Skip to content
Kulular Teknoloji, Kulular Bilişim Teknolojileri Limited Şirketi

← Writing

What an Auditor Checks First in a Data Protection Notice

25 July 20264 minVersion 1.0

Summary

A data protection notice is the controller's disclosure, required under Article 10 of Turkish Law No. 6698, made when collecting personal data, of its identity, the purpose of processing, the recipients data will be transferred to, the method of collection, the legal basis, and the rights set out in Article 11. The duty is fulfilled not by producing a document, but by that document accurately reflecting what is actually being processed.

Author

Tarık İsmet Alkan

Organisation

Kulular Bilişim Teknolojileri Limited Şirketi

When I review an organisation's data protection notice, the first thing I do isn't read it. It's take the data categories the notice lists and compare them against the database schema.

That comparison produces almost the same result nearly every time: fields exist that the notice doesn't mention. Sometimes the reverse happens too — categories listed in the notice that the system never actually collects. Both point to the same underlying problem: the notice was drawn from a template, not from a proper check of the facts.

The duty is not to produce a document

Article 10 of Law No. 6698 requires the controller, when collecting personal data, to disclose certain things: its identity, the purpose of processing, the recipients data will be transferred to and why, the method of collection and the legal basis, and the rights set out in Article 11.

The operative verb here is "disclose." The document is a vehicle; the duty is to give accurate information. A notice that gives inaccurate information is worse than having no notice at all, because the organisation has now made a statement that doesn't match reality.

That's why drafting the notice has to come after the inventory, not before. An organisation with an inventory writes the notice in a day. One without writes it without knowing what it's actually writing about.

The five mistakes I see most often

I've been seeing the same mistakes for years, and none of them come from a lack of legal knowledge.

Merging the notice and consent into a single checkbox. The user ticks "I have read and agree" and is deemed both to have been informed and to have given consent. A notice is a disclosure, not something to be accepted. Merging the two undermines consent's character as a separate declaration of will.

Showing the notice after the transaction is already complete. The form is submitted, and a link to the notice then appears on a thank-you page. By that point the data has already been collected.

Forcing a single notice to fit every process. Recruitment, customer contact, supplier relationships and website visits all get folded into one document. The result is a general notice that accurately describes none of them.

Not stating the legal basis, or listing all of them at once. A phrase like "under the conditions set out in Articles 5 and 6" states no legal basis at all. Whichever ground a given instance of processing actually relies on should be the one that's written down.

Not stating the retention period. The Communiqué expects this to be included in the information given to the data subject, and without it the data subject has no way to learn how long their data will be kept.

How the notice should be structured

A good notice is written process by process. It doesn't start with "our company processes your personal data" — it starts with "when you fill in the contact form, the following data is processed."

A four-column table for each process makes this much easier to get right: data category, purpose of processing, legal basis, retention period. With that table in hand, the notice writes itself, and the reader can actually find what they're looking for.

Language matters too. The Communiqué expects information to be conveyed in clear, understandable and plain language. In practice we see the opposite: notices get longer, sentences get heavier, and the result becomes unreadable. A notice nobody reads doesn't fulfil the disclosure function. Simplifying it isn't a stylistic choice here — it's what the duty requires.

Keeping the notice current

A data protection notice isn't a document you write once and forget. When a new field is added, a new supplier comes on board, or a new transfer is introduced, the notice needs updating too.

The only sustainable way to manage this is to tie the update to the development process itself. A change that adds a new personal-data field to the data model should trigger an update to both the inventory and the notice. Without that link, the notice drifts away from reality within the first year, and nobody notices.

We built that link into our own site this way: when we added the AI-assisted analysis feature, a separate section explaining the cross-border transfer went into the notice at the same time. The feature didn't go live without it. That's the order it should happen in.

Frequently asked

01Are a data protection notice and a consent form the same thing?
No. A notice is a one-way disclosure and is always required. Consent is only obtained for processing that relies on it, and is a separate declaration of will. Merging the two into a single checkbox makes the validity of the consent questionable.
02When should the notice be shown?
At the point personal data is collected. A notice that only appears after a form has been submitted may not satisfy the duty to inform in time.
03Is one notice enough for every process?
Usually not. A recruitment process and a customer contact form involve different data categories, different purposes and different legal grounds. Preparing a separate notice for each process is both more accurate and more defensible than a single general one.

Sources

  1. 01Law No. 6698 on the Protection of Personal Data, Arts. 10 and 11This is Turkish law; it does not track UK GDPR or EU GDPR transparency requirements
  2. 02Communiqué on Procedures and Principles to be Complied with in Fulfilment of the Obligation to Inform
  3. 03Personal Data Protection Authority of Türkiye, guidance on the duty to inform

Suggested citation

Tarık İsmet Alkan. “What an Auditor Checks First in a Data Protection Notice”. Kulular Teknoloji, version 1.0, 25 July 2026. https://kulular.com.tr/en/writing/writing-a-privacy-notice

  • Data protection
  • Privacy notice
  • Compliance