Turkey - Deepfake Information Note
Deepfake Information Note
Deepfake Bilgi Notu
Turkey
RAI-TR-NA-DINDBXX-2024The Turkish Personal Data Protection Authority (KVKK) published the "Deepfake Bilgi Notu" on 19 January 2024 to explain deepfake technologies, highlight threats to personal data and fundamental rights, and provide practical detection and mitigation guidance for individuals and organizations. The note situates deepfakes within Turkey’s data protection framework (Law No. 6698) and encourages risk-based safeguards, transparency and cooperation with supervisory authorities.
Summary
On 19 January 2024 the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, KVKK) published an information note titled "Deepfake Bilgi Notu" to explain the technology commonly referred to as "deepfake" (Turkish: derin kurgu / derin sahte), to identify the data protection and fundamental-rights risks it creates, and to provide practical detection tips and mitigation measures for individuals and organisations. The note frames deepfakes as AI-driven manipulations of audio, image and video that frequently mix authentic personal data with synthetic content, creating privacy, reputational and security risks under Turkey's personal data protection framework (Law No. 6698).
The Information Note is an awareness and guidance document (not a binding regulation) that sets out KVKK's assessment of threats posed by deepfake technologies, practical indicators for detection, and recommended technical and organisational precautions for data controllers, processors and individuals. It highlights the application of existing Turkish personal data protection obligations (Law No. 6698) to the creation, dissemination and use of deepfake material and stresses reporting, risk management and platform-level mitigation as key responses.
Full article
Read full text ↗Overview
Published by the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, KVKK) on 19 January 2024, the "Deepfake Bilgi Notu" (Deepfake Information Note) explains deepfake technologies, how they are produced and used, and the specific risks they pose to personal data and individual rights under Law No. 6698 on the Protection of Personal Data (KVKK). The Note is intended as a practical awareness and guidance document addressed to the public, private-sector data controllers and processors, and public institutions. It frames deepfakes as AI-driven manipulations of audio, image and video that frequently mix authentic personal data with synthetic content, creating privacy, reputational and security risks under Turkey's personal data protection framework.
Definitions
The Information Note sets out key definitions and clarifications to ensure consistent understanding of terms used throughout the guidance:
- Deepfake: AI-driven synthetic or manipulated audio, image or video that realistically imitates a real person's appearance, voice or behaviour (Turkish: derin kurgu / derin sahte).
- Personal data: Any information relating to an identified or identifiable natural person, including images, video and voice recordings, as defined by Law No. 6698.
- Sensitive personal data / special categories: Categories such as biometric data that may be processed in deepfake contexts; these require heightened protections and specific legal bases under Law No. 6698.
Governance and Institutional Framework
The Note was issued by KVKK as an awareness and guidance instrument rather than a binding regulation. KVKK positions the Note within its supervisory and advisory remit: it provides KVKK's assessment of risks, practical detection indicators and recommended technical and organisational precautions for data controllers, processors and individuals. Although not legally binding, the Note clarifies that processing activities involving deepfakes remain subject to existing obligations under Law No. 6698. The target audiences are natural persons (to increase awareness) and legal persons acting as controllers or processors in Turkey or processing the personal data of persons in Turkey. The Note encourages coordination among legal, security and communications teams within organisations and cooperation with supervisory authorities where incidents occur.
Key Focus Areas
- Definition and characteristics of deepfakes: AI-based techniques to synthetically generate or manipulate images, audio and video to realistically mimic persons' faces, gestures, expressions and voices.
- Risk identification: Discussion of privacy, reputational, financial and security harms, including heightened risks for children and other vulnerable groups. The Note highlights how deepfakes can combine authentic personal data with synthetic elements, increasing the potential for misuse such as impersonation and fraud.
- Detection guidance: Practical indicators and heuristics for spotting deepfake content: visual and audio artefacts, inconsistent lighting or eye movement, mismatches between audio and lip movement, metadata anomalies, and verification of original sources.
- Recommended mitigations for individuals and organisations: Limiting sharing of raw biometric media, strengthening cybersecurity measures, incident reporting and internal monitoring, development and deployment of anti-deepfake detection tools, and public-awareness efforts.
- Legal framing and compliance expectations: Application of existing obligations under Law No. 6698, including data security duties, requirements for appropriate legal bases for processing, purpose limitation, transparency and the possibility of sanctions for violations.
Implementation Framework
While the Information Note itself does not create new legal obligations, it outlines an implementation framework of expectations and recommended actions for organisations and individuals facing deepfake-related risks. The central elements of the framework include:
- Legal basis and purpose limitation: Ensure any processing of personal data used to create deepfakes has a lawful basis under KVKK (e.g., explicit consent where required) and that processing purposes are clearly specified, limited and documented.
- Data security measures: Implement technical and organisational protections for datasets that could be repurposed to create deepfakes, such as access controls, encryption, detailed logging, secure deletion, and anonymisation where feasible.
- Transparency and notice: Provide clear information to affected data subjects when their personal data are used or published in synthetic media; obtain lawful authorisations or consents where required by applicable law.
- Risk assessment and governance: Carry out risk analyses focused on synthetic media and integrate deepfake risk into privacy and security governance frameworks, incident response plans, internal reporting lines and staff training programmes.
- Platform, contractual and third-party measures: Require safeguards from third-party service providers, include contractual clauses with processors about permissible use and security of personal data, and seek platform-level mitigations where content is disseminated via online services.
- Operational detection and response: Adopt or develop technical tools for detection, monitor media channels for misuse, document findings, and prepare communications protocols to address reputational impacts and notify relevant authorities when required.
Monitoring and Evaluation
KVKK encourages continuous monitoring and evaluation of measures taken to mitigate deepfake risks. Practical monitoring and evaluation measures described or implied in the Note include:
- Regular review of internal policies and data inventories to identify datasets at elevated risk of misuse for synthetic media generation.
- Integration of deepfake-related risk indicators into existing incident detection and response workflows, including logging and forensic capabilities for audio/video assets.
- Periodic risk assessments that consider evolving AI capabilities, changes in threat actors' tactics, and sector-specific vulnerabilities (e.g., media, finance, electoral communications).
- Coordination and information-sharing between legal, security, privacy and communications functions to evaluate the effectiveness of mitigations and adjust controls accordingly.
- Engagement with platform providers and service suppliers to assess the effectiveness of platform-level detection and content-moderation measures, and updating contractual requirements where necessary.
Penalties, Liability, and Appeals
Although the Information Note is non-binding guidance, KVKK reiterates that unlawful processing, inadequate security measures or failures to comply with obligations under Law No. 6698 may expose controllers and processors to administrative fines and corrective measures provided by the Law. The Note emphasises existing compliance mechanisms: administrative monetary fines, corrective orders, documentation and reporting obligations, and potential follow-up supervisory action by KVKK. Additionally, misuse of deepfakes may engage relevant provisions of Turkish criminal law in cases involving fraud, impersonation, harassment or other offences; the Note reminds organisations that criminal liabilities may arise independently of administrative sanctions. The Note encourages timely reporting of incidents to internal governance structures and to supervisory authorities where statutory notification requirements apply.
Relationship to Other Instruments
The Information Note situates deepfake-related expectations within the broader framework of Law No. 6698 on the Protection of Personal Data and other KVKK guidance. It cross-references controller and processor obligations, data security duties and administrative sanction powers established by the Law. The Note also points to secondary KVKK guidance and sectoral advisories on data security, cross-border transfers and sensitive processing categories as complementary resources. Where relevant, criminal law provisions applicable to fraud, impersonation or harassment using synthetic media are also noted as related instruments that may be engaged by deepfake misuse.
International Alignment
KVKK's Information Note aligns with a broader international supervisory trend addressing generative AI and synthetic media. While the Note focuses on the application of Turkey's Law No. 6698, it complements international supervisory activity and guidance from other authorities and highlights the need for cross-border coordination with platforms and foreign service providers where data flows are involved. KVKK positions the Note as part of a global movement among data protection authorities to provide practical detection tips, risk-management approaches and recommendations for platform-level mitigation.
Implementation Timeline
| Date | Event |
|---|---|
| 2024-01-19 | KVKK publishes Deepfake Bilgi Notu (Deepfake Information Note) on its website and provides a downloadable PDF of the guidance. |
| 2016-04-07 | Law No. 6698 on the Protection of Personal Data (KVKK) promulgated — establishes the legal framework within which deepfake-related processing is assessed under Turkish law. |
Sources and References
| Source | URL |
|---|---|
| KVKK — Deepfake Information Note (Deepfake Bilgi Notu), published 19 January 2024 (PDF) | https://kvkk.gov.tr/SharedFolderServer/CMSFiles/015794c4-061b-4560-a0b2-e372ee536642.pdf |
| Law No. 6698 on the Protection of Personal Data (KVKK) — official text | https://www.mevzuat.gov.tr/mevzuat?MevzuatNo=6698&MevzuatTur=1&MevzuatTertip=5 |
Requirements for a company
What an organisation has to do under Turkey - Deepfake Information Note, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
7- Ensure processing of personal data for synthetic media has a lawful basis and specified purposes.Data controllers and processors.
- Implement technical and organisational security measures for datasets vulnerable to deepfake misuse.Data controllers and processors.
- Provide clear information to data subjects when their personal data are used in synthetic media.Data controllers and processors.
- Establish internal reporting lines and notify authorities when legal obligations require reporting deepfake incidents.Data controllers and processors.
- Conduct risk analyses focused on synthetic media and integrate deepfake risk into governance frameworks.Data controllers and processors.
- Require safeguards from third-party service providers and include contractual clauses for personal data used in synthetic media.Data controllers.
- +1 more in the table below
Must not do
0Nothing in this category.
Should do
2- Adopt or develop technical tools for deepfake detection and monitor media channels for misuse.Data controllers and processors.
- Continuously monitor and evaluate measures taken to mitigate deepfake risks.Data controllers and processors.
Should not do
0Nothing in this category.
Who must do what
The obligations under Turkey - Deepfake Information Note, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Data controllers and processors. | Ensure processing of personal data for synthetic media has a lawful basis and specified purposes. “Ensure any processing of personal data used to create deepfakes has a lawful basis under KVKK... and that processing purposes are clearly specified, limited and documented.” | Before processing personal data | — | Critical |
| 2 | Data controllers and processors. | Implement technical and organisational security measures for datasets vulnerable to deepfake misuse. “Implement technical and organisational protections for datasets that could be repurposed to create deepfakes, such as access controls, encryption, detailed logging...” | — | — | Critical |
| 3 | Data controllers and processors. | Provide clear information to data subjects when their personal data are used in synthetic media. “Provide clear information to affected data subjects when their personal data are used or published in synthetic media; obtain lawful authorisations or consents where required.” | When personal data are used or published | — | Critical |
| 4 | Data controllers and processors. | Establish internal reporting lines and notify authorities when legal obligations require reporting deepfake incidents. “The Note encourages timely reporting of incidents to internal governance structures and to supervisory authorities where statutory notification requirements apply.” | Upon incident detection | — | Critical |
| 5 | Data controllers and processors. | Conduct risk analyses focused on synthetic media and integrate deepfake risk into governance frameworks. “Carry out risk analyses focused on synthetic media and integrate deepfake risk into privacy and security governance frameworks, incident response plans...” | — | — | Important |
| 6 | Data controllers. | Require safeguards from third-party service providers and include contractual clauses for personal data used in synthetic media. “Require safeguards from third-party service providers, include contractual clauses with processors about permissible use and security of personal data...” | Before engaging third-party providers | — | Important |
| 7 | Data controllers and processors. | Implement staff training programmes on deepfake risks and detection. “...integrate deepfake risk into privacy and security governance frameworks, incident response plans, internal reporting lines and staff training programmes.” | — | — | Important |
| 8 | Data controllers and processors. | Adopt or develop technical tools for deepfake detection and monitor media channels for misuse. “Adopt or develop technical tools for detection, monitor media channels for misuse, document findings, and prepare communications protocols...” | — | — | Recommended |
| 9 | Data controllers and processors. | Continuously monitor and evaluate measures taken to mitigate deepfake risks. “KVKK encourages continuous monitoring and evaluation of measures taken to mitigate deepfake risks.” | — | — | Recommended |
Related Regulations
Explanatory Note on Chatbots (ChatGPT Example) (Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu)
Turkey91% similar
Recommendations Guide on the Protection of Personal Data in the Field of Artificial Intelligence (Yapay Zeka Alanında Kişisel Verilerin Korunmasına Yönelik Tavsiyeler Rehberi)
Turkey91% similar
Bill on Amendments to Certain Laws Regarding Artificial Intelligence (Kanun Teklifi — Esas No. 2/3358)
Turkey90% similar
Deepfake Guide (UAE National Programme for Artificial Intelligence)
United Arab Emirates89% similar
Yapay Zeka Kanun Teklifi (Artificial Intelligence Law Bill) — TBMM Esas No. 2/2234
Turkey89% similar
© Regulations.AI · updated on 13-Jun-2026