Gains:
- Ability to use candidate and employee data in accordance with KVKK principles (purpose limit, data minimization)
- Ability to protect personal data through masking/anonymization and safe tool selection
- Ability to support disclosure, consent and retention processes with AI for data processing in HR
Candidate CVs, performance scores, salary information, reference comments, medical reports, disciplinary records... HR is the guardian of the most sensitive personal data in a company. Using artificial intelligence (AI) tools with this data provides tremendous efficiency; but it also creates serious legal and ethical responsibility. Simply pasting all the CVs of a candidate pool into a haphazard tool could turn into a data breach within minutes. In this unit, we will learn how to make the use of AI in HR compliant, safe and defensible in accordance with KVKK (Personal Data Protection Law).
A few terms: Personal data is any information regarding an identified or identifiable natural person (name, ID, e-mail, even a unique CV text). Special quality (sensitive) data is extra protected data such as health, religion, sexual life, criminal conviction, union membership. The data controller is the institution (your company) that determines the purpose of processing the data. Anonymization means making data so that it cannot be linked back to a person in any way. Masking (pseudonymization) is replacing identifiers with pseudonyms (Candidate 1, Candidate 2); It is weaker than anonymization but is sufficient for most analyses.
Basic Principles of KVKK and Its Equivalent in HR
The general principles of KVKK also bind your use of AI. For a transaction to be legal, it must comply with these principles:
principle
Meaning in HR
Legality and honesty
Whether there is a legal basis for processing (contract, legitimate interest, explicit consent)
Limitation of purpose
Only use data for the purpose for which it was collected (do not use recruitment data in marketing)
Data minimization
As much data as the job requires; don't give too much to the model
accuracy
Make sure the data is up-to-date and accurate
storage limit
Indefinite storage; Destroy data no longer needed
Security
Process data with appropriate technical and administrative protections
Caution: Pasting all CVs of a candidate pool into a generic AI tool with no guarantee of corporate data retention is a serious risk for KVKK. That data can be stored with the provider of the model and even used in training in some service conditions. Corporate/approved tools, data processing agreements (DPA) and anonymization/masking wherever possible are essential when working with personal data.
Steps for Safe Use
- Select the tool. Choose tools that are corporate, have a data processing agreement, and offer the option of "using my data in education".
- Minimize data. Provide the minimum data required for analysis; remove the excess.
- Mask/anonymize. Replace name, ID, contact, full date of birth with nickname value or range.
- Limit the purpose. Process data only for the purpose for which it was collected.
- Keep the trail. Record which data was processed, for what purpose, and with which tool.
- Put human approval. Let a person make the decision that affects the person.
Mask personal data before evaluating the CV below:- Make "Candidate" instead of name, make contact information [REDACTED]- Use age range (e.g. 30-35) instead of date of birth- Generalize if school/company name could lead to discriminationThen make a structured summary according to job-related criteria only.
Anonymization and Masking Practice
Most HR analysis can be done without identifying the individual. The analysis logic does not change, personal data is not disclosed:
Weak (risky): Pasting data with real name, ID, unit and full salary. Strong (safe): Code people as "Person 1/2/3", use age range instead of date of birth, band (e.g. 40-50k) instead of full salary. Use region instead of location, month/year instead of exact date.
AI also helps in the drafting of KVKK documents, such as the clarification text and retention period — but again, only the draft:
Your role: a data privacy assistant. Task: Write a DRAFT of a candidate information text for the recruitment process. Content: which data will be processed, for what purpose, on what legal basis, how long it will be stored, what are the candidate's rights. Rule: Mark the legal statements with the [VERIFY TO KVKK EXPERT] tag; certain period/item DO NOT FAKE. This is a draft, not the final text.
Three Mini Cases
Case 1 — Narrowly averted violation. A recruiter was about to paste 60 CVs into his personal vehicle account at once. The team leader intervened; The process was moved to a corporate, DPA-enabled tool and CVs were masked and processed. Thus, both efficiency was maintained and the risk of a possible violation and administrative fine was eliminated.
Case 2 — Purpose limit violation. One company subsequently used candidate emails collected for recruitment in a marketing campaign. This was a violation of the principle of "limitation of purpose" and was the subject of a complaint. After the incident, HR implemented a rule labeling the purpose of each dataset and preventing misuse.
Case 3 — Storage limit. An organization kept the CVs of candidates who were not hired for years. Matched data, purpose and retention period with an AI-powered inventory; Expired data was included in the destruction plan. Thus, both the legal storage limit was complied with and unnecessary risk was reduced.
Weak Prompt / Strong Prompt
Weak prompt: Evaluate the information of these candidates. [real name, Turkish ID, salary, full CV]
Result: sensitive personal data is processed insecurely; Risk of KVKK violation and data leakage.
Powerful prompt: [masked data (Candidate 1/2, age range, salary band) + objective limit + "job-related criteria only" + corporate/approved tool + human approval rating]
The result: the same analytical power, without revealing personal data; a defensible and legal process.
Tip: Before giving data to AI, test this: “Would someone's privacy be harmed if this screenshot were leaked?” If the answer is "yes", either mask that data or don't provide it at all. If in doubt, decide to minimize the data.
Common mistakes
- Giving raw personal data to an unsecured tool. Vehicles used in training without DPA are risky.
- Skipping masking. Name/TC/full date is unnecessary in most analyses; remove it.
- Misuse. Do not use recruitment data for any other purpose, such as marketing.
- Indefinite storage. Place data whose purpose is no longer on a destruction plan.
- Underestimating sensitive data. Health/penalty/religion data is extra protected; Avoid engaging in AI.
- Leave no trace. If you don't record what you do with what data, you can't be audited.
In summary
- Personal data in HR (CV, performance, salary, health) is within the scope of KVKK; The use of AI is also subject to these principles.
- Choose corporate/approved tools that have DPA and do not use your data in training; Do not paste raw data into generic tools.
- Purpose limitation and data minimization: process only the necessary data for the purpose for which it was collected.
- Masking and anonymization make most analyzes secure; Use alias and range instead of name/TC/full date.
- AI produces drafts in disclosure, consent and retention documents; Have the legal details verified by a KVKK expert and leave the decision that affects the person to the person.
Application task
Take a CV or employee record you have (or a fictional one). First list the personal data fields in it and ask “is this required for analysis?” for each one. Answer the question. Create a secure version by removing the unnecessary and masking the necessary (Candidate, age range, salary band). Have the AI produce a job-related summary with only this masked data. Also have a brief candidate prospectus drafted and mark the legal statements as “to be verified.”
checklist
- [ ] Is the tool used corporate/approved and DPA-certified?
- [ ] Is the data minimized (only required fields)?
- [ ] Are identifiers such as name/ID/full date masked?
- [ ] Is special quality (health, criminal, religious) data excluded from the process?
- [ ] Is the data used only for the purpose for which it was collected?
- [ ] Have the storage period and destruction plan been determined?
- [ ] Is the final decision affecting the person in a person?