Jump to

Explicit Consent: Marketing Permissions, Tick Boxes and Service Conditions

Explicit Consent: Marketing and Opt-In Decisions — Vircon Legal

Explicit consent is the most frequently recurring heading across the 47 decisions reviewed. Read together, these five decisions show the Board applying three principles consistently: consent cannot be inferred from conduct, the provision of a service cannot be made conditional on consent, and asking for consent when a valid processing condition already exists can itself be a ground for infringement.

This article is part 5 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.

Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.

Decisions covered in this article

Explicit Consent: Marketing Permissions, Tick Boxes and Service Conditions — the decisions reviewed in this instalment.
Decision Date Subject Outcome
2026/1183 10 June 2026 Did Not Treat Silence in Referral Marketing as Consent and Imposed a Fine at the Statutory Upper Limit TRY 1,000,000
2023/1610 21 September 2023 Once Again Confirmed the Principle That a Service Cannot Be Made Conditional on Consent Not stated in the source
2024/1350 8 August 2024 Held That a Legal Basis Does Not Legitimise the Frequency of Sending Not stated in the source
2024/1393 15 August 2024 Found a Consent Box Requested for a Processing That Was Already Lawful to Be Misleading Fine imposed (amount not stated in the source)
2024/282 22 February 2024 Penalised the Redundant Consent Clause in the Contract on the Fourth Repetition of the Same Breach Fine imposed (amount not stated in the source)

“Not stated in the source” means the summary published by the Board contains no information about an administrative fine; it should not be read as meaning that no fine was imposed.

The Board Did Not Treat Silence in Referral Marketing as Consent and Imposed a Fine at the Statutory Upper Limit

Decision no: 2026/1183  ·  Date: 10 June 2026  ·  Outcome: TRY 1,000,000

The facts

In the incident forming the subject of the application, a referral programme called “brand ambassadorship” operated by a savings finance company was examined. The purpose of such programmes is to provide a bonus or advantage in return for existing customers introducing the company to those around them. Under the programme, existing customers were able to add the name, surname and telephone number of their acquaintances directly into the company’s system through their own membership accounts; the third-party information obtained in this way was used by the company for direct marketing purposes by means of SMS and telephone calls, even though those persons had no prior relationship whatsoever with the company.

In the incident forming the subject of the complaint, a person added to the system in this way was called by the company; no information whatsoever was given to that person, either before the call or at the beginning of the call, as to who was calling, where their data had been obtained from and for what purpose it would be processed. The complainant’s remaining silent during the call, or giving a brief reaction indicating interest in the campaign, was subsequently sought to be construed by the company as a declaration of explicit consent and relied upon in its defence.

What the Board held

The Board assessed one by one the three elements of explicit consent required by the Law — relating to a specific subject, being based on information, and being declared with free will — and established that remaining silent during a telephone call, or continuing with the call, did not carry these elements.

At the centre of the assessment lies the principle that the provision of information must take place before the data processing activity and as a separate step. According to the Board, calling first and then seeking to construe the person’s reaction as consent reverses the correct order of information and consent, and is therefore not acceptable.

Why this decision matters

This decision constitutes the Board’s clearest and most recent answer to the concept of “implied consent”. In its earlier decisions the Board had stated that explicit consent cannot be made a precondition (e.g. 2023/1610) and that unnecessary consent requests may be misleading (2024/1393, 2024/282); with this decision, the door has also been clearly closed on practices under which consent may be inferred from conduct.

The fact that the upper limit of the administrative fine provided for in the Law (TRY 1,000,000) was applied in full may be read as an indication of the Board’s sensitivity on this matter. Among the decisions examined, it is one of only four examples in which this upper limit was applied in full.

What organisations should watch for

  • Companies operating referral or “recommend a friend” type marketing programmes are required to obtain separate and explicit consent before the first contact with the person recommended.
  • In marketing activities conducted by telephone or through a call centre, it is recommended that call scripts be designed so as to include the provision of information at the very beginning of the call and as a separate step.
  • Conduct such as “showing interest in the campaign” or “continuing with the call” must not be accepted as evidence of consent in internal procedures; it must be ensured that consent is obtained in writing, in a manner confirmable by voice recording, or in a digitally verifiable manner.

Vircon Legal assessment

Since the decision dates from 2026 and reflects the Board’s current approach, an increase in similar applications may be expected in the period ahead in sectors conducting referral/recommendation marketing (finance, insurance, real estate, e-commerce), and this decision may be expected to be cited frequently as a precedent. This assessment is a prediction made by us and is not based on any official statement by the Board.

The Board Once Again Confirmed the Principle That a Service Cannot Be Made Conditional on Consent

Decision no: 2023/1610  ·  Date: 21 September 2023  ·  Outcome: Not stated in the source

The facts

In the incident under examination, it was established that access to the “live match broadcast” service offered by an online sports betting and games of chance platform was made conditional on the user consenting to the sending of commercial electronic messages (marketing communications such as SMS, e-mail and push notifications). In the user interface, access to the broadcast service could not be obtained without the relevant consent box being ticked; in other words, the user was compelled to agree to marketing communications even when they merely wished to watch a sports match.

The complainant argued that this practice effectively forced them to consent to marketing communications, failing which they would be deprived of a fundamental content feature offered by the platform.

What the Board held

The Board established that the element of explicit consent requiring it to be “given with free will” was undermined by making the use of the service conditional on that consent, and that the data processing was therefore carried out without relying on any of the processing conditions set out in Article 5 of the Law. (Although certain earlier decisions of the Board — for example 2019/82, 2019/198, 2019/206, 2021/389 — were cited by the parties in the complaint petition and in the data controller‘s defence, the Board did not separately refer to those decisions in the reasoning of its own decision.)

The Board characterised the processing of data without a valid processing condition as a “failure to take the necessary technical and administrative measures to prevent the unlawful processing of personal data” within the scope of subparagraph (a) of paragraph (1) of Article 12 of the Law, and decided accordingly.

Why this decision matters

In confirming the principle that explicit consent cannot be made a precondition for a product or service, the decision is a current application of the Board’s consistent approach on this matter and leaves companies no room for the question “is a different interpretation possible on this point”.

What organisations should watch for

  • The provision of a service and consent to marketing/commercial messages are required to be structured as steps independent of one another, both in the user interface and in the contract text.
  • It is recommended that single-box designs of the “I accept in order to continue” type be reviewed as to whether they cover the main function of the service and marketing permission together.

Vircon Legal assessment

Read together with decisions 2024/1393 and 2024/282 addressed below, this decision shows that the Board’s approach to “seeking consent in addition where a valid processing condition already exists” has become even clearer over the years and has turned into a recurring head of review.

The Board Held That a Legal Basis Does Not Legitimise the Frequency of Sending

Decision no: 2024/1350  ·  Date: 8 August 2024  ·  Outcome: Not stated in the source

The facts

In the incident under examination, the complainant, a subscriber of an electronic communications (GSM/satellite) operator, submitted a refusal request to the company for the cessation of marketing SMS messages. According to the complainant’s allegation, despite the refusal request the company continued to send marketing SMS messages with the same content at frequent intervals; the examination established that more than 20 messages with similar content had been sent within a short period.

As a separate matter, the examination also established that the company had placed its explicit consent text not as a standalone document but scattered within the lengthy text of the subscription contract in a manner difficult to notice.

What the Board held

While accepting that the legal basis for the messages (an obligation arising from legislation within the scope of Article 5(2)(ç)) was in itself lawful, the Board emphasised that this basis cannot be used without limit and without the frequency of sending being subject to review.

In the assessment, it was concluded that messages sent at frequent intervals and with the same content were contrary to the rule of good faith under Article 4(2)(a) and amounted to the exercise of a right contrary to its purpose.

Why this decision matters

This decision is a relatively new and important approach in that it shows that the Board does not limit its power of review solely to the question of “is there a legal basis or not”, and that even a processing activity with a lawful basis may additionally be reviewed in terms of proportionality and good faith. The defence of “I have a legal basis” is no longer regarded as sufficient on its own.

What organisations should watch for

  • It is required to ensure that messages to persons who have submitted a refusal request are stopped immediately at system level.
  • It is recommended that the frequency of messages with the same content be monitored and limited to reasonable intervals.
  • It must be ensured that explicit consent texts are presented separately and noticeably, without being embedded within the contract.

Vircon Legal assessment

Since it sets out a review criterion directly applicable to almost every sector that sends marketing SMS messages, e-mails or notifications, it is considered that this decision will continue to be cited in frequency/proportionality-based complaints in the period ahead.

The Board Found a Consent Box Requested for a Processing That Was Already Lawful to Be Misleading

Decision no: 2024/1393  ·  Date: 15 August 2024  ·  Outcome: Fine imposed (amount not stated in the source)

The facts

In the case at hand, the login screen of the wifi service jointly offered by an airline company and a separate company providing the in-flight internet service was examined. It was established that, on the login screen presented to passengers when they wished to connect to the internet during the flight, after entering identity/contact details (such as name and surname, e-mail address and flight information) they were required to tick a consent box worded “I accept that my information be shared with the relevant authorities and with the company”. Access to the internet service could not be obtained without the box being ticked.

The examination revealed that the service was offered within the framework of a business model jointly operated by two separate data controllers (the airline company and the internet service provider), and that both parties were able to access passengers’ identity and contact data for different purposes.

What the Board held

The Board established that the data processing in question was already lawful on other legal grounds within the scope of Article 5(2), such as the conclusion of a contract, a legal obligation and the establishment of a right, and that seeking explicit consent in addition was therefore unnecessary.

The crucial point of the assessment is that an unnecessary consent request may mislead the user into thinking “I have to give consent in order to receive the service”, and that this constitutes a breach of the rule of good faith under Article 4(2)(a). The Board carried out a separate assessment in respect of each of the two data controllers (the airline company and the internet service provider) and imposed the fine only on the internet service provider.

Why this decision matters

Read together with 2024/1350 and 2024/282, the decision constitutes the third concrete example of the theme of “seeking unnecessary explicit consent where another valid legal ground exists”, and these three decisions together point to what has now become a settled approach of the Board.

In addition, the fact that each of several data controllers involved in the provision of the same service (a business partnership/integration model) is assessed independently in terms of its own obligations is also an instructive procedural point.

What organisations should watch for

  • It is recommended that each consent box on forms and login screens be reviewed one by one as to whether it genuinely requires a separate legal basis.
  • In business partnerships where a service is jointly provided, it is required that which data is processed by which party and for what purpose, and the legal basis for that processing, be clearly separated out.

Vircon Legal assessment

It is considered that this decision provides a direct reason, particularly for companies operating digital products and platforms, to review the consent designs on their registration/login screens.

The Board Penalised the Redundant Consent Clause in the Contract on the Fourth Repetition of the Same Breach

Decision no: 2024/282  ·  Date: 22 February 2024  ·  Outcome: Fine imposed (amount not stated in the source)

The facts

In the incident subject to the Board’s assessment, a subscriber of a telecommunications company requested a change to their subscription package. In order to verify the subscriber’s identity, the company asked the complainant to produce an identity document again; when the document was not provided, it cancelled the existing service. The complainant applied to the Board, considering both the request for an identity document and the cancellation of the service to be contrary to the KVKK.

The examination also established, as a matter independent of the main subject of the complaint, that the same company had included in its standard subscription contract a separate provision in the nature of explicit consent, even though the data processing was already possible on another legal ground (an obligation arising from BTK legislation).

What the Board held

The Board found the request for an identity document and the cancellation of the service to be lawful within the framework of the relevant legislation (BTK regulations) and the legal ground of the establishment of a right, and found no grounds for action in this part.

However, it assessed the redundant explicit consent provision in the contract as a breach of the rule of good faith, on the ground that explicit consent was sought in addition where a valid processing condition already existed, and imposed an administrative fine.

Why this decision matters

This decision is the fourth example of the same theme that we identified in the period we examined — together with decisions 2023/1610, 2024/1350 and 2024/1393; this repetition is a pattern that we observed across the set of decisions we examined, and not in the text of the Board’s decision itself, and it shows how widespread the practice in question is in the sector.

What organisations should watch for

  • It is recommended that standard contract and membership texts be reviewed not individually but at the level of the draft/template, since the same defective clause may have been reflected in more than one type of contract at the same time.
  • It is required that the lawfulness of mandatory processes arising from legislation, such as identity verification, and the lawfulness of separate consent provisions added to those processes be assessed independently of one another.

Vircon Legal assessment

In showing that a single correction made at the level of the contract template can pre-empt more than one recurring breach, this decision offers companies a practical compliance priority.

Other parts of this series

The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Açık Rıza Kararları: Pazarlama İzinleri, Onay Kutucukları ve Hizmet Şartı.

For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

Considering a similar matter?See how we work on KVKK and GDPR compliance, or book a call directly.
Book a call →
Published: 18 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.