# KVKK Fines a Platform 250,000 TL for Tying Live Match Streaming to “Explicit Consent”

**URL:** https://securesys.com.tr/en/blog/kvkk-fine-live-match-streaming-tied-to-consent

A user simply wanted to watch a live match broadcast. They had met the membership conditions, but another condition appeared: giving explicit consent to receive commercial electronic messages.

When the user did not give that permission, they could not use the live match broadcast service.

The matter was taken to the Personal Data Protection Authority (KVKK) and an important decision emerged — one that concerns a very broad group, from digital platforms to e-commerce companies, from mobile applications to any organisation running a membership system.

KVKK decided to impose an administrative fine of 250,000 TL on an online licensed sports and games of chance platform that made use of its live match broadcast service conditional on explicit consent being given for commercial electronic messaging.

At the centre of the decision sits one of the most critical concepts of KVKK compliance:

Was the explicit consent genuinely given by free will?

### How Did the Incident Begin?

In the case underlying the KVKK decision, a user holding a membership on an online platform wanted to use the live match broadcast service.

The user stated that although they had met the other membership conditions set by the platform, they could not use the live match broadcast service because they had not given approval for commercial electronic messages to be sent.

In other words, the user was effectively offered this choice:

“If you give permission for commercial messages, you can use the service.”

The user then filed a complaint with the Personal Data Protection Authority.

As a result of the examination carried out by KVKK, it was established that the platform had made the provision of its live match broadcast service conditional on explicit consent being given for personal data to be processed for the purpose of sending commercial messages.

Result: an administrative fine of 250,000 TL.

But the importance of the decision for companies does not consist of the size of the fine alone.

### Why Did KVKK Impose a Fine?

Under Law No. 6698 on the Protection of Personal Data, one of the most important elements of explicit consent is that the person can make their decision by free will.

When a user is told;

“If you do not give consent you cannot use this service.”

it becomes debatable whether the consent given genuinely rests on free will.

The KVKK decision also drew attention to the fact that one of the fundamental elements of explicit consent is that it is “given by free will”.

This distinction is extremely important.

Because a box being ticked on a screen does not, on its own, necessarily mean that lawful explicit consent has been obtained under KVKK.

Organisations must also be able to answer this question:

When the user does not give this consent, can they continue to use the service in a reasonable way?

If the answer is no, a serious compliance risk can arise as to whether the explicit consent was given by free will.

### An “Accept” Button Does Not Always Mean Explicit Consent

One of the important mistakes made regarding KVKK compliance on digital platforms is the assumption that obtaining approval from the user is sufficient on its own.

But what matters under KVKK is not merely that the user pressed a button.

For explicit consent to be valid it must generally;

- relate to a particular subject,
- rest on information having been given,
- be expressed by free will.

These conditions must be met.

Making explicit consent mandatory for a personal data processing activity unrelated to membership, a campaign, application use or the provision of another service can therefore create a significant KVKK risk.

Marketing and commercial messaging permissions in particular must be handled carefully at this point.

### Can Service and Marketing Permission Be Tied Together?

One of the most striking points of the decision for companies emerges precisely here.

Personal data processing activities genuinely necessary for the provision of a service must be separated from personal data processing carried out within the scope of marketing activities.

Processing particular information may be necessary for a user to create an account, for instance.

But that same user wanting to receive advertising, campaigns or commercial electronic messages can be assessed within a different purpose.

Organisations must therefore be extremely careful when placing;

membership approval, the service agreement, the privacy notice, explicit consent and commercial electronic messaging permissions into a single approval mechanism.

An “accept everything with one box” approach can in some cases lead to serious KVKK compliance problems.

### KVKK Did Not Only Impose a Fine

Another important point of the decision sits here.

KVKK did not only decide to impose an administrative fine of 250,000 TL.

It also decided to instruct the platform to end the practice of making the provision of the service conditional on explicit consent being given for personal data to be processed for the purpose of sending commercial messages, and to inform the Authority about the action taken.

This shows why KVKK decisions must not be assessed by companies merely as a “fine risk”.

A KVKK decision;

- changes to existing membership processes,
- redevelopment of the application or website,
- changes to explicit consent screens,
- redesign of marketing processes,
- updating of privacy notices,
- review of the data processing inventory

can produce operational consequences extending this far.

The real cost may therefore in some cases not be the administrative fine alone.

### A Critical Warning for Companies: Check Your Explicit Consent Screens

This decision must not be seen as one concerning only sports or games of chance platforms.

Similar practices appear across very different sectors.

Similar risks can form on e-commerce sites, mobile applications, financial technology companies, retail platforms, loyalty programmes, digital content services, SaaS applications and other digital services holding a membership system.

Reassessing these structures in particular carries importance:

#### \1. Mandatory explicit consent boxes

It must be checked whether the user is required to consent to data processing activities not genuinely necessary for them to use the service.

#### \2. Pre-ticked options

Designs in which the user is treated as having given approval without showing an active intention must also be assessed.

#### \3. Multiple operations under a single approval

Combining the membership agreement, the KVKK privacy notice, explicit consent and commercial messaging permission within the same mechanism must be examined in compliance terms.

#### \4. Withholding service from a user who does not consent

It must be determined whether the explicit consent is genuinely necessary for the provision of the service.

#### \5. Withdrawal of consent

Processes must exist through which the user can easily withdraw the consent they gave.

### Dark Pattern Designs Can Also Create Risk Under KVKK

Another important dimension of the matter is user interface design.

Offering a user a theoretical “reject” option may not always be enough.

For example;

the “Accept” option being extremely visible while the “Reject” option is hidden, the user being steered continuously towards giving approval, or unnecessary permissions being made mandatory in order to continue with the service can all affect the user's will.

KVKK compliance must therefore no longer be seen as consisting only of the texts prepared by the legal department.

Web and mobile application design is also part of the personal data protection process.

Many units must be involved in the process, from UX/UI teams to software developers, from the marketing department to the legal and information security teams.

### KVKK Compliance Is Not Merely Preparing a Privacy Notice

One of the most important misconceptions we encounter in companies is KVKK compliance being assessed at the level of;

“we prepared a privacy notice, we have an explicit consent text, we added a cookie banner”.

That is where the thinking stops.

But a genuine KVKK compliance process is far broader than that.

The organisation's;

which personal data it collects, why it collects it, which legal basis it relies on, where it stores it, who it shares it with, how long it keeps it, how it destroys it and with which technical and administrative measures it protects it

must be assessed as a whole.

This incident is one of the concrete examples of that.

The platform holding an explicit consent mechanism was not enough.

How the consent was obtained and whether the service was tied to that consent were also examined.

### What Should Organisations Do?

Following decisions of this kind, companies must test their existing KVKK processes not merely at document level but through the real user journey.

In a KVKK compliance review these scenarios must be checked in particular:

Which screens does the user encounter when signing up?

Which permissions are mandatory?

Which permissions are optional?

What happens when the user refuses?

Can they continue using the service?

Have explicit consent and the obligation to inform been separated from one another?

At which stage are commercial messaging permissions obtained?

How does the user withdraw the permission they gave?

Are records of the permissions given being kept?

To which systems is personal data transferred on the back end?

The answers to these questions must be on the agenda not only of the legal teams but of the information security, software, operations, marketing and management teams too.

### KVKK Technical and Administrative Compliance With SecureSys

KVKK compliance does not consist only of preparing legal documents.

Organisational processes and technical security controls must be handled together for personal data to be protected.

As SecureSys we support organisations in their KVKK and information security compliance processes under the headings of;

- current state and GAP analysis,
- assessment of personal data processing procedures,
- analysis of technical and administrative measures,
- review of access privileges,
- data discovery and classification,
- logging and monitoring procedures,
- DLP and data security controls,
- penetration tests and vulnerability analyses,
- incident response procedures,
- assessing ISO/IEC 27001 and KVKK compliance work together

These are the areas in which we provide support.

Because in the protection of personal data the critical question is not merely;

“Did you obtain explicit consent?”

That is not the whole of it.

The real questions are these:

Was that consent obtained lawfully?

Do you genuinely need the data you collect?

And can you genuinely protect the personal data you collect?

### Conclusion: One Tick Box Cost 250,000 TL

A process that began with the explicit consent condition faced by a user who wanted to watch a live match broadcast ended with an administrative fine of 250,000 TL.

But the message the decision gives companies is far more important than the size of the fine:

Obtaining explicit consent and obtaining lawful explicit consent are not the same thing.

Organisations providing digital services must separate their membership, marketing, commercial messaging and personal data processing procedures from one another correctly; offer the user a genuine right of choice; and base personal data processing activities on appropriate legal grounds.

A tick box that looks small today can become the subject of a KVKK examination tomorrow.

Source: TRT Haber – “KVKK'dan canlı maç yayını izlemek için ‘açık rıza’ şartı koşan platforma ceza”
