Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
← All Insights
CategoryData Protection
Published12 February 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law

Push Notifications in Mobile Applications Under the Personal Data Protection Law

As a result of complaints submitted to the Personal Data Protection Authority and the examinations conducted, a need has arisen to assess whether push notifications sent to users via mobile applications comply with the fundamental principles and explicit consent requirements set forth under Law No. 6698 on the Protection of Personal Data.

A notification permission screen is where the lawfulness of an entire processing activity is decided.

Legal Framework and Fundamental Principles

In the processing of personal data, compliance with the general principles set forth under Article 4 of Law No. 6698 and the processing conditions stipulated under Article 5 thereof constitutes a legal obligation. Mobile application providers, in their capacity as data controllers, are required to observe the following legal standards in all technical structures and processes they design and implement.

Constitutional safeguard and the right to privacy. The protection of personal data constitutes a fundamental right pursuant to Article 20 of the Constitution. Given that mobile applications, by their very nature, provide direct access to individuals’ private spheres, they must refrain from any interference that would impair the essence of this right.

Compliance with law and the principle of good faith. Data processing activities must be aligned with the reasonable expectations of data subjects and must not involve deceptive practices. Complex consent mechanisms that steer users toward providing consent without genuine awareness constitute a violation of this principle.

Specificity, transparency and legitimate purpose. The data controller must clearly and explicitly define the concrete purposes for which personal data are processed. Rather than employing vague expressions such as “improving service quality”, specific purposes such as “sending real-time delivery notifications” or “assigning discount coupons” should be articulated.

Relevance, limited scope and proportionality. Processing personal data that is not necessary for the core functionality of a mobile application — for example, mandating location data solely for the purpose of sending promotional notifications — constitutes a breach of the principle of proportionality. In line with the data minimisation principle, only data that is strictly indispensable for the specified purpose should be processed.

Cumulative assessment of processing conditions. Pursuant to Article 5 of Law No. 6698, exceptions to explicit consent must be interpreted narrowly. While operational notifications may fall within the scope of performance of a contract, notifications intended for marketing purposes may only be based on the data subject’s explicit consent.

Legal Deficiencies Identified in Push Notification Mechanisms

In complaints submitted to the Personal Data Protection Authority and in ex officio investigations conducted by the Authority, it has been determined that the consent mechanisms presented to users during the installation or initial launch of mobile applications have been structured in violation of the mandatory provisions of Law No. 6698. In particular, as a result of direct examinations of the technical infrastructure and authorisation processes, the principal areas of non-compliance identified are set out below.

Bundled consent structure and violation of the principle of specificity. It has been observed that data controllers consolidate operational notifications directly related to the performance of a contract — such as order status and shipment tracking — together with marketing notifications containing campaign and advertising content under a single consent checkbox. This practice undermines the principle of processing for specific, explicit and legitimate purposes as set forth under Article 4 of Law No. 6698, as the data subject is unable to distinguish for which specific purpose consent is granted and to what extent. Consequently, the data processing activity lacks transparency.

Designs impairing free will. The ability of users to receive notifications that they reasonably expect by virtue of the nature of the service — for example, information on whether their order has been dispatched — is made conditional upon their consent to marketing content that provides no direct benefit to them. Such a structure eliminates the element of free will, which constitutes one of the fundamental components of explicit consent. Users are effectively compelled to provide consent in order not to be deprived of a functional feature, thereby rendering the consent legally defective.

Prohibition of conditioning the provision of services. Making the provision of a product or service conditional upon obtaining consent for a data processing purpose that is not necessary for the performance of that service is unlawful. In the practice of the Personal Data Protection Board, presenting marketing notifications as if they were an integral part of the service is regarded as an unlawful imposition, contrary to the spirit of Law No. 6698 and the principle of good faith.

Indeed, the Board’s Principle Decision dated 10 June 2025 and numbered 2025/1072 confirms this position. In its assessment, the Board characterised the combination of SMS verification codes sent during the provision of products and services with additional purposes — such as obtaining consent for commercial electronic communications or approval of a membership agreement — as “misleading data subjects”. The Board further resolved that structuring operational processes as a precondition for marketing activities, or obtaining approval for multiple purposes through a single action, would invalidate explicit consent by impairing its voluntary nature.

“Obtaining approval for multiple purposes through a single action invalidates explicit consent by impairing its voluntary nature.”

The Principle of Granular Explicit Consent

For explicit consent to constitute a legally valid ground for processing, it must relate to a specific subject matter, be based on adequate information, and be declared through a manifestation of free will that is free from any external influence. Within the mobile application ecosystem, these criteria materialise through the principle of granular explicit consent.

In scenarios where multiple data processing purposes of a different nature coexist, it is a mandatory requirement to provide the data subject with a separate and independent choice for each individual purpose. In examinations carried out within the scope of the Board’s supervisory authority, the practice of combining distinct purposes and presenting them in the form of bundled consent has been characterised as contrary to the principle of specificity underlying Law No. 6698.

Pursuant to the Board’s Principle Decision numbered 2025/1072, practices whereby entirely distinct processing activities — such as approval of a membership agreement, obtaining consent for the processing of personal data, and securing consent for commercial electronic communications — are carried out through a single action, for example a single “Accept” button within a mobile application or the entry of a single verification code, must be discontinued. The Board has ruled that separate options must be provided for each individual processing purpose.

Structuring a single declaration of consent in a manner that is technically or administratively indivisible compels the user either to accept all data processing activities or to reject them entirely — thereby being deprived of the digital service offered, in an “all or nothing” approach. Such a configuration fundamentally undermines the element of free will required for valid explicit consent and renders the consent legally invalid from the outset.

In circumstances where a personal data processing activity is not technically or legally necessary for the performance of the core service provided — for example, order tracking within a mobile commerce application — making such processing a precondition for accessing the service is incompatible with the principle of good faith.

The principle of granular consent is not merely a theoretical legal construct; it constitutes one of the most significant safeguards enabling users to exercise effective control over their own personal data. Data controllers are therefore obliged to design their application architectures and user interfaces in a manner that preserves this autonomy and transparently separates each individual data processing purpose.

Operational, promotional and analytics notifications must each carry their own, independently revocable choice.
Each purpose needs its own switch — technically as well as legally.

Obligations Within the Scope of Technical and Administrative Measures

Pursuant to Article 12 of Law No. 6698, data controllers are required to take all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, to prevent unlawful access to data, and to safeguard the preservation of data.

Data controllers must structure their application architecture in a manner that enables users to manage their preferences without any technical impediment. Within this framework, users should be provided — through in-app settings or notification management panels integrated with the device’s operating system — with the ability to select or refuse individually different categories of notifications, such as operational and shipment information, campaign and promotional announcements, or personalised analytics.

Indeed, under Article 12 of Law No. 6698, data controllers are obliged to conduct periodic audits of their systems and to provide the necessary training to their personnel. As demonstrated in the Board’s Decision dated 7 October 2022 and numbered 2022/1072, even the defence that an advertising communication was sent by an employee without the company’s knowledge does not absolve the data controller of liability. The Board imposed an administrative fine on the data controller for failing to ensure an appropriate level of security through adequate technical and administrative measures, and further ruled on the destruction of the relevant data.

Conclusion

Mobile application providers are required to reassess their push notification consent mechanisms in the light of the principles of granular explicit consent and specificity. The clear separation of notification purposes and the provision of mechanisms enabling users to manage their preferences effectively constitute a legal obligation in terms of both regulatory compliance and data security.

Practices that fail to adhere to these principles may give rise to administrative sanctions under Law No. 6698 on the Protection of Personal Data.