KVKK, Turkey's data protection law numbered 6698, applies to AI and LLM use whenever a system processes personal data belonging to identifiable individuals, which includes prompts, uploaded documents, and any customer or employee records fed into a model. Companies need a lawful basis under KVKK Article 5 for ordinary personal data and a stricter basis under Article 6 for special category data such as health or biometric information before that data can be used in an AI workflow, and the 2024 amendment to KVKK, Law No. 7499, tightened the rules on sending personal data outside Turkey, which matters enormously for any cloud-based LLM. The KVKK Board, known as the Kurul, has issued guidance treating AI processing like any other data processing activity rather than creating a separate AI-specific regime, so existing KVKK obligations around consent, data minimization, and the appointment of a data controller representative all apply. Companies should inventory which AI tools touch personal data and confirm a lawful basis and, where data leaves Turkey, a valid transfer mechanism for each one. This overview is general information rather than a KVKK compliance opinion for a specific company. Nanobase AI, a Silicon Valley engineering team with Turkish market experience, helps companies map AI data flows against KVKK requirements.
KVKK does not distinguish AI from any other processing method
Turkey's data protection law, KVKK (Law No. 6698), was written before generative AI existed, and it does not contain an AI-specific chapter the way the EU AI Act does. Instead, it applies its existing rules to any processing of personal data belonging to an identifiable person, and an LLM prompt containing a customer's name, a patient's health note, or an employee's performance review is personal data processing exactly like storing it in a database. The absence of an "AI section" in KVKK does not mean AI use is unregulated; it means the general rules apply with no AI-specific carve-out or exemption.
The two-tier lawful basis structure
KVKK Article 5 sets the lawful basis conditions for ordinary personal data, including explicit consent, contractual necessity, and legitimate interest of the data controller, among others. Article 6 sets a stricter standard for special category data, which includes health, biometric, genetic, and certain other sensitive categories, generally requiring explicit consent or a specific legal exception. This matters directly for AI use because prompts and documents fed into an LLM frequently carry both types without the application design distinguishing between them.
| Data type in the prompt | KVKK basis needed |
|---|---|
| Customer name, email, order history | Article 5 basis (consent, contract, or legitimate interest) |
| Employee performance notes | Article 5 basis, with care around power-imbalance consent concerns |
| Patient health information | Article 6 basis, generally explicit consent or a specific legal exception |
| Biometric identifiers (voice, face) | Article 6 basis, same stricter standard as health data |
Most AI applications mix ordinary and special category data in the same prompt without the application distinguishing between them, which is exactly where KVKK exposure tends to hide.
What the 2024 amendment changed
Law No. 7499, which amended KVKK in 2024, most significantly restructured Article 9 governing cross-border data transfers, moving Turkey's regime closer to GDPR's adequacy-and-safeguards model rather than the narrower consent-based mechanism it replaced. For AI use specifically, this matters because most LLM providers, including OpenAI and Anthropic, process data on infrastructure outside Turkey, making every prompt sent to those services a cross-border transfer subject to the amended rules, covered in more detail for the OpenAI and Claude case specifically elsewhere in this series. The 2024 amendment is what makes routine commercial LLM use in Turkey a cross-border transfer question by default, not an edge case.
Building a KVKK-aware AI workflow
- Classify every AI use case by whether prompts can realistically contain personal or special category data, rather than assuming a technical or coding assistant is automatically exempt.
- Establish the Article 5 or Article 6 lawful basis for each use case before deployment, not retroactively.
- Confirm whether the LLM provider processes data outside Turkey, which is true for essentially all major commercial LLM APIs, and apply the required cross-border transfer mechanism.
- Apply data minimization and, where practical, PII masking before prompts reach any third-party model, reducing the volume of KVKK-regulated data in transit.
A company that gets the lawful basis and cross-border transfer mechanism right but skips data minimization is still compliant, but it carries more residual exposure than one that also reduces what leaves its own systems in the first place.
This is general information, not legal advice, and specific KVKK obligations should be confirmed with counsel familiar with Turkish data protection law.
Frequently asked questions
Does KVKK apply to a company outside Turkey using Turkish customer data?
Yes, KVKK applies based on whose personal data is processed and where the effects are felt, similar in spirit to GDPR's extraterritorial reach, so a foreign company processing Turkish individuals' data through an AI system is generally in scope.
Is there a Turkish KVKK Board guidance document specifically on AI?
The Kurul (KVKK's supervisory board) has issued general guidance and decisions relevant to automated processing and profiling, though it has not published a comprehensive AI-specific framework equivalent to the EU AI Act; existing KVKK principles are applied to AI cases as they arise.
Do internal, employee-only AI tools need the same KVKK treatment?
Yes. Employee data is personal data under KVKK regardless of whether the tool is customer-facing, and employee consent carries the same power-imbalance concerns it does under GDPR, making legitimate interest or another Article 5 basis often more defensible than consent alone.
How does KVKK relate to the EU AI Act for a Turkish company?
They address different things and can both apply simultaneously: KVKK governs the personal data processing itself, while the EU AI Act would only apply to a Turkish company's AI system if that system is placed on the EU market or its output reaches EU individuals, detailed in our analysis of the AI Act's reach outside the EU.
How Nanobase AI helps
Nanobase AI works with Turkish and international companies to structure AI deployments that satisfy KVKK's lawful basis and cross-border transfer requirements, including private, in-country model hosting where cross-border transfer risk needs to be minimized entirely. This is part of our AI security and compliance practice and our broader on-premise LLM deployment work.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.