FISCAL SOLUTIONS...

Turkey Extends Loyalty Card Verification Compliance Deadline to February 2027

Add to Favorites Leave a Comment
Summary

Turkey has extended the deadline for businesses to implement verification mechanisms for loyalty card use from August 28, 2026, to February 28, 2027. Retailers must ensure that loyalty accounts cannot be used by third parties without the cardholder’s knowledge and consent, using appropriate verification methods such as SMS codes, QR codes or similar solutions.

Content

Turkey has extended the deadline for businesses to introduce verification mechanisms for the use of customer loyalty cards. Companies now have until February 28, 2027, instead of August 28, 2026, to comply with the new requirements.

The requirement originates from a decision issued by Turkey’s Personal Data Protection Board (KVKK Board) on February 11, 2026. It addresses a common retail practice where a customer can use a loyalty account simply by giving a mobile phone number or loyalty card number to the cashier, without any additional verification.

The Board found that this creates a personal data protection risk because another person could provide someone else’s phone number or loyalty card number and make a purchase under that customer’s account without their knowledge. As a result, purchases, products, dates and other transaction information could incorrectly be recorded against the loyalty card holder, and invoices or similar documents could potentially be issued in that person’s name.

Under the new rules, businesses operating loyalty programs must introduce an appropriate mechanism to verify that use of a loyalty card during a purchase takes place with the knowledge and consent of the loyalty card holder. This applies not only when loyalty points are spent, but also when the loyalty program is used to earn points or obtain discounts and promotions.

The Board does not prescribe one single verification technology that every business must use. Companies may introduce different verification methods depending on the type of transaction and its level of risk. The decision also allows alternative approaches to be offered to different groups of customers. Existing loyalty systems already commonly use methods such as one-time SMS verification codes or barcodes/QR codes for certain processes.

The change is particularly relevant for retailers and other businesses in Turkey that operate loyalty or membership programs, including businesses in sectors such as food, cosmetics, technology, clothing and home improvement.

Companies should review how loyalty accounts are identified at checkout and make sure that, by February 28, 2027, customers cannot use another person's loyalty account merely by providing that person's phone number or card number without an appropriate verification process.

Businesses that continue operating contrary to the requirements after the compliance period may face action under Article 18 of Turkey’s Personal Data Protection Law No. 6698, which provides for administrative sanctions for violations of data-security obligations and Board decisions.

Importantly, this is not a GDPR compliance deadline. The requirement is based on Turkey’s Personal Data Protection Law No. 6698 (KVKK) and decisions of the Turkish Personal Data Protection Board.

The main source confirming this deadline is the Decision No. 2026/266 of the Personal Data Protection Board dated 11/02/2026 provided by the Personal Data Protection Authority: https://www.resmigazete.gov.tr/eskiler/2026/02/20260228-5.pdf 

Comments

Questions and comments (0)

There are no comments on this news yet.

The latest 3 updates: