Before You Paste It into ChatGPT: A Practical KVKK Compliance Guide for Companies Using Generative AI in Turkey

Generative artificial intelligence tools such as ChatGPT, Gemini, Claude, Microsoft Copilot and similar large language model-based systems are rapidly becoming part of ordinary corporate workflows. Employees use them to summarise documents, draft emails, analyse contracts, prepare reports, translate correspondence, review CVs, generate marketing materials, write software code and even respond to customers.

From a Turkish data protection perspective, however, the main legal question is not whether a company “uses artificial intelligence.” The critical question is what information is entered into the AI system, why it is processed, where it is transferred, who can access it, how long it is retained and which party determines the purposes and means of that processing.

Turkey’s Personal Data Protection Authority (“KVKK Authority”) has increasingly focused on artificial intelligence. Its November 2025 Guide on Generative Artificial Intelligence and the Protection of Personal Data specifically evaluates generative AI under Law No. 6698 on the Protection of Personal Data (“KVKK”), and in March 2026 the Authority published a separate document on the use of generative AI tools in workplaces. The latter expressly highlights the risks created when employees use publicly available third-party AI tools without a clearly defined corporate strategy or policy.

For companies operating in Turkey, this means that “employees are only using ChatGPT” is no longer an adequate compliance position. AI use should be treated as a separate data-processing activity within the company’s KVKK governance framework.

1. Why Using ChatGPT Can Become a KVKK Issue

Consider a simple example.

A customer sends a complaint containing their name, mobile number, order history and medical information to a company. An employee copies the complaint into an AI tool and asks:

“Summarise this complaint and draft a response.”

Although the employee may consider this merely a productivity task, several personal data processing activities may have occurred. The information has been collected, transmitted to another technical environment, analysed, potentially stored in logs and used to generate a new output.

The KVKK Authority has expressly recognised that AI chatbots may involve extensive collection and processing of personal data and has published a specific information note using ChatGPT as an example.

The same issue arises when employees upload:

  • employment contracts,
  • customer correspondence,
  • CVs,
  • court documents,
  • medical reports,
  • identification documents,
  • meeting transcripts,
  • call-centre records,
  • payroll files,
  • internal investigation reports,
  • customer databases,
  • screenshots containing personal information.

The fact that the purpose is only to obtain a summary or improve a text does not take the activity outside the KVKK.

2. The First Step: Map the AI Data Flow

Before approving an AI tool for corporate use, the company should understand its actual data flow.

A useful compliance assessment begins with practical questions:

What types of personal data will employees enter into the AI system? Will customer, employee or supplier information be processed? Can documents containing special categories of personal data be uploaded? In which country are the provider’s servers located? Are prompts retained? Can the provider use prompts or outputs for service improvement or model training? Are subprocessors involved? Can administrators access employee conversations? What happens when the corporate account is terminated? Can data be deleted?

This analysis should not be limited to the AI provider’s marketing page. The company should review the applicable enterprise terms, privacy documentation, data-processing terms, security documentation, retention settings and international transfer structure.

The resulting AI processing activities should then be reflected, where applicable, in the company’s personal data processing inventory, retention structure, privacy notices, contractual framework and VERBİS declarations.

The Authority has consistently underlined that KVKK compliance involves, where applicable, preparation of a personal data processing inventory and retention/destruction framework alongside technical and administrative security measures.

3. Who Is the Data Controller: The Company or the AI Provider?

This is one of the most important questions.

Under Article 3 of the KVKK, the data controller is the natural or legal person who determines the purposes and means of processing personal data. The data processor, by contrast, processes personal data on behalf of the controller under the authority given by the controller. The KVKK Authority emphasises that the decisive issue is essentially who determines “why” and “how” the personal data will be processed.

If a company decides to use an AI system to analyse customer messages in order to improve customer support, the company will normally remain the data controller in relation to its own customer-processing purpose.

The AI provider may act as a data processor for certain operations if it processes the information exclusively on behalf of the company and according to its instructions.

However, the relationship is not automatically that simple.

If the AI provider independently determines additional purposes — for example, using certain data for its own service development, security, analytics or other independent activities — it may potentially act as a separate data controller for those activities.

Therefore, companies should not rely solely on labels such as “processor” contained in a contract. The real allocation of decision-making power must be examined.

4. Every AI Use Case Needs a Lawful Basis

There is no special exemption under Turkish law simply because personal data is processed through artificial intelligence.

The KVKK Authority’s 2025 Generative AI Guide expressly states that personal data processing through generative AI must rely on one of the processing conditions under Article 5 or, for special categories of personal data, Article 6. The technology used does not itself create an independent lawful basis.

Depending on the circumstances, a company may rely on grounds such as necessity for the performance of a contract, compliance with a legal obligation, establishment or protection of a right, legitimate interests or explicit consent.

The correct lawful basis must be determined before the data is entered into the AI system.

For example, imagine an employer using an AI tool to summarise an employee’s performance records. Even if the employer has a legitimate reason to process those records internally, this does not automatically mean that transferring the full file to an external generative AI provider is necessary and proportionate.

The company must separately assess whether using that external AI service is genuinely necessary for the stated purpose.

This is where many corporate implementations fail. They establish a lawful basis for the original processing but do not examine whether the subsequent disclosure to the AI service is justified.

5. Data Minimisation Is Probably the Most Important AI Compliance Rule

Article 4 of the KVKK requires personal data to be processed lawfully and fairly, for specified, explicit and legitimate purposes, and to be relevant, limited and proportionate to those purposes. Data must also be accurate where necessary and retained only for the required period. The KVKK Authority confirms that these principles apply equally to generative AI systems.

For corporate AI use, the principle of proportionality should translate into a simple operational rule:

Do not give an AI tool more information than it actually needs.

If an employee wants an AI system to improve the wording of a customer email, there is usually no reason to include the customer’s full name, Turkish identity number, address, account number or other identifying details.

Instead of writing:

“Prepare a response to Ahmet Yılmaz, T.C. No. 123…, who lives at …”

the company should, where possible, provide:

“Prepare a response to a customer who claims that the delivery was delayed by seven days.”

Names, identification numbers, account numbers, medical details and other identifiers should be removed, masked or pseudonymised before information is entered into an external AI system.

True anonymisation is even stronger where practicable, because information that can no longer be associated with an identifiable person falls outside the personal data framework.

6. Special Categories of Personal Data Require a Much Higher Level of Caution

Companies in healthcare, insurance, banking, HR, legal services and other data-intensive industries face greater risks because employees may handle special categories of personal data.

Article 6 covers information such as health data, biometric and genetic data, criminal conviction and security-measure information, political opinions, religious or philosophical beliefs and certain other sensitive categories.

Article 6 was materially amended in 2024, expanding and restructuring the lawful grounds on which special categories may be processed. The KVKK Authority subsequently issued a dedicated guide explaining the amended regime.

The existence of a lawful ground does not mean that uploading such data to a general-purpose AI service is automatically proportionate.

A hospital employee, for instance, should not simply upload a patient’s full medical record into a publicly available AI chatbot and ask for a summary.

Likewise, an HR department should exercise extreme caution before uploading disability records, health reports, biometric information or criminal-record information for AI-assisted candidate evaluation.

Where sensitive data must genuinely be processed through AI, companies should consider dedicated enterprise environments, contractual restrictions, strict access controls, data masking and additional technical and administrative safeguards.

7. International Data Transfers May Be the Biggest Hidden Risk

Perhaps the most significant issue for Turkish companies using global AI services is international data transfer.

An employee sitting in Istanbul may type personal information into an AI interface on a computer in Istanbul, but the underlying processing infrastructure may be located in another jurisdiction.

That may constitute a transfer of personal data abroad under Article 9 of the KVKK.

Turkey substantially amended its international transfer regime in 2024. Under the current framework, transfers may be based on an adequacy decision or, where the relevant requirements are satisfied, appropriate safeguards such as standard contracts, binding corporate rules or certain undertakings approved by the Board. Exceptional transfer grounds exist separately and are intended for specific circumstances rather than routine structural transfers.

For many commercial relationships with foreign cloud or AI providers, standard contracts are therefore particularly important.

The Authority has issued four different standard contract models depending on whether the transfer occurs from controller to controller, controller to processor, processor to processor or processor to controller.

If a standard contract mechanism is used, the signed contract must be notified to the KVKK Authority within five business days. The Authority has also established an electronic Standard Contract Notification Module for this purpose.

This means that merely signing an ordinary “Data Processing Agreement” drafted under GDPR standards may not, by itself, satisfy the Turkish international transfer regime.

8. The Company Should Sign a Proper AI/Data Processing Agreement

Before permitting systematic corporate use, companies should review whether their contract with the AI provider adequately regulates personal data processing.

A robust contractual structure should address matters such as the scope and purpose of processing, categories of data, confidentiality, security obligations, authorised personnel, subprocessors, locations of processing, international transfers, data retention, deletion, incident notification, audit rights and termination.

The agreement should also clarify one particularly important AI issue:

Can corporate prompts, uploaded documents or generated outputs be used to train or improve the provider’s general models?

The answer should never be assumed.

Different providers, account types and enterprise products can operate under different contractual and technical settings. Companies should therefore verify the terms applicable to the specific service being purchased rather than assuming that consumer and enterprise versions operate identically.

Where possible, organisations handling material amounts of personal data should prefer enterprise solutions that provide contractual confidentiality protections, administrative control, retention options and clear restrictions regarding secondary use of corporate data.

9. Companies Need an Internal Generative AI Policy

One of the most underestimated risks is not the officially approved AI system.

It is Shadow AI — employees independently creating accounts and entering corporate information into public AI services without the company’s knowledge.

The KVKK Authority’s March 2026 workplace document specifically points to the difficulty of managing generative AI where usage develops through employees’ individual choices rather than within a clearly defined corporate strategy, policy or guidance framework.

Accordingly, companies should establish an internal Generative AI Use Policy.

The policy should explain which AI tools are authorised, what categories of information may be entered, what information is prohibited, whether customer or employee data may be processed, how sensitive documents must be masked, whether employees may upload entire files and who must approve new AI tools.

Rather than imposing an unrealistic total ban, many organisations will obtain better compliance by establishing a controlled “approved tools” environment.

Employees should receive practical examples.

For instance:

A sales employee may ask AI to improve the tone of a generic sales email.

An employee should normally not upload an Excel file containing 5,000 customer names and phone numbers simply to create a marketing summary.

A lawyer within a company should not copy an entire confidential litigation file containing third-party data into an unapproved public chatbot merely to obtain a case summary.

A doctor or clinic employee should not enter identifiable patient records into a general AI tool without a specifically assessed legal and technical structure.

10. Transparency Obligations Must Also Cover AI Processing

Article 10 of the KVKK requires data controllers to provide relevant information to data subjects concerning their processing activities.

If a company begins using AI in a way that materially changes how customer, employee or applicant data is processed, existing privacy notices should be reviewed.

A privacy notice may need to explain, depending on the circumstances, the purposes of AI-assisted processing, categories of recipients, applicable legal grounds and whether personal data may be transferred abroad.

Transparency becomes particularly important where AI is used to evaluate individuals rather than merely to assist with drafting.

For example, using AI to summarise a customer complaint poses one level of risk.

Using AI to calculate whether the same customer should receive credit, whether an applicant should be hired or whether an employee should be dismissed creates substantially greater legal concerns.

11. Be Extremely Careful with AI-Based Profiling and Automated Decisions

Article 11 of the KVKK gives individuals several rights regarding their personal data, including the right to object where the analysis of their data exclusively through automated systems produces a result against them.

The KVKK Authority’s Generative AI Guide confirms that the architecture of generative AI does not eliminate these rights and notes that these rights become particularly important when generative AI is used in decision-making processes.

Companies should therefore exercise particular caution when AI affects:

recruitment,
employee performance evaluations,
creditworthiness,
insurance assessments,
fraud classifications,
customer blacklists,
pricing decisions,
access to services,
termination of contracts.

Human review should be meaningful rather than cosmetic.

An employee merely clicking “approve” on whatever the AI recommends will not necessarily solve the underlying risk.

12. Security Obligations Continue Even When the Data Is Processed by an AI Provider

Article 12 requires the data controller to take all necessary technical and administrative measures to prevent unlawful processing, prevent unlawful access and ensure the secure storage of personal data. Where processing is conducted by another person on behalf of the controller, the controller and processor have responsibilities regarding those security measures.

For AI systems, reasonable measures may include enterprise accounts rather than employees’ personal accounts, multi-factor authentication, role-based access controls, data-loss-prevention rules, encryption, access logging, monitoring, secure API management, restrictions on plug-ins and integrations, separation of test and production environments and controls preventing employees from uploading prohibited categories of data.

Companies should also prepare an AI-specific incident response scenario.

For example, what happens if an employee accidentally uploads a database containing thousands of customer records into an unauthorised AI service?

The issue should be immediately escalated to the company’s data protection and information security teams so that deletion possibilities, exposure, transfer circumstances and potential breach-notification obligations can be assessed.

13. Retention and Deletion Rules Must Include Prompts and AI Logs

Another common misconception is that once the chatbot window is closed, the information disappears.

Companies should determine whether prompts, uploaded documents, generated outputs, audit logs and API records are retained, and for how long.

Retention should correspond to a defined purpose.

If information is no longer required for that purpose and no legal retention obligation applies, the company should ensure that deletion, destruction or anonymisation procedures can operate effectively.

This requirement should also be reflected contractually with the AI provider.

A company that cannot determine whether its supplier is capable of deleting customer information may later have difficulty responding to a valid data subject request.

14. A Practical Corporate KVKK–AI Compliance Model

A compliant company does not necessarily need to prohibit artificial intelligence.

It needs to govern it.

A practical implementation model can be built around the following framework:

  1. Identify every AI tool currently used by employees.
  2. Classify each use case according to the personal data involved.
  3. Determine the controller–processor relationship.
  4. Establish the Article 5 or Article 6 lawful basis.
  5. Apply data minimisation and masking.
  6. Identify whether information is transferred abroad.
  7. Establish the appropriate Article 9 transfer mechanism.
  8. Execute the necessary data-processing and confidentiality agreements.
  9. Review privacy notices and the personal data processing inventory.
  10. Adopt an internal generative AI policy.
  11. Train employees on permitted and prohibited AI use.
  12. Establish technical controls to prevent unauthorised uploads.
  13. Define retention and deletion procedures.
  14. Create procedures for data subject requests.
  15. Periodically audit AI providers and corporate AI practices.

This should not be a one-time exercise. AI tools change rapidly. Providers alter their infrastructure, subprocessors, retention mechanisms, functionality and contractual terms.

Companies should therefore reassess significant AI systems periodically and whenever a material new feature is introduced.

15. Does the Company Need to Register the AI Activity with VERBİS?

Using ChatGPT does not create a separate and automatic obligation to register with VERBİS.

VERBİS obligations depend on whether the relevant company falls within the registration requirements and applicable exemptions.

However, if a company is already subject to VERBİS and AI changes its processing activities, data categories, purposes, recipients, retention periods or foreign transfer practices, its processing inventory and, where necessary, VERBİS declarations should be reviewed.

The exemption thresholds have also evolved. The Authority announced in 2025 a new exemption for certain very small controllers whose main activity involves special categories of personal data, while the broader employee and financial-balance-sheet criteria remain relevant to the general exemption framework.

16. The Biggest Corporate Mistake: Treating AI as an IT Procurement Issue Only

Generative AI implementation is often managed entirely by IT departments.

That approach is insufficient.

AI procurement potentially involves:

data protection law, confidentiality, employment law, intellectual property, trade secrets, cybersecurity, consumer law and sector-specific regulations.

Legal, information security, procurement and operational teams should therefore review high-risk AI solutions together.

This is especially important where AI systems are connected directly to CRM systems, email accounts, HR databases, hospital systems, customer service platforms or internal document repositories.

The legal risk changes significantly when an employee manually asks a chatbot to rewrite a generic email compared with an AI agent that automatically reads thousands of customer records and takes actions on their behalf.

Conclusion: Companies Should Control the Data Before They Control the AI

The central KVKK issue surrounding ChatGPT and similar systems is ultimately straightforward:

Artificial intelligence does not suspend existing data protection obligations.

Before employees upload customer files, employee records, medical documents or other identifiable information into an AI service, the company should know why the data is being processed, whether the processing is necessary, which legal basis applies, who receives the information, whether the data leaves Turkey, what contractual protections exist and whether the information can later be deleted.

The KVKK Authority’s recent guidance shows an increasingly clear regulatory direction: generative AI should be transparent, accountable, secure and governed throughout its lifecycle. The Authority also specifically recognises the difficulty created by uncontrolled employee use of publicly available AI services.

The safest corporate approach is therefore not simply to tell employees “do not use AI.”

It is to establish a system under which employees know which AI they may use, what they may upload, what they must never upload and what legal safeguards must exist before personal data is processed.

For Turkish companies, an effective AI compliance programme should ultimately combine KVKK data mapping, an internal AI policy, data minimisation, supplier due diligence, appropriate data-processing agreements, international transfer compliance, employee training and continuous technical supervision..

Categories:

No Responses

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Our Client

    We provide a wide range of Turkish legal services to businesses and individuals throughout the world. Our services include comprehensive, updated legal information, professional legal consultation and representation

    Our Team

    .Our team includes business and trial lawyers experienced in a wide range of legal services across a broad spectrum of industries.

    Why Choose Us

    We will hold your hand. We will make every effort to ensure that you understand and are comfortable with each step of the legal process.

    Call Now Button