Jump to

Türkiye’s DPA Publishes Its Agentic AI Guide: Reading Notes for Everyone Building or Deploying Agents

On 12 March 2026, Türkiye’s Data Protection Authority published its guide on Agentic AI — with a deliberate terminology choice of its own: “Etken YZ” for agentic systems and “YZ Aracısı” for AI agents. The guide is not binding, but it is the first official text showing how the Board will look at these systems — in other words, the question sheet for the next investigation. We read all forty-one pages; here is what the Authority says, and what it means for any team building or deploying agent-based systems with a Türkiye nexus.

What worries the Authority — and how agentic differs from classic AI

The guide’s starting point: generative AI produces content, agentic AI does work. You set the goal; the system plans its own steps, calls its own tools, and re-routes when conditions change. The data protection concern flows directly from that autonomy: in a classic application you know upfront which data serves which purpose; in a multi-step agent flow, processing expands with the task, datasets not foreseen at the start get pulled in, and existing data is reused across missions. The guide’s most important methodological sentence sits here: assessment must be made over the system’s holistic operation, not over individual processing activities — analyses that look innocent in isolation can combine into a comprehensive profile.

The guide’s risk list, mapped to the law

Risk in the guide KVKK anchor Where it bites in practice
Processing scope expanding as tasks progress Purpose limitation + data minimisation (Art. 4) The agent reading every CRM field “to be helpful”
New data uses detaching from the original legal basis Continuity of the Art. 5 basis Support data drifting into sales scoring
Comprehensive profiling by combining sources Objection to automated results (Art. 11) + proportionality Calendar + e-mail + transcripts merging into a single dossier
The black box deepening in multi-agent structures Disclosure duty (Art. 10) + accountability Nobody able to answer “why was this decided?”
Hallucination propagating through multi-step flows Accuracy principle (Art. 4/1-d) Step one’s invention becoming step five’s processing
Input manipulation and a wider attack surface Data security (Art. 12) Prompt injection walking the agent past its permissions

Who is responsible? The quietest, hardest part

The Authority states plainly that processing is distributed among developers, deployers and other actors, and that attributing responsibility after a breach is difficult — and offers that difficulty to no one as an excuse. The Turkish translation is familiar: whatever your model provider does behind the agent, you are the controller toward your customers and employees. The homework the guide expects follows from that: fix the role allocation contractually, register agent flows in your records of processing, and build human oversight from the design phase — not as an approval button bolted on later.

Alignment with the EU: two regimes, one architecture

The guide doesn’t borrow the AI Act’s vocabulary, but it looks in the same direction: human-centred approach, explainability, lifecycle risk management. For an EU-facing product the practical consequence is convenient — if you are already building human oversight and DPIA muscle for the AI Act, the Turkish guide’s expectations are largely served by the same architecture. See the AI Compliance Hub for the full comparison.

If the guide isn’t binding, why care?

Because Board decisions follow the guides — the biometrics guide preceded the attendance-tracking enforcement line. A guide is today’s expectation and tomorrow’s audit criterion; the only difference between the two is time.

We only use Copilot-style agents internally — are we covered?

Yes — the guide addresses deployers, not just developers. Every agent flow touching employee data needs the same trio: an inventory record, an updated privacy notice, and access limits.

Where to start

With one question: “Which personal data do our agents touch, for which task, on whose decision?” If the answer doesn’t fit on a page, every risk in the guide is already live in your stack — and writing that page before the Board’s letter is always cheaper than after.

Source: KVKK Agentic AI Guide (full text, Turkish) · Related: profiling · generative AI at work and KVKK.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals — including crypto-asset infrastructure, fintech and games — bringing a former startup founder's perspective to every engagement.

    View all posts
Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 16 July 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.