In plain terms
Both laws rest on the same idea: an organisation may use information about a person only for a stated purpose, on a recognised legal ground, and no more of it than the purpose requires, and the person keeps rights over that information throughout. The laws do not mention language models and did not need to. Pasting a customer's complaint into an AI assistant is processing personal data, exactly as storing it in a database is.
Why it matters
Most AI projects in a company touch personal data sooner or later, and the questions are the same each time. On what legal ground is the data used? Was this use foreseeable when it was collected? Does it leave the country when it is sent to a model provider? Is the provider a processor acting on instructions, and does it keep the data or train on it? Can a person still have their data corrected or deleted? Answering these before a launch is far cheaper than after a complaint. For Turkish companies the transfer of data abroad needs particular attention, since most model providers process it outside Türkiye.
Example
A retailer in Istanbul wants its support team to use a cloud AI assistant on 200,000 customer conversations. The review finds three issues: the provider's servers are abroad, the standard terms allow the provider to keep prompts for 30 days, and conversations sometimes contain health information. The retailer signs a data-processing agreement with zero retention, completes the cross-border transfer mechanism that the law requires, and masks identifiers before sending. The launch moves by five weeks.
Most often confused with
GDPR / KVKK vs. EU AI Act
Data protection law asks whether personal data is handled lawfully. The AI Act asks whether an AI system is safe and trustworthy for its purpose. An AI project that processes personal data answers to both, and to two different supervisory authorities.
Under the hood
GDPR: Regulation (EU) 2016/679, applicable since 25 May 2018, with fines of up to 20 million euros or 4% of worldwide annual turnover; it also reaches organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour. KVKK: Law No. 6698, in force since April 2016. Amendments effective from 1 June 2024 revised the conditions for processing special categories of data and set a new regime for transfers abroad: an adequacy decision, appropriate safeguards such as standard contracts notified to the authority, or limited exceptions. What matters for AI under both laws: legal basis and purpose limitation, data minimisation, transparency notices, security, processor contracts, impact assessments for risky processing, and the rights of access, correction and erasure, which are hard to honour once data is inside a trained model. The GDPR restricts decisions based solely on automated processing that have legal or similarly significant effects; KVKK gives a right to object to an adverse result produced solely by automated analysis. The Turkish authority has published recommendations on AI (2021), a guide on generative AI (2025) and a note on generative AI in the workplace (2026). As of October 2026 Türkiye has no AI-specific law in force; bills are before parliament.