What Is Email Marketing Consent? Approval, Explicit Consent, and Opt-Out

What Is Email Marketing Consent? Approval, Explicit Consent, and Opt-Out

This guide covers the differences between commercial message consent, explicit consent, the privacy notice, and İYS registration — and how to manage email collection and unsubscribe processes.

Category: Marketing Technology#Email Marketing#Marketing Automation#Permission Management#KVKK
Summarize with ChatGPT

Email marketing consent isn’t just a checkbox someone ticks. Setting up marketing communication requires managing commercial electronic message consent, the legal basis under which personal data is processed, the privacy notice obligation, communication preferences, and opt-out requests together.

In practice, these concepts often get lumped together under a single phrase — “consent under the data protection law” — even though they represent distinct obligations. A well-run automation system should be able to show what purpose each record is held for and which channel it can be contacted through.

This article is for general informational purposes only. It is not legal advice. Outcomes can vary depending on the applicable law, the nature of the activity, and the type of recipient. Current obligations should be verified with legal and data protection specialists before setup.

How Do the Three Layers Break Down?

It’s clearer to think of permission management in three layers:

LayerCore questionOperational record
Commercial electronic message consentCan marketing messages be sent to this person?Channel, consent date, source, text version
Legal basis for processing personal dataUnder what legal basis and purpose is the contact information processed?Purpose, processing basis, retention and access information
Privacy notice obligationWas the individual clearly informed about the data processing activity?The text presented, date, and channel

These records can live on the same screen, but the underlying concepts and the statements themselves shouldn’t be conflated.

Commercial electronic message consent is a recipient’s agreement to receive commercially oriented messages through channels like email, SMS, or phone calls. Campaigns, promotions, discounts, product announcements, and similar marketing content generally fall under this category.

The general rule is that consent must be obtained before sending a commercial electronic message. The Turkish Ministry of Trade’s guidance on commercial electronic messages explains prior consent for sending to contact addresses such as email and phone numbers, and how consent/opt-out records should be managed.

Consent needs to be provable. “This person was already on our list” isn’t, by itself, an adequate record-keeping practice. It should be possible to see which source the consent came from, what scope it covered, and which version of the text it was collected through.

Not always. Commercial electronic message consent relates to the conditions for sending commercial messages. Explicit consent, on the other hand, is one of the legal bases that can be relied on when processing personal data.

When evaluating a communication activity, two separate questions need to be asked:

  1. Under commercial-message law, can this channel be used to send messages?
  2. Under data protection law, what legal basis is the email address or phone number being processed under?

Not every instance of personal data processing automatically requires explicit consent. If another processing basis under the law applies, the process can rely on that — but the privacy notice obligation is still assessed separately. When contact information is used for marketing purposes, though, the processing basis and commercial message consent both need to be looked at together.

The Turkish Personal Data Protection Authority’s summary of decision no. 2022/861 shows why it’s risky to assume that a business email address visible online can be used for marketing purposes without limit.

Yes — both the concepts and the statements should be arranged separately. The privacy notice is the obligation to inform someone about a data processing activity. It doesn’t depend on the person’s consent. Where explicit consent is required, it needs to be a separate statement that’s specific, based on being informed, and freely given.

The Turkish Personal Data Protection Authority’s announcement on its February 18, 2026 policy decision explains that privacy notices and explicit-consent texts shouldn’t be presented intertwined.

Form design should preserve this separation:

  • The privacy notice is presented clearly and accessibly.
  • Where explicit consent is required, it uses a separate heading and a separate statement.
  • The commercial message preference is shown clearly in terms of channel and purpose.
  • An active, affirmative choice is captured instead of a pre-checked box.
  • Marketing consent that isn’t required for the service isn’t presented as a mandatory condition of the service.

Operationally, the following fields make up a basic consent record:

  • A unique identifier for the person or record.
  • The communication channel: email, SMS, or phone call.
  • Consent status: opted in, opted out, or unknown.
  • The date and time consent was obtained.
  • The source the consent was obtained from: form, contract, physical record, or another channel.
  • The version of the consent text shown to the person.
  • The version of the privacy notice and the date it was presented.
  • The most recent action that changed the status and its source.
  • İYS registration status, where applicable.

It may not be necessary to keep all of this information inside the marketing tool itself. What matters is having a clear data architecture that defines which system is the system of record and how the other systems align with it.

In electronic consent, the affirmative statement of intent needs to be clear; a person doing nothing doesn’t count as consent. The Turkish Personal Data Protection Authority’s guidance on obtaining explicit consent states that explicit consent must be a statement relating to a specific matter, based on being informed, and given of free will.

In practice, the following checks can be applied:

  1. Is the checkbox empty by default?
  2. Is the channel and communication purpose clear?
  3. Is a vague “any kind of communication” phrasing avoided?
  4. Are the consent text and the privacy notice text kept separate?
  5. Is the text version and the time of the action being recorded?
  6. Is there a verification process for incorrectly entered contact addresses?
  7. Is the way to unsubscribe or change preferences easy to find?

Is the Situation Different for Sending to Merchants and Tradespeople?

There is an exception to the prior-consent requirement for merchant and tradesperson recipients under the commercial electronic message framework. But this exception shouldn’t be read as an unlimited right to send messages.

According to the Ministry of Trade’s statement, once a merchant or tradesperson exercises their right to opt out, no further messages can be sent to them. Obligations relating to the processing of personal data also continue to apply separately.

The fact that an email address is published online or has a corporate domain doesn’t remove the need to evaluate the data source, the processing purpose, and the data subject’s rights.

Are Transactional Notifications the Same as Marketing Messages?

No. Notifications about orders, delivery, payment collection, debt reminders, ongoing memberships, or legally required information are not the same as promotional messages.

The Ministry of Trade’s regulation guidance carves out certain notifications tied to an ongoing transaction or service that don’t require prior consent. But adding campaign or promotional content to these messages can change their nature.

At least two message types should be kept separate when setting up automation:

  • Transactional messages: Required notifications for orders, membership, security, delivery, or service processes.
  • Marketing communication: Messages meant for promotion, campaigns, offers, or sales.

Whether required transactional notifications stop when someone opts out of marketing messages should be managed according to this distinction.

How Should the Opt-Out Process Be Set Up?

A recipient should be able to decline to receive commercial messages without giving a reason. The way to opt out should be easy, free, and consistent with the channel used.

The Ministry of Trade’s FAQ page states that sending commercial electronic messages must stop within three business days of an opt-out request.

The technical process can run in this order:

  1. The opt-out request reaches the central record.
  2. Consent status for the relevant channel is changed.
  3. The person is removed from active campaigns and automations.
  4. The change is propagated to connected systems.
  5. Re-import is prevented from reactivating the record.
  6. The time and source of the action are retained.

Simply removing someone from one mailing list may not be enough. The same record could resurface in a different segment, a different team’s list, or a sales automation flow. That’s why the opt-out record needs to be the central, overriding rule.

Where Does İYS Fit Into This Structure?

The İleti Yönetim Sistemi (İYS, Turkey’s centralized message management system) supports central management of consent and opt-out processes for commercial electronic messages. The Ministry of Trade’s İYS overview explains the system’s role in letting citizens view and change their consent from a single point, and in service providers’ burden of proof.

The following questions should be answered about the data flow between marketing automation and İYS:

  • Which system holds the master consent record?
  • How often do İYS changes reach the marketing system?
  • How does an opt-out inside the automation tool get reflected in the İYS process?
  • What’s the safe default that halts sending when sync fails?
  • Are channel-based preferences kept separate?

How Should Old Lists Be Migrated?

Records whose source and consent status are unknown shouldn’t automatically be treated as “consented.” When moving to a new tool, the list needs to be sorted by record quality rather than size.

A practical classification:

  • Records whose consent source and date can be verified.
  • Records kept because of a transactional relationship, where the marketing preference is separate.
  • Records whose merchant or tradesperson status needs separate evaluation.
  • Records with an unclear or conflicting source.
  • Records that opted out and need to stay on a suppression list.

Bulk emailing suspicious records to ask for renewed consent also requires separate legal review, since there are limits on requesting consent via electronic message itself.

Common Mistakes

  • Combining the privacy notice and explicit consent into a single checkbox.
  • Using a pre-checked box for marketing consent.
  • Not storing which version of the consent text was accepted.
  • Automatically treating business email addresses found online as opted in.
  • Applying an opt-out record to only a single list.
  • Adding promotional content to a transactional message.
  • Keeping consent and opt-out data inconsistent across different systems.
  • Treating the tool provider’s settings as the entirety of the legal process.

A Minimum Permission Architecture for Marketing Automation

Summary

Email marketing consent isn’t a single checkbox. Commercial electronic message consent, the legal basis for processing personal data, the privacy notice obligation, İYS registration, and the right to opt out all need to be managed as distinct pieces.

A good consent system keeps a provable record of the affirmative statement, the channel and purpose, the time of the action, the text version, and the change history. When an opt-out comes in, the person needs to be removed not just from one list, but from every relevant marketing flow.

Read this topic inside a learning path

You can read this post on its own, or continue through the guide section to follow related topics in a clearer order.

Open learning pathsSend feedback

Değerlendirme

Bu yazı ne kadar faydalıydı?

1 ile 5 arasında puanla

Değerlendirme

Bu yazı işine yaradı mı?

Tek tıkla puanlayabilirsin.

1 ile 5 arasında puanla