KVKK-Compliant Cold Outbound: The Legal Boundaries in Turkey

Strategy
Most B2B sales teams in Turkey still run cold outbound with an "everyone does it, nothing will happen" mindset. They get a lead list, load the email addresses into a tool and launch sequences to a few hundred people a week. Meanwhile, the Personal Data Protection Board issues more decisions every year, and public awareness keeps growing. Since the Message Management System (İYS) went live, commercial messages are also tracked far more systematically. And with the KVKK amendments that took effect in 2024, the rules for cross-border data transfers were rewritten from scratch. In short, doing outbound without knowing the legal boundaries is now both a legal and a reputational risk.
The good news: KVKK-compliant cold outbound is possible. Set up properly, it also gives you better-qualified lists, a cleaner CRM and higher reply rates. In this article, we cover the two core pieces of legislation governing cold outbound in Turkey, the limits for each channel, the obligations that come with using tools hosted abroad, and a step-by-step compliance plan your team can start implementing tomorrow.
Note: This article is for general information only and does not constitute legal advice. Legislation and Board decisions may change. Always consult a KVKK specialist or lawyer about your own processes.
Cold Outbound in Turkey Is Governed by Two Separate Laws
Many teams only think about KVKK. In reality, cold outbound in Turkey sits at the intersection of two separate legal frameworks:
- Law No. 6698 on the Protection of Personal Data (KVKK): Governs how you collect, store, process and transfer a person's name, email address, phone number or job title. In short, it answers the question: "Do you have the right to hold and use this data?"
- Law No. 6563 on the Regulation of Electronic Commerce and the Regulation on Commercial Communications and Commercial Electronic Messages: Governs sending promotional messages through channels such as email, SMS and phone calls. It answers the question: "Can you send a marketing message to this person through this channel?"
The two laws operate independently. Even if you are free to send a message under Law 6563, you are still in breach if you obtained the recipient's data in violation of KVKK. The reverse is also true: processing data lawfully does not mean you have permission to send messages. Your compliance plan should answer these two questions separately.
Under KVKK: Which Legal Basis Does Your Outbound Rely On?
Article 5 of KVKK states that, as a rule, personal data may be processed with explicit consent. It then lists exceptions that do not require explicit consent. In cold outbound, there is no explicit consent to begin with, because you have never been in contact with the person. That is why two exceptions come to the fore.
Legitimate interest (5/2-f)
The law permits data processing for the data controller's legitimate interest, provided it does not harm the fundamental rights and freedoms of the data subject. In a B2B context, "introducing a corporate decision-maker to a solution directly relevant to their work" may fall within this scope. However, this is not an automatic permission. You need to carry out a balancing test:
- Is your interest legitimate and specific? "Introducing our route optimization software to operations managers at logistics companies" is a specific interest. "Selling to everyone" is not.
- Is the processing necessary and proportionate? If the person's work email and job title are enough, collecting their date of birth, personal phone number or home address is disproportionate.
- What are the person's reasonable expectations? A company's procurement manager can reasonably expect supplier offers related to their job. A sales email sent to a software developer's personal Gmail address, however, falls outside that expectation.
Put your balancing test in writing. If a complaint comes from the Board or a data subject, you will have a documented answer to the question "why did we target this person, and why with this data?"
Data made public (5/2-d) and a common misinterpretation
The reasoning "Their LinkedIn profile is public and their email is on the company website, so I can use it" is common but risky. Under the Board's established approach, data made public is interpreted as limited to the purpose for which it was made public. An "info@" address on a company website is published for customer communication. An executive's LinkedIn profile is public for professional networking. This data does not grant unlimited permission for every kind of marketing activity.
In practice, a safer approach is this: rather than relying on data made public as your sole basis, use it as part of your legitimate interest analysis. "The person shared this information for professional communication. Our outreach is also professional and directly related to their role." This argument is far stronger than simply saying "it was already public."
Law 6563 and İYS: Rules for Commercial Electronic Messages
The core rule of Law No. 6563 is clear: commercial electronic messages may only be sent with the recipient's prior consent. The Regulation on Commercial Electronic Messages, however, contains a critical exception for B2B: commercial electronic messages may be sent to tradespeople and merchants without prior consent. The recipient's right to opt out remains intact.
This exception is an important part of the legal foundation for B2B outbound. Still, there are points to watch:
- Is the recipient really a merchant? If the message is sent to a company, or to an authorized person acting on behalf of a company at their corporate address, the exception may apply. Sending a message to a company employee's personal address, targeting them as an individual consumer, falls outside this scope. Communication with employees at corporate addresses is a gray area. Assess your risk together with your legal counsel.
- The opt-out right must be available in every message. Every message must offer a way for the recipient to opt out easily and free of charge.
- Opt-outs must be honored within three business days. Under the Regulation, you must stop sending messages within three business days of receiving an opt-out. In automated sequences, this deadline is very easy to miss. If step four of a sequence is scheduled for the day an opt-out arrives and no one stops it, a breach occurs.
- İYS registration and checks. Although consent is not required for messages sent to merchants, you must take into account opt-outs submitted via İYS. Clarify your İYS registration and checking obligations based on your sending volume and channel.
- The sender's identity must be clear. The message must include the service provider's identity and contact information. Sending under fake names or from "no-reply" addresses is problematic from both a trust and a regulatory standpoint.
Remember that administrative fines under Law 6563 can be assessed separately for each message. Fine amounts are updated every year according to the revaluation rate. A systematic error in a thousand-person campaign can mean a thousand times the risk of a single mistake.
Legal Boundaries, Channel by Channel
Cold email
This is the most common and relatively safest channel in B2B, provided it is set up correctly. The minimum elements of a compliant cold email are:
- Sent to a corporate address, on a topic directly related to the recipient's role
- Clear identification of the sending person and company
- A short privacy notice: where the data was obtained, plus a link to the privacy notice
- A one-click or one-reply opt-out option
- Immediate removal of opted-out addresses from all sequences
A compliant email does not have to have a low reply rate. Role-based targeting both strengthens your legitimate interest argument and improves conversion. We explain how to systematically test subject lines and message variations in detail in our guide to A/B testing in B2B cold email.
Cold calling
Promotional phone calls also count as commercial electronic messages under Law 6563. The merchant exception applies here too. However, calling a company switchboard or company line does not carry the same level of risk as calling an executive's personal mobile phone. Personal mobile numbers, especially those obtained from third-party databases, are the most sensitive area under both KVKK and Law 6563. In the first 15–20 seconds of the call, state who you are, why you are calling and how you got the number. If someone says "I don't want to be called again," remove them from the list the same day.
LinkedIn messages
Whether in-platform LinkedIn messaging falls under Law 6563 is debatable. KVKK, however, applies in every case. Scraping profile data from LinkedIn and importing it into your own database is a separate risk area. It may violate the platform's terms of use and also creates a purpose limitation issue under KVKK. If you use automation, pay attention to platform limits and personalization quality. You can see how a controlled automation workflow is built in our case study on automated LinkedIn outbound with n8n. If you want to manage your corporate LinkedIn presence professionally and support outbound with organic visibility, Social Media Corner's B2B LinkedIn management service can take care of that side.
SMS and WhatsApp
These are the riskiest channels for cold outbound. They almost always reach personal mobile numbers, which makes the merchant exception questionable. WhatsApp Business's own policies also require prior permission from the user. Our recommendation is clear: do not use SMS or WhatsApp for cold outreach. Only bring these channels in after the other party has replied first and said they prefer that channel.
Data Source: Where Does Your Lead List Come From?
The weakest link in KVKK compliance is usually the data source. "We bought a 5,000-contact list from an agency" is one of the hardest statements to defend before the Board. If you don't know how the seller collected the data, you can't know whether that data is lawful.
When evaluating a source, look for answers to these questions:
- Does the provider have its own KVKK or GDPR compliance statement? Does it explain the legal basis on which it collected the data and through which channel data subjects can object?
- Is the data corporate or personal? A dataset made up mostly of work emails and company phone numbers carries far lower risk than one full of personal mobile numbers.
- Is the data up to date? Trying to reach someone who has left the company at their old corporate address increases both your bounce rate and your complaint risk.
- Are there targeting filters? Filters such as industry, job title and company size make the "role-relevant outreach" argument in your legitimate interest analysis concrete.
B2B contact data platforms like Apollo.io make it easier to build targeted lists, since they let you filter by job title, industry and company size. However, using such a tool does not release you from your obligations as a data controller. The moment you import data from the platform into your own CRM, you are responsible under KVKK. Not exporting sensitive fields such as personal mobile numbers by default is a good starting point.
Foreign Tools and Data Transfers After 2024
Most of the tools in your outbound stack are probably hosted abroad: CRM, email sequencing tool, data enrichment service, AI models. Uploading data about people in Turkey to these tools constitutes a cross-border transfer of personal data.
Article 9 of KVKK was amended by Law No. 7499, and the new version took effect on June 1, 2024. The main features of the new system are:
- Adequacy decision: Transfers to countries the Board has decided provide adequate protection. In practice, this route is still limited.
- Appropriate safeguards: The most practical of these are the standard contracts published by the Board. A standard contract must be notified to the Authority within five business days of signing.
- Exceptions for incidental transfers: These are for exceptional cases that are not regular or ongoing. Relying on this route for a continuously running CRM or outbound tool is not appropriate.
Your practical steps:
- Create an inventory of all tools in your outbound workflow that process personal data. Note which data each tool processes and where the data is hosted.
- Start the standard contract process with each tool provider and keep track of your notifications.
- If you use AI-powered personalization, limit which fields are sent to the model. Company name, industry and job title are usually enough for personalization. Sending a person's full profile data to an external model is an unnecessary transfer.
The workflows described in our article on hyper-personalization automation in B2B outbound campaigns with n8n give you more control over data flows, because n8n can run on your own server (self-hosted). This is a practical way to reduce the number of cross-border transfer points.
Privacy Notice in the First Message: A Sample Setup
Article 10 of KVKK requires you to inform the data subject when you obtain their personal data. If the data was not obtained directly from the person, you must inform them at the latest at the time of first contact. In cold outbound, that means the "first email." You don't need to paste a long legal text into the body of the email. A short note with a link to the full text is a sufficient and readable solution.
A sample closing note:
I'm sending you this email because, given your role at [Company Name], we believe it may be relevant to your work. We found your contact details via [source: e.g., your corporate website / our B2B data provider]. You can find out how your data is processed in our privacy notice: [link]. If you'd prefer not to receive similar emails, simply reply "no." We'll remove your record the same day, not within three business days.
This note has three benefits. It fulfills the obligation to inform, clearly offers a way to opt out, and builds brand trust through transparency. A sales rep who openly states their source has already answered the "where did you get my number?" question up front.
Your privacy notice should include at least the following: the identity of the data controller, the purpose of processing, to whom and for what purpose the data may be transferred (including foreign tools), the collection method and legal basis, and the data subject's rights under Article 11.
Building Opt-Outs, Objections and Deletion Requests into Your System
The operational heart of compliant outbound is processing opt-outs and objections quickly and completely. Manual tracking will inevitably break down at some point as the number of sequences grows.
Here's the structure we recommend:
- Create a central suppression list. Every email address, phone number and domain that opts out should go on this list. All tools should check this list before sending.
- Automate reply classification. An n8n workflow or AI classifier that catches replies like "no," "remove me from the list" or "not interested" can immediately remove the person from all active sequences. We described a similar approach for positive replies in our article on AI-powered lead qualification automation in cold email. The same logic can be applied to negative replies.
- Share the suppression list if you have multiple brands or business units. Sending an email from Brand B to someone who opted out of Brand A is a problem both legally and reputationally. We cover this need for multi-brand structures in our guide to centralized CRM strategies and data integrity.
- Put Article 11 requests on a schedule. Data subjects may want their data deleted or corrected, or may want to know what data of theirs is being processed. You must respond to these requests within 30 days at the latest. Log requests the way you would a support ticket.
- Set a retention period. Keeping leads who don't reply or aren't interested indefinitely violates the principle of proportionality. For example, define a periodic disposal process to delete or anonymize records with no engagement within six months.
An Actionable 10-Step Compliance Checklist
A concrete list your team can work through over the next two weeks:
- Take inventory: List all data sources and tools used in outbound.
- Write up your balancing test: Document the legitimate interest analysis for your target segments (e.g., "procurement managers at manufacturing companies with 100–500 employees").
- Trim your data fields: Identify the fields you actually need for outbound. Typically these are first name, last name, job title, company and corporate email. Don't collect the rest.
- Filter out personal channels: Remove personal emails and mobile numbers from cold sequences.
- Update your privacy notice: Add the outbound purpose, data sources and foreign tools to the text.
- Add a privacy and opt-out note to your email templates.
- Set up a central suppression list and integrate it with all sending tools.
- Complete your cross-border transfer contracts and track your notifications to the Authority.
- Check your VERBİS obligation. Clarify whether you are required to register based on the employee count and annual balance sheet thresholds set by the Board.
- Train your team: Make sure your SDRs have a single, correct answer to the question "where did you get my data?" Add this answer to your sales playbook.
Common Mistakes
- Thinking "KVKK doesn't apply to B2B." KVKK protects the data of natural persons. A company executive's name and corporate email are personal data too.
- Using a purchased list without question. Data of unclear origin puts the entire campaign at risk.
- Forgetting to stop the sequence. An automated follow-up email going to someone who has opted out is the most common and most easily preventable breach.
- Sacrificing targeting for volume. Messages sent to people unrelated to the role both weaken your legitimate interest defense and increase spam complaints.
- Giving AI more data than necessary. Sending a person's entire profile to an external model for personalization creates an unnecessary transfer risk.
Compliance and performance usually pull in the same direction. A narrower, more relevant audience means fewer bounces, fewer complaints and higher reply rates. If you're curious how AI can support this balance, take a look at our case study on outbound sales efficiency with AI in B2B SaaS. If you want to build your outbound infrastructure compliantly from the ground up or hand over your existing process, SAAS Corner's B2B SaaS-focused outbound and lead generation service can manage it end to end.
Conclusion
Cold outbound is not prohibited in Turkey, but it isn't unregulated either. KVKK governs how data is collected and processed, while Law 6563 governs through which channel and under what conditions a message is sent. Base your targeting on documented legitimate interest. Prefer corporate channels. Provide a transparent privacy notice in the first message. Process opt-out requests within three business days, or better yet, the same day. Complete the standard contract process for foreign tools. A team that takes these steps both reduces its legal risk and builds a higher-quality pipeline.
If you want to make your outbound processes KVKK-compliant, redesign your automations or build a shared compliance infrastructure for your multi-brand structure, the Corner Group team is ready to help. Reach out via our contact page and let's assess your process together.