You will certainly have encountered the notice “This site uses cookies…” appearing at the bottom or top of a website when you visit it. So what are these cookies, why do sites keep reminding us about them, and what obligations do you have as a site owner?
What Is a Cookie?
Cookies are small text files saved to your computer or phone when you visit a website. These files allow the site to remember you. For example, on an e-commerce site, the reason a product is still in your basket when you return the next day, after adding it and closing the page, is cookies.
By storage duration, cookies are divided into session cookies (deleted when the browser is closed) and persistent cookies (remaining on the device for a set period); by source, into first-party cookies placed by the site itself and third-party cookies placed by other organisations such as advertising networks.
Which Cookies Require Explicit Consent?
Not all cookies are subject to the same legal regime. The distinction is drawn according to the function of the cookie:
- Strictly necessary (technical) cookies: Cookies indispensable for the delivery of the service, such as operating the site, session security and preserving the basket. Separate explicit consent need not be obtained for these; they must nonetheless be explained in the cookie policy.
- Functional and preference cookies: These remember language, region or display preferences. They require consent to the extent they are not strictly necessary for delivery of the service.
- Analytics and performance cookies: These measure visitor behaviour. They are subject to consent to the extent they render the user identifiable.
- Advertising and marketing cookies: Used for profiling and targeted advertising. Explicit consent must always be obtained for these cookies.
Legal Basis
The legal framework for cookie practices does not consist of a single provision. In Türkiye, the provisions of Personal Data Protection Law No. 6698 on the conditions for data processing, the duty to inform and data security are applied together with the relevant rules of Electronic Communications Law No. 5809. The Personal Data Protection Board has also published a separate guide on cookie practices, emphasising that cookies should not be placed before consent is obtained.
What Makes Cookie Consent Valid?
Placing a banner on the screen stating “By continuing to use the site you are deemed to have accepted cookies” does not, by itself, constitute valid consent. For consent to be legally valid, it must be:
- Obtained in advance. Non-essential cookies must not be placed on the device before the user has made a choice.
- Based on information. Which cookie is used for what purpose, for how long, and with whom it is shared must be explained in plain language.
- Freely given. Refusing must be as easy and as accessible as accepting; designs offering only an “Accept” button are problematic.
- Not pre-ticked. Consent boxes that come switched on by default do not count as valid consent.
- Withdrawable. The user must be able to change their preferences easily afterwards.
- Separate from the information notice. Discharging the duty to inform does not mean explicit consent has been obtained; these two steps must be carried out separately.
What Should a Cookie Policy Contain?
- The identity and contact details of the data controller.
- A list of the cookies used, with the type, purpose and retention period of each.
- Third-party cookies and the organisations to which they belong.
- Whether data is transferred abroad.
- The user’s rights under the data protection legislation and how to exercise them.
- How cookie preferences may be changed, with an explanation of browser settings.
Consequences of Non-Compliance
Where the duty to inform is not discharged, where cookies requiring explicit consent are used without obtaining it, or where data security measures are not taken, the Personal Data Protection Board may impose an administrative fine. The Board has the power to open an investigation upon complaint or of its own motion. Beyond that, the damage to user trust and to brand reputation should not be overlooked.
If you have a website, taking an inventory of the cookies you use, establishing properly configured consent management and documenting these in a comprehensible cookie policy is the first and most important step in bringing your site into compliance. Since additional obligations may arise depending on the types of data your site collects, it is advisable to carry out the compliance exercise with a lawyer.