← All guides 3 min read
7 data protection points for companies using ChatGPT
Every prompt typed into ChatGPT, Claude or Gemini that contains a name, phone number, email or customer file is processing of personal data. As the servers are outside Türkiye, it is usually also a cross-border transfer. Liability lies with the company as data controller, not with the employee using the tool.
7 points to check
- What data goes in?Find out whether employees enter customer, staff or applicant data or trade secrets, and set out in a written AI use policy what may be entered.
- Account type and training settingsOn personal and free accounts, content may be used to improve the model depending on settings. Look for a business agreement, a data processing addendum and a no-training commitment.
- Cross-border transferUnder KVKK Art. 9, absent an adequacy decision, an appropriate safeguard such as standard contractual clauses is required; the clauses must be notified to the Authority within five business days of signing. Consent is no longer a stand-alone basis for regular transfers.
- Privacy noticesCustomer, employee and applicant privacy notices should reflect the use of AI tools, the purpose and the recipients of transfers.
- Special categories of dataHealth, biometric, criminal record or union data (Art. 6) may only be entered under strict conditions; for most companies the right rule is not at all.
- Automated decisions and human reviewWhere outcomes such as candidate screening, credit or pricing rely solely on AI output, the individual has a right to object (Art. 11). Put a human review step in place.
- Retention, access and breachesDecide how long chat history is kept, who can access it and what happens if an account is compromised. A data breach must be notified to the Authority within 72 hours of becoming aware of it.
Outright bans rarely work; staff keep using personal accounts. The better route is an approved tool, a short use policy, updated privacy notices and a transfer safeguard.
