KVKK verification rules for loyalty cards
This article is for information only and is not legal advice. Consult your own counsel on how the rules apply to your programme. The decisions and article references below were last checked against primary sources on 25 August 2026.
A customer reads out their phone number at the till, the cashier types it in, points are applied. That is how most loyalty programmes in Turkey have worked for years, and it has a gap: nobody checks that the person reading out the number actually owns the account.
Turkey’s Personal Data Protection Board has closed that gap.
What the rule requires
Board principle decision 2026/266, dated 11 February 2026 (Official Gazette, 28 February 2026, issue 33182), obliges data controllers running loyalty card programmes to put in place a verification mechanism confirming that a transaction is genuinely being made by the cardholder.
You are the data controller here: the business that collects customer data and decides why it is processed. Buying your programme from a software vendor does not transfer that responsibility.
The decision does not mandate a specific method. Its operative wording asks data controllers to establish “appropriate verification mechanisms serving this purpose” (our unofficial translation of the Turkish original). It offers one-time SMS codes, and barcode or QR scanning provided through a mobile app or website, as examples only, and then leaves the list explicitly open-ended.
That detail works in your favour. You can build verification around your own till flow, and you are free to use different methods for different customer groups. What the Board is after is the outcome rather than the label: verification has to rest on something showing the person present owns the account, not on information anyone else could also know.
The legal basis is not a single article either. The Board reasons that a programme without verification cannot rely on any processing condition in Article 5 of Law No. 6698, that writing a transaction to the wrong account breaches the “accurate and up to date” principle in Article 4, and that placing responsibility on the customer through a membership agreement does not remove the data security obligation in Article 12.
The deadline: 28 February 2027
The original compliance window was six months from publication in the Official Gazette, which put it at 28 August 2026. Board decision 2026/1491, dated 22 July 2026, extended it to 28 February 2027 (Official Gazette, 13 August 2026).
Two practical readings. First, this is not an emergency. Second and more useful: do not expect a second extension. The deadline has already moved once, and making the same argument twice is harder.
What the penalty actually is
This is the question owners researching the topic ask most, so here it is without evasion.
There is no separate “loyalty programme fine”. The exposure comes from KVKK’s data security obligations (Article 12): controllers that fail to take the required technical and organisational measures can face administrative fines under Article 18. After the Board’s decision, a loyalty programme with no verification falls on the wrong side of “required measures”.
Amounts are revalued annually and the current lower and upper band is published in the Official Gazette each January. We do not print a figure here, because it would be wrong within a year, and a stale number in a compliance article is worse than none. Confirm the current band at kvkk.gov.tr or with your counsel. As an order of magnitude: the fine sits far above the cost of implementing verification.
Independently of any fine, a programme without verification already creates two concrete problems:
Points to the wrong person. One mistyped digit at the till writes points to somebody else’s account. That is both a loss for the customer and a complaint that takes time to unwind.
Account visibility. Anyone who knows the number can see that account’s spending history. In a small business this reads as theoretical; it stops being theoretical as the member base grows.
Does this apply to you
You are in scope if any of these is true:
- Customers earn or spend points by giving a phone number, email or card number at the till
- That information gives access to purchase history, balance or personal details
- Staff can complete the transaction without any further verification
Size is irrelevant. A single-site cafe and a 40-branch retail chain fall under the same rule.
Do we have to re-verify our existing members
The decision is about the transaction at the till, not the membership record. The phrase running through the text is “alışveriş esnasında”, during the purchase, and the obligation is to confirm that the transaction is genuinely being made by the cardholder. The reading that follows: you are not being asked to retroactively re-verify your existing member base, you are being asked to verify transactions from 28 February 2027 onward.
That difference is large in practice. The work is not a data cleanup project, it is a change to the till flow. A chain with 60,000 members does not have to reach every one of them; it has to put a working verification step at the register. This is our reading of the text rather than legal advice, so confirm it against your own member base with your counsel.
Choosing a method, and what it really costs
Because the Board published no closed list, the choice is yours. The methods in common use in Turkey are technically close to one another and operationally nothing alike. Seconds at the till and cost per transaction are what decide it:
| Method | Time at till | Cost per transaction | Best fit |
|---|---|---|---|
| SMS OTP | 10-20 seconds | An SMS charge every time | Businesses with no app |
| App approval | Instant | None | Chains with an app |
| Dynamic QR | Instant | None | High till traffic |
Programmes that already run physical card infrastructure also use a PIN tied to the card. It is fast at the till and costs nothing per transaction, but printing and distributing cards rules it out for any programme starting from scratch.
Is SMS verification mandatory
No. The decision mandates no method at all; it asks you to establish an “appropriate verification mechanism”. SMS OTP is assumed to be compulsory because it is the best known option, when in fact it is only one of the two examples the decision mentions, and the only one that bills per transaction. App or QR based verification meets the same obligation, and it is faster at the till.
The line item people miss is SMS. OTP is the easiest method to set up, but every verification sends a message and every message is billed. For a chain running 400 transactions a day that is not a setup cost, it is a permanent operating expense. App approval and dynamic QR cost nothing per transaction.
Adding 20 seconds to every transaction is its own cost in a QSR with queues at peak. Put those two together and app or QR based verification is usually the better call for high-volume operators.
On İYS: Law No. 6563 defines a commercial electronic message as one sent for commercial purposes. A verification OTP does not meet that definition: it is transactional, not a campaign or discount announcement. So you are not expected to collect separate İYS consent in order to verify someone. The one condition is that the message stays purely a verification: add a campaign or discount line to the same SMS and it becomes a commercial electronic message subject to İYS rules. Your İYS obligations for marketing messages continue as before.
What happens if you wait
Technically nothing until 28 February 2027. Two practical reasons make waiting expensive.
First, verification is not just a setting. The till flow changes, staff have to adjust, and customers have to learn a new step. This is not a switch you flip the week before.
Second, thousands of businesses will be doing this work at the same time. Expect queues at your software vendor and integrator in January and February 2027.
A practical path to compliance
1. Write down your current flow. What the customer gives, what staff do, what the system checks. Most businesses discover at this step that there is no verification at all.
2. Pick the method that fits your volume. Read the table above against your own transaction count.
3. Brief your staff. A cashier who sees verification as pointless friction will find a way around it. Explaining why matters as much as the mechanism.
4. Review your privacy notice. If verification introduces a new processing activity, your notice needs to cover it. You are welcome to look at our own KVKK notice as an example.
5. Produce evidence. Saying “we verify” may not satisfy an inspection; expect to show which transaction was verified and how.
Five questions to put to your current provider
Because the decision is outcome-based, “we are compliant” means nothing on its own. Ask these instead:
- How does the transaction at the till prove it was made by the account holder?
- Which plan includes that verification, and does it cost extra?
- If verification runs over SMS, who pays for the messages, and what does it do to the monthly bill?
- Is there a record of which transaction was verified and how, and can we produce it in an inspection?
- What do you need from us to switch it on before 28 February 2027, and how long is the queue?
Question four separates vendors. Saying “we verify” is easy; showing which transaction was verified is a different thing.
Where you stand with Bonobo
Verification ships on all three plans: Lite, Connected and Connected Pro. No add-on module, no upgrade required.
What happens at the till. The member shows a continuously refreshing QR code from their own Webapp, staff scan it, and the transaction is written to that member’s account. The code is not static, so a screenshot does not become something another person can use at the register. Recognition is instant, there is no per-transaction charge, and nothing for the customer to download from the App Store. This flow maps directly onto one of the two examples the Board itself names: barcode or QR scanning provided through a mobile app or website.
The first visit. If a new customer gives their phone number at the till and earns points on that same transaction, that transaction is in scope too. Bonobo checks the number against existing members first: if it already belongs to an account, the transaction is routed to the QR flow, so reading out somebody else’s number cannot write points to their account. If the number is new, there is no account to impersonate.
The alternative: a one-time code by SMS or email. You choose which. The email option removes the per-transaction SMS charge shown in the table above entirely. It is a reasonable starting point for businesses that do not want the QR flow, or whose member base does not use the Webapp.
The enrolment side is covered too. Consent at sign-up can be captured by sending a short code, or the member can register through the Webapp and give consent themselves. İYS flows work in both directions, from us to İYS and from İYS to us. These are consent rather than verification, but an inspection asks about both, so both are recorded.
Evidence. Which transaction was verified, and by which method, is written to the record. Step five of the roadmap above said that “we verify” may not satisfy an inspection; this is the answer to that step.
Our own legal counsel reviewed Bonobo’s membership consent and İYS flows and confirmed they meet the consent requirements in Turkey. That is not legal advice for your programme: confirm the effect of 2026/266 on your own till flow with your own counsel.
If you are coming from a programme with no verification at all, this is usually not new development: it is reviewing the existing flow, choosing a method, and getting staff used to the extra step. You can review the plans and what each includes.
Let us review where your programme stands, in 20 minutes. We will look at your current till flow and tell you which method suits your volume, with no commitment: request a compliance check.
Summary
- The Board decision requires cardholder verification in loyalty programmes
- The compliance date is 28 February 2027, already extended once
- Reading out a phone number does not count as verification
- The decision mandates no specific method: an “appropriate verification mechanism” is what it asks for, and the choice is yours
- SMS is not compulsory. App and QR based verification meet the same obligation
- The choice is operational: SMS costs per transaction, app and QR do not
- The job is verifying transactions from here on, not re-verifying your existing member base (our reading of the text, not legal advice)
- Verification OTPs are transactional messages and need no separate İYS consent