Home/Resources/Articles/Is a Cookie Policy Mandatory? A KVKK and ePrivacy Comparative Guide
Back to Articles
Çerez Yönetimi9 min read

Is a Cookie Policy Mandatory? A KVKK and ePrivacy Comparative Guide

A cookie policy and cookie consent are not the same thing. This guide compares KVKK with the European ePrivacy approach and explains, step by step, which documents and mechanisms your website actually needs.

JUS. Hukuk Ekibi
Uyum ve Veri Koruma
April 3, 2026
Is a Cookie Policy Mandatory? A KVKK and ePrivacy Comparative Guide

When you see a cookie banner on a website, the first question that usually comes to mind is: "Is this really required, or are we doing it just because everyone else does?" For businesses operating in Türkiye, the answer requires looking not at a single regulation but at two distinct legal logics: KVKK (Personal Data Protection Law No. 6698) and the ePrivacy approach in the European Union. Although these frameworks overlap in many respects, they view cookies quite differently. In this guide we explain when a cookie policy is mandatory, how it differs from cookie consent, and which steps you should take in practice.

A Cookie Policy and Cookie Consent Are Not the Same Thing

The most common mistake is confusing a "cookie policy" with "cookie consent." These are complementary but separate elements:

  • Cookie policy (disclosure): A transparency document that explains which cookies your site uses, for what purpose, for how long, and who (first party / third party) places them.
  • Cookie consent (opt-in mechanism): The technical and legal mechanism used to obtain the user's explicit choice before non-essential cookies start running (banner, preference center, reject button).

Having a document does not mean you have obtained valid consent. Likewise, a well-designed banner does not, on its own, satisfy the transparency obligation if there is no disclosure text behind it.

Mandatory Under KVKK

KVKK does not regulate cookies by name; however, if a cookie processes personal data (for example, if it tracks an identity, device, or behavior in an attributable way), it falls directly within the scope of KVKK. In that case, two core obligations stand out:

  1. Duty to inform: The data controller must inform the data subject clearly and understandably about the personal data being processed. A cookie policy is the cookie-specific form of this obligation.
  2. Legal basis: Every cookie needs a processing basis. Strictly necessary (technically required) cookies can often rely on grounds such as legitimate interest or performance of a contract, whereas marketing and profiling cookies typically require explicit consent.

In short, KVKK makes a cookie policy indirectly mandatory: for every cookie that processes personal data, transparent disclosure and an appropriate legal basis are essential.

Mandatory Under ePrivacy (EU)

The ePrivacy approach in Europe looks at cookies more specifically than KVKK. The core principle here is: placing information on, or reading information from, a user's device requires prior consent unless it is strictly necessary. In other words, it is not only personal data but access to the device itself that is subject to consent. This distinction matters for sites that serve users in Europe in addition to the Turkish market.

Comparing the Two Frameworks

CriterionKVKK (Türkiye)ePrivacy (EU)
TriggerIf the cookie processes personal dataIf the cookie is not strictly necessary
Essential cookiesUsually no consent neededUsually no consent needed
Marketing cookiesExplicit consentPrior consent
DisclosureDuty to informTransparency obligation
RejectionMust be easyMust be as easy as accepting

As you can see, the outcome converges in practice: non-essential cookies should not run before the user consents, rejecting should be as easy as accepting, and everything should be transparently documented.

Conditions for Valid Consent

Under both KVKK and ePrivacy logic, valid cookie consent must have these characteristics:

  • Freely given: The user must not be forced to consent in order to use the site; "accept" must not be the only way out.
  • Specific: Separate choices must be available per purpose (analytics, marketing, personalization).
  • Informed: The user must clearly understand what they are consenting to.
  • Given by clear action: Pre-ticked boxes or "continued browsing counts as consent" approaches are not valid.
  • Withdrawable: The user must be able to change their preference easily at any time.

The prior blocking principle is also critical: non-essential cookies and tags must not load before the user consents.

Step-by-Step Compliance Checklist

  1. Scan your site to inventory all cookies and trackers (run a cookie scan).
  2. Categorize each cookie: essential, functional, analytics, marketing.
  3. Determine the legal basis for each category (consent or legitimate interest).
  4. Set up a mechanism that blocks non-essential cookies before consent.
  5. Present accept, reject, and customize-preferences options with equal visibility.
  6. Publish a detailed cookie policy (cookie list, purpose, duration, party).
  7. Store consent records (when, which version, which preferences).
  8. Periodically update the cookie inventory and the texts.

Example Scenario

An e-commerce site, "ModaX," uses essential cookies for cart and session management; Google Analytics to measure visitor behavior; and Meta Pixel for remarketing. ModaX first runs a cookie scan and detects 14 cookies in total. Of these, 3 turn out to be essential, 2 analytics, and 9 marketing/third-party.

ModaX runs the essential cookies without requiring consent; however, it fully blocks the Analytics and Meta Pixel tags until the user consents on the banner. On the banner, the "Accept All" and "Reject All" buttons are presented in the same size and color, and category-based selection is possible via a "Manage Preferences" link. Each consent is logged together with the date, time, selected categories, and policy version. This way, ModaX satisfies both the KVKK duty to inform and the conditions for consent.

Frequently Asked Questions

If I only use essential cookies, do I have to show a banner?

If you use only strictly necessary cookies, a consent banner is not required in most scenarios. However, it is still advisable, for transparency, to have a cookie policy that informs users which cookies you use and why.

Can the cookie policy and the privacy policy be the same document?

They can, but the cookie-specific details (cookie names, purposes, durations, parties) must be clearly stated. Most businesses prefer a separate cookie policy page linked from the privacy policy.

If a user does not consent, can I block them from using the site?

Making consent for non-essential cookies a condition of accessing the site creates a problem for valid consent, because it undermines the "freely given" principle. The core functions of the site should continue to work with essential cookies.

How long should I keep consent records?

Although the legislation does not prescribe a single period, the accountability principle means you are expected to keep them for a reasonable time long enough to prove consent. In practice, these records are kept to include preference changes and policy versions.

This content is for general information purposes only and does not constitute legal advice. With JUS., you can run a free cookie scan and make your consent management infrastructure KVKK-compliant, request a demo to get started.

Share this article

Need Help?

JUS. can help you implement best practices for compliance.

Book a Demo
Request Demo