The Personal Data Protection Board (“Board”) has drawn a line in the sand. With its Principle Decision dated 11 February 2026 (No. 2026/266), published in the Official Gazette on 28 February 2026, the Board has taken aim at a widespread and long-standing practice in Türkiye’s retail ecosystem: the ability for third parties to use another individual’s loyalty card benefits simply by verbally providing the cardholder’s phone number or loyalty card number at checkout. The Board concluded that this practice amounts to the processing of personal data without the data subject’s knowledge or consent, in direct violation of the Law on the Protection of Personal Data No. 6698 (Kişisel Verileri Koruma Kanunu, “KVKK”).
How Loyalty Card Schemes Operate Today
Loyalty programmes span a remarkably diverse range of sectors — food retail, electronics, cosmetics, DIY, and fashion — and virtually all of them gate membership creation behind SMS verification codes or digital identifiers such as barcodes or QR codes. Yet the Board identified a striking disconnect: while sign-up processes involve clear authentication, no equivalent safeguards exist at the point of sale. Cashiers routinely accept a mere phone number or loyalty card number to grant discounts, promotions, or points — no questions asked. The result is a gap wide enough for transactions to sail through even when the cardholder is nowhere near the till, and without any mechanism to confirm that the person reciting the number actually has the cardholder’s authorisation.
The Board’s investigation laid bare the real-world consequences of this gap. The practice is not merely theoretical — it actively generates incorrect customer transaction records, produces invoices in the name of individuals who never made the purchase and populates loyalty histories with inaccurate data. Each of these outcomes collides with one of the KVKK’s most fundamental principles: personal data must be accurate and, where necessary, kept up-to-date.
Legal Assessment: Violations of Articles 4, 5, and 12 of KVKK
The Board found that transactions carried out solely through the verbal declaration of a phone number or loyalty card number cannot be justified under any of the legal grounds for processing set out in Article 5 of KVKK, and therefore constitute unlawful processing of personal data. In addition, recording purchases that were not made by the actual data subject, or issuing invoices in their name, violates Article 4’s accuracy and data quality requirements.
Perhaps most notably, the Board dismissed a defence that many retailers have long relied upon. Even though loyalty card agreements commonly state that cards are for personal use only, the Board made clear that contractual fine print does not relieve data controllers of their Article 12 duty to deploy appropriate technical and administrative measures for data security. In short: you cannot outsource your compliance obligations to your customers through membership terms.
New Compliance Standard for the Retail Sector
Going forward, data controllers must build verification mechanisms that confirm loyalty card transactions genuinely occur with the cardholder’s knowledge and consent. The Board did not prescribe a single solution — instead, it offered a menu of acceptable approaches:
- SMS-based one-time verification codes,
- scanning a barcode or QR code generated in the mobile application or website,
- presenting or scanning the physical loyalty card,
- entering the loyalty card password at the POS terminal,
- or providing opt-in settings through the online membership account to specify which transactions require verification.
The common thread across these options is flexibility rooted in proportionality. The Board envisions a risk-based verification architecture — one that scales the level of authentication to the transaction type, sensitivity level, and customer profile, including considerations such as technology literacy.
Six-Month Compliance Deadline and Enforcement
The clock is ticking. The Board has granted all data controllers a six-month compliance window running from the date of publication in the Official Gazette. Once that window closes, any data controller still permitting unverified transactions — or otherwise falling short of the Principle Decision’s requirements — faces administrative sanctions under Article 18 of the KVKK.
Six months may sound generous, but the operational lift is substantial. Companies will need to redesign checkout flows, update CRM and loyalty software, enhance POS technical capabilities, and retrain front-line cashier staff — all while ensuring that verification measures are applied consistently across every channel and location.
As of the date of this publication, the Board has not announced any extension or grace period beyond the original six-month window, and the Decision itself contains no mechanism for seeking one. Data controllers should therefore treat 28 August 2026 as a firm deadline rather than plan around the possibility of relief.
Implications for Retailers and Service Providers
This ruling marks a watershed moment for loyalty schemes in Türkiye. Companies must now walk a fine line: embedding robust verification without introducing friction that erodes the customer experience. Yet the decision is not all burden — it is also an opportunity. By stamping out unauthorised transactions, retailers stand to sharpen the accuracy of customer profiles, reduce disputes, boost data reliability, and ultimately deepen consumer trust.
For companies ready to get ahead of the curve, the practical starting points are clear:
- mapping all loyalty card transaction types and associated risks,
- designing tiered verification flows,
- implementing technical updates across POS, mobile and back-end systems,
- ensuring alignment across online and in-store environments, and
- updating privacy notices, membership terms and cashier training materials.
Conclusion
The Board’s 2026/266 Principle Decision is more than an enforcement action — it is a reset of the ground rules for loyalty card operations across Türkiye. By mandating verification for every loyalty card-based transaction, the Board aims to stamp out unauthorised use, safeguard the accuracy of customer data, and reinforce the integrity of personal data processing in the retail sector. With the six-month compliance window already running, the message to the market is clear: act now, or face the consequences.
For tailored guidance on implementation strategies, risk assessments, or sector-specific compliance considerations, reach out to the CMS Türkiye Data Protection and Technology team: Dr. Döne Yalçın and Erdinç Dalar.