
Last updated: 2026-07-28
A prospect stays on a sales call. An existing customer asks about a campaign. Someone does not reply “RET” to an SMS. Can the CRM record any of these people as having consented to marketing?
Not on that basis alone.
In a public announcement dated 21 July 2026, Türkiye’s Personal Data Protection Authority addressed practices involving contact details obtained from customers and other third parties. It expressly stated that listening to a campaign, remaining on a call, requesting information or failing to send an opt-out response does not, by itself, constitute valid explicit consent under the Personal Data Protection Law No. 6698 (KVKK).
For marketing, customer-experience and compliance teams, the operational lesson is simple: absence of refusal is not consent.
Explicit consent should not be added to every customer journey by default.
KVKK permits personal data processing without consent when one of the other processing conditions in Article 5 applies. The correct condition must be assessed for each activity. Processing a telephone number to respond to a quote requested by a prospective customer, for example, is not necessarily the same activity as retaining that number for future campaigns.
Where a marketing activity relies on explicit consent, the consent must be:
It must also contain an affirmative expression of choice. The controller bears responsibility for proving that valid consent was obtained.
Consider this call:
Agent: “Your colleague gave us your number. We have a new corporate package that may interest you.”
Prospect: “What type of package?”
Agent: “It includes several services. I can explain them.”
Prospect: “Okay, go ahead.”
The agent selects Marketing consent: Yes in the CRM because the prospect continued listening.
Remaining on the call is not an affirmative consent statement. Nor is asking what the offer is about.
The prospect may simply be trying to understand who is calling and why. Converting that behaviour into consent would treat ambiguity as permission.
If the business needs explicit consent for a defined marketing activity, it should first provide the required information and then request a separate, clear choice.
A campaign team sends this message:
“We may contact you about our products. Reply RET if you do not want marketing communications.”
The recipient does not reply. The CRM changes the status from Consent unknown to Consent granted.
This is an opt-out mechanism, not evidence of an opt-in decision. Silence or failure to send a rejection does not establish valid explicit consent under KVKK.
The same problem arises when:
A valid opt-in requires a conscious action by the person. An available unsubscribe mechanism remains important, but it cannot retrospectively create consent that was never validly obtained.
Consider another call:
Prospect: “Could you send me the price and product details?”
Agent: “Of course.”
The CRM records:
Requesting information about a particular product is not the same as agreeing to unrelated or continuing marketing.
The business may be able to process relevant details to respond to the request, subject to the appropriate KVKK processing condition and notice. That does not automatically authorise:
CRM permissions should follow the purpose and scope of the person’s actual request. They should not expand it.
A customer enters a friend’s name and telephone number into a referral form. The CRM creates a new lead with:
Source: Customer referral
Consent: Yes
A referral identifies where the information came from. It does not prove that the referred person gave consent to the business.
The July 2026 announcement specifically addressed contact information received through referrals, recommendations, brand ambassadors and similar channels. Obtaining data from another person does not, by itself, create a legal basis for using it in advertising or marketing.
When personal data has not been obtained directly from the individual, the applicable transparency rules also require the controller to provide notice within the required period. Where the data will be used to contact the person, notice is generally required during the first communication.
That notice does not itself create consent. If the activity relies on explicit consent, the consent must be requested separately after appropriate information has been provided.
Importantly, the announcement does not create a general entitlement to make a marketing call simply to ask for consent. The processing condition for obtaining, storing and using the referral data—including the initial contact—must still be assessed.
A registration page contains one checkbox:
“I have read and accept the Privacy Notice, Terms of Service and consent to all processing and marketing activities.”
Registration cannot be completed unless the box is selected.
A privacy notice and an explicit-consent request perform different functions.
The notice explains the processing. Consent, where required, records a voluntary decision about a specific activity. KVKK transparency rules require these processes to be handled separately.
A single bundled checkbox may create several problems:
General statements such as “all marketing,” “all products,” “all channels” or “current and future business partners” should be treated as warning signs. The Authority has previously criticised broad, future-facing and pre-selected permissions.
A practical CRM model should distinguish evidence from assumptions:
A defensible consent record should normally show what the person agreed to, which controller requested it, the relevant purpose and channel, when and how the choice was made, and the version of the wording presented.
If call recordings are used as evidence, the recording, retention, access and notice arrangements must themselves comply with the applicable data-protection requirements.
An approved script might separate the stages as follows:
Agent: “I am calling from [Company]. We obtained your telephone number through [specific source]. Before proceeding, I need to explain how we use your information. You can access the full privacy notice at [accessible channel].”
Agent: “May we use your telephone number to contact you by phone about [specific campaign or product category] until [relevant period]? Saying no will not affect [the core service or inquiry, where applicable].”
Prospect: “Yes.”
The wording must match the actual processing operation. A script cannot repair an unlawful data source, an unsuitable legal basis or broader processing hidden elsewhere in the CRM.
Telephone calls, SMS messages and emails may also fall under Türkiye’s commercial electronic communications regime and the Message Management System (İYS). Prior approval is generally relevant under that regime, subject to its scope and exceptions.
Compliance with İYS requirements does not remove the need to comply with KVKK when telephone numbers, email addresses, preferences and campaign histories are processed. Likewise, a broad CRM flag should not be assumed to prove compliance with both regimes.
Teams should map the requirements together while keeping the legal bases, notices, consent evidence, channel preferences and withdrawal records distinguishable.
Marketing, customer-experience, legal and compliance teams should test whether:
The most important redesign may not be the wording of a checkbox. It may be the rule that determines when the CRM changes a person from unknown to consented.
Under KVKK, a person’s silence is not a marketing asset. Neither continued listening, curiosity nor failure to opt out should be converted into explicit consent.
Organizations should use affirmative, informed and specific choices—and ensure that call-centre scripts, privacy notices, CRM fields and campaign platforms all preserve that choice accurately.
Kooch helps organizations review consent journeys, redesign privacy notices and operational workflows, and train marketing and customer-facing teams on practical KVKK implementation. If your CRM cannot show how a marketing permission was obtained, what it covers and whether it remains current, that is a sensible place to begin the review.