Loyalty Verified Türkiye Closes the Checkout Gap
New Verification Rules for Loyalty Card Programs in Türkiye
Picture this: you walk up to a checkout, recite a phone number, and walk out with someone else’s loyalty benefits, without them ever knowing.
Türkiye’s Personal Data Protection Board (the “Board”) just closed that gap. The era of carrying out loyalty card transactions at the checkout by only providing a phone number to the cashier has come to an end. A point-of-transaction verification obligation has been introduced for loyalty card programs.
Data controllers have been granted a six-month period to review their loyalty card applications and put appropriate verification mechanisms in place to comply with the new rules.
1. The New Rulebook for Data Controllers
The Board’s Principle Decision dated 11 February 2026 and numbered 2026/266 (the “Principle Decision”) was published in the Official Gazette dated 28 February 2026.
According to the Principle Decision, the use of a loyalty card member’s mobile phone number or loyalty card number by third parties during shopping, across various sectors including food, cosmetics, technology, home improvement, and apparel, constitutes unlawful data processing. The Principle Decision therefore introduces new rules governing loyalty card programs.
Under the Principle Decision, data controllers are required to:
- Discontinue any practice that allows third parties to use a loyalty card without the cardholder’s knowledge and consent.
- Implement appropriate technical and administrative measures to verify that any use of a loyalty card for any purpose, including membership registration, earning points during shopping, redeeming points, and using discounts or promotions, takes place with the knowledge and consent of the data subject.
- Establish adequate verification mechanisms using appropriate methods, including but not limited to:
- Sending a one-time SMS verification code to the customer for verification at checkout
- Scanning a barcode or QR code through a mobile application or website
- Presenting or scanning the physical loyalty card at checkout
- Entering the loyalty card PIN into the payment terminal at checkout
- Providing an opt-in preference through the online membership account, allowing the cardholder to determine which types of transactions may be carried out solely by providing their mobile phone number
The Board did not mandate any specific solution. Instead, it recognized that the verification mechanism should be calibrated to the relevant data subject groups, transaction types, and associated risk levels.
2. Why Now?
The Authority’s engagement with loyalty program data protection issues predates the Principle Decision.
In 2019, the Board issued Decision No. 2019/82 and Decision No. 2019/198, examining loyalty card practices across a range of issues, including information obligations, inconsistencies between consent and privacy notices, and the relationship between explicit consent and service conditionality.
In 2022, the Authority published a Draft Guideline on the Processing of Personal Data in Loyalty Programs, which remained at the draft stage. The Draft Guideline addressed core compliance topics, including legal grounds for data processing, fulfillment of the notice obligation, and the data processing principles applicable to loyalty programs.
With the Principle Decision, the Authority has taken a more decisive step, one that represents a significant regulatory intervention in the loyalty program space.
The trigger for the Principle Decision was a series of notifications and complaints concerning third parties conducting transactions using loyalty cardholders’ information without their knowledge or consent.
The Board found that while membership agreements designate loyalty cards for personal use and registration typically involves identity verification, the widespread practice of conducting transactions by merely declaring a phone number or card number to a cashier contains a fundamental gap.
This practice enables:
- Purchases
- The use of discounts
- The accrual of points
These transactions can take place without any mechanism confirming the cardholder’s knowledge or consent. As a result, inaccurate data may be recorded in membership accounts, and documents may be issued in the cardholder’s name for transactions they did not authorize.
3. The Board’s Legal Assessment
In essence, the Board found that the widespread practice of allowing third parties to use loyalty card credentials was generating and recording transaction data in cardholders’ names without their knowledge or involvement.
| Legal Basis | Assessment |
|---|---|
| Article 5 of the PDPL Conditions for Processing Personal Data |
Data processing activities carried out through the use of the cardholder’s mobile phone number or loyalty card number without their knowledge and consent do not rely on any of the processing conditions set forth under Article 5 of the Personal Data Protection Law (“PDPL”) and constitute unlawful data processing. |
| Article 4 of the PDPL General Principles |
Issuing invoices or similar documents in the name of the data subject and/or recording customer transaction information in the loyalty cardholder’s records for a purchase made without their knowledge and consent violates the principle of “being accurate and, where necessary, kept up to date” under Article 4 of the PDPL. |
| Article 12 of the PDPL Data Security |
Even if the membership agreement imposes an obligation on the cardholder not to allow third parties to use the loyalty card, this does not eliminate the data controller’s obligation to ensure personal data security under Article 12 of the PDPL. |
4. Compliance Timeline and Sanctions
Data controllers have been granted a six-month compliance period from the publication date of the Principle Decision. The compliance deadline is therefore 28 August 2026.
Data controllers that fail to implement the required measures and continue the prohibited practice may be subject to administrative fines under Article 18 of the PDPL, with penalties determined according to the circumstances of the violation.
For reference, the applicable administrative fine ranges under the Personal Data Protection Law, as updated for 2026, are as follows:
| Violation | Minimum Fine (TRY) | Maximum Fine (TRY) |
|---|---|---|
| Failure to fulfill the obligation to inform | 85,437 | 1,709,200 |
| Failure to fulfill data security obligations | 256,357 | 17,092,242 |
| Non-compliance with Board decisions | 427,263 | 17,092,242 |
| Failure to register with the Data Controllers Registry | 341,809 | 17,092,242 |
| Failure to notify the Authority of standard contractual clauses | 90,308 | 1,806,177 |
5. Concluding Remarks
The Principle Decision sets a clear compliance baseline for data controllers operating loyalty card programs. With the six-month compliance window closing on 28 August 2026, practical steps to consider include the following:
- Audit Loyalty Card Operations: Map all loyalty card-related data flows, identify points where third-party use occurs without verification, and assess current authentication methods against the Principle Decision’s requirements.
- Implement Verification Mechanisms: Evaluate which verification method best suits the organization’s operations and deploy tailored solutions, such as SMS codes, QR scans, or PINs, calibrated to customer segments, transaction risk levels, and existing infrastructure.
- Review Documentation: Review loyalty card terms and conditions, privacy notices, and data processing disclosures. Where necessary, revise them to reflect the new verification requirements and clearly inform cardholders of the changes.
- Provide Training: Train cashiers and front-line staff on the new procedures and on the prohibition against processing loyalty card transactions without proper verification. Clear operational protocols should be established, with particular emphasis on PDPL liability exposure.
While our focus here is the data privacy dimension of loyalty card programs, that is only one facet of a broader compliance landscape.
Loyalty card schemes are subject to wide-ranging regulatory considerations spanning consumer protection, advertising regulations, and data security. Organizations operating or rolling out such programs should approach compliance holistically across all applicable frameworks.