Gains:
- Evaluating the information according to its sensitivity and distinguishing between the open vehicle and the secure system with the 'ask the class, match the vehicle' reflex
- Understanding the minimum data, security and responsibility principles of KVKK and seeing that deleting a name is not enough and the context is identity.
- Ability to adopt the discipline of choosing the safest path in case of doubt, protecting sensitive data at the highest level and reporting the violation transparently.
What a client tells you—violence, illness, poverty, addiction, family secrets—is the most fragile, private information of his or her life. He gives this information to you in confidence of professional confidentiality. This trust is the foundation that makes it possible for social work to work; When it is shaken, the client does not open up again and the service loses its function. Maintaining this trust in the age of artificial intelligence has taken on a new dimension: entering a client's information into the wrong tool is now not only a breach of privacy, but also a legal liability under KVKK (Personal Data Protection Law) and can lead to irreversible leakage of information. In this unit, you will learn how to protect client data in the age of AI, the basic logic of KVKK, the distinction between open vehicles and secure vehicles, and a practical "data hygiene" discipline.
The most basic rule from the start is the one we repeat throughout this module: No personal data that identifies the client will be entered into a public AI tool that your institution has not approved. This one sentence is the essence of all the details below.
Summarizing KVKK for the social worker
KVKK regulates how personal data (any information that makes a person specific or identifiable - name, ID, address, telephone, but also information such as health, family status, criminal record) can be processed. Most of the data you process in social work is sensitive personal data (data whose leakage is particularly harmful, such as health, sexual life, religion, ethnicity, criminal convictions) and requires the highest protection. The practical meaning of KVKK for you comes down to a few principles:
- Purpose limitation and minimum data: Only as much data as necessary is processed. When processing text into the AI, do not enter any personal details that are not required for the job.
- Security: Data is protected against unauthorized access. A public AI tool does not provide this security.
- Consent and transparency: Informing the client about how data is processed. Providing a client's data to an uncontrolled external tool is not within the scope of any consent.
- Accountability: If a breach occurs, the responsibility lies with the organization processing the data and the person entering that data — “AI wanted it that way” is not a defense.
Caution: Deleting names is often NOT a sufficient protection. Even if a name is not mentioned in a text, context (neighborhood + age + event + date + family structure) can make a person identifiable. Real protection is provided not by masking, but by choosing the right tool and environment.
Two worlds: open vehicle vs. secure system
Separate your use of AI into two clear worlds:
1. Public/open tool world. It can be used for tasks that do not identify the client: general information questions ("How to write a SMART goal?"), training with fictional/anonymous examples, general explanation of legislation, program texts that do not point to anyone. Real client data is never entered here.
2. The world of client data. Any work that involves a real client's information — recording, report, risk note, referral — is done only in secure systems approved by your institution, where data does not leak. If there is no such system, that work is done without AI, with the traditional safe method.
Confusing the two — giving real client data to the open tool — is the most dangerous and common mistake of this module.
Step by step: data hygiene discipline
- Ask about the class. Ask before each job: "Does this text describe the client?" If yes, secure system; If no, open vehicle can be used.
- Minimize. Limit the data entered to the minimum required by the job, even if the job really requires it.
- Disidentify (and know your limits). Remove identifiers where necessary; but remember that context can also give away identity.
- Use approved tool. Know which vehicle the institution approves for which data and do not deviate from it.
- If you're not sure, act like an upperclassman. If you are not sure whether a data is sensitive or not, choose the most protected path.
- Report the violation. If there is a leak or error, hide it; Report according to the institution's procedure. Early intervention reduces damage.
three mini cases
Case 1 — Context gave away identity. An expert submitted a case summary to the open tool, saying "I deleted the names, it's safe now." There was no name in the text, but there was the phrase "A visually impaired woman in X neighborhood, with 3 children, whose husband is in prison." There was only one person in that neighborhood who fit that description — the identity was practically clear. The senior expert noticed this; The job was moved to the secure system. Lesson: context is also personal data.
Case 2 — The minimum data policy worked. An expert only needed to simplify one sentence. Instead of giving the entire file to the tool, he just gave that one sentence with no personal details. The job was done, no sensitive data got out. The minimum data policy was both safe and sufficient.
Case 3 — Early reporting reduced damage. A new hire accidentally pasted a client's information into an open tool and noticed immediately. Instead of panicking and hiding, she immediately reported it to her supervisor. The institution evaluated the incident according to the KVKK procedure, took the necessary steps and taught the employee how to use it correctly. Transparent and rapid notification prevented the incident from escalating.
Four copyable templates
1) Data class preflight:
Evaluate the following text BEFORE processing it in an AI tool: Does this text make a person directly (name, ID, address, phone) OR indirectly (context: neighborhood, age, event, family structure) identifiable? Does it contain sensitive data (health, religion, ethnicity, criminal record)? If so, which sections? Tell me if this text can be rendered in the public tool. Text: [paste text]
2) Downgrading to minimum data:
Determine the LEAST information needed to do the following job. Remove all personal details that are not required by the job and leave only the non-identifying part that is required by the job. List what information you omitted and why.Job: [describe the task]Text: [paste text]
3) De-identification and context control:
Extract identifiers (name, ID, address, telephone, institution name) directly from the text below. Also mark any context elements that remain in the text (a rare combination of circumstances, specific location + event) that may INDIRECTLY give away identity. Before removing these, evaluate whether the text still makes the person identifiable.Text: [paste text]
4) Creating an anonymous/fictional training example:
Produce an example case that resembles a real case, but is completely FICTIONAL and does not belong to any real person; I will use this for training/practice. Using real names, places or events; Let everything be fake. [Topic: elder care initial assessment]
Weak prompt / Strong prompt
Weak prompt:
I am pasting this client's entire file below, it will give me a nice summary. (including name, address, health information)
This is giving sensitive personal data to an uncontrolled external system — a KVKK violation and an irreversible privacy risk. Just because the summary is "nice" does not excuse this violation.
Powerful prompt:
(Only in an institution-approved secure system, or with de-identified text.) Summarize the DE-IDENTIFIED text below. I have not left any context in the text that could give away name, address, ID or identity. Only process the information required for the task. Text: [paste anonymous text]
The difference: working in the right tool, with minimal and de-identified data, protects privacy and law while getting the job done.
Data type and correct path
Data type
example
the right tool
General information
“What is a SMART goal?”
open vehicle
fictional example
Contrived training case
open vehicle
Without identity + without context
Simplification of a general sentence
Open vehicle (carefully)
Client data
actual record, report
Secure system only
Special quality data
Health, punishment, ethnicity
Highest protection / secure system
Risk/safety note
Violence, protection information
Highest protection / secure system
Common mistakes
- Giving real client data to the open tool. The most dangerous and common mistake; KVKK violation and irreversible penetration.
- "I deleted the names" thinking it's security. Context can give away identity; Masking is not protection.
- Entering more data than necessary. Apply the minimum data policy; Give as much as the job requires.
- Taking risks when you are not sure. When in doubt, choose the safest path, act like an upper class.
- Concealing the violation. Early and transparent reporting reduces harm; Hiding makes it bigger.
In summary
Client privacy is the foundation of trust in social work, and in the age of AI, it also turns into a legal obligation with KVKK. The basic rule is clear: no personal data identifying the client enters an unapproved public tool. Keep the two worlds (open tool vs. secure system) separate, apply the minimum data principle, know that deleting names is not enough and context is identity, in case of doubt, choose the safest path and report the violation transparently. Privacy is not a measure added later, but a principle observed from the very beginning.
Application task
Write a fictional case text and see which items the AI marks as personal/private data with the “data class preflight” template. Then test with the "de-identification and context check" pattern to see if the context still gives away the identity even after deleting the names. Finally, produce an example that you can safely use in the open tool with the "anonymous/fictional training example" template.
checklist
- [ ] Before each job, "Does this text describe the client?" I asked.
- [ ] I process client data only in approved, secure systems.
- [ ] I applied the minimum data policy; I didn't go into much detail.
- [ ] Knowing that deleting the name is not enough, I also checked the context.
- [ ] In case of doubt, I chose the safest path and I know the way to report in case of violation.