Single Blog Title

This is a single blog caption

Data Security in the Age of AI: GDPR Risks for Companies Using ChatGPT and LLM Tools

Artificial intelligence, and particularly Large Language Models (LLMs), has revolutionized the business world. Today, models like ChatGPT developed by OpenAI, Anthropic's Claude, Google's Gemini, and native AI models trained in-house by companies have become indispensable tools for increasing operational efficiency, accelerating coding processes, performing text analysis, and automating customer relationships.

However, this technological leap has brought with it a huge legal gray area and data security vulnerability. Text pasted into the ChatGPT interface by an employee to summarize an internal company report, a programmer sending a code block containing personal data to AI for debugging, or a human resources department using AI algorithms to filter hundreds of job applications, all unknowingly expose companies to severe penalties under the Law No. 6698 on the Protection of Personal Data (KVKK)

The working principle of artificial intelligence systems is to train and optimize themselves with continuously fed "input" (prompt) data. This creates the risk that personal data, trade secrets, and strategic information entered into the system may become part of the AI ​​provider's data pool, thus leading to an uncontrollable data leakage. In light of the European Union's Artificial Intelligence Act (AI Act) and the decisions of the Personal Data Protection Board (Board) in Türkiye, the uncontrolled use of LLM tools in corporate structures is now not only a cybersecurity vulnerability but also a direct legal violation.

This comprehensive legal review will address the key GDPR risks faced by companies integrating artificial intelligence, the impact of the revised international data transfer regime on AI tools, department-based risk scenarios, and the administrative and technical measures that should be taken to avoid heavy administrative fines.

1. Basic Concepts: The Relationship Between Artificial Intelligence, LLM, and Personal Data

To analyze the legal standing of artificial intelligence tools under the Turkish Personal Data Protection Law (KVKK), it is first necessary to define the architecture of these systems from a legal perspective.

1.1. Input (Prompt) Data and Personal Data Matching

Any command, text, file, or code that a user types into the chat box of the LLM interface, uploads, or sends to the system via an API (Application Programming Interface) input (prompt) . If this input includes a customer's name, email address, financial history, an employee's performance report, or a patient's health information, it is legally considered a "personal data processing" activity.

1.2. Legal Status of the AI ​​Provider: Data Controller or Data Processor?

One of the biggest mistakes companies make is viewing global AI companies like OpenAI as simply "software providers" or "data processors." However, the situation varies depending on the version used:

  • Use of Individual/Free Web Interfaces: If company employees use public web interfaces like ChatGPT with their personal accounts or free corporate accounts, the AI ​​provider stores these inputs to retrain the model, improve the algorithm, and process them for its own business purposes. In this scenario, the AI ​​company is a Data Controller. Control of the data completely leaves the Turkish company.

  • Enterprise APIs and Enterprise Deployments: When companies acquire AI services through paid API integrations or “Enterprise” subscription agreements, providers typically commit that the inputs will not be used to train the model and will only be processed on demand. In this scenario, the AI ​​company can legally be positioned as a Data Processor . However, the data flow and server locations behind these commitments need to be legally verified.

2. Key GDPR Risks in the Use of Artificial Intelligence

The nature of artificial intelligence tools directly contradicts the fundamental principles set forth in Article 4 of the Turkish Personal Data Protection Law (KVKK), which must be adhered to in all data processing activities.

2.1. Data Minimization and Violation of the Principle of Limitation to Purpose

The Turkish Personal Data Protection Law (KVKK) mandates that personal data be processed only for specific, explicit, and legitimate purposes, and in a manner that is limited, proportionate, and relevant to those purposes. However, when data is uploaded to an LLM (Learning-Learning Module), the data controller (company) cannot know how the AI ​​will process that data in the background, which tokens (semantic particles) it will divide it into, and which weighting matrices it will associate it with. Exceeding the intended purpose and feeding excessive data into the system constitutes a clear violation of the principle of proportionality.

2.2. Data Leakage in Prompt Inputs

If a company employee pastes the text of a customer's complaint letter verbatim into an artificial intelligence system to respond, this constitutes the transfer of data to an unauthorized third party (the AI ​​company). This directly violates the obligation to take technical and administrative measures to ensure data security (Article 12 of the Turkish Personal Data Protection Law). Numerous global incidents have proven that sensitive data previously entered by users as prompts has been generated and disclosed by artificial intelligence as "responses" in searches conducted by other users.

2.3. The Right to Be Forgotten and the Dilemma of LLM Architecture

According to Article 7 of the KVKK (Law on Protection of Personal Data), personal data must be deleted, destroyed, or anonymized when the reasons requiring its processing cease to exist. Similarly, citizens have the right to request the deletion of their data by applying to companies (Article 11).

The Structural Dilemma of Artificial Intelligence: In traditional SQL-based databases, deleting a row takes seconds. However, if personal data is included in the training data of an LLM model, and the model has "learned" this data with billions of parameters, it is technically almost impossible to extract that data from the model's memory (Machine Unlearning). Completely removing data from a model could mean retraining the model from scratch, which costs millions of dollars. Therefore, personal data mixed into the training data becomes a direct and permanent GDPR violation because it cannot be deleted.

2.4. Transparency, the Black Box Problem, and the Obligation to Inform

Data controllers are obligated to inform the individuals whose data they process. However, artificial intelligence models with deep learning architecture are "black boxes." Even the company's own IT department cannot fully explain the stages the data passes through, the algorithmic logic used in its processing, and the resulting output. The lack of transparency makes it impossible to prepare a legally compliant and auditable data protection document.

3. Artificial Intelligence Tools and the New International Data Transfer Regime (KVKK Article 9)

In Turkey, the most critical, dangerous, and overlooked legal risk for companies using artificial intelligence on data transfer abroad . Popular AI tools used today, such as ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), Midjourney, and Microsoft Copilot, all have their headquarters abroad (primarily in the US and Europe) and their cloud servers are located outside of Turkey.

The moment you type a single sentence containing personal data into an AI chat screen and press the "Send" button, that data is transmitted across our borders via the internet to servers abroad.

3.1. “Explicit Consent” Is Not a Sustainable Method

In line with the reforms made to Article 9 of the Turkish Personal Data Protection Law (KVKK), data transfer abroad has been made in accordance with European Union (GDPR) standards. In the past, companies could operate with the logic of, "I obtained explicit consent from the customer/employee for international data transfer, therefore I can use ChatGPT." However, in the new era, explicit consent is only an exception for one-off and temporary (incidental) situations that are not continuous. Regularly conducting internal operations, customer support systems, or HR processes with an artificial intelligence tool constitutes continuous data processing and cannot be considered incidental. Therefore, it is no longer possible to legalize these processes with explicit consent.

3.2. Solution: Standard Contracts (SCC) and AI Providers

Under the new legislation, in order for continuous data transfer to a country (such as the USA) that does not have a qualification decision, it is mandatory for the parties to sign the standard contractual clauses (Standard Contractual Clauses – SCC) announced by the Board .

  • The problem: Technology giants like OpenAI or Google are reluctant to sign Standard Agreements specifically tailored to Turkey's GDPR legislation for individual users or standard SME-sized enterprise clients. Instead, they impose their own global "Data Processing Addendums" (DPA) and GDPR-compliant SCCs. However, these documents are invalid under Turkish law unless directly approved or notified to the Personal Data Protection Authority.

  • Exception (Enterprise Solutions): Only in very large-scale enterprise procurements or when using OpenAI services via Microsoft Azure, can certain privacy and regional data residency commitments be obtained. However, even in these cases, the signed Standard Agreements within 5 business days . Companies that fail to make this notification will be penalized with heavy administrative fines for illegal data transfer abroad, even if no data leakage occurs.

4. Risk Matrix of AI Usage Models for Companies

The methods that companies can choose when using artificial intelligence tools and their levels of compliance with the Turkish Data Protection Law are shown comparatively in the table below:

Artificial Intelligence Usage Model Where the data is stored Model Training Risk Situation International Transfer Risk GDPR Compliance Level
Free / General Web UI (e.g., Free ChatGPT) Provider's Global Servers Very High (Inputs used to train the model) %100 (Data is sent directly abroad) Strictly Illegal (Personal data cannot be entered)
Enterprise API Integration (e.g., OpenAI API) Provider's Servers (Cloud) Low (Training can be terminated by contract) High (Data is transferred abroad depending on the data server location) ⚠️ Risky/Strict Contract and SCC Notification Required
Local / On-Premise LLM (e.g., Llama 3 installed on a company server) The company's own secure servers No (Data is entirely under company control) Zero (Data remains within the borders of Turkey) Fully Compliant (The most secure corporate method)

5. Department-Based AI Use Cases and Legal Analyses

Let's examine the legal risk boundaries in the three departments where artificial intelligence is most frequently used within the company, using concrete examples.

Scenario A: Human Resources (HR) and CV Screening Processes

A company's HR department uploaded the resumes of 500 applicants for an open position to an LLM tool and instructed it to "sort these candidates by experience, select the top 10, and report your reasoning for selection.".

  • Legal Analysis: CVs contain a significant amount of personal data, such as the candidate's name, surname, date of birth, educational background, contact information, and even photograph. Uploading this data to a general AI tool constitutes unauthorized data transfer.

  • Risk of Automated Decision-Making: According to Article 11, paragraph g, of the Turkish Personal Data Protection Law (KVKK), individuals have the right to object to a decision resulting in an outcome detrimental to them solely through the analysis of processed data by automated systems. If a candidate's CV is reviewed and rejected entirely by an AI algorithm without any human intervention (human-in-the-loop), the candidate can legally appeal this decision, and the company must legally prove that this does not constitute algorithmic discrimination.

Scenario B: Software Development (IT) and Code Analysis

A senior software engineer at the company was unable to resolve an error in an API code that connected to the company's customer database and copied and pasted the code block into an AI assistant (e.g., GitHub Copilot or ChatGPT). However, the code block contained real customer names, phone numbers, and database access credentials that had been forgotten for testing purposes.

  • Legal Analysis: This situation constitutes a "Data Breach" . Personal data and critical company system passwords have been leaked. The company within 72 hours and to inform affected customers. Otherwise, it will face double penalties for both the leakage and the late notification.

Scenario C: Customer Service and Chatbot Integrations

The company has integrated an intelligent chatbot, powered by an LLM (Learning Management Center) model, into its website to instantly respond to customer complaints and requests. Customers request support by entering their membership information, shipping address, and the first six digits of their credit card into the chat window.

  • Legal Analysis: In scenarios like these, where it's impossible to predict what a customer will type, if the AI ​​model behind the chatbot sends data directly to a main server abroad without encryption (masking), the company is committing a structural GDPR violation every second. An intermediate filter software that detects and censors personal data (PII Masking) must be installed before these systems.

6. Technical and Administrative Measures to be Taken in Artificial Intelligence Integration

To ensure companies can benefit from the efficiency of AI while remaining within legal limits, they urgently need to implement the following compliance steps:

Corporate Artificial Intelligence GDPR Compliance Procedure

1. Preparation of Yair's Artificial Intelligence Usage Policy (AI Policy):Step 1.

A mandatory corporate policy document should be prepared and distributed to all employees with their signatures, specifying which AI tools can be used by which departments and under what conditions within the company. This policy should clearly state that "Entering customer, employee, or company data into free web interfaces is strictly prohibited.".

2. Transitioning to Corporate Accounts and API Model:Step 2.

Employees should be prevented from using AI with individual accounts. Corporate (Enterprise) accounts should be opened in the company's name, or an API model should be adopted. The "Prevent inputs from being used for model training" (Data Opt-Out) option should be activated in the AI ​​provider's panel, and data retention periods should be minimized.

3. Establishing the Data Masking and Anonymization Infrastructure (Technical Filter):Step 3.

A PII (Personally Identifiable Information) Gatekeeper/Masking software should be installed between the data traffic going from the company network or computers to artificial intelligence services . This technical filter should automatically detect data such as national identity number, phone number, and name that personnel type into the prompt, mask it as "[PERSONAL DATA]", and then send it to the artificial intelligence.

4. Establishing the Legal Framework or Localization for International Transfers:Step 4.

If the artificial intelligence tool used is a system with servers located abroad, the opportunity to sign Standard Contracts (SCCs) compliant with the GDPR legislation should be sought with the provider company, and if signed, it should be reported to the Board within 5 business days. If this cannot be done, for operations where sensitive data is processed, domestic artificial intelligence models with servers located in Türkiye or open-source (e.g., Llama 3, Mistral) local LLM architectures installed on the company's own servers should be preferred.

5. Updating the Information and Consent Forms:Step 5.

The company's existing Customer and Employee Data Protection Notices should be amended to include the following statement: "Some of your personal data may be processed through artificial intelligence algorithms and subcontracted AI service providers for the purpose of optimizing business processes and generating analytical reports," with a transparent explanation of the data processing logic and the algorithm's operating principles.

 

7. Current GDPR Penalties and the Cost of Artificial Intelligence Risks as of 2026

Fixed administrative fines imposed for KVKK (Personal Data Protection Law) violations increase significantly each year in line with the revaluation rate. Since uncontrolled data processing activities in artificial intelligence systems are often not limited to a single data breach but affect the data of thousands of users, penalties risk being applied directly at the upper limits.

  • Violation of Data Security Obligations (Article 12): In case of data leakage to an artificial intelligence tool, an administrative fine of 250,000 TL to 8,500,000 TL will be imposed due to failure to take technical and administrative measures

  • Violation of International Transfer Rules (Article 9): Penalty for unlawful transfer if data is sent to global LLM servers without the Board's permission or the assurance of the Standard Contract.

  • Failure to Submit Standard Contract Notification Obligation: Failure to notify the Board of the signed SCC text within 5 business days will result in a fixed penalty of up to 1,800,000 TL

8. Frequently Asked Questions (FAQ)

1. If we disable the “Chat History & Training” feature in ChatGPT's settings, will we completely eliminate the GDPR risk?

No, the risk is only partially reduced. When you turn this setting off, OpenAI guarantees that it will not use the prompts you type to train the AI ​​model; this is a positive step in terms of data security (administrative measure). However, your data still continues to travel across borders over the internet to OpenAI's cloud servers in the US. Therefore, the risk of a "Transfer of Data Abroad" (KVKK Article 9) violation remains the same. Turning this setting off does not prevent data from leaving the country, it only prevents it from being permanently trained on the model there.

2. We use Microsoft Copilot to analyze company emails and documents. Since we have a corporate Microsoft license, are we safe in terms of GDPR (Turkish Personal Data Protection Law)?

If your company uses “Microsoft 365 Enterprise” commercial licenses instead of standard individual Office licenses , and you have signed enterprise-level data processing terms (DPA) with Microsoft, you are in a safer position. Microsoft legally guarantees that corporate data will not be leaked and that commercial data will not be used to train models. However, the location of Microsoft's data centers is critical. If your data is going to servers in the EU or the US, you must identify the Standard Contracts (SCCs) attached to your corporate contract and notify the Personal Data Protection Authority within the legal timeframe. Otherwise, even if there is no technical leak, a procedural transmission violation occurs.

3. If a programmer using artificial intelligence writes code that does not contain personal data, but only company trade secrets or source code, will they be fined under the Turkish Personal Data Protection Law (KVKK)?

If the source code or algorithm does not contain any data identifying a real person (name, email, ID, IP address, log data, etc.), this does not fall under the scope of the Personal Data Protection Law (KVKK) , and the Personal Data Protection Board cannot impose penalties on the company ecosystem for this reason. However, this situation means that the company's trade secrets, intellectual property rights, and registered source code are being leaked, which triggers labor law and commercial lawsuits under the Turkish Commercial Code (TTK) for "Unfair Competition" and under the Turkish Code of Obligations for "Violation of the Duty of Loyalty and Confidentiality".

4. Can we upload fully anonymized data to ChatGPT for analysis?

Yes, you absolutely can have this done, and it's one of the most legal methods. If you change the names in a dataset to "Customer A," "Customer B," completely delete identifiers like phone numbers and addresses, and make the data impossible to trace back to a real person (true anonymization), then that dataset loses its "Personal Data" status. You can then upload this data, which is no longer covered by the Turkish Personal Data Protection Law (KVKK), to any global artificial intelligence tool you choose and have it analyzed.

5. If an employee uses ChatGPT on a company computer on their own initiative and leaks data, will the penalty be imposed on the company or the employee?

Under the law, the responsible party is always the legal entity itself, i.e., the company acting as the Data Controller. When the Board detects a violation, it imposes the penalty directly on the company. The company cannot escape the penalty by saying, "I didn't know, the employee uploaded it on their own," because the company is obligated to supervise its employees and take technical measures (DLP – Data Loss Prevention systems) to prevent data entry to such insecure sites through the system. However, the company can seek recourse from the employee who clearly violated corporate policies and the employment contract (claim the damages from the employee) within the framework of labor law and terminate the employment contract for just cause.

6. If we obtain explicit consent from our customers asking, "Do you agree to your data being processed by artificial intelligence tools?", can we circumvent the travel ban?

Under the new legal regulations, obtaining explicit consent for regular and continuous operations is no longer a legal way to circumvent the travel ban. If your company responds to hundreds of customer requests daily using artificial intelligence, this is not an incidental (exceptional/one-off) operation. The Board considers hiding behind explicit consent in continuous data flows as a legal circumvention and deems it invalid. The only legal way for continuous data transfers is through Standard Contracts (SCC) mechanisms or local architectures that do not transfer data abroad.

7. How safe is it to install an open-source artificial intelligence model on a company server (on-premise)?

This is the most secure and GDPR-compliant method from a legal standpoint . For example, when you download Meta's Llama 3 model, Mistral, or similar open-source models and install them on your company's physical servers or on local cloud providers located in Turkey, none of the prompts you write to the AI ​​will leave the company. Data will not circulate on the internet and will not be transferred abroad. Since the company's data recording system will remain entirely under your control, you will have eliminated the risks of GDPR Article 9 (Transfer Abroad) and Article 12 (Data Security).

8. We are an e-commerce site and we use ChatGPT to print our product descriptions. Is there a risk of violating GDPR (Turkish Personal Data Protection Law) here?

Product descriptions (e.g., “Features of a red cotton men's t-shirt…”) do not contain any personal data belonging to any real person. They consist solely of commercial product information. There is no GDPR risk. You can use it with peace of mind.

9. If a personal data breach occurs in the outputs produced by artificial intelligence, who is responsible?

If an AI tool, acting on your commands, scans publicly available data on the internet or combines data from its own memory to produce an output that is unlawful, false, or reveals the identity of an individual, and you, as a company, publish this output on your website or in your reports, you are. The fact that the AI ​​experiences "hallucinations" (fabrications) or produces incorrect data does not absolve you, as the data controller, of your obligation to verify the accuracy of the data (Article 4 of the Turkish Personal Data Protection Law).

10. Should a separate department or role be established within the company to oversee the use of artificial intelligence?

In large-scale firms and data-intensive sectors (Fintech, E-commerce, Healthcare, Logistics), it is strongly recommended to establish an Artificial Intelligence Governance Committee or to expand the authority of the existing Data Protection Officer (DPO) / GDPR Committee in this direction. This committee should subject every new AI tool to a legal and technical cybersecurity assessment (AIA) before it begins operation.

Conclusion: Integration of Legal Regulation into Artificial Intelligence Strategy

While artificial intelligence technologies offer companies a tremendous competitive advantage, they can also become "ticking time bombs" if legal regulations are not followed. The Personal Data Protection Law (KVKK) is not an obstacle to innovation or the use of artificial intelligence; on the contrary, it is a guide that ensures this process is carried out in a controlled, safe, and prestigious manner.

Companies need to stop focusing solely on technical performance criteria in their AI integration processes and instead design the legal aspects of the architecture (data flow direction, server locations, contractual clauses) from the very beginning. It should be remembered that recovering from a data leak in the cyber world can lead to far greater financial and legal damage than any annual productivity gains from AI. The most practical way to navigate this complex process flawlessly is to build a corporate "AI Governance Infrastructure" by bringing together the technical IT team and a legal team specializing in AI and data protection law

Leave a Reply

Call Now Button