Offer

3 months of free support on every e-commerce package

See Details
Get a Quote
E-COMMERCE

E-Commerce Law: KVKK Compliance and the Distance Sales Contract

A comprehensive guide to e-commerce law, KVKK compliance, the distance sales contract and the right of withdrawal. Avoid penalties.

E-COMMERCE 16 April 2026 6 min read Toserof Tech.
HUK E-Ticaret Hukuku KVKK Uyumu

E-commerce law and KVKK compliance has, with the increased audits and rising penalty amounts since 2024, become a priority that Turkish e-commerce businesses can no longer ignore. Businesses that fail to meet their obligations under the Personal Data Protection Law (KVKK) and the Distance Contracts Regulation face serious administrative fines and suffer reputational damage. This guide covers the practical steps that will bring your e-commerce site into legal compliance.

What Is KVKK and What Are Its Obligations for E-Commerce Businesses?

The Personal Data Protection Law No. 6698 came into force in 2016 and introduced protection standards parallel to the GDPR in Europe. Because e-commerce businesses process personal data such as customer name and surname, email address, delivery address, telephone number and payment history, they hold the status of 'data controller'. This status gives rise to various legal obligations at the stages of collecting, storing, processing and deleting data. Registration with the Data Controllers' Registry (VERBIS) is mandatory for businesses whose annual net turnover exceeds five hundred million TL or which transfer data abroad; however, the obligations under KVKK apply to all businesses.

  • Explicit consent requirement: Explicit, freely given and informed consent must be obtained in order to send marketing emails, create profiles or share data with third parties.
  • Privacy notice: Before collecting data, the user must be presented with a notice explaining which data is collected and why, with whom it will be shared and the retention period.
  • Data minimisation: Only data that is essential for the service should be collected; date of birth or national ID number should not be requested if not required for the order.
  • Data security: Mandatory SSL, an encrypted database, access authorisation and regular security updates form the basis of the technical measures.

Cookie Policy Requirements

Under KVKK and the related secondary legislation, e-commerce sites cannot place analytics, marketing or targeting cookies without the user's explicit consent. Only strictly necessary cookies (session management, basket memory) can be used without consent. On first entry to the site, the user must be presented with a consent panel (cookie banner or cookie consent manager) that allows them to accept or reject each cookie category (necessary, functional, analytics, marketing) separately. A 'Reject All' option must be present that is as prominent as the 'Accept All' button. OneTrust, Cookiebot or local alternatives automate this management.

Mandatory Elements of the Distance Sales Contract

The Distance Contracts Regulation makes it mandatory for the consumer to be informed before the contract and for their approval to be obtained. The elements that must be included in the distance sales contract are as follows: the seller's title, address and contact details; the essential characteristics of the product or service; the total price (including all taxes and delivery charges); payment, delivery and return conditions; the right of withdrawal and the procedure for exercising it; and, where applicable, technical protection measures and digital content compatibility. The contract should be presented before order confirmation with a checkbox the user ticks to confirm they have read and accepted it; a permanent copy should then be sent by email.

The 14-Day Right of Withdrawal (Return)

The consumer's right of withdrawal period, raised from 7 to 14 days, became standard with the amendment that came into force in 2022. The consumer may withdraw from the contract within fourteen days of receiving the product without giving any reason. The seller must refund the payment within fourteen days of the withdrawal notice, and the consumer must hand the product over to the courier within ten days following the notice. The product categories in which the right of withdrawal is restricted are listed in the law: perishable goods, products personalised to the consumer's request, hygiene products whose packaging has been opened and digital content fall within this scope.

Privacy Policy and Data Controller Obligations

The privacy policy is the fundamental document that fulfils the obligation to inform under Article 10 of KVKK. Simply downloading and publishing a template is not enough; the policy must reflect your actual data processing practices. The headings that must be included in the policy are as follows: the categories of data collected, the purposes of processing and their legal bases, the third parties to which data is transferred (courier companies, payment intermediaries, advertising platforms), retention periods and the rights of the data subject (access, rectification, erasure, objection). Data subject requests (deletion and access requests) must be answered within thirty days; for this it is recommended that you set up a request form or a dedicated email address.

Penalties, Risks and a Compliance Checklist

The Personal Data Protection Board (the KVKK Board), through decisions issued in 2024, imposed administrative fines on e-commerce companies ranging from a few hundred thousand TL to several million TL. The data breach notification obligation is also a significant risk point; the Board must be notified within seventy-two hours of becoming aware of the breach. The compliance checklist should include the following items: VERBIS registration (if mandatory), privacy notice, explicit consent mechanisms, cookie consent panel, privacy policy, distance sales contract, preliminary information form, return procedure, technical data security measures and a data subject request channel.

Frequently Asked Questions

Are small-scale e-commerce sites also subject to KVKK?

Yes. KVKK covers all natural and legal persons that process personal data, regardless of business size. Although the VERBIS registration thresholds provide a partial exemption, the obligations regarding privacy notices, consent, privacy policy and data security also apply to small-scale businesses.

Must the distance sales contract be signed again for every order?

The contract terms must be presented to and approved by the user during every order. Usually a checkbox at the payment step reading 'I have read and accept the Distance Sales Contract' satisfies this obligation. A one-off signature at account creation is not sufficient.

Can a no-returns policy be applied?

Refusing returns is not possible for products covered by the statutory right of withdrawal; this is an inalienable right granted to the consumer. However, in the legal exception categories such as perishable foods, made-to-order products and hygiene products whose packaging has been opened, the seller may decline returns. These exceptions must be stated clearly in the contract.

What should be done in the event of a data breach?

The Personal Data Protection Board must be notified within seventy-two hours of the moment you learn of the data breach. Delaying the notification and failing to inform the individuals affected by the breach lay the ground for additional sanctions. During the breach process, preserving evidence, isolating the affected systems and obtaining legal advice are the priority steps.

Conclusion

E-commerce law and KVKK compliance does not merely reduce the risk of penalties; it reinforces customer trust and contributes to building long-term brand value. Compliance is not a one-off project; it is a living process that must be updated in step with changing legislation. Contact Toserof Tech. for your e-commerce growth strategy.