Guide · Data Protection

Cookie banner and information notice: KVKK/GDPR dual compliance in e-commerce

Stores selling to both Türkiye and the EU have to satisfy two data protection regimes on the same site. A practical guide that combines the cookie banner, the information notice and the consent setup in a single layer.

23 June 20263 dk okumaBy Sven Köksal · Data Protection
Köksal Attorney Partnership — data, artificial intelligence, cybersecurity and legal tech work
Summary · At a glance
  • Cookie consent and the duty to inform are different obligations: one asks for permission, the other provides information — and the two are audited separately.
  • Loading non-essential cookies BEFORE consent is a violation under both the KVKK Guideline and ePrivacy — and it can be scanned from the outside.
  • If there is no “Reject” option as easy as “Accept all”, the consent may not be considered valid.
  • A single consent layer, if set up correctly, serves TR and EU traffic together; language and text variants can be selected automatically.

Two regimes, one site

If you sell to Türkiye and the EU from the same storefront, you are meeting two data protection regimes at once: KVKK + the Cookie Guideline, and GDPR + ePrivacy (in Germany, TDDDG §25). The good news: the rules largely point in the same direction — inform, obtain consent, do not load without consent. The bad news: a setup that “gets by” under one of the two regimes can produce a violation under the other.

Practical guidance

Quick test: open your site in a private window and, without clicking anything, check the cookies in the developer tools. If entries such as _ga or _fbp have been set, your consent setup is in violation.

Let’s build your consent layer correctly

We prepare the cookie inventory, the banner setup, the information notice and the policy set in a single project — in three languages: TR/DE/EN.

Request a preliminary assessment

Information notice: the obligation to inform

Under KVKK Art. 10, the identity of the data controller, the purposes of processing, the legal ground, the recipients, the method of collection and the data subject’s rights must be presented — alongside forms and sign-up flows, in a layered and accessible form. The practical standard in e-commerce is the trio of a general notice + a short notice under each form + a cookie policy. On the GDPR side, Art. 13 serves the same function; a single text can satisfy both regimes.

Everything other than strictly necessary cookies (session, cart, security) — analytics, marketing, personalisation — is subject to prior consent. Valid consent has three conditions: prior (before loading), freely given (rejecting is equally easy) and informed (per purpose and per tool). The formula “by using this site you are deemed to have accepted” is invalid under both regimes.

How does it look from the outside?

Consent violations can be scanned technically: _ga/_fbp cookies set before the banner appears, designs without a reject button, dark-pattern banners (hiding the reject option). That is why the cookie setup is the second item in our outside-in scan and is raised increasingly often in German cease-and-desist practice.

A single-layer dual-compliance setup

The architecture we recommend: (1) a tool-based cookie inventory; (2) consent management split into categories (necessary/analytics/marketing) with text and language variants by geography; (3) retention of consent records; (4) a consistent trio of information notice + cookie policy + privacy policy; (5) an inventory refresh every three months. This setup also closes step 4 of the GDPR roadmap.

Five common mistakes

(1) There is a banner, but the cookies load first; (2) the reject button is hidden in the second layer; (3) the information notice appears only on the homepage; (4) no consent records are kept — the burden of proof is forgotten; (5) an English template text is shown to TR traffic. The common result of all five: compliance on paper, violation in practice.

Conclusion

The cookie and notice layer is the shop window of data compliance: if it is incomplete, the inside is assumed to be incomplete too. A single, correctly built layer satisfies KVKK, GDPR and marketplace reviews at the same time. For the setup, see our KVKK/GDPR programme; for the transfer dimension, see our KVKK legislation record.

This content is intended for general information purposes and does not constitute legal advice. For an assessment of your specific situation, please contact our team.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all

Keeping them separate is the cleanest solution: the information notice carries the mandatory elements of KVKK Art. 10, while the cookie policy provides tool-level detail. The banner should link to both.

If there are no cookies requiring consent, a consent banner is not required either; but the obligation to inform continues, and the question “is it really only strictly necessary?” must be verified with a technical inventory.

Not on its own: a correctly configured consent management platform + Consent Mode + the text set are required together. In a faulty setup, data keeps flowing without consent.

Knowledge Centre

Let’s build your consent layer correctly

We prepare the cookie inventory, the banner setup, the information notice and the policy set in a single project — in three languages: TR/DE/EN.