Jump to

Whose Voice Is It Anyway? Voice Cloning Under Turkish Personality Rights, KVKK Biometrics and FSEK

Whose Voice Is It Anyway? Voice Cloning Under Turkish Personality Rights, KVKK Biometrics and FSEK

A Turkish game studio wants its beloved dubbing actor’s voice for a new character, but the actor retired, so the studio trains a voice model on old recordings instead. A marketing agency “features” a celebrity in an ad the celebrity never saw. A fintech’s onboarding call is opened by a cloned executive voice. All three are the same legal problem wearing different clothes: who owns a voice, and what does consent to yesterday’s recording say about tomorrow’s synthesis?

The Turkish stack: three protective layers

Personality rights (Civil Code Arts. 24–25) protect voice and likeness as attributes of the person: unauthorised commercial cloning is an infringement independent of any copyright question, remediable by injunction and damages. Data protection: a voiceprint used to identify a person is biometric data; a special category under KVKK requiring an explicit legal basis, and the KVKK Board’s biometrics line of decisions shows how narrowly “necessity” is read. Copyright (FSEK): the underlying recordings carry performer and producer rights, so training a model on old sessions engages neighbouring rights even where the voice itself is not a “work.” A licence to use a recording in a 2015 commercial is not a licence to synthesise new speech in 2026; purpose limitation cuts across all three layers.

The incoming labelling regime

Two regimes are converging on synthetic voice. The AI Act’s Article 50 (live since 2 August 2026) requires machine-readable marking of AI-generated audio and disclosure of deepfakes. On the Turkish side, the pending TCK amendment bill would require visible “AI-generated” labels on synthetic content with a six-hour takedown for infringing material and platform obligations enforced through BTK. Build voice features with labelling and revocation in the pipeline now; retrofitting provenance into shipped audio is close to impossible.

The contract that makes it lawful

If you commission or use voice cloning, paper it like a rights deal, not a service order: explicit consent naming synthesis as the use; scope by product, term and territory; a revocation mechanism and its consequences; compensation tied to usage; and a warranty chain covering the training recordings’ performer and producer rights. On the vendor side, ask where consent records live and what happens to the model when the licence ends.

Three layers, three remedies

Layer Source What triggers it Remedy profile
Personality rights Civil Code Arts. 24–25 Unauthorised commercial use of voice/likeness Injunction, material and moral damages, disgorgement
Data protection KVKK (special categories) Voiceprint used to identify a person Board fines, processing bans, deletion orders
Neighbouring rights FSEK (performers/producers) Training or synthesis from protected recordings Infringement damages up to three-fold, seizure

The consent clause, sketched

A synthesis consent worth the paper covers seven points: (1) named technology; “training of a voice model and generation of new speech,” not “use of recordings”; (2) scope, which products, which languages, which markets; (3) term and what happens to the model (not just the outputs) at expiry; deletion or escrow; (4) approval rights over sensitive contexts (politics, health, endorsement); (5) compensation structure; flat fee, per-use, or revenue share; (6) revocation mechanics and a wind-down period for shipped content; (7) warranty from whoever supplies the recordings that performer and producer rights are cleared. Put the same seven points, mirrored, into your vendor contract if a platform hosts the cloning for you; the gap between the two documents is where liability pools.

Is a sound-alike (human imitator) safer than a clone?

Not automatically; passing off a voice to suggest endorsement can still infringe personality rights and unfair-competition rules; the technology is not the test, the deception is.

Can we train on our own employees’ voices?

Only with genuinely free, specific consent; employment context makes consent fragile under both KVKK and GDPR, so pay for it separately and allow refusal without consequence.

This week’s homework

If any product feature speaks with a human-derived voice, locate the consent artefact that covers synthesis specifically. If it does not exist, stop expanding that feature until it does; this is the cheapest moment you will ever fix it.

Related: prohibited practices · AI Compliance Hub.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on KVKK and GDPR compliance, or book a call directly.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 26 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.