6 regulations in force in Türkiye and the EU, on one page.
KVKK, GDPR, EAA, KAİK, Google Consent Mode v2 and Circular No. 2025/10: which one affects you, what is the scope, what should you do? Practical guides, penalty details and direct solution paths.
Every company operating in Türkiye is affected by at least one, and those selling into the EU market by more than one.
KVKK
KVKK: Cookie Management
Law No. 6698 (Türkiye)
The personal data protection law mandatory for all companies operating in Türkiye. Cookie usage requires disclosure and explicit consent. KVKK Board administrative fines are updated annually by the revaluation rate.
Covers all companies targeting the EU market, including Turkish firms. It jointly governs cookie consent, the ePrivacy Directive and Schrems II data transfer rules. The maximum fine is 20M€ or 4 percent of global turnover.
Mandatory for all companies offering B2C digital services in the EU. WCAG 2.1 AA compliance and an official accessibility statement are required. E-commerce, mobile apps and SaaS products targeting the EU are within scope.
The public information systems accessibility guide published by the Presidential Digital Transformation Office. Public institutions and private firms bidding on public tenders must comply with the WCAG criteria.
Mandatory for EU and UK traffic for all advertisers using Google Ads and GA4. It manages data flow based on consent status; without it, conversion data cannot be sent and personalized ads cannot be run.
Contains the latest regulations on accessibility and personal data management in public digital services. It sets out the priorities and implementation timeline for public institutions and firms that partner in public services.
Quickly check which obligations apply to you based on your company profile.
Company Profile
KVKK
GDPR
EAA
KAİK
GCM v2
E-commerce in Türkiye (TR sales only)
✓
-
-
-
Recommended
E-commerce targeting the EU (Trendyol Europe etc.)
✓
✓
✓
-
✓
Public institution in Türkiye (municipality, ministry)
✓
-
-
✓
-
Private software firm bidding on public tenders
✓
-
-
✓
-
News and publishing site (TR and EU)
✓
✓
✓
-
✓
SaaS B2B (TR customers only)
✓
-
-
-
Recommended
SaaS B2B (has EU customers)
✓
✓
-
-
✓
Mobile app B2C (EU market)
✓
✓
✓
-
✓
Quick comparison
Penalties, scope and effective date at a glance.
Compare the regulations by supervisory authority, maximum sanction and subject matter.
Regulation
Max. Sanction
Supervisory Authority
Effective Date
Subject
KVKK
Updated annually (kvkk.gov.tr)
KVKK Board
07.04.2016
Personal data and cookies
GDPR
20M€ or 4 percent of turnover
Member state data authorities
25.05.2018
Personal data and cookies
EAA
Varies by member state
Member state accessibility boards
28.06.2025
Digital accessibility
KAİK
Exclusion from tenders
Presidential DDO and the Court of Accounts
Circular 2019/12
Public site accessibility
GCM v2
Loss of advertising and analytics data
Google (automatic)
03.2024 (EU and UK)
Advertising consent signal
2025/10
Tender and audit sanction
Presidential DDO
2025
Public digital compliance
FAQ
The questions on your mind
What is the main difference between KVKK and GDPR?
KVKK applies in Türkiye, GDPR in the EU. KVKK is Law No. 6698 (which took effect in 2016), while GDPR took effect in 2018. KVKK administrative fines are updated annually by the revaluation rate; for current figures see kvkk.gov.tr. Under GDPR the maximum sanction is 20M€ or 4 percent of global turnover. While GDPR is interpreted much more strictly, the KVKK Board has recently raised penalty amounts significantly.
Does the EAA cover companies in Turkey?
Yes. All Turkish companies offering goods or services in the EU fall under Directive 2019/882 (effective 28 June 2025). If you have a distributor in the EU, an e-commerce site, a B2C mobile app, or you offer SaaS services to EU customers, the EAA is mandatory for you. It is not mandatory for the Turkish domestic market; for the domestic market the KAİK and TSE TS EN 301 549 standards apply.
Does Google Ads work without Google Consent Mode v2?
Since March 2024, GCM v2 has been mandatory for EU and UK traffic. Without it you cannot send conversion data or run personalized ads, and your Google Ads campaigns will show a warning. It is not yet mandatory for Türkiye traffic; however, it is also recommended for those who want to use Google's Enhanced Conversions feature. cerez.io The SDK sends GCM v2 signals automatically.
Which companies are affected by all 6 of these regulations?
Turkish e-commerce sites that sell to the EU and bid on public tenders fall under the broadest scope: KVKK and GDPR apply for cookie management, EAA for accessibility, KAİK for tender specifications, GCM v2 for Google ads, and Circular 2025/10 for public channels. cerez.io The bundle package lets you manage all of them from a single panel.
Does KAİK cover non-public companies?
KAİK directly binds public institutions; however, private companies participating in public tenders are considered within scope because the tender specifications will require KAİK compliance. For example, a private firm developing e-municipality software for a municipality must document KAİK compliance at the bid stage. The EAA, on the other hand, covers all EU B2C private companies.
cerez.io what does it offer for these 6 regulations?
A Cookie Consent panel for KVKK and GDPR (cookie scanning, category management, consent log), an Accessibility Widget for EAA and KAİK (40+ features, 10+ profiles, WCAG-based scanning), automatic Google Consent Mode integration for GCM v2. One SDK, one panel, one invoice. A TL payment option is available for Turkish companies. View pricing.
6 regulations, 1 platform. Start today.
Manage all your compliance needs from KVKK to GCM v2 from a single panel. Start free, no credit card required.
⚡ YASAL ZORUNLULUK2025/10 Cumhurbaşkanlığı Genelgesi: Kamu, belediye, banka, üniversite, hastane, okullar için
21 Haziran 2026'ya WCAG 2.2 A zorunlu
· Ceza: 5.000–25.000 TL/tespit