What is Consent?
Consent in privacy law refers to an individual’s specific, informed, and freely given agreement to data processing, serving as a legal basis under GDPR and other privacy frameworks.
Valid Consent Requirements
GDPR-valid consent must be: freely given (no detriment for refusing), specific (for each processing purpose), informed (clear information about what’s being agreed to), unambiguous (clear affirmative action), and withdrawable (as easy to withdraw as to give). Pre-checked boxes, silence, or inactivity do not constitute valid consent. Sensitive data requires ‘explicit consent’ with additional requirements.
Consent in Practice
Practical consent implementation requires: clear language explaining processing purposes, granular options (separate consents for different purposes), accessible withdrawal mechanisms, records of consent (who, when, what, how), and re-consent when material changes occur. Cookie consent has become particularly visible: most websites now use consent management platforms to comply with ePrivacy and GDPR requirements.
Limitations of Consent
Consent is one of several legal bases under GDPR and not always the right choice. Consent fatigue (excessive consent requests) reduces meaningful choice. Other legal bases (contract performance, legitimate interests, legal obligations) may be more appropriate. Many organizations over-rely on consent rather than properly mapping each processing activity to the most appropriate legal basis. Consent should be used when truly meaningful, not as default cover.
Practical notes: validity, burden of proof and withdrawal
For consent to be a valid lawful basis it must be freely given, specific, informed and unambiguous. Under the KVKK it generally takes the form of açık rıza (explicit consent) and cannot be bundled as a precondition for a service the person is otherwise entitled to receive. The data controller carries the burden of proving that valid consent was actually obtained, which is why consent flows should be logged with a timestamp, the text shown, and the version of the privacy notice in force at the time. Consent may be withdrawn at any moment, and withdrawal must be as easy as giving it; processing carried out before withdrawal stays lawful, but the controller must stop the relevant processing going forward. In practice consent is the most fragile basis: where another ground such as performance of a contract, a legal obligation or legitimate interest genuinely applies, relying on it is preferable because it is not revocable at will.
Consent versus explicit consent under the KVKK
Turkish data protection law treats plain consent (rıza) and explicit consent (açık rıza) differently. The distinction is often overlooked, but it has legal consequences.
- Form: plain consent may be implied or express; explicit consent can only be express.
- Specificity: plain consent may be general; explicit consent must relate to a specific matter.
- Information: plain consent does not require prior information; explicit consent must be based on information given to the person.
- Role under the KVKK: plain consent is not a lawful basis under Article 5; explicit consent is a lawful basis under Article 5(1) and Article 6.
The GDPR concept of consent is very close to explicit consent under the KVKK.
Other lawful bases under Article 5 of the KVKK
Explicit consent is the basis set out in Article 5(1). Article 5(2) lists situations in which explicit consent is not required, including where:
- the processing is expressly provided for by law;
- it is necessary to protect the life or physical integrity of the data subject or another person, where the data subject cannot give consent due to actual impossibility or the consent is not legally valid;
- it is necessary for the conclusion or performance of a contract;
- it is necessary for the data controller to comply with a legal obligation;
- the data has been made public by the data subject;
- it is necessary for the establishment, exercise or protection of a right;
- it is necessary for legitimate interests, provided the data subject’s fundamental rights and freedoms are not harmed.
When explicit consent is and is not needed
- Explicit consent required: marketing communications, profiling, and cross-border transfers only where there is neither an adequacy decision nor one of the appropriate safeguards in Article 9(4) (such as standard contracts or binding corporate rules) and the transfer is occasional (Article 9(6)(a)).
- Special category data: since the 2024 amendment by Law No. 7499, Article 6(3) lists explicit consent as one of several conditions, together with express provision by law, protection of life or physical integrity, data made public by the data subject, the establishment of a right, health services, and legal obligations in employment and social security. The adequate measures set by the Board must also be taken (Article 6(4)).
- Explicit consent not required: processing needed to perform a contract (for example, an address needed to fulfil an e-commerce order), compliance with a legal obligation (such as tax reporting) and legitimate interest (such as fraud detection).
Every change in a person’s consent status should be logged with a timestamp and IP address.
Sources. Regulation (EU) 2016/679 (GDPR).