AI-built projects

Legal review for projects built with AI

Project-specific legal texts, KVKK (Turkish data protection law) compliance and a lawyer's pre-launch review for websites and mobile apps built with AI tools.

Hands working on a laptop at night

← All guides 3 min read

7 data protection points for companies using ChatGPT

Every prompt typed into ChatGPT, Claude or Gemini that contains a name, phone number, email or customer file is processing of personal data. As the servers are outside Türkiye, it is usually also a cross-border transfer. Liability lies with the company as data controller, not with the employee using the tool.

7 points to check

  1. What data goes in?Find out whether employees enter customer, staff or applicant data or trade secrets, and set out in a written AI use policy what may be entered.
  2. Account type and training settingsOn personal and free accounts, content may be used to improve the model depending on settings. Look for a business agreement, a data processing addendum and a no-training commitment.
  3. Cross-border transferUnder KVKK Art. 9, absent an adequacy decision, an appropriate safeguard such as standard contractual clauses is required; the clauses must be notified to the Authority within five business days of signing. Consent is no longer a stand-alone basis for regular transfers.
  4. Privacy noticesCustomer, employee and applicant privacy notices should reflect the use of AI tools, the purpose and the recipients of transfers.
  5. Special categories of dataHealth, biometric, criminal record or union data (Art. 6) may only be entered under strict conditions; for most companies the right rule is not at all.
  6. Automated decisions and human reviewWhere outcomes such as candidate screening, credit or pricing rely solely on AI output, the individual has a right to object (Art. 11). Put a human review step in place.
  7. Retention, access and breachesDecide how long chat history is kept, who can access it and what happens if an account is compromised. A data breach must be notified to the Authority within 72 hours of becoming aware of it.

Outright bans rarely work; staff keep using personal accounts. The better route is an approved tool, a short use policy, updated privacy notices and a transfer safeguard.

Ask a question