When it comes to email marketing, the first question on many businesses' minds is: "How do I do this legally?" In Turkey, the answer lives in two concepts: KVKK (the Turkish Personal Data Protection Law) and the commercial electronic message regulations. It may sound intimidating, but here is the good news: following the rules is not only about avoiding penalties — it is also about doing better marketing.
Because a business that works with permission writes to an audience that genuinely wants to hear from it, which means higher open rates, fewer complaints, and a stronger brand over time. In this guide we cover — in plain language and step by step — what KVKK-compliant email marketing is, how to obtain consent correctly, what İYS is for, and what to watch out for in practice.
Important note: This article is for informational purposes only and is not legal advice. For obligations specific to your situation, rely on the current legislation and a qualified legal advisor. It focuses on the rules that apply in Turkey.
KVKK and Email: Why Does It Matter So Much?
Under KVKK, an email address is personal data on its own, because it points to a specific individual. That means collecting, storing, and sending marketing emails to someone's address counts as processing personal data — and that processing needs a lawful basis. For marketing messages, in most cases that basis is the person's explicit consent.
Not following the rules has two kinds of cost. The first is direct enforcement: sending without consent can lead to administrative fines and complaints. The second is more insidious: people who receive unwanted email mark you as spam, which damages your sender reputation, until over time you can no longer even reach your consenting subscribers. So compliance protects your business both legally and in terms of deliverability.
There Are Actually Two Separate Rules: KVKK and Commercial Messages
To make things clear, it helps to separate the two frameworks, because they are often confused:
- KVKK (Law No. 6698): Concerns the lawful collection, storage and processing of personal data — here, the email address. The duty to inform, and explicit consent in most marketing scenarios, fall under this.
- Commercial Electronic Messages (Law No. 6563 and its regulation): Governs whom you may send commercial email/SMS to, and under what conditions. The core rule: obtain prior consent and provide an easy opt-out (unsubscribe) in every message.
In practice the two go hand in hand: when you send someone a marketing email, you need both a basis to process their personal data (usually consent) and that message must follow the commercial-message rules.
Obtaining Consent Correctly: The Most Critical Step
The heart of all compliance is obtaining consent correctly. Valid consent carries a few qualities at once: the person must give it of their own free will, clearly know what they are consenting to, and that consent must be provable when needed. The way to achieve this is simpler than it looks:
- Use a clear point of sign-up. The newsletter opt-in should clearly state what the consent is for: something like "I would like to receive campaigns and announcements by email."
- Keep the consent box empty (unchecked). A pre-ticked box is not valid consent; the person must make the choice themselves.
- Keep a record of the consent. Store when, from which source, and to what the person consented. Later, you will have a ready answer to "did this person give permission?"
- Use double opt-in where possible. Right after sign-up, send a confirmation email and ask the person to click the link. This also confirms that the real owner of the address gave consent.
If you want to start growing a permission-based list from scratch, our guide to creating your first campaign shows the whole flow, from collecting subscribers to your first send.
Do
- State clearly what you will send and ask for consent
- Leave the consent box empty (unchecked)
- Record the date, source and scope of consent
- Confirm the address with double opt-in
- Offer an easy unsubscribe link in every email
Don't
- Don't buy ready-made email lists
- Don't pre-tick the consent box
- Don't add people to a list without consent
- Don't make opting out hard or hidden
- Don't send content different from what was agreed
What Is İYS (the Message Management System)?
İYS (İleti Yönetim Sistemi) is a national system where consents for commercial electronic messages are stored and managed. Its purpose is simple: recipients can see which brands they have given consent to in one place, and exercise their right to opt out whenever they wish.
On the business side, the basic logic is this: if you send commercial electronic messages, you are expected to record the consents you obtain in İYS and, before sending, check whether the relevant number/address is in an opt-out state. If someone has opted out via İYS, you can no longer send them commercial messages.
The İYS obligation belongs to the sending business, and your exact scope (e.g. individual vs. trader recipients, your message volume) can vary under the legislation. For your own situation, it is best to rely on İYS's current rules and an expert's opinion.
What Every Commercial Email Must Include
Once you have obtained consent correctly, every commercial email you send must also carry a few essentials. These are both a legal requirement and a way to build trust:
- Make it clear who you are. Your sender name and brand identity should be visible; the recipient should understand at a glance who the email is from.
- Include contact information. Provide a way to reach you (e.g. legal trade name, address/email).
- Offer an easy opt-out. Every email must include a one-click unsubscribe link; anyone who wants to leave should be able to do so effortlessly.
- Keep content consistent with the consent. Send content that matches what the person agreed to; do not drift off-topic and erode trust.
When someone requests to opt out, you must process that request within a reasonable time (generally three business days under the regulation) and stop sending them commercial messages. A good email platform manages this for you automatically.
How Does Keysletter Help You Here?
Part of compliance concerns your own processes (consent texts, İYS records); but a good platform takes on most of the technical side. Keysletter is designed to make working with permission and transparency easier:
- Automatic unsubscribe link: Every email you send includes a one-click unsubscribe link, and opt-out requests are processed automatically.
- Double opt-in option: You can send new subscribers a confirmation email to verify that the real owner of the address gave consent.
- Consent record: The subscriber's join date, confirmation time and source are stored, so you can document consent when needed.
- Subscription preference management: Your subscribers can update their preferences or opt out entirely, and you keep your list clean and current.
Business-specific obligations such as İYS records remain yours to manage; but Keysletter takes on most of the technical load — building a permission-based list, processing opt-outs automatically, and documenting consent.
Common Mistakes
Most compliance problems come not from bad intentions but from a few common bad habits. The most frequent ones are:
- Buying ready-made lists. Purchased or scraped lists carry no consent; this both breaks the rules and quickly destroys your reputation.
- Sending to an old list with unclear consent. Deciding to "just try" a list collected years ago, with unknown source and consent, is risky.
- Making opting out hard. Hiding or complicating the unsubscribe link both violates the rule and creates anger.
- Not keeping consent records. If you cannot answer "did this person give permission?", you will be in a difficult position when a problem arises.
Frequently Asked Questions
What is KVKK-compliant email marketing?
It means collecting people's email addresses on a lawful basis (usually explicit consent) and sending email only with the content they agreed to, while offering an easy opt-out. At its core, it is about working with permission and transparency.
Can I send to an email list I purchased?
No. People on purchased lists have not given you consent; such sends break the commercial-message rules and seriously damage your sender reputation. Always grow your own permission-based list.
Is double opt-in mandatory?
It is not mandatory, but it is strongly recommended. Double opt-in confirms that the real owner of the address gave consent, makes consent easier to prove, and keeps your list cleaner from the start.
Can I email my existing customers without consent?
The general rule is prior consent. There may be some limited exceptions in the legislation (for example trader recipients or certain customer-relationship situations), but they are narrow and conditional. For your own situation, it is safest to rely on the legislation and a legal advisor.
Is registering with İYS mandatory?
Businesses that send commercial electronic messages are expected to record consents in İYS and check opt-out status before sending. İYS's current rules determine exactly what your scope is.
In Short
KVKK-compliant email marketing is not complex bureaucracy; it is the sum of a few common-sense principles. Obtain consent clearly and provably, send only the content that was agreed to, offer an easy opt-out in every email, and keep your processes (especially the İYS side) in order. When you do this, you are both legally safe and building a healthier, higher-performing list.
Remember: compliance is not an obstacle but the foundation of trust. Writing honestly and transparently to an audience that wants to hear from you is, in the long run, the most rewarding form of marketing. If you want to revisit the fundamentals of email marketing, take a look at our "What Is Email Marketing?" guide as well.
Start Permission-Based Email Marketing for Free
Note: This content is for informational purposes and does not constitute legal advice.