Gains:
- It applies KVKK principles and data minimization when processing citizen personal data in AI tools.
- It establishes a governance framework for an organization that includes an AI usage policy, audit trail, and chain of responsibility.
- It holistically argues that responsible public AI is built on human oversight, transparency, and accountability.
Throughout this module, we saw how AI is a powerful accelerator in public: response to citizen questions, petitions and correspondence, legislative research, policy analysis, reporting, data-driven decision-making, e-government and transparency. Now we come to the framework that holds it all together: personal data protection and responsible governance. Public, by its nature, processes the most sensitive data of the citizen: identity, address, income, health, criminal record, family situation. Processing this data with AI tools must fully comply with the framework of KVKK (Personal Data Protection Law No. 6698; the law regulating the lawful, limited and secure processing of personal data). In this final unit, we will establish the privacy and governance backbone of public AI use — what data can be given to which tool, what policies apply, who is responsible, how an organization manages AI safely. This unit is the roof placed over the previous ten units.
Basic principles of KVKK touching public AI
KVKK sets out several basic principles, each of which directly limits the use of AI:
- Compliance with law and adherence to purpose: Personal data is processed only for a specific, legitimate purpose. Data collected for one purpose (for example, applying for help) cannot be used for another purpose (for example, training a model) without permission.
- Data minimization: No more data is processed than necessary for the purpose. If a name is not required for a category analysis, no name is given.
- Security: Data is protected against unauthorized access. Pasting citizen data into a public AI tool is taking that data outside the organization — it's a violation of security policy.
- Storage period: Data is deleted when the purpose ends; It is not kept indefinitely.
- Information and rights: Citizens have the right to know how their data is processed, correct, delete and object to automated decisions.
Attention: Uploading a citizen's data to a public AI tool that the institution has not approved, where the data is stored and who has access to it is unclear, is in most cases a violation of KVKK and opens the institution to sanctions. The rules are never bent "to make the job easier".
Which data, to which vehicle? Three-zone model
As a rule of thumb, divide the data into three regions:
- Red (never enters public vehicle): ID number, health, criminal, religion, ethnicity, biometrics, full address, anything that identifies the person. These are processed only in a contracted/in-house and KVKK compliant environment approved by the institution.
- Yellow (carefully, by masking): Data that can be indirectly linked to the person. Anonymize/aggregate first, then process.
- Green (free): Impersonal, public, general information (legislative text, public statistics, general procedure). You can easily process these with AI.
Tip: Before giving a text to the AI, do the 5-second test: “Is there anything in this content that could identify a person?” If the answer is “yes/maybe,” mask up or drive an approved vehicle. If in doubt, consider red.
Corporate governance: from person to system
Responsible public AI cannot be left to the good will of individual civil servants; An institutional framework is required:
- Policy: The institution must have an AI usage policy: which tools are approved, what data can be entered, who is responsible.
- Approved tool list: Personnel should use tools that the institution has evaluated and approved, not randomly.
- Training: Staff must know the verification discipline and data regions (like this module).
- Recording and auditing: An audit trail of decisions produced with AI should be kept.
- Accountability: Every AI-powered output must have a human owner and approval. The responsibility lies with the institution and the officer, not the vehicle.
- Human-centered principle: No final rights-creating/restricting decision is made without human consent.
three mini cases
Case 1 — Red data leak prevented. A staff member was about to upload a summary of a list of health benefits for 1,200 people to a public tool. Thanks to the agency's approved vehicle policy and "red data" training, it stopped; The data was processed in an in-house approved environment and with identity fields masked. A possible KVKK violation and loss of trust for tens of thousands of people was prevented.
Case 2 — Misuse. One unit wanted to use data collected for outreach for a pre-election communications plan. The data protection officer recalled the principle of adherence to purpose: this was a use of the data outside the purpose for which it was collected and was unlawful. The request was denied.
Case 3 — Governance gap closed. In one municipality, different units were using different AI tools without control; No one knew which data went where. The agency introduced an AI use policy, approved vehicle list and audit trail; Within 3 months, unregistered vehicle use decreased by 90% and a data inventory was created.
Four copyable templates
1) Data region classification (before exporting to the vehicle):
Your role: data protection advisor. Classify the following content before giving it to an AI agent: RED (identifies person, never enters public vehicle), YELLOW (indirectly connectable, mask), GREEN (non-personal, free). Mark the red/yellow areas one by one and tell them how to mask. Count the suspect as red. CONTENT: [text]
2) Masking/anonymization:
Anonymize all personal data before processing the following text: name -> [PERSON-1], ID number -> [IDENTITY], address ->[ADDRESS], health/penalty -> [SENSITIVE]. Tag the same person. Export anonymized text separately. Never write actual data to the output. TEXT: [text]
3) KVKK compliance checklist (for the use of an AI):
Your role: KVKK compliance specialist. Produce a compliance checklist for the following AI use: (1) is the purpose of processing legitimate and specific, (2) is it connected to the purpose (is it shifting to another purpose), (3) is it optimized, (4) is the tool secure/approved, (5) is the retention period certain, (6) are citizen rights (objection, deletion) protected. Mark the missing items with a red flag. USAGE: [recipe]
4) Corporate AI policy framework:
Your role: public IT governance expert. Produce an AI usage policy framework for our organization: scope, approved tools, data zones (red/yellow/green), prohibited uses, human approval points, audit trail, responsibilities, training, and violation notification. Fill in each heading with 1-2 sentences. INSTITUTION: [unit and typical jobs]
Weak prompt / Strong prompt
Weak: "Summarize this list of references."
Strong: "Your role is data protection consultant. First, classify this list by data region (red/yellow/green) and mark all fields that identify the person. Mask the red/yellow fields with [PERSON]/[IDENTITY]/[SENSITIVE], keep the same person with the same label. Only produce a category summary with anonymized, aggregated data; do not write real personal data to the output. At the end, note where this process requires attention in terms of KVKK (purpose, storage, vehicle security) add."
The difference: the powerful prompt classifies, masks, minimizes and integrates KVKK principles before processing the data.
Data regions and rule
Region
example
rule
red
TR ID number, health, penalty, full address
Never enter a public vehicle; approved environment
yellow
Age+neighborhood+occupation, indirect identifier
Mask/aggregate, then process
green
Legislation, public statistics, general procedure
freelance work
Common mistakes
- Exporting red data to public tool. The most serious violation; ID/health/penalty data does not leave the approved environment.
- Misuse. It is against the law to use data collected for one purpose for another purpose (model training, communication) without permission.
- Processing too much data. Do not move unnecessary fields (name, address) for the purpose; Minimize.
- Driving without approval. It is unclear where the data goes in vehicles that the institution has not evaluated.
- Not determining the retention period. Data should be deleted when the purpose is completed; should not be kept indefinitely.
- Putting the responsibility on the vehicle. The output is owned and approved by the human; “AI did it” is not a defence.
In summary
The framework for responsible public AI is personal data protection and corporate governance. KVKK principles — purposefulness, minimization, security, retention limit, citizens' rights — limit any use of AI. Separate data into red/yellow/green zones, never give red to a public tool, mask personal data, use only approved tools, and connect a human owner to every decision. Institutional level policy, approved vehicle list, training and inspection record; The discipline of verification at the person level. Thus, AI serves the public by protecting the rights of citizens.
Application task
Choose an actual AI use you have made (or are considering making) in your unit. Separate the content you will process into red/yellow/green with the "Data region classification" template. Apply the "KVKK compliance checklist" template and find at least one missing/risky point. Finally, draft a short policy suitable for your unit with the "Corporate AI policy skeleton".
checklist
- [ ] I divided the content into red/yellow/green zone; I counted the suspect as red.
- [ ] I did not provide the red data to the public tool; I used approved media.
- [ ] I masked personal data and removed unnecessary fields (minimization).
- [ ] I have checked the purpose of processing, storage period and vehicle security.
- [ ] I have observed the citizens' rights of objection/deletion.
- [ ] I attached a human owner and approval to each output; I kept an audit trail.
Module Exam
1. As a public official, what is the best priority question you should ask before handing over a job to AI?
- A) What does the citizen lose if this output is wrong? ✔
- B) How fast can AI do this job?
- C) Is this AI tool free?
- D) Will another unit also use this output?
Explanation: The decision to transfer is made based on the damage that the citizen will suffer if the output is incorrect. The damage is easily transferred if it's just a few minutes of rewriting; If it is unfair rejection, wrong penalty or loss of rights, AI only produces a draft, the decision and verification belongs to the official.
2. What is it called when AI presents a non-existent law or a fabricated court decision as real?
- A) Caching
- B) Triage
- C) Anonymization
- D) Hallucination ✔
Explanation: Hallucination is when AI confidently produces information that does not actually exist (fabricated substance, repealed regulation, wrong number). In the field of legislation, this is one of the most dangerous risks, as it can lead to loss of rights and cancellation of the administrative action.
3. An officer is about to reject the application based on a regulation article pointed out by YZ. Which is the most correct behavior?
- A) The AI directly writes the rejection because it seems confident
- B) Ask the same question to another AI vehicle and get confirmation
- C) Confirms the article from the current consolidated text on Çözüm.gov.tr ✔
- D) Verbally asks the decision to a superior
Description: The AI's training data is frozen at a certain date; The article it shows may have been repealed or changed. Confirming that the article is in force and its final version from the current consolidated text on Çözüm.gov.tr before the decision prevents an unfair rejection and possible annulment suit.
4. Why is it quality assurance for a citizen chatbot to be able to say 'I don't know, I'm transferring you to an official'?
- A) Improves statistics by increasing turnover rate
- B) Prevents misinformation by delegating information to humans when unsure ✔
- C) Extends the call time by distracting the citizens
- D) Allows the chatbot to receive fewer questions
Explanation: In public, a confident wrong answer is much more costly than an honest take; It leads to loss of rights and distrust of the institution. The ability of the chatbot to hand over to the human when unsure is a safety mechanism that prevents hallucinatory misinformation.
5. What is the most important risk to consider when 'simplifying' official correspondence with AI?
- A) The text is too short
- B) Changing the font
- C) Dropping a condition or exception ✔
- D) Wrong spelling of the addressee's name
Explanation: Stylistic adaptation should not change the content. When simplifying, AI sometimes drops an exception, condition, or duration. Therefore, the simplified text should always be compared with the original decision or legislation.
6. Name and T.R. in a data set. What do you call it when the combination of 'neighbourhood + year of birth + type of disability' can reveal a person even if the ID number has been deleted?
- A) Redefinition ✔
- B) Data minimization
- C) Coverage rate
- D) Consolidation
Explanation: Re-identification is finding a person through a combination of indirect identifiers from data thought to be anonymous. If a rare category is found in a single person, deleting the name will not be enough; Additional measures are required, such as converting age to range and combining rare categories.
7. What is it called when an inspection model marks a neighborhood that has been heavily inspected in the past as 'risky' and sends more inspections there, which pushes the model to see that neighborhood as more risky?
- A) Data minimization
- B) Hallucination
- C) Anonymization
- D) Feedback loop ✔
Explanation: The feedback loop is when the model's output affects subsequent training data, reinforcing existing bias. The difference increases not in the actual risk, but in where one looks. The way to protect yourself is to monitor the impact, not the output, and to control the group-based distribution of decisions.
8. After a benefits application moved entirely online, the number of applications dropped 30 percent in the first month. What's the most likely explanation for this?
- A) Citizens' real needs have decreased
- B) Citizens without internet and digital literacy were left out ✔
- C) Interest decreased because the aid amount decreased
- D) The system automatically approved all applications
Description: The digital divide is the inability of citizens without internet access or digital literacy to access services. The number decreases because the most needy group, the elderly and citizens without internet, cannot apply. The solution is to leave alternative channels, such as assisted referral points.
9. While the actual success rate in an annual report is 63 percent, the executive summary produced by YZ says 'the vast majority of applications were positive.' What is the correct behavior?
- A) The expression is left as it is because it is positive.
- B) The ratio is deleted and only the qualitative expression is used
- C) The expression is replaced with the real number 63 percent ✔
- D) The summary is completely removed from the report
Explanation: Exaggerated positive perception in the public report puts the institution in a difficult situation in subsequent audits. Each claim in the executive summary should be compared to the raw data and the actual number (63 percent) should be written; AI summaries are not included in the report without being audited.
10. When making data-based decisions in the public sector, if the 'number of files closed monthly' increases while the 'resolution rate at first contact' decreases, what does this teach us first?
- A) Choosing the right indicator is more important than multiplying the number ✔
- B) The number of personnel should be increased
- C) Graphs should be colored
- D) The chatbot should answer more questions
Explanation: The wrong indicator leads to the wrong decision even with correct data. Files may be quickly closed and reopened. Choosing the right indicator and reading the indicators together prevents bragging based on a misleading number alone.
11. In a chart, the vertical axis starts at 40 instead of zero and a 2 percent increase looks like a dramatic jump is an example of what problem?
- A) Hallucination
- B) Data minimization
- C) Digital divide
- D) Misleading visualization ✔
Explanation: Misleading visualization is distorting perception through techniques such as axis not starting from zero, disproportionate scale, or selected time period. It is part of honest visual governance in public data; The real table should be shown by pulling the axis to zero.
12. Why is it unacceptable to say 'AI wrote that' as a justification for an administrative action?
- A) Because AI tools are too expensive
- B) Administrative action must be justified and the responsibility lies with the officer ✔
- C) Because AI does not know Turkish
- D) Because citizens do not like AI
Explanation: Administrative action must be reasoned and auditable; The responsibility lies not with the AI, but with the public official and institution that uses the output without verifying it. 'The AI said so' is not a justification and does not sustain the administrative action.
13. What are the four principles that distinguish the use of AI in the public sector from the private sector and that should be additionally observed?
- A) Speed, cheapness, profitability, competition
- B) Automation, scale, marketing, brand
- C) Equality, transparency, accountability, protection of personal data ✔
- D) Privacy, confidentiality, privacy and confidentiality
Explanation: In works where public power is used, AI is framed by the principles of equality (similar treatment of a similar situation), transparency (explainability of the justification of the decision), accountability (responsible for each transaction and audit trail) and protection of personal data (KVKK).
14. What should an automated preflight system do when it is unsure of a rare document type?
- A) To reject the application silently
- B) Forwarding the application to human review ✔
- C) Automatically approve the application
- D) Delete the application
Explanation: Good automation directs the model to the officer when it is unsure rather than silently rejecting it. Otherwise, legitimate applications will fall into a blind spot and victimization will occur. Keeping people at the decision point is the basis of exception management.