AI for Business
Turkey's Data Protection Authority Just Published Generative AI Guidance: 10 Rules for Businesses Operating There
In November 2025, Turkey's data protection authority quietly did something that a lot of businesses operating in the country hadn't planned for: it published a 64-page official guidance document on generative AI and personal data. The authority is called KVKK (Kişisel Verileri Koruma Kurumu, the ...

In November 2025, Turkey's data protection authority quietly did something that a lot of businesses operating in the country hadn't planned for: it published a 64-page official guidance document on generative AI and personal data. The authority is called KVKK (Kişisel Verileri Koruma Kurumu, the Turkish Personal Data Protection Authority), and it enforces Turkey's Law No. 6698, the country's own data protection statute. It is not GDPR, it is not a global rule, and it does not apply just because you use ChatGPT somewhere in the world. It applies if your business processes personal data connected to Turkey, whether that's Turkish employees, Turkish customers, or a Turkish entity using AI tools day to day.
If that describes you, whether you're a foreign company with a Turkish subsidiary, an agency serving Turkish clients, or a founder building toward the Turkish market, this guidance is now the closest thing Turkey has to a rulebook for AI at work. It reads like it was written by lawyers, for lawyers. So we read the whole thing and turned it into 10 rules a business owner can actually act on, plus the one scenario that trips up almost everyone.
What KVKK is, and who this guidance is actually for
KVKK is Turkey's national data protection regulator, similar in role to a European DPA but operating under its own law rather than the EU's GDPR. Its November 2025 guidance, titled the "Generative AI and Personal Data Protection Guide," targets anyone using generative AI tools while handling personal data tied to Turkey, from an employee pasting a client email into ChatGPT to a company running its own AI-powered chatbot for Turkish customers.
Technically the guidance is advisory rather than a new law. But it interprets a binding statute, so practices that contradict it can still result in administrative fines under Law No. 6698. One detail is worth noting if you also operate in Europe: KVKK built this guidance on references to the European Data Protection Board (EDPB), France's CNIL, and the UK's ICO. In other words, the Turkish framework is deliberately aligned with European norms, so compliance work you do here tends to carry over if you also serve EU markets, and vice versa.
On penalties, the numbers are current as of 2026: violations of data security obligations can draw fines exceeding 17 million Turkish lira, and violations of the disclosure (transparency) obligation can reach 1.7 million lira. To be fair, as of this writing there's no publicly reported KVKK enforcement action citing "ChatGPT use" by name. But the framework is now in place, and once the first precedent case lands, "we didn't know" won't be a viable defense.
10 rules for businesses operating in Turkey
These 10 rules are the practical core of KVKK's 15-question guidance document. Each one starts with what you need to do, followed by why the regulator frames it that way.
1. Using AI doesn't exempt you from Turkish data protection law
Turkey's Law No. 6698 is technology-neutral, and generative AI gets no special carve-out. The guidance's own example makes this concrete: a company that has an AI tool summarize internal training videos, videos that include participants' names and faces, is processing personal data, full stop. Only genuinely data-free uses, like asking a model to design a generic sale banner, fall outside the law's scope.
2. You're the responsible party, not the AI vendor
"OpenAI built the model, so any problem is on them" doesn't hold up. The guidance's clearest example involves HR: a company that uses an off-the-shelf model to screen CVs is classified as the data controller, because it decides what data gets uploaded and how the output gets used. Whoever actually controls the "why" and "how" of the processing carries the legal responsibility, regardless of what the vendor contract says. Whoever answers that question is accountable.
3. Vague purposes like "to improve our systems" won't cut it
The guidance explicitly rejects broad, catch-all purposes such as "for use in our AI systems" or "to enhance our database," calling them a violation of the purpose limitation principle. Every use case needs its own clear description. "Responding to customer support tickets" is one purpose. "Using those same conversations to train a model" is a completely different one, and it needs its own separate legal justification.
4. Consent for using AI doesn't cover training AI, and vice versa
Here's a line taken almost directly from the guidance: explicit consent obtained for using generative AI does not extend to consent for developing or training it. Your chatbot processing a customer's message to answer their question might be justified under contract performance. Using those same conversations to train your model or personalize ads later requires a separate legal basis entirely. Bundling both into one "I agree" checkbox is, per the guidance, a misuse of consent.
5. Publicly available data isn't automatically fair game
Another near-verbatim line from the guidance: data that anyone can freely access does not mean data that anyone can freely process. Scraping social media profiles, websites, or public directories to train a model, or to enrich a customer list, can't be justified just because the data was sitting out in the open. This also applies if you're buying a pre-scraped dataset from a data broker serving the Turkish market; you should be asking where it came from.
6. Typing data into ChatGPT counts as an international data transfer
ChatGPT, Claude, Gemini, Copilot: their servers sit outside Turkey. Under Article 9 of Turkey's data protection law, entering personal data into any of these tools counts as a cross-border data transfer, which in practice means signing a standard contractual clause and notifying the authority. Skipping just that notification step can draw fines up to roughly 1.8 million lira in 2026. The simplest fix is the most reliable one: don't put identifiable personal data into these tools at all. Mask names, phone numbers, and ID numbers before you ask.
7. Your chatbot needs to say "I'm an AI"
Transparency here works on two levels. First, any bot talking to a customer has to clearly disclose that it's AI, and that disclosure needs to happen at the start of the conversation. Second, you need separate notices covering data processed to run the system versus data used to further develop or train it. In practice, this means adding one clear sentence plus a link to your privacy notice at the top of your chatbot's first message.
8. Don't let AI make the final call alone
Article 11 of the law gives individuals the right to object to decisions made solely by automated systems when those decisions have a negative effect on them, and the guidance specifically calls out hiring, lending, and insurance as examples. If you're using AI to screen CVs, score credit, or evaluate employees, a human needs to make the final decision, and that human actually needs to review the case rather than reflexively clicking "approve." The guidance even names the failure mode: automation bias.
9. Keep health and biometric data away from generative AI
Special category data (health, biometrics, religion, union membership, and similar) doesn't have access to the flexible legal bases, like contract performance or legitimate interest, that ordinary data does. That effectively closes off most generative AI uses for this kind of data. If you run a clinic, an insurance agency, or an HR department, the rule is simple: patient or employee health information doesn't go into any general-purpose AI tool. The guidance gives individual users the same advice: avoid sharing health, financial, or legal details with these tools.
10. Don't ban AI, manage it: put a written policy in place
A follow-up KVKK announcement from early 2026, on generative AI use in workplaces, formally acknowledges the reality of "shadow AI," employees quietly using tools without approval, and takes a notably pragmatic position: outright bans, the authority says, "are unlikely to produce realistic results in practice." Its recommendation is guidance and awareness instead: define in writing which tools, which purposes, and which data types are allowed, and train your staff accordingly.
A real scenario: the customer complaint email
The rules get broken most often in the moment that feels most harmless. A customer service rep pastes an angry customer's email straight into ChatGPT and asks it to "make this sound more professional." That email usually contains the customer's name, phone number, order number, and sometimes a national ID number. In one move, three rules just got broken: personal data left the country without a valid transfer mechanism (rule 6), there was no legal basis for that specific purpose (rules 3 and 4), and the customer never consented to any of it (rule 7).
The compliant version of this same task needs only two small changes: strip the name, phone number, and order number before pasting ("customer complained that product X arrived late" is enough context), or route it through a system that masks personal data automatically. In the systems we build for clients, we handle that masking in software rather than relying on employee discipline, because a rule that depends on people remembering it under deadline pressure rarely survives a busy Tuesday.
Where Turkish AI regulation is headed
As of mid-2026, Turkey still doesn't have a dedicated AI law in force; KVKK's guidance documents are effectively the whole framework for now. That's changing quickly, though. Three separate AI bills are currently pending in the Turkish parliament, and the parliament's AI Research Commission recommended in a March 2026 report that Turkey draft its own AI law aligned with the EU's AI Act.
That has two practical implications if you operate in Turkey. First, compliance work you do against the current KVKK guidance isn't wasted effort, since the guidance is already aligned with EDPB and CNIL thinking, you'll likely be most of the way to compliant once formal AI legislation lands. Second, if you sell into the EU as well, waiting isn't really an option regardless: the EU AI Act's extraterritorial reach already covers Turkish companies whose products or services touch users in Europe, right now.
One more point worth clearing up: this November 2025 guidance isn't KVKK's first move on AI. The authority issued general AI recommendations back in 2021, followed by an informational note on chatbots (using ChatGPT as its example) in June 2025. The 2025 guidance is the most comprehensive version of a position KVKK has held consistently for years: don't ban it, put a framework around it.
Frequently asked questions
Does using ChatGPT at a Turkish company automatically violate KVKK rules?
No, not by itself. The violation comes from what data goes in and how the tool is managed, not from using the tool at all. KVKK's own guidance treats use that involves no personal data or trade secrets, like brainstorming, editing text, or summarizing public content, as a reasonable, low-risk use case.
How large are KVKK fines for AI-related violations?
There's no AI-specific fine category; general KVKK penalties apply. At 2026 rates, disclosure (transparency) violations can reach 1.7 million lira, and data security violations can exceed 17 million lira. On top of that, Turkey's Penal Code criminal data provisions and civil compensation claims are both still on the table.
Can we train our own chatbot on customer data?
Not directly or automatically. Processing customer conversations to run your chatbot and using that same data to train or improve a model are two separate processing activities, and the second one needs its own legal basis and its own disclosure. Anonymization is often the practical answer, but the guidance is specific that anonymization has to be demonstrated through actual technical methods and objective criteria; simply deleting names doesn't count.
So what should you actually do?
Here's the 64-page guidance condensed into five steps:
- Take inventory. Which AI tools are actually being used in your company today, and with what data? Include shadow usage; an anonymous team survey is the fastest way to find out.
- Set a bright line. One sentence covers most of the risk: "Customer personal data, employee data, and trade secrets never go into any AI tool in raw form."
- Add disclosure to your chatbot. A short "you're talking to an AI assistant" notice plus a link to your privacy notice. It's half a day of work against a fine that can reach 1.7 million lira.
- Fix your cross-border transfer. Work with legal counsel to put a data processing agreement and standard contractual clause notification in place with your AI vendor, or add a masking layer that strips personal data before it ever leaves the country.
- Write the policy, then train on it once a year. KVKK's own position is "don't ban it, manage it." A written policy plus a short annual training session is your strongest protection against both fines and simple employee mistakes.
The spirit of KVKK's guidance is worth keeping in mind as a closing thought: the authority isn't against AI, it's against ungoverned AI. A business that puts these 10 rules in place can scale its AI use with confidence while competitors are still stuck wondering whether it's even allowed. If you want a second pair of eyes on what a KVKK-compliant setup looks like for your business, masking layer, disclosure flow, written policy and all, that's a conversation worth having before the first enforcement case sets the precedent.

Written by
Muhammet Fatih Batman
Founder & Editor
Founder of YZ Uzman, with 20+ years of experience in web design and software development.
Comments
No comments yet. Be the first to comment!