Gains:
- Prepares responses to information requests in accordance with the legislation, explaining neither more nor less.
- It anonymizes open data before publishing and scans it at the level of combinations that risk re-identification.
- Knows that transparency is a governance tool that increases public trust and distinguishes what should be kept confidential.
The cornerstone of a democratic public administration is transparency: the ability of citizens to learn how and on what basis decisions that concern them are made. This principle comes to life in two concrete mechanisms. The first is the right to information (Law on the Right to Information No. 4982; citizens can request information and documents from public institutions, with exceptions). The second is open data (public institutions publish the non-personal and non-confidential part of the data they produce in a way that everyone can access and use). Here, AI is a powerful aid in classifying incoming information requests, producing response drafts, pre-evaluating which information can be given and which is exempt, and preparing open data sets for publication. But the two-fold caveat of this unit is important: transparency should be no more, no less – the citizen should be given the information he is entitled to, but personal data and real exceptions should be protected; This balance is established by the responsible public officer, not the AI.
The two wrong ends of gaining knowledge
In requests for information, errors can be made in two directions:
- Lack of transparency: Unnecessarily rejecting giveable information as "confidential/exceptional". This both violates the right and creates distrust in the institution, and often ends up in the judiciary.
- Over-disclosure: Accidentally revealing third party personal data, a trade secret, or a real exception (security, etc.) when submitting a document. This violates KVKK and causes damage.
AI can help on both ends: it can scan a document, mark personal data within it, and suggest redaction (obscuring/removing confidential/personal parts of the document); It may list the exception category under which you will evaluate the request. But the final decision - whether this information is given, which part is obscured - belongs to a person who bears legal responsibility.
Attention: AI's statement that "this information is within the scope of exception" or "can be given" is not a legal opinion. Exception evaluation is made and justified in accordance with the relevant articles of the Law on Access to Information; AI only produces pre-quals and drafts.
Publishing open data safely
Open data increases public efficiency and accountability; entrepreneurs, journalists, researchers create value from this data. But before publishing a data set, it should be checked against the risk of re-identification (data thought to be anonymous is linked back to individuals by combining it with other data). For example, the combination "age + neighborhood + rare occupation" may indicate a single person. When preparing a data set for publication, AI is helpful in flagging risky column combinations and writing a data dictionary (a description of what each column means).
Tip: Before publishing open data, ask: “Can I find a single person by combining two-three columns in this set?” If the answer is “maybe,” aggregate (group instead of individual), combine rare categories, or remove the sensitive area.
Step by step flow of information
- Understand and classify demand. What is requested, which unit does it concern, what is the duration?
- Does information exist or does it need to be produced? The law covers existing knowledge; the institution may not have to produce new analysis (confirmed).
- Exception evaluation. Are there any exceptions such as personal data, security, trade secrets, internal opinion?
- Redaction. Remove parts of the exportable document that need to be preserved.
- Reasoned answer. The part given/not given and its basis; Objection method if rejected.
- Log and audit trail. The request, decision and justification are recorded.
three mini cases
Case 1 — Editing error avoided. An agency would submit a tender document to a freedom of information request. AI scanned the document and marked the phone numbers and TR ID numbers of three people. If it had been sent without proofreading, it would have been a violation of KVKK; personal data was blackened, the document was delivered safely.
Case 2 — Unfair rejection corrected. A unit would habitually reject a request for activity data as “in-house.” When AI was asked about the exception categories, it was seen that this data was actually already publishable as open data. The request was met, a possible objection and lawsuit was prevented.
Case 3 — Re-identification risk. A municipality would publish its “service requests” dataset as open data. The set included neighborhood + full address district breakdown. The AI warned that the address field could point to individual digits; The address was aggregated to street level and the set was published safely.
Four copyable templates
1) Information request classification:
Your role: information acquisition specialist. Process the following request: (1) what exactly is requested, (2) which unit it concerns, (3) whether it requires existing information or new production, (4) possible exception categories (personal data, security, trade secret, etc.). Specify that each exception "must be justified by the relevant article". Decision making, pre-evaluate. REQUEST: [text]
2) Redaction (marking personal/confidential data):
In the document below, mark all parts that should be MASKED in an information response: name-surname, TR ID number, address, telephone, health/criminal information, third party data, trade secret. Write brief justification for each sign. Leave the exportable part of the document as is. DOCUMENT: [text]
3) Reasoned answer draft:
Draft a reasoned response to the following request: (1) what information was given, (2) which part was not given and why (exception clause [to be confirmed]), (3) appeal method and duration [to be confirmed]. The language should be formal and respectful. The justification for the part not given should be concrete, not general. REQUEST: [summary] DECISION: [what was/was not given]
4) Open data re-authentication control:
Examine the columns of the dataset below. List which combinations of columns may indicate a single person (risk of re-identification). Suggest some mitigation for each risk: aggregation, rare category aggregation, field extraction. Just use the given column list. COLUMNS: [list]
Weak prompt / Strong prompt
Weak: “Respond to this request for information.”
Güçlü: "Your role is an information unit expert. First, classify the request: what is requested, which unit, is it available, what are the possible exceptions. Mark each exception as 'to be justified by the relevant article', do not make a legal decision yourself. Then, mark the personal/confidential parts that need to be masked in the document to be submitted with a redaction suggestion. Finally, produce a reasoned response draft including the part given/not given and the way to object; make the justification concrete."
Difference: strong prompt balances transparency and protection, ties the exception to the justification, adds redaction and appeal path.
Approach by information type
Information type
Default
Attention
Statistics, aggregated data
open
Re-identification check
Reason for administrative action
can be given
Redact third party data
Third party personal data
protected
KVKK; but with permission/exception
Security/privacy exception
protected
Is it real exception, confirm
Internal opinion/negotiation
Depends
Evaluate according to the relevant article
Anonymization and risk of re-identification
The most technical but critical step in publishing open data is anonymization (making a person unidentifiable directly or indirectly from a data). Name and T.R. Deleting the ID number is often not enough; because the combination of several ordinary areas makes a person reidentifiable. This is called re-identification (finding the person by cross-matching data thought to be anonymous with other information). For example, if there is a single 92-year-old widower in a neighborhood, the trio "neighborhood + age + marital status" will reveal him. AI can help screen which combinations of fields in a data set are at risk of disclosure and suggest safer grouping (converting age to range, combining rare categories); But the decision to publish and the final audit are the responsibility of the institution.
Mini case — disclosure with three areas. One municipality published social assistance data "anonymously": no name, but neighborhood, year of birth, and type of disability. A journalist noticed a rare type of disability in a single person in a single neighborhood and identified the person. Data withdrawn; It was republished when the year of birth was converted to a 10-year interval and the rare categories were grouped under "other".
Template that screens for re-identification risk:
Task: Examine the columns of the following data set; I do not publish personal data, I only want risk screening.Columns: [column names]Output: 1) Direct identifiers (must be deleted). 2) Indirect identifier combinations (risk of re-identification). 3) Recommended grouping/masking for each risky combination. 4) Final check questions before publication.Rule: I did not paste any real personal values; just consider the column structure.
Caution: "I deleted the name, now anonymous" is the most common and dangerous misconception. Anonymity is determined not by the field itself, but by the combination of fields and the probability of matching with external data. If in doubt, do not publish; Anonymity is an irrevocable decision.
Common mistakes
- To habitually reject. Considering the information that can be given as unnecessary "confidential" is a violation of rights and a cause for lawsuit.
- Submitting unredacted documents. Revealing third party data is a violation of KVKK.
- Using the exception without justification. Rejection must be made with concrete substance and concrete justification; Saying "in-house" is not enough.
- Relying on the AI's legal judgment. The decision to make an exception is human; AI pre-qualifies.
- Bypassing re-identification in open data. Column combinations can find people; aggregate.
- Not specifying the means of objection. In rejections, the application method and duration must be written (confirmed).
In summary
Transparency is the foundation of public trust; AI is a powerful aid in classifying FOI requests, recommending proofreading, drafting responses, and preparing open data for publication. But the balance is critical: citizens must be given the information they are entitled to, real exceptions and personal data must be protected. The decision to make an exception must be reasoned and human; Open data should be audited for the risk of re-identification before publication.
Application task
Receive a real (masked) freedom of information request. Pre-evaluate with the "Request classification" template, apply the "Redaction" template to an attached document and mark the areas to be masked. Apply the "Open data re-identification check" template to the columns of an open data set and find at least one risky combination.
checklist
- [ ] I classified the request; I did not reject the information that could be given unnecessarily.
- [ ] I evaluated the exceptions with concrete substance and justification (human decision).
- [ ] I have redacted the personal/confidential data in the document to be submitted.
- [ ] In case of rejection, I have stated the objection method and duration (confirmed).
- [ ] I checked the risk of re-identification in open data.
- [ ] I recorded the request, decision and justification for audit.