Turkey KVKK Issues Generative AI Data-Protection Guidance | TLY

AI Regulation Tracker  /  Data protection and privacy

Turkey's KVKK Puts Generative AI Squarely Under Its Data-Protection Law

The guidance is non-binding, but the message is not soft. On November 24, 2025, Turkey's Personal Data Protection Authority published a fifteen-question guide that treats generative AI as fully subject to the country's data-protection law, Law No. 6698, at every stage of the model lifecycle. It tells data controllers what the regulator expects before enforcement ever starts.

The Leveraged Years AI Regulation News

There is a pattern worth naming, and Turkey just added to it. Around the world, data-protection regulators are not waiting for a dedicated AI statute before they act on generative AI. They are reaching for the privacy law already on the books and saying, plainly, that it already applies. On November 24, 2025, Turkey's Personal Data Protection Authority, the KVKK, did exactly that. It published a guide, framed as fifteen questions and answers, on generative AI and the protection of personal data, and it evaluates generative AI processing within the framework of Turkey's existing data-protection law, Law No. 6698.

Is this binding law?

No, and it is important to be precise about that. This is a guide, not a regulation and not a fine. It does not, by itself, create a new binding obligation on anyone. What it does is tell you how the regulator reads the law it already enforces. That distinction matters in practice because the KVKK does have real teeth under Law No. 6698, including administrative fines, and guidance like this is the map of how the authority is likely to apply those powers to AI. Treating it as "just guidance" and ignoring it is the kind of shortcut that looks fine until an investigation lands. The safer read is that the guide is the regulator telling you its expectations in advance.

What does the guide actually expect?

The core move is to apply data-protection law across the full generative AI lifecycle rather than at a single point. The KVKK's framing is that each phase of that lifecycle, from assembling training data through building the model to running it and using its outputs, needs to be planned and managed as a distinct processing activity. In practice that means a controller cannot lean on one blanket justification for the whole system. Each distinct processing activity may need its own lawful basis under the law, its own justifiable retention period, and its own risk assessment. The guide leans on the familiar toolkit of European-style data protection: purpose limitation, data minimization, transparency to the people whose data is used, privacy-by-design, and impact assessments. It also speaks to individuals directly, flagging what people should watch for when they use generative AI tools in daily life. The regulator's stated aim is that these systems be developed and used in a way that is human-centric, secure, and respectful of individual privacy.

Why a US attorney should care about a Turkish guide

Two reasons, and I want to keep them honest. The first is direct but narrow. If your client processes the personal data of individuals in Turkey through a generative AI system, Law No. 6698 is in play, and this guide is now the clearest statement of how the Turkish regulator will judge that processing. That is a real, if bounded, compliance concern for multinationals and for US firms with Turkish operations or users. The second reason is broader and, for most US practices, more useful. This guide is one more entry in a growing library of regulators reaching the same conclusion: existing data-protection law already governs generative AI, lifecycle by lifecycle, and you need a lawful basis and a retention justification at each stage. Turkey, the EU authorities, and others are converging on that structure. A US privacy lawyer building an AI data-governance program can treat these guides as a shared checklist, because the substantive expectations rhyme across jurisdictions even when the statute cited changes.

The practical move

If you advise on AI and privacy, map your client's generative AI use as a sequence of processing activities, not a single black box. Identify the lawful basis for training data separately from the lawful basis for operating the model and for using its outputs. Set and document retention periods you can defend. Build transparency and data-subject-rights handling into the design rather than bolting it on. That is what this guide asks for in the Turkish context, and it is very close to what the strongest privacy regulators everywhere are asking for. Doing it once, cleanly, satisfies most of them at the same time.

Questions professionals are asking

Is the KVKK generative AI guide legally binding?

No. It is interpretive guidance, not a regulation or a fine, so it does not create new binding obligations on its own. It sets out how the KVKK will apply Turkey's existing data-protection law, Law No. 6698, to generative AI. That underlying law is binding and enforceable, which is why the guidance matters in practice.

What law does it apply to generative AI?

Turkey's Personal Data Protection Law No. 6698. The guide treats generative AI processing as subject to that law across the full lifecycle, meaning training data, model building, deployment, and output use are each assessed as processing activities that may need their own lawful basis and retention justification.

Does it affect US law firms or companies?

Directly, only where you process the personal data of individuals in Turkey through generative AI. For most US practices its greater value is as a benchmark: it is one more regulator confirming that existing data-protection law already governs generative AI, so an AI data-governance program built to that structure will travel across jurisdictions.

What should controllers do in response?

Map generative AI use as a sequence of distinct processing activities rather than one system. Establish and document a lawful basis and a justifiable retention period for each stage, build in transparency and data-subject-rights handling, and run impact assessments. That aligns with the KVKK guide and with the wider convergence among privacy regulators.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how any guidance or law applies to your situation with qualified data-protection counsel in the relevant jurisdiction.