Ertuğ & Partners
Blog
Sep 23, 20262026 Q3

On the KVKK's new guidelines for lawyers: the legal and practical dimensions of data controllership, AI use and cross-border data transfers

KVKKLegal ProfessionAI

The "Guidelines on the Protection of Personal Data in the Professional Activities of Lawyers", prepared by the Personal Data Protection Authority (KVKK) with the opinions and contributions of the Union of Turkish Bar Associations, were announced to the public on 22 September 2026. In this article I will try to assess the main findings of the 158-page guidelines and the issues that, in my view, they do not sufficiently address.

The guidelines were prepared following the cooperation protocol signed between the Authority and the Union of Turkish Bar Associations on 14 December 2022 and the event "The Position of Lawyers under the Personal Data Protection Law" organised by the two institutions on 26 September 2023; as far as I can tell, they are the Authority's first comprehensive document specific to the legal profession. Shortly before the guidelines, on 28 August 2026, the "Recommendation Guide on the Use of Artificial Intelligence for Lawyers", prepared by the Information and Technology Law Commission of the Union of Turkish Bar Associations (TBB), was published. Unless otherwise indicated, "the guidelines" in this article refers to the Authority's guidelines and "the TBB guide" to the AI guide of the Union of Turkish Bar Associations.

It should be noted at the outset that the guidelines are not a law, a regulation or a principle decision of the Personal Data Protection Board; they are an interpretation of the existing legislation and Board decisions as applied to the legal profession. Even so, they matter because they show which criteria the Board will apply to complaints against lawyers.

The lawyer as data controller

According to the guidelines, when a complaint is filed with the Board, lawyers most often argue first that their activity falls outside the scope of the Law (p. 22). The guidelines reject this argument (pp. 21-26). The exception in Article 28(1)(d) of the Law covers only the investigation, prosecution, adjudication and enforcement activities of judicial and enforcement authorities; a lawyer, although a constituent element of the defence, is not a judicial authority.

The guidelines also state that the attorney-client agreement is not a data processing agreement. Its principal obligation is the provision of legal assistance; the processing of personal data is an ancillary obligation serving the performance of that obligation. Since it is the lawyer, not the client, who determines which data are processed and for what purpose, the lawyer is, as a rule, the data controller (pp. 36-49).

The exemption from registration with VERBİS (the data controllers' registry) granted by Board decision 2018/32 remains in place. The guidelines observe that in practice this exemption has been read as meaning that lawyers have no obligations at all under the Law, and stress that it concerns only the obligation to register (p. 132). The duties to inform, to ensure data security, to retain and destroy data, and to answer data subject requests within 30 days at the latest apply to lawyers as well.

Lawyers working together in the same office

Under Article 44 of the Attorneyship Law, lawyers may carry on their professional activities together in a shared office without legal personality. The guidelines distinguish this arrangement from a law partnership (pp. 50-53). Each lawyer working under a name such as "A and B Law Office" is a separate data controller for the processing relating to their own clients. In a law partnership with legal personality, the data controller for the activities carried out on behalf of the partnership is the partnership itself.

What the guidelines leave unanswered is the question of resources shared by lawyers working together. According to the guidelines, office employees are part of the data controller's organisation and are therefore not separate data processors (pp. 60-62). It is unclear, however, within which lawyer's organisation a shared secretary who processes the data of several lawyers' clients should be placed. The same uncertainty arises for shared file servers, cloud storage and an AI subscription opened in the name of one of the lawyers; in that case only one lawyer is a party to the contract with the service provider, while data are uploaded by several. The Law contains no provision on joint controllership, and the guidelines do not address the point either. For now, lawyers working together would be well advised to set out their responsibilities for shared resources in a written arrangement among themselves.

Use of generative AI tools

One of the most notable parts of the guidelines concerns generative AI tools (pp. 120-122, 145-146). The guidelines mention ChatGPT, Claude and Gemini by name and state that uploading client files, case documents or other documents containing personal data to these tools cannot be regarded merely as obtaining technical support or conducting legal research. Where the service provider or its servers are located abroad, this may constitute a cross-border transfer under Article 9 of the Law; even where the provider is established in Türkiye, a domestic transfer under Article 8 may be at issue.

Appropriate safeguards for cross-border transfers

Under Article 9, as amended by Law No. 7499 in 2024, personal data may be transferred abroad where one of the processing conditions in Articles 5 and 6 is met and the Board has issued an adequacy decision for the destination country. In the absence of an adequacy decision, in addition to the existence of a processing condition and the data subject's ability to exercise their rights and to seek effective remedies in the destination country, one of the following appropriate safeguards must be provided (Art. 9(4)):

a) an agreement, not in the nature of an international treaty, between public institutions or international organisations abroad and public institutions or professional organisations having the status of public institutions in Türkiye, together with the Board's authorisation of the transfer,

b) binding corporate rules, approved by the Board, which companies within a group of undertakings engaged in joint economic activity are required to comply with,

c) a standard contract announced by the Board,

d) a written undertaking containing provisions that ensure adequate protection, together with the Board's authorisation of the transfer.

A standard contract must be notified to the Authority within 5 business days of its signature (Art. 9(5)). Where there is neither an adequacy decision nor an appropriate safeguard, only occasional transfers may rely on the exceptions listed in paragraph 6 of Article 9.

For an individual lawyer, these safeguards offer very little. The agreement in (a) covers only public institutions and international organisations on the foreign side, so it cannot apply to a relationship with an AI company. Binding corporate rules are specific to transfers within a group of companies. The written undertaking route requires separate Board authorisation. That leaves the standard contract, which must also be signed by the service provider; yet a lawyer on a monthly subscription faces not a counterparty to negotiate with but terms of use to be accepted as they are. Nor does it seem possible to treat a use that is repeated every day as occasional. In these circumstances it is difficult to identify an Article 9 basis for routinely uploading client files containing personal data to an AI tool established abroad.

Providers established in Türkiye

Choosing a provider established in Türkiye does not solve the problem by itself. As the guidelines note, the legal ground, purpose, categories of data transferred and proportionality of the transfer must then be assessed separately under Article 8 (p. 121). It should also be borne in mind that many tools offered domestically may rely on models developed abroad or on cloud infrastructure located abroad. What the lawyer knows about whether the data actually leave the country, who the sub-processors are, how long the data are kept and which security measures are applied is usually limited to the provider's own statements. The fact that a provider is established in Türkiye does not mean that these questions have been answered.

Measures recommended by the guidelines

The guidelines do not prohibit the use of AI; instead they recommend the following measures (p. 146): masking or anonymising personal data as far as possible, avoiding the upload of special categories of personal data, sharing only the minimum data necessary for the purpose, reviewing the tool's policies on data retention, model training, human review, sub-processors and security, and setting internal office rules on the use of these tools.

One point not covered in the guidelines deserves mention here. The fact that a provider does not use the data for model training does not make the transfer lawful. A model training setting is a choice about the purposes for which the data will be used; Article 9 asks for the legal basis of the transfer and its safeguards.

The approach of the TBB guide

The use of AI is addressed in far greater detail and within a stricter framework in the guide of the Union of Turkish Bar Associations. The TBB guide divides AI use into four groups, namely free auxiliary use, limited and controlled use, use subject to special safeguards and prohibited use, according to criteria such as the type of data, the impact on the client, whether the tool is an open or closed system and the likelihood of cross-border transfer (TBB guide, pp. 14-16). Accordingly, non-anonymised client data, the contents of case or enforcement files, party details, evidence and special categories of personal data should not be entered into publicly available tools or tools with insufficient contractual safeguards; and in files in areas such as criminal, family, child, health and immigration law, open-system tools should not be used at all (p. 16).

The TBB guide is equally clear on cross-border transfers: it notes that in cloud-based language model services data are mostly processed on infrastructure located abroad, and stresses that inputs containing personal data cannot be used without assessing adequacy decisions, appropriate safeguards or occasional-transfer cases (p. 22). The TBB guide also includes a sample internal office policy clause, a sample clause that can be added to the client agreement, review questions to put to service providers, and an assessment of professional liability insurance (pp. 34-40). As regards the practical details of AI use, the TBB guide can be said to complement the Authority's guidelines to a significant extent.

Steps towards anonymisation

Under Article 3(1)(b) of the Law, anonymisation means rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even when matched with other data. In light of this definition, deleting the names in a document is not sufficient on its own. The TBB guide likewise stresses that anonymisation is not limited to deleting names and identity numbers, and that the date of events, place, amount, company name, type of case and unique facts may also make a person identifiable (TBB guide, pp. 21, 32). For a document to be sent to an AI tool, at least the following should be considered:

  • Removing direct identifiers: name and surname, national identity number, address, telephone number, e-mail address, IBAN and account numbers, vehicle plate, land registry details and case file numbers.
  • Generalising indirect identifiers: using the month or year instead of exact dates, the region instead of the province and district, the sector instead of the company name, and ranges instead of exact amounts. Since the particular details of a case can also make a person identifiable, details not needed for the review should be removed from the text.
  • Using role names: referring to the parties as "Claimant", "Defendant", "Witness 1" and so on. As long as the lawyer retains the means to match them with the real identities, however, this method alone is pseudonymisation, not anonymisation. Anonymisation can be spoken of only where, applied together with the other measures, it leads to a result in which identity can no longer be re-established in any way.
  • Technically cleaning the document: deleting embedded data such as author and organisation details in the file properties, tracked changes and comments; removing signatures, stamps and photographs from scanned documents. Since placing a black box over text in a PDF does not delete the underlying text, redaction should be done with a tool that actually removes the text.
  • Sending only the necessary part: sending the section to be reviewed rather than the whole file.
  • Never sending special categories of personal data: data such as health information, criminal convictions or trade union membership.
  • Checking automatic masking tools: if such tools are used, their output should always be checked before sending.
  • Techniques described in the Authority's guidelines on the deletion, destruction or anonymisation of personal data, such as removing variables, generalisation, top and bottom coding and regional suppression, will also be helpful in this context.

    In my view, the options available in practice are: anonymising the document as described above before sending it to the tool, working under an enterprise agreement that provides a transfer safeguard compliant with Article 9, or using a model that runs locally on the lawyer's own infrastructure so that the data never leave the country.

    Communication channels the guidelines leave out

    The fact that the guidelines name AI tools makes an unaddressed issue all the more visible. The guidelines do not mention WhatsApp, Gmail, Hotmail or cloud storage services at all. Yet it is well known that a large share of professional communication runs through these channels, while the use of e-mail tied to a firm's own domain name remains limited.

    Uploading a client document to an AI service abroad and sending it through an e-mail or messaging service that runs on a foreign provider's infrastructure raise similar legal questions as regards cross-border transfer of personal data, even though their technical and contractual conditions differ. Factors such as the provider's ability to access content, end-to-end encryption, backup settings and whether a personal or business version of the service is used may affect the outcome of the assessment; none of these questions, however, is addressed in the guidelines.

    While the guidelines make an apt observation about AI tools, they say nothing about the communication channels in which similar questions arise far more widely. The TBB guide, whose scope is limited to AI tools, contains no assessment of these channels either.

    Examples from Board decisions

    The guidelines refer to various Board decisions concerning lawyers. Some of them are:

  • an administrative fine of TRY 50,000 on a lawyer who disclosed debt information to a relative of the debtor by text message (2019/166),
  • an administrative fine of TRY 50,000 on a lawyer who sent a text message to a number known to belong to a relative of the person concerned (2021/111),
  • an administrative fine on a lawyer who obtained the telephone numbers of the debtor's relatives and colleagues without a definite legal basis (2020/429),
  • an administrative fine on a lawyer who obtained a criminal record by relying on Article 2 of the Attorneyship Law (2021/1111).
  • For breaches of data security obligations, the administrative fine applicable in 2026 ranges from TRY 256,357 to TRY 17,092,242 (p. 144).

    Practical recommendations

    Drawing on the findings of the guidelines, some points lawyers should keep in mind in practice are:

    Explicit consent. According to the guidelines, explicit consent should not be relied on where another processing condition exists, since doing so may mislead the data subject and thus breach the law and the principle of good faith (pp. 74-75). The guidelines illustrate this with an example in which the client is asked to sign a standard explicit consent form together with the attorney-client agreement and the service is made conditional on consent. Since the client's data are processed for the conclusion or performance of the contract, and the opposing party's data mostly on the ground of the establishment, exercise or protection of a right, no separate explicit consent is needed for these activities where the relevant processing condition is present. The duty to inform and any obligations relating to data transfers nevertheless remain.

    A difference between the two guides deserves attention at this point. The TBB guide recommends that where client data, file contents or special categories of data are processed with AI tools, the client should be informed and "an explicit consent/approval mechanism where necessary" should be operated (TBB guide, p. 27). In my view, this approval should be understood as the client's informed approval, within the framework of the rules of the profession, of the way in which the service is carried out. If the same approval were designed as explicit consent within the meaning of the KVKK, it could conflict with the Authority's guidelines, which provide that explicit consent should not be relied on where another processing condition exists. It should not be overlooked, however, that explicit consent has a separate place in cross-border transfers under Article 9(6)(a), where it is limited to occasional transfers.

    Source of the data. The guidelines note that a significant share of complaints to the Board concern requests to learn how the personal data were obtained, and that lawyers are often unable to document this (p. 136). It is therefore important to record whether the data were obtained from the client, from the case file, from UYAP (the national judiciary information system) or from a publicly available source.

    Search software. Under the Board's principle decision 2019/308, administrative sanctions will be imposed on those who use software that allows the identity and contact details of individuals to be queried from unlawfully obtained data, and the matter will be reported to the public prosecutor's office (pp. 106-107).

    Retention and destruction. Under Article 39 of the Attorneyship Law, a lawyer must keep the documents handed over to them for 3 years from the end of the mandate; if the client has been notified in writing to collect the documents, this obligation ends 3 months after the notification. Where a fee claim exists, the guidelines also accept retention for 5 years under Article 147 of the Turkish Code of Obligations (pp. 127-128). If a request for erasure is refused, the reason for refusal and the period for which the data will be kept must be clearly communicated to the data subject (p. 134).

    Data breaches. Using the example of a case file lost on the way back from the courthouse, the guidelines explain that the loss of physical files may also constitute a data breach, in which case the Board must be notified within 72 hours (pp. 140-141).

    Contact details. Since data subject requests are usually made through the contact details on lawyers' websites or on the bar association's roll, these details must be kept up to date (p. 137).

    Conclusion

    The Authority's guidelines set out lawyers' obligations regarding the protection of personal data in detail. As regards the use of AI, the TBB guide, with its risk-based classification, sample policy and contract clauses and supplier review questions, has largely set the standards within the profession. Neither guide addresses, however, that the cross-border transfer assessment made for AI tools raises similar questions for the e-mail, messaging and cloud services lawyers use every day. Nor is there any explanation regarding the resources shared by lawyers working together. The question of how these obligations can be met within the existing digital service infrastructure, particularly by individual lawyers and small law firms, also remains largely unanswered. Indeed, putting in place the appropriate safeguards required by Article 9 poses serious practical difficulties, especially for individual lawyers working under standard subscription terms.

    For this reason, the matter cannot be left to lawyers' individual compliance efforts alone. It would be appropriate for the standard-setting role the Union of Turkish Bar Associations has assumed in the field of AI to be extended to cover the communication and document-sharing channels lawyers use every day. Bar associations and the Union of Turkish Bar Associations, in cooperation with the Authority, should also take on a role in developing secure communication and document-sharing infrastructures suited to the needs of the profession and in establishing lawful data transfer mechanisms with service providers. The Authority's guidelines are themselves the product of such cooperation.

    Reminding lawyers of their obligations is important; so is creating the conditions in which they can meet them.

    Mehmet Kemal Ertuğ, Attorney at Law

    Sources: Personal Data Protection Authority, Guidelines on the Protection of Personal Data in the Professional Activities of Lawyers (Avukatların Mesleki Faaliyetlerinde Kişisel Verilerin Korunmasına İlişkin Uygulama Rehberi), KVKK Publications No. 115, Ankara 2026; Union of Turkish Bar Associations, Information and Technology Law Commission, Recommendation Guide on the Use of Artificial Intelligence for Lawyers (Avukatlar İçin Yapay Zekâ Kullanımı Tavsiye Rehberi), 2026. Unless otherwise indicated, page numbers refer to the Authority's guidelines. This article is for general information purposes only and does not constitute legal advice.

    Last updated: 23 September 2026.