Turkey - Personal Data Protection Guidelines

Recommendations Guide on the Protection of Personal Data in the Field of Artificial Intelligence

Yapay Zeka Alanında Kişisel Verilerin Korunmasına Yönelik Tavsiyeler Rehberi

Turkey

RAI-TR-NA-RGPPDXX-2021
In Force(In Force)
GuidelineData Protection and PrivacyGovernance and OversightAccountability and Documentation
Export PDF

Published by the Turkish Personal Data Protection Authority (KVKK), this non-binding recommendations guide (September 2021) provides practical guidance for developers, manufacturers, service providers and decision‑makers to ensure personal data protection in AI projects under Law No. 6698. It emphasizes privacy-by-design, risk assessments (including DPIAs), transparency, human oversight and security measures, and aligns Turkey’s approach with international standards such as OECD and Council of Europe guidance.

Summary

The Recommendations Guide on the Protection of Personal Data in the Field of Artificial Intelligence (published by the Kişisel Verileri Koruma Kurumu — KVKK — in September 2021) is a non‑binding framework document aimed at ensuring that AI system development and deployment in Turkey respect the requirements of Law No. 6698 on the Protection of Personal Data. The Guide addresses the whole AI lifecycle (design, training, testing, deployment, monitoring and decommissioning) and sets out recommended practices for data minimization, anonymization where possible, lawful processing, purpose limitation, accuracy, retention controls, and robust technical and organizational security. It highlights the need to identify the roles of data controllers and processors early in projects, to apply privacy‑by‑design and privacy‑by‑default principles, and to adopt accountability practices such as records of processing activities and impact assessments.

The Guide makes specific recommendations for different actors: developers and manufacturers are urged to integrate privacy protections into models and toolchains, select appropriate datasets and avoid unnecessary collection of special category personal data; service providers and platform operators are instructed to ensure contractual controls, transparency towards end users, mechanisms enabling data subject rights, and secure data handling; decision‑makers and procurers are advised to require demonstrable compliance, human oversight capabilities and risk mitigation measures before adopting AI systems.

Particular attention is drawn to high‑risk scenarios (e.g., automated decision‑making that affects fundamental rights, biometric identification, profiling for sensitive purposes) where the Guide recommends privacy impact assessments and consultation with relevant regulators where fundamental rights may be significantly affected. The document also encourages codes of conduct and certification mechanisms suited to the Turkish legal context and notes the importance of interoperability with international standards (OECD AI Principles, Council of Europe guidance and EU data protection practice) to reduce fragmentation and support cross‑border data flows with appropriate safeguards.

Practically, the Guide recommends: documenting processing purposes and lawful bases; ensuring data minimization and quality; building traceability, explainability and human‑in‑the‑loop controls; performing and updating risk assessments and DPIAs; implementing strong encryption, access controls and data segregation; enabling data subject rights and remedies; and establishing monitoring, auditing and incident response processes. While not creating new legal obligations, the Guide is intended to inform compliance with existing Turkish law (Law No. 6698) and to serve as a policy resource for both public and private actors developing or deploying AI systems in Turkey.

Full article

Read full text ↗

Overview

The "Recommendations Guide on the Protection of Personal Data in the Field of Artificial Intelligence" was prepared and published by the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu - KVKK) in September 2021 to provide guidance to developers, manufacturers, service providers and decision makers on how AI activities should be designed and implemented to comply with Law No. 6698. The Guide is advisory rather than legislative, but it frames the privacy considerations that should be embedded across the AI lifecycle and references international frameworks such as the OECD AI Principles and Council of Europe data protection guidance. It promotes privacy‑by‑design, risk‑based oversight, explainability, human oversight and strong technical and organizational safeguards to prevent harm to data subjects.

Definitions

The Guide defines core terms for the Turkish context, aligning with Law No. 6698 terminology: "personal data" (any information relating to an identified or identifiable natural person), "special categories" (sensitive personal data), "data controller" and "data processor" as per roles under the law, and an operational understanding of "AI system" as a lifecycle of systems that process data to make predictions, recommendations or decisions. It stresses that certain outputs or inferences from AI (including inferred sensitive attributes) may themselves constitute personal data under the law.

Governance and Institutional Framework

The Guide urges organisations to embed AI governance into their corporate or institutional data protection frameworks, appointing responsible owners and ensuring board‑level awareness. It recommends clear role allocation between controllers and processors, documented contracts addressing AI‑specific risks, internal approval gates (including DPIA sign‑off), and the creation of interdisciplinary review boards for high‑risk projects. It further recommends coordination with the national regulator (KVKK) and consultation with sectoral supervisors where projects may impact fundamental rights.

Key Focus Areas

Key focus areas described in the Guide include: (1) lawfulness and purpose limitation — defining specific, limited purposes and lawful bases for processing; (2) data minimization and quality — choosing datasets that are necessary and accurate, avoiding or reducing use of special categories; (3) privacy‑enhancing techniques — anonymization, pseudonymization, local processing and differential privacy where appropriate; (4) transparency and information provision — telling data subjects about AI use and meaningful information about automated decisions; (5) human oversight — enabling meaningful human intervention in automated decision‑making; (6) testing and validation — continuous model evaluation for bias, accuracy and drift; (7) security — technical measures including encryption, access control and secure model management; (8) accountability and documentation — records, logs and auditable trails for model training, datasets and decision rationales; and (9) redress and remedies — channels for individuals to query, appeal or seek correction. The Guide stresses particular caution for biometric processing, profiling for legal or significant effects, and public‑sector AI uses affecting individual rights.

Implementation Framework

Implementation is presented as a lifecycle approach: (i) concept and planning — assess necessity and alternatives (including non‑personal data); (ii) design and data collection — adopt privacy‑by‑design, define legal bases, and document datasets; (iii) training and testing — use representative data, test for bias and overfitting, maintain validation datasets and version control; (iv) deployment — enforce access, monitoring and human override; (v) monitoring and update — continuous post‑deployment evaluation for performance and privacy risks; and (vi) decommissioning — secure deletion/archiving and retention limit enforcement. Each phase should produce documentation and evidence for potential regulatory review.

Monitoring and Evaluation

The Guide recommends continuous monitoring mechanisms and periodic audits for AI systems, including automated alerts for performance drift, fairness metrics, and privacy breaches. It suggests publishing internal or sectoral audit summaries and encourages independent third‑party testing and certification where possible. Monitoring should include metrics on accuracy across protected groups, explainability testing and logging of model inputs/outputs to enable investigations of incidents.

Penalties, Liability, and Appeals

While the Guide itself is non‑binding, it clarifies that failure to meet Law No. 6698 obligations may lead to administrative fines and sanctions by the KVKK, and possibly civil or criminal liability under Turkish law. It advises organisations to maintain appeals and redress channels for data subjects, and to design systems to facilitate correction, objection and human review to reduce legal exposure.

Relationship to Other Instruments

The Guide explicitly links its recommendations to domestic law (Law No. 6698) and international instruments. It draws on and encourages alignment with the OECD AI Principles, Council of Europe guidance on AI and data protection, and EU data protection practice (GDPR-related guidance and EDPB/EDPS opinions). This alignment is intended to promote interoperability and support lawful cross‑border data flows with safeguards.

International Alignment

The Guide encourages Turkish AI actors to follow international good practice in order to remain interoperable with trading partners and regulatory regimes — referencing the OECD Recommendation on AI and Council of Europe guidance. It recommends designing documentation and certification schemes that can be recognized internationally to facilitate trust and market access.

Implementation Timeline

MilestoneIndicative Deadline
KVKK publication of Guide2021-09-15
Initial internal risk assessments for existing AI systemsWithin 6 months of publication
Adopt privacy-by-design in new projectsImmediate / ongoing
Periodic review and DPIA updatesAt least annually or on material change

Sources and References

SourceType
Recommendations on the Protection of Personal Data in the Field of Artificial Intelligence (KVKK, 2021)Primary Source
Recommendation of the Council on Artificial Intelligence (OECD, 2019)International Guidance
Guidelines on Artificial Intelligence and Data Protection (Council of Europe, 2019)International Guidance

Requirements for a company

What an organisation has to do under Turkey - Personal Data Protection Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Define specific purposes and lawful bases for processing personal data in AI systems.Organizations developing or deploying AI systems.
  • Conduct Data Protection Impact Assessments (DPIAs) for high-risk AI systems.Organizations developing or deploying AI systems.
  • Implement privacy-by-design principles in all new AI projects.Organizations developing or deploying AI systems.
  • Ensure data minimization and accuracy for all datasets used in AI systems.Organizations developing or deploying AI systems.
  • Implement robust technical and organizational security measures for AI systems.Organizations developing or deploying AI systems.
  • Provide clear and meaningful information to data subjects about AI use and automated decisions.Organizations developing or deploying AI systems.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Turkey - Personal Data Protection Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organizations developing or deploying AI systems.Define specific purposes and lawful bases for processing personal data in AI systems.
defining specific, limited purposes and lawful bases for processing
Before processing personal dataKey Focus Areas (1)Critical
2Organizations developing or deploying AI systems.Conduct Data Protection Impact Assessments (DPIAs) for high-risk AI systems.
internal approval gates (including DPIA sign‑off)
Before deployment of high-risk AI systemsGovernance and Institutional FrameworkCritical
3Organizations developing or deploying AI systems.Implement privacy-by-design principles in all new AI projects.
Adopt privacy-by-design in new projects
Immediate / ongoing for new projectsImplementation TimelineCritical
4Organizations developing or deploying AI systems.Ensure data minimization and accuracy for all datasets used in AI systems.
data minimization and quality — choosing datasets that are necessary and accurate
Before data collection and processingKey Focus Areas (2)Critical
5Organizations developing or deploying AI systems.Implement robust technical and organizational security measures for AI systems.
security — technical measures including encryption, access control and secure model management
Before deployment and continuouslyKey Focus Areas (7)Critical
6Organizations developing or deploying AI systems.Provide clear and meaningful information to data subjects about AI use and automated decisions.
transparency and information provision — telling data subjects about AI use
Before processing personal data with AIKey Focus Areas (4)Critical
7Organizations developing or deploying AI systems.Establish mechanisms for meaningful human oversight and intervention in automated decision-making.
human oversight — enabling meaningful human intervention in automated decision‑making
Before deployment of AI systemsKey Focus Areas (5)Critical
8Organizations developing or deploying AI systems.Maintain auditable records, logs, and documentation for AI system training and decisions.
accountability and documentation — records, logs and auditable trails
Continuously from design to decommissioningKey Focus Areas (8)Critical
9Organizations developing or deploying AI systems.Establish channels for data subjects to query, appeal, or seek correction of AI decisions.
redress and remedies — channels for individuals to query, appeal or seek correction
Before deployment of AI systemsKey Focus Areas (9)Critical
10Organizations developing or deploying AI systems.Embed AI governance into existing corporate data protection frameworks.
embed AI governance into their corporate or institutional data protection frameworks
Governance and Institutional FrameworkImportant
11Organizations with existing AI systems.Conduct initial internal risk assessments for all existing AI systems.
Initial internal risk assessments for existing AI systems
Mar 15, 2022Implementation TimelineImportant
12Organizations deploying AI systems.Continuously monitor AI systems for performance drift, fairness, and privacy risks.
continuous monitoring mechanisms and periodic audits for AI systems
Ongoing after deploymentMonitoring and EvaluationImportant

© Regulations.AI · updated on 13-Jun-2026