Launching an e-commerce site in Türkiye involves more than preparing a product catalog and payment page. The business model must be classified correctly, while company, tax, electronic document, consumer law, personal data, commercial communication, and payment security obligations must be designed together. Applicable rules may also change according to the seller’s status, the product or service, the target market, and the technology providers used. This guide explains e-commerce site legal requirements within a corporate decision framework extending from business formation to ongoing post-launch compliance.

01

The Legal Scope of Launching an E-Commerce Site in Türkiye

The legal scope of launching an e-commerce site in Türkiye primarily depends on correctly identifying the sales model and the parties involved. B2C, B2B, D2C, subscription, digital product, and marketplace models are not subject to identical rules. Therefore, the business model is the starting point of compliance; legal texts, software flows, and operations should be prepared according to this classification.

Which legislation and business models should be assessed together?

The Elektronik Ticaretin Düzenlenmesi Hakkında Kanun No. 6563 (Law on the Regulation of Electronic Commerce), Tüketicinin Korunması Hakkında Kanun No. 6502 (Consumer Protection Law), and Kişisel Verilerin Korunması Kanunu No. 6698 (Personal Data Protection Law) establish the main framework. The Mesafeli Sözleşmeler Yönetmeliği (Distance Contracts Regulation), electronic commerce regulations, tax legislation, sector-specific rules, and payment services requirements complete that framework.

  • Determine whether the buyer is a consumer or a commercial customer.
  • Classify the offering as goods, physical services, digital content, or subscriptions.
  • Separate the responsibilities of sellers and marketplace intermediaries.
  • Assess domestic and cross-border sales channels separately.
  • Verify sector-specific licensing, advertising, or sales restrictions.
The end of law is not to abolish or restrain, but to preserve and enlarge freedom. - John Locke
02

Company, Tax Registration, and Electronic Document Duties

Regular online sales intended to generate income must be conducted through an appropriate tax registration and business structure. However, e-commerce does not require every seller to establish the same type of company. The choice among individual business structures, sole proprietorships, and capital companies should reflect partnership, liability, investment, expected revenue, and operational scale.

How should e-Fatura and e-Arşiv Fatura adoption be planned?

Tax registration, an appropriate activity code, accounting arrangements, and sales document creation should be planned before launch. e-Fatura and e-Arşiv Fatura are separate applications; mandatory adoption and the document to be issued must be determined under current Gelir İdaresi Başkanlığı (GİB, Revenue Administration) rules based on the company’s circumstances. The software must align with accounting and authorized integrator processes.

  • Select the tax status and company structure suitable for the activity.
  • Verify NACE or other applicable activity codes with the accountant.
  • Complete tax certificate, trade name, and banking procedures.
  • Assess e-Fatura and e-Arşiv Fatura coverage separately.
  • Align cancellation, return, and retention workflows with accounting systems.
03

ETBİS Registration and Website Disclosure Requirements

Registration with Elektronik Ticaret Bilgi Sistemi (ETBİS, Electronic Commerce Information System) should be assessed before operations begin for service providers operating through their own e-commerce environment and other businesses specified by the legislation. The position may differ for sellers operating solely through a domestic marketplace. Therefore, the ETBİS registration requirement must be verified by sales channel.

Which corporate details must an e-commerce site display?

Based on current Ministry of Trade guidance, businesses should review ETBİS coverage, MERSİS or ESBİS records, domain information, and notification details. The service provider’s trade name, business or brand information, accessible contact channels, registered address, and relevant registry details should also be presented in an easily accessible manner to the extent required by applicable rules.

  • Distinguish ETBİS coverage for independent sites and marketplace channels.
  • Report domain names and e-commerce environment information accurately.
  • Keep the trade name, address, and contact details current.
  • Display MERSİS, tax, or tradespeople registry details where applicable.
  • Update changed business and integration information when required.
04

Distance Sales Contracts and Consumer Rights Management

For online consumer sales, pre-contractual information and the distance sales contract are complementary processes with different functions. Before ordering, consumers should receive information about the seller, product, total price, additional charges, payment, delivery, withdrawal rights, and application methods. Required confirmations must be obtained at the appropriate point in the purchasing journey.

How should withdrawal, delivery, and refunds be structured?

The right of withdrawal is a general consumer protection but includes exceptions based on the product or service. Exceptions should not be copied from a generic template; they must be matched with current provisions concerning the relevant product, digital content, customization, hygiene, and service performance. The payment obligation, total price, and additional charges should be visible before the order is completed.

  • Make pre-contractual information readable and confirmable before contracting.
  • Ensure the order button clearly indicates an obligation to pay.
  • Define delivery, cancellation, return, and refund procedures.
  • Legally verify withdrawal-right exceptions for each product category.
  • Assign a responsible team for defective goods and consumer applications.
05

KVKK, Cookies, and Cross-Border Data Transfer Processes

E-commerce compliance with Kişisel Verilerin Korunması Kanunu (KVKK, Personal Data Protection Law) cannot be achieved by publishing a privacy policy alone. Data processed through membership, orders, payments, delivery, support, analytics, and marketing should be mapped, including purpose, legal basis, recipient group, retention period, and safeguards. The transparency obligation and explicit consent are not the same process, and consent is not automatically required for every processing activity.

How should cookie preferences and foreign providers be managed?

Strictly necessary cookies should be distinguished from analytics, functional, and advertising cookies by purpose and legal basis. When a user rejects advertising cookies, those technologies must actually stop operating. Foreign cloud, CRM, email, advertising, and analytics providers’ access to data must be reviewed separately under the current KVKK cross-border transfer regime and applicable safeguard mechanisms.

  • Prepare the KVKK privacy notice from actual data flows.
  • Manage explicit consent separately from membership and marketing permission.
  • Classify and scan cookies according to their purposes.
  • Implement retention, deletion, and anonymization rules in the system.
  • Verify Veri Sorumluları Sicil Bilgi Sistemi (VERBİS, Data Controllers Registry Information System) coverage using current criteria and exemptions.
  • Document cross-border transfers and service-provider roles.
06

Commercial Electronic Message Consent and İYS Management

Advertising, campaign, and promotional email, SMS, or telephone processes must be designed in accordance with commercial electronic messaging rules. The recipient, content, and legal nature of the message may affect the consent requirement. Where required, consent should be obtained, opt-out rights should be easy to exercise, and İYS records and messaging systems must remain consistent.

What should the system do when marketing consent is withdrawn?

A user’s opt-out request should not remain merely as an inactive record in İleti Yönetim Sistemi (İYS, Commercial Electronic Message Management System) or the CRM. Email automation, SMS providers, call lists, and customer segments should be updated to stop relevant messages. Combining the KVKK notice, marketing consent, membership acceptance, and cookie preferences in one mandatory checkbox can create risks concerning free choice and evidence.

  • Separate message types and recipient groups by legal status.
  • Obtain required consents in a demonstrable form before sending messages.
  • Regularly reconcile İYS records with CRM permission statuses.
  • Keep opt-out channels simple, free of charge, and operational.
  • Define agency and messaging-provider responsibilities contractually.
07

Payment Security, Cyber Controls, and Intellectual Property

E-commerce payment security requires both working with banks or licensed payment service providers authorized by Türkiye Cumhuriyet Merkez Bankası (TCMB, Central Bank of the Republic of Türkiye) and implementing the merchant’s own technical controls. Storing card data directly in company systems may substantially expand security and compliance obligations. Therefore, processing payment data within the narrowest possible scope is a fundamental risk-reduction approach.

How should technical security and content rights be protected?

SSL/TLS alone is insufficient; access control, strong authentication, patching, logging, backups, vulnerability management, and incident response should operate together. PCI DSS applicability should be assessed according to the payment architecture. Ownership or usage rights should be documented for the domain, trademark, software licenses, product images, descriptions, and third-party content.

  • Verify the payment provider’s TCMB authorization and permitted activities.
  • Map every point at which card data touches the systems.
  • Apply strong authentication to administrator accounts.
  • Test logging, backup, and incident-response procedures.
  • Record trademark, image, software, and content licenses.
08

Sector-Specific Sales, Marketplaces, and Cross-Border Trade

General e-commerce legislation is not sufficient for every product and sales model. Food, health, cosmetics, financial services, alcoholic products, products aimed at children, and other sensitive categories may be subject to additional permits, disclosures, advertising rules, or sales restrictions. Product-specific regulatory review should be completed before catalog publication.

How does responsibility change in marketplaces and cross-border sales?

A marketplace may provide technical infrastructure, but it does not automatically assume every tax, product compliance, consumer transaction, and data protection responsibility of the seller. An independent site gives the business a broader technical and operational control area. Cross-border sales additionally require reviewing the target country’s consumer, tax, customs, currency, product safety, and data protection rules.

  • Verify sales and advertising restrictions for each product category.
  • Implement suitable controls for products requiring age verification.
  • Compare marketplace contracts with statutory responsibilities.
  • Determine the seller’s and platform’s data-controller roles.
  • Plan cross-border tax, customs, and return procedures.
  • Review the target country’s consumer and data protection rules.
09

Pre-Launch Compliance, Costs, and Partner Selection

Before an e-commerce site launches, legal texts, user interfaces, integrations, and operational procedures should be tested together. The presence of a policy page does not establish compliance when the software behaves differently. Rejected advertising cookies must not operate, withdrawn marketing consent must reach messaging lists, and a return request must be routed to the responsible team.

How should an e-commerce agency or software company be assessed?

When evaluating e-commerce site development costs, initial implementation and ongoing compliance expenses should be separated. Legal advice, accounting, electronic documents, security, logging, consent management, updates, and periodic reviews should be included. Technical implementation and legal assessment must be coordinated; an e-commerce agency or software company does not automatically replace legal counsel.

  • Approve the business model, data flows, and responsibility matrix.
  • Test contract, cookie, ordering, and return scenarios end to end.
  • Ask the solution partner to disclose data locations and subprocessors.
  • Assign responsibility for breaches, complaints, opt-outs, and data-subject requests.
  • Regularly monitor document versions and regulatory changes.
  • Obtain legal counsel and accountant input for the specific activity.