Your Data Is in Türkiye, But Your AI Is Abroad: Is Your SaaS Already Making an International Data Transfer Under the KVKK?

The Data Residency Trap for AI and SaaS Companies

A Turkish SaaS company stores all customer records on servers located in Istanbul. Its database, backups and application infrastructure are hosted in Türkiye. From a technical perspective, the company therefore considers itself to have a “Türkiye-only” data architecture.

There is, however, one additional component.

Whenever a user sends a message, the relevant text is transmitted through an API to an artificial intelligence model operating on servers in Frankfurt. The model generates an answer and sends the output back to the Turkish application. The company may use Google Cloud, Microsoft Azure, AWS infrastructure, OpenAI or another foreign AI provider.

The prompt may remain abroad only for a few seconds. The foreign provider may contractually promise not to use the data for model training. The permanent customer database may never leave Türkiye.

Does this mean there is no international transfer of personal data?

No.

Under Turkish data protection law, the location of the primary database is not the decisive factor. If personal data are transmitted to, processed by, or otherwise made accessible to a controller or processor located abroad, an international data transfer may occur even if the master copy of the data remains physically stored in Türkiye.

This distinction has become particularly important for AI startups, healthcare platforms, CRM providers, WhatsApp automation systems, legal technology companies and SaaS businesses using foreign AI APIs.

The good news is equally important: using an AI service located abroad is not automatically unlawful under the KVKK.

The real question is whether the international transfer architecture has been established in accordance with Article 9 of Law No. 6698.


1. “Stored in Türkiye” Does Not Mean “Processed Only in Türkiye”

One of the most common compliance mistakes is to equate data storage with data processing.

Under the Personal Data Protection Law No. 6698 (“KVKK”), processing is broader than storage. It includes collection, recording, storage, alteration, disclosure, transfer, retrieval and making personal data available.

The rules on transfers abroad take an equally functional approach.

The Turkish international transfer regime treats personal data as transferred abroad where data subject to the KVKK are transmitted to a controller or processor abroad or otherwise made accessible to such a recipient.1

Therefore, consider this architecture:

Patient → Turkish SaaS application → Turkish database → AI API in Frankfurt → AI-generated answer → Turkish SaaS application

Even if the patient’s complete file remains in Istanbul, the part of the conversation sent to Frankfurt is processed outside Türkiye.

That API call is the legally relevant event.

The question is therefore not:

“Where is our database?”

The better question is:

“Can any personal data handled by our system be transmitted to or accessed by a controller or processor outside Türkiye?”

This approach follows the structure of the current transfer regime and the broad concept of processing under the KVKK.


2. A Five-Second AI API Call Can Still Be an International Transfer

Some startups assume there is no transfer if the foreign AI provider does not permanently store the prompt.

This is risky.

International transfer does not depend exclusively on permanent storage.

Imagine a Turkish healthcare SaaS platform receiving this WhatsApp message:

“I had a rhinoplasty three months ago. I am still experiencing breathing difficulties. My name is A.B. and I would like an appointment next Tuesday.”

If that message is transmitted to an AI model in Germany to prepare a response, the system may process:

the patient’s identity, contact information, medical information, appointment information and potentially other contextual information.

The fact that the AI provider processes the message for ten seconds rather than ten years does not, by itself, remove the transaction from Article 9.

Likewise, statements such as “we do not train the model on your data” and “zero-retention API” may significantly improve the risk profile, but they do not necessarily mean that no international transfer has occurred.

Retention and transfer are separate legal questions.


3. Frankfurt Is Still Abroad for KVKK Purposes

Another frequent misunderstanding is:

“The server is in Frankfurt, not the United States, so there is no KVKK problem.”

Germany may provide a sophisticated GDPR-based data protection environment, but Frankfurt is nevertheless located outside Türkiye.

Article 9 of the KVKK introduced a new international-transfer framework effective from 1 June 2024. Personal data may first be transferred where an Article 5 or Article 6 processing condition exists and the Personal Data Protection Board has adopted an adequacy decision concerning the relevant country, sector or international organisation.

This creates an important practical issue.

As of August 2026, the Turkish Personal Data Protection Authority states that the Board has not yet designated any country as providing adequate protection under this mechanism.

Therefore, a Turkish company should not simply argue:

“Germany is subject to the GDPR, therefore Germany is automatically an adequate country under the KVKK.”

That conclusion does not follow from Turkish law.

The legal transfer mechanism must still be examined under Article 9.


4. The 2024 KVKK Reform Changed the International Transfer System

The amendment introduced by Law No. 7499 significantly modernised Article 9.

Under the current model, the transfer analysis broadly operates in three levels.

First, the company should determine whether there is an applicable adequacy decision.

Second, if there is no adequacy decision, the transfer may take place where the relevant conditions under Articles 5 or 6 exist, data subjects are able to exercise their rights and access effective legal remedies, and an appropriate safeguard under Article 9(4) is established.

These safeguards include binding corporate rules approved by the Board, the standard contracts published by the Board, certain agreements involving public authorities, and written undertakings approved by the Board.

Third, where neither adequacy nor an appropriate safeguard is available, Article 9 contains limited derogations for incidental transfers.

This third category should not normally be treated as the default architecture for a SaaS platform making thousands of API requests every day.

The Authority expressly describes incidental transfers as transfers that are not regular, continuous or systematic and that occur only rarely.

Accordingly, a production AI API continuously processing customer communications is fundamentally different from a genuinely exceptional or occasional transfer.


5. The Most Important Rule: Article 9 Is Not Enough by Itself

A compliant international transfer generally requires two different legal questions to be answered.

Question One: Is the underlying processing lawful?

The processing must satisfy the principles of Article 4 and generally rely on an appropriate legal basis under Article 5 or, where special categories of personal data are involved, Article 6.

Question Two: Is the international transfer itself lawful?

The transfer must separately fit within Article 9.

This distinction is especially important for startups.

A company cannot repair unlawful data collection merely by signing an international transfer contract.

Likewise, a company may have a perfectly legitimate reason for processing customer information but still violate the KVKK if it routinely sends that information abroad without establishing the appropriate Article 9 transfer mechanism.


6. Standard Contracts Have Become the Most Practical Solution for Many SaaS Companies

For many private-sector AI and SaaS structures, the most practical Article 9 mechanism is likely to be the standard contract published by the Turkish Personal Data Protection Board.

The Board has published four different models:

Data ExporterForeign Data ImporterRelevant Model
ControllerControllerStandard Contract No. 1
ControllerProcessorStandard Contract No. 2
ProcessorProcessorStandard Contract No. 3
ProcessorControllerStandard Contract No. 4

This role classification matters enormously in SaaS projects.

Suppose a clinic determines why patient information is processed, while a Turkish SaaS company processes messages exclusively on behalf of the clinic. The SaaS company then sends necessary message content to a foreign AI provider acting as a subprocessor.

The architecture could potentially be characterised as:

Clinic: Data Controller
Turkish SaaS: Data Processor
Foreign AI Provider: Subprocessor / Data Processor

In that scenario, the foreign transfer may require analysis under the processor-to-processor standard contract.

However, contractual labels alone are not decisive.

If the SaaS company independently determines additional purposes for the data—for example, using conversations to improve its own models, create behavioural profiles or develop unrelated products—its legal role may become more complex.

Controller and processor roles should therefore be mapped according to the actual purposes and means of processing, not merely according to what the commercial contract calls the parties.


7. Signing the Standard Contract Is Not the End of the Process

The standard contract must also be notified to the Turkish Personal Data Protection Authority.

Article 9(5) requires notification within five business days following execution.

The Authority has created an electronic Standard Contract Notification Module for this purpose.

Recent guidance from the Authority is particularly important for startups negotiating contracts with multinational technology providers.

The Authority states that the Turkish standard-contract text should not generally be altered, except for provisions expressly designed as optional or alternative provisions. It has also emphasised proper execution by authorised representatives, signatures on the Turkish version where bilingual versions are used, evidence of signatory authority and timely notification.

This creates a practical negotiation issue.

A foreign AI provider’s ordinary GDPR Data Processing Addendum or EU Standard Contractual Clauses do not automatically replace the Turkish KVKK standard contract.

A Turkish company should therefore review the vendor’s willingness and operational ability to execute the applicable Turkish transfer instrument.


8. “We Obtained Consent” Is Not Always a Sustainable SaaS Strategy

Another tempting approach is to place the following sentence in a privacy policy:

“By using our service, you consent to your data being transferred abroad.”

For continuous commercial AI processing, relying on this alone can be problematic.

Under the current Article 9 framework, explicit consent appears among the derogations applicable where adequacy and appropriate safeguards cannot be established, but that mechanism is expressly linked to incidental transfers and requires the person to be informed about possible risks.

A permanent SaaS architecture in which every customer message is automatically routed to an overseas LLM is difficult to describe as occasional or incidental.

In addition, Turkish data protection practice has consistently required explicit consent to be specific, informed and freely given. Consent should not be unnecessarily bundled into general terms where another lawful basis applies.

For scalable SaaS operations, a structured transfer mechanism is therefore often more robust than attempting to make every technical operation dependent on end-user consent.


9. Health Data Changes the Risk Significantly

The analysis becomes considerably more sensitive when the SaaS product is used by clinics, hospitals, dentists, aesthetic centres, psychologists or medical tourism companies.

Health information is a special category of personal data under Article 6 of the KVKK.

A patient message such as:

“I was diagnosed with diabetes and I need to change my appointment because my blood sugar is unstable.”

is not merely ordinary CRM data.

It contains health information.

Article 6 was also amended in 2024 and now provides several legal grounds for processing special-category personal data. One of these concerns processing necessary for public health, preventive medicine, medical diagnosis, treatment and care services and the planning, management and financing of healthcare services by persons subject to confidentiality obligations or competent public institutions.

For an AI SaaS provider, however, the existence of health data should trigger a much more detailed analysis of controller/processor roles, purpose limitation, confidentiality, access controls, data minimisation and the additional safeguards applicable to special-category data.

Sending entire patient conversations to an AI system simply because doing so is technically convenient may fail the necessity and proportionality analysis.


10. Pseudonymisation Can Help — but It Does Not Automatically Eliminate Article 9

One of the strongest architectural measures is to minimise the data sent to the model.

Instead of sending:

“Ahmet Yılmaz, Turkish ID No. XXXXX, underwent hair transplantation at Clinic X on 12 June and is complaining of bleeding.”

the system could transform the prompt into something such as:

“Patient #5482 underwent a hair transplantation procedure and reports post-operative bleeding.”

Where the receiving system cannot identify the person, the compliance risk can be significantly reduced.

But there is an important distinction.

Pseudonymised data remain personal data if the individual can still be identified through additional information.

Only genuinely anonymised information that can no longer be linked to an identified or identifiable individual falls outside the definition of personal data.

Consequently, replacing a patient’s name with an internal customer ID should not automatically be treated as eliminating the transfer.

The technical architecture should be tested realistically for re-identification.


11. Encryption Does Not Mean There Is No Transfer

Encryption is essential, but companies should avoid another common argument:

“The API traffic is encrypted, so technically no personal data are transferred.”

If the foreign AI provider must decrypt the content in order to process the prompt, the provider receives access to the personal data.

TLS encryption during transit protects the communication channel; it does not change the legal character of the processing performed once the receiving system obtains the data.

Encryption therefore operates primarily as a security measure, not as a substitute for a lawful international transfer mechanism.


12. The Hidden Risk Is Often Not the AI Model — It Is the Subprocessor Chain

A startup may select “Frankfurt” as the model region and assume the entire processing operation is confined to Germany.

That assumption should be verified contractually and technically.

AI infrastructure may involve model providers, cloud infrastructure providers, observability systems, logging services, content-moderation tools, technical support personnel, security providers, backup infrastructure and other subprocessors.

Article 9 expressly requires the applicable safeguards to continue to apply to onward transfers.

Therefore, a compliance review should not stop at:

Türkiye → Frankfurt

It should examine the complete chain:

Turkish controller → Turkish SaaS processor → foreign AI provider → cloud provider → subprocessor → support/access locations

A carefully drafted architecture on paper can become non-compliant if a downstream provider is able to access identifiable customer information from another jurisdiction.


13. A Practical Example

Consider a Turkish startup providing an AI appointment assistant for cosmetic surgery clinics.

Customer messages are received through WhatsApp.

The startup stores all conversations in an Istanbul data centre.

To generate responses, the relevant conversation is sent to an LLM hosted in Frankfurt.

The LLM returns a response.

The result is then stored in Istanbul.

The founders say:

“Nothing is stored abroad, so we are KVKK compliant.”

That conclusion is incomplete.

The correct legal analysis is approximately as follows.

The patient conversation contains personal data and may contain special-category health data. Sending the prompt to the Frankfurt-hosted model constitutes processing outside Türkiye and may constitute an international transfer. Türkiye currently has no general adequacy designation covering Germany under the Article 9 mechanism. An Article 5 or Article 6 legal basis must first exist for the underlying processing. The transfer must then be supported by an appropriate Article 9 mechanism, most commonly a relevant Turkish standard contract depending on the parties’ controller/processor roles. The standard contract must be notified within five business days. The privacy notice should accurately disclose recipients and overseas transfer purposes. Data minimisation and special-category safeguards must be implemented. The subprocessor chain and foreign support access must also be reviewed.

If these steps are correctly implemented, the fact that the AI operates abroad does not, by itself, make the service unlawful.


14. What Should an AI or SaaS Startup Do Before Launch?

A startup designing a Turkish product around OpenAI, Azure, AWS, Google Cloud or another overseas AI infrastructure should complete at least the following compliance work before production deployment:

  • Map every location where customer data are stored, transmitted, logged, backed up or remotely accessible; determine the controller, processor and subprocessor status of each party; identify an Article 5 or Article 6 basis for every relevant processing operation; determine which Article 9 transfer mechanism applies; execute the correct Turkish standard contract where appropriate and notify the Authority within five business days; review the provider’s DPA, subprocessors, retention policy, model-training terms and international access locations; update privacy notices and, where applicable, VERBIS records; minimise the information included in AI prompts; pseudonymise or anonymise information before API transmission where technically possible; restrict AI processing of special-category information; define retention and deletion periods; apply encryption, access-control, logging and audit measures; prohibit uncontrolled use of consumer AI tools by employees; and document the entire international-transfer decision in a written KVKK compliance file.

The Turkish Data Protection Authority has increasingly addressed generative AI as a distinct compliance issue and has published specific guidance on generative AI and personal-data protection as well as workplace use of generative AI tools.


15. Administrative Risk Should Not Be Underestimated

Failure to establish a compliant transfer architecture may create exposure under several different provisions of the KVKK rather than a single “foreign transfer fine.”

Depending on the circumstances, issues may arise concerning transparency, data security, Board decisions, VERBIS declarations and the notification of standard contracts.

The KVKK expressly provides an administrative fine for failure to notify a standard contract under Article 9(5). The statutory base range introduced in 2024 was TRY 50,000 to TRY 1,000,000, and administrative fines are adjusted through annual revaluation.2

For 2026, the Authority’s published table shows the revalued range for failure to fulfil the Article 9(5) notification obligation as approximately TRY 90,308 to TRY 1,806,177.

More importantly, Article 15 gives the Board authority in appropriate circumstances to order the suspension of processing or international transfers where serious and difficult-to-remedy harm may arise and there is an explicit violation of the law.

For a technology company whose entire product depends on a foreign AI API, suspension of the data flow may represent a considerably greater commercial risk than an administrative fine.


Conclusion: Data Residency Is Not the Same as KVKK Compliance

The statement:

“Our data are stored in Türkiye.”

is useful, but it does not answer the international-transfer question.

A more accurate compliance question is:

“Does any person or system outside Türkiye receive, process or gain access to identifiable personal data generated by our service?”

If the answer is yes, Article 9 must be considered.

A Turkish database combined with a foreign AI inference layer can therefore constitute an international transfer architecture.

This architecture is not automatically prohibited.

But it must be deliberately structured.

For most AI and SaaS businesses, compliance will depend on correctly identifying the controller and processor relationships, establishing an Article 5 or Article 6 processing condition, implementing an Article 9 transfer mechanism, executing and notifying the appropriate standard contract, controlling subprocessors, updating privacy documentation and applying serious technical data-minimisation measures.

The most dangerous approach is therefore not using foreign AI.

It is building the entire business on foreign AI while assuming that “the database is in Türkiye” solves the KVKK problem.


Categories:

No Responses

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Our Client

    We provide a wide range of Turkish legal services to businesses and individuals throughout the world. Our services include comprehensive, updated legal information, professional legal consultation and representation

    Our Team

    .Our team includes business and trial lawyers experienced in a wide range of legal services across a broad spectrum of industries.

    Why Choose Us

    We will hold your hand. We will make every effort to ensure that you understand and are comfortable with each step of the legal process.

    Call Now Button