You often hear the phrase "get explicit consent for KVKK." In reality, however, not every processing activity requires explicit consent. Explicit consent is just one of the seven separate processing conditions under KVKK, and it is usually the weakest legal basis of all.
The 3 Requirements for Explicit Consent
Article 3/1-a of KVKK defines explicit consent as "consent related to a specific subject, based on being informed, and declared with free will." Three elements are essential for valid explicit consent:
1. Being Informed
When giving consent, the data subject must know which data will be processed, for what purpose, and by whom. For this reason, the disclosure notice must be shown before consent is collected.
2. Based on Free Will
Consent cannot be made a precondition for receiving a service. For example, the approach "if you do not give explicit consent, you cannot benefit from our service" does not constitute valid consent.
3. Related to a Specific Subject
Blanket consents such as "I consent to all my data being used for all purposes" are invalid. Separate, specific consent must be obtained for each purpose.
When Is Explicit Consent Not Required?
If one of the other legal bases listed in Article 5/2 of KVKK applies, explicit consent is not required. These are:
- Being expressly provided for by law (e.g. traffic data under Law No. 5651)
- Protection of life or physical integrity
- Establishment or performance of a contract
- Enabling the data controller to fulfil a legal obligation
- Data made public by the data subject
- Establishment, exercise, or protection of a right
- Legitimate interest (without harming fundamental rights and freedoms)
For example, if you are entering into a contract with a customer, you do NOT need explicit consent to process their billing information for the performance of that contract. This falls under Article 5/2-c (performance of a contract).
Typical Situations That Require Explicit Consent
- Marketing communications: Sending commercial electronic messages (Law No. 6563 + KVKK).
- Profiling: Automated decision-making processes.
- Transfer abroad: To countries without an adequacy decision (in certain cases following the amendment to Article 9 of KVKK).
- Special categories of personal data: Health, biometrics, criminal record, religion, etc. (subject to special rules).
- Use of cookies: Non-essential cookies.
How Should Explicit Consent Be Obtained?
- A separate checkbox: It must not be combined with the same box used to confirm reading the disclosure notice.
- Unchecked by default: The tick box must be empty by default.
- Clear language: Worded as "I give explicit consent for processing for the following purpose."
- Dated record: The date on which consent was obtained and the exact wording used must be retained.
- A way to withdraw: Consent can be withdrawn at any time, and the method of withdrawal must be clearly communicated to the user.
Examples of Invalid Explicit Consent
- A checkbox that is pre-ticked
- The "consent is mandatory to become a member" approach
- A single tick box reading "I have read the entire disclosure notice and consent to the processing of all my data"
- Undisclosed forms signed during a meeting
- Consent given by children (under 18) without their legal representative
What Should You Do When Consent Is Withdrawn?
When a data subject withdraws their consent:
- Processing is stopped immediately;
- The data is deleted, destroyed, or anonymized (KVKK Art. 7);
- If the data has been transferred, third parties are notified;
- If other legal bases exist (e.g. a statutory retention period), processing may continue for those bases.
Common Mistakes
- Confusing explicit consent with the disclosure notice.
- Requesting consent as a contractual condition.
- Obtaining consent for multiple purposes with a single checkbox.
- Failing to provide notification when consent is withdrawn.
- Presenting the consent box in hidden or tiny print.
Explicit Consent Management in SignLogger
SignLogger manages multiple consent categories (marketing, profiling, analytics), records each consent with a timestamp, and provides a withdrawal flow. Forms such as reseller applications, demo requests, and download requests apply the correct pattern for explicit consent: a linked disclosure notice, a separate checkbox, unchecked by default, and an open channel for withdrawal.
For details, see our KVKK disclosure notice.
Is Explicit Consent Required for Guest Wi-Fi?
This is one of the most frequently confused topics in the field. To collect a user's phone number on a guest Wi-Fi portal, verify it by SMS, and keep traffic logs, explicit consent is not required — because this processing relies on the "fulfilment of a legal obligation" (KVKK Art. 5/2-ç), arising from Law No. 5651. Asking for consent, or even offering a "do not accept" option, is a mistake; if consent is refused, the logging obligation does not disappear.
By contrast, if you want to use the same number captured on that portal screen to send campaign SMS messages, that is a separate purpose and requires its own explicit consent checkbox. The correct setup is: a disclosure notice (not consent) for logging + an optional opt-in box for marketing. For portal setup, see our Law No. 5651 Logging Obligation guide.
Practical Examples: Is Consent Required?
| Scenario | Explicit consent? | Legal basis |
|---|---|---|
| Keeping Wi-Fi traffic logs | No | Legal obligation (Law No. 5651) |
| Name and address for invoicing | No | Legal obligation (Tax Procedure Law) |
| Contact details for a contract | No | Establishment/performance of a contract |
| Marketing SMS/email | Yes | Explicit consent (+ commercial message approval) |
| Behavioral advertising via cookies | Yes | Explicit consent |
| Security camera recording | No | Legitimate interest (+ signage notice) |
Frequently Asked Questions
Can I make consent a condition of service?
No — a setup such as "you must accept marketing messages in order to use the Wi-Fi" removes consent from being based on free will and renders it invalid.
How do I prove explicit consent?
Keep a record of when consent was obtained, with what wording, and through which channel. SignLogger portal records can archive checkbox confirmations with a timestamp.