Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
The Law on the Protection of Personal Data (KVKK) contains no specific provision on explicit consent. The legislature merely defined explicit consent (in general terms). This led to incorrect practices, and attempts were made to correct them through the decisions of the Board and the guidelines of the Authority.
One of the most important Board decisions on explicit consent is undoubtedly the “loyalty card decision” concerning a supermarket chain. In that decision the Board stated that explicit consent cannot be made a condition of service. The subject of this study is the Board’s decision concerning an insurance company that had, once again, made explicit consent a condition of service. The study first discusses explicit consent and the requirement that it be based on free will (and, briefly, the loyalty card decision), and then assesses the decision concerning the insurance company.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
Murat Volkan Dülger* / Cansu Ceren Kahraman*
Introduction
The Law on the Protection of Personal Data (KVKK) contains no specific provision on explicit consent. The legislature contented itself with defining explicit consent (in general terms). This has led to erroneous practices, and an attempt has been made to correct these errors through the decisions of the Personal Data Protection Board and the guidelines of the Personal Data Protection Authority.
One of the most important Board decisions on explicit consent is undoubtedly the “loyalty card decision” concerning a supermarket chain. In that decision the Board stated that explicit consent cannot be made a condition of the service. The subject of this study, in turn, is the Board’s decision concerning an insurance company’s making explicit consent – once again – a condition of the service. After first discussing explicit consent and the requirement that explicit consent be based on free will (and, briefly, the loyalty card decision), we shall assess the decision concerning the insurance company.
I. Explicit Consent
Law No. 6698 on the Protection of Personal Data contains no specific provision on explicit consent. The only provision on what explicit consent is can be found in Art. 3(1)(a) of the Law, entitled “Definitions”. Under that provision, explicit consent means “consent that relates to a specific matter, is based on information and is expressed of free will”. In other words, explicit consent is consent that has the following minimum elements:
• Relating to a specific matter,
• Being based on information,
• Being expressed of free will.
Where explicit consent does not have these elements, it is not possible to speak of lawful/valid consent. In addition to these elements, explicit consent must be obtained for the processing of personal data and/or special categories of personal data if, as regards personal data, the legal grounds in Art. 5(2) of the Law1 and, as regards special categories of personal data, the legal grounds in Art. 6(3) of the Law2 are absent.
Explicit consent must, first of all, be obtained in relation to a specific matter. For example, one should not attempt to create a legal ground for the data processing activities in all business processes by means of a single explicit consent text. In practice in particular, one frequently encounters a single explicit consent being obtained for many business processes simply in order to avoid paperwork.
Before explicit consent is obtained, data subjects must without fail be informed in a lawful manner. Information should not be provided and explicit consent obtained in one and the same text; data subjects should be informed and given the option of not giving explicit consent. Otherwise, where the information notice and the explicit consent are contained in the same text, this option does not exist.
In addition, it must be ensured that explicit consent is given of free will. Arguments that vitiate the data subject’s will, such as that he or she will be dismissed or that the service cannot be provided to him or her if explicit consent is not given, must not be advanced. The decision of the Personal Data Protection Board concerning an insurance company (which will be assessed in detail below) relates precisely to this second situation.
II. The Requirement that Explicit Consent Be Based on Free Will
That explicit consent is based on free will means that the data subject gives consent without thinking that he or she will suffer a disadvantage or sustain harm if explicit consent is not given. For example, where a person working at a company gives explicit consent to the processing of his or her personal data out of fear of being dismissed, it is not possible to speak of free will. It is also sufficient for the vitiation of free will that the person is made to feel this fear (whether this can be proved is open to debate). Indeed, in practice too, whether the explicit consents given by employees are given of free will is a matter of controversy.
Another example of situations that vitiate free will is making explicit consent a condition of the service, and the Board’s decision – which forms the subject of this paper – concerns precisely that. Before examining that decision, mention should also be made, on the question of making explicit consent a condition of the service, of the Board’s precedent-setting decision of 25.03.2019, No. 2019/82, concerning the loyalty card scheme of a supermarket chain.
A supermarket chain published the following statement on its website in connection with its loyalty card, which offers the advantage of discounts and the collection of points on certain purchases of goods and services: “Please update your permission under the Law on the Protection of Personal Data. Customers whose permission is not up to date will not be able to shop at our checkouts by giving their mobile phone number, as their personal information will be erased.” Thereupon a complaint was lodged with the Authority on the ground that explicit consent had been made a condition of the service. Following the examination it carried out upon the complaint, the Board decided that the obtaining of explicit consent had not been made a condition of the service, on the ground that a customer who is not a member of the Loyalty Card Programme cannot benefit from the world of product-specific and personalised offers provided by the company, but that this in no way prevents any customer from making use of the shopping environment offered by the company.
The following important conclusion emerges from this decision of the Board: where the giving of explicit consent is made a prerequisite for the application of a discount / promotion, explicit consent has not been made a condition of the service (because the failure to give explicit consent does not prevent the service from being provided); consequently, since free will is not vitiated, the explicit consent obtained is valid and lawful (provided that it also satisfies the other elements).
III. Summary of the Decision Concerning the Insurance Company
In the complaint that forms the subject of the decision, it was stated that the data subject had applied to an insurance company, the controller, wishing to renew the health insurance policy taken out on behalf of the data subject’s family, but that the controller wished to obtain explicit consent from the data subject in order to renew the policy. Upon the application the Board carried out an examination, as a result of which it decided that the health insurance policy contains health data, which have the character of special categories of personal data; that the health data contained in the policy cannot, in accordance with Art. 6(3) of the Law, be processed without obtaining explicit consent; that the request to obtain explicit consent from the data subject therefore did not constitute a breach of the Law; and that there was no action to be taken under the Law in respect of the complaint.
IV. Assessment of the Decision
In order for health insurance policies to be drawn up and the health insurance service to be provided to individuals, not only the data subjects’ personal data falling within the categories of “Identity Information (Name, Surname, Turkish Identity Number, Date of Birth, Sex, etc.), Contact Information (Address, Telephone Number), Customer Transaction Information (Amount Payable, Number of Instalments, etc.)” but also their special categories of personal data falling within the category of “Health Information” are processed.
Since the insurance company employees who renew policies and provide the health insurance service are not among the persons bound by a duty of confidentiality (doctors, nurses, etc.), and since the data processing activity is not carried out for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, or the planning and management of health services and their financing, health information can be processed only if explicit consent is obtained from the data subject.
For this reason, in the case at hand it was not possible for the insurance company to process the data subject’s health information without obtaining explicit consent, and its not carrying out the policy renewal because explicit consent was not given (since it could not process the health information) is a lawful practice. However, the fact that the data subject believed that explicit consent was being presented as a condition of the service raises questions about the quality of the information provided by the insurance company. When data subjects are informed, the focus should not be solely on meeting the minimum elements set out in Art. 10 of the Law and in the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform. While the minimum elements are met, the content should also aim to ensure that the data subject is properly informed. To take an example from the present case, a data subject who wishes to renew a health insurance policy should, on reading the information notice, learn why health information is processed on the basis of explicit consent and that explicit consent is in fact not being made a condition of the service.
Although the Board does not mention this in its decision, one of the greatest problems in practice is that information notices are not of an adequate standard and quality. Since most controllers confine themselves in their information notices to meeting only the minimum elements laid down in the legislation, texts that are far from informing people are used under the name of information notices. Yet the purpose of the obligation to inform is that data subjects be informed about their personal data that are processed. Here, the profile of the data subjects should be assessed, the content of information notices developed and their quality improved.
Regrettably, although some five years have passed since the Law entered into force, awareness of the protection of personal data has not yet fully taken shape in practice. The fact that many of those working in this field in particular disregard the reasoning behind the statutory provisions has also played a part in bringing about this result.
Compliance with the protection of personal data must be achieved specifically for each controller, taking into account that controller’s field of activity and the nature and quantity of the data it processes. Template information notices and explicit consent texts should not be used; information notices and explicit consent texts should be prepared specifically for the business processes of each controller. Moreover, matters should not be limited to this: controllers and/or their employees must be knowledgeable about personal data protection law and must guide data subjects correctly. When a data subject wishes to ask a question about the information notice and the explicit consent text, the controller’s employees who present the information notice and the explicit consent text must be able to provide information on the matter. Perhaps in the present case too, had the data subject been informed about the matter by means of a good-quality information notice and had his or her questions also been answered orally, the matter would not have come before the Board.
V. Health Data Processed by Insurance Companies
In order to provide the insurance service, insurance companies process, in addition to the data subject’s personal data falling within the categories of “Identity Information, Contact Information, Customer Transaction Information”, special categories of personal data such as “Health Information”. Indeed, personal data must necessarily be processed in order for the insurance policy to be prepared, the contract to be concluded and the service to be provided.
As regards the processing of personal data falling within the categories of identity information, contact information and customer transaction information, explicit consent is not required for the processing of the personal data in these categories, because the legal grounds in Art. 5(2) of Law No. 6698 on the Protection of Personal Data are present. Where the processing of health data is concerned, however, explicit consent must without fail be obtained, since the conditions in Art. 6(3) are not met.
An insurance company that needs health data in order to provide the service naturally asks for explicit consent in order to process those data. It is not possible for it to provide the service without obtaining explicit consent. Does the controller in that case make explicit consent a condition of the service?
The Board’s decision concerns precisely this. On the question of making explicit consent a condition of the service, it is necessary to determine for which data and for which processing activity explicit consent is requested, and to draw a twofold distinction. That is to say, if explicit consent is necessary in order for the main service to be provided, the fact that the service cannot be provided where explicit consent is not given does not mean that explicit consent has been made a condition of the service. Of course, in such a situation data subjects should be offered an alternative route by which they can receive the service without giving explicit consent, although an alternative route may not always exist.
To make the position concrete with regard to insurance companies: insurance companies issue policies by processing health data. The persons who issue the policy are, moreover, persons who are not bound by a duty of confidentiality. Even if the policy of a person who does not wish to give explicit consent were issued by a person bound by a duty of confidentiality (that is, even if the person were referred to a doctor, a nurse or the like), the processing of health data for the purpose of providing the health insurance service is not possible where explicit consent is not given, because the purpose for which the health data are processed is not one (or more than one) of the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, or the planning and management of health services and their financing.
It is plain that, since under the existing rules there is no alternative route for the activity in question, the fact that the main service cannot be provided where explicit consent is not given does not mean that explicit consent has been made a condition of the service. Had there been a workable alternative route, however, and had the insurance company, without establishing that alternative route, not provided the service to those who did not give explicit consent, explicit consent would have been made a condition of the service. In this respect, what insurance companies need to do is to prepare their information notices to a high standard. A person who reads the information notice should understand why the insurance company obtains explicit consent and why the health insurance service cannot be provided to him or her if explicit consent is not given. In addition, the insurance employees who present the information notice and the explicit consent text to the data subject (presumably the persons authorised to issue policies) must be equipped to give data subjects information orally where needed. Once the information element of explicit consent has been fully satisfied, the idea that explicit consent has been made a condition of the service will not arise in the minds of data subjects either.
Although there are points of uncertainty in the decision, this decision, given by the Board on a matter of which similar examples are encountered very frequently in practice, is very important. We nevertheless hope that the Board will include more detail in its decisions, draw attention to the alternative route as well and prevent practice from being steered in the wrong direction. Otherwise, such an important decision may push controllers towards obtaining explicit consent, which appears easier and cost-free, even in situations where the service can be provided without obtaining explicit consent, that is, even in situations where an alternative route exists.
Lastly, explicit consent should be addressed in relation to ancillary services. Where explicit consent is sought for the processing of personal data in order to provide ancillary services, it is not possible to speak of explicit consent being made a condition of the service. This is because the controller provides its main service and asks for explicit consent in respect of its ancillary services such as advertising, promotions and discounts. Since obtaining explicit consent in this way will not vitiate the free-will element of explicit consent, it cannot be said that the service has been made conditional on explicit consent either. On this point, however, the information must be provided very well, the explicit consent texts obtained for the main service and for the ancillary services must be separated, and the data subject must be in a position to know very well what he or she is giving explicit consent for.
Conclusion
Explicit consent is defined in Art. 3(1)(a) of Law No. 6698 on the Protection of Personal Data. Under that provision, explicit consent must relate to a specific matter, be based on information and be given of free will. If one of these three elements is missing, the explicit consent is unlawful. Explicit consent having these elements must be obtained where the legal grounds in Art. 5(2) of the Law, as regards personal data, and in Art. 6(3), as regards special categories of personal data, are absent. Explicit consent obtained for the processing of personal data when these legal grounds are present is unlawful. Yet although five years have passed since the Law entered into force, we still encounter situations in which explicit consent is obtained even though the legal grounds in Arts. 5(2) and 6(3) are present (in the belief that it will serve as a safeguard), in which the information notice and the explicit consent are set out in the same text (in the belief that there will be less paperwork), in which explicit consent is made a condition of the service, or in which information notices and explicit consent texts are poorly drafted (with the sole thought of not receiving an administrative fine). The fact that such situations still occur is the clearest indication that awareness of the protection of personal data has not yet been achieved.
As we have also stated in our earlier works, the Board must in its decisions without fail act with the aim of solving the problems encountered in practice, and must also draw up its decision summaries with this in mind. Regrettably, however, with this decision too the Board has been unable to go beyond repeating what is already known.
In the decision that forms the subject of this paper, the insurance company wished to obtain explicit consent for the renewal of the health insurance policy (because it needed to process special categories of personal data falling within the category of health information and Art. 6(3) of the Law did not apply), and stated that it would not renew the policy if explicit consent were not given. The data subject, for his or her part, lodged a complaint with the Authority on the ground that explicit consent had been made a condition of the service.
Since making explicit consent a condition of the service vitiates the element of its being given of free will, which is one of the elements of explicit consent, explicit consent that has been made a condition of the service becomes unlawful. Whether explicit consent has been made a condition of the service must therefore be assessed in the light of the particular case. If explicit consent has to be given for the processing of personal data (and/or special categories of personal data) for the purpose of providing the service, and the personal data (and/or special categories of personal data) cannot be processed because the data subject has not given explicit consent, it is naturally not possible for the controller to provide the service. However, where the personal data necessary for the provision of the service can be processed without obtaining explicit consent (because the legal grounds in Arts. 5(2) and 6(3) are present), and explicit consent is requested for the processing of the personal data needed for ancillary services (promotion, advertising, etc.) and it is stated that the main service will not be provided unless this consent is given, then one speaks of explicit consent being made a condition of the service. It should be noted, however, that in cases where explicit consent is required for the main service to be offered, if there is an alternative route that makes it possible to provide the main service without obtaining explicit consent as well, that route must without fail be established and the alternative route must also be pointed out to the data subject. Otherwise explicit consent will, once again, have been made a condition of the service. In this respect – in a situation such as the example that is the subject of the decision – insurance companies’ making explicit consent a condition of the service will be regarded as lawful.
Lastly, even though the Board did not examine the point, it is very important that controllers use good-quality texts when providing information and that they inform data subjects, so that erroneous assessments such as that in the case forming the subject of the decision may be prevented. In this respect, insurance companies too must draw up their information notices and explicit consent texts to a high standard; in particular, in situations (with no alternative) where the service cannot be provided without explicit consent being given, the content must be such that persons reading the information notice can readily understand why the service cannot be provided to them if they do not give explicit consent.
In addition, the controller’s employees who present the information notice and the explicit consent text to data subjects must also be equipped to inform data subjects about the matter orally as well. In this way the information element of explicit consent will have been fully satisfied.
Footnotes
- Attorney-at-Law, Assoc. Prof. Dr., Istanbul Aydın University Faculty of Law, Department of Criminal Law and Criminal Procedure Law, [email protected]. ↑
- Attorney-at-Law, Istanbul Bar Association; Master’s student, Department of Public Law, Institute of Social Sciences, Marmara University, [email protected], ORCID No: 0000-0003-4641-2687 ↑
- “Personal data may be processed without seeking the explicit consent of the data subject if one of the following conditions is present: a) It is expressly provided for by laws. b) It is necessary for the protection of the life or bodily integrity of the person himself or herself or of another person, where that person is unable to express his or her consent owing to actual impossibility or his or her consent is not recognised as legally valid. c) It is necessary to process personal data belonging to the parties to a contract, provided that this is directly related to the conclusion or performance of the contract. ç) It is necessary for the controller to be able to fulfil its legal obligation. d) The data have been made public by the data subject himself or herself. e) Data processing is necessary for the establishment, exercise or protection of a right. f) Data processing is necessary for the legitimate interests of the controller, provided that it does not harm the fundamental rights and freedoms of the data subject.”. ↑
- “Personal data other than those relating to health and sexual life listed in the first paragraph may be processed without seeking the explicit consent of the data subject in the cases provided for by laws. Personal data relating to health and sexual life, however, may be processed without seeking the explicit consent of the data subject only for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing, by persons under a duty of confidentiality or by authorised institutions and organisations.”. ↑
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
