Article · Data Protection

Key points on explicit consent for data protection compliance

Explicit consent under Türkiye's Data Protection Law: the three elements of valid consent, why blanket consents are invalid, recording and proving consent, and the data subject's right to withdraw consent with prospective effect.

10 October 20214 dk okumaBy Mehmet Köksal · Data Protection
Köksal Attorney Partnership — data protection compliance under KVKK and the GDPR

Personal data cannot be processed without the explicit consent of the data subject where other legal bases are not applicable (Article 5(1) of the Data Protection Law). For special-category data, explicit consent is only one of the eight grounds in Article 6(3) as amended by Law 7499. Explicit consent should be freely given, specific, and informed (Article 3 of the Data Protection Law).

The definition and the three elements

Explicit consent means consent that the data subject gives on a specific matter, on the basis of having been clearly informed, and of their own free will.

Under the definition of explicit consent set out in Article 3 of the Law, explicit consent has the following three elements:

• It relates to a specific matter.
• It is based on the data subject having been informed.
• It is declared by free will.

Explicit consent must enable the data subject to determine the limits, the scope, the manner and the duration of the processing to which they have consented. Explicit consent must therefore contain a “positive declaration of intention” by the data subject giving it. As a rule, explicit consent may also be obtained through electronic media. The burden of proof here lies with the data controller.

Companies would be prudent to both record and retain consents, either in writing or electronically.

Why blanket consents are invalid

General consents that are not limited to a specific matter and the relevant transaction are treated as “blanket consents” and are legally invalid. For example, consent statements that indicate no specific matter or activity — such as “all kinds of commercial transactions, banking transactions, and data processing activities” — may be regarded as blanket consents.

Giving explicit consent is a right strictly personal to the data subject, and the data subject may withdraw it. Since the data subject has the right to determine the future of their personal data, consent may be withdrawn at any time. Withdrawal takes effect prospectively, however: all processing carried out on the basis of explicit consent must be stopped by the data controller from the moment it learns of the withdrawal.

A practical checklist

When reviewing existing consent wording, the three elements above translate into a practical checklist (as of July 2026):

  • Legal basis first: can the activity rest on one of the other legal bases in the Law? Explicit consent applies where the other bases are not available, and the question must be answered separately for each processing activity.
  • Specificity: which processing activity, which data categories and which purposes does the wording cover? Broad language tied to a single tick box creates blanket-consent risk.
  • Information: what was the data subject told before consent was taken, and are the text and the date of that information retained?
  • Free will: is consent captured through a positive declaration of intention by the data subject?
  • Records: is it recorded when, through which channel and against which version of the text consent was given? Because the burden of proof lies with the controller, the record-keeping regime is decisive.
  • Withdrawal: through which channel does a withdrawal arrive, who receives it, and is the step of stopping consent-based processing defined in writing?

These points are closed out not by piecemeal fixes but by separating consent texts per processing activity: reusing one text across unrelated purposes weakens both the specificity and the information element. Keeping text versions and consent dates traceable also makes withdrawal requests far easier to act on.

For support in designing consent flows and keeping demonstrable consent records, see our KVKK/GDPR compliance programme.

This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Mehmet Köksal

Author

Mehmet Köksal

Founder and Managing Partner

Combining legal practice with academic work since 1987, Prof. Dr. iur. Mehmet Köksal advises on corporate and commercial law, contracts, employment, foreign direct investment, ESG and supply-chain due diligence, dispute resolution, consumer law and family law.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all
Knowledge Centre

Get a legal assessment on this matter.

Get in touch with our team for an assessment of your specific situation.