Cookies are widely used to run websites and measure visitor behaviour. Because many cookies process personal data, they create obligations under KVKK and Board decisions. This guide helps you make your website compliant in 10 steps and avoid the most common mistakes.
What Is a Cookie and Why Does It Matter?
A cookie is a small text file a website stores on the visitor's device. It is used for a wide range of purposes, from innocent functions like keeping a session open to building an advertising profile by tracking users across sites. Cookies that directly or indirectly identify a person process personal data and therefore fall within KVKK.
Cookie Types and Their Relationship to Consent
Classifying cookies legally is the first step to deciding which ones require explicit consent:
| Cookie type | Example | Explicit consent required? |
|---|---|---|
| Functional | Personalisation preferences | Depends |
| Analytics | Visitor measurement, heatmaps | Yes |
| Marketing / targeting | Advertising, retargeting, social pixels | Yes |
Strictly necessary cookies are those genuinely required for the site to work. "Necessary in our view" is not enough; the test is whether the service can be delivered without the cookie.
Compliant Cookie Consent in 10 Steps
- Inventory your cookies: Use a cookie scan to detect which cookies run on your site. Most sites are unaware of their third-party cookies (ad networks, embedded videos, social buttons).
- Categorise them: Classify each cookie as necessary/functional/analytics/marketing and note its purpose.
- Apply prior blocking: Non-essential cookies must not run before the user consents. This is technically the most-skipped step of compliance.
- Offer equal choices: A "Reject" option must be as easy and visible as "Accept". Making rejection harder invalidates consent.
- Provide category-level control: Users should manage analytics and marketing separately; "accept all" must not be the only path.
- No pre-ticking: Categories requiring consent must be off by default.
- Publish a cookie policy: Explain which cookie is used for what purpose, by whom and for how long; list third-party cookies separately.
- Keep consent records: Store who consented, when and to which text/version, in a provable way.
- Make withdrawal easy: Users must be able to change their decision at any time, as easily as they gave it (a persistent "cookie preferences" link).
- Scan regularly: New cookies appear as the site changes and as plugins or ad tags are added; periodic scanning is essential.
Example Scenario: How an Ad Pixel Causes Problems
Your marketing team added a social-media pixel to measure conversions. If this pixel fires as soon as the page loads — before any choice on the banner — the visitor's data has gone to a third party before consent. This shows why prior blocking is critical: even if the banner "looks nice", there is no compliance if tags fire before consent in the background.
What Does a Compliant Banner Look Like?
A good banner uses plain language the user can understand, presents options with equal visibility, and does not create a "you can't proceed without accepting" feeling. Designs that steer the user toward "Accept" through colour, size or position (dark patterns) carry both ethical and legal risk.
Common Mistakes
- Offering the banner with an "Accept"-only button.
- Loading analytics/marketing cookies before consent (missing prior blocking).
- Failing to keep the cookie policy up to date, or never publishing one.
- Not storing consent records; having no proof of "we obtained consent" in an audit.
- Misconfiguring tools like Google Consent Mode so tags run before consent.
Checklist
- Cookie scan done and all cookies inventoried.
- Cookies split into four categories.
- Prior blocking active for non-essential cookies.
- Equal "Accept / Reject" options on the banner.
- Separate category-level consent possible.
- Cookie policy published and current.
- Consent records kept.
- Persistent "change preferences" link present.
- Periodic scanning schedule defined.
Frequently Asked Questions
Do I need consent for strictly necessary cookies too?
No. Explicit consent is generally not required for cookies that are strictly necessary for the site to work; but you should still describe them in your cookie policy.
Is consent required for Google Analytics?
Yes. Analytics cookies are in the non-essential category and must not run before the user consents.
How long should I keep consent records?
Since the burden of proof is on you, keep them for as long as the consent is valid, plus a reasonable additional period. Ideally the record includes the consent date, its scope and the version of the text shown.
Must "Accept" and "Reject" be equally visible?
In practice, yes. Hiding, shrinking or burying the reject option behind extra clicks undermines the freedom of consent and creates risk.
How often should I scan cookies?
On major site changes and whenever a new tag/plugin is added; regular (e.g. quarterly) periodic scans are also recommended.
This content is for general information only and does not constitute legal advice. With JUS. you can scan your site's cookies for free, categorise them, and set up KVKK-compliant consent management.