Gains:
- Seeing the similarities and differences between GDPR and KVKK
- Protection against automated decisions and enforcement of the right to human intervention (Article 22 GDPR)
- Knowing that cross-border data transfer requires appropriate assurance and choosing mechanisms
Why does a Turkish company also have to know Europe's data protection law (GDPR)? Because GDPR binds not only companies located in the EU, but any company that provides goods/services to people in the EU or monitors their behavior. Moreover, two issues that go to the heart of AI use — automated decisions and cross-border data transfer — are crystal clear in the GDPR. In this unit, we will compare GDPR and KVKK, learn what GDPR Article 22 means for AI and the rules of operating data on an AI server abroad.
GDPR and KVKK: siblings but not the same
GDPR (General Data Protection Regulation) is the EU's data protection regulation that came into force in 2018. KVKK is largely inspired by the GDPR; so most of the concepts are common. But there are also differences.
Subject
KVKK
GDPR
Source
Law No. 6698 (Türkiye)
EU Regulation
geographical scope
processing in Türkiye
Service/tracking to persons in the EU
Right to automatic decision
Right of objection in Law 11
Explicit protection in Article 22
Administrative fine
Amounts specified in the law
Up to 4% of annual global turnover
Data protection officer (DPO)
limited obligation
Mandatory in certain cases
Cross-border transfer
Appropriate assurance/explicit consent
Adequacy decision / appropriate safeguards
Tip: If you are performing processing that is subject to both KVKK and GDPR, complying with the stricter rule will generally keep you on the safe side of both. Rather than managing the two texts separately, a “highest bar” approach is practical and defensible.
Article 22: protection against decision made solely by the machine
The most critical provision of the GDPR in terms of AI is Article 22. Its essence is this: a person has the right not to be subject to a decision that significantly affects him or her, legally or similarly, and which is based solely on automated processing (i.e., entirely on AI, without human intervention). Examples: a loan application being rejected entirely by the algorithm, a candidate being eliminated entirely automatically.
There are exceptions to this right (if necessary for a contract, if there is explicit consent, etc.), but even in case of exception, the person should be given at least the following guarantees:
- The right to request human intervention (to have a human review the decision).
- The right to express your opinion.
- The right to appeal the decision.
- Meaningful information about the rationale for the decision (transparency).
In practice, this means: making AI the sole decision-maker for decisions that significantly affect the person; Always put in a real human approval/review step.
three mini cases
Case 1 — Completely automatic rejection. A fintech company rejects loan applications entirely with an AI score; people never look. An applicant asks for the reason for rejection and requests human review. According to Article 22, the company must meet this request, have a human review the decision and explain the logic in a meaningful way. The right design: Making AI a "decision recommender" and requiring human approval for negative decisions.
Case 2 — Foreign transfer risk. An Istanbul company summarizes EU customer support requests with an AI tool abroad. This is a cross-border transfer in terms of both GDPR and KVKK. The company realizes that it is operating without a suitable mechanism for transfer (below) and is adding standard contractual clauses to the data processing agreement and updating the disclosure to customers.
Case 3 — Compliance with solid bar. A Turkish software company serving its customer in Germany is covered by both KVKK and GDPR. Instead of managing the two texts separately, the team builds on the stricter requirements of the GDPR: conducts data protection impact assessment, provides clear lighting, guarantees human supervision. Thus, it is safe in both jurisdictions with a single compliance framework.
Cross-border data transfer
Cross-border transfer is the sending of personal data to another country (for example, to the AI provider's overseas server). Data cannot be transferred haphazardly; A suitable mechanism is required:
mechanism
briefly
Qualification decision
Official recognition that the target country provides adequate protection
Appropriate safeguards
Standard contractual clauses, binding corporate rules, letter of undertaking
Explicit consent / exception
Informed explicit consent of the person in certain cases
In practice, the most common way to use AI is to include standard contractual clauses in the data processing contract signed with the provider and transparently document where data is processed.
Attention: Saying "I encrypted the data, it is now secure" does not eliminate the transfer obligation. Encryption is a good security measure, but it is not the sole legal transmission mechanism. The transfer also requires an appropriate contractual/legal basis.
Copiable templates
TEMPLATE 1 — Article 22 check: "Evaluate the following AI-powered decision process: [describe the process]. Does this decision 'significantly' affect the person and is it made 'only automatically'? Does it fall within the scope of Article 22 GDPR? If so, what safeguards (human intervention, objection, explanation) should I include, write out clause by clause."
TEMPLATE 2 — Choice of transfer mechanism: "I will process personal data on the overseas server of the following AI tool: [describe tool and data]. Is this a cross-border transfer? Evaluate appropriate transfer mechanisms (adequacy decision, standard contractual clauses, express consent) according to my situation. Refer to law for final decision; just compare options."
TEMPLATE 3 — Human review step design: "Design a 'human review' step to the following automated decision process: [describe the process]. Which decisions should be directed to the human (e.g. negative outcomes), what should the human check, how should the objection be recorded? Write the flow step by step."
TEMPLATE 4 — KVKK/GDPR gap analysis: "Compare side by side the KVKK and GDPR obligations for the following processing: [describe the processing]. Show 'What does KVKK say / what does GDPR say / which is stricter' in each line and add a suggestion 'what should I do to comply with the strictest bar'."
Weak prompt / Strong prompt
WEAK: “Is this AI credit system legal?”-> The model gives a vague, generic 'it depends' answer; It does not evaluate Article 22 and transfer dimensions. GÜÇLÜ: "For EU customers, we are establishing a system that evaluates loan applications with an AI score; the data is processed abroad. (1) What safeguards should we add in terms of Article 22 GDPR, (2) what mechanism is required for cross-border transfer? Mark where you are not sure." -> The model addresses two critical dimensions separately, in an applicable way.
Common mistakes
- Thinking "We are a Turkish company, GDPR does not concern us"; whereas providing services to people in the EU is sufficient.
- Leaving the decision that significantly affects the person entirely to AI and not requiring human review.
- Bypassing Article 22 safeguards (human intervention, objection, disclosure).
- Not establishing the transfer mechanism (contractual terms) at all when using an overseas AI tool.
- Mistaking encryption as a legal transmission mechanism.
- Managing KVKK and GDPR separately and falling into contradiction; whereas the strictest bar approach is simpler.
- Not reflecting the transfer and automatic decision logic in the clarification text.
In summary
- GDPR also binds Turkish companies providing services to people in the EU; It largely overlaps with KVKK but may be stricter.
- Article 22 protects against decisions that significantly affect the person and are made solely automatically; It brings with it the right to human intervention, objection and explanation.
- AI decisions that impact a person should always have a real human review step.
- Processing data on an overseas AI server is a cross-border transfer; It requires an appropriate mechanism (mostly standard contractual clauses).
- If you are covered by both KVKK and GDPR, complying with the strictest bar is the most practical and safe way.
Application task
Choose an AI use your organization taps into EU people's data. First evaluate whether this use falls within the scope of Article 22 GDPR; If so, put the four assurances to be added (human intervention, opinion, objection, explanation) into concrete steps. Then determine if this use involves cross-border transfer and select the appropriate transfer mechanism on the grounds. Finally, create a short table of differences that puts KVKK and GDPR obligations side by side for the same use and write down the three steps you will take to "comply with the strictest bar".
checklist
- [ ] I have determined whether the use falls within the scope of the GDPR.
- [ ] I have carried out the Article 22 check and designed the necessary safeguards.
- [ ] I added a human review step to decisions that affect the person.
- [ ] I detected whether there was cross-border transfer.
- [ ] I have selected and documented the appropriate transfer mechanism.
- [ ] I made the KVKK/GDPR difference analysis and set the strictest bar.
- [ ] I reflected the automatic decision and transfer in the illumination text.