this announcement and manage the remediation. Talk to our team. Related reading from our KVKK practice: KVKK’s Agentic AI Guide.
Author
-
View all postsVircon Legal'de Avukat / Associate at Vircon Legal — Venture transactions · IP and licensing · Tech-sector regulatory
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
AI in Hiring: Your Compliance Deadline Is Not December 2027 — Most of It Is Already Binding
July 15, 2026KVKK Is Already Regulating Your AI: Automated Decisions, Biometrics, Training Data
July 8, 2026The KVKK Compliance Audit: A Step-by-Step Guide to Measuring Your Data-Protection Health
June 25, 2026ChatGPT at Work: The Internal AI Use Policy That Employees Actually Follow
July 22, 2026You Are the Assistant: Generative AI at Work and KVKK
July 1, 2026The Clock Is Running: A Data-Breach Response Plan and the 72-Hour Rule
June 30, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →ICOs, Crypto & Blockchain
Crypto-asset regulation, token offerings, exchange and custody licensing.
View service →