Legislation Categories
Legislative Updates
Here you can access most recent articles on legislative updates regarding Personal Data Protection Law, Social Security Law, Taxation Law, Occupational Health and Safety Law, Code of Obligations, Labor Law, Turkish Commercial Code, Law on Protection of the Value of Turkish Currency, Foreign Exchange Legislation, and Immigration Law in Türkiye.
Bilateral Treaties
You can access the dates of the most recent international bilateral social security and double taxation treaties made between Türkiye and other countries and relevant documents here.
Test
12 August 2025
Artificial intelligence systems, with their rapid development in recent years, have not only brought about a technical transformation but have also created new areas of debate regarding fundamental rights and freedoms, especially the right to the protection of personal data. In particular, in scenarios such as automated decision-making, profiling, and bias generation, personal data processing activities have become systemic, making a regulatory framework in this area inevitable.
The guide titled “Recommendations on the Protection of Personal Data in the Field of Artificial Intelligence”, published by the Personal Data Protection Authority in April 2025, provides a comprehensive framework to address this need. The guide defines specific areas of responsibility for developers, manufacturers, service providers, and decision-makers, aiming to ensure that AI systems are developed and implemented in compliance with Law No. 6698 and the relevant legislation.
In this article, in light of the guide in question, the principles, obligations, and practical recommendations regarding the protection of personal data in AI systems are revisited, offering a guiding perspective for all relevant actors.
The guide emphasizes that in the processes of developing and implementing AI systems, all activities related to personal data processing should be carried out within a framework based on human rights, data security, and transparency. The main principles set out in the guide are as follows:
Developers, manufacturers, and service providers involved in all processes from the development to distribution, deployment, and updating of AI systems bear direct responsibility for the protection of personal data. The guide also includes several recommendations for these actors:
Managers, public authorities, or senior private sector representatives who decide to use or integrate AI systems within their organizations cannot leave responsibility for personal data protection solely to technical teams. According to the 2025 guide of the KVKK, the following principles apply to this group:
The fact that AI systems have become structures that directly affect individuals’ private lives and personal data has made it necessary to evaluate these systems not only technically but also legally, ethically, and in terms of governance. The guide published by the Personal Data Protection Authority in April 2025 offers an important and constructive starting point in this context. The clear definition of separate areas of responsibility for developers, manufacturers, decision-makers, and service providers is a first in the context of implementation in Türkiye.
Although the guide does not introduce directly binding regulations on topics such as automated decision-making, explainability, and human intervention, considering that previous decisions and practices of the Board explicitly reference the General Data Protection Regulation (GDPR) and the guidelines of the European Data Protection Board (EDPB), it is clear that practices in these areas will also be instructive for the Turkish data protection regime.
In particular:
For this reason, it is important for all public and private institutions using or integrating AI to adopt a data protection compliance approach that not only adheres to current Turkish legislation but also takes GDPR standards into account, in order to be prepared for future audit processes.
In this context, all public and private institutions using or integrating AI should consider the following questions, alongside compliance with Turkish legislation, in line with GDPR standards:
The answers to these questions will form the basis not only for legal compliance but also for a trust-based digital transformation. You can access the relevant guide here.
These principles should form the foundation for building a strong data protection culture at both technical and organizational levels.
This article is based on the following official document:
Should you have any queries or need further details, please contact us here.
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.