While Türkiye’s framework AI law waits in commission and the EU AI Act’s deadlines dominate headlines, one regulator is already deciding AI cases in Türkiye today: the Personal Data Protection Authority. If your product profiles, scores, ranks, verifies or generates — KVKK is your operating AI regulator. Three fronts matter.
1. Automated decisions
KVKK Article 11 gives data subjects the right to object to a result that is produced exclusively by automated analysis of their data and works against them. It is narrower than GDPR Article 22 — an objection right rather than a general prohibition — but it directly touches the standard startup toolkit: CV screening and candidate ranking, credit and fraud scoring, dynamic pricing, content moderation, account-suspension engines.
Practical consequences: build a human-review path for adverse automated outcomes, say in your privacy notice that automated analysis occurs, and be able to explain — at least at a system level — how the result was produced. “The model decided” is not an answer a regulator accepts.
2. Biometrics
The Authority’s 2026/921 principle decision on biometric attendance tracking is the template for how Turkish AI enforcement works: biometric data is special-category data, explicit consent does not cure a disproportionate system, and if a less intrusive alternative exists (a card, a code), the biometric route fails the necessity test. Read it once and you understand how the Authority will approach face recognition, voice ID and every “verify with your face” feature in your roadmap.
3. Training data and AI-generated content
Model training runs on data, and where that data relates to identifiable persons, all KVKK principles apply: lawful basis, purpose limitation, data minimisation, retention limits. Scraping Turkish users’ data for training without a lawful basis is a KVKK problem today, not a future AI-law problem. On the output side, Ankara is moving too: the November 2025 penal-code draft on AI-generated content and the Authority’s ongoing work on AI signal that synthetic-content questions will be answered through existing institutions before the framework law arrives.
A six-step KVKK-for-AI review
- Map every fully automated decision in your product that affects users; add a human-review path for adverse outcomes.
- Update privacy notices to name automated analysis and profiling explicitly, in Turkish for Turkish users.
- Run the 2026/921 proportionality test on any biometric feature — necessity first, consent second.
- Document lawful basis for every training dataset touching personal data; minimise and de-identify where possible (see our glossary on anonymization).
- Check whether your AI processing purposes are reflected in your VERBIS registration.
- Watch KVKK principle decisions the way you watch EU guidance — in Türkiye they arrive faster than legislation.
We cover KVKK’s AI-relevant decisions as they land — see the KVKK Tracker and our KVKK + GDPR compliance practice.
The four KVKK hooks, mapped to your product
| KVKK hook | Where it bites an AI product | First artefact to produce |
|---|---|---|
| Art. 11 — objection to automated results | Scoring, ranking and reject flows without human review | A human-review branch and a documented objection channel |
| Biometric data (special category) | Face/voice login, attendance tracking, age estimation from images | Necessity analysis — the Board reads “zorunluluk” narrowly |
| Legal basis for training data | Models trained on customer or scraped data | Basis memo per dataset + retention link to the envanter |
| Cross-border transfer | Prompts and telemetry flowing to foreign model APIs | SCC pack + five-business-day notification receipt |
Do we need consent to use AI on customer data?
Not as a default — consent is one basis among several, and often the weakest for systematic processing. Contract necessity and legitimate interest carry most product flows; what is non-negotiable is honest disclosure and, for special categories, a specific statutory basis.
Is a chatbot transcript personal data?
Almost always — users type names, orders and complaints into free text. Treat transcripts as personal data by design: retention limits, redaction before vendor calls, and inclusion in the processing inventory.
This week’s homework
Pick your highest-volume AI feature and produce the first-artefact column above for it — four documents, none longer than a page. That file is your answer to the customer questionnaire, the Board inquiry and the diligence request alike.
This article is for general information only and does not constitute legal advice. It reflects the position as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals — including crypto-asset infrastructure, fintech and games — bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call