A contact form, a Google Analytics tag, an embedded map: any one of these means your website processes personal data. In the EU, the GDPR governs how you collect and use that data; in Turkey, Law No. 6698 on the Protection of Personal Data (KVKK) does the same. This article isn't legal advice. It's a summary of the requirements and mistakes we run into most often as an agency that builds and runs websites.
What personal data does your website process?
Many businesses assume their site doesn't process personal data. If any of the following is on your site, it does:
- Contact, quote or newsletter forms that collect names, e-mail addresses or phone numbers
- Analytics tools that collect IP addresses and device information (such as Google Analytics)
- Advertising pixels such as the Meta Pixel or the Google Ads conversion tag
- Embedded content that makes the visitor's browser call third-party servers: YouTube videos, Google Maps, externally hosted fonts, live-chat widgets
- Accounts, orders and payment systems
The first step is an inventory of these touchpoints: what data is collected, for what purpose, where it goes and how long it's kept.
The privacy notice: the first document every site needs
Article 13 of the GDPR (and Article 10 of the KVKK) requires you to inform people when you collect their data. Your privacy notice should state, at a minimum:
- Who the controller is and how to contact them
- The purposes of processing and the legal basis for each
- Who receives the data, including hosting, e-mail and analytics providers
- Whether data is transferred outside the EU (or Turkey) and on what safeguards
- How long the data is kept
- People's rights, how to exercise them and the right to complain to a supervisory authority
The most common mistake is copying a template from the internet. Templates list tools you don't use and miss the ones you do. Your privacy notice should be built from the inventory in the previous step.
Another key point: informing people and asking for consent are separate acts. Under the GDPR, a request for consent must be clearly distinguishable from other matters, and Turkish rules likewise require the information duty to be fulfilled separately from consent. Bundling both into one checkbox puts the validity of that consent in doubt.
Photo: Dan Nelson / Unsplash
Cookie banners: “This site uses cookies” isn't enough
European practice under the GDPR and ePrivacy rules, and the cookie guidance published by Turkey's data protection authority in 2022, point the same way: apart from cookies strictly necessary for the site to work, analytics, personalisation and marketing cookies need the visitor's prior, freely given consent. In practice, that means:
- No non-essential cookies before consent. Analytics and advertising tags must not run until the visitor agrees. The most common error is tags already firing in the background while the banner is still on screen.
- Refusing must be as easy as accepting. If “Accept” is big and colourful and “Reject” is a small link three clicks away, consent isn't freely given. France's CNIL is especially clear on this.
- Pre-ticked boxes don't count. Cookie categories should be off by default.
- Continuing to browse isn't consent. Implied consent doesn't meet the standard.
- Visitors must be able to change their mind. A “cookie settings” link should be available at all times, typically in the footer.
If you use Google Analytics or Google Ads, you also need Google's Consent Mode v2. Since 2024, Google has tied personalised advertising and remarketing features for users in the European Economic Area to these consent signals. Set up correctly, the visitor's choice is passed to Google's tags in full and your ad measurement keeps working. We cover what's actually worth measuring in our GA4 article.
Contact forms: less data, clear information
- Ask only for what you need. Data minimisation means not collecting data you don't need for the purpose. A quote form has no reason to ask for a date of birth or an ID number. Shorter forms also convert better.
- Link to the privacy notice right next to the form. Visitors should see how their data will be used before they submit it.
- Marketing consent must be separate and optional. Submitting the form must not mean signing up to a newsletter, and the box must not be pre-ticked. In the EU, marketing e-mails to individuals generally require prior consent; in Turkey, commercial message consents must also be registered in the İYS (Message Management System).
- Transmit and store the data securely. The site must run on HTTPS, and form submissions shouldn't pile up in a shared inbox everyone can open or in an unprotected spreadsheet. Any spam-protection service you use should also appear in the privacy notice.
- Set a retention period. Keeping enquiries from two years ago that never turned into work, indefinitely, is both a risk and a liability.
Invisible data flows: fonts, videos and maps
An embedded YouTube video or a font loaded from Google's servers sends the visitor's IP address to a third party as soon as the page opens. In Europe, this has even reached the courts. The fixes are simple:
- Serve fonts from your own server. It makes pages faster, too.
- Use a “click to load” approach for videos and maps, or YouTube's privacy-enhanced embed mode.
- Remove old tags and pixels you no longer use. Many sites still send data through tags left over from campaigns that ended years ago.
International transfers
Most hosting, e-mail and analytics services process data outside the EU. Under Chapter V of the GDPR, transfers need a legal mechanism: an adequacy decision, the European Commission's Standard Contractual Clauses, or, for certified US recipients, the EU–US Data Privacy Framework. Check which mechanism each of your providers relies on and reflect it in your privacy notice.
If you also operate in Turkey: KVKK
The KVKK's core principles largely overlap with the GDPR, with some specifics. Since a 2024 amendment, Article 9 allows transfers abroad on appropriate safeguards such as standard contracts, which must be notified to the authority within five business days of signing. Depending on size and sector, you may also have to register in VERBİS, the data controllers' registry; check the current exemption thresholds for headcount and annual balance sheet on the authority's website. And while the KVKK has its own penalty regime, the GDPR allows fines of up to €20 million or 4% of worldwide annual turnover for serious breaches. On a multilingual site, privacy and cookie texts must be complete and equivalent in every language; for the technical side, see our guide to multilingual websites.
Quick checklist
- Every data touchpoint on the site (forms, tags, embeds) has been inventoried.
- An up-to-date privacy notice based on that inventory is published.
- A separate cookie policy explains the cookie categories in use.
- Non-essential cookies don't run before consent; “Reject” is as visible as “Accept”.
- Cookie preferences can be changed from any page.
- Consent Mode is set up for Google tags.
- Forms ask only for necessary data and link to the privacy notice.
- Marketing consent is separate, optional and not pre-ticked.
- Fonts are self-hosted; videos and maps are embedded in a privacy-friendly way.
- International transfers and any registration duties have been reviewed with an expert.
Frequently asked questions
I'm a small business with just a contact form. Does this apply to me?
Yes. Both the GDPR and the KVKK apply to anyone processing personal data, whatever their size. Some obligations have exemptions, but the duty to inform and to keep data secure applies to every business.
Will a cookie banner hurt my site's performance and conversions?
A badly built one can: a pop-up that covers half the screen, shifts content as the page loads or is hard to close hurts both users and your Core Web Vitals. A lightweight notice that doesn't shift the layout and lets people decide with one tap causes none of these problems.
Is an off-the-shelf consent management tool enough?
The tool is only part of the job. Even the best tool is useless if your tags run without being connected to it. After setup, always use your browser's developer tools to check which requests are sent before consent is given.
In short
Compliance isn't a document you write once and forget; it's a process to update whenever you add a new tool, form or campaign. The good news is that a compliant site is also a faster, cleaner site that visitors trust more. At Kasel, we design and build websites with consent management, self-hosted fonts and data minimisation planned in from the start. For the legal texts themselves, we recommend working with a legal adviser; if you need help on the technical side, get in touch.