There is a line inside the Turkish data protection law that most companies deploying artificial intelligence have not read, and it is the one that decides whether a deployment is defensible. Article 11 of Law No. 6698 lists the rights of the data subject. Sub-paragraph (g) gives everyone the right to object to a result arising against them through the analysis of processed data exclusively by automated systems.
Not a right to an explanation. Not a right to be informed. A right to object to the outcome. That single provision is the reason the design question in this area is never “is the model accurate enough” but “where is the human, and what can they actually change”.
This is the fifth part of a series on the legal consequences of a company’s move to artificial intelligence, following the board decision, the vendor contract, the data going in and the workplace.
The word that carries the weight is “exclusively”
The provision bites where the analysis is exclusively automated. That is the hinge, and it is also where most companies quietly fail, because they believe they have a human in the loop when what they have is a human at the end of it.
A reviewer who sees a score and a recommendation, has no access to the underlying factors, processes forty cases an hour and overrides perhaps one in two hundred is not making the decision. The record will show a human name against the outcome; the substance will show automation. If the question is ever examined, it is examined on substance.
Meaningful human involvement has recognisable features. The reviewer has authority to reach a different conclusion and is not penalised for using it. They see the inputs, not only the output. They have time proportionate to the consequence. And there is evidence — in the system, not in a policy document — that overrides happen at a rate consistent with genuine review.
Where this actually arises
Three processes account for most of it in Turkish companies. Hiring, where a screening tool ranks or filters applicants before anyone reads a file. Performance and compensation, where a model contributes to ratings, bonus allocation or the composition of a redundancy pool. And credit or pricing, where a score determines whether a customer is offered terms and on what basis.
Each of these produces a result against a person within the meaning of the provision. Each therefore needs the objection route to be real: a named point of contact, a defined period for response, and a process that can actually reverse the outcome rather than confirming it with a second automated pass.
The European layer, for companies that have one
Companies placing systems on the European market or serving European users acquire an additional classification problem, because employment, worker management and access to essential services including creditworthiness assessment sit in the high-risk category under the EU artificial intelligence framework, with obligations that run to documentation, human oversight, logging and conformity. We set out how that reaches Turkish-incorporated companies in the piece on extraterritorial application, and the domestic direction of travel in the analysis of Türkiye’s AI Action Plan.
The practical consequence for a Turkish company without European exposure is not that these obligations apply. It is that the same design features — documented oversight, retained logs, a tested objection route — are what the domestic framework already requires in substance through Article 11, and building them once serves both.
What to record before the system goes live
Four things, and they fit on a page. What the system decides or contributes to, expressed as an outcome for a person rather than as a technical function. Where the human sits, what they can see, and what they are empowered to change. How a person objects, to whom, and within what period. And what is logged, for how long, so that a specific past decision can be reconstructed if it is questioned.
Companies that have this page can answer a regulator, a claimant or a counterparty in a single meeting. Companies that do not spend months reconstructing from vendor telemetry what their own process was doing, and the reconstruction is rarely flattering.
The last part of the series turns to what happens when the output is simply wrong, and how loss is allocated between the company, the supplier and the provider of the underlying model.
Sources. Law No. 6698 on the Protection of Personal Data (KVKK). Statute links open the official consolidated Turkish texts on mevzuat.gov.tr.
This entry is for general information only and is not legal advice. How any of it applies depends on the company, the deployment and the agreements actually in place.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
More from Vircon Insights
Feeding Company Data to a Model: KVKK Basis, Transfer Abroad and the Trade Secret You Just Uploaded
October 5, 2026The Data Processing Agreement Under KVKK: How It Differs from GDPR Article 28 and What to Put in the Annexes
October 2, 2026When Does a Turkish Game Studio Need a UK or US Holding?
October 2, 2026TCC Article 376 for a Cash-Burning Startup: Capital Loss, Over-Indebtedness and the Board's Three Thresholds
October 1, 2026Raising Your First Round as a New Game Studio: The Chain of Title Problem When the Founders Still Work Elsewhere
September 30, 2026Hybrid Working Is Now in the Regulation: Article 9(2) of the Remote Working Regulation and What Contracts Must Say
September 27, 2026Related Practice Areas
Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →ICOs, Crypto & Blockchain
Crypto-asset regulation, token offerings, exchange and custody licensing.
View service →