Unit 3 / 12

KVKK Fundamentals, General Principles and VERBIS

Gains:

  • Distinguishing the concepts of personal data, special quality data, data controller and data processor
  • Applying KVKK general principles (limitation by purpose, minimization) to the use of AI
  • Understand that entering data into AI is processing and often transfer, and the obligation to record

Using AI in an organization is almost always intertwined with processing personal data: summarizing a customer email, evaluating a CV, parsing a call recording. Therefore, the backbone of AI governance is understanding Türkiye's data protection law, KVKK (Personal Data Protection Law No. 6698). In this unit, we will learn the basic concepts, general principles and VERBIS registration of KVKK, directly linking it to the use of AI. The aim is not to become a lawyer; It is to establish a solid basis for a data protection officer to make correct daily decisions.

Basic concepts: who is who?

The language of KVKK is based on several key concepts. Without distinguishing these, no AI decision can be made correctly.

concept

Meaning

example in AI

personal data

Any information about an identified/identifiable natural person

Name, email, phone, IP, customer number

Special quality data

Sensitive categories such as health, religion, biometrics

Patient history, blood type, facial data

Contact person

Person whose data is processed (data owner)

Customer, employee, candidate

Data controller

Determining the purpose and method of processing

Organization using AI

data processor

The party that processes data on behalf of the controller

Company providing AI service

This distinction has legal consequences: the data controller (the institution itself) is the primary owner of the liability. The AI ​​provider is often the data processor and a written contract (data processing agreement) must be concluded with it. Saying “the AI ​​provider did it” does not absolve the organization from liability.

Attention: Data is personal data as long as it makes it "identifiable". It is not enough to say "I deleted the name"; Even the combination of date of birth + zip code + occupation can make a person identifiable. Always check for this combined identifiability in the data entered into AI.

General principles of KVKK and AI

KVKK sets general principles that all processing must comply with. The direct translation to AI usage is:

  1. Compliance with law and honesty: Processing data secretly or misleadingly.
  2. Being accurate and up to date: AI can produce hallucinations; The output cannot be saved as personal data without verification.
  3. Specific, clear and legitimate purpose: Data cannot be processed because "it may be needed in the future"; The purpose is clear in advance.
  4. Purpose-related, limited and measured (data minimization): Only data necessary for the purpose is entered into the AI.
  5. Retention for required period: Once the purpose is over, data (including AI chat history) will be deleted/anonymized.

Data minimization is the most violated principle in AI: instead of pasting the entire file to summarize a text, it is necessary to enter only the required paragraph, and if possible in its masked (names hidden) form.

three mini cases

Case 1 — Too much data. A call center manager feeds 5,000 call transcripts to the AI, along with name, phone number and ID number, to “extract themes of customer dissatisfaction.” However, there is no need for identity data for theme analysis. According to the principle of minimization, the correct way is to delete the ID fields and give only the call text. Thus, the identity data of 5,000 people will not be processed unnecessarily.

Case 2 — Purpose drift. Marketing feeds employee clock-in and clock-out times to AI for “productivity analysis.” However, this data was collected for occupational health and safety purposes. Misuse violates the principle of "limitation by purpose". The right decision: to re-evaluate the legal basis and clarification before processing the data for this new purpose.

Case 3 — The unerasable past. An insurance professional has been entering customer data into the same AI chat for months to assess damage, and the history is never cleared. 8 months later, the data of more than 300 customers is accumulated in a single chat. Per retention policy, this history should be purged once the purpose is over (the file is closed) or the transaction should be moved to an institutional, no-logs tool.

Entering data into AI is “processing”

Processing in KVKK; It is any process including obtaining, recording, storing and transferring data. Pasting a text into AI means sending the data to the provider's server — this is a transaction, and often a transfer (if the server is abroad). Therefore, every use of AI requires a valid legal basis behind it (the subject of the next unit) and an appropriate contract.

Tip: “Can I input this data into the AI?” Test the question with three filters: (1) Personal data? (2) Is it necessary for the purpose and has it been minimized? (3) Do I have a valid legal basis and a suitable contract? If all three are not "yes", stop and evaluate.

VERBIS and processing inventory

VERBIS (Data Controllers Registry Information System) is the official registry in which data controllers who exceed certain thresholds record their personal data processing activities. The institution maintains a personal data processing inventory: a live record showing what data it processes, for what purpose, on what legal basis, how much it stores and to whom it is transferred. When a new AI-based processing activity is started, this inventory should be updated and, if necessary, reflected in the VERBIS record.

inventory space

Example for AI activity

Purpose of processing

Automatic summarization of customer emails

Data category

Contact, customer transaction data

Legal basis

Performance of contract / legitimate interest

recipient group

AI service provider (data processor)

transfer

Overseas server (with appropriate assurance)

Storage period

Delete from file closing

Copiable templates

TEMPLATE 1 — Masking the text without entering it into AI: "Remove personal data (name-surname, phone, e-mail, ID number, address) from the text below and replace them with tags such as [NAME], [TEL]. Preserve the meaning and structure of the text. Only return the masked text, do not make any other explanations."

TEMPLATE 2 — Minimization check: "I will perform the following task: [write task]. List which of the FOLLOWING data fields would be UNNECESSARY for this task: [write fields]. Mark 'discard' any field not needed for the purpose and write in one sentence why."

TEMPLATE 3 — Processing inventory line outline: "Fill out the personal data processing inventory line for the following AI use:[describe the use]. Fields: processing purpose, data category, contact group, possible legal bases (suggest multiple), recipients, transfer, estimated retention period. Precise legal decision-making, present options."

TEMPLATE 4 — Personal data detection: "Which personal data types and especially which SPECIAL data (health, religion, biometrics, etc.) are in this document? List the types and write down which class they fall into for each. Do not change the document, just detect it."

Weak prompt / Strong prompt

WEAK: “Analyze this customer list.” (with full name, phone, ID)-> Violates minimization; sends unnecessary personal/private data to the provider; raises legal basis and transfer problems.STRONG: "Analyze the regional demand distribution using only the 'city' and 'product category' columns in the list below. Ignore the name, phone, ID columns — I have already deleted them."-> Only non-personal data necessary for the purpose are processed; The principle is preserved.

Common mistakes

  • Thinking "I deleted the name, it's not personal anymore"; whereas combined data can make a person identifiable.
  • Not making a distinction between data controller and data processor and not signing a contract with the provider.
  • The unnecessary areas for the purpose are also entered into the AI ​​and violated the minimization.
  • Using data collected for one purpose in AI for another purpose (purpose drift).
  • Saving AI output as “accurate and up-to-date” personal data without verifying it.
  • Not reflecting new AI activity in processing inventory and VERBIS if necessary.
  • Accumulating AI chat history without binding it to a retention/deletion rule.

In summary

  • The core of KVKK; is to distinguish the concepts of personal data, data controller and data processor.
  • The data controller (institution) is the main obligor; The AI ​​provider is often the data processor and requires a contract.
  • Among the general principles, the most critical for AI are data minimization and purpose limitation.
  • Entering data into AI is a transaction, and often a transfer; Legal basis and contract are required.
  • Each new AI activity should be recorded in the processing inventory and, if necessary, reflected in the VERBIS record.

Application task

Choose a real processing activity your organization would like to do with AI (e.g. theme analysis of customer complaints). Fill out a processing inventory line for this activity: purpose, data category, contact group, possible legal bases, recipients, transfer status and retention period. Then pass the data to be entered into the AI ​​in this activity through a minimization filter: list which fields are unnecessary and which to mask. Finally, write down who is the data controller of this activity, who is the data processor, and what contract is required between them.

checklist

  • [ ] I detected personal and private data in the activity.
  • [ ] I clarified the data controller and data processor.
  • [ ] I applied minimization: removed/masked unnecessary areas.
  • [ ] I have defined the purpose of processing specifically and legitimately.
  • [ ] I filled out a processing inventory line.
  • [ ] I evaluated the transfer (overseas server) situation.
  • [ ] I have scheduled the retention period and deletion of AI history.