Two concepts most often confused in KVKK compliance are the privacy notice and explicit consent. They are different obligations, and getting them wrong is among the top causes of sanctions. In practice many organisations collect unnecessary consent for processing that could rest on another legal basis, while others genuinely need consent but fail to obtain or document it validly. This guide separates the two clearly and shows, with examples, when each is required and how to do it correctly.
The Core Difference: Notice ≠ Consent
The privacy notice is a duty to inform that everyone processing data must fulfil (KVKK Art. 10). Whatever legal basis you rely on, you must inform the data subject before processing. In other words, the notice is always required, whether or not you also take consent.
Explicit consent is only one legal basis (Art. 5). If another basis exists (contract, legal obligation, legitimate interest, etc.), you do not need consent — and obtaining it anyway is a mistake. Unnecessary consent both misleads the user ("will I be denied service if I refuse?") and makes processing legally fragile once consent is withdrawn.
| Privacy Notice | Explicit Consent | |
|---|---|---|
| When? | Every processing | Only if no other basis |
| Approval needed? | No (one-way notice) | Yes (expression of will) |
| Withdrawable? | N/A | Yes, at any time |
When Is Consent Actually Needed?
Consent is the last resort in the ranking. First check whether the processing can rest on one of the other bases in Art. 5/2:
- Expressly provided for by law,
- Necessary for the conclusion or performance of a contract,
- A legal obligation of the controller,
- Made public by the data subject themselves,
- Necessary for the establishment, exercise or protection of a right,
- Legitimate interest, provided it does not harm the data subject's fundamental rights.
If none of these applies, consent comes into play. For example, processing an address to deliver an order rests on contract; keeping an invoice rests on a legal obligation. By contrast, marketing profiling or newsletter sending usually requires consent.
What Must a Privacy Notice Contain?
- Identity of the data controller (and representative, if any),
- The purposes for which the data will be processed,
- To whom and for what purpose it may be transferred,
- The method of collection and legal basis,
- The data subject's rights under KVKK Art. 11.
The text must be clear, plain and understandable; not buried in legal jargon. The notice should be presented at the moment of processing and in a form suited to the channel: next to a web form, spoken at a call centre, at the application stage in HR. Rather than pasting one generic text everywhere, use notices that reflect each channel's purposes and transfers.
The Three Conditions of Valid Consent
- Freely given: Without pressure or disadvantage.
- Specific: Blanket consents like "any and all processing" are invalid.
- Informed: The person must know what they consent to (which is why the notice comes first).
Additionally: pre-ticked boxes cannot be used, consent cannot be tied to a service, and it must be withdrawable at any time. Withdrawal must be as easy as giving consent; forcing users into long processes or phone calls effectively blocks withdrawal and weakens validity.
Consent for Special Categories of Data
Special categories such as health, religion, sexual life, biometric/genetic data (Art. 6) are subject to a stricter regime. If you take consent for such data, the purpose must be highly specific and additional safeguards (access restriction, encryption, separate logging) are expected. Outside cases where the law grants a specific basis (as with health data), a generic "process all my data" approval is not sufficient for special categories.
Example Scenario: Newsletter Subscription
An e-commerce site presents a pre-ticked "I want to receive campaign e-mails" box during signup, and registration cannot be completed without leaving it ticked. This is invalid consent — both for freedom and for tying to a service. The correct way: the box should be empty, and registration should complete even if it is left unticked. The user should also be able to withdraw later with a single click via the "unsubscribe" link in every e-mail. The system must record the date, scope and text shown for this consent; otherwise you cannot prove the "we obtained consent" claim in an audit.
Common Mistakes
- Merging the notice and consent into one mandatory text.
- Obtaining unnecessary consent when another legal basis exists.
- Making consent a precondition of the service.
- Not keeping consent records (date, scope, text shown).
- Making withdrawal hard, or continuing to process after withdrawal.
Checklist
- Legal basis determined for each processing activity.
- Privacy notice contains the Art. 10 elements and is plain.
- Consent obtained only where genuinely required.
- Consent boxes empty (not pre-ticked).
- Consent not tied to the service.
- Withdrawal mechanism and consent records in place.
Frequently Asked Questions
Do I need explicit consent for every processing?
No. Explicit consent is a last resort. If a basis such as contract, legal obligation or legitimate interest exists, consent is not required — and taking unnecessary consent is itself a mistake.
Can I merge the notice and consent into one text?
Do not confuse information with approval. Consent must be a separate, free and withdrawable statement; the notice is a one-way information duty. Even if both appear on one page, the consent element must be separate and optional.
What should I do with the data of a user who withdraws consent?
If consent was the sole legal basis, you must stop processing and run your erasure/destruction process. If another legal basis exists (e.g. an invoice-retention obligation), you may continue processing limited to that basis only.
How do I prove I obtained consent?
Record the date consent was taken, its scope, the version of the text shown to the user, and the method (e.g. ticking an empty box). These records are the most important evidence of valid consent in an audit.
This content is for general information only and does not constitute legal advice. With JUS. you can manage your privacy notices and consent records on a single platform — request a demo.