Gains:
- Ability to classify and anonymize student data within the framework of KVKK and special personal data concepts and apply safe vehicle selection
- Ability to adapt PDR professional ethics principles (confidentiality, beneficence, non-maleficence, autonomy) to the use of artificial intelligence
- Ability to recognize bias, cultural insensitivity and hallucination in artificial intelligence output and create an ethical use policy
Trust is at the heart of the PDR profession. If a student can tell his/her most intimate feelings, family, and fears to a specialist, it is only because he/she believes that the information will be protected. Artificial intelligence tools pose a serious new test to this trust: the most sensitive data can go out of control in a sentence. In this unit, we systematically discuss privacy, KVKK, PDR professional ethics and how they apply to the use of artificial intelligence. We have applied these principles piece by piece in previous units; Here we will combine it as a whole and turn it into a permanent policy.
KVKK and data types: what is more protected
KVKK (Personal Data Protection Law) is the law that regulates the lawful processing of people's data. Two concepts are particularly important. Personal data is any information that identifies or identifies a person: name, surname, school number, class, address, photograph. Special personal data is a type of sensitive data that requires higher protection: health, mental state, diagnosis, sexual life, religion, ethnicity, criminal status. The majority of PDR records fall into this second, sensitive category; because mental status, family issues and support history are directly private data. This means that PDR data should never be entered in its raw form into public tools.
In practice, this translates into three rules: (1) Data minimization — work with the least amount of data needed to do a job. (2) Anonymization — make data unlinkable to the individual by removing personally identifiable information. (3) Secure means and purpose boundary — use data-secured enterprise tools where possible and process data only for the purpose for which it was collected.
Attention: It is not enough to say "I anonymized it somehow". Even if a name is omitted from a text, a unique description of the situation (a very specific situation in a single student at a small school) can make the person identifiable. In anonymization, generalize not only the name but also the details that together indicate the person.
Anonymization practice: a control procedure
Before exporting a text to the tool, follow this procedure: (a) Remove direct identifiers such as name, surname, number, class-branch, parent name, address, telephone, school name. (b) Generalize indirect descriptors: “a middle school student” instead of “the only visually impaired student in 12-B.” (c) Blur date and event details as necessary. (d) Post-reading: "Can anyone reading this text find out who is being mentioned?" If the answer is vague, generalize further. The authenticated record is written only to the institution's closed, secure system; The AI tool is outside this system.
PDR professional ethics and AI
PDR professional ethics is based on four fundamental principles, each of which directly applies to the use of AI:
- Confidentiality (keeping secrets): Student information is protected. Not entering raw data into AI, anonymizing it and choosing a safe tool is a requirement of this principle.
- Beneficence: Everything done should serve the well-being of the student. AI is used for convenience, not in a way that would compromise the student's benefit.
- Nonmaleficence: The priority is to do no harm. Unverified output, inaccurate statistics, labeling, and the use of AI in crisis are risks of harm; therefore verification and crisis boundary is an ethical imperative.
- Autonomy: The student's right to make his or her own decision is protected. AI should not reduce the student to a label or make decisions on his/her behalf.
Accountability is added to this: The responsibility for every output used lies with the expert; "AI produced it" is not a defence.
Bias, cultural sensitivity and transparency
AI can reflect social patterns in training data. In PDR, this is an issue of fairness: outcomes that stereotype a student according to their gender, culture, or socioeconomic status undermine equality of opportunity. The expert checks the content produced for cultural sensitivity and bias. Also transparency: where appropriate, it should be made clear internally that AI was used in the preparation of a material or draft; It should not be used as a secret "magic". Confidentiality is essential in the relationship with the student; What the student explains does not carry over to a vehicle.
Step by step: establishing an AI usage policy
- Classify data. Separate all the information you have as "personal / private / public".
- Select vehicle. The only secure, enterprise tool for sensitive data; Work anonymously for the general outline.
- Follow the anonymization procedure. Run the check routine before each entry.
- Validation and bias checking. Examine each output for fact and fairness.
- Maintain crisis limit. Keep the crisis and consultation relationship out of the vehicle.
- Take responsibility and be transparent. Final approval belongs to the expert; Usage is open within the organization.
Copiable templates
1) Anonymization control:
Your role: privacy audit assistant. List each statement in the text below that could DIRECTLY or INDIRECTLY identify the person (name, number, class, school, unique situation description) and suggest a more general alternative for each. Commenting content.Text: [paste text]
2) Bias and cultural sensitivity audit:
Check the following PDR material for bias and cultural sensitivity: Does it contain stereotypes about gender, culture, socioeconomic status, or family structure? Who can exclude? Flag risky statements and suggest inclusive alternatives.Material: [paste material]
3) Draft corporate AI usage policy:
Your role: PDR writing assistant. For the guidance service, draft a short internal policy on the use of artificial intelligence tools. Headings: in which jobs it is used, in which jobs it is not used (crisis, diagnosis, consultation), data anonymization rule, verification obligation, responsibility rests with the expert. Short and applicable.
Weak prompt / Strong prompt
Weak:
To summarize Ahmet Yılmaz 8-C's situation, he was being subjected to violence at home.
It enters the most sensitive data (name, class, special status) into the vehicle in its raw form — a serious violation of KVKK and ethics; Moreover, this can be a notification situation (unit 9).
Strong:
Your role: privacy control assistant. Note: I anonymized the text below before submitting it to the tool. However, check again: is there any detail left that makes the person identifiable? Text: "A middle school student hinted that he was experiencing tension at home."
three mini cases
Case 1 — Indirect disclosure. An expert was about to enter a text into the tool from which he had omitted the name; but he realized that the phrase "the school's only student who uses a wheelchair" directly referred to that person. He generalized this to "a student". Name-making alone was not enough; The description of the unique situation was also identifying.
Case 2 — Bias correction. An expert who audited a career material found that the AI always used male names in engineering examples and female names in care professions. It balanced the samples and broke the mould. This seemingly minor correction preserved the fairness of the message sent to students.
Case 3 — Establishing policy. A guidance service created a common internal policy text to eliminate the confusion arising from the fact that everyone uses AI differently: in which tasks it is used, not in crisis and diagnosis, data is anonymised, output is verified, responsibility lies with the expert. AI gave draft; The team finalized the content with their own values. Uncertainty gave way to a clear framework.
Common mistakes
- Entering raw data. Writing to vehicle with name/status. Solution: anonymization procedure, secure tool.
- Just removing the name. Forgetting indirect identifiers. Solution: generalize unique details as well.
- Ignoring bias. Adopting stereotypical output. Solution: bias and culture audit.
- Putting the responsibility on the vehicle. It means "AI produced it". Solution: accountability lies with the expert.
- Misuse. Processing data collected for one purpose for another purpose. Solution: respect the purpose limit.
Table: Data type and AI rule
Data type
example
AI rule
public
General profession introduction
freely available
personal data
Name, number, class
Cannot be entered without anonymization
Special quality data
Mental status, family, diagnosis
It can never be entered in its raw form.
crisis data
Risk, abuse, suicide
Never enter the vehicle (unit 9)
In summary
In PDR, confidentiality is the foundation of trust in the profession and the most tested principle in the AI era. KVKK separates data into personal and private data; Most PDR data is sensitive and is not entered into the tool in its raw form. Data minimization, anonymization (with direct and indirect identifiers) and safe tool selection are the basic rules. The four principles of professional ethics—confidentiality, beneficence, nonmaleficence, autonomy—are binding on the use of AI; Bias is controlled, responsibility remains with the expert, and usage is transparent within the organization.
Application task
Draft a brief "AI Use Policy" for your own guidance service. Get a head start with the “Enterprise AI usage policy draft” template; Then adjust it according to the reality of your own institution. Also pass a (fictional) text through the "anonymization check" template and capture and generalize at least one indirect identifier.
checklist
- [ ] I have classified the data I have as personal / private / public.
- [ ] I have generalized direct and indirect identifiers in anonymization.
- [ ] I used secure/enterprise tool for sensitive data.
- [ ] I checked the output for bias and cultural sensitivity.
- [ ] I accepted responsibility and kept usage transparent.