What is Explicit Consent?
Definition
Explicit consent is permission to process personal data that a person gives knowingly, for a specific purpose and of their own free will, through a clear affirmative act. Turkey's KVKK defines it as consent that is specific, informed and freely given; the GDPR requires a similar standard and explicit consent for sensitive data. It can be withdrawn at any time and is only one of several legal bases, not the default.
Also known as: consent, açık rıza, express consent, opt-in consent, GDPR consent

What makes consent valid
- Specific: it must be clear which data is covered and for which purpose. A blanket line such as “I agree to the processing of my personal data” does not qualify, a point Turkey's data protection authority makes explicitly in its cookie guidance.
- Informed: before agreeing, the person must be able to understand who will process the data, why, and who it will be shared with.
- Freely given: saying no must not cost the person anything, and consent must not be made a condition of an unrelated service.
The GDPR adds that consent must be unambiguous and given by a statement or clear affirmative action. It reserves “explicit consent”, a higher bar usually met with an express written or recorded statement, for situations such as processing special category data. Turkey's KVKK uses the single term açık rıza (“explicit consent”) for all consent-based processing.
One legal basis among several
Both laws treat consent as one possible basis, not the default. Shipping an order relies on the contract, keeping invoices on a legal obligation, and security logging usually on legitimate interests. Asking for consent in those cases backfires: it suggests the person has a choice they do not really have, and if they withdraw and processing carries on under another basis, they have been misled. Check the other bases first and fall back on consent only when none applies.
Consent is also distinct from transparency. A privacy notice must be provided whatever the legal basis; consent is collected only for processing that depends on it. Folding both into one “I have read and agree” checkbox weakens each of them.
Bundling and interface traps
If a sign-up form cannot be submitted until the user ticks “I agree to marketing emails and to sharing my data with partners”, consent has been made a condition of the service and is hard to call freely given. Other patterns lead to the same outcome:
- pre-ticked checkboxes
- marketing permission buried in the terms of service
- a decline option that is hidden or worded to shame the user, a classic dark pattern
The sound approach is one separate, unticked option per purpose:
<label>
<input type="checkbox" name="marketing_email">
Email me about offers and new products.
</label>
<a href="/privacy-notice/">Privacy notice</a>Electronic marketing is often governed by additional rules beyond data protection law, such as Turkey's commercial electronic messages regime or national ePrivacy rules in the EU.
Withdrawal and proof
People can withdraw consent at any time, and withdrawing should be as easy as giving it: a one-click unsubscribe link, a toggle in account settings, or a small preferences icon for cookies. The burden of proving consent lies with the organisation, so keep a record of who agreed, when, through which channel, to which version of the wording, and when they withdrew. The cookie-specific rules are covered under cookie consent, and the meaning of the data involved under personal data.
This entry is general information, not legal advice.

