Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
EU personal data protection law, which is the source of inspiration for Turkish personal data protection law in general and for Law No. 6698 on the Protection of Personal Data (KVKK) in particular, has recently gone through an important process of reform. Directive 95/46, which formed the backbone of the Union’s personal data protection law, was replaced by the General Data Protection Regulation No. 2016/679 (GDPR). The GDPR is a text that adopts and maintains the main principles laid down in Directive 95/46. On certain matters, however, it has introduced more detailed rules in order to be more in line with present-day requirements and to meet the new needs created by new technologies. The GDPR’s rules on consent should also be considered in this context.
Consent, which is among the most fundamental concepts of personal data protection law, gives legal legitimacy to the processing of personal data. In personal data protection law, the processing of data is prohibited unless there is a legal ground, in other words a ground of lawfulness. From this point of view, therefore, the non-processing of personal data is the rule and their processing is the exception. Against this general prohibition, the consent of the data subject, that is, his or her approval of the processing of his or her personal data, constitutes a general exception or a general ground of lawfulness. For this reason, “consent” is a concept whose scope and meaning must be examined and understood well. Although Directive 95/46 was repealed when the GDPR entered into force, the earlier acquis on the concept of consent remains valid.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
The Concept of Consent in the EU General Data Protection Regulation and the KVKK
(This information note has been prepared on the basis of the Article 29 Working Party’s “Guidelines on consent under Regulation 2016/679” of 10.4.2018)
Introduction
EU data protection law, which is the source of inspiration for Turkish data protection law in general and for Law No. 6698 on the Protection of Personal Data (KVKK) in particular, has recently undergone an important process of reform. Directive 95/46, which formed the backbone of the Union’s data protection law, was replaced by the General Data Protection Regulation 2016/679 (GDPR). While the GDPR is a text that adopts and maintains the main principles laid down by Directive 95/46, it has introduced more detailed rules on certain matters in order to be more in keeping with present-day requirements in the face of the new needs created by new technologies1. The GDPR’s provisions on consent must also be considered in this context.
Consent, which is among the most fundamental concepts of data protection law, confers legal legitimacy on the processing of personal data. In data protection law, the processing of data is prohibited unless there is a legal ground, in other words a ground of justification. From this point of view, therefore, the non-processing of personal data is the rule and their processing the exception. In the face of this general prohibition, the existence of the data subject’s consent, that is, his or her approval of the processing of his or her personal data, constitutes a general exception or a general ground of justification. For this reason “consent” is a concept whose scope and meaning must be carefully examined and understood.
Although Directive 95/46 was repealed upon the entry into force of the GDPR, the former acquis on the concept of consent remains valid. For the concept of consent was first regulated by Directive 95/46 along the same lines as in the GDPR (albeit in greater detail in the GDPR). Accordingly, the case law on the concept of consent in Union law and the recommendations and opinions of institutions and commissions also remain valid2.
1. The Problem of the Name of the Concept
In Directive 95/46 the concept is designated as “consent”, but it is used together with the condition of being “unambiguously given”. Since this usage also expresses the quality that consent must possess and the conditions it must satisfy in order to be valid, the concept is frequently referred to in EU data protection law as “unambiguous consent”. The GDPR, by contrast, has used the concept simply as “consent” and has preferred to regulate separately the qualities that consent must possess and the conditions it must fulfil.
With regard to special categories of personal data, Directive 95/46 speaks of the condition of “explicit consent”. The GDPR, too, has continued to use the concept of “explicit consent” with regard to special categories of personal data. In addition, the GDPR speaks of the condition of “explicit consent” with regard to data that are to be transferred abroad and data that are to be subject to automated decision-making.
In the KVKK, which was drafted under the inspiration of EU law and in particular of Directive 95/46, the expression “explicit consent” (açık rıza) is, by contrast, always used for the concept of consent. Whereas both the Directive and the GDPR require a qualified form of consent (açık rıza/explicit consent) for special categories of personal data, in the KVKK there is no separate and different type of consent for special categories of personal data, because “açık rıza” is used as the general name of the concept3. In other words, the distinction between “consent” and “explicit consent” in EU data protection law and the emphatic expression “unambiguous consent” have been abandoned, and a single concept, “açık rıza”, has been adopted as the equivalent of all of them.
The point that may give rise to conceptual confusion here is the question of the equivalent in EU law of the concept of “açık rıza” in Turkish law. Although Article 3 of the KVKK, headed “Definitions”, gives a definition of açık rıza, this definition, which again explains consent by means of consent, is hardly a helpful guide4. For according to the definition given there, açık rıza means “consent that relates to a specific matter, is based on information and is declared of one’s free will”. According to this definition, “açık rıza” is not the exact equivalent of any of the concepts in EU law. Linguistically, the expression “açık rıza” corresponds to the concept of “explicit consent”. Where a distinction has to be drawn between the concepts, “açık rıza” should be translated as “explicit consent”. Leaving the activity of translation aside, however, when the legislation and the concepts attached to it are compared, the expression “açık rıza”, which appears in the KVKK as the only type of consent, is the equivalent of “consent”, of “unambiguous consent” and of “explicit consent” alike. At this point it would not be wrong to say that the expression “açık rıza” used in our legislation is not very clear and is liable to cause conceptual confusion.
Another potential problem to which the expression “açık rıza” may give rise in comparative law studies is that it is the Turkish equivalent not only of “explicit consent” but also of “open consent”. Yet “explicit consent” and “open consent” are entirely different concepts with almost opposite meanings. “Open consent” denotes the data subject’s general consent that is not directed at concrete purposes, and it is not a valid type of consent from the standpoint of data protection law5. The expressions “genel rıza” (general consent) or “beyaz rıza” (blank consent) should be used as the Turkish equivalent of the concept of “open consent”, which is also called “general consent” (genel rıza), “broad consent” (geniş rıza) or “blanket consent” (battaniye rıza), and the expression “open consent” should on no account be used as the English equivalent of the concept of “açık rıza” in Turkish law.
As can be seen, the three basic texts (Directive 95/46, the GDPR and the KVKK) have each adopted different expressions for the concept of consent. Moreover, the meanings that each of them attaches to these concepts also differ. For example, the concept of “consent” in the GDPR proposes a more qualified consent than the concept of “explicit consent” in Directive 95/46. Since the main subject of this study is the GDPR, the terminology used there will be taken as the basis. At the end of the study there is a table that compares the concepts of consent in these three different texts.
2. Valid Consent under the GDPR
According to the definition in Directive 95/46: “consent means the consent, obtained freely and after information has been provided, that signifies the data subject’s agreement to the processing of personal data relating to him or her.” According to Article 4 of the GDPR, headed “Definitions”: “consent of the data subject is a freely given, specific, informed and unambiguous indication by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”
As can be seen, the GDPR’s definition of consent, although more developed, is similar to that of the Directive. However, particularly in the light of Article 7 on the validity of consent and of the explanations in the recitals at the beginning of the text, it is apparent that the GDPR’s concept of consent is a new and advanced one, which is revocable and under which control lies clearly with the data subject.
According to the definition in Art. 4(11) GDPR, the conditions of valid consent are as follows:
- Freely given,
- Specific,
- Informed (based on information), and
- An indication by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
2.1. Freely given
“Freely given” means that the data subject makes a genuine choice and has control. If the data subject has no genuine choice, feels compelled to consent or feels that he or she will suffer negative consequences if he or she does not consent, the consent is invalid6. Consent that is included among general terms and conditions as a non-negotiable option is deemed not to have been freely given. Accordingly, there is no freely given consent unless the data subject is able to refuse or withdraw consent without any detriment7.
In line with this, the processing of data by public authorities and employers on the basis of explicit consent is rejected in principle, and requesting consent “bundled” with or “tied” to contractual terms is regarded as a ground of invalidity8. Furthermore, where a processing activity serves more than one purpose, it is required that the data subject have the option of giving or refusing consent separately for each of those purposes9. The burden of proving that the data subject was in free circumstances when giving consent and gave it without any detriment lies with the controller10.
For example, where a bank obtains, as part of the service contract it concludes with its customers, consent to the sharing of the customer’s payment details with third parties for marketing purposes, one cannot speak of freely given consent. Consent to this processing activity, which is not directly necessary for the banking service that is the subject of the contract, has been obtained tied to and bundled with the banking service contract. Moreover, if the customer does not consent, he or she will be unable to use the banking services. Consent obtained in this way is invalid because it does not satisfy the condition of being freely given.
2.2. Specific
Article 6(1)(a) expressly states that the data subject’s consent must be given “for one or more specific purposes”. An important point emphasised by the text here is, as we have stated above, that there is a right to choose among these purposes. The requirement that consent be “specific” serves to guarantee a degree of control and transparency for the data subject11. Article 5(1)(b), under the heading “Principles relating to processing of personal data”, states that personal data shall be “collected for specified, explicit and legitimate purposes and not processed in a manner that is incompatible with those purposes”. The fact that the condition of being “specific” is required here in addition to the principle of purpose limitation is intended to provide a safeguard against the gradual widening over time of a purpose for which consent has been given12. To put it more concretely, the controller must provide separate and clear information for each separate purpose and must obtain consent by offering a separate consent option for each separate purpose.
For example, a service provider offering cable television services must state its purposes specifically when processing its customers’ personal data concerning their viewing preferences, and must obtain consent in that manner. Where there is more than one purpose, such as suggesting newly released films that may interest its customers and sharing these data with third-party service providers for other services that may interest them, it is essential that these purposes be stated separately, even if they are close and similar to one another in subject matter. Otherwise, consent obtained for a “catch-all” purpose such as “suggesting products and services that may be of interest”, intended to cover both purposes, is not valid because it is not specific.
2.3. Informed (based on information)
For consent to be informed, it is essential that, before consent is obtained, the data subject be informed of what he or she is agreeing to and of his or her rights. If the controller does not provide the necessary information in an accessible form, the data subject’s control becomes illusory and deceptive, and consent obtained in this way is invalid.
For consent to be informed, the data subject must be informed of certain basic matters that will affect his or her decision. These are13:
- The identity of the controller,
- The purpose of each processing activity for which consent is sought,
- What (type of) data will be collected and used,
- The existence of the right to withdraw consent,
- Where the data are to be subject to automated decision-making, information on this,
- In the case of transfer abroad, the risks that may arise in the absence of an adequacy decision and of the necessary safeguards.
The GDPR contains no absolute standard as to the manner in which information must be provided. However, Article 7(2) and Recital 32 in particular have introduced numerous conditions for informed consent and have led to a higher standard as regards the clarity and accessibility of information. Accordingly, information must always be given in clear and plain language; it must not be smothered in legal terminology or hidden among other matters. Consent requested in connection with a contract (a physical document) must be independent of and separate from the other contractual documents. Consent obtained online must likewise be clear and separate and must not form part of the general privacy policy.
The manner and the degree of detail in which information is to be provided must be determined according to the controller’s field of activity and the profile of the data subjects addressed. A controller wishing to be sure that it has fully and correctly discharged its responsibility in determining the scope, method and language of appropriate information may test, by means of a voluntary survey, whether the information is understandable and accessible. Information may also be layered. For example, where, in the case of consent obtained online, the page displayed at the first stage, that is, when consent is given, does not explain in detail how the controller can be contacted but offers a link through which that information can be accessed, there is informed and valid consent, provided that the link in question is noticeable.
2.4. Unambiguous indication of wishes
Consent may be given by the data subject’s statement to that effect or by his or her clear affirmative action. In other words, consent must necessarily take the form of an active act or declaration on the part of the data subject. It must be evident that the data subject has consented to the specific processing activity. On this point the GDPR maintains the same approach as Directive 95/46 and clarifies the matter by expressly providing that “an unambiguous indication of wishes in the form of a statement or a clear affirmative action” is required.
Accordingly, consent will not be valid where no active conduct is involved, for example where the box for giving consent is already ticked, or where, by a notice such as “if you agree, you may continue browsing the page”, “the consequence of consent is attached” to proceeding on the current page or scrolling it. Furthermore, pursuant to Recital 40 consent must be obtained before the processing activity, and consent obtained subsequently by way of ratification has no validity.
3. Obtaining Explicit Consent
In certain situations in which the risk attached to data processing is higher, the GDPR has considered it appropriate for the data subject’s control over his or her data to be stronger and has therefore required explicit consent. The data subject’s explicit consent must be obtained for special categories of personal data under Article 9, for data to be transferred abroad under Article 49 and for data to be subject to automated decision-making processes under Article 22.
The GDPR has made the existence of “a statement or affirmative action” a precondition of “regular” consent. Given that, by comparison with Directive 95/46, the standard of “regular” consent has been raised to such an extent, the questions arise of what “explicit consent” means and of what the controller must do in order to obtain “explicit consent” under the GDPR.
That consent is “explicit” is a quality relating to the way in which the data subject expresses his or her consent. The primary way of making sure that consent is explicit is for it to be based on a written statement. Wherever possible, the controller should obtain the statement of consent with a wet-ink signature and thereby remove all possible doubt and any problems of proof that might arise in the future14.
While a statement bearing a wet-ink signature is the soundest way of obtaining explicit consent, it is not the only way. It cannot be said that the GDPR requires a written statement with a wet-ink signature for explicit consent in all circumstances. Explicit consent may, for example, also be obtained online or by telephone. In such cases, however, it must be clear that the data subject’s action is directed at giving consent, and there must always be an identity verification procedure15.
4. Additional Conditions for Valid Consent
The GDPR has also laid down additional conditions for controllers, relating to the proof and retention of consent, for the period after consent has been correctly and properly obtained. These conditions, set out in Article 7, also apply to the other articles concerning consent (for example Articles 8 and 9).
The first of these conditions concerns proof. Article 7(1) expressly lays down the controller’s obligation to demonstrate the existence of consent in cases where personal data are processed on the basis of consent. Recital 42 states with equal clarity that the obligation to prove consent lies with the controller. The GDPR contains no specification or limitation as to the form that such proof is to take. Accordingly, proof may be adduced by any means under the rules of evidence of the relevant national law.
Article 7(3), for its part, contains additional conditions relating to the withdrawal of consent. First of all, where data are processed on the basis of consent, the data subject has the right to withdraw his or her consent at any time and unconditionally. The data subject, who has been informed of this when giving consent, must be able to withdraw consent by accessible means. Furthermore, withdrawing consent must be as easy as giving it. It may not be possible here to withdraw consent in exactly the same way as it was given, for example by ticking a button. In any event, however, there must be proportionality between the difficulty of the process of giving consent and that of the process of withdrawing it.
Another prominent provision of the GDPR on consent concerns processing activities based on consent when children access information society services. Accordingly, in respect of data collected while children under the age of sixteen access information society services, consent is valid only on condition that it has been given or authorised by the child’s parent or guardian. Although there is no express provision here as to how parental consent is to be obtained, controllers have been placed under an obligation to make efforts to verify the identity of the parent.
5. Status of Consents Obtained before the GDPR
Consents obtained under national data protection law before 25 May 2018, the date on which the GDPR took effect, are valid in so far as they comply with the GDPR. Controllers are not obliged automatically to renew all the consents they obtained before that date, but they are obliged to obtain the consents they collect after that date in full compliance with the GDPR. For example, presumed consents for which there are no records capable of proving them must be renewed. Likewise, consents obtained by means of a pre-ticked box will not be regarded as valid unless they are renewed, because they do not satisfy the condition of being expressed by affirmative action, and they will not provide a legal basis for the processing activity.
In conclusion, the GDPR has regulated the meaning and the conditions of the concept of consent in detail and has raised the standard of the concept considerably by comparison with Directive 95/46. It would not be wrong to say that processing data on the basis of consent is now far more difficult in the EU. For this reason, controllers wishing to obtain explicit consent in conformity with the GDPR and to process personal data on that basis must make comprehensive changes to their business processes and not merely to their consent forms16. Where the new conditions, such as that consent be purpose-related and specific, that it be based on a statement or an active affirmative action and that it be demonstrable by the controller, are not met, consents obtained earlier must be updated. In addition, business processes for the withdrawal of consent and for confining it solely to the purposes at which it is directed must also be put in place without fail.
TABLE: COMPARATIVE CONSENT MATRIX (GDPR – Directive 95/46 – KVKK)
Directive 95/46 GDPR
Text
Subject matter
Concept
- Personal data
CONSENT
(Consent)
- Special categories of personal data
EXPLICIT CONSENT
(Explicit Consent)
Conditions
- freely given
- specific
- informed
- unambiguously given
-Statement of consent bearing a wet-ink signature or other identity verification (in addition to the above conditions relating to consent)
Subject matter
- Personal data
- Special categories of personal data
- Transfer
abroad - Data subject to automated decision-making
Conditions
- freely given
- specific
- informed
- unambiguously given
- statement or
affirmative action - capable of being withdrawn - must be demonstrable by the controller
-Statement of consent bearing a wet-ink signature or other identity verification (in addition to the above conditions relating to consent)
KVKK
Subject matter Conditions
-none- -none-
- Personal - Specific data - Based on
- Special categories free of personal data will
- Transfer - informed to third parties
- Transfer abroad
Bibliography
Küzeci, Elif, Kişisel Verilerin Korunması, Turhan Kitabevi, Ankara, 2019, s. 193.
Braun, Cihan Avcı “Kişisel Verilerin İşlenmesinde Rıza”, YÜHFD, C.XV, 2018/1, s.13-33.
Article 29 Working Party Guidelines on consent under Regulation 2016/679, Adopted on 28 November 2017 As last Revised and Adopted on 10 April 2018.
Hallinan, Dara / Friedewald, Michael, “Open consent, biobanking and data protection law: can open consent be ‘informed’ under the forthcoming data protection regulation?”, Life Sciences, Society and Policy (2015) 11:1 DOI 10.1186/s40504-014-0020-9.
Article 29 Working Party Opinion 15/2011 on the definition of consent, adopted on 13 July 2011, (WP
Footnotes
- Elif Küzeci, Kişisel Verilerin Korunması, 3. Bası, Turhan Kitabevi, Ankara, 2019, s. 193. ↑
- Article 29 Working Party Guidelines on consent under Regulation 2016/679, Adopted on 28 November 2017 As last Revised and Adopted on 10 April 2018, s. 3. ↑
- Murat Volkan Dülger, Kişisel Verilerin Korunması Hukuku, Hukuk Akademisi, İstanbul, 2019, s. 220. ↑
- Cihan Avcı Braun, “Kişisel Verilerin İşlenmesinde Rıza”, YÜHFD, C. XV, 2018/1, s. 19. ↑
- Dara Hallinan / Michael Friedewald, “Open consent, biobanking and data protection law: can open consent be ‘informed’ under the forthcoming data protection regulation?”, Life Sciences, Society and Policy (2015) 11:1 DOI 10.1186/s40504-014-0020-9, s. 16. ↑
- Article 29 Working Party Opinion 15/2011 on the definition of consent, adopted on 13 July 2011, (WP 187), s. 12. ↑
- GDPR, Recitals 42 and 43; Article 29 Working Party Opinion 15/2011, s. 12. ↑
- GDPR, Recitals 42 and 43. ↑
- GDPR, Recitals 32, 42 and 43. ↑
- Article 29 Working Party Guidelines on consent under Regulation 2016/679, s. 11. ↑
- Article 29 Working Party Guidelines on consent under Regulation 2016/679, s. 12. ↑
- Article 29 Working Party Opinion 15/2011, s. 12. ↑
- Kaniz Fatema / Ensar Hadziselimovic / Harshvardhan Pandit / Christophe Debruyne / Dave Lewis / Declan O’Sullivan, “Compliance through Informed Consent: Semantic Based Consent Permission and Data Management Model”, Proceedings of the 5th Workshop on Society, Privacy and the Semantic Web - Policy and Technology (PrivOn2017), Vienna, Austria, October 22, 2017, s. 11. 187). Dülger, M. Volkan, Kişisel Verilerin Korunması Hukuku, Hukuk Akademisi, İstanbul, 2019. Fatema, Kaniz/Hadziselimovic, Ensar/Pandit, Harshvardhan/Debruyne, Christophe/ Lewis, Dave / O’Sullivan, Declan, “Compliance through Informed Consent: Semantic Based Consent Permission and Data Management Model”, , Proceedings of the 5th Workshop on Society, Privacy and the Semantic Web - Policy and Technology (PrivOn2017), Vienna, Austria, October 22, 2017. ↑
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
