Türkiye’s KVKK Referral Marketing Warning | 2026

Türkiye’s KVKK Warning on Referral Marketing: What “Refer a Friend” Campaigns Must Fix

Last updated: 2026-07-27

Referral marketing is not prohibited in Türkiye. But collecting a friend’s phone number, adding it to a CRM and treating it as a ready-to-contact lead creates a sequence of personal-data and electronic-marketing obligations that a referral form alone does not satisfy.

On 21 July 2026, Türkiye’s Personal Data Protection Authority published a public announcement addressing personal data obtained from third parties and used for advertising or marketing. The announcement followed numerous reports and complaints involving telephone numbers, email addresses and similar contact details sourced through referrals, recommendations, brand-ambassador schemes, acquaintance referrals and customer suggestions.

The Authority’s central message is straightforward:

Receiving contact details from a customer or another third party does not itself provide a legal basis for using those details for advertising or marketing.

This is not a new blanket rule that explicit consent is mandatory for every marketing activity. The Authority expressly states that the applicable processing condition under Law No. 6698—the Turkish Personal Data Protection Law, commonly called the KVKK—must be assessed for each specific case. The practical warning is that “someone referred this person” is not one of those processing conditions.

Organizations should therefore test referral campaigns against two separate legal layers:

  1. Is there a valid KVKK processing condition for collecting, recording, using and, where relevant, transferring the referred person’s data?
  2. Is the call, SMS or email permitted under Türkiye’s commercial electronic communications rules, including the rules governing the Message Management System (İleti Yönetim Sistemi or IYS)?

Passing one test does not automatically satisfy the other.

What the Authority announced on 21 July 2026

The Authority said it had received numerous reports and complaints concerning controllers that used contact information obtained from existing customers or other third parties for advertising and marketing.

The reported practices included:

  • referrals and recommendations;
  • brand-ambassador programs;
  • referrals by acquaintances;
  • customer suggestions; and
  • marketing calls or SMS messages made without properly informing the referred person or obtaining explicit consent where consent was the applicable processing condition.

The announcement also refers to Board examinations in which data obtained from third parties had been used for marketing. It reminds controllers that any such activity must comply with the KVKK’s processing conditions, transparency requirements and general principles.

Although the announcement expressly names referral-style methods, its reasoning is also relevant to purchased, exchanged or informally shared lead lists. Buying or receiving a list changes the source of the data; it does not establish the buyer’s legal basis for its own use.

The announcement is a public warning and explanation of existing obligations, rather than a new statutory ban on referral marketing. However, the Authority expressly notes that controllers found to be acting contrary to the KVKK may face administrative enforcement under Article 18.

Why receiving a phone number does not create a legal basis

A typical referral form asks an existing customer to enter a friend’s name and telephone number. Once submitted, the company may assume that:

  • the friend is interested;
  • the customer has already explained the campaign;
  • the friend has agreed to be contacted; or
  • one introductory call is harmless.

None of these assumptions establishes a KVKK processing condition.

The referrer’s statement is not normally the referred person’s own explicit consent. A campaign rule saying “only refer people who agree” may be a useful behavioral control, but it does not prove that the data subject received the controller’s information and gave a specific, informed and freely given declaration.

This matters from the moment the company receives the data. Collection, entry into a CRM, enrichment, scoring, sharing with a call centre and making a call are all separate processing operations. Consent obtained later cannot retroactively legalize earlier collection or use that lacked a processing condition.

Referral incentives can increase the risk. Where customers, ambassadors or affiliates receive a discount, commission or reward, they have a reason to submit larger numbers of contacts or to overstate the contacts’ interest. The controller should design for that incentive rather than treating the referrer’s assurance as reliable evidence.

Determining the correct KVKK processing condition

Article 5 of the KVKK permits ordinary personal data to be processed with explicit consent or, where the relevant requirements are met, under one of the non-consent conditions listed in Article 5(2).

The correct condition must be selected for each purpose. A condition that supports a requested quotation may not also support future promotional messages, profiling or disclosure to a campaign partner.

Scenario or purpose Processing condition that may be relevant Important limit
The individual clicks a referral link and asks the company to call, prepare an offer or take steps toward a contract Processing directly necessary for establishing or performing a contract may apply The processing must be genuinely necessary for the person’s request. It does not automatically cover unrelated future marketing
The individual has deliberately made a business contact detail public for the specific purpose of receiving this type of approach Processing of data made public by the data subject may be considered Public availability alone is insufficient. Use must remain connected to the purpose for which the person made it public
The company keeps a minimal suppression record after an objection or withdrawal Legal obligation, establishment or protection of a right, or legitimate interests may be relevant depending on the record and purpose Retain only what is necessary to prevent further contact and demonstrate compliance; do not preserve the full marketing profile by default
The company checks duplicate referrals, prevents reward fraud or accounts for a qualifying referral Legitimate interests may be relevant after a documented necessity and balancing assessment This may support limited anti-fraud or accounting processing, not the initial cold marketing approach itself
A referred consumer has not initiated contact and no other Article 5 condition applies Explicit consent will often be the realistic condition for promotional processing Consent must come from the referred person, meet the KVKK standard and be obtained before the consent-based processing begins


The “legitimate interests” condition should be approached carefully in cold marketing. In an earlier decision concerning unsolicited insurance marketing, the Board rejected the argument that the company’s economic interest in selling policies made the marketing processing necessary. It reasoned that sales could be pursued through other methods and that unsolicited advertising could harm individuals’ ability to control their data.

Similarly, a telephone number or work email found online is not automatically available for unrelated advertising. Board decisions have emphasized that publicly available data may be used only consistently with the person’s purpose in making it public.

When can a non-consent condition realistically apply?

Non-consent conditions are not theoretical. They may apply where:

  • the referred person initiates contact and asks for information, a quotation or pre-contractual steps;
  • processing is necessary to administer an existing contract or a transaction requested by the person;
  • a narrowly defined record must be kept to comply with commercial-message rules or defend a legal claim;
  • limited data are needed to prevent referral abuse or duplicate reward payments, following a documented legitimate-interest assessment; or
  • the person deliberately made the relevant details public for a purpose that genuinely includes the intended contact.

What is difficult to defend is using a broadly framed “legitimate interest in growing sales” to turn third-party contact data into an unsolicited consumer marketing list.

KVKK and commercial electronic-message rules are separate

A marketing call, SMS or email can engage both the KVKK and Law No. 6563 on the Regulation of Electronic Commerce, together with the Regulation on Commercial Communication and Commercial Electronic Messages.

Under the commercial-message regime, prior approval is generally required before sending promotional electronic messages. Telephone and call-centre communications, SMS and email are included. Approvals and refusals must also be managed through the IYS where the regime requires it.

The regulations contain specific exceptions, including:

  • communications about changes, use or maintenance relating to goods or services already obtained, where the recipient provided contact details for communication;
  • notifications concerning an ongoing subscription, membership or partnership, collection, debt reminders, information updates, purchases, delivery or similar operational matters, provided that no product or service is promoted;
  • communications to recipients who are merchants or tradespeople, subject to their right to refuse further messages; and
  • certain informational communications by firms carrying out capital-markets intermediation.

These exceptions should be read narrowly.

Türkiye does not provide a broad “similar products” marketing exception

Existing-customer status is not a general permission to advertise. Türkiye’s regulation contains an exception for changes, use and maintenance concerning goods or services already obtained. It also permits specified transactional or membership communications that do not promote goods or services.

That is not the same as a broad rule allowing a company to market its own “similar products or services” to every existing customer without prior approval.

A receipt, delivery update or maintenance notice should not be used as a vehicle for a sales offer. Adding promotional content can move the communication outside the exception.

The merchant and tradesperson exception does not remove KVKK analysis

Prior commercial-message approval is generally not required when the recipient is a merchant or tradesperson, unless that recipient has exercised the right to refuse. Before relying on this exception, the sender should verify and record the recipient’s relevant status and check the applicable IYS refusal status.

But this exception concerns commercial electronic-message approval. It does not automatically establish a KVKK Article 5 processing condition.

The Board has previously considered a case where a company relied on the merchant/tradesperson exception to market to a lawyer’s publicly available work address. The Board found both that the recipient did not have the claimed status for that exception and that the public business contact had not been made public for advertising. The case illustrates why the two legal tests must not be collapsed into one.

Approval cannot be requested through the promotional channel itself

The commercial communications regulation states that a recipient cannot be sent a commercial electronic message merely to request approval for future commercial messages.

This creates a fundamental problem for “we will call once and ask permission” referral flows. Before the call, the controller still needs a KVKK basis for using the number. The call itself may also fall within the commercial-message rules. An approval or explicit consent obtained during the call cannot cure a lack of legal basis for the earlier receipt, storage and use of the contact information.

When must the referred person receive the privacy notice?

Article 10 of the KVKK requires the controller—or a person it authorizes—to inform the individual about:

  • the identity of the controller and, where applicable, its representative;
  • the purposes of processing;
  • recipients and transfer purposes;
  • the method and legal reason for collection; and
  • the individual’s rights under Article 11.

For data not obtained directly from the person, the Transparency Notice Communiqué provides specific timing rules where direct collection is impossible in practice or the person cannot be reached. The notice must be provided:

  • within a reasonable period after obtaining the data;
  • during the first communication if the data will be used to contact the person; or
  • no later than the first transfer if the data will be transferred.

The July announcement specifically reminds controllers of these rules. The safer operational approach is to provide the information at the earliest feasible point and, when relying on the first-contact rule, before delivering the marketing pitch.

The timing rule does not create a processing condition. A controller still needs a legal basis for obtaining and using the number in the first place.

Organizations should also read this alongside the Board’s February 2026 Principle Decision, which states the general expectation that transparency is completed before processing starts and that notices clearly identify the actual purpose, data and legal reason. Referral flows should therefore be redesigned to collect data directly where feasible rather than treating first-contact disclosure as the default solution.

A privacy notice is not explicit consent

The Authority highlights a repeated compliance failure: treating disclosure and consent as the same event.

A privacy notice is information provided by the controller. It is required regardless of whether processing is based on explicit consent or another Article 5 condition. The individual is not required to “approve” the controller’s notice.

Explicit consent is the individual’s separate declaration permitting a specified processing activity. Under the KVKK, it must be:

  • related to a specific subject;
  • based on adequate information; and
  • freely given.

The Board’s February 2026 Principle Decision requires transparency notices and explicit-consent texts to be presented separately. If they appear on the same page, they should have different headings, be displayed separately and require distinct declarations.

The July announcement also says the following behaviors do not, by themselves, amount to valid explicit consent:

  • continuing to listen to the campaign;
  • not immediately ending the call;
  • asking questions about the controller’s activities;
  • asking for information; or
  • failing to reply “stop” or otherwise opt out from an SMS.

Silence, passivity and the absence of an objection are not affirmative consent.

Who is responsible in a referral ecosystem?

Labels in commercial contracts do not decide KVKK roles. The factual allocation of decisions does.

Party Likely role and responsibility
Business operating the campaign Usually the controller because it decides why leads are collected, which data are required, who will be contacted, how the campaign works and how long records are retained
Referring customer Usually a source of data, not the person who can give consent for the referred individual. The campaign operator cannot transfer its controller obligations to the customer through campaign terms
Professional ambassador, affiliate or lead generator May be an independent controller, joint participant in determining the processing, or a processor depending on who decides the purposes and essential means. Incentives, independent list-building and reuse of leads point away from a purely mechanical processor role
Outsourced call centre May be a processor where it acts only on documented instructions and does not select leads, determine purposes or reuse data. It may become a controller for activities whose purposes and essential means it independently determines
Marketing agency Role depends on whether it merely executes the controller’s instructions or designs targeting, selects data sources, combines lists or uses data for its own purposes
Lead-list seller and buyer The seller must justify disclosure and the buyer must independently justify acquisition and use. A contractual warranty from the seller is evidence to examine, not a substitute for a lawful processing condition



Under Article 12, controllers must take the necessary technical and organizational measures to prevent unlawful processing and access and to protect personal data. Where a processor is used, the controller and processor share responsibility for the security measures required by the KVKK.

Contracts with call centres, agencies and lead providers should therefore address:

  • documented instructions and prohibited uses;
  • approved data sources and legal-basis evidence;
  • transparency and consent scripts;
  • IYS checks and channel controls;
  • access restrictions, exports and sub-processors;
  • complaint and data-subject request handling;
  • incident reporting;
  • deletion, return and audit evidence; and
  • a ban on retaining or reusing referral lists for the vendor’s own purposes.

“Aracı hizmet sağlayıcı” under the commercial electronic-message regulation is a statutory role and should not automatically be treated as identical to “data processor” under the KVKK. Each classification must be assessed under its own rules.

Business contact details and sole traders

B2B data should not be excluded from the review.

A named work email, direct business telephone number or other contact detail linked to an identifiable employee, professional or sole trader can be personal data under the KVKK. A sole trader’s business information will often relate directly to that natural person.

A genuinely generic company address—such as info@company.example—may not identify a natural person and may therefore fall outside the KVKK definition in a particular case. However, the commercial electronic-message rules apply to electronic addresses of both natural and legal-person recipients. The KVKK and commercial-message classifications should therefore be assessed separately.

Do not assume that:

  • a company domain makes an address non-personal;
  • a business card authorizes general marketing;
  • an online professional directory authorizes unrelated advertising; or
  • every business contact is a merchant or tradesperson for the commercial-message exception.

Can a compliant referral flow avoid collecting the friend’s details?

Yes. In many cases, the strongest design is not to collect the referred person’s name, phone number or email until that person chooses to engage.

A lower-risk flow can work as follows:

  1. Give the existing customer a shareable referral link or non-identifying code.
  2. Let the customer send that link through the customer’s own chosen channel.
  3. Do not request access to the customer’s address book and do not ask the customer to upload the friend’s details.
  4. When the friend opens the link, present the controller’s concise privacy notice before collecting personal data.
  5. Let the person request a call, quotation or other service through a clear affirmative action.
  6. Where future marketing relies on explicit consent, present a separate consent text and choice. Manage any required commercial-message approval and IYS record separately and correctly.
  7. Attribute the referral reward through the code after the relevant qualifying event, without requiring the referrer to disclose the friend’s contact details.

This design does not eliminate every obligation. Cookies, attribution technologies, fraud controls and referral-reward records still need their own assessment. But it removes the riskiest feature: the controller receiving an unsuspecting person’s contact details and using them for an unsolicited approach.

What evidence should the CRM retain?

A referral source field labelled “customer recommendation” is not enough. The CRM and connected systems should be able to demonstrate why each relevant processing and communication step was permitted.

Record What to retain
Source and collection Source type, referrer or partner ID where necessary, collection time, channel, campaign and the exact form or integration used
Purpose and processing condition Purpose-specific KVKK condition, documented reasoning and any legitimate-interest necessity and balancing assessment
Transparency Notice version, language, delivery method, date and time, and evidence of display or delivery
Explicit consent Separate consent-text version, exact affirmative action, scope, channel, date and time, and evidence linking the declaration to the person
Commercial-message approval Channel-specific approval status, source, date, IYS registration or check, and applicable exception where no prior approval was required
Calls and messages Campaign, sender, recipient channel, date, time, content or approved script version, and delivery or call outcome
Objections and withdrawals Date, channel, scope, IYS update, suppression status and confirmation that downstream systems and vendors were updated
Vendors Controller instructions, recipient list version, access logs, sub-processor details, return or deletion evidence and audit results
Retention Retention rule, trigger date, legal rationale, deletion date and systems in which copies or backups exist

Do not record “referrer confirmed consent” as if it were the referred person’s consent evidence. If the controller relies on explicit consent, it should be able to prove the referred individual’s own informed and affirmative declaration.

How long should referral and consent records be retained?

The KVKK does not prescribe one universal retention period for all referral data. Article 4 requires personal data to be kept only for the period provided by relevant legislation or necessary for the processing purpose. When the reasons for processing cease, Article 7 requires deletion, destruction or anonymization in accordance with the applicable rules.

The commercial electronic-message regulation adds a specific minimum evidence period:

  • approval records must be retained for three years after the approval ceases to be valid; and
  • other commercial electronic-message records must be retained for three years from the record date.

This does not justify keeping every CRM field, call recording or enriched profile for three years. Separate the records:

  • keep permission and communication evidence for the legally required or defensible period;
  • delete unqualified referral details when there is no remaining processing condition or purpose;
  • define a short review and deletion trigger for dormant referrals;
  • retain only the minimum suppression data needed to honor an objection, where an appropriate processing condition supports that record; and
  • propagate deletion and suppression decisions to call centres, agencies, exports, marketing platforms and backups under a documented process.

Longer retention may be justified for a specific legal claim or statutory duty, but it should be documented rather than applied as a blanket “just in case” period.

Practical remediation checklist

Organizations using referrals, customer recommendations, ambassadors, affiliates or external lead sources should consider the following actions:

  • Inventory every way third-party contact data enters the business, including manual CRM entry, spreadsheets, forms, APIs, call centres and purchased lists.
  • Pause automated outreach where the source, KVKK processing condition or commercial-message status cannot be demonstrated.
  • Map each purpose separately: receipt, validation, contact, marketing, profiling, reward administration, fraud prevention and retention.
  • Select and document the Article 5 condition for each purpose. Do not use “referral” as a legal-basis label.
  • Test the planned call, SMS and email against Law No. 6563, the commercial communications regulation and IYS requirements.
  • Remove any assumption that an existing customer may automatically receive marketing for similar products.
  • Verify merchant or tradesperson status before relying on the relevant commercial-message exception, and still complete the KVKK analysis.
  • Separate the privacy notice, explicit-consent declaration and commercial-message approval in both the interface and the evidence model.
  • Rewrite call scripts so the controller is identified and the required notice is delivered at the correct time; do not treat continued conversation as consent.
  • Stop asking referrers to upload contact details where a person-initiated referral link can achieve the objective.
  • Review call-centre, agency, affiliate and lead-provider roles, instructions, access, reuse restrictions and deletion obligations.
  • Add source, legal-basis, notice, consent, IYS and retention fields to the CRM, with validation rules that prevent outreach when required evidence is missing.
  • Synchronize refusals, withdrawals and suppression records across all channels and vendors.
  • Create purpose-specific retention rules and verify deletion from operational systems, exports and vendor environments.
  • Sample historical referral records and remediate or delete records that cannot be supported.

Frequently asked questions

Can a customer consent on behalf of a friend?

Not ordinarily. The referring customer’s assurance does not replace the referred person’s own specific, informed and freely given declaration. A legally authorized representative is a different situation and should not be confused with an ordinary customer referral.

Can we make one call solely to ask whether the person wants marketing?

This is difficult to justify where the company has no prior KVKK processing condition for receiving and using the number. The commercial-message regulation also prohibits sending a commercial electronic message simply to request approval. A person-initiated referral link is usually the more defensible design.

Can we market similar products to existing customers without new approval?

Do not assume so. Türkiye’s commercial-message rules contain narrow exceptions for changes, use or maintenance relating to obtained goods or services and for specified non-promotional operational notifications. They do not establish a broad existing-customer exception for marketing similar products. The KVKK processing condition must also be assessed separately.

Are B2B referrals outside the KVKK?

No. Contact data relating to an identifiable employee, professional or sole trader can be personal data. The merchant/tradesperson exception under commercial-message rules does not remove the need for a KVKK basis.

Does outsourcing calls transfer responsibility to the call centre?

No. A controller remains responsible for the lawfulness and governance of the campaign. The call centre may also have direct obligations as a processor, an intermediary service provider under commercial-message rules, or a controller for activities it determines independently.

Conclusion

The 21 July announcement does not ban referral marketing, and it does not say explicit consent is the only possible basis for every marketing activity. It does, however, remove a common shortcut: a third party’s willingness to provide someone’s details is not a legal basis for the company’s processing.

The most defensible referral programs minimize third-party collection, invite the prospective customer to initiate contact, keep privacy notices and permissions separate, and connect CRM outreach to evidence that can be tested. Businesses should review the whole chain—from the referral form and reward model to call-centre scripts, IYS status, suppression and deletion—not only the wording of a consent checkbox.

Kooch Cybersecurity & Compliance can help organizations map referral and lead-generation flows, distinguish KVKK and IYS requirements, improve notices and CRM evidence, and review vendor and retention controls. Where a campaign depends on a disputed legal interpretation, the operational review should be coordinated with qualified Turkish legal counsel.

Sources and references

This article provides general information and does not constitute legal advice.

Masoud Salmani