What happened

In the trend, spreading under hashtags such as "#80lerchallenge", users upload their own photos to AI-powered apps to get images styled after the fashion, hair and photography of the 1980s, then share the results. As the trend grew, the KVKK issued a public message with two core calls to users: check what data an app can access before sharing any photo with it, and find out what purposes that data may be used for. The gist of the Authority's message was that memories can be kept alive, but what belongs to a person should stay with that person.

The timing is no accident. Similar transformation trends have erupted periodically in recent years: ageing filters, anime-style conversions, "professional headshot" generators. With each wave, millions of people send high-resolution images of their faces to foreign servers — usually without reading the terms of use.

Why a selfie can be "biometric data"

Turkey's Law No. 6698 on the Protection of Personal Data (the KVKK) lists biometric data as a "special category of personal data." Like health and genetic data, it is subject to a stricter protection regime because unlawful processing can have severe consequences for the individual.

There is, however, an important distinction: not every photograph is biometric data by default. Under the approach also adopted in European data-protection law, a facial image becomes biometric data when it is processed through specific technical means that allow or confirm the unique identification of a person. Keeping a photo in an album is one thing; extracting the geometry of a face — the distance between the eyes, the jawline, the shape of the nose — and turning it into a mathematical model is quite another.

Most AI transformation apps perform precisely the second kind of processing: they detect the face, extract its landmarks, and generate a new image that preserves that structure. The transformed picture still "looks like you" only because the distinctive features of your face have been processed technically. That is where the legal basis of the KVKK's warning lies.

What happens behind the scenes when you upload a photo

To make the legal assessment concrete, it helps to walk through how a typical AI transformation app works. Apps differ, but the general pipeline usually looks like this:

  • Collection. The photo is uploaded to the app's server, often uncompressed and with metadata such as location, device model and capture date. If broad gallery access has been granted, the app may technically be able to reach photos the user never selected.
  • Face detection and alignment. The model finds the face in the image, marks its contours with dozens of landmarks and aligns the image around them.
  • Encoding. The face is typically converted into a numerical vector known as an "embedding." This vector densely represents the distinctive features of a person's face and is technically quite similar to the representations used by facial-recognition systems.
  • Generation. A generative model produces a new image in the requested style while preserving that representation.
  • Retention and secondary use. The original photo, the generated image and the intermediate representations may be stored for a defined or undefined period to deliver the service, debug, improve quality or train models.

The legally critical point is that the user sees only the "fun image" at the end, while the truly valuable data is produced in the intermediate steps. Most privacy notices say nothing about those steps.

The legal framework for special-category data after the 2024 amendment

Law No. 7499, adopted in March 2024 and in force since 1 June 2024, fundamentally changed the KVKK's provisions on special categories of personal data and on cross-border transfers. The picture today:

  • Conditions for processing. Special-category data is prohibited by default and may be processed only with the data subject's explicit consent or under one of a limited set of other conditions listed in the law. For an entertainment photo app, the only condition that can realistically be relied on is usually explicit consent.
  • The quality of explicit consent. Explicit consent must relate to a specific subject, be based on information and be freely given. Blanket, service-bundled approvals of the "by using the app you accept all terms" type may not amount to valid explicit consent for biometric data.
  • The duty to inform. The controller must tell data subjects the purpose of processing, to whom the data may be transferred, the method of collection and the legal basis. The KVKK's finding that "users are not informed of the purposes" points directly at this obligation.
  • Cross-border transfers. The amendment introduced adequacy decisions, appropriate safeguards — such as standard contracts that must be notified to the Authority within the statutory deadline and binding corporate rules — and, in limited cases, occasional transfers. Uploading a photo to an app whose servers are abroad will in most cases amount to a cross-border transfer.

We cover how these rules apply in practice in our guide to KVKK and AI governance and in training data: the KVKK and GDPR questions to settle first.

What apps can do with your face: five concrete risks

1. Use for model training

Many apps' terms grant a broad licence over uploaded content "to improve the service." That wording can cover your face becoming training data for future AI models. Once a face has entered a model's training data, tracing it and securing its deletion is extremely difficult.

2. Undefined retention periods

The promise that "your image is deleted after processing" does not always rest on a written, auditable commitment. If no retention period is stated, there is no way of knowing when and how the data is destroyed.

3. Facial-recognition databases

Faces collected at scale are valuable raw material for facial-recognition systems. The fines of tens of millions of euros imposed on companies such as Clearview AI by several European data-protection authorities for scraping facial images show how real this risk is. The EU AI Act likewise lists the untargeted scraping of facial images from the internet or CCTV footage to build facial-recognition databases among its prohibited practices.

4. Deepfakes and identity abuse

High-resolution facial images taken from different angles are the basic material for realistic deepfakes. We examined how such content is used for sexual abuse, fraud and reputational harm in our analysis of South Korea's deepfake crisis and in our report on AI sexual content of people who don't exist.

5. Other people's and children's data

Group photos carry the faces of third parties who never consented. Uploading children's photos calls for particular care: the legal validity of a child's own consent is debatable, and the limits of a parent consenting on a child's behalf to this kind of biometric processing deserve separate scrutiny.

Precedents from around the world: the price of facial data

The legal risks around facial data are not theoretical; in recent years they have produced striking outcomes in different legal systems:

  • The FaceApp controversy (2019). The app that went viral with its ageing filter triggered a major public debate and calls for political scrutiny in the US and Europe over the broad licence language in its terms and the location of its servers. It was one of the first big examples of how thin the line is between an "entertainment app" and a "data-collection tool."
  • Illinois BIPA litigation. The Biometric Information Privacy Act in the US state of Illinois provides per-person damages for unauthorised face scanning. In 2021 Facebook agreed a USD 650 million settlement in a class action over the automatic face-tagging of photos.
  • The Texas–Meta settlement (2024). In a suit brought under the state's biometric-data law, the Texas Attorney General reached a USD 1.4 billion settlement with Meta, recorded as one of the largest privacy settlements ever obtained by a single state.
  • Clearview AI fines. The company, which built a facial-recognition database from billions of images scraped from the internet, was fined EUR 20 million each by the Italian, Greek and French data-protection authorities, and more than EUR 30 million by the Dutch authority in 2024.

In Turkey, too, the Personal Data Protection Board has in past decisions found the use of biometric methods such as fingerprint scanning at workplaces and gyms problematic under the principle of proportionality where less intrusive alternatives were available. That approach shows that the expectation of "achieving the purpose with the least possible data" is well established in Turkish practice for biometric data.

Phrases to watch for in terms of use

App privacy policies and terms of use are usually long and technical. The following patterns are examples of language that deserves a careful read:

  • "A worldwide, perpetual, irrevocable, sublicensable licence." This can give the company an almost unlimited scope of use over the content you upload.
  • "To improve our services and develop new products." This can open the door to broad secondary uses, including model training.
  • "We may share with our partners and affiliates." It leaves unclear who, and in which countries, may receive the data.
  • "Your data is retained for a commercially reasonable period." A subjective yardstick in place of a concrete retention period.
  • "By continuing to use the service you accept these terms." This may be incompatible with the explicit consent the KVKK requires for biometric data.

None of these phrases is unlawful on its own. But where special-category data is involved, whether information and consent can be secured through such general wording is seriously open to question.

Reading the warning correctly: informed choice, not panic

The KVKK's message should not be read as "never use AI photo apps." Such apps are not unlawful per se, and some providers design their services responsibly — processing images on the device, publishing clear retention periods and refusing to use customer content for training. The point of the warning is to replace a reflexive tap with an informed choice. That shift matters legally as well: the more data subjects know about how their data is handled, the more meaningful their consent becomes — and the more clearly responsibility lies with controllers who fail to inform them. An awareness campaign therefore does not only protect users; it also raises the standard against which companies will be measured if a complaint reaches the Board.

A practical checklist for users

  • Whose app is it? Check the developer, where it is based and its contact details. Do not entrust your face to an app whose data controller you cannot identify.
  • Read the privacy notice. Look for answers to four questions in particular: How long is the image kept? Is it used to train models? Is it transferred abroad? Is it shared with third parties?
  • Limit permissions. Grant access only to the photo you choose, not your whole gallery, and refuse unnecessary permissions such as camera or contacts.
  • Do not upload photos of children or other people.
  • Delete when you are done. Ask for your data and account to be deleted from within the app.
  • Use your rights. Article 11 of the KVKK gives you the right to learn whether your data is processed, to know the purpose and the recipients, to request deletion and to claim compensation if you have suffered harm. You must first apply to the controller; if your request is rejected, the answer is inadequate or no answer arrives in time, you can complain to the Board.

Compliance notes for app developers and brands

These trends also have a commercial side: for brands using similar transformation filters in their campaigns and for developers serving users in Turkey, the risk is not limited to reputation.

  • Separate explicit consent. Obtain explicit consent for biometric processing separately from the general terms, in clear language and on a freely given basis.
  • Process on the device. Where possible, processing the image on the user's device and never sending it to a server is the strongest data-minimisation measure.
  • Close the door to secondary use. Commit explicitly not to use user images for model training, or make it subject to a separate, optional consent.
  • Document the transfer mechanism. If you rely on a provider abroad, document which of the transfer mechanisms introduced by the 2024 amendment you are using, and make the required notifications on time.
  • Set a retention period. Decide when images and derived facial data will be deleted, and automate it.

For an example of the KVKK's willingness to enforce against AI-driven processing, see our report on the fine for AI-driven predictive profiling.

Beyond data protection: the AI-regulation angle

Processing faces with AI is a focus not only of data-protection law but of the new generation of AI regulation. The EU AI Act takes a layered approach here:

  • Prohibited practices. Building facial-recognition databases through untargeted scraping of facial images, and using biometric data to categorise people by sensitive characteristics such as race, political opinion or sexual orientation, are banned.
  • High-risk systems. Remote biometric identification systems generally fall into the high-risk category and are subject to strict conformity obligations.
  • Transparency obligations. People exposed to emotion-recognition or biometric-categorisation systems must be informed, and artificial content resembling real people (deepfakes) must be disclosed as artificially generated.

We examined the global debate on labelling synthetic content in marking AI-generated content. Turkey does not yet have an AI law in force, but we assessed the draft approaches under discussion in our analysis of the draft Turkey Artificial Intelligence Act. For now, the KVKK remains the primary shield for users in Turkey — which is why the Authority's awareness warnings carry extra weight.

The bigger picture: the economic value of digital identity

This debate is not only about data security. In the AI era, your face, your voice and your appearance have become assets with economic value. Who owns a digital identity, which rights its unauthorised use infringes, and how those rights are protected after death are questions now being argued in courts around the world. We explored that dimension in our analysis of the Seoul right-of-publicity debate. Innocent-looking trends like the "80s challenge" can lead us to hand over that valuable asset for nothing.

Frequently asked questions

Has the KVKK banned these apps?

No. The Authority's message is an awareness warning, urging users to check access permissions and data-use purposes before sharing photos.

Is every photo biometric data?

No. A photo becomes biometric data when it is processed through specific technical means that enable a person's unique identification. AI transformation apps that process facial geometry mostly fall within that scope.

I have already used an app. What can I do?

Request deletion of your data and account from within the app; if you get no response, make a written application to the controller under Article 11 of the KVKK. If that fails, you can file a complaint with the Board.

Does the KVKK apply to an app based abroad?

Whether the KVKK applies to apps that process the data of people in Turkey and serve them is assessed case by case; but the transfer abroad of a Turkish user's data is subject to the KVKK's transfer rules. In practice, exercising rights against a foreign company can be harder.

Is it a problem to upload my child's photo?

Children's biometric data is especially sensitive. Given the risk that a child's facial data could be used for model training or long-term retention, it is advisable not to upload children's photos to such apps.

Is the image the app generates also personal data?

Yes. As long as it relates to an identifiable person, the transformed image is personal data too. Even if the style changes, the person remaining recognisable keeps the image within the scope of the KVKK.

What should companies watch for in campaigns like this?

A brand using a third-party filter or app in its own campaign can become part of the processing chain itself. The provider's processing terms, retention period, model-training policy and transfer mechanism should be reviewed before the campaign starts, and each party's role — controller or processor — made clear in the contract.

Expert Opinion

This section reflects my personal assessment as the founder of this site and an AI ethics & compliance counsel.

In my view, the KVKK's warning captures the most fundamental problem of data-protection law in the AI era: the greatest risks often hide in the most innocent-looking interactions. The user who uploads a face for a nostalgia filter rarely realises they are handing over biometric data, for an undefined period, for purposes they do not know, and often to another country. The legal problem is the attempt to legitimise that handover with the label of "explicit consent"; an approval that is unread, not understood and bundled with the service does not meet the explicit consent the law requires for special-category data.

I welcome the Authority's proactive awareness warning, but awareness alone is not enough. For apps that spread at mass scale, clear guidance for developers — and for brands that use these filters in campaigns — backed by enforcement where needed, is more effective. The uncertainties around secondary use for model training and cross-border transfers in particular should be resolved through concrete decisions.

My advice to users is simple: think of your face as a password. You can change a password; you cannot change your face. My advice to companies is this: when designing a feature that processes biometric data, the first question should not be "how viral will it go?" but "can we do this without ever sending the data to a server?" In the AI era, the most valuable currency of trust will be the respect shown to users' data.

This article is for information only and does not constitute legal advice. Facts about the KVKK warning are based on press reports of 10 September 2026; statements about the legislation are general in nature and specific cases require individual assessment. The analysis and assessments are the author's own.