Your Customer Said It on WhatsApp — Did You Just Export It Abroad?

Sending WhatsApp Customer Chats to ChatGPT, Gemini or Claude Under Turkish Data Protection Law

Artificial intelligence is rapidly becoming part of ordinary customer service operations. A sales representative may copy a WhatsApp conversation into ChatGPT to draft a reply. A clinic may connect its WhatsApp inbox to Gemini to classify patient requests. An e-commerce company may automatically send incoming customer messages to Claude through an API and use the generated response in its support system.

From a technical perspective, these workflows may look simple.

From the perspective of Turkish data protection law, however, a crucial question arises:

Does sending a customer’s WhatsApp message to ChatGPT, Gemini or Claude constitute a transfer of personal data abroad?

In most real-world scenarios, the answer is yes.

The important point is that a cross-border transfer does not depend on whether the artificial intelligence provider trains its model using the conversation. The legal question arises at an earlier stage: has personal data collected in Türkiye been made available to or processed by an entity or infrastructure located abroad?

Following the amendments to Article 9 of Law No. 6698 on the Protection of Personal Data (“KVKK”), which entered into force on 1 June 2024, companies must analyse these AI integrations under Türkiye’s new cross-border data transfer regime. The Turkish Data Protection Authority (“KVKK Authority”) currently states that no country, sector or international organisation has yet been designated through an adequacy decision.

This makes the issue particularly important for Turkish businesses using global AI platforms.


1. A WhatsApp Message Is Often Personal Data

A customer WhatsApp message does not have to contain a Turkish ID number to qualify as personal data.

A typical conversation may include:

  • the customer’s name and surname;
  • telephone number;
  • profile photograph;
  • e-mail address;
  • home or delivery address;
  • customer or order number;
  • financial information;
  • transaction history;
  • complaints;
  • voice recordings;
  • photographs;
  • location information; or
  • information about another identifiable person.

For example:

“Hi, I am Mehmet Yılmaz. My order number is 12345. Please deliver the product to my home in Kadıköy.”

This message contains several pieces of personal data.

If an employee copies the message and pastes it into an AI application with the instruction:

“Draft a professional response to this customer.”

the company is carrying out an additional personal data processing operation.

If the AI provider processing the message is located abroad or the message is processed through infrastructure abroad, Article 9 KVKK must also be considered.


2. The Key Rule: Sending the Message to an AI Provider Can Be a Cross-Border Transfer

The most important misconception is the belief that:

“We are only asking the AI a question; we are not transferring a database.”

This distinction is generally irrelevant.

Uploading, transmitting or otherwise making personal data available to an AI provider can itself constitute processing and, where the foreign element exists, a cross-border transfer.

The Turkish Data Protection Authority previously addressed a similar principle in its WhatsApp investigation. It stated that processing activities such as recording, storage, alteration and transfer carried out after personal data had been obtained in Türkiye could amount to an international transfer where the relevant servers were not located in Türkiye.

Therefore, transferring even one customer conversation to a foreign AI provider can fall within the concept of cross-border data transfer.

The situation becomes much more significant where the transfer is systematic.

Examples include:

Manual use

A customer service employee regularly copies customer messages from WhatsApp into ChatGPT.

Automated API use

Incoming WhatsApp messages are automatically sent:

WhatsApp → CRM → AI API → generated response → customer.

AI customer-service agent

The AI system directly reads incoming WhatsApp messages and produces customer responses.

All three scenarios may involve an international transfer.


3. “But We Do Not Send the Customer’s Name” Is Not Always Enough

Removing the customer’s name does not necessarily anonymise the conversation.

Consider:

“The patient who had rhinoplasty at our Nişantaşı clinic yesterday says that she has severe bleeding after the operation. Her appointment number is 74261.”

Even without a name, the patient may still be identifiable through the combination of clinic, procedure, time and appointment number.

Under KVKK, removing obvious identifiers normally results in pseudonymisation, not necessarily anonymisation.

If the company can reconnect the information with an identifiable customer, the data will usually remain personal data.

Accordingly, companies should not assume that deleting a person’s first and last name automatically removes the transfer from KVKK.


4. What Changes If ChatGPT Is Used?

For users outside the EEA and Switzerland, OpenAI’s current privacy policy identifies OpenAI OpCo, LLC in the United States as the relevant controller for its individual services. Türkiye therefore falls within the “elsewhere” category described in that policy.

Accordingly, copying identifiable Turkish customer correspondence into an ordinary ChatGPT account creates an obvious international-data-processing issue from a KVKK perspective.

The position becomes more sophisticated when a company uses ChatGPT Enterprise, ChatGPT Business or the OpenAI API.

OpenAI states that, by default, customer inputs and outputs from its business offerings and API are not used to train its models. It also offers retention controls and, for qualifying API users, zero-data-retention arrangements.

However:

“The provider does not train on our data” does not mean “there is no international transfer.”

Model training and cross-border transfer are legally separate questions.

OpenAI also offers regional data-residency and, for eligible Enterprise/Edu customers, inference-residency options in Europe. Yet even European processing is still processing outside Türkiye for purposes of Turkish cross-border transfer rules. OpenAI further notes that certain processing, metadata or external integrations may occur outside the selected region depending on the product and configuration.

Therefore:

EU data residency may reduce risk, but it does not transform the processing into a domestic Turkish transfer.

5. What About Gemini?

A similar analysis applies to Google’s Gemini services.

Google’s Gemini privacy information currently states that Gemini Apps are provided by Google Ireland Limited for users in the EEA and Switzerland and by Google LLC elsewhere. Türkiye is therefore outside the EEA-specific category.

The distinction between consumer Gemini and Google Workspace with Gemini is particularly important.

Google states that qualifying Workspace customers receive enterprise protections under which customer content is not human reviewed or used to train generative AI models outside the customer’s domain without permission. Google also provides controls allowing certain Workspace customers to restrict Gemini processing to the United States or the EU.

Again, however, these protections do not eliminate the international-transfer analysis under KVKK.

They primarily affect:

  • the security level;
  • provider contractual responsibilities;
  • model-training practices;
  • storage location;
  • processing location; and
  • technical and organisational safeguards.

For a Turkish company, the legal question remains:

On which Article 9 mechanism is the transfer to Google based?


6. What About Claude?

The same principle applies to Anthropic’s Claude.

Anthropic states that for commercial offerings such as Claude for Work and its API, the commercial customer generally remains the controller of submitted data and Anthropic acts as a processor. Anthropic also states that it does not use commercial customer inputs and outputs for model training by default.

For its API, Anthropic currently states that inputs and outputs are normally deleted from backend systems within 30 days unless another arrangement applies, including eligible zero-data-retention agreements.

However, Anthropic also states that commercial customer data may be processed across infrastructure in the United States, Europe, Asia and Australia, while storage remains US-only by default unless otherwise agreed.

Thus, sending Turkish customer WhatsApp conversations to Claude may clearly trigger Article 9 KVKK.


7. The 2024 Reform Completely Changed Türkiye’s Cross-Border Transfer System

Until 2024, many Turkish companies attempted to solve international data transfers principally through explicit consent or the previous undertaking/Board-approval mechanism.

The system changed fundamentally on 1 June 2024.

Article 9 now essentially establishes a three-level structure:

Level 1 — Adequacy Decision

If the Turkish Data Protection Board has issued an adequacy decision concerning the relevant country, sector or international organisation, personal data may be transferred where the applicable Article 5 or Article 6 processing condition is also satisfied.

However, the Authority currently states:

No adequacy country has yet been designated.

Accordingly, companies using major foreign AI providers will generally move to the second level.

Level 2 — Appropriate Safeguards

Where there is no adequacy decision, the transfer may take place where:

  1. a processing condition under Article 5 or Article 6 exists;
  2. the data subject can exercise his or her rights and access effective legal remedies in the destination country; and
  3. one of the appropriate safeguards specified in Article 9 is established.

For private-sector AI integrations, the most practical instrument will frequently be the KVKK Standard Contract.

The Authority has published four different models:

  1. Controller → Controller;
  2. Controller → Processor;
  3. Processor → Processor; and
  4. Processor → Controller.

Where a Turkish company determines why customer WhatsApp messages are processed and the foreign AI provider processes them on the company’s instructions, the Controller-to-Processor Standard Contract may normally be the relevant starting point.

But the actual contractual architecture must be checked case by case.

Level 3 — Exceptional / Occasional Transfers

If there is neither an adequacy decision nor an appropriate safeguard, Article 9 allows transfer only in narrowly defined occasional circumstances.

These include, for example, explicit consent after informing the data subject of potential risks.

The important word is occasional.

The KVKK Authority expressly states that these derogations are intended for transfers that are non-regular, non-continuous and rare.

Therefore, a company cannot safely design a permanent system such as:

“Every WhatsApp message will automatically be sent to ChatGPT, and we will simply obtain customer consent.”

For systematic AI integrations, reliance on the occasional-transfer exception may be legally problematic.


8. A Standard Contract Does Not Solve Everything

Another common mistake is:

“If we sign the KVKK Standard Contract, our system becomes compliant.”

Not necessarily.

The standard contract solves only one part of the compliance architecture.

The company must separately identify a lawful processing condition under Article 5 or, where special-category data is involved, Article 6.

For example, the company should determine:

  • why the WhatsApp conversation is being processed;
  • whether sending the entire conversation to AI is necessary;
  • what categories of data are included;
  • whether less data could achieve the same purpose;
  • whether the AI provider is a processor or separate controller;
  • which subprocessors may receive the information;
  • where those subprocessors process the data;
  • how long prompts and outputs are retained; and
  • whether the information will be used for model improvement.

The standard contract cannot legitimise unnecessary or disproportionate processing.

9. The Five-Business-Day Notification Requirement

Companies using the Turkish Standard Contract should pay particular attention to procedural requirements.

Article 9 provides that the signed standard contract must be notified to the KVKK Authority within five business days.

The Authority has specifically reiterated this requirement and has recently issued guidance concerning signatures, authorised representatives and Turkish-language execution of standard contracts.

Therefore, merely incorporating an AI provider’s international DPA or GDPR Standard Contractual Clauses into the contract is not automatically equivalent to signing the Turkish KVKK Standard Contract.

A company’s GDPR SCC documentation and its KVKK transfer documentation should not be confused.


10. What If WhatsApp Messages Contain Health Information?

This is where the risk becomes significantly higher.

Imagine a medical-tourism clinic receives:

“I had a gastric sleeve operation two months ago. I am diabetic and currently taking insulin. Is it safe for me to have another procedure?”

This conversation may contain health data.

Health information is a special category of personal data under Article 6 KVKK.

The KVKK Authority’s updated guidance confirms that health information includes not merely confirmed diagnoses but also data indicating a person’s physical or mental health status, examinations, preliminary diagnoses, treatment details and similar medical information.

Consequently, automatically sending this message to a foreign AI platform requires at least two separate analyses:

  1. Is processing the health data lawful under Article 6?
  2. Is transferring that health data abroad lawful under Article 9?

Additional security measures applicable to special-category personal data must also be implemented.


11. Is Asking the Customer for Consent Enough?

For one-off exceptional transfers, explicit consent may sometimes form part of the Article 9 analysis.

But for routine AI-based customer support, consent is a weak structural solution.

Suppose a website states:

“By contacting us via WhatsApp, you consent to your messages being transferred abroad to AI service providers.”

There are several risks.

First, consent must be specific, informed and freely given.

Second, the company must explain meaningful information concerning the transfer.

Third, if AI processing is a permanent and systematic part of business operations, Article 9’s occasional-transfer requirement becomes critical.

Fourth, bundling consent into general terms or making unnecessary processing compulsory may undermine its validity.

For recurring AI processing, companies should therefore generally focus on creating an appropriate-safeguard architecture rather than treating customer consent as a universal shortcut.


12. What If the Message Is Sent to an EU Server?

This is another common misunderstanding.

Suppose a Turkish company configures its AI service so that:

WhatsApp message → Frankfurt AI server → response → Türkiye.

The company may say:

“The information remains in Europe, so there is no problem.”

Under KVKK, however, Germany is still outside Türkiye.

Therefore, the transfer remains a cross-border transfer.

EU processing may offer advantages relating to GDPR compliance, security, processor governance and data localisation, but it does not remove Article 9 from the analysis.


13. Does the Same Rule Apply If the Server Is in Türkiye but Foreign Employees Can Access It?

The physical location of the server is important but should not be treated as the only relevant factor.

The compliance analysis should also identify:

  • who can access the information;
  • from which countries;
  • whether overseas support personnel can retrieve customer content;
  • whether subprocessors receive logs;
  • whether backups are stored abroad; and
  • whether prompts are routed through foreign infrastructure.

A system advertised as “hosted in Türkiye” may still contain international-access or subsequent-transfer mechanisms.

The KVKK Authority’s transfer framework expressly recognises that onward transfers by foreign processors and subprocessors must also be considered.


14. Who Is the Data Controller?

In a standard commercial customer-service system, the Turkish business will usually determine:

  • why WhatsApp messages are collected;
  • what they are used for;
  • whether AI is used;
  • which AI provider is selected;
  • how long customer records are retained; and
  • what responses are sent.

The Turkish company will therefore generally be the data controller.

Where the AI provider processes customer content only on the company’s instructions to generate a response, it may operate as a data processor.

For example, Anthropic expressly describes itself as processor in relation to certain Claude commercial offerings, while the customer organisation remains controller.

Similar processor arrangements can exist under enterprise/API contracts of other providers.

However, companies should not infer roles merely from marketing descriptions.

The applicable:

  • Terms of Service;
  • Data Processing Addendum;
  • privacy documentation;
  • subprocessor list;
  • retention terms; and
  • AI training settings

must be reviewed.


15. Consumer AI Accounts Are Particularly Risky for Company Data

One of the highest-risk practices is allowing employees to use their personal AI accounts for customer correspondence.

For example:

Customer writes to the company → employee copies the message → employee pastes it into his personal ChatGPT, Gemini or Claude account.

This creates several governance problems.

The company may not know:

  • which account was used;
  • which provider terms apply;
  • whether conversation history is enabled;
  • whether training or model-improvement settings are enabled;
  • how long data remains stored;
  • whether the employee deletes the conversation;
  • whether plugins or external tools receive the information; or
  • whether the company can respond effectively to a customer’s deletion or access request.

This is therefore not merely a cross-border transfer issue.

It is also an internal data-governance and security problem.


16. A Safer Corporate Architecture

For businesses that genuinely need AI-based WhatsApp customer support, a more defensible architecture would normally involve:

WhatsApp Business Platform → Turkish CRM / backend → data-minimisation layer → enterprise AI API → generated response → human or automated review → WhatsApp

Before sending data to the AI provider, the system should remove information unnecessary for the AI task.

Instead of sending:

“Ahmet Yılmaz, TC No. 12345678901, telephone +90…, lives at…, bought product number…, please write him a polite answer.”

the model may only need:

“Customer states that the product arrived damaged and requests replacement. Draft a polite response explaining the replacement procedure.”

Where technically possible, identifiers should remain in the Turkish CRM and only the minimum necessary contextual information should be transmitted to the model.

This is a much stronger application of the KVKK principles of proportionality and data minimisation.


17. Practical Compliance Checklist for Turkish Companies

Before connecting WhatsApp customer messages to ChatGPT, Gemini, Claude or another generative AI service, the company should complete at least the following steps.

1. Map the Data Flow

Identify exactly:

WhatsApp → integration provider → server → AI provider → subprocessor → storage → response.

2. Identify Personal Data Categories

Separate:

  • identity;
  • contact;
  • customer transaction;
  • financial;
  • location;
  • voice/image;
  • health;
  • criminal conviction; and
  • other special-category data.

3. Determine the Article 5 or Article 6 Processing Condition

International transfer cannot compensate for the absence of a lawful domestic processing basis.

4. Identify the Data Recipient

Determine the exact legal entity receiving the data.

“ChatGPT” or “Gemini” is a product name, not necessarily the contractual data recipient.

5. Review the DPA and Subprocessor List

Check:

  • storage country;
  • processing locations;
  • subprocessors;
  • retention;
  • deletion;
  • model training;
  • human access;
  • government-access provisions; and
  • onward transfers.

6. Select the Appropriate Article 9 Mechanism

Because the KVKK Authority currently has no published adequacy-country designation, most recurring commercial transfers will need an appropriate safeguard.

7. Consider the KVKK Standard Contract

Where the foreign AI provider is acting as processor, the controller-to-processor model may be relevant.

8. Notify the Authority

Where a Standard Contract is used, comply with the five-business-day notification requirement.

9. Update the Privacy Notice

Customers should be informed transparently that their information may be processed using AI service providers and transferred abroad, where applicable.

10. Introduce an Internal AI Usage Policy

Employees should be prohibited from entering customer data into unauthorised personal AI accounts.

11. Apply Data Minimisation

Send only the information genuinely required to generate the answer.

12. Introduce Special-Category Data Controls

Health, biometric, genetic and other special-category data should be technically detected and blocked or routed through specially approved workflows where necessary.

13. Control Retention

Prefer enterprise/API configurations offering limited or zero retention where available.

14. Maintain Logs and Access Controls

The company should be able to determine which customer information was sent to which AI system, when and for what purpose.


18. Example: A Turkish E-Commerce Company

Assume a Turkish e-commerce company receives 2,000 WhatsApp messages each day.

The company automatically sends every message to an overseas LLM API to:

  1. classify the customer’s request;
  2. generate a draft response; and
  3. identify whether the customer appears dissatisfied.

The customer messages contain names, phone numbers, order IDs and purchase histories.

This is not a rare or accidental transfer.

It is:

  • automated;
  • systematic;
  • recurring;
  • commercially organised; and
  • integral to the company’s customer-service process.

Accordingly, attempting to characterise the transfer as an occasional Article 9 exception would be difficult.

The company should instead establish an appropriate safeguard, determine the applicable controller/processor structure and modify its privacy and contractual architecture accordingly.


19. Example: A Clinic Using AI for WhatsApp

The risk is even higher for healthcare businesses.

Suppose:

A patient writes to a clinic’s WhatsApp number → the conversation is automatically transferred to Gemini or Claude → the AI determines the requested treatment → an appointment is automatically created.

The message may include:

  • diagnosis;
  • symptoms;
  • medication;
  • pregnancy information;
  • previous operations;
  • photographs;
  • laboratory results; and
  • treatment preferences.

The company is therefore processing and potentially transferring special-category health data.

In such a scenario, simply adding:

“Your data may be transferred abroad.”

to a privacy notice does not itself establish legal compliance.

The company must analyse Articles 6 and 9 together, adopt enhanced security measures and carefully evaluate whether every item of health information genuinely needs to be transmitted to the AI model.


20. The Most Important Distinction: “Training” Is Not “Transfer”

Companies frequently ask AI vendors:

“Do you train your model using our data?”

This is an important question, but it is not the first legal question under KVKK.

The correct sequence is:

Question 1: Are we processing personal data?

Question 2: Is that processing lawful under Articles 5 or 6?

Question 3: Are we making the data available abroad?

Question 4: If yes, which Article 9 transfer mechanism applies?

Question 5: What does the AI provider do with the data after receiving it?

Accordingly:

No training ≠ no processing.

and

No training ≠ no international transfer.

Enterprise AI products that do not train on customer data may considerably reduce compliance and confidentiality risk, but the cross-border transfer itself must still have a legal basis.


Conclusion: Sending WhatsApp Chats to AI Should Be Treated as a Data-Transfer Project, Not Just an AI Feature

For Turkish companies, integrating customer WhatsApp conversations with ChatGPT, Gemini, Claude or similar foreign generative AI systems should not be treated as merely installing another software tool.

Where identifiable customer information is transmitted to foreign AI infrastructure or a foreign recipient, the processing will generally require a cross-border data transfer analysis under Article 9 KVKK.

The compliance risk is particularly significant where:

  • customer messages are transferred automatically;
  • the transfer occurs every day;
  • health or other special-category data is involved;
  • employees use personal AI accounts;
  • provider subprocessors are unknown;
  • data retention cannot be controlled; or
  • the company relies solely on generic customer consent.

For recurring commercial AI systems, the more defensible approach is generally to build a structured architecture combining:

lawful processing basis + data minimisation + enterprise/API provider + processor agreement + KVKK Article 9 transfer mechanism + Standard Contract where appropriate + five-business-day notification + updated privacy documentation + technical and organisational safeguards.

In other words, the relevant question is no longer simply:

“Can our employees use ChatGPT to answer customers?”

The legally correct question is:

“Where does the customer’s personal data go when the employee presses Enter, who receives it, under what legal basis, and can we prove that the entire transfer chain complies with KVKK?”

For Turkish companies implementing AI-powered customer service, that question should be answered before the first WhatsApp message is connected to the model — not after a complaint or KVKK investigation begins.


Categories:

No Responses

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Our Client

    We provide a wide range of Turkish legal services to businesses and individuals throughout the world. Our services include comprehensive, updated legal information, professional legal consultation and representation

    Our Team

    .Our team includes business and trial lawyers experienced in a wide range of legal services across a broad spectrum of industries.

    Why Choose Us

    We will hold your hand. We will make every effort to ensure that you understand and are comfortable with each step of the legal process.

    Call Now Button