Turkey's Personal Data Protection Authority has published both a question-and-answer guide on generative AI and a separate document on its use in the workplace. Inspections are grounded in these texts.
01. Why It Matters
Guidance is not binding legislation, but it shows the authority's expectations. Once a review begins, the assessment follows that framework; treating it as binding in practice is the right posture.
02. Employee Use
The most emphasised heading is employees entering personal data into generative AI tools. Pasting customer lists, CVs, health information or contact details into external tools is a processing activity in its own right.
03. An Internal Policy
The expectation is clear: which tool may be used, which data may be entered and who is responsible must be written down. In an organisation without a policy, responsibility falls squarely on the data controller.
04. Notice and Consent
The privacy notice needs updating for personal data processed with AI. Most existing texts don't cover this activity; a single added sentence usually isn't enough, purpose and transfer should be written separately.
05. Technical Measures
Masking, access restriction, logging and retention periods. These four are the measures asked about concretely in an inspection. Having taken them matters as much as having documented them.
06. A Quick Check
Can you answer three questions today: which teams use which AI tool, what data goes to those tools, and is that use covered in your privacy notice. If any answer is missing, that's your starting point.