What the Board decided, and why it matters now
On 8 October 2026 Türkiye's Personal Data Protection Authority (KVKK) published a principle decision of its Board on how employers may monitor the corporate e-mail accounts they give employees and the other channels used for work. It is Decision No. 2026/2035 of 16 September 2026, and it appeared the same day in the Official Gazette of 8 October 2026 (No. 33394).
The decision is short, about 1,100 words in Turkish, set out as fourteen headed points. It came out of complaints. The Board says it received "various notices and complaints" alleging that employers' monitoring breached Law No. 6698 on the Protection of Personal Data (the KVKK). Having examined them, it found a pattern. Employers were monitoring work channels, reading message content, reviewing traffic and log records and running "filtering or routine audit practices". They then used the results in disciplinary and dismissal proceedings, without having informed employees "adequately, clearly and concretely".
Nothing in the decision mentions artificial intelligence. It does not refer to algorithms, automated analysis or any particular software. The AI angle in this article is our analysis, not the Board's. We take it up because the practices the decision restricts are now largely carried out by software, and a growing share of that software uses machine learning. Spam and phishing filters, data-loss-prevention scanners, "productivity analytics" dashboards, insider-threat tools that score messages for risk, sentiment analysis and AI assistants that index a whole mailbox all process workplace communications, and several of them read the content of every message. A decision that limits routine, continuous content review is therefore, in practice, a decision about these tools, whether or not it names them.
What the decision actually says
The Board's premise sets the tone. A corporate e-mail account is not merely a means of communication but a data source about the employee's professional and sometimes personal network, working patterns and correspondence. Monitoring it requires a fair balance between the employer's powers under the employment contract and its right to manage, and the employee's rights under Articles 20 and 22 of the Constitution: privacy, protection of personal data and freedom of communication. The fourteen points, summarised in our words and quoted where the wording matters, are:
- The Law applies in full. Monitoring is subject to the KVKK's processing conditions, general principles and its notice and security duties. "İletişim aracının işverene ait olması veya işyerinde kullanılması, işverene çalışanların iletişim faaliyetleri üzerinde sınırsız bir denetim yetkisi sağlamamaktadır" ("That the communication tool belongs to the employer or is used at the workplace does not give the employer unlimited power to monitor employees' communications").
- Business and private use must be distinguished, by reference to the purpose for which the tool was provided and the rules on its use.
- Rules on private use may be set, but must be clear and knowable. Even where private use is banned, monitoring is limited by proportionality; where the two uses cannot be separated, the power to monitor is read more narrowly.
- Technical access is not legal access. Technical reach into a device, session or network does not entitle the employer to read the employee's personal e-mail, messaging apps or social media.
- Prior notice is one element of lawfulness. But the notice required in Constitutional Court case law and the duty to inform under Article 10 of the KVKK "are not the same concepts". A proper Article 10 notice can satisfy the prior-notice requirement; not every notice is an Article 10 notice.
- Content of the notice: the legal basis, purpose, scope and method of processing, the circumstances in which content may be accessed, the retention period and the employee's rights under Article 11.
- General statements are not enough. A bare statement that the account "may be monitored" may not count as prior notice and does not by itself discharge Article 10.
- Explicit consent cannot, as a rule, be treated as the primary legal basis for e-mail monitoring, given the dependency and power imbalance in employment. Where it is relied on, its freedom must be assessed on the facts; and no consent or other condition gives unlimited monitoring power.
- General principles and proportionality under Article 4: lawful and fair, for specific, explicit and legitimate purposes, relevant, limited and proportionate, and no longer retained than necessary.
- Graduated monitoring. "Denetim faaliyetlerinde kademelilik esas alınmalıdır" ("Monitoring must be graduated"). A heavier method must not be used where a less intrusive one would do.
- Content review should, as a rule, take place only where a legitimate purpose is linked to a concrete suspicion or a specific incident, and only so far as that purpose requires. "Kapsamı belirsiz, genel ve sürekli nitelikte içerik incelemelerinden kaçınılması gerekmektedir" ("Content reviews of indeterminate scope and of a general and continuous nature must be avoided").
- Special categories and third parties. Content may contain special-category data under Article 6, and communications carry correspondents' data; effects on them must be considered.
- Access control and security. Access is limited to a defined number of staff given that task and authority, with rights set by job description, access logged and confidentiality secured.
- End of employment. Processing a departed employee's account needs its legal basis reassessed; the end of employment "does not mean that the data may be accessed or processed indefinitely".
The Board closes by announcing that where these points are not observed it will act against controllers under Article 18 of the Law, the administrative-fines provision.
The constitutional backdrop, and where the Board goes further
The Board's reference to "the Constitutional Court's case law" points to two individual-application judgments. The first is the Plenary judgment in application no. 2016/13010 (17 September 2020), published in the Official Gazette of 14 October 2020 (No. 31274). A lawyer employed by a law partnership was dismissed after the employer, in a disciplinary inquiry, examined corporate e-mail accounts, including his team leader's. The Court unanimously found violations of Article 20 and Article 22, ordered a retrial and awarded non-pecuniary damages.
Its reasoning supplies most of the Board's vocabulary. Employers may in principle monitor the tools they provide, for reasons such as efficiency, information control, liability, productivity or security. But treating ownership of the tools as conferring "sınırsız ve mutlak bir gözetleme ve denetleme yetkisi" (an unlimited and absolute power of surveillance and monitoring) is incompatible with the employee's legitimate expectation of respect for fundamental rights at work (§ 69). The Court then set out safeguards (§ 70): legitimate reasons, with "more serious reasons" required for content than for the flow of communications; transparent prior notice of the legal basis, purposes, scope, retention, rights, consequences and recipients; suitability; necessity, asking whether the aim could be met without reading content; proportionality; and a fair balance. On the facts, no clear notice had been shown, less intrusive means (analysing complaints, hearing witnesses, examining work records) had not been considered, and the review had reached third-party correspondence and content of uncertain relevance (§§ 76–78).
The second judgment, more favourable to employers, went the other way. In B. No: 2018/31036 (First Section, 12 January 2021), published in the Official Gazette of 5 February 2021 (No. 31386), a bank employee's contract stated that the corporate account was for business use only and could be monitored "without notice". The Court found no violation. Once clear notice is given, it said, the employer "cannot be expected" to obtain separate consent, and absent a recorded objection the employee's consent is presumed valid (§ 40). The employer had also examined only messages relevant to the specific allegation and used them only in the litigation (§ 43).
Both judgments draw on the Grand Chamber judgment in Bărbulescu v. Romania (no. 61496/08, 5 September 2017), which found a violation of Article 8 by eleven votes to six. Its paragraph 121 lists the factors: clear advance notice of the possibility and nature of monitoring; its extent and intrusiveness, distinguishing flow from content and asking how many people had access to the results; legitimate reasons, with weightier justification for content; the availability of less intrusive methods; the consequences for the employee and whether the results were used for the declared aim; and adequate safeguards, in particular against access to content without prior notice.
Against this background the Board's fifth, seventh and eighth points are its most important move. The 2021 judgment accepted a contractual "may be monitored without notice" clause as notice, and even as consent. The Board now says that constitutional notice and Article 10 information are different things, that a general statement does not discharge Article 10, and that consent is suspect as a primary basis in employment. The positions are not formally in conflict: the Constitutional Court asks whether courts adequately protected fundamental rights in a dismissal case, while the Board asks whether a controller complied with the KVKK. An employer could therefore win the dismissal case and still be fined for the monitoring. In our reading, a clause of the 2021 kind, stating neither legal basis, method, scope, retention nor Article 11 rights, is exactly the "general notice" the Board says may not suffice. For the many employers who rely on one paragraph in a contract or IT policy, that paragraph is now the starting point, not the finish line.
Why AI is at the centre of a decision that never mentions it
The decision is technology-neutral and does not distinguish between a manager reading messages and software doing so. It would be wrong to say the Board has ruled on AI tools. Three features of the text nonetheless map directly onto how those tools work.
Processing does not need a human reader. Article 3(1)(e) of the KVKK defines processing as any operation on personal data "wholly or partly by automated means", such as obtaining, recording, storing, retaining, classifying or blocking its use. A model that ingests every e-mail to classify, summarise, score or flag it is processing that e-mail's content even if no person ever opens it. The distinction between traffic data and content therefore applies to software as much as to people, and a tool that reads message bodies is on the content side of the line.
The main restriction targets what many monitoring products are built to do. The decision ties content review to "a concrete suspicion or a specific incident" and warns against review that is "general and continuous". Continuous scanning of all messages for sentiment, disengagement, attrition risk or "insider threat" is general and continuous by design. The absence of a specific suspicion is the point of such tools: they exist to generate the suspicion. That is very hard to reconcile with the tenth and eleventh points.
AI creates new personal data. A summary, a risk score or an inferred emotional state is new data about the employee, often more sensitive than the underlying correspondence and more likely to be used in decisions about them. The Board's concern that monitoring results were being used in disciplinary and dismissal processes without proper notice is sharper when the result is a model's inference rather than a quoted e-mail.
Sorting the tools: not all workplace AI is monitoring in the same sense
Nor should every AI tool that touches a mailbox be treated as forbidden. Applying the decision's graduated approach, we would sort them as follows. This is our analysis, not a classification the Board has made.
- Security filtering (spam, malware, phishing) works mainly on metadata, attachments and patterns, to protect the system rather than evaluate the employee. It is part of the "filtering" the Board observed, so it needs notice, a defined purpose and limits on who sees results. With those in place it is the easiest case to defend, under the employer's legitimate interest and its Article 12 security duty.
- Data-loss prevention scans content for defined patterns, such as identity numbers, IBANs or client files leaving the organisation. It is content processing for a narrow, stated purpose. The decision's logic points to a design in which the machine flags matches and a human looks only at the flagged item, under restricted and logged access.
- Employee-facing assistants that help users draft, summarise or search their own mail are not monitoring tools in purpose. But they typically build an index of the mailbox that an administrator may be able to query, so access, retention and hosting matter.
- Manager-facing "productivity analytics" (response times, after-hours activity, collaboration networks) usually work on traffic data, which the Constitutional Court treats as less intrusive. But they profile and compare individuals, engage the right to object to automated analysis in Article 11(1)(g), and need a purpose more specific than a general wish to "measure productivity".
- Sentiment, attrition and insider-threat scoring continuously analyses content and produces risk scores on individuals. It is general, continuous content review without a specific incident. It may generate inferences about health, belief or trade-union activity, and it is designed to feed decisions about the employee. These tools sit furthest from the decision.
The same product can fall into several categories depending on configuration. A mail-security suite with an "insider risk" module switched on is in a different legal position from the same suite running malware detection only. The analysis follows the configuration, not the product name.
Legal basis: which processing condition can carry AI monitoring?
Explicit consent (Article 5(1)) is weak as a primary basis on the Board's approach. That matters for AI tools in particular, because a consent step is sometimes proposed when such tools are rolled out. The decision makes clear such consent will be scrutinised and does not unlock unlimited monitoring in any event.
Performance of the contract (Article 5(2)(c)) requires a direct link to performing the employment contract. An employee's own drafting assistant may fit; continuous behavioural scoring is hard to describe as necessary for performing the contract. Legal obligation (Article 5(2)(ç)) covers recording or retention that sector rules require, but not analytics built on top of it.
Establishing, exercising or defending a right (Article 5(2)(e)) fits the investigation of a specific incident or dispute, matching the decision's "concrete suspicion or specific incident". It supports targeted, time-limited, AI-assisted review of a defined set of messages in a misconduct investigation. It does not support standing analysis of everyone.
Legitimate interest (Article 5(2)(f)) is where most employers will turn. It requires the processing to be necessary for the employer's legitimate interests without harming the employee's fundamental rights and freedoms, and that balance is where the graduated-monitoring and content-review points do their work. Security filtering and narrow DLP can pass it. General, continuous content scoring is unlikely to.
Special categories change the analysis. Since the 2024 amendments made by Law No. 7499, Article 6(3) of the KVKK permits processing of special-category data only on a closed list of grounds. These include explicit consent, express provision by law, establishment or defence of a right, and fulfilment of legal obligations in employment, occupational health and safety and social security. There is no legitimate-interest ground. A system that infers stress, illness, religious practice or union activity from message content therefore has no obvious basis except explicit consent, which the Board has just called weak in employment. In our view the decision's twelfth point, read with Article 6(3), is the strongest argument against emotion and sentiment analysis of employee communications under Turkish law.
Turkish labour law points the same way. Article 419 of the Code of Obligations lets employers use an employee's personal data only so far as it concerns suitability for the job or is necessary to perform the contract. Article 417 requires the employer to protect and respect the employee's personality, and Article 75 of Labour Law No. 4857 requires information about employees to be used in good faith and lawfully. None was written with AI in mind; all narrow the room for analytics beyond what the job requires.
Notice: what an Article 10 notice for an AI tool must say
Translated into an AI deployment, the sixth point means a notice should state at least:
- which channels are processed (e-mail, chat, call transcripts), and whether only metadata or also content and attachments;
- what the tool does (filters, classifies, summarises, scores, flags or indexes), the purpose of each function and the processing condition relied on;
- whether outputs about individuals are produced, who sees them, and whether they may be used in performance, disciplinary or termination decisions;
- when a human will look at content, who, and on what trigger;
- how long inputs, outputs, logs and any indices or embeddings are kept;
- the vendor and any transfer abroad, which engages Article 9 as amended in 2024;
- the employee's Article 11 rights, including the right to object to an adverse result produced exclusively through automated analysis.
Few IT policies say anything of the kind. After this decision, "corporate systems may be monitored for security and compliance purposes, including through automated tools" is unlikely to satisfy Article 10 on its own.
Article 11(1)(g) deserves particular attention. It gives data subjects the right to object to "the emergence of a result against the person by analysis of the processed data exclusively through automated systems". An insider-risk score that triggers an investigation, or a productivity score feeding a performance rating, is the kind of result it contemplates. The safest design is one in which no adverse step rests on an automated output alone: a trained person reviews the underlying facts and records their own assessment, and the employee can contest it.
Graduated monitoring, minimisation and retention as design rules
The tenth point translates naturally into system design. A graduated architecture would run: automated, content-blind controls first (authentication, access logs, attachment rules, malware scanning); then narrow pattern detection for defined risks, producing alerts rather than profiles; then human review of the specific flagged item only, by a small logged group with a recorded reason; and broader review of an individual's correspondence only where a concrete suspicion is documented, scoped in time and subject, and approved by someone other than the investigator. Continuous behavioural or emotional scoring of all staff has no natural place on that ladder, because it starts everyone on the top rung. That, rather than the novelty of the technology, is why it fits poorly with the decision.
AI also strains three Article 4 principles. Purpose limitation: a mailbox index built for employees' own searches becomes, with an administrator's query, a tool for searching everyone's mail, and summaries made for convenience drift into HR files. Repurposing should be treated as a new processing activity with its own assessment and notice. Minimisation: tools default to processing everything. The decision points the other way: switch off content analysis where metadata suffices, and exclude channels where business and private use cannot be separated. Retention: AI multiplies copies (logs, prompts, outputs, caches, vector indices). The fourteenth point bites hard on a practice now common: feeding departed employees' mailboxes into a "knowledge base" for a corporate assistant. In our reading that is a new purpose needing its own basis, and it must be reconciled with the deletion duty in Article 7.
Access, vendors and third parties
The thirteenth point requires access to be limited, role-based and logged. AI-enabled search and eDiscovery consoles make it trivial to query every mailbox in natural language, so whoever holds that console can in effect read everyone's correspondence. Access to it should be a privileged function with its own approval and audit.
Almost every tool also involves a vendor, often a cloud provider abroad. Under Article 12(2) the employer is jointly responsible with its processors for security. Under Article 9 as amended in 2024, transfer abroad in principle requires an adequacy decision or one of the listed appropriate safeguards, such as the Board's standard contractual clauses, which must be notified to the Authority within five working days of signature. Employers should know where the model runs, whether prompts and outputs are retained, and whether they may be used to train the vendor's models.
The twelfth point is a reminder that the machine also reads the clients, suppliers and applicants who wrote to the employee. They have not seen the internal notice, and some may have disclosed special-category data. External privacy notices should say that incoming communications may be processed by automated tools for stated purposes, and analysis of sensitive incoming data should be designed around the narrow Article 6(3) grounds rather than assumed to be covered by legitimate interest.
The comparative picture: the European Union and South Korea
European Union. Article 88 of the GDPR lets Member States adopt more specific employment-data rules by law or collective agreement, with safeguards "with particular regard to the transparency of processing … and monitoring systems at the work place". The AI Act adds a product-regulation layer. Annex III, point 4(b), classifies as high-risk AI systems "intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships". Article 26(7) requires employers to inform workers' representatives and affected workers before such a system is used at the workplace. Under the Digital Omnibus on AI (Regulation (EU) 2026/1744 of 8 July 2026), these obligations for Annex III systems apply from 2 December 2027 instead of 2 August 2026.
The prohibition in Article 5(1)(f) on inferring emotions in the workplace is narrower than often assumed. An emotion recognition system is defined by inference "on the basis of their biometric data" (Article 3(39)). Inferring emotions at work from voice or facial images is therefore in principle prohibited, save for medical or safety reasons. Because the definition turns on biometric data, sentiment analysis of written e-mails does not appear to be caught by the prohibition, but it may be high-risk under Annex III(4)(b) where it is used to monitor and evaluate behaviour. The AI Act can also reach deployers outside the Union where a system's output is used in the Union, which matters for Turkish groups with EU staff.
South Korea approaches the problem through privacy law, labour-relations law and its AI framework. Under Article 15(1)(6) of the Personal Information Protection Act (PIPA), legitimate interest applies only where the controller's interest "clearly" overrides the data subject's rights and within a reasonable scope, a higher bar than the Turkish balancing test. Article 37-2 gives a right to refuse fully automated decisions (expressly including AI systems) that significantly affect rights or obligations, and a right to an explanation. The right to refuse does not apply where the decision rests on consent, law or contract, but the right to an explanation does. The Act on the Promotion of Worker Participation and Cooperation makes "the installation of worker-monitoring equipment in the workplace" a matter for consultation in the labour-management council (Article 20(1)(14)). The AI Basic Act treats as "high-impact AI" systems used for "judgements or evaluations that significantly affect individuals' rights and obligations, such as hiring or loan screening" (Article 2(4)(사)). Whether workplace-monitoring scores fall within that wording is, to our knowledge, not settled.
Türkiye has no AI-specific statute in force and no collective-consultation requirement for monitoring tools comparable to Korea's. For now the KVKK decision is the most specific statement of the regulator's position available to Turkish employers, and it brings Turkish practice closer to the European model of notice, necessity and graduated intrusion than the 2021 judgment did.
Practical implications for employers
- Mapping the tools. Employers should map the tools that process employee communications (mail security, DLP, archiving, eDiscovery, analytics, assistants, transcription), recording for each whether it reads metadata or content, which modules are on, and who sees outputs.
- Purposes and bases. Purposes and processing conditions under Article 5 should be recorded for each function; where special-category data may be inferred, an Article 6(3) ground should be identified or the function switched off.
- The notice. Notices should be rewritten to cover the decision's sixth point, including when content will be accessed, retention and Article 11 rights, with AI functions described specifically.
- Less reliance on consent. Monitoring that rests on consent forms should be reassessed under another processing condition.
- A graduated ladder. Human content review should take place only on a defined flag or a documented suspicion, with a recorded reason and separate approval for broader reviews.
- A person between score and decision. No disciplinary, performance or termination step should rest on an automated output alone.
- Restricted consoles. Access to AI search and eDiscovery consoles should be restricted, and every query logged and reviewed.
- Retention. Retention periods should be set for logs, outputs and indices, and what happens to a departed employee's mailbox and any index built from it should be decided in advance.
- Vendor terms. Hosting location, retention and training terms, and Article 9 transfer mechanisms should be checked.
- Private channels. Personal accounts and channels should be excluded in policy and configuration, even when technically reachable from a corporate device.
Objections and limits
"The decision is about e-mail, not AI." True, and we have said so. But it is framed around activities (filtering, routine audit, content review, logs), not around who performs them. A limit on general and continuous content review does not lapse because the reviewer is software; software makes such review cheap enough to become the default.
"A machine does not read; privacy is touched only when a human looks." The argument has intuitive force, and the Board has not addressed it. But it sits uneasily with a statutory definition of processing that expressly covers automated operations. It also ignores that automated analysis produces scores and inferences that humans do see and act on, and that Article 11(1)(g) exists precisely because automated analysis can affect people without anyone reading anything.
"Security requires continuous scanning." Some of it does, and the decision does not prohibit it. The difficulty arises when "security" is used to describe continuous behavioural or emotional profiling of staff, which serves a different purpose and must be justified on its own terms.
"Our employees signed a contract agreeing to monitoring." After this decision that clause begins the analysis rather than ending it.
"It is only a principle decision." It was published in the Official Gazette, sets out how the Board will apply the Law and states that the Board will act under Article 18 where its points are not observed. It is the standard against which complaints will be assessed.
What to watch next
- Individual Board decisions applying the principles, which will show how strictly "general and continuous" is read and whether automated analysis is treated as content review.
- The KVKK symposium. The Authority and İbn Haldun University have announced a symposium on AI in employment and personal data protection for 3–4 December 2026, covering privacy, discrimination, transparency and accountability.
- The courts, which will have to reconcile the 2021 approach to contractual notice with the Board's stricter view.
- The EU timetable: Annex III obligations for employment AI from 2 December 2027.
- Korea: how the AI Basic Act's high-impact category and PIPA Article 37-2 are applied to workplace evaluation tools.
Frequently asked questions
Does the KVKK decision mention artificial intelligence?
No. It refers to monitoring, content review, traffic and log records and "filtering or routine audit practices". Its application to AI tools is our analysis based on the text and on the KVKK's definition of processing.
Can an employer still monitor corporate e-mail in Türkiye?
Yes. The decision does not prohibit monitoring. It requires a legal basis, a specific purpose, a detailed Article 10 notice, graduated methods, restricted and logged access, limits on retention and, as a rule, a concrete suspicion or specific incident before content is reviewed.
Is an AI e-mail assistant used by the employee "monitoring"?
Not in its purpose, but it is processing and often creates an index or summaries that others could access. It becomes monitoring if its outputs reach managers or are used to evaluate the employee.
What about a departing employee's mailbox?
The legal basis must be reassessed after employment ends, and the data are not accessible indefinitely. Using the mailbox to feed a corporate AI assistant is, in our reading, a new purpose needing its own justification.
Is sentiment analysis of employee e-mails banned in the EU?
Not by the Article 5(1)(f) prohibition, which concerns emotion inference from biometric data. Text-based scoring used to monitor or evaluate workers may, however, be high-risk under Annex III(4)(b), with obligations from 2 December 2027, and remains subject to the GDPR.
Burhan Doğuş Ayparlar's View
This section sets out my personal assessment as the founder of this site and an attorney at law (Türkiye).
The most important sentence in this decision is not about notice or consent. It is the one saying that owning the tool does not give the employer unlimited power over what passes through it. Turkish workplace practice has long run on the opposite intuition: the server is ours, the account is ours, so the messages are ours to read. The Constitutional Court rejected that intuition in 2020. The Board has now turned the rejection into a working standard and attached Article 18 to it.
I think the decision matters more for AI than its silence suggests. The commercial logic of AI monitoring is to replace targeted review with continuous coverage: instead of investigating the incident, score everyone to find incidents before they happen. The Board's insistence on graduated monitoring and on a concrete suspicion before content is reviewed answers that logic directly, if unintentionally. It does not prohibit the technology. It prohibits the default setting in which the technology is usually sold.
I would draw a clear line between tools that protect the system and tools that evaluate the person. Security filtering and narrowly configured data-loss prevention can comfortably be brought within the decision. Continuous sentiment, engagement or "insider risk" scoring of employees' correspondence cannot, in my view, without a very specific justification that few employers will be able to give. Where such scoring could reveal health, belief or union activity, I see no workable basis under the amended Article 6 at all. Employers who have such modules, often bundled with a security suite, should check what is actually switched on.
Two things would help. The Authority should say expressly, in guidance or its first individual decisions, how it treats automated analysis of content; employers and vendors should not have to infer it from a definition in Article 3. And in the longer term Turkish law lacks a collective dimension. Korea requires consultation with the labour-management council before monitoring equipment is installed, and the EU AI Act requires employers to inform workers' representatives before using high-risk AI at work. Monitoring designed together with those being monitored is more likely to be proportionate and more likely to be trusted. That is a matter for the legislature, and worth considering when Türkiye's AI framework is drafted.
This article is for information only and does not constitute legal advice. It is based on the Personal Data Protection Board's principle decision No. 2026/2035 of 16 September 2026 as published on the KVKK website and in the Official Gazette of 8 October 2026 (No. 33394), the Constitutional Court judgments in applications 2016/13010 and 2018/31036 as published in its decisions database, the European Court of Human Rights judgment in Bărbulescu v. Romania, and the legislative texts cited, as consulted on 8 October 2026. The decision does not refer to artificial intelligence; its application to AI tools, and the classification of those tools, are the author's analysis and have not been confirmed by the Board. Statements about Turkish, EU and Korean law are general in nature; specific cases require individual assessment. The analysis and assessments are the author's own.