All articles

Software Development · 6 min read

Is your website ready under Turkish data protection law?

Adding a disclosure notice does not by itself create compliance. Knowing what you actually collect is where the work starts.

01Take an inventory first

Compliance begins with discovery, not with writing text. Where on your site do you collect personal data? The contact form, cookies, server logs, newsletter sign-ups, application forms. A notice written without that list does not reflect reality, and that is precisely where the risk lies.

02The text must match the truth

A notice copied from a template may describe practices you don't have or omit something you genuinely do. It should accurately state what you collect, why, how long you keep it and who you share it with. What gets examined is not whether a notice exists but whether it is accurate.

03Ask for consent at the right moment

The disclosure must be reachable at the point where data is given. A link beside the form is better than forcing the user to hunt in the footer. Non-essential cookies should run only after explicit consent; a tracking tag firing before consent is the most common failure.

04Be ready for deletion requests

When someone asks for their data to be deleted, you must be able to do it within a reasonable time. If you don't know where the data sits, you cannot honour the request. That is the second benefit of the inventory: when a request arrives, you know where to look.

Need a hand with this?

Let's solve the same problem for you.

Tell us about your project