Single Blog Title

This is a single blog caption

Company Secrets Can Be Leaked with a Prompt: GDPR and Data Security Limits of AI Use in the Workplace

Company Secrets Can Be Leaked with a Prompt: GDPR and Data Security Limits of AI Use in the Workplace

Entrance

It is becoming increasingly commonplace in the workplace for a HR professional to upload dozens of resumes to an AI application and say, "Select the five most suitable candidates," for a sales representative to import a customer list into the system to create personalized emails, or for an accounting staff member to upload a payroll spreadsheet for error checking. Similarly, a lawyer uploading a case file, a doctor uploading a patient report, or a software developer uploading source code to a generative AI system can save significant time in just a few minutes.

However, the information entered into the AI ​​by the employee is not merely a "question" displayed on the screen. This information can be transmitted to the service provider's servers, stored in system logs, subjected to security reviews, transferred to servers in other countries, or used in model development processes depending on the nature of the service. Therefore, the use of artificial intelligence in the workplace is not only a matter of productivity; it is also a matter of personal data processing, data security, protection of trade secrets, and the employer's legal responsibility. The Personal Data Protection Authority also states that productive artificial intelligence systems come into intensive contact with personal data; and that it is important for these systems to be used in a transparent, auditable, secure, and human-centered manner.

Legal Framework to be Applied to the Use of Artificial Intelligence in the Workplace in Türkiye

In Türkiye, a comprehensive law regulating artificial intelligence systems in all aspects has not yet been enacted. Records of the Turkish Grand National Assembly show that the Artificial Intelligence Law Proposal dated 2024 is still in the committee stage. Therefore, the legality of using artificial intelligence in the workplace is currently assessed primarily through existing provisions on the protection of personal data, labor law, contract law, criminal law, trade secrets, and intellectual property.

The main legal grounds in this context are as follows:

  • Law No. 6698 on the Protection of Personal Data,
  • The provisions of the Constitution regarding the privacy of private life and the protection of personal data,
  • Articles 417 and 419 of the Turkish Code of Obligations No. 6098, concerning the protection of the employee's personality and the use of their personal data,
  • The provisions of the Labor Law No. 4857 regarding equal treatment, working conditions, and termination,
  • The provisions of the Turkish Penal Code regarding the unlawful recording, acquisition, and sharing of personal data,
  • Trade secrets, customer secrets, professional secrets, and confidentiality obligations
  • Employment contract, information security policy, and internal workplace regulations.

Article 417 of the Turkish Code of Obligations imposes on the employer the obligation to protect the employee's personality and to establish an order in the workplace that conforms to the principles of honesty. According to Article 419 of the same Code, the employer may only use the employee's personal data to the extent that it is related to the employee's suitability for the job or is necessary for the performance of the employment contract. Therefore, the use of artificial intelligence applications in the workplace does not allow the employer to collect unlimited data about employees or to analyze their behavior without limit.

Does inputting information into artificial intelligence constitute personal data processing?

An employee uploading customer names, phone numbers, email addresses, employee performance reports, resumes, photos, voice recordings, health information, payrolls, invoices, or court documents to an artificial intelligence system may constitute personal data processing.

The concept of "processing" under the Turkish Personal Data Protection Law (KVKK) is quite broad. Uploading, transferring, recording, classifying, analyzing, summarizing, or matching data with other information can all be considered data processing. The defense that the artificial intelligence system was used only temporarily or that the employee uploaded the information from their own account does not automatically absolve the employer of legal responsibility.

For example, if someone working in the sales department uploads their customer list to their personal AI account;

  • Personal data belonging to customers has been transferred to a third-party service provider,
  • The data has been removed from systems controlled by the employer,
  • If so, it has been forwarded to servers abroad,
  • The employer's retention and deletion policy has become unenforceable

it could be.

Therefore, the approach that "the employee did it from their own account, the company is not responsible" is not safe. Employers are obligated to provide training to their employees, establish usage rules, restrict access, and put in place the necessary monitoring mechanisms.

How are the fundamental principles of the Turkish Personal Data Protection Law (KVKK) applied in the use of artificial intelligence?

According to Article 4 of Law No. 6698, in the processing of personal data;

  1. Compliance with the law and principles of honesty,
  2. Being accurate and up-to-date when necessary,
  3. Processing for specific, explicit and legitimate purposes,
  4. Being relevant to the purpose for which they are committed, limited and proportionate,
  5. To be kept for the necessary period

Adherence to these principles is mandatory. These principles apply to all business processes that use artificial intelligence.

For example, instead of requiring the human resources department to upload all resumes of job applicants to the system for evaluation, it should remove identification, address, photo, and contact information that are not necessary for the evaluation. Because if the goal is to compare the professional qualifications of the candidates, processing the person's full address or identity number would not be proportionate.

Similarly, when preparing a response to a customer complaint, the customer's full name, phone number, address, and order number should not be entered into the system. Anonymized or generalized expressions such as "Customer A," "Order dated X," or "product price" can be used. The KVKK's 2025 Generative Artificial Intelligence Guide also recommends that directly or indirectly identifying data such as name, surname, address, phone number, and identity information should not be entered into artificial intelligence systems; and that anonymized and generalized descriptions should be used as much as possible.

Does Explicit Consent Solve Every Problem?

One common mistake in using artificial intelligence in the workplace is the belief that obtaining general explicit consent from employees or customers will render all data processing activities lawful.

However, explicit consent;

  • It should relate to a specific topic
  • It should be based on information
  • It must be explained by free will
  • It should not be made a mandatory condition for other transactions.

Due to the economic and hierarchical relationship between employee and employer, it must be further assessed whether the employee's consent is truly based on free will. A general and unlimited statement such as "All your workplace data can be processed by artificial intelligence systems" does not constitute a valid legal guarantee.

The employer must first determine whether the data processing is based on another legal ground stipulated in the Law. Grounds such as fulfilling a legal obligation, performing a contract, establishing or protecting a right, or legitimate interest provided that it does not harm fundamental rights, may be evaluated according to the specifics of the case. However, regardless of which legal ground is used, the principles of relevance to the purpose and proportionality remain in effect.

Risky AI Use Cases in Everyday Business Life

1. Uploading resumes to artificial intelligence

When a human resources employee uploads candidates' resumes to artificial intelligence, it results in the processing of a significant amount of personal data, including identity, contact information, photograph, education, work history, and references. The risk increases if the resume contains more sensitive information such as disability, health status, or criminal record.

Eliminating candidates solely based on AI scores can also lead to discrimination and erroneous decisions. Past biases in educational data can lead to systematically under-scoring certain age, gender, school, or regional groups. The GDPR Guide states that AI systems can produce erroneous and inconsistent outputs, recreate biases in educational data, and that some systems' decision-making processes can be "black box" in nature.

2. Automatic recording and summarization of meetings

Recording online meetings using artificial intelligence leads to the processing of employees' voices, images, and conversational content. Participants should be informed in advance about the recording and analysis.

Voice data is not biometric data in all cases. However, it can acquire the characteristics of biometric data if it is processed using special technical methods for the purpose of uniquely identifying or verifying a person's identity. The processing of special categories of personal data may also come into question if information about health, union activities, criminal investigations, or private life is discussed at the meeting.

3. Having payroll and personnel lists analyzed

Payroll records may contain information on wages, bank details, bonuses, deductions, leave, and social benefits. Uploading these documents to a publicly accessible AI system poses a serious data security risk. If error detection is required, the information should be anonymized, only closed systems approved by the institution should be used, and access permissions to the system should be restricted.

4. Creating marketing text from customer lists

If an employee uploads a customer list to AI and tells it to "create sales emails for these people," this could lead to the data being used for a purpose different from its original intended use. Just because customer information was collected to provide a service doesn't mean that data can be used for any kind of AI analysis and marketing activity.

5. Summarizing the case file or patient report

Case files, medical records, and consulting documents may contain not only personal data but also information that falls under the scope of trade secrets and client-patient confidentiality. Simply removing names is not always sufficient. The date of the incident, workplace, title, type of illness, or real estate information may allow for the indirect identification of the individual.

6. Uploading the source code to artificial intelligence

Software code can contain customer information, database connections, API keys, passwords, security vulnerabilities, and company trade secrets. If an employee transfers this information to an external system for code development purposes, it can lead to both a data security breach and the disclosure of trade secrets.

The Problem of Transferring Personal Data Abroad

Many AI service providers are based abroad and may process data on servers in different countries. If an employee uploads a file to a foreign AI system, depending on the terms and conditions, this could result in the transfer of personal data abroad.

According to Article 9 of Law No. 6698, data transfer abroad must be based on one of the following reasons: a decision of adequacy, appropriate safeguards, or exceptional transfer grounds applicable only in incidental cases. Appropriate safeguards include standard contracts published by the Authority and other legal transfer methods. With the amendments made in 2024, the data transfer regime abroad was restructured, and the new provisions entered into force on June 1, 2024.

Therefore, the employer's mere payment for the artificial intelligence application or acceptance of its terms of service does not automatically mean that the conditions for transferring data abroad under the Personal Data Protection Law (KVKK) have been met. The company must:

  • in which countries the data is processed
  • who the subcontractors are
  • whether the inputs were used in model training,
  • how long the data is stored,
  • how deletion requests are fulfilled,
  • data breach notification process

It needs to be reviewed.

Can an employer prohibit the use of artificial intelligence?

Within the scope of their management rights, employers may establish rules regarding the use of information systems in the workplace. They may completely prohibit certain artificial intelligence applications due to data security, customer confidentiality, protection of trade secrets, or industry obligations; they may only permit the use of approved corporate tools.

However, the imposed ban or restriction;

  • It should be based on an objective purpose,
  • This must be clearly and in advance communicated to employees
  • It should be related to the nature of the job
  • should be applied in moderation
  • It should be applied equally to employees in similar situations.

For example, a hospital prohibiting the uploading of patient information to publicly accessible AI systems might be justified and necessary from a data security perspective. However, secretly monitoring all digital activities of employees without any explanation would not be legally permissible.

Can an employer monitor an employee's use of artificial intelligence?

An employer may have a legitimate interest in ensuring information security, protecting company secrets, and monitoring the proper use of corporate systems. However, this authority is not unlimited.

The Personal Data Protection Board's decision numbered 2023/86 acknowledges that employers may monitor corporate emails under certain conditions to protect trade secrets and corporate communication tools. However, it states that monitoring should primarily be limited to communication traffic and suspicious activity; content review should only be undertaken when necessary. It is crucial that monitoring is limited to relevant personnel and for specific purposes.

In its decision numbered 2021/1187, the Board found that accessing corporate email accounts without informing employees was unlawful. The decision emphasized that prior notification to the employee is necessary, the intervention must be based on a legitimate purpose, a less intrusive method must not be available, the control must be limited to the purpose, and a fair balance must be struck between the interests of the employee and the employer.

These principles also apply to monitoring the use of artificial intelligence. If an employer wants to monitor which AI websites employees visit or which files they upload;

  • The purpose of the audit is,
  • scope,
  • method,
  • which data will be recorded,
  • storage time,
  • who can access it,
  • how to use the audit results

Employees should be informed about this in advance.

Could the use of artificial intelligence be grounds for dismissal?

An employee's use of artificial intelligence does not, in itself, automatically constitute grounds for justified termination. All the specific circumstances of the case must be considered when evaluating termination.

Especially;

  • whether there is a clear artificial intelligence policy in the workplace,
  • whether the employee was informed beforehand,
  • the nature of the uploaded data,
  • whether customer or employee data exists,
  • whether or not a trade secret has been disclosed,
  • whether actual or potential damage has occurred,
  • employee's intent or negligence,
  • whether the violation was repeated or not,
  • whether a warning was given previously,
  • how the employer behaved in similar situations

It should be evaluated.

For example, if data security training has not been provided, approved tools have not been demonstrated, and the prohibition has not been explicitly stated, applying immediate termination for justifiable reasons at the first breach may be considered disproportionate. Conversely, if an employee uploads the identity and financial data of thousands of customers to an external system despite a clear prohibition, or knowingly discloses company secrets, more severe disciplinary sanctions may be considered.

Furthermore, digital evidence supporting the termination must be legally obtained by the employer. Using data obtained through unlawful and covert surveillance could create a separate personal data breach and a violation of privacy.

Employee Performance Evaluation with Artificial Intelligence

It is becoming increasingly common for artificial intelligence systems to create performance scores for employees by analyzing their email traffic, task completion time, online time, sales volume, customer interactions, or keyboard activity.

However, evaluating employee performance solely through automated systems carries significant legal risks. The system;

  • You may use incomplete or incorrect data
  • Disability can be indirectly affected by factors such as age, gender, or family circumstances
  • It may only consider measurable activities, not the quality of the work
  • They may not be able to explain the reason for the decision.

Therefore, AI output alone should not be the sole determining factor for salary, promotion, disciplinary action, or termination decisions. A genuine and effective assessment must be made by a human; the employee must be informed of the basis for the decision and be able to object to erroneous data. Article 11 of the Personal Data Protection Law also grants individuals the right to object to a result that is detrimental to them, obtained solely through analysis by automated systems.

Employer's Responsibilities Regarding Data Security

According to Article 12 of Law No. 6698, the data controller is:

  • to prevent the unlawful processing of personal data,
  • to prevent unlawful access to personal data,
  • to ensure the protection of personal data

The employer must take the necessary technical and administrative measures for this purpose. If the employer works with an artificial intelligence service provider that processes data on its behalf, the employer may also share responsibility with the service provider regarding security measures.

To establish a secure artificial intelligence system in the workplace, at least the following measures should be taken:

  1. The types of artificial intelligence tools that are permitted and prohibited should be clearly defined.
  2. Data classification should be performed for customer, employee, patient, client, and financial data.
  3. Corporate accounts should be used instead of publicly accessible personal accounts.
  4. Institutional options that prevent the use of data in model training should be preferred.
  5. Personal data must be anonymized before being entered into the system.
  6. Access permissions should be limited to the task at hand, and multi-factor authentication should be used.
  7. File uploading and data export activities should be meticulously recorded.
  8. Artificial intelligence outputs must be validated by humans.
  9. A breach notification procedure should be established for cases of faulty output, data leaks, or incorrect uploads.
  10. Employees should receive regular training on artificial intelligence and GDPR.

How should a workplace policy for the use of artificial intelligence be prepared?

It is often insufficient for an employer to simply publish a one-sentence announcement stating, "The use of artificial intelligence is prohibited." An effective AI usage policy should clearly regulate the following:

Free use areas

Low-risk tasks can be identified, such as correcting general texts that do not contain personal data or company secrets, generating ideas, summarizing publicly available information, and preparing sample templates.

Areas of use subject to permission

Activities such as the analysis of anonymized customer data, code development, meeting summarization, and human resources processes may require the permission of the unit manager or data protection officer.

Prohibited data

Uploading identification numbers, health information, biometric data, bank information, passwords, customer lists, payroll, case files, patient records, trade secrets, source code, and confidential contracts to unauthorized systems may be explicitly prohibited.

Human control

Regulations should be put in place to prevent the use of AI-generated legal opinions, financial calculations, performance scores, recruitment recommendations, or customer responses without verification by an authorized person.

Breach notification

If an employee accidentally uploads personal data, they should immediately report it to the information security or legal department instead of concealing it. Early notification is crucial for data deletion and limiting harm.

Conclusion

The legal limits on the use of artificial intelligence in the workplace are less about whether the technology is used at all, and more about which data is used, for what purpose, and under what security conditions.

An employer's complete unchecking of artificial intelligence could lead to the uncontrolled transfer of customer data, employee information, and trade secrets to external systems. Conversely, continuously and secretly monitoring employees without any notification could also constitute a violation of the law in terms of personal data protection, privacy, and freedom of communication.

The fundamental principles of a lawful workplace AI system are as follows:

  • A clear and legitimate purpose of use,
  • A valid condition for processing personal data,
  • Using a minimum amount of data,
  • Informing employees and relevant parties,
  • Compliance with the terms and conditions for transferring funds abroad,
  • Taking technical and administrative security measures,
  • Human oversight of artificial intelligence outputs,
  • Training employees with a clear and understandable policy.

A single command entered into an AI application may seem like a process lasting only a few seconds. However, if that command contains customer names, health reports, payroll records, court documents, or company secrets, that few-second process can escalate into a long-term GDPR violation, loss of trade secrets, and serious legal liability for the employer. Therefore, the fundamental rule in the workplace should not be "Don't use AI," but rather "Don't upload personal data and company secrets to unapproved systems . "

Leave a Reply

Call Now Button