Guide · Data Protection

GDPR compliance in e-commerce: a roadmap for Turkish stores selling to the EU

Every Turkish store selling to consumers in the EU is within the scope of the GDPR — not having a company in the EU does not change the rule. From the representative to cookies, an actionable six-step compliance plan.

16 June 20263 dk okumaBy Sven Köksal · Data Protection
Köksal Attorney Partnership — data, artificial intelligence, cybersecurity and legal tech work
Summary · At a glance
  • The GDPR applies to anyone offering goods/services to persons in the EU; having your company headquartered in Türkiye does not remove you from its scope (Art. 3/2).
  • If you are not established in the EU, in most scenarios you must appoint an Art. 27 representative — this is the most frequently skipped obligation.
  • Cookie consent is a layer separate from the privacy policy: pre-consent tracking can be detected technically from the outside.
  • Data flowing from the EU to Türkiye is a “cross-border transfer”: SCC + the KVKK-side standard contract and the 5-business-day notification must be planned together.

Scope: the “it doesn’t apply to us” fallacy

The territorial scope of the GDPR (Art. 3/2) also catches sellers not established in the EU: you are within scope where an intention to target persons in the EU is apparent. The indicia are weighed together: pricing in euro, an EU delivery option, an interface in German or French through which orders can be placed, a store on EU marketplaces. Mere accessibility of your site from the EU is not enough on its own. The most expensive mistake made by stores selling from Türkiye is postponing compliance with “we’ll look at it once we set up a company in the EU”; yet marketplaces and payment institutions are already asking for proof of compliance today.

Practical guidance

The order of compliance work matters: first the data inventory, then the documents. The privacy policy of a store without an inventory describes a template, not the actual situation.

Let’s build your GDPR setup together

We set up the scope test, the representative appointment, the document set and the cookie layer in a single project — and close the KVKK side in the same matter.

Request a preliminary assessment

Step 1: Data inventory

Which data do you process, with which tools, and where? Order data, analytics, marketing pixels, e-mail tool, shipping integration, payment provider… Any text drafted before the inventory exists is fiction. The inventory is also the input for VERBİS and the transfer analysis on the KVKK side.

Each processing activity is assigned a basis: performance of a contract (orders), legitimate interest (security), consent (marketing). Your privacy policy must describe this map — together with recipient categories, retention periods and rights — according to your own operation. Copy-pasted text is obvious from the outside at first glance and is the first finding of an outside-in scan.

Step 3: Art. 27 EU representative

If you are not established in the EU and your processing is no longer occasional, you must appoint a representative in the EU. The representative’s name and address appear in your privacy policy; authorities and data subjects reach you through them. This obligation can be discharged cheaply and quickly — skipping it, however, is read as a sign that “compliance was never set up at all”.

Analytics and marketing cookies require prior consent; refusing must be as easy as accepting. Technical verification is simple: look at which cookies are set in network traffic before consent is given. The KVKK Cookie Guideline is built in the same direction — a single layer can satisfy both regimes at once. For details, see our dual-compliance guide.

Step 5: Data flow to Türkiye

Data collected from the EU flowing into your systems in Türkiye is a cross-border transfer: on the GDPR side, standard contractual clauses (SCC) and a transfer impact assessment; on the KVKK side, the standard contract introduced with the 2024 regime requires notification to the Authority within 5 business days of signature. Both regimes can be set up with a single contract set — that is precisely the subject of our transfer service.

Step 6: Breach plan and records

The 72-hour notification window is short for a company without a plan. Who detects, who decides, which records are kept — even a one-page workflow makes a difference in an audit. Records of processing (RoPA) and vendor (Art. 28) contracts complete the set.

Conclusion

GDPR compliance is the passport for selling into the EU: you pass marketplace reviews, you do not become a target for cease-and-desist letters, and customer trust increases measurably. For a mid-sized store, all six steps together are a project measured in weeks — our KVKK/GDPR compliance programme is the standard for this setup.

This content is intended for general information purposes and does not constitute legal advice. For an assessment of your specific situation, please contact our team.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all

Yes. Under Art. 3/2, if you offer goods/services to persons in the EU (with signals such as shipping to the EU, € prices or a store on an EU marketplace), the GDPR applies. In practice, enforcement operates through cooperation and marketplace checks.

No. The representative is the point of contact for authorities and data subjects in the EU; responsibility remains with you. We can set up the representative structure through our Berlin office.

If you run it before consent, yes. The correct setup means addressing the consent management layer, IP truncation/appropriate configuration and transfer safeguards (SCC) together.

Knowledge Centre

Let’s build your GDPR setup together

We set up the scope test, the representative appointment, the document set and the cookie layer in a single project — and close the KVKK side in the same matter.