What the guide says
The guide addresses lawyers' obligations across the whole of professional practice: client data, litigation files, assignment by the bar, lawyers in employment, domestic and cross-border transfers, data-controller duties and data security. The section that will matter most in practice is the one on the use of generative AI tools.
Its reasoning is short and hard to argue with. A generative AI service processes what is submitted to it on infrastructure the user does not control. Where that infrastructure sits outside Türkiye — which is true of every major general-purpose model service — submitting personal data to it makes the data available to a recipient abroad. Under Law No. 6698, that is a transfer, and transfers abroad must satisfy Article 9.
From that the guide draws a set of expectations. Lawyers should check the provider's terms of use, its retention policy and its sub-processor arrangements before submitting anything. They should mask or anonymise as far as possible. They should submit only the minimum necessary for the task. And they should not upload special-category data at all.
None of these are new legal rules. That is the point, and the reason the guide is more consequential than a new rule would be.
Why a guide matters more than it looks
KVKK guides are not legislation. They do not create obligations, and a lawyer who departs from one has not thereby broken the law. What they do is fix the regulator's stated expectation, and in Turkish data protection practice that is most of what determines outcomes.
Article 12 of Law No. 6698 requires the data controller to take appropriate technical and organisational measures. "Appropriate" is not defined and cannot be — it is a standard that takes its content from circumstances, and one of those circumstances is what the regulator has said it expects. Once KVKK has published a specific expectation in a specific context, a controller who did the opposite is not arguing about an unsettled question. They are explaining a departure.
The same mechanism operates on the administrative fine. Law No. 6698 directs attention to the nature of the breach and the circumstances in which it occurred. A breach that occurs despite a good-faith attempt to follow published guidance is a different case from one that occurs because published guidance was ignored.
So the guide's practical effect is not that uploading a file to a chatbot became unlawful on 22 September. It is that after 22 September, doing it without having considered Article 9 is no longer something a Turkish lawyer can characterise as an oversight.
The transfer analysis, in detail
Article 9 of Law No. 6698, as amended in 2024, permits transfer abroad on three routes.
The first is an adequacy decision. KVKK has issued none. This route is, for the present, theoretical.
The second is an appropriate safeguard: standard contractual clauses notified to the Authority within five business days of signature, binding corporate rules, an international agreement, or a written undertaking approved by the Board. In practice this means standard contractual clauses, and the notification requirement is where most compliance fails — the obligation is to notify, and firms routinely sign and do not.
The third is the exceptional route, available only where neither of the first two is, and only for transfers that are incidental rather than regular. Its grounds include explicit consent for the specific transfer, necessity for the performance of a contract, and the establishment, exercise or protection of a right.
Now apply that to a lawyer using a general-purpose AI assistant.
The realistic route is the second. That means an agreement with the provider, containing the clauses in the form KVKK has published, notified to the Authority. Enterprise offerings from major providers do include data-processing terms, and some can be brought into the required form. Consumer-tier accounts, which is what most lawyers actually use, cannot.
The third route is worth examining because it will be reached for, and it does not work as well as people hope. Explicit consent must be specific, informed and freely given, which means telling a client that their file will be submitted to a named foreign service, and accepting that the client may say no. Contract necessity is a poor fit: the retainer requires legal services, not a particular tool, and the tool is a choice the lawyer made for efficiency. The "protection of a right" ground is genuinely arguable in some litigation contexts, but it will not carry routine drafting or summarisation. And the whole exceptional route is confined to transfers that are not regular — daily use of an AI assistant is regular by any reading.
Special-category data and the bright line
The guide's instruction not to upload special-category data is the one part that functions as a rule rather than a consideration, and it is the easiest to breach without noticing.
Under Article 6 of Law No. 6698, special categories include health, biometric and genetic data, criminal convictions and security measures, race and ethnicity, political opinion, philosophical belief, religion or sect, dress, and trade-union, association or foundation membership.
Run an ordinary Turkish legal practice against that list. Employment files contain health reports and union membership. Criminal defence work is constituted by data on convictions and security measures. Family law files carry health and sometimes religious matters. Personal injury work is medical from beginning to end. Administrative law challenges routinely turn on disciplinary and criminal records.
The categories are not a niche. For a large part of the profession they are the practice. A criminal defence lawyer asking a model to summarise an indictment is submitting data on criminal convictions and security measures, which under Article 6 requires explicit consent unless a statutory exception applies — and the exception for data necessary for the establishment, exercise or protection of a right exists, but it does not obviously extend to choosing a foreign processing tool.
Privilege, which the guide does not resolve
Data protection is not the only regime in play, and the second one is in some ways more serious.
Article 36 of the Attorneys' Act imposes a professional secrecy obligation on lawyers, and Article 130 of the Turkish Penal Code criminalises disclosure of professional secrets. The secrecy duty is owed to the client and is not satisfied by compliance with data protection law. It is possible to satisfy Article 9 and still breach Article 36.
The question the guide does not answer is whether submitting client information to a third-party processor is a disclosure at all. The orthodox answer, and the one that lets law firms use any outsourced service, is that a processor acting under the lawyer's instruction and bound to confidentiality is an extension of the practice rather than a third party. This is how cloud storage, transcription services and document review platforms have always been treated.
Generative AI strains that reasoning at two points. Where the provider's terms permit use of submitted content for model improvement, the information has gone somewhere that is not under the lawyer's instruction and not returned. And where the provider retains content for abuse monitoring, as most do by default, an operator not bound by Turkish professional secrecy may read it.
Consumer-tier terms typically permit training use by default and require the user to opt out. Enterprise terms typically do not. This is the single most important practical distinction in the whole area, and it is a contract term rather than a technical property of the tool.
What a Turkish law firm should do this week
The guide is long; the operational response is not.
Establish which tier is in use. Consumer accounts and enterprise accounts differ on training use, retention and the availability of data-processing terms. Most firms do not know which their people are using, because most people signed up individually.
Get the transfer basis in place or stop. If AI tools are part of the workflow, the firm needs contractual terms capable of being brought into the standard-clause form and notified to KVKK within five business days. If that is not going to happen, the honest position is that the tools should not receive client data.
Draw the special-category line as a hard rule. Not a consideration to be weighed. Health, criminal, biometric, union, belief — these do not go into a general-purpose model, whatever the tier, until a considered and documented basis exists.
Make anonymisation the default working method. Names, identity numbers, dates of birth, addresses and case numbers can be stripped from most legal questions without loss. A question about limitation periods does not need the client's name. This single habit removes the majority of the exposure and costs nothing.
Address the engagement letter. Where tools will be used on client material, clients should be told. This is partly a consent question and largely a professional one: clients increasingly ask, and the answer should exist before the question.
Write the policy down. Which tools are permitted, on which tier, for what categories of work, with what handling of client data. The document is worth more than its content, because it evidences that the firm turned its mind to the question.
How this compares elsewhere
Türkiye is not the first jurisdiction to reach this question, and the comparison is useful because it shows KVKK taking a narrower and more practical line than some of its counterparts.
In the European Union the transfer analysis is structurally similar but softened by a mechanism Türkiye lacks. Chapter V of the GDPR imposes the same basic requirement, but adequacy decisions exist, and most major AI providers can rely on one for at least part of their processing, or on standard contractual clauses that do not require notification to a supervisory authority. The European conversation has therefore shifted away from transfer and toward lawful basis and purpose limitation — whether submitting client data to a model has a basis at all, and whether use for model improvement is compatible with the purpose of collection. Italy's supervisory authority has been the most active on this front, and its interventions against generative AI services have turned on basis, transparency and children's data rather than on transfer.
The absence of a Turkish adequacy decision is what makes the Turkish position stricter in practice than the European one, despite the rules looking alike on paper. A European firm using an American model service has a route that mostly works. A Turkish firm has standard contractual clauses and a notification obligation, or it has the exceptional route, which does not fit regular use.
South Korea arrived at the same subject from a different angle in the same week. On 23 September its Personal Information Protection Commission convened its AI privacy policy council on agentic AI, where participants identified excessive permissions granted to autonomous agents and prompt injection as the principal risks, and the Commission committed to publishing a dedicated guide on personal data processing in agentic AI by the end of 2026. Korea's question is about what an autonomous system may reach once it is inside the organisation. Türkiye's is about what leaves the organisation when a person submits it. Both are correct halves of the same problem, and a firm that solves only one has solved neither.
The Korean comparison carries a second lesson. Korea's professional-services question — a Ministry of Justice draft guideline that would bar lawyers from providing paid consumer-facing services in which an AI applies law to facts — is a monopoly and consumer-protection question rather than a data question. Between them, the two jurisdictions show the three distinct regimes that generative AI in legal practice engages: data protection, professional secrecy, and the regulated scope of legal services. They are usually discussed as one topic. They are three, with different regulators, different tests and different penalties.
The wider signal
It would be a mistake to read this as guidance for lawyers only.
The analytical move — treating submission to a foreign-hosted AI service as a transfer abroad requiring an Article 9 basis — is not specific to legal practice. Nothing in the reasoning depends on the data being a case file. A hospital submitting patient notes, a bank submitting customer correspondence, an employer submitting personnel records, a software company submitting user data for debugging are all, by the same reasoning, transferring personal data abroad.
KVKK has chosen to say this first in the context of a regulated profession with a statutory secrecy duty, which is the context where the point is least deniable. The reasoning it establishes applies to every sector, and everyone should expect it to be applied.
The timing places it in a busier week than it first appears. KVKK's own summit on personal data in the age of AI, 5G and smart technologies followed on 24 September, with a theme of responsible data governance. The Constitutional Court's President set out principles for AI in the judiciary on 23 September. The President called at the UN General Assembly on 22 September for acceleration of an international AI convention. A regulator that publishes a concrete, operational instrument in the same week as three high-level statements of principle is telling you which of the four it expects to be acted on.
Frequently asked questions
Is using ChatGPT now forbidden for Turkish lawyers?
No. The guide does not prohibit generative AI. It states that submitting personal data to a foreign-hosted service is a transfer abroad requiring an Article 9 basis, and sets expectations — minimisation, masking, checking terms, no special-category data — for use that complies.
Does this apply if the tool runs on Turkish infrastructure?
The transfer analysis falls away if processing genuinely stays in Türkiye, but the rest does not. Article 12 security duties, professional secrecy under Article 36 of the Attorneys' Act, and the special-category rules in Article 6 apply regardless of where the servers are.
Is anonymised data still personal data?
Properly anonymised data falls outside Law No. 6698. The difficulty is that legal fact patterns are often identifying even without names — a distinctive dispute in a small sector can identify the parties to anyone who knows the sector. Masking direct identifiers reduces risk substantially; it does not always achieve anonymisation.
Does client consent solve it?
Sometimes, and less often than hoped. Explicit consent must be specific, informed and freely given, and the exceptional transfer route it sits in is confined to transfers that are not regular. Consent is a workable basis for an occasional transfer and a poor one for a daily tool.
What about an employed lawyer whose firm provides the tool?
The firm is the controller and carries the compliance burden, but the professional secrecy duty under the Attorneys' Act attaches to the individual lawyer and is not discharged by the employer's policy. A lawyer who believes the firm's arrangement breaches secrecy has a personal problem that firm policy does not solve.
Does this create liability for past use?
The guide does not change the law retrospectively — Article 9 has applied throughout. What changes is the difficulty of characterising past practice as an honest misunderstanding. The sensible response is to fix the arrangement now rather than to audit the past.
Burhan Doğuş Ayparlar's View
This section sets out my personal assessment as the founder of this site and an AI ethics & compliance counsel.
I want to start with the part of this that is uncomfortable for my own profession, because the discussion will otherwise be conducted as though the problem is KVKK's.
A very large number of Turkish lawyers have spent the past two years pasting client material into consumer-tier chatbots. I know this because they say so, cheerfully, at conferences where I am speaking about data protection. The material includes indictments, medical reports, employment files and correspondence. Almost none of it has been preceded by a look at the provider's terms, and essentially none by an Article 9 analysis. This was not malice. It was a tool that arrived faster than the profession's habits, and the habits are what regulate most behaviour most of the time.
What KVKK has done is close the gap between what we were doing and what we would have said we were doing if anyone had asked. That is the proper function of guidance, and I think the reasoning is correct. A file submitted to infrastructure in another jurisdiction has left the country, and the fact that it left through a text box rather than an email attachment changes nothing about where it went.
Where I would push back a little is on proportionality. The guide asks lawyers to check terms of use, retention policies and sub-processor arrangements. For a large firm with a compliance function this is a task. For a sole practitioner in Gaziantep it is an invitation to read forty pages of English-language contract terms that are themselves subject to unilateral amendment. The obligation is correct in principle and difficult in practice, and the gap between those two is where guidance quietly turns into a rule that only large firms can follow. I would like to see KVKK and the Union of Turkish Bar Associations do the assessment centrally — evaluate the main services, publish which tiers can support a compliant arrangement, and produce a model clause set. That is one afternoon of institutional work that would save fifty thousand individual afternoons and would produce better compliance than any amount of exhortation.
The part I would take most seriously is the privilege question, which the guide raises and does not settle. Data protection breaches are expensive. A professional secrecy breach under Article 36 of the Attorneys' Act, with Article 130 of the Penal Code behind it, is a different order of problem, and it does not turn on whether you notified a standard contractual clause. If the provider's terms permit content to be used for model improvement, I do not think the processor-as-extension-of-the-practice reasoning survives, because the information has gone somewhere that is not under your instruction and does not come back. The enterprise-versus-consumer distinction is therefore not a procurement preference. It is the line between a defensible arrangement and one I would not want to explain to a disciplinary board.
The broader reading is the one I would give to non-lawyers, because they are the ones who will be surprised. Nothing in KVKK's reasoning is about legal practice. Submitting personal data to a foreign-hosted model is a transfer abroad whether the data is a case file, a patient note, a personnel record or a customer complaint. The Authority has made the point first where it is hardest to deny, and the analysis it has now put on the record will be applied to everyone else. Hospitals, banks, insurers and human resources departments running the same behaviour on the same consumer-tier tools should read this guide as being about them, and should read it this week rather than after the first decision that says so.
This article is for information only and does not constitute legal advice. It is based on the guide published on 22 September 2026 and public statements from the same week. Guidance issued by the Authority does not itself create legal obligations. Statements about Turkish law are general in nature; specific cases require individual assessment. The analysis and assessments are the author's own.