Communication

Commercial e-message consent (Turkey/İYS)

Why permission comes first: what a commercial electronic message and commercial message consent mean, and how to build a clean, opt-in list in Turkey.

Rocketly · 2026-07-19

You send one bulk campaign SMS on a quiet Saturday, and before noon your inbox fills with "who gave you my number?" replies. For a small business, few ways of starting the day sting quite like it. The frustrating part is that the problem usually isn't the text itself; it's that the message went out without commercial message consent — meaning the recipient never actually said yes. An unpermitted message chips away at your brand and, in a market like Turkey, skips an obligation you cannot simply ignore.

This article covers what a commercial electronic message is, why permission comes first, what Turkey's İYS (İleti Yönetim Sistemi) is, and how to move from a messy contact dump to a clean, permission-based list. It is a general overview, not legal advice; because rules and exceptions change over time, confirm your own situation with official sources and a professional.

What exactly is a commercial electronic message?

A commercial electronic message is, in short, any message sent electronically to promote or market a product or service, raise a business's profile, or pass on greetings. SMS, email, automated calls and voice messages sit at the centre of that definition.

Not every message falls inside it, though. Transactional and informational content — an order confirmation, a shipping update, an appointment reminder, a payment notice — is usually treated differently. The line isn't always sharp: the moment you add "you might also like this" under "your order has shipped," a notification quietly turns into marketing.

A practical test: is the message's real purpose to sell, promote or win someone back? If so, it is most likely a commercial electronic message, and the consent rules apply. When unsure, read it through the recipient's eyes: "who is sending me this, and why?"

The rule is simple: permission first, message second

The foundation of permission-based marketing fits in one sentence: you don't send someone a commercial message until they have said yes. For that "yes" to count, it should have a few qualities.

  • Clear and informed: the person should know exactly what they agreed to; consent shouldn't be buried at the bottom of text no one reads.
  • Given in advance: permission comes before the message; "we'll keep sending unless you object" is not a substitute for consent.
  • Specific to sender and channel: giving one brand permission to email you doesn't mean that brand can call you, or that a different company can text you.
  • Easy to withdraw: pulling consent back should be as easy as giving it.

These may sound strict, but they protect you. Bought number lists, a pile of business cards from a trade fair, or the "they'll be a customer one day" assumption meet none of them — having a phone number is not the same as having the right to message it. As we cover in the myths that quietly hurt cold email, "send to everyone and see who bites" mostly buys you lost reputation.

What İYS is and why it exists

The Message Management System — İYS for short — is a national registry in Turkey where consents and opt-out requests for commercial electronic messages are held. The idea is simple but powerful: instead of permissions sitting scattered across each company's own database, they are gathered in one shared place the recipient can also see and manage.

That reassures both sides. The recipient can see in one place which brands they have said yes to and switch off the rest in a single move. For the sender, the question "did this person actually consent?" gets an orderly answer you can point to if a dispute arises.

1Get consent2Record in İYS3Send message4Honour opt-out
The cycle of permission-based messaging: it doesn't start without consent, and it doesn't continue past an opt-out.

Exactly who the system covers, which channels, and on what timeline can change over time, and the process can work differently for a small sender than a high-volume one. So confirm "does this apply to me, how do I register, which channels count?" with an official source or your accountant. The point isn't to memorise regulation, but to grasp the logic behind it.

Exceptions, gray areas, and "our case is different"

As with any rule, there are nuances — and most of the confusion lives right here.

  • Existing customers: reaching a customer who has already bought from you, about things close to what they bought, can sometimes be treated more flexibly. Even so, it isn't an unlimited licence, and the customer can stop it whenever they like.
  • Businesses (B2B): business-to-business contact and messaging aimed at individuals aren't always judged by the same yardstick. But "the other side is a business too" doesn't make the idea of consent disappear.
  • Requested information: replying to a quote or a question the person asked for isn't marketing in itself; the moment you staple a campaign to that reply, the line blurs.

The edges of these exceptions are thin, and it is far too easy to stretch them into "this covers us too." Whenever you're unsure, let your default be to ask for permission — it is both safer and, over time, more profitable. Consent isn't an obstacle; it's how you filter out an indifferent crowd and talk to an audience that actually listens.

Sleep easier with a permission-based list

Rocketly helps you keep your WhatsApp, email and SMS permissions tidy in one inbox.

Try Rocketly free

The right to opt out is non-negotiable

Being able to leave as easily as they joined is the recipient's most basic right. Every commercial message should carry a clear, free and effortless way to say "no more" — not a formality, but insurance for trust.

  • Visible: the unsubscribe link or "STOP" instruction should be obvious enough not to need a magnifying glass.
  • Fast to take effect: reappearing in someone's next campaign after they have opted out erodes both trust and reputation.
  • Manageable by channel: a person may want to cut the emails but keep order notifications; an "all or nothing" demand is a poor experience.

Don't read a high opt-out rate as a disaster; more often your list is refining itself toward the people who genuinely want you. A small but willing list beats a large but indifferent one on almost every measure — deliverability, opens and replies concentrate in that willing core.

Permission isn't one-size-fits-all across channels

The most common misconception here is thinking a single "permission" covers every channel at once. In reality each channel has its own frame and its own rules, and consent from one doesn't carry over automatically to another.

PermissionSMSEmailWhatsAppCalls
One consent doesn't cover every channel; each has its own permission frame.
  • SMS and automated calls: these sit at the centre of İYS; consent and opt-out are most directly tied to the system. With bulk SMS, "is this permitted?" should be the first question of every send.
  • Email: the same permission logic applies, and habits like double opt-in also protect your deliverability. We walk through how email marketing actually works step by step in a separate guide.
  • WhatsApp: here the platform's own (Meta's) permission and template rules take over; the user either writes to you first or opts in clearly. Sending bulk WhatsApp messages without getting banned and writing a template that isn't rejected are separate skills.

If you use two channels together, it helps to clarify which suits which moment; our comparison of SMS versus email is a good start. And as you add channels, seeing every permission and conversation in one place — bringing multichannel communication into a single inbox — shifts from nice-to-have to necessary.

How to build a clean, permission-based list

The good news: building a permission-based list is less work than it sounds — it just takes a little patience and order. A few simple habits do most of the job.

  • Collect consent at the source: a web form, a clear "yes" on WhatsApp, a QR-code sign-up in the shop — record where and when each permission came from.
  • Say up front what you'll send: if you promised "a few campaigns a month," don't message every three days; expectation and practice should match.
  • Clean the list regularly: emails unopened for months, or numbers that keep bouncing, are both a cost and a reputation risk.
  • Keep the record: being able to show when and with what wording you obtained consent is your firmest footing if a problem arises.

Let's be honest: for a workshop serving a few dozen customers a month, an elaborate bulk-messaging setup is usually overkill. Sometimes a handful of genuinely personal messages, sent by hand, beat thousands of automated ones. Scale calls for a system; while you are small, it isn't worth over-engineering. What matters at any size is keeping consent at the centre.

Frequently asked questions

Do I have to register with İYS?

If you send commercial electronic messages, you most likely have some relationship with the system; but the scope and details of the obligation can vary by business and change over time. For your own case, check current official sources or your accountant.

I have my customer's number — can I message them?

Having a number isn't the same as having permission to send commercial messages. An informational message and a marketing message are treated differently; for marketing, seeking clear consent is the safest path.

Are WhatsApp messages covered by İYS?

On WhatsApp the platform's own permission and template rules apply first; the user's opt-in or writing to you first is essential. Because the legal scope of channels can shift, confirm the current rules for bulk and marketing sends.

How should I store consent?

Keep a record that shows from whom, when, for which channel and with what wording you obtained consent. That record is your strongest footing in both an audit and a dispute.

Permission-based messaging isn't an obstacle but an advantage: a way to talk to an audience that has made room for you and is waiting to hear from you. The rule is easy to hold in mind — consent first, message second, always an easy way out. With a CRM like Rocketly that gathers permissions, conversations and channels in one place, "did this person actually opt in?" stops being a worry and becomes a detail the system quietly handles.