Turkey - Chatbot Privacy Guidelines
Explanatory Note on Chatbots (ChatGPT Example)
Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu
Turkey
RAI-TR-NA-ENCCEXX-2024The Personal Data Protection Authority of Turkey (KVKK) published an explanatory note on chatbots, using ChatGPT as an example, that outlines how AI-driven conversational agents interact with personal data and provides guidance for developers, service providers and users on compliance with Turkish data protection law (Law No. 6698). The note emphasizes transparency, data minimization, security, and accountability while warning users about sharing sensitive personal information with chatbots.
Summary
On 8 November 2024 the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu - KVKK) published the explanatory note titled "Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu" which examines privacy and personal-data protection issues arising from the use of AI-powered chatbots (illustrated by ChatGPT). The note explains chatbot functionality, the typical categories of personal data processed through conversational systems (text input, voice, metadata, derived/inferred attributes), and highlights practical legal obligations for organisations that develop, deploy, or integrate chatbots in services that process the personal data of Turkish residents. Key legal anchors referenced include Law No. 6698 on the Protection of Personal Data (KVKK Law), related secondary legislation and the Authority’s existing guidance on data controller/processor responsibilities. The document stresses that chatbot-related processing is subject to the same principles as all personal data processing under Turkish law: lawfulness, purpose limitation, data minimization, accuracy, storage limitation and security. It flags heightened concerns where chatbots process special categories of personal data, children’s data, or where models are trained on large datasets that may include personal data transferred cross-border. The note recommends implementing privacy-by-design and privacy-by-default measures, conducting data protection impact assessments (DPIAs) where appropriate, drafting transparent user-facing disclosures and terms, establishing clear contractual safeguards with third-party model providers, and ensuring secure technical measures (encryption, access controls, retention policies, anonymization/pseudonymization). KVKK also calls on organizations to keep records, respond to data subject rights requests, and report data breaches. The explanatory note serves primarily as practical guidance rather than new binding regulation, but it clarifies that violations of the KVKK remain enforceable and may attract administrative fines and other corrective measures under Law No. 6698. The note complements Turkey’s broader digital governance work and aligns with international trends in AI regulation by urging conformity with privacy-preserving practices and international standards.
Full article
Read full text ↗Overview
The Personal Data Protection Authority (KVKK) issued the "Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu" to clarify privacy and personal-data implications of AI-powered chatbots for Turkish stakeholders. The note uses ChatGPT as an illustrative example to describe how conversational AI collects, stores, and processes personal data through user inputs, interaction logs, voice or audio, and derived inferences. It emphasizes that conventional data-protection principles under Law No. 6698 apply to chatbot deployments, and that developers, service providers, and integrators must adopt proactive safeguards. The explanatory note is available from the Authority’s web pages and accompanying document repositories; see the Authority’s publication page at Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu and the associated PDF released by the KVKK. The overview clarifies the objective of the note: to raise awareness, explain typical processing patterns, and provide pragmatic guidance for compliance and risk mitigation.
Definitions
The note defines key terms to prevent ambiguity: "chatbot" (a software application that simulates human conversation through text or voice via an interface), "AI conversation model" (machine-learning models used to generate or interpret natural language), "data controller" (entity determining purposes and means of processing), "data processor" (entity processing data on behalf of a controller), "personal data" (any information relating to an identified or identifiable natural person) and "special categories/sensitive data" (health, biometric, racial/ethnic, political opinions, sexual life, criminal records, etc.). It clarifies that metadata, usage logs and model-derived inferences that can identify or profile individuals remain personal data under Law No. 6698.
Governance and Institutional Framework
The KVKK positions the explanatory note within Turkey’s established data-protection framework and points practitioners to primary obligations under the Law No. 6698 (Personal Data Protection Law) and related regulations. Entities that determine purposes and means of chatbot processing are data controllers and must comply with registration, transparency, and security obligations; processors (including cloud or ML service providers) must act per contracts and controller instructions. The KVKK retains investigative and sanctioning authority where non-compliance is suspected. The note references the statutory text and guidance repositories hosted by the Authority; see the Law and KVKK materials at Personal Data Protection Law (KVKK) and the specific chatbot note at Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu. It advises organizations to appoint responsible officers for data protection governance and to embed privacy-by-design during product lifecycle stages.
Key Focus Areas
The explanatory note highlights several risk and compliance focal points. First, transparency: users should be informed when they interact with an AI, how their data is used, retention periods and channels for exercising rights. Second, legal basis: controllers must identify lawful grounds for processing (contract, legal obligation, legitimate interests where appropriate, or explicit consent for sensitive data). Third, data minimization and purpose limitation: chatbots should collect only necessary inputs and avoid persistent storage of conversational content unless required and justified. Fourth, security: technical and organizational measures (encryption, access controls, secure logging, model hardening) must be proportionate to the risks. Fifth, special categories: the note stresses that processing sensitive data requires particular care and usually explicit legal justification or consent. Sixth, children: services likely to reach minors need age-appropriate protections and parental consent where applicable. Seventh, vendor and model-provider governance: contractual safeguards, audits, subprocessors’ transparency and cross-border transfer safeguards are required when using international ML platforms. Eighth, dataset provenance and training data: entities must consider whether training corpora contain personal data and whether that processing complies with the law. Ninth, data subject rights: the ability to access, correct, delete, and object to processing must be maintained and implementable. Tenth, incident reporting: controllers must be ready to notify the Authority and affected individuals about data breaches where required.
Implementation Framework
The note sets out practical steps for implementers. It recommends mapping data flows to identify where personal data enters chatbot systems and to apply risk-based controls. Organizations should conduct Data Protection Impact Assessments (DPIAs) for systems that present high privacy risks (for instance, chatbots that profile users or process sensitive data). Privacy-by-design and privacy-by-default principles should be integrated into software development lifecycles, with role-based access, logging, retention policies, anonymization/pseudonymization techniques, and secure model hosting. Contractual measures must require subprocessors to meet KVKK standards and to avoid unauthorized transfers. For cross-border transfers, entities should implement legally recognized safeguards under Law No. 6698. The note also advises that organizations maintain internal policies and staff training programs and maintain up-to-date records of processing activities in line with KVKK expectations.
Monitoring and Evaluation
KVKK recommends ongoing monitoring of chatbot systems to detect drift, unintended information leakage, or model behaviors that may produce discriminatory or privacy-infringing outputs. Evaluation routines should include periodic security assessments, model output testing, red-team exercises, and auditing third-party providers. Metrics for monitoring should measure data access, retention compliance, frequency of sensitive data occurrences in inputs, and the timeliness of breach response. The Authority encourages documentation of monitoring processes and results as evidence of compliance during inspections or inquiries.
Penalties, Liability, and Appeals
While the explanatory note itself is guidance, KVKK reminds stakeholders that violations of Law No. 6698 can result in administrative fines, corrective orders (deletion, anonymization, limitation), and reputational consequences. The Authority can initiate investigations and impose sanctions on controllers/processors that fail to meet obligations. Criminal liability may also arise under Turkish law in certain circumstances. The note explains appeal routes against administrative decisions and advises organizations to remediate quickly to mitigate sanction risk. For statutory details on administrative fines and enforcement, consult the underlying law and KVKK enforcement policies at Law No. 6698.
Relationship to Other Instruments
The KVKK explanatory note situates chatbot guidance within Turkey’s broader legal environment, cross-referencing consumer protection, electronic communications, cybersecurity rules, and sectoral regulations (finance, healthcare, telecommunications). It notes overlap with obligations under sector-specific laws (e.g., banking secrecy, health data confidentiality) and the need to coordinate compliance programs accordingly. The note also indicates that while the document clarifies data-protection duties, other regulatory regimes (cybersecurity authorities, sectoral supervisors) may impose additional requirements, and compliance with one regime does not exempt an entity from others.
International Alignment
The explanatory note references international regulatory developments and best practices, emphasizing alignment with EU data-protection approaches (GDPR principles) and emerging AI governance frameworks. KVKK encourages use of internationally recognized safeguards for cross-border transfers and suggests cooperation with global-standard technical measures. The note signals that Turkey monitors international AI policy developments and that operators should anticipate converging obligations—particularly regarding transparency, technical robustness, and human oversight—by consulting materials from international regulators and standards bodies. This alignment is intended to facilitate trade and interoperability while preserving Turkish data protection standards.
Implementation Timeline
| Milestone | Date/Period |
|---|---|
| Publication of explanatory note | 08 November 2024 |
| Recommended immediate actions (mapping, contract review) | Within 3 months of publication |
| Conduct DPIAs for high-risk chatbot projects | Within 3-6 months (or before deployment) |
| Implement technical and contractual safeguards | Ongoing; priority within 6 months |
Sources and References
| Source | Type |
|---|---|
| Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu | Primary Source |
| KVKK - Chatbot Explanatory Note (PDF) | Primary Source |
| Law No. 6698 (KVKK information page) | Primary Source |
Requirements for a company
What an organisation has to do under Turkey - Chatbot Privacy Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
12- Identify and document lawful grounds for all personal data processing.Data controllers of AI-powered chatbots
- Inform users about AI interaction, data use, retention, and their rights.Providers of AI-powered chatbots
- Collect only necessary personal data and avoid persistent storage of conversational content.Data controllers of AI-powered chatbots
- Implement proportionate technical and organizational security measures.Data controllers and processors of AI-powered chatbots
- Exercise particular care when processing special categories of personal data.Data controllers of AI-powered chatbots
- Maintain and implement mechanisms for users to exercise their data rights.Data controllers of AI-powered chatbots
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
2- Map data flows to identify personal data entry points and apply risk-based controls.Organizations deploying AI-powered chatbots
- Conduct ongoing monitoring of chatbot systems to detect drift or privacy-infringing outputs.Organizations deploying AI-powered chatbots
Should not do
0Nothing in this category.
Who must do what
The obligations under Turkey - Chatbot Privacy Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Data controllers of AI-powered chatbots | Identify and document lawful grounds for all personal data processing. “controllers must identify lawful grounds for processing (contract, legal obligation, legitimate interests where appropriate, or explicit consent for sensitive data).” | Within 3 months of publication | Key Focus Areas | Critical |
| 2 | Providers of AI-powered chatbots | Inform users about AI interaction, data use, retention, and their rights. “users should be informed when they interact with an AI, how their data is used, retention periods and channels for exercising rights.” | Ongoing | Key Focus Areas | Critical |
| 3 | Data controllers of AI-powered chatbots | Collect only necessary personal data and avoid persistent storage of conversational content. “chatbots should collect only necessary inputs and avoid persistent storage of conversational content unless required and justified.” | Ongoing | Key Focus Areas | Critical |
| 4 | Data controllers and processors of AI-powered chatbots | Implement proportionate technical and organizational security measures. “technical and organizational measures (encryption, access controls, secure logging, model hardening) must be proportionate to the risks.” | Ongoing; priority within 6 months | Key Focus Areas | Critical |
| 5 | Data controllers of AI-powered chatbots | Exercise particular care when processing special categories of personal data. “processing sensitive data requires particular care and usually explicit legal justification or consent.” | Ongoing | Key Focus Areas | Critical |
| 6 | Data controllers of AI-powered chatbots | Maintain and implement mechanisms for users to exercise their data rights. “the ability to access, correct, delete, and object to processing must be maintained and implementable.” | Ongoing | Key Focus Areas | Critical |
| 7 | Data controllers using third-party AI models or services | Implement contractual safeguards and audit rights for third-party providers. “Contractual measures must require subprocessors to meet KVKK standards and to avoid unauthorized transfers.” | Within 3 months of publication | Key Focus Areas | Critical |
| 8 | Data controllers transferring personal data internationally | Implement legally recognized safeguards for international personal data transfers. “For cross-border transfers, entities should implement legally recognized safeguards under Law No. 6698.” | Ongoing; priority within 6 months | Implementation Framework | Critical |
| 9 | Data controllers of AI-powered chatbots | Be ready to notify the Authority and affected individuals about data breaches. “controllers must be ready to notify the Authority and affected individuals about data breaches where required.” | Ongoing | Key Focus Areas | Critical |
| 10 | Organizations deploying high-risk chatbot systems | Conduct Data Protection Impact Assessments for high-risk chatbot systems. “Organizations should conduct Data Protection Impact Assessments (DPIAs) for systems that present high privacy risks” | Within 3-6 months (or before deployment) | Implementation Framework | Critical |
| 11 | Developers and integrators of AI-powered chatbots | Integrate privacy-by-design and privacy-by-default principles into development. “Privacy-by-design and privacy-by-default principles should be integrated into software development lifecycles” | Ongoing; priority within 6 months | Implementation Framework | Important |
| 12 | Data controllers of AI-powered chatbots | Maintain internal policies, staff training programs, and records of processing activities. “organizations maintain internal policies and staff training programs and maintain up-to-date records of processing activities” | Ongoing | Implementation Framework | Important |
| 13 | Organizations deploying AI-powered chatbots | Map data flows to identify personal data entry points and apply risk-based controls. “It recommends mapping data flows to identify where personal data enters chatbot systems and to apply risk-based controls.” | Within 3 months of publication | Implementation Framework | Recommended |
| 14 | Organizations deploying AI-powered chatbots | Conduct ongoing monitoring of chatbot systems to detect drift or privacy-infringing outputs. “KVKK recommends ongoing monitoring of chatbot systems to detect drift, unintended information leakage, or model behaviors” | Ongoing | Monitoring and Evaluation | Recommended |
Related Regulations
Recommendations Guide on the Protection of Personal Data in the Field of Artificial Intelligence (Yapay Zeka Alanında Kişisel Verilerin Korunmasına Yönelik Tavsiyeler Rehberi)
Turkey93% similar
Deepfake Information Note ("Deepfake Bilgi Notu") — Personal Data Protection Authority (KVKK)
Turkey91% similar
Yapay Zeka Kanun Teklifi (Artificial Intelligence Law Bill) — TBMM Esas No. 2/2234
Turkey89% similar
Yapay Zeka ve Eğitim: Öğretmenler İçin Uygulamalı Prompt Mühendisliği ve Üretken Araçlarla Yenilikçi Öğrenme Stratejileri (Teacher Guide)
Turkey89% similar
Data Protection Commission Guidance on AI and Large Language Models
Ireland88% similar
© Regulations.AI · updated on 13-Jun-2026