Gains:
- Ability to evaluate which data can be entered into the AI tool in line with KVKK principles
- Ability to protect personal data with masking/anonymization and set up a secure prompt
- Ability to draft and verify KVKK documents such as information text and data processing inventory
The most sensitive asset in the hands of a legal and compliance professional is data: client information, employee records, personal data in contracts. Entering wrong data into an artificial intelligence (AI) tool is as easy as pressing a button, but the consequences are severe: KVKK violation, administrative fine, contractual confidentiality violation and loss of reputation. The question for this unit is clear: which data can be entered into which tool and how? We will learn to use AI both safely in KVKK processes and position it as an assistant in preparing documents such as clarification text, processing inventory, etc. — but the responsibility for the data entered always remains with you.
Let's clarify the terms. KVKK is the Personal Data Protection Law No. 6698; regulates the processing of personal data. Personal data is any information regarding an identified or identifiable natural person (name, ID number, telephone, e-mail, location). Special quality (sensitive) data is a type of data that is more strictly protected, such as health, religion, sexual life, criminal convictions. Data minimization is the principle of processing only as much data as is necessary for a purpose. Anonymization is the process of making data unable to be linked back to a person; Masking/pseudonymization is hiding the identity information but protecting the relationship with a key. Information text is a notification that tells the data owner how their data is processed.
Which Data, To Which Vehicle?
The basic decision is made on two axes: the sensitivity of the data and the assurance of the tool. Personal or confidential data can only be entered into approved tools that provide institutional data assurance (data not to be used in education, not to be stored, not to be shared with third parties). Entering personal data into an unsecured public tool is taking that data out of your control.
The decision flow is as follows:
- Classify. Is there personal/private/confidential data in the text?
- Ask if it is necessary. Is personal data really necessary for this task (minimization)?
- Check vehicle insurance. Does the tool provide corporate data assurance?
- Protect. Mask or anonymize if not necessary.
- Document it. Record the purpose, basis and duration of processing.
Your role: a KVKK/data protection consultant. Perform a data classification BEFORE entering the following text into the AI tool: 1) List the personal data in it (type: name, ID number, contact, location...). 2) Mark if there is sensitive (sensitive) data. 3) Mark personal data that is not required for the task as "removable". 4) Give a masking/anonymization recommendation for those that should remain. Interpret the content of the text; just inventory the data.<text>[text to review]</text>
Caution: Deleting a chat does not get the data back. Once personal/confidential data is entered into an unsecured tool, that data is deemed processed in the third party's systems. "I'll delete it later" is not a protection; The place of protection is before entering the data.
Masking and Secure Prompt Arming
Most tasks can be done without knowing who the person is. A party's real name is not required to summarize a contract; "Side A" is enough. AI also helps in masking a text — but the human must control the completeness of the masking.
In the following text, replace all direct identification information with consistent aliases: person names → "Person 1, Person 2"; companies → "Company A, B";TR number, phone, e-mail, address, IBAN → [MASKED]. Preserve meaning and relationships. At the end, provide a mapping table of what information you replaced with what, so I can link the result back. In case you missed it, I'll check the masking.
It's important to know the limits of masking: sometimes information that seems individually innocuous combined together makes a person identifiable (e.g. "The only female CFO in Istanbul"). That's why anonymization is not always guaranteed, and for high-sensitivity work the safest way is to use corporate-approved tools.
Drafting KVKK Documents
AI quickly produces first drafts of documents such as disclosure text, explicit consent text, and data processing inventory. But these documents are legally binding; The draft must correspond exactly to your actual processing activity and must pass legal approval.
Prepare a DRAFT information text for the following processing activity. It should include the following headings: data controller, categories of data processed, purposes of processing, legal reason, transfer (recipient groups, if any), storage period, rights of the data owner, remedy. Rules: - Fill in each field with the information I provide; If it is missing, leave [TO BE FILLED] and do not assume. - Add a note "legal approval required" for the legal reason and retention period.<processing_activity>[purpose, data types, recipients, duration]</processing_activity>
Weak Prompt / Strong Prompt
Weak prompt: Summarize this client file. [real name, TR number, case details are pasted]
Result: Personal and possibly private data is entered into a tool with uncertain security. Even if the task is completed, there has been a violation of KVKK and confidentiality.
Powerful prompt: [first data classification + removal of unnecessary personal data + masking (pseudonyms, [MASKED]) + approved/secured tool + then summarization with masked text]
Result: The task is still done, but the person cannot be identified; Data protection was ensured before the mission.
Data Type and Appropriate Processing
Data type
example
unsecured vehicle
Approved vehicle
It's not personal
Anonymous/public text
suitable
suitable
personal
Name, contact, IBAN
Mask/use
Suitable by masking
specially qualified
Health, criminal record
Using
Required+approved only
Client secret/privileged
Litigation strategy
Using
Secure only
Three Mini Cases
Case 1 — Stopping before entering. An expert would have the AI summarize a 30-person employee performance list (name, record, medical leave notes). The data classification prompt revealed that the medical notes were proprietary data and not needed for the mission at all. The expert removed this column entirely, changed the names to “Employee 1-30” and worked with performance scores only. The task was done; Sensitive data never entered the vehicle.
Case 2 — Re-identification. A team would share a complaint text saying "we anonymized it"; but the text included the phrase "the only manager in the head office who uses a wheelchair." This made the person identifiable even if their name was erased. This was noticed in the masking check and the statement was generalized. Lesson: de-identifying does not always ensure anonymity; Context can also give the person away.
Case 3 — Acceleration of inventory. An institution had not been able to manually update its KVKK data processing inventory for years. With AI, the processing activities of each department were put into a structured outline (purpose, data type, retention period, recipient); The legal team verified and corrected them. Inventory preparation estimates decreased from 6 weeks to 2 weeks. Critical point: each line entered into the inventory was human-verified by comparison with actual activity; The AI draft was not accepted as is.
Common mistakes
- Entering data without classification. Pasting the text into the tool without seeing what kind of data is in it is the most common violation.
- Carrying unnecessary personal data. When minimization is skipped, personal/sensitive data is processed even though it is not necessary.
- Relying on "I'll delete it later." Data is processed as soon as it is entered; protection is done first.
- Not controlling masking. AI can skip a credential; masking must be human verified.
- Not seeing contextual re-identification. Individually harmless information combined can give the person away.
- Publishing the KVKK document without approval. Information/consent text and inventory require legal approval and confirmation of actual activity.
In summary
The basic question in KVKK is "which data, to which vehicle, how?" Classify data first, remove what is not needed (minimization), mask or anonymize what is needed, and process sensitive/confidential data only in approved tools with corporate assurance. One must control the completeness of masking and the risk of contextual re-identification; Documents such as clarification text and inventory must pass legal approval. AI speeds up preservation and documentation work; The authorized professional decides which data can be processed and the adequacy of protection.
Application task
Select text that contains personal data (do not use real data; create an example). (1) Remove personal and sensitive data with the data classification prompt. (2) Identify and remove those that are not needed for the task, alias those that are required with the masking prompt, and manually control the masking. (3) Look for phrases that are at risk of contextual re-identification. (4) Produce draft information text for a processing activity and list the "legal approval" marks.
checklist
- [ ] Is the data classified before entering the tool?
- [ ] Has unnecessary personal/sensitive data been removed for the task (minimization)?
- [ ] Has the remaining personal data been masked/anonymised?
- [ ] Is masking controlled by human?
- [ ] Has the risk of contextual re-identification been assessed?
- [ ] Is sensitive/confidential data processed only in the approved secured vehicle?
- [ ] Were KVKK documents prepared with legal approval and actual activity confirmation?