Turkey’s Personal Data Protection Authority (KVKK) adopted the principle Resolution No.2025/1072 on 10 June 2025, officially published in Official Gazette No.32938 on 26 June 2025. The resolution explicitly prohibits merchants from indirectly obtaining user marketing consent through SMS verification codes during payment, registration, membership opening and other workflows. It requires separate, explicit consent for each data processing activity and bans bundling verification code procedures with marketing authorisation.
1. Prohibition on obtaining multiple consents bundled via SMS verification codes
The resolution states that combining different data processing activities (such as confirming membership contracts, obtaining permission for personal data processing, consenting to receive commercial electronic communications) into a single operation via SMS verification codes constitutes an illegal act and must cease immediately.
In practice, many retail merchants request mobile numbers and SMS verification code entry from customers at checkout, claiming it is mandatory to complete transactions or issue invoices. Unbeknownst to customers, entering the verification code in effect grants consent to subsequent marketing SMS. The new rule explicitly bans this “one code, multiple purposes” practice. Merchants must set independent consent options separately for contract performance, data processing and commercial marketing.
2. Clear disclosure of the genuine purpose and consequences of SMS verification codes
Authorised personnel of data controllers must clearly and comprehensibly explain to data subjects the purpose of SMS messages sent to their mobile phones and the consequences of providing the verification code. Merchants shall not mislead consumers by presenting SMS verification codes as an “indispensable transaction step”. Verification SMS must contain sufficient information channels. If the code is only used for transaction verification, merchants must clearly inform users, and marketing consent cannot be disguised as part of the transaction workflow.
3. Marketing consent shall not be a prerequisite for accessing products or services
Data subjects shall not be forced to consent to receive commercial electronic communications as a condition for obtaining products or services. Merchants must solicit marketing consent separately after transaction completion, via SMS, paper or electronic forms. Users must be clearly notified: sharing the verification code is not required to complete purchase; products or services can be purchased even without providing the code; consent and preferences submitted via verification code can be modified at any time.
4. Administrative penalties for violations
Data controllers breaching these obligations face administrative sanctions under Article 18 of the Personal Data Protection Law. This resolution addresses existing complaints, confirms that this widespread industry practice is unlawful, and provides guidance for designing future compliance systems. Data controllers must deliver regular staff training and awareness programmes, and review existing consent and disclosure mechanisms to meet the resolution requirements.
