Part of the AI Regulation News hub.
Turkey's data protection authority says in a guide for lawyers, which binds nobody by itself, that uploading client files to generative AI tools such as ChatGPT, Claude and Gemini may amount to a transfer of personal data abroad under Article 9 of Law No. 6698
The guide, which binds nobody by itself, says uploading a client file to a generative AI tool should not be regarded solely as technical support or legal research, and may constitute a transfer of personal data abroad under Article 9, depending on five factors.
Bottom line: This is a guide, and it binds nobody by itself. It does not call itself binding or non-binding; it describes itself as setting out the relevant legislation, solution proposals and good-practice examples. What it interprets is Law No. 6698, which the guide reads as already applying to lawyers who process personal data.
Who this affects: Turkish advocates and law partnerships, trainee lawyers and law office staff, legal operations and IT leads at Turkish firms, and data protection counsel who advise firms using generative AI tools on client matters.
Issue date: KVKK announced publication on 22 September 2026. The cover and imprint read Temmuz 2026 (July 2026), Ankara, KVKK Yayınları No: 115. We treat 22 September 2026 as the publication date.
What the guide says: In non-binding guidance, Section VIII.C, on generative AI tools, says uploading a file or document containing personal data to such a tool should not be regarded solely as technical support or legal research, and may constitute a transfer of personal data abroad.
Analysis: On our reading, the practical change is the diligence the guide expects before upload: the tool's terms, privacy policy, storage and processing locations, sub-processor terms and transfer mechanisms. A firm that cannot answer those questions cannot say whether Article 9 is engaged.
Primary sources: Avukatların Mesleki Faaliyetlerinde Kişisel Verilerin Korunmasına İlişkin Uygulama Rehberi (KVKK Yayınları No: 115, PDF) · KVKK announcement of publication, 22 September 2026
- Instrument (EN)
- Implementation Guide on the Protection of Personal Data in Lawyers' Professional Activities (Avukatların Mesleki Faaliyetlerinde Kişisel Verilerin Korunmasına İlişkin Uygulama Rehberi)
- Authority
- Kişisel Verileri Koruma Kurumu (Personal Data Protection Authority, KVKK). The guide says it was prepared by the Authority, drawing on the views and contributions of Türkiye Barolar Birliği (Union of Turkish Bar Associations)
- Jurisdiction
- Turkey
- Status
- Published. KVKK announcement dated 22 September 2026; cover dated Temmuz 2026 (July 2026)
- Bindingness
- Guidance. Binds nobody by itself; we found no Board decision number on it. It interprets Law No. 6698, whose Articles 8, 9 and 12 are binding law
- Issue date / next deadline
- Published 22 September 2026. We found no compliance date or transition period in the sections we read
- Document
- KVKK Yayınları No: 115, 158 pages. Generative AI section VIII.C at pages 120 to 122; data security passage at pages 145 to 146
- Legal basis
- Law No. 6698 on the Protection of Personal Data: Article 8 (transfers within Turkey), Article 9 (transfers abroad, as amended by Law No. 7499) and Article 12 (data security)
- Primary source
- https://www.kvkk.gov.tr/SharedFolderServer/CMSFiles/MTZhYjI0ZTE1NWIwMWM.pdf
What the guide says about uploading client files
Section VIII.C, headed "Üretken Yapay Zekâ Araçları Kullanımı ve Kişisel Verilerin Aktarılması", opens by naming the tools. Because this is guidance without binding force, what follows is the Authority's reading of the law and creates no new rule. In our translation, it says that where lawyers upload client files, case documents or documents containing personal data to generative AI tools such as ChatGPT (OpenAI OpCo, LLC), Claude (Anthropic) or Gemini (Google LLC), processing of those data over the provider's technical infrastructure will arise (page 120).
The next step is conditional. Where the provider is resident abroad, its servers are abroad, or data are processed through sub-service providers abroad, a transfer of personal data abroad within the scope of Article 9 "söz konusu olabilecektir", in our translation may be at issue.
The section's central sentence spans pages 120 and 121. The guide says uploading such a file should not be regarded solely as obtaining technical support or conducting legal research, and that it should be borne in mind that the activity may constitute a transfer abroad, judged against five factors: the tool's technical infrastructure, its data retention policy, the provider's country of residence, the location of its servers, and the location of its sub-service providers. That is our translation; the Turkish original is reproduced in the quotation on this page.
The operative verb is "teşkil edebileceği", may constitute. The guide does not say every upload is a transfer abroad.
Why a domestic provider does not close the question
Page 121 turns to providers based in Turkey. Even where the provider is resident in Turkey and the data are processed in Turkey, handing over files containing personal data "veri aktarımı niteliği taşıyabilecektir" on the guide's account, in our translation may have the character of a data transfer under Law No. 6698.
For that case the register softens, to "tavsiye edilmektedir", it is recommended. What is recommended is acting in line with Article 8 on transfers within Turkey and assessing separately the legal basis of the transfer, its purpose, the categories of data involved and its proportionality. Because this is a guide, that recommendation binds nobody; Article 8 itself is current law.
The diligence the Authority expects before an upload
Still on page 121, and still in non-binding guidance, the guide lists what a lawyer is expected to review, and here it uses the stronger "gerekmektedir", it is necessary: the tool's terms of use, its privacy policy, its data processing terms, its statements on where data are stored and in which countries they are processed, its sub-processor provisions, and any mechanisms for transfer abroad. If that review shows a transfer abroad is taking place, compliance with the transfer conditions in Article 9 "sağlanmalıdır", in the guide's words should be ensured.
Those conditions come from the statute itself. Pages 115 to 119 reproduce Article 9 as amended by Law No. 7499, which the guide says was published in the Official Gazette of 12 March 2024. Under that text, and subject to any special provisions in other laws that paragraph 10 preserves, the general route for a transfer abroad needs a processing condition under Article 5 or 6 plus a Board adequacy decision; failing that, a processing condition under Article 5 or 6 again, together with one of the appropriate safeguards in paragraph 4, such as a Board-announced standard contract or Board-approved binding corporate rules, and the data subject's ability to exercise rights and seek effective remedies in the destination country; failing both, one of the incidental derogations in paragraph 6. Article 9(5), as reproduced, requires a standard contract to be notified to the Authority by the controller or processor within five business days of signature. Those are statutory requirements, not guidance.
Pages 121 and 122 also point readers to four earlier Authority publications on AI, which the guide, again as guidance, says need to be taken into account when assessing risk and choosing technical and administrative measures: a document on generative AI tools in the workplace (February 2026), an information note on chatbots using ChatGPT as the example (June 2025), a guide on generative AI and personal data in 15 questions (November 2025), and recommendations on personal data protection in AI (April 2025).
Security measures: masking, minimisation and firm rules
The guide, still as guidance, comes back to AI in section XI on data security. At pages 145 and 146 it says the use of ChatGPT, Claude, Gemini and similar tools in professional work also has to be assessed separately against data security obligations, and it restates that lawyers' duty under Article 12 to take the technical and administrative measures needed to prevent unlawful processing and access, and to safeguard personal data, continues.
What it lists after that is framed as important, not mandatory. In our translation, it says it is important that personal data be masked or anonymised as far as possible, that uploading special categories of personal data be avoided, that only the minimum data needed for the purpose be shared, that the tool's policies on data retention, model training, human review, sub-processors and security be reviewed, and that internal rules on using these tools be set within the organisation or law office.
Article 12 is binding law. The list of measures is the guide's advice about how to meet it. On our reading, a firm could meet Article 12 by other means.
Publication date, and how this differs from the bar's own AI guide
The cover and imprint page read "Temmuz 2026, Ankara". The PDF's embedded creation date is 19 August 2026, and the Authority's announcement is headed "Yayınlanma Tarihi: 22 Eylül 2026, Salı", publication date Tuesday 22 September 2026. We date the event to the announced publication. The Authority's announcement lists the use of generative AI tools among the subjects the guide covers.
This is not the Türkiye Barolar Birliği recommendation guide on AI for lawyers, which the bar shared on 20 June 2026 and which we have covered separately. That document came from the profession's own body. This one is a data protection authority publication; the guide says at page 12 that the Authority prepared it and drew on TBB's views and contributions, in the framework of a cooperation protocol signed on 14 December 2022.
It is also narrower than the Authority's general November 2025 guidance on generative AI. The subject here is lawyers as data controllers: the guide takes the position at page 43 that lawyers practising independently are data controllers for the personal data of clients and third parties they process in professional work.
What we did not verify
What we opened: the full 158 page PDF of KVKK Yayınları No: 115 from kvkk.gov.tr, re-fetched on 23 September 2026 and byte-identical to the copy we worked from, and the KVKK announcement page dated 22 September 2026 that links to it. We read the table of contents, the introduction at pages 11 and 12, the statement of purpose at page 27, parts of the controller analysis at pages 39 to 48, section VIII on transfers at pages 113 to 122, the data security passage at pages 145 and 146, and the recommendations at pages 147 and 148. We did not read every page of the guide.
What we did not open: the four earlier KVKK AI publications the guide cites at footnotes 97 to 100, the official text of Law No. 6698 and of Law No. 7499 (we rely on the guide's reproduction of Article 9), the implementing regulation on transfers abroad, any Board decisions the guide cites, and any statement by Türkiye Barolar Birliği about this guide.
What we refuse to claim: we do not say that uploading a client file to an AI tool is a transfer abroad, because the guide says it may be one, depending on five factors. We do not say the guide bans or approves any named tool, that it is binding or enforceable in itself, that any sanction attaches to ignoring it, or that it classifies AI providers as data processors, which section VIII.C does not do. We do not state when the amended Article 9 took effect, because we read it only as reproduced in the guide, and we make no claim that this is the first guidance of its kind.
Translations from Turkish are our own and are labelled as such. The quotation on this page is reproduced in the original Turkish, joined across the page break at pages 120 and 121 and across two end-of-line hyphenations, with no words changed or omitted.
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Before anyone at a Turkish firm puts a client file into a generative AI tool, someone should be able to say where that provider stores and processes the data, who its sub-processors are, and which Article 9 route any transfer abroad would run on. The guide binds nobody, but it tells lawyers how the Authority reads a law that already applies to them.
Source File
https://www.kvkk.gov.tr/SharedFolderServer/CMSFiles/MTZhYjI0ZTE1NWIwMWM.pdf
Open KVKK Yayınları No: 115 and confirm four things: the publication date on the KVKK announcement page (Icerik/8990), section VIII.C on generative AI tools at pages 120 to 122, the Article 12 data security passage at pages 145 and 146, and the statement at page 12 that the Authority prepared the guide with TBB's views and contributions.
Bu nedenle, yapay zekâ aracına kişisel veri içeren dosya veya belge yüklenmesi yalnızca teknik destek alınması veya hukuki araştırma yapılması olarak değerlendirilmemeli; bu suretle gerçekleştirilen faaliyetin, kullanılan üretken yapay zekâ aracının teknik altyapısı, veri saklama politikası, hizmet sağlayıcının mukim olduğu ülke, sunucuların bulunduğu yer ve alt hizmet sağlayıcıların konumu dikkate alınarak kişisel verilerin yurt dışına aktarımı teşkil edebileceği göz önünde bulundurulmalıdır. · KVKK Yayınları No: 115, Bölüm VIII.C, s. 120-121, published 22 September 2026
FAQ
Does the guide stop Turkish lawyers using ChatGPT, Claude or Gemini?
No. The guide, which has no binding force, names those tools as examples and does not prohibit any of them. It says uploading files that contain personal data may amount to a transfer of personal data, abroad under Article 9 or within Turkey under Article 8, and sets out what a lawyer is expected to review before doing so.
Is the guide binding?
Not by itself. It is an Authority publication on which we found no Board decision number, and it describes itself as setting out the relevant legislation, solution proposals and good-practice examples. The provisions it interprets, Articles 8, 9 and 12 of Law No. 6698, are binding law.
What if the AI provider is based in Turkey and keeps data in Turkey?
The guide says the upload may still have the character of a data transfer under Law No. 6698, and recommends acting in line with Article 8 and assessing the legal basis, purpose, data categories and proportionality of the transfer.
What does the guide suggest doing before an upload?
In non-binding terms, the guide expects a review of the tool's terms of use, privacy policy, data processing terms, data storage and processing locations, sub-processor terms and transfer mechanisms. For data security it calls it important to mask or anonymise data as far as possible, avoid special categories of data, share only the minimum needed, and set internal rules for the tools.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.