Your support team pipes customer tickets (names, order numbers, occasional complaints about health products) into a US-hosted model API for summarisation. Under KVKK, that is not “using AI.” That is an international transfer of personal data, and since the 2024 amendments it has a specific legal machinery most Turkish companies still have not wired up.
Step zero: is personal data actually leaving?
Three honest checks. Does the prompt or context window contain identifiable data (names, e-mails, IDs, free text about individuals)? Where is the inference endpoint hosted and where is support access located (the EU region of a US provider still involves the US parent in most support models)? And does your vendor agreement let the provider use inputs for training (for most enterprise API tiers, no; verify, screenshot, file)? If no personal data goes in, because you strip or pseudonymize upstream, the transfer analysis ends here, which is why a redaction layer is the highest-ROI compliance component in an AI stack.
The 2024 KVKK transfer toolkit, applied to model APIs
Since the March 2024 amendment, KVKK transfers work on a three-tier ladder. Adequacy decisions: none currently cover the US, so the workhorse is tier two. Appropriate safeguards: in practice the Board’s standard contractual clauses, signed with the provider or your reseller, with the uniquely Turkish twist that the executed SCCs must be notified to the Authority within five business days, an obligation with its own administrative fine attached. Tier three, the old explicit-consent route, survives only as an exception for occasional transfers. Building a product flow on it is design malpractice. Practically: map the flow (you → API provider → subprocessors), execute SCCs covering onward transfers, notify, and mirror it all in your aydınlatma text.
The GDPR overlay for your EU users
If EU-resident data rides the same pipeline, you are running a parallel GDPR analysis: EU SCCs plus a transfer impact assessment. The efficient pattern is one architecture serving both regimes: EU/TR-region endpoints where the vendor offers them, a single redaction layer, and one vendor data-processing addendum that covers both sets of clauses.
The transfer ladder for AI APIs
| Mechanism | Available for model APIs? | Key action | Trap |
|---|---|---|---|
| Adequacy decision | Rarely; none covers the US | Check the Board’s current adequacy list per destination | Assuming an EU region equals adequacy |
| Standard contractual clauses | Yes; the workhorse | Execute with provider/reseller; notify the Authority within 5 business days | Signed but never notified; a standalone fine |
| Binding corporate rules | Group-internal only | Relevant if you route via your own foreign affiliate | Approval timeline measured in months |
| Explicit consent | Exception, occasional transfers only | Reserve for one-off cases | Building a product flow on a revocable basis |
What a redaction layer actually strips
The highest-leverage component deserves specificity. Before the prompt leaves your infrastructure, a filter replaces direct identifiers (names, e-mails, phone numbers, national ID and IBAN patterns) with stable placeholders, drops free-text fields that are not needed for the task, and truncates conversation history beyond the current context. The mapping table stays inside your perimeter, so responses can be re-personalised on the way back. Done this way, most support-summarisation and drafting use cases send no personal data at all, which collapses the entire transfer analysis, shortens your DPIA, and gives the enterprise questionnaire a one-line answer. Budget: one engineer-week with off-the-shelf libraries, against a permanent reduction of your regulatory surface.
Our provider offers an EU region; does that solve KVKK?
It helps but does not end the analysis: remote access from outside Türkiye counts as transfer, and support/telemetry paths often cross regions. Ask the vendor where humans can access data from, not just where disks sit.
Do we need consent from every user to use an AI API?
No. Consent is the wrong instrument for a systematic flow. You need a lawful basis for the processing itself plus a transfer mechanism (SCCs) for the border crossing, and honest disclosure.
This week’s homework
Draw the actual data path of one AI feature: field-level input, endpoint region, subprocessor list, support access. If SCCs are missing or were never notified within the five-day window, that is your first fix. It is also the first document a diligence team will request.
Related: cross-border transfer · KVKK · AI Compliance Hub.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call