vosetu.

الحدود القانونية للوصول إلى الشركات الصغيرة: التواصل المصرّح به وجمع البيانات

بناء قائمة للوصول إلى الشركات سهل تقنيًا ومقيّد قانونيًا. ملاحظات من بحثنا الخاص.

تحدث مع خبير
نمو الأعمال·26 يوليو 2026·8 دقيقة قراءة#pazarlama#kvkk#izinli-iletisim#buyume

First a warning: this is not legal advice

What follows are notes we produced while researching how to reach businesses for our own products; it is not legal advice and cannot be. Legislation changes, regulator decisions build precedent, and every company's situation differs. Consult your own lawyer before setting up a concrete campaign. The value here is in showing which questions you need to ask.

Our reason for the research was simple: we have a product sold to small businesses and needed to work out how to reach them. The technical side was easy — building a list of businesses and collecting phone numbers and emails is possible. The hard part was understanding which of it is legally doable; and what we learned differed from what we expected.

Commercial electronic messages: the rule and the exemption

In Türkiye, commercial electronic messages — marketing emails, SMS and calls — are governed by a specific law, and the basic rule is prior consent: if the recipient has not asked for it, you cannot send. Alongside that rule there is a central permission system; companies sending commercial messages must register their consents there, and recipients must be able to exercise their right to refuse through it.

There is an important exemption that concerns everyone selling B2B: prior consent is not required when the recipient is a merchant or tradesperson. So sending a commercial message to a restaurant, a clinic or an estate agency does not require prior permission. That does not mean 'we can do as we like' — the right to refuse still applies, and a refusal must be honoured within a short period.

In practice this exemption makes cold outreach possible on the B2B side but demands discipline: a system that records refusals, a mechanism to remove people from send lists, and a clear opt-out in every message. Without those three the exemption will not protect you either; the problem then is not consent but failing to honour the right to refuse.

Why the 'I took it from a public source' defence is weak

If a business's phone number sits publicly on the internet, is it free to collect and add to a marketing list? Intuition says yes; the data-protection view is not that simple. A personal data point being public somewhere does not mean you may process it for any purpose — what matters is not where it came from but for what purpose and on what legal basis it is processed.

The distinction matters most for data tied to a person: a mobile number registered in the name of a sole trader can be treated differently from a corporate switchboard line. The regulator's approach is that being public is not in itself a basis for processing, and there are decisions and administrative fines supporting that view. So data that can technically be collected is not automatically data you may lawfully use.

The practical conclusion we drew: distinguish between corporate contact details (a business's main phone and general email) and details tied to an individual, and stay away from the second. When building a list, 'is this number used by a person or by a business' is the most useful filter you can apply yourself before consulting a lawyer.

The data source's licence: a quiet trap

The easiest way to build a business list is to draw on existing open data sources — map data, business directories, public registries. The trap here is legal but on the copyright and licensing side rather than data protection: some open sources are distributed under a share-alike licence. That can oblige you to release work derived from that data under the same licence.

If you plan to build a commercial customer database and sell on top of it, that is a serious constraint: your database may have to be shared. The answer is choosing the source by its licence from the start. There are sources distributed under more permissive licences; building the backbone from those and using share-alike sources only for verification saves you from a problem that is hard to unwind later.

There is also a data quality issue that can devalue a list regardless of the law: a significant share of business records in open sources have no phone number at all, and a considerable share of those that do have not been updated in years. Discovering that a list you may lawfully use is not practically reachable is an expensive surprise.

Terms of use: technically possible, contractually forbidden

Collecting data from a website may be technically possible; that does not mean the site's terms of use allow it. Many platforms explicitly prohibit automated collection in their terms, and breaching that creates liability independent of data-protection law. In precedent disputes abroad, exactly this distinction — 'the data is public' versus 'collecting it breaches the contract' — has been decisive.

The rule that follows is to ask two separate questions before collecting: do I have a legal basis to process this data, and does taking it this way breach the source's terms? The two answers are independent; saying yes to the first does not settle the second.

The sturdier route: building a permission-based list

Looking at the legal and practical problems of harvested lists, building your own permission-based list is slower but far sturdier. The classic method is obtaining contact details in exchange for something useful to the business: a calculator, a checklist, a sector report or a free trial. Consent removes the entire debate about where the data came from.

The second benefit of a permission-based list shows in conversion. A business that left its details voluntarily responds at a far higher rate than one that does not know it is on a list. So getting consent is not only a legal requirement but a more efficient channel — a small consented list outperforms a large cold one.

The third route is using an intermediary: targeting through advertising platforms. There you hold no personal data, the platform does the targeting; the legal burden sits largely with the platform and you only follow advertising rules. The cost is paying per click, but not carrying the legal responsibility for a list is worth that cost for most small teams.

Phone, email, visit: different rules per channel

The commercial message regime covers electronic channels: email, SMS and automated calls. A person calling in the flesh or visiting a business falls outside that frame — but that does not mean data-protection obligations disappear. If you keep the number you called somewhere, that record still needs a legal basis and a retention period.

Channel choice is a practical decision as well as a legal one. In small businesses the decision maker is usually the person running the place, and they do not read email during the day; the most effective way to reach that audience is often the phone or a face-to-face visit. The electronic channel's advantage is scale, its disadvantage the low conversion in this audience.

A third option is going through an intermediary: sector associations, suppliers, accountants. In the small-business world trust runs in chains, and the value of one recommendation exceeds a hundred cold calls. That route builds slowly, but it carries a light legal burden and it lasts.

The life of a list: retention and deletion policy

A marketing list creates responsibility not on the day it is built but for years afterwards. How long you keep the data, under what conditions you update it and when you delete it should be a written policy. An old list kept 'in case it is useful one day' is both a legal risk and a practical illusion — a large share of three-year-old contact data is invalid anyway.

Refusal records are the opposite: they must be kept. If a business has said it does not want messages, that record should be held with a 'do not send' flag rather than deleted; otherwise, when the same list is loaded again six months later, you send to them again. The suppression list should outlive the marketing list.

Internal discipline: who sends what, to whom?

The most common source of legal risk is not bad intent but disorder: two people in sales sending from their own personal lists, an old campaign's list being reused, an intern trying out a list they found. However well the policy is written, it cannot be enforced unless sending happens from one place.

The practical rule: all commercial outreach goes through one tool, and the suppression list is applied automatically in that tool. Then who sent what is on record, refusals are processed centrally, and there is something to show in an audit. That is a measurement necessity as much as a legal safeguard — scattered sending also makes it impossible to know which message worked.

Do the arithmetic before choosing a channel

Whichever channel you choose, first calculate what acquiring one customer can cost you. Three numbers suffice: a customer's average lifetime value, the conversion rate from conversation to customer, and the share of that value you are willing to spend on acquisition. Together they give the ceiling you can pay per conversation — and that ceiling tells you which channel is realistic.

Trying channels without doing that arithmetic is the most common way to lose budget. If you do not know your ceiling you cannot tell whether a campaign is going well or badly; you only say 'we spent money and a few people called'. A team that knows its ceiling can stop in the second week and say 'this channel does not fit us'.

Conclusion

Reaching businesses looks like a technical problem, but the real constraints are legal: the commercial message regime, the basis for processing personal data, the source's licence and platforms' terms of use. All of them turn 'can we do it' into 'in what form can we do it' — and usually a small, consented, real list is both safer and more effective than a large harvested one.

These notes summarise our own research and are not legal advice. We recommend speaking to a lawyer before setting up your channel — but going in knowing which questions to ask makes that conversation far more productive.

لنخطُ خطوة اليوم

اكتب احتياجك في رسالة؛ نعود إليك خلال 24 ساعة ونرسم الطريق معًا.

الحدود القانونية للوصول إلى الشركات الصغيرة: التواصل المصرّح به وجمع البيانات · Vosetu