ARTICLE
20 August 2026

Processing Of Personal Data In Generative Artificial Intelligence Systems: Key Principles To Consider

SO
Sakar Law Office

Contributor

Sakar is a client and solution oriented, investigative and innovative law firm based in Istanbul. Our Firm is committed to provide our clients with high-quality legal services and business-minded approach. We are a full service law firm to clients across a wide range of areas including Mergers and Acquisitions, Corporate and Commercial, Contracts, Banking and Finance, Competition, Litigation, Employment, Real Estate, Energy, Capital Markets, Foundations, E-commerce, Media and Technology, Data Privacy and Data Protection and Intellectual Property. In order to offer the best possible service for our clients, we harness the latest market developments in legal technology and innovation and we closely follow the legislative changes in Turkish Law. Our lawyers are multi-specialists, equipped to handle a broad range of legal matters. In addition to our depth of experience and awareness of market practice, clients know they will benefit from our team’s innovative mindset and willingness.
Generative artificial intelligence (“GAI”) systems have found widespread use in recent years at both the individual and organizational levels due to their ability to generate content in various formats, such as text, images, audio, and software code. Since the operation of these systems is largely data-driven, it is inevitable that they will come into contact with information constituting personal data during both the training and operational phases.
Turkey Privacy
Gözde Esen Sakar’s articles from Sakar Law Office are most popular:
  • in United States
Sakar Law Office are most popular:
  • within Energy and Natural Resources, Employment and HR and Environment topic(s)

Generative artificial intelligence (“GAI”) systems have found widespread use in recent years at both the individual and organizational levels due to their ability to generate content in various formats, such as text, images, audio, and software code. Since the operation of these systems is largely data-driven, it is inevitable that they will come into contact with information constituting personal data during both the training and operational phases. This article addresses the fundamental principles that must be observed in the processing of personal data within GAI systems under the Personal Data Protection Law No. 6698 (“the Law”), based on the practices and guidelines of the Personal Data Protection Authority (“the Authority”).

  1. The Relationship Between Generative Artificial Intelligence and Personal Data Processing Activities

Generative AI systems utilize large-scale datasets during their learning processes. If these datasets contain information about individuals, such data can directly influence the model’s internal structure and the outputs it generates.

In this context, the processing of personal data is not limited solely to the stage of collecting training data for the AI system; it can also occur through outputs (such as audio, visuals, music, text, etc.) generated from user inputs after the model is made available for use. Indeed, the fact that the model does not specifically target the processing of personal data or that the inputs do not contain personal data does not eliminate the possibility of personal data being processed in the outputs or at another stage. Therefore, the existence of personal data processing activities must be assessed separately for each stage.

Conversely, if only anonymous or anonymized data is used during the design, development, and testing of systems, these activities generally fall outside the scope of the Law. Anonymization is defined in Article 3/1-b of the Law as “the process of rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even when matched with other data.” There is no doubt that personal data that has been anonymized must be processed in accordance with the Law during the process leading up to its anonymization. Furthermore, while it may be argued that the use of anonymous or anonymized data at any stage of a GAI system generally falls outside the scope of the Law, it is necessary to objectively and technically demonstrate whether the anonymized data is truly anonymous.

  1. General Principles Governing the Processing of Personal Data

The principles listed in Article 4 of the Law apply to all types of personal data processing activities, regardless of the tools or technologies used, and GAI systems are also evaluated within this scope.

  1. Compliance with the Law and Principles of Good Faith

This principle requires that personal data be obtained from lawful sources, that information be provided to data subjects in a transparent manner, and that processing be conducted transparently.

In particular, algorithmic biases that may arise from the underrepresentation of certain groups in training data must be evaluated separately regarding the application of this principle. Large datasets used in educational processes may reflect certain social patterns and inequalities in the AI system. This, in turn, could lead to problems in the AI system’s outputs. Indeed, this situation must not result in discrimination or a violation of rights—not only in terms of the protection of personal data but also with regard to individuals’ fundamental rights and freedoms.

In this context, certain measures must be taken to prevent unfair, misleading, or discriminatory results from emerging in the outputs. To facilitate the implementation of this principle, it is of utmost importance to establish monitoring and oversight structures that ensure the regular review of system outputs, identify risks of discrimination, and enable intervention when necessary. In this vein, it would be appropriate to utilize approaches such as fine-tuning to reduce the risks of biased outputs. In addition, taking other proactive, protective, and supportive measures aimed at safeguarding individuals’ rights and interests will also enhance the effectiveness of this principle.

  1. Accuracy and Timeliness

Maintaining personal data in an accurate and up-to-date manner is important not only for protecting the fundamental rights and freedoms of the data subject but also for safeguarding the interests of the data controller.

Actors who develop, provide, and use AI systems must filter out incorrect or unverifiable information in training data and review and filter personal data in the outputs. Recording data sources, reviewing data before entry, and cleaning up erroneous or outdated content strengthens this process. The principle should cover not only inputs but also outputs; indeed, even systems trained on high-quality data can generate content that contains personal data, is out of context, or is untrue (“hallucinations”). While data quality reduces the risk of hallucinations, it cannot eliminate it entirely. Therefore, it is critical to regularly monitor system outputs and support them with human oversight, particularly to prevent erroneous outputs—especially those containing personal data—from causing harm to individuals.

  1. Processing for Specific, Explicit, and Legitimate Purposes, and Being Relevant, Limited, and Proportionate to the Purpose 

Data processing takes place in a complex and multi-layered manner throughout the AI system’s lifecycle. Consequently, this principle is crucial for ensuring the legality of data processing within the AI system.

Data controllers must ensure that personal data processing activities at every stage of the system are limited to the extent necessary for the processing purpose and avoid indiscriminate, general data collection. For example, vague statements such as “for use in our AI systems” or “to improve our database” do not clearly define the purpose of data processing and may therefore violate the principle of “processing for specific, explicit, and legitimate purposes” set forth in Article 4 of Law No. 6698. Accordingly, developers should define specific, clear, and justifiable purposes for each stage of the system lifecycle—rather than using general definitions like “developing an AI model”—and demonstrate the necessity of data processing. Consequently, only personal data relevant to the purpose should be processed; collection, storage, and sharing processes must be structured within these boundaries. In cases of secondary use—such as reusing data collected for training one model in another model—the compatibility of this process with the original purpose must be assessed, the reasonable expectations of the data subjects must be taken into account, and, in the event of non-compliance, a new data processing procedure must be designed.

  1. Retention for the Period Specified in Relevant Legislation or Necessary for the Purpose for Which They Are Processed

Throughout the lifecycle of AI systems, personal data may be processed for different stages and purposes and retained for specific periods. In this context, retention periods must be determined in accordance with the purpose of each processing activity; retention and destruction processes must be designed to ensure that data is retained only for as long as required by that purpose.

If the purpose for which personal data is processed ceases to exist, such data must be deleted, destroyed, or anonymized. Storing data indefinitely on the grounds that “it may be reused in the future” constitutes a violation of the retention and destruction obligation.

  1. Other Key Considerations in Practice

In addition to the general principles, the processing of personal data in GAI systems must be based on at least one of the processing conditions listed in Articles 5 and 6 of the Law. Each condition—such as explicit consent, performance of a contract, disclosure, and legitimate interest—must be evaluated separately based on the nature of the specific processing activity; one must not fall into the misconception that even publicly available data can be processed freely. Furthermore, the status of different actors—such as developers, deployers, and users—as data controllers or data processors throughout the system’s lifecycle should be determined based on actual control and decision-making authority rather than contractual language.

  1. Conclusion

The innovative capabilities offered by AI systems must be evaluated alongside the risks associated with the protection of personal data. The Law’s technology-neutral, general-framework provisions are applicable to AI systems as well; it is of great importance for data controllers to separately define the purpose of processing for each stage, ensure the accuracy and security of the data sets used, limit retention periods to the purpose, and inform data subjects transparently. Accordingly, ensuring compliance with personal data protection legislation during the use of AI systems will contribute to the lawful and sustainable use of AI technologies.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More