Tecof • September 29, 2026

What Is İYS (Message Management System)? SMS and Email Consent

What Is İYS (Message Management System)? SMS and Email Consent

In Brief

İYS (the Message Management System) is Turkey's central registry where consents and opt-out requests for commercial electronic messages are held. The logic is simple: if a customer has given you permission for SMS, email or calls, that permission must exist not only in your own database but in a shared registry as well; and when the customer withdraws it, the opt-out comes back to you from that same registry. Consent is no longer a brand's private list — it is a verifiable record. As of 2026 the question is not "did we get consent" but "can we prove the consent we hold, and how many hours does it take us to drop an opt-out from our list".

Thursday evening, 20.40. A home textiles store sends a discount campaign by SMS to a list of 38,400 people. The report arrives the next morning: 31,200 messages delivered, 7,200 dropped by the messaging provider with the reason "no consent found". The marketing team had pulled the list from the CRM, where all 7,200 of those people appeared as opted in. The gap between the two records had one cause: those customers had opted out not through the link at the bottom of a message but directly through İYS, and that opt-out had never been written back into the CRM.

The loss here is not just wasted send budget. Had the messages gone out without consent, the problem would have moved to the regulatory side; this time the provider's filter stepped in, so only money and time were lost. The real point is this: İYS is not a one-way notification box but a record that has to be synchronised in both directions. Most brands build the first direction (uploading consents) and forget to build the second (pulling opt-outs back).

This article describes the mechanism: which messages require consent, how consent is collected, how the record is synchronised and what check runs before a send. Because current provisions, timeframes and sanctions can change over time, confirm your setup with your own financial or legal advisor before putting it live; the framework here covers the technical and operational side.

1. What Is İYS and How Does It Work?

İYS is a shared record layer where consent and opt-out data is stored independently of any single brand. The brand collects consent and writes it to the registry; the recipient can opt out through that same registry, and the brand is obliged to see that opt-out.

The three parties

The easiest way to think about it is through three parties: the brand sending the message, the person receiving it, and the registry sitting in between. The brand collects consent through its own channels (site, store, call centre) and uploads it. The recipient can see, in one place, which brand they gave permission to and through which channel, and can opt out individually or in bulk. Before any send, the list is filtered against that registry.

  • Consent: a recipient's acceptance of commercial messages from a specific brand through a specific channel.
  • Opt-out: withdrawal of a previously given consent; the opt-out always takes precedence over consent and must be free of charge.
  • Channel: the message type the consent covers — SMS, email and calls each require their own permission.
  • Consent source: the environment in which the consent was obtained (e.g. a web sign-up form, an in-store tablet, a call centre record).
  • Evidence: the data set showing the moment consent was given, which must be retained; the burden of proving consent sits with the sender.

The life cycle of a consent record

A consent record goes through four stages: collection, upload to the registry, verification and expiry. Collection happens at the customer touchpoint. Upload must happen within the period the regulation prescribes — confirm that period in its current form with your own advisor, because a consent uploaded late may in practice be treated as absent. Verification is the filtering of the list against the registry before a send. Expiry happens in one of two ways: the recipient opts out, or the brand removes the record.

Why the opt-out mechanism is critical

The opt-out is the most neglected and most expensive part of the system. A recipient can opt out in three separate places: through the opt-out route inside the message you sent, through your call centre, or directly through the registry's own interface. The first two land in your system; the third does not — you have to pull it. If you have not built that pull, your list drifts a little further from reality every month, and you only notice when a send collapses.

2. Which Messages Require Consent, and Which Do Not?

What determines the need for consent is not the channel but the purpose: a message carrying marketing, promotional or campaign intent requires consent, while a notification belonging to the running of an order is generally assessed differently.

Commercial message versus transactional notification

In practice you can draw the line like this: if the message is trying to sell the recipient something or encourage a purchase, it is a commercial message. If it delivers information needed to carry out a relationship the recipient already entered into, it is transactional. "Your order has been handed to the courier" is transactional; "If you liked your order, everything in the category is 20 percent off this week" is a commercial message. The most common mistake is appending a campaign sentence to a transactional message — that makes the character of the entire message arguable.

Consent is per channel

Consent is channel-based: email permission does not grant the right to send SMS. This explains why collecting "permission for all channels" through a single checkbox is a weak construction. Asking per channel lowers conversion somewhat, but it raises the quality and the defensibility of the list. We covered the cost and conversion side of channel choice separately in our comparison of email and SMS.

The B2B side

The regime for individual recipients and for recipients carrying on a commercial activity is not identical; in B2B communication the requirement for prior consent works differently in some cases, but the right to opt out is preserved in every case. So there is no shortcut along the lines of "corporate customers can be messaged without consent"; once an opt-out arrives, you must comply. Managing your B2B list as a separate consent pool is the cleanest way to avoid having to untangle it later. Clarify with your legal advisor how this distinction applies to your own business model.

Example messageChannelNaturePrior consent expected?
Order confirmation, tracking numberSMS / emailTransactionalGenerally no
Return process notificationEmailTransactionalGenerally no
Weekly discount newsletterEmailCommercialYes
Abandoned cart reminderSMS / emailCommercial (contains an inducement)Yes
Back-in-stock alert (to the person who asked)EmailRequest-basedThe request must be retained
Birthday coupon messageSMSCommercialYes

3. How Is Consent Collected on an E-commerce Site?

Valid consent is consent the recipient understands, gives through a clear action, and that can be proven afterwards. Design is a legal matter here, not an aesthetic one.

Rules for the checkbox

The checkbox cannot arrive pre-ticked; the user has to tick it themselves. The consent text must not be buried inside the membership agreement or the distance sales contract — it must be its own element. Split the channels into separate boxes and say in the text what you will send: a concrete phrase such as "campaign and discount announcements" is both more valid and better converting than a vague "communication permission".

  • Separate consent: a purchase cannot be made conditional on marketing consent; someone who declines must still be able to order.
  • Plain text: in one sentence — what will be sent, through which channel, by whom.
  • A way out: every commercial message must carry a free and easy opt-out route.
  • The moment of record: the date and time of consent, the IP and the form identifier must be stored at that moment; they cannot be produced later.

Is double opt-in necessary?

Double opt-in is not a mandatory construction, but it strengthens the evidentiary side noticeably. It works like this: the user fills in the form, a confirmation link or code goes to their address or phone, and consent counts as valid only once that step is completed. The cost is a somewhat smaller number of records entering the list; the gain is that mistyped addresses, details entered in someone else's name and automated form fills never enter it at all. In email, your deliverability score is directly affected by that cleanliness. Use double opt-in at low-friction entry points such as newsletters and competitions; where identity is already verified, such as the order flow, a single step is enough.

The right places to collect consent

In e-commerce, four touchpoints provide most of the consent volume: membership registration, the order completion step, the newsletter field and the communication preferences screen inside the customer account. Asking at the order step brings the highest volume but is the place that needs the most care; a single-line, separate box that does not interrupt the payment flow is the correct construction. Because every extra field added to the payment flow lowers completion, this box should sit below the order summary and stay on one line.

What should be retained as evidence?

Because the burden of proof sits with the sender, the answer to "how did I obtain this consent" must sit next to the consent record. Keep the fields below in a single, tamper-evident table, and make them visible from the customer service screen too, so that an objection can be answered within seconds.

Field to retainExample valueWhy it is needed
Consent date and time2026-03-14 14:22:07Sequence and validity
ChannelSMSConsent is per channel
Recipient identifierPhone / emailMatching against the registry
Consent sourceWeb sign-up formThe environment it came from
Version of the consent textv3 (2026-01-10)Proof of what was read at the time
IP and session data—Technical verification trail
Opt-out date (if any)2026-06-02Input for the send filter

4. İYS Integration: Manual Upload or API?

The right answer on integration method depends on volume: a store collecting a few dozen new consents a month can use the screen by hand, while a store collecting hundreds a day needs an automated connection.

Three methods

There are three ways to write consent into the registry: entering it one by one through the admin screen, uploading it in bulk as a file, and connecting your software directly. The third removes the delay and lets you pull opt-outs back automatically. If the technical logic of that connection is unfamiliar, our article explaining what an API is is a good starting point.

MethodSuitable scaleDelayTechnical requirementMain risk
Single entry (panel)< 50 consents a monthManual, person-dependentNoneForgotten records
Bulk file upload50-5,000 a monthAs often as you uploadFile preparationWrong format, duplicates
API connection> 5,000 a monthNear real timeDevelopment + monitoringSilent failure, unwatched queue
Through an intermediary platformAny scalePlatform dependentConfigurationUnclear ownership of responsibility

The two-way synchronisation loop

The correct construction is not one-way but circular, and it has four steps: write new consents to the registry, download the opt-outs coming from it, update the state in your own database, and build the send list from that updated state. Run the opt-out download at regular intervals, not right before a send; a team running the sync for the first time on campaign day cannot know in advance how many people will drop off the list, and is left holding a target audience that no longer exists.

Error handling and monitoring

The real danger in integrations is not a connection that breaks but one that quietly stops working. Set three simple alarms: warn if more than your chosen interval has passed since the last successful sync; warn if the share of rejected records rises above normal; warn if the pre-send filtering step dropped no records at all (which usually means the filter is not running). Building these patterns from ready-made components on the integrations side saves every store from learning the same lessons from scratch.

5. Pre-send Checks and List Hygiene

The pre-send check is the step where the list is filtered against the current consent registry and opted-out or invalid records are removed, and it must be repeated for every campaign.

The filtering flow

The flow runs like this: the marketing tool produces the raw list, the filtering service compares it against the consent registry, non-matching records drop out, and the remaining list goes to the sending provider. It matters that filtering runs as a separate step before the send rather than at the moment of sending; that way you can report how many people dropped and why. Say filtering removed 7,200 records from a list of 38,400 — knowing the reason for that number is what lets you build the next campaign's audience correctly.

Segmentation and send frequency

Consent is not a right to send without limit. What raises the opt-out rate is usually not content but frequency: three campaign messages a week to the same person is the fastest way to un-consent a list. Cap frequency per segment and run a different flow for records that have shown no engagement in the last 90 days. We described how personalisation and flows are built in our article on email campaigns.

Which record wins when the two conflict?

The rule is plain: the opt-out always wins. If a record that looks opted in within your own database appears as opted out in the central registry, no commercial message goes to that person and your own record must be corrected. The reverse also happens: the user opted out on your site but the opt-out never reached the registry — in that case you are the incomplete side. So run the comparison in both directions at regular intervals, not only at send time, and report the number of discrepancies. A discrepancy count growing over the months is the earliest sign that synchronisation has broken somewhere.

Four metrics to watch

  • Filter-out rate: what share of the raw list drops at the consent check; if it is rising, something is wrong at your consent collection points.
  • Opt-out rate: new opt-outs per send; the earliest indicator of a frequency or targeting problem.
  • Delivery rate: the share of messages reaching and delivered by the provider; in email it should also be tracked by sending domain.
  • Consent age: the average age of your records; a list that has grown too old neither converts nor stands up to scrutiny.

6. Six Common Mistakes

Most mistakes come not from bad intent but from failing to notice that the system runs in two directions.

Mistakes on the data side

  • Using a purchased list: treat consent as non-transferable; permission somebody else collected is not valid on your behalf.
  • Collecting all channels in one box: without a channel split, which channel was consented to cannot be proven.
  • Keeping opt-outs only in the marketing tool: change tools and the opt-out history disappears; the opt-out record belongs in the main database.

Mistakes on the process side

  • Uploading consent late: a send made before the collected consent reaches the registry is not treated as consented.
  • Adding a campaign to a transactional message: one sentence of discount copy changes the character of the notification.
  • Processing opt-outs slowly: a message reaching a customer who knows they opted out is the scenario that generates the most complaints.

These six are not the whole of your obligations; the other processes in e-commerce that demand record and evidence discipline should be built with the same logic — that is, around the question "can this be proven afterwards".

Building the Consent Infrastructure in Thirty Days

Thirty days is not enough to build a flawless system from nothing, but it is enough to close the two biggest risks: consent you cannot prove and opt-outs you do not process. The order matters: do not fix anything before you know what you have.

Days 1-7: inventory

Gather every list you hold into a single table: how many records, which channel, from what date, from which form. Move records with an unknown source into a separate pool. Archive a screenshot and the text version of every consent box on the site. No sends happen this week; only the current state is established.

Days 8-14: registry and synchronisation

Write the consents to the registry, download the opt-out list and update the state in your own database. For records whose source cannot be proven, either build a re-consent flow or exclude them from marketing sends. This week's output is a smaller list — and that is the correct outcome.

Days 15-21: fixing forms and flows

Split the consent boxes on the membership, order and newsletter forms, version the texts, and test that the evidence fields are actually being stored. Add a communication preferences screen inside the customer account. Push "when and where did this person consent" onto the customer service screen.

Days 22-30: automation and alarms

Attach the synchronisation to a scheduled job, set the three alarms, and make the pre-send filtering step a mandatory part of the campaign process. Make the four metrics visible in a weekly report and write the list for the next thirty days. On an e-commerce platform where consent, order and customer data sit in one place, most of these steps turn into configuration work.

Here is the job for tomorrow morning: open the send report for your last campaign and read the number of records dropped for "no consent found" or a similar reason; if that number is not zero, your opt-out synchronisation is not working, and fixing it is both faster and cheaper than designing a new campaign.

Frequently Asked Questions

What is İYS and what does it do, briefly?

İYS is the central registry where consents and opt-out requests for commercial electronic messages are held independently of any brand. For a brand it does two things: it makes the consent you hold verifiable, and it carries opt-outs made through the system back to you.

Do order and shipping notifications require consent?

Notifications belonging to the fulfilment of an order are generally not treated as commercial messages, and separate marketing consent is not expected. But the assessment changes the moment you add a campaign, a discount or a product recommendation inside that message; keep transactional notifications apart from marketing content.

Can I send an SMS to someone who consented by email?

No. Consent is channel-based; permission given for email does not create a right to SMS or calls. Collect consent separately for each channel and keep that distinction as a separate field in your database too.

How do I prove that I obtained consent?

By retaining the data from the moment of consent: date and time, channel, recipient identifier, the source it was collected from, the version of the consent text shown at the time, and the technical trail. Because these fields cannot be produced afterwards, they must be recorded as the consent is collected.

Can I send to a list I purchased?

In practice, no. Treat the consent as having been given to the party that collected the list, not to you; sending on transferred consent generates complaints and cannot be defended. The cleanest route is never to bring such lists into the marketing flow at all.

How quickly must I process an opt-out?

The regulation sets an upper limit; confirm the current period with your advisor. The operational advice is this: do not wait for the limit — run the opt-out download daily and write the opt-out into your main database. The cost of delay is not only compliance but reputation.

Are the consent rules the same for corporate (B2B) customers?

For recipients who are traders or craftspeople the prior consent requirement can work differently, but the right to opt out applies in every case. Manage B2B lists in a separate pool and process opt-outs with the same discipline as on the consumer list; confirm your own situation with your legal advisor.

Should I build the İYS integration myself or use an intermediary platform?

If your monthly consent volume is below a few hundred, an intermediary platform or bulk upload is enough. As volume grows and consent arrives through more than one channel, a direct connection is safer, because it removes both delay and human error. Whichever route you choose, make sure the opt-out download step is in place.

Is consent valid forever?

Technically the record stands until an opt-out arrives, but a very old consent that has never produced engagement is worthless in practice: it does not convert, it raises complaint risk and it lowers your delivery score. Building a re-consent flow for unengaged records is more profitable than growing the list.

Are KVKK and İYS the same thing?

No — they are separate obligations and neither replaces the other. The framework for processing personal data and the registration of commercial message consent are different subjects; having a privacy notice does not mean you have obtained commercial message consent. You need to build both sides separately.