Generative AI Guide (15 Soruda) — What KVKK Actually Said
On 24 November 2025, the Kurul published its first guidance written specifically for generative AI: Üretken Yapay Zekâ ve Kişisel Verilerin Korunması Rehberi, structured as answers to 15 questions. It is the document to read before Etken Yapay Zekâ (Agentic AI) Guidance — KVKK's March 2026 Framework — that later guide assumes this one's role-assignment logic and builds autonomy considerations on top of it.
Scope
The guide walks the full lifecycle of a generative AI system — training, fine-tuning, deployment, output generation — and evaluates each stage's personal-data processing against Law 6698. It explicitly covers content generation, usage areas, and the risk profile particular to generative systems, not just data protection in the abstract.
Who is the controller, who is the processor
This is the guide's most practically load-bearing answer. Role is not fixed by who built the model — it is determined by context, the scope of the processing activity, and who actually holds decision-making authority over purposes and means. The default pattern the guide describes:
- The company deploying/using the generative AI tool is generally the veri sorumlusu (data controller) — it decides why the tool is used and on what inputs.
- The platform/model provider is generally the veri işleyen (data processor) — it processes on the deployer's instructions, under contract.
This confirms the pattern already described in KVKK in Brief — for AI Builders: get the roles explicit in writing per deployment, not assumed from the vendor relationship.
What else the guide addresses
- Cross-border transfers inside generative AI workflows — read alongside Cross-Border Transfers After the 2024 Reform; a generative AI call to a foreign-hosted model is a transfer event like any other, subject to the Art. 9 framework.
- Lawful bases for processing at each lifecycle stage (training data collection, prompt processing, output storage) — these can differ stage to stage, so a single blanket lawful-basis analysis for "the AI system" is usually wrong; do it per processing activity.
- İlgili kişi (data subject) rights in a generative context — including how a subject exercises rights over data that shaped a model's outputs, not just data stored in a database.
- Risk framing: the guide names deepfakes, manipulative content, and misleading/false information as generative-AI-specific risks a controller's risk assessment should address, alongside the standard KVKK risk factors.
Why this belongs in the architecture, not just the compliance file
The role-assignment question above is exactly the kind of fact that goes stale silently — it depends on how a specific deployment is configured, not on the law itself. That is the Pattern 5 argument: record the lawful basis, roles, and data categories per use case, and keep that record's verification date honest.
This guide assumes a deliberately built or procured system. If the actual starting point is employees already pasting data into ChatGPT on their own, start instead at Employee Use of Generative AI Tools — a Different Problem Than Deploying One — a narrower, earlier problem most organizations have before they have this one.
---
Educational reference maintained by Avalanche AI — not legal advice. Verify against the current guide text at kvkk.gov.tr before relying on it.