KVKK Fines Company TRY 1 Million Over Referral Marketing
KVKK Referral Marketing Fine: TRY 1 Million Decision
Masoud Salmani
•
KVKK Fines Company TRY 1 Million Over Referral Marketing
Last updated: 2026-08-17
The most important lesson is not simply that the company lacked consent for a later SMS. Personal-data processing had already begun when the referred person’s phone number entered the company’s application and was recorded for outreach. A third party’s claim that the person wanted information did not create a lawful basis on that person’s behalf.
The decision also has programme-wide significance. The Board said its assessment of the individual complaint applied to other people whose data had been processed through the same method. Businesses using refer-a-friend campaigns, customer recommendations, lead-sharing incentives, agents or outsourced call centres should therefore review the full workflow—not only the complaint that first exposed it.
What the Board’s decision confirms
The Board’s decision is dated 10 June 2026 and numbered 2026/1183. The official summary was published on 10 August 2026.
According to the summary:
A customer participating in the company’s “brand ambassador” programme entered a third person’s phone number through an application.
People supplying referrals received a premium or incentive.
The company recorded the number, called the referred person and later sent one campaign SMS.
The company argued that it provided information during the call, obtained consent, recorded the call with the person’s knowledge and continued because the person asked questions.
The Board found that the call moved into persistent campaign promotion without the required transparency or a valid consent process. Continuing the conversation showed, at most, implied interest in hearing the promotion—not valid explicit consent to personal-data processing.
The Board also noted that the call was recorded without appropriate information being provided about the recording.
The company said that it stopped contact after the complaint, deleted the person’s record and blocked the number in its SMS systems.
The Board found the company had responded to the person’s data-subject application, so it took no action on the allegation that the application had gone unanswered.
The TRY 1 million fine was imposed under KVKK Article 18(1)(b) for failure to take the measures required by Article 12(1) to prevent unlawful processing. The underlying problem was that the phone number was processed without a valid condition under Article 5.
The Board did not impose a separate transparency fine in the published summary. It stated that, because no processing condition existed in the first place, no additional action was required on the transparency issue. That does not make transparency optional; it means a privacy notice cannot rescue processing that has no lawful basis.
What Decision 2026/1183 confirms—and what remains unproven
Issue
Confirmed by the official summary
Important limit
Referral source
Confirmed A customer entered a third person’s phone number through the brand-ambassador programme; referrers could receive a premium.
The company’s identity and the total number of referred people were not disclosed.
Processing sequence
Confirmed The number was recorded, the person was called, the call was recorded and one campaign SMS was later sent.
The summary does not provide complete system logs, retention periods or vendor details.
Lawful basis
Confirmed The Board found no valid Article 5 condition and no KVKK-compliant explicit consent.
A third party’s assertion and the person’s continued conversation did not create consent.
Fine
Confirmed TRY 1 million under Articles 12(1) and 18(1)(b).
The summary records no separate Article 10 fine or Law No. 6563/IYS penalty.
Programme scope
Confirmed The individual assessment was considered applicable to others processed by the same method.
The summary does not quantify the wider population or set out a separate remediation order.
Judicial status
No court outcome is stated in the official summary.
No publicly confirmed challenge was identified as of 17 August 2026; anonymisation limits verification.
How the “brand ambassador” programme worked
The programme created a short but legally significant chain:
An existing customer entered another person’s phone number into the company’s application.
The company stored the number as a potential lead.
A call-centre agent contacted the referred person.
The agent promoted the company’s campaign and recorded the conversation.
The company treated the person’s continued participation in the call as consent.
A campaign SMS followed.
The referring customer could receive a premium for the referral.
The commercial incentive matters operationally. A paid referral mechanism encourages volume and makes inaccurate claims such as “my friend wants to be contacted” more likely. It also shows that the collection was a designed company process, not a purely private exchange between acquaintances.
When did personal-data processing actually begin?
Processing did not begin only when an agent spoke to the person or sent the SMS. It began when the company received and recorded the identifiable phone number in its application or connected systems.
Under KVKK, collection, recording, storage, consultation, use, transfer and deletion are all parts of the processing lifecycle. The later call, call recording and SMS were additional processing operations, each requiring a defined purpose, a valid processing condition and appropriate controls.
This timing point prevents a common design error: calling a person first and trying to obtain permission during the call does not retroactively legalise the earlier collection and CRM entry.
Why a third party cannot manufacture a lawful basis
A referrer can say, “I think this person may be interested.” That statement is not the referred person’s explicit consent.
Valid explicit consent must be an informed, freely given indication by the person whose data will be processed and must concern a specific purpose. A referrer generally cannot provide that declaration for another competent adult. Nor can a company convert the referrer’s assertion into consent simply by adding a checkbox stating, “I confirm my friend agreed.”
That checkbox may help allocate contractual responsibility between the company and referrer, but it does not prove that the referred person received the necessary information or made a valid declaration to the company.
The safer architecture is to keep the referred person’s contact details outside company systems until the person acts. Give the customer a general referral link or code to share through the customer’s own channel. The prospective customer can then open the link, review the privacy information and submit their own details.
Could legitimate interest ever support a referral workflow?
Legitimate interest under KVKK Article 5(2)(f) is not a general marketing permission. It requires a current, specific and lawful interest; necessity; compliance with the general principles; and a balance showing that the person’s fundamental rights and freedoms are not harmed.
The Board’s earlier Decision 2021/584 rejected legitimate interest for unsolicited advertising and marketing where the asserted benefit was essentially commercial gain and the person would be exposed to unwanted calls or messages. Decision 2026/1183 likewise found no processing condition for the brand-ambassador programme before it.
There may be narrow situations in which a referral-related administrative step has another defensible basis—for example, where the prospective customer personally submits a request and processing is directly necessary to take steps toward a contract. That is materially different from paying customers to upload other people’s numbers for outbound marketing.
If a business considers legitimate interest for any limited referral step, it should document:
the precise interest, rather than “marketing” or “business growth” in the abstract;
why processing that specific data is genuinely necessary;
why a less intrusive self-referral link cannot achieve the purpose;
what the referred person would reasonably expect;
the effect of incentives, vulnerability, frequency and contact channel;
safeguards, including strict purpose limitation, minimal data, short retention and immediate objection handling; and
a separate analysis of Türkiye’s commercial-electronic-message rules.
For a paid, unsolicited phone-number referral programme, legitimate interest is a high-risk basis and the cited Board decisions weigh strongly against relying on it.
Indirect collection and first-contact transparency
KVKK’s transparency rules recognise that data are sometimes obtained indirectly. Where contact details will be used to communicate with the person, the applicable notice must generally be provided at the first communication, subject to the conditions in the Transparency Communiqué.
The notice should identify the controller and, where relevant, its representative; explain the specific purposes; identify possible recipients and transfer purposes; state the collection method and actual legal basis; and explain the person’s Article 11 rights.
Two limitations are crucial:
First, the first-contact timing rule does not itself provide a lawful basis for receiving and storing the number. A controller still needs an Article 5 processing condition.
Second, it does not override Law No. 6563 or the commercial-electronic-message regime. If the first call or message is itself marketing, a company cannot assume that KVKK’s indirect-collection timing rule gives it permission to make that contact.
Two legal layers must be checked separately
Control question
KVKK
Law No. 6563 / İYS
What is regulated?
Obtaining, recording, storing, using, transferring and deleting the person’s contact data and call records.
Sending commercial electronic messages, including marketing SMS and voice calls, and managing approval and rejection records.
What must exist?
A valid Article 5 processing condition, compliance with general principles and Article 10 transparency.
Prior approval unless a defined exception applies, plus compliant content, channel handling and rejection controls.
Does the referrer’s statement suffice?
No. It is not the referred person’s informed, freely given and specific explicit consent.
It does not by itself prove the recipient’s valid commercial-message approval or an applicable exception.
Can the first marketing contact request permission?
First-contact transparency does not cure a missing basis for prior collection or storage.
A commercial electronic message cannot be sent merely to ask for permission to send marketing.
Does an opt-out cure the first message?
No. Later objection handling cannot retroactively validate earlier processing.
No. It governs future contact; rejection must be implemented within the applicable period.
Are business recipients different?
A business number linked to a natural person can still be personal data; KVKK remains relevant.
A prior-approval exception may apply to merchants and tradespeople, but rejection must still be respected.
Why continuing the call was only implied behaviour
The company argued that the referred person asked questions, showed interest and continued the conversation. The Board treated this as implied behaviour directed at continuing the campaign discussion, not valid explicit consent to processing.
Silence, failing to hang up, listening to a sales pitch, asking about an offer or failing to send an opt-out message does not by itself satisfy KVKK’s definition of explicit consent.
Where explicit consent is the relevant basis, the company should be able to prove an affirmative declaration that is:
specific: tied to defined processing rather than a blanket acceptance;
informed: preceded by clear information about the data, purposes, consequences and controller;
freely given: not bundled into an unrelated service or produced through pressure; and
obtained before the consent-based processing begins: not inferred after collection or outreach.
Transparency and consent are separate steps. Reading a notice is not consent, and obtaining consent does not replace the duty to provide a compliant notice.
Voice-recording implications
A call recording creates another personal-data record. The business must define and document why recording is necessary, which processing condition applies, how long the audio will be kept, who may access it and whether a call-centre or cloud provider receives it.
The person must be appropriately informed about the recording and its purpose. A generic “calls may be recorded” statement may be insufficient if the full Article 10 information is neither provided nor made readily accessible through a valid layered notice.
Voice recordings are not automatically special-category biometric data. They may become biometric data where technical processing is used to uniquely identify or authenticate a person. Ordinary call audio nevertheless remains personal data and can contain financial, health or other sensitive information disclosed during the conversation.
Recording a call can help prove what happened, but it cannot create consent that the conversation never contained or cure an outreach workflow that was unlawful from the start.
SMS marketing after the first call: KVKK, Law No. 6563 and IYS
The official decision summary records the company’s claim that one campaign SMS was sent after the call and that the message contained an opt-out instruction. It does not establish that the person had separately approved commercial electronic messages or that a valid permission existed in the Message Management System (İYS).
It is equally important not to overstate the ruling: the published decision imposed the TRY 1 million KVKK fine under Articles 12(1) and 18(1)(b). It did not record a separate administrative penalty under Law No. 6563.
The two regimes still apply side by side:
Consumer-facing marketing by SMS or voice call generally requires prior approval under the commercial-electronic-message rules.
Approval and rejection records must be handled through İYS in accordance with the applicable rules; operational checks should distinguish message and voice-call channels.
A message cannot be used merely to ask the recipient for permission to send marketing messages.
An unsubscribe instruction supports the right to reject future messages. It does not retroactively authorise the first marketing message.
There are exceptions, including rules for recipients who are merchants or tradespeople, but those exceptions do not remove the need for a KVKK processing condition, transparency and purpose limitation. A rejection must still be respected.
Businesses should therefore maintain separate evidence for the KVKK processing condition and the commercial-communication permission or exception. A green status in one system should not automatically be treated as proof that every requirement in the other regime has been met.
CRM suppression, deletion and evidence retention
Stopping campaigns is not the same as deleting data. A compliant response must identify every copy: the referral application, CRM, dialler, call recordings, SMS platform, spreadsheets, lead exports, analytics tools, agency systems and accessible backups.
Where all processing conditions have disappeared, KVKK Article 7 and the deletion regulation require deletion, destruction or anonymisation. Controllers with a retention and destruction policy act at the first periodic destruction cycle, which cannot be more than six months apart. Controllers not required to maintain such a policy must generally act within three months. A deletion request must be answered within 30 days. These are outer procedural periods, not reasons to continue actively using an unlawful lead; access and outreach should be stopped immediately while remediation is completed.
Suppression creates a difficult issue. Keeping a phone number on an internal “do not call” list is itself processing. In Decision 2021/584, the Board distinguished numbers originally obtained lawfully from numbers obtained unlawfully and rejected continuing to hold an unlawfully obtained number on an internal suppression list without a processing condition.
A company should therefore not automatically move every unlawful lead into a permanent raw-number blacklist. It should determine whether a separate duty or defensible basis requires a limited record—for example, an İYS rejection, a complaint record or evidence needed to establish or defend a legal claim—and apply the relevant retention period and access restrictions. Where technically appropriate, a carefully designed cryptographic suppression method may reduce exposure, but a hash that can still be linked to or used to single out a person remains personal data and still needs a basis.
Programme-wide remediation matrix
Area
Immediate control
Evidence to retain
Owner
Immediate Intake
Disable third-party phone-number entry and bulk referral uploads.
Configuration change, affected forms, source codes and pause approval.
Product / Marketing
Immediate Campaigns
Stop queued calls and SMS for unverified referral leads.
Suppression run, campaign IDs, dialler and SMS platform logs.
Marketing Ops
Population review
Identify every lead created through ambassadors, referrals, agents, lists and manual uploads.
Reconciled inventory, query logic, counts by source and system.
Privacy / Data
Legal validation
Test the Article 5 basis, notice, call recording, commercial-message approval or exception, and İYS status separately.
Assessment, consent artefacts, IYS extracts, scripts and balancing tests.
Privacy / Legal
Deletion
Quarantine invalid leads, delete or otherwise lawfully dispose of copies, and propagate instructions to processors.
Deletion tickets, vendor confirmations, logs and backup handling record.
IT / CRM
Suppression
Avoid retaining an unlawfully obtained raw number without a separate documented basis; minimise any required rejection or claims record.
Basis, data fields, access list, retention trigger and destruction date.
Privacy / CRM
Redesign
Use a generic link or code so the prospective customer initiates contact and supplies their own information.
Approved data flow, requirements, test results and revised notices.
Product
Monitoring
Alert on unverified sources, abnormal referral volume, missing permissions and repeat objections.
Control reports, exception tickets, complaint trends and review minutes.
Compliance / Internal Control
Programme-wide remediation: do not fix only the complainant’s record
Decision 2026/1183 expressly extended the individual assessment to other people whose data were processed by the same method. Remediation should therefore cover the population and the system design.
A practical response should include:
Pause referrals and outbound campaigns. Disable new third-party lead entry and prevent queued calls or messages while the review is underway.
Preserve controlled evidence. Secure relevant logs, scripts, consent records, IYS records, referral terms, incentive records and vendor instructions without allowing the data to remain available for marketing.
Map the affected population. Identify all leads sourced through referrals, brand ambassadors, agents, purchased lists, events and manual uploads.
Test the claimed processing condition. Do not assume that a referrer checkbox, CRM label or call-centre disposition proves consent.
Separate the legal layers. Assess the KVKK basis, Article 10 transparency, commercial-message approval or exception, IYS status and call-recording basis independently.
Quarantine or delete invalid leads. Propagate instructions to call centres, SMS providers, agencies and other processors, and retain evidence of completion.
Review suppression records. Keep only the minimum record supported by a documented processing condition and defined retention period.
Rebuild the referral design. Prefer person-initiated forms or links that collect information directly from the prospective customer.
Correct scripts and technical gates. Prevent agents from beginning promotion, recording calls or triggering SMS until the required checks have passed.
Audit incentives and vendors. Ensure referral premiums, sales targets and processor contracts do not reward collection that the organisation cannot lawfully use.
Prepare a documented decision record. Record affected systems, legal analysis, deletion decisions, residual evidence, owners, dates and validation results.
Monitor complaints and regulator developments. Treat repeated objections or abnormal referral volumes as control failures, not isolated customer-service events.
A safer referral model
The lowest-risk structure usually avoids collecting a friend’s contact details altogether:
Give the existing customer a generic link or referral code.
Let that customer share it privately without giving the company access to the recipient’s address book or phone number.
Allow the prospective customer to initiate contact and receive the privacy information directly.
Collect only the minimum information needed for the requested next step.
Obtain and record any required marketing permission separately from a service enquiry.
Pay any referral reward only after an independently defined qualifying event, without exposing the prospective customer’s unnecessary information to the referrer.
Referral programme design
A safer referral workflow
The compliance risk changes depending on when the prospective customer’s data enters company systems and who initiates the contact.
High-risk design
The customer uploads a friend’s number
The company receives the contact data before hearing directly from the referred person.
1
Customer uploads a friend’s phone numberPersonal-data processing begins at this point.
2
An automatic CRM lead is createdNo direct declaration or verified processing condition from the prospective customer.
3
The call centre makes a marketing call and records itThe call and its recording are separate processing operations.
4
A campaign SMS is triggeredCommercial-electronic-message requirements apply separately.
Why it is high-risk: the person’s number enters marketing systems before the person acts, while the referrer’s statement does not itself establish the referred person’s consent or another lawful basis.
Safer model
The prospective customer initiates contact
The company avoids collecting a third party’s contact details from the referring customer.
1
Customer receives a generic referral link or codeNo friend’s phone number or email address is collected.
2
Customer shares it through their own private channelThe company does not see or store the recipient’s identity.
3
Prospective customer opens the linkThe individual chooses whether to engage with the company.
4
Privacy information is shown before form submissionOnly the minimum information needed for the requested next step is collected.
5
Marketing choice is requested and recorded separatelyPermission, channel, time and source can be evidenced where required.
Why it is safer: the individual initiates the relationship, receives the relevant information directly and controls which details are submitted.
Control checkpoints
Person-initiated contactNotice before submissionMinimum data collectionSeparate marketing choiceRetained evidence
What businesses should take from the TRY 1 million fine
Referral marketing is not exempt from data-protection and electronic-marketing rules because the lead came from a friend, customer, agent or “brand ambassador.” The controller remains responsible for the workflow it designs and the systems it operates.
The immediate priority is to determine where third-party contact details enter the organisation, what condition is claimed at that moment and whether the evidence actually comes from the person concerned. The next step is to align call-centre scripts, recording, SMS permissions, İYS controls, CRM retention and vendor instructions around that answer.
Kooch helps organisations map marketing data flows, test KVKK processing conditions, review notices and consent evidence, and turn remediation decisions into practical CRM, call-centre and vendor controls. If your referral or outbound-marketing programme depends on customer-supplied contact details, a focused KVKK gap analysis can identify the highest-risk steps before they become programme-wide findings.
Status of any judicial challenge
As of 17 August 2026, no publicly confirmed judicial challenge or final court ruling concerning Decision 2026/1183 was identified in the official decision summary or the public sources reviewed for this article. Because the published summary anonymises the company, independent verification is limited. The decision should not be described as having been upheld by a court—or as unchallenged—without later confirmation.