Turkey - Chatbot Privacy Guidelines

Explanatory Note on Chatbots (ChatGPT Example)

Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu

Turkey

RAI-TR-NA-ENCCEXX-2024
In Force(In Force)
GuidelineData Protection and PrivacyGovernance and Oversight
Export PDF

The Personal Data Protection Authority of Turkey (KVKK) published an explanatory note on chatbots, using ChatGPT as an example, that outlines how AI-driven conversational agents interact with personal data and provides guidance for developers, service providers and users on compliance with Turkish data protection law (Law No. 6698). The note emphasizes transparency, data minimization, security, and accountability while warning users about sharing sensitive personal information with chatbots.

Summary

On 8 November 2024 the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu - KVKK) published the explanatory note titled "Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu" which examines privacy and personal-data protection issues arising from the use of AI-powered chatbots (illustrated by ChatGPT). The note explains chatbot functionality, the typical categories of personal data processed through conversational systems (text input, voice, metadata, derived/inferred attributes), and highlights practical legal obligations for organisations that develop, deploy, or integrate chatbots in services that process the personal data of Turkish residents. Key legal anchors referenced include Law No. 6698 on the Protection of Personal Data (KVKK Law), related secondary legislation and the Authority’s existing guidance on data controller/processor responsibilities. The document stresses that chatbot-related processing is subject to the same principles as all personal data processing under Turkish law: lawfulness, purpose limitation, data minimization, accuracy, storage limitation and security. It flags heightened concerns where chatbots process special categories of personal data, children’s data, or where models are trained on large datasets that may include personal data transferred cross-border. The note recommends implementing privacy-by-design and privacy-by-default measures, conducting data protection impact assessments (DPIAs) where appropriate, drafting transparent user-facing disclosures and terms, establishing clear contractual safeguards with third-party model providers, and ensuring secure technical measures (encryption, access controls, retention policies, anonymization/pseudonymization). KVKK also calls on organizations to keep records, respond to data subject rights requests, and report data breaches. The explanatory note serves primarily as practical guidance rather than new binding regulation, but it clarifies that violations of the KVKK remain enforceable and may attract administrative fines and other corrective measures under Law No. 6698. The note complements Turkey’s broader digital governance work and aligns with international trends in AI regulation by urging conformity with privacy-preserving practices and international standards.

Full article

Read full text ↗

Overview

The Personal Data Protection Authority (KVKK) issued the "Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu" to clarify privacy and personal-data implications of AI-powered chatbots for Turkish stakeholders. The note uses ChatGPT as an illustrative example to describe how conversational AI collects, stores, and processes personal data through user inputs, interaction logs, voice or audio, and derived inferences. It emphasizes that conventional data-protection principles under Law No. 6698 apply to chatbot deployments, and that developers, service providers, and integrators must adopt proactive safeguards. The explanatory note is available from the Authority’s web pages and accompanying document repositories; see the Authority’s publication page at Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu and the associated PDF released by the KVKK. The overview clarifies the objective of the note: to raise awareness, explain typical processing patterns, and provide pragmatic guidance for compliance and risk mitigation.

Definitions

The note defines key terms to prevent ambiguity: "chatbot" (a software application that simulates human conversation through text or voice via an interface), "AI conversation model" (machine-learning models used to generate or interpret natural language), "data controller" (entity determining purposes and means of processing), "data processor" (entity processing data on behalf of a controller), "personal data" (any information relating to an identified or identifiable natural person) and "special categories/sensitive data" (health, biometric, racial/ethnic, political opinions, sexual life, criminal records, etc.). It clarifies that metadata, usage logs and model-derived inferences that can identify or profile individuals remain personal data under Law No. 6698.

Governance and Institutional Framework

The KVKK positions the explanatory note within Turkey’s established data-protection framework and points practitioners to primary obligations under the Law No. 6698 (Personal Data Protection Law) and related regulations. Entities that determine purposes and means of chatbot processing are data controllers and must comply with registration, transparency, and security obligations; processors (including cloud or ML service providers) must act per contracts and controller instructions. The KVKK retains investigative and sanctioning authority where non-compliance is suspected. The note references the statutory text and guidance repositories hosted by the Authority; see the Law and KVKK materials at Personal Data Protection Law (KVKK) and the specific chatbot note at Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi Notu. It advises organizations to appoint responsible officers for data protection governance and to embed privacy-by-design during product lifecycle stages.

Key Focus Areas

The explanatory note highlights several risk and compliance focal points. First, transparency: users should be informed when they interact with an AI, how their data is used, retention periods and channels for exercising rights. Second, legal basis: controllers must identify lawful grounds for processing (contract, legal obligation, legitimate interests where appropriate, or explicit consent for sensitive data). Third, data minimization and purpose limitation: chatbots should collect only necessary inputs and avoid persistent storage of conversational content unless required and justified. Fourth, security: technical and organizational measures (encryption, access controls, secure logging, model hardening) must be proportionate to the risks. Fifth, special categories: the note stresses that processing sensitive data requires particular care and usually explicit legal justification or consent. Sixth, children: services likely to reach minors need age-appropriate protections and parental consent where applicable. Seventh, vendor and model-provider governance: contractual safeguards, audits, subprocessors’ transparency and cross-border transfer safeguards are required when using international ML platforms. Eighth, dataset provenance and training data: entities must consider whether training corpora contain personal data and whether that processing complies with the law. Ninth, data subject rights: the ability to access, correct, delete, and object to processing must be maintained and implementable. Tenth, incident reporting: controllers must be ready to notify the Authority and affected individuals about data breaches where required.

Implementation Framework

The note sets out practical steps for implementers. It recommends mapping data flows to identify where personal data enters chatbot systems and to apply risk-based controls. Organizations should conduct Data Protection Impact Assessments (DPIAs) for systems that present high privacy risks (for instance, chatbots that profile users or process sensitive data). Privacy-by-design and privacy-by-default principles should be integrated into software development lifecycles, with role-based access, logging, retention policies, anonymization/pseudonymization techniques, and secure model hosting. Contractual measures must require subprocessors to meet KVKK standards and to avoid unauthorized transfers. For cross-border transfers, entities should implement legally recognized safeguards under Law No. 6698. The note also advises that organizations maintain internal policies and staff training programs and maintain up-to-date records of processing activities in line with KVKK expectations.

Monitoring and Evaluation

KVKK recommends ongoing monitoring of chatbot systems to detect drift, unintended information leakage, or model behaviors that may produce discriminatory or privacy-infringing outputs. Evaluation routines should include periodic security assessments, model output testing, red-team exercises, and auditing third-party providers. Metrics for monitoring should measure data access, retention compliance, frequency of sensitive data occurrences in inputs, and the timeliness of breach response. The Authority encourages documentation of monitoring processes and results as evidence of compliance during inspections or inquiries.

Penalties, Liability, and Appeals

While the explanatory note itself is guidance, KVKK reminds stakeholders that violations of Law No. 6698 can result in administrative fines, corrective orders (deletion, anonymization, limitation), and reputational consequences. The Authority can initiate investigations and impose sanctions on controllers/processors that fail to meet obligations. Criminal liability may also arise under Turkish law in certain circumstances. The note explains appeal routes against administrative decisions and advises organizations to remediate quickly to mitigate sanction risk. For statutory details on administrative fines and enforcement, consult the underlying law and KVKK enforcement policies at Law No. 6698.

Relationship to Other Instruments

The KVKK explanatory note situates chatbot guidance within Turkey’s broader legal environment, cross-referencing consumer protection, electronic communications, cybersecurity rules, and sectoral regulations (finance, healthcare, telecommunications). It notes overlap with obligations under sector-specific laws (e.g., banking secrecy, health data confidentiality) and the need to coordinate compliance programs accordingly. The note also indicates that while the document clarifies data-protection duties, other regulatory regimes (cybersecurity authorities, sectoral supervisors) may impose additional requirements, and compliance with one regime does not exempt an entity from others.

International Alignment

The explanatory note references international regulatory developments and best practices, emphasizing alignment with EU data-protection approaches (GDPR principles) and emerging AI governance frameworks. KVKK encourages use of internationally recognized safeguards for cross-border transfers and suggests cooperation with global-standard technical measures. The note signals that Turkey monitors international AI policy developments and that operators should anticipate converging obligations—particularly regarding transparency, technical robustness, and human oversight—by consulting materials from international regulators and standards bodies. This alignment is intended to facilitate trade and interoperability while preserving Turkish data protection standards.

Implementation Timeline

MilestoneDate/Period
Publication of explanatory note08 November 2024
Recommended immediate actions (mapping, contract review)Within 3 months of publication
Conduct DPIAs for high-risk chatbot projectsWithin 3-6 months (or before deployment)
Implement technical and contractual safeguardsOngoing; priority within 6 months

Sources and References

SourceType
Sohbet Robotları (ChatGPT Örneği) Hakkında Bilgi NotuPrimary Source
KVKK - Chatbot Explanatory Note (PDF)Primary Source
Law No. 6698 (KVKK information page)Primary Source

Requirements for a company

What an organisation has to do under Turkey - Chatbot Privacy Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Identify and document lawful grounds for all personal data processing.Data controllers of AI-powered chatbots
  • Inform users about AI interaction, data use, retention, and their rights.Providers of AI-powered chatbots
  • Collect only necessary personal data and avoid persistent storage of conversational content.Data controllers of AI-powered chatbots
  • Implement proportionate technical and organizational security measures.Data controllers and processors of AI-powered chatbots
  • Exercise particular care when processing special categories of personal data.Data controllers of AI-powered chatbots
  • Maintain and implement mechanisms for users to exercise their data rights.Data controllers of AI-powered chatbots
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

2
  • Map data flows to identify personal data entry points and apply risk-based controls.Organizations deploying AI-powered chatbots
  • Conduct ongoing monitoring of chatbot systems to detect drift or privacy-infringing outputs.Organizations deploying AI-powered chatbots

Should not do

0

Nothing in this category.

Who must do what

The obligations under Turkey - Chatbot Privacy Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Data controllers of AI-powered chatbotsIdentify and document lawful grounds for all personal data processing.
controllers must identify lawful grounds for processing (contract, legal obligation, legitimate interests where appropriate, or explicit consent for sensitive data).
Within 3 months of publicationKey Focus AreasCritical
2Providers of AI-powered chatbotsInform users about AI interaction, data use, retention, and their rights.
users should be informed when they interact with an AI, how their data is used, retention periods and channels for exercising rights.
OngoingKey Focus AreasCritical
3Data controllers of AI-powered chatbotsCollect only necessary personal data and avoid persistent storage of conversational content.
chatbots should collect only necessary inputs and avoid persistent storage of conversational content unless required and justified.
OngoingKey Focus AreasCritical
4Data controllers and processors of AI-powered chatbotsImplement proportionate technical and organizational security measures.
technical and organizational measures (encryption, access controls, secure logging, model hardening) must be proportionate to the risks.
Ongoing; priority within 6 monthsKey Focus AreasCritical
5Data controllers of AI-powered chatbotsExercise particular care when processing special categories of personal data.
processing sensitive data requires particular care and usually explicit legal justification or consent.
OngoingKey Focus AreasCritical
6Data controllers of AI-powered chatbotsMaintain and implement mechanisms for users to exercise their data rights.
the ability to access, correct, delete, and object to processing must be maintained and implementable.
OngoingKey Focus AreasCritical
7Data controllers using third-party AI models or servicesImplement contractual safeguards and audit rights for third-party providers.
Contractual measures must require subprocessors to meet KVKK standards and to avoid unauthorized transfers.
Within 3 months of publicationKey Focus AreasCritical
8Data controllers transferring personal data internationallyImplement legally recognized safeguards for international personal data transfers.
For cross-border transfers, entities should implement legally recognized safeguards under Law No. 6698.
Ongoing; priority within 6 monthsImplementation FrameworkCritical
9Data controllers of AI-powered chatbotsBe ready to notify the Authority and affected individuals about data breaches.
controllers must be ready to notify the Authority and affected individuals about data breaches where required.
OngoingKey Focus AreasCritical
10Organizations deploying high-risk chatbot systemsConduct Data Protection Impact Assessments for high-risk chatbot systems.
Organizations should conduct Data Protection Impact Assessments (DPIAs) for systems that present high privacy risks
Within 3-6 months (or before deployment)Implementation FrameworkCritical
11Developers and integrators of AI-powered chatbotsIntegrate privacy-by-design and privacy-by-default principles into development.
Privacy-by-design and privacy-by-default principles should be integrated into software development lifecycles
Ongoing; priority within 6 monthsImplementation FrameworkImportant
12Data controllers of AI-powered chatbotsMaintain internal policies, staff training programs, and records of processing activities.
organizations maintain internal policies and staff training programs and maintain up-to-date records of processing activities
OngoingImplementation FrameworkImportant
13Organizations deploying AI-powered chatbotsMap data flows to identify personal data entry points and apply risk-based controls.
It recommends mapping data flows to identify where personal data enters chatbot systems and to apply risk-based controls.
Within 3 months of publicationImplementation FrameworkRecommended
14Organizations deploying AI-powered chatbotsConduct ongoing monitoring of chatbot systems to detect drift or privacy-infringing outputs.
KVKK recommends ongoing monitoring of chatbot systems to detect drift, unintended information leakage, or model behaviors
OngoingMonitoring and EvaluationRecommended

© Regulations.AI · updated on 13-Jun-2026