Trust and compliance · 2026-08-13

Can a Turkish public institution use ChatGPT or the OpenAI API? The KVKK cross-border transfer framework

Explains the legal basis on which Turkish public institutions may use ChatGPT, OpenAI and Anthropic APIs, covering Article 9 of Law No. 6698 (KVKK), the three-tier transfer regime and the derogations that do not apply to public bodies.

Diagram showing the three-tier cross-border transfer regime under Article 9 of Turkish Law No. 6698 as adequacy decision, appropriate safeguards and derogations, with the sub-paragraphs closed to public institutions marked.

On what legal basis can a Turkish public institution use ChatGPT or the OpenAI API?

Turkish public institutions may use foreign-hosted generative AI services such as ChatGPT, the OpenAI API or the Anthropic API. However, the moment personal data enters a prompt, that use becomes a cross-border transfer under Article 9 of Law No. 6698 on the Protection of Personal Data (KVKK), and the institution must establish a separate legal basis for each provider.

Article 9 was replaced in its entirety by Article 34 of Law No. 7499 dated 2 March 2024, with effect from 1 June 2024. The new text builds cross-border transfers on three tiers: an adequacy decision, appropriate safeguards, and derogations for occasional transfers. The decisive difference between public institutions and the private sector appears in that third tier.

The Turkish Data Protection Authority (Kişisel Verileri Koruma Kurumu) addressed the topic directly in its Guide on Generative Artificial Intelligence and the Protection of Personal Data (Üretken Yapay Zekâ ve Kişisel Verilerin Korunması Rehberi, Publication No. 113), published on 24 November 2025. The guide states that where data controllers use generative AI systems through service providers established abroad, the resulting transfer must comply with Article 9 and with the implementing regulation. The sections below set out what that framework means for a public institution in practice.

  • Prompts that contain no personal data (general legislative summaries, code generation, editing of anonymous text) fall outside Article 9; the transfer regime is triggered only where personal data is involved.
  • A production integration is not assessed prompt by prompt. It is assessed as a continuous transfer activity carried out within the ordinary course of the institution's operations.
  • The institution remains the data controller even when the service is procured through a contractor; the contractor is typically a data processor.
  • This article covers only the cross-border transfer regime under Law No. 6698. Public institutions are also subject to a separate information and communication security framework, which must be assessed independently.

How does the KVKK three-tier cross-border transfer framework work?

The Turkish Data Protection Authority describes the cross-border transfer regime as an explicitly tiered structure in its own guidance. The Guide on the Transfer of Personal Data Abroad (Kişisel Verilerin Yurt Dışına Aktarılması Rehberi, KVKK Publication No. 48, January 2025) titles its chapters first tier (transfers based on an adequacy decision), second tier (transfers based on appropriate safeguards) and third tier (exceptional transfers). The tiers are sequential: an institution moves down only when the tier above is unavailable.

The first tier, the adequacy decision, is issued solely by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) under Article 9(2). It is published in the Official Gazette (Resmî Gazete) and reviewed at least once every four years. When issuing an adequacy decision, the Board takes into account the six criteria in Article 9(3): reciprocity, the legislation and practice of the receiving country, the existence of an independent and effective data protection authority together with administrative and judicial remedies, membership of relevant international conventions, membership of global or regional bodies that Türkiye belongs to, and the international conventions to which Türkiye is a party.

The Authority's January 2025 guide states that the countries deemed to provide adequate protection under the pre-amendment version of Article 9 had not yet been determined by the Board. Institutions should separately verify, as at the date of their own assessment, whether an adequacy decision covering the relevant country, sector or international organisation has been published in the Official Gazette. In practice, the weight of the analysis falls on the second and third tiers.

The procedures and principles governing all three tiers are set out in the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelik), published in Official Gazette No. 32598 of 10 July 2024.

The three tiers of Article 9 of Law No. 6698 (KVKK) and their applicability to public institutions (based on the statutory text, last checked 13 August 2026)
TierStatutory basisApplies to public institutions?Practical burden
Tier 1: Adequacy decisionArt. 9(1), 9(2) and 9(3)Yes, no distinction between public and private sectorRequires no separate act by the institution; the Board issues the decision, publishes it in the Official Gazette and reviews it at least every four years
Tier 2: Appropriate safeguardsArt. 9(4), sub-paragraphs (a), (b), (c) and (ç)Yes; sub-paragraph (a) is written specifically for Turkish public institutionsA separate instrument per provider; a standard contract must be notified to the Authority within five business days of signature (Art. 9(5)), while agreements and undertakings require prior Board authorisation
Tier 3: Derogations for occasional transfersArt. 9(6), sub-paragraphs (a) to (f), seven itemsPartly no: sub-paragraphs (a), (b) and (c) do not apply to activities of public institutions subject to public law (Art. 9(7))Four sub-paragraphs remain available; in addition the transfer must be occasional, which continuous API usage does not satisfy

Why are three of the derogations unavailable to public institutions?

The Turkish Data Protection Authority states plainly, on page 47 of its generative AI guide, that the third-tier derogations are restricted for public institutions. The relevant sentence reads: “Ancak mezkur (6) numaralı fıkranın (a), (b) ve (c) bentlerinde sayılan arızi haller kamu kurum ve kuruluşlarının kamu hukukuna tâbi faaliyetlerine uygulanmaz.” — the derogations listed in sub-paragraphs (a), (b) and (c) of paragraph 6 do not apply to activities of public institutions and organisations that are subject to public law.

This is not an interpretation specific to the guide; it restates the statute. Article 9(7) of Law No. 6698 provides: “Altıncı fıkranın (a), (b) ve (c) bentleri, kamu kurum ve kuruluşlarının kamu hukukuna tâbi faaliyetlerine uygulanmaz.”

The three excluded sub-paragraphs are precisely the ones the private sector relies on most: explicit consent given after the data subject has been informed of the possible risks; necessity for the performance of a contract between the data subject and the controller; and necessity for the conclusion or performance of a contract concluded in the data subject's interest. A public institution cannot base a transfer to a foreign AI service on consent obtained from a citizen, as regards its activities subject to public law.

The four remaining sub-paragraphs are narrow and will not carry a routine AI integration. Beyond that, the third tier is itself conditioned on the transfer being occasional. The Authority's January 2025 guide describes an occasional transfer as one that takes place once or a few times, is not continuous and does not occur within the ordinary flow of operations. A generative AI integration embedded in daily workflows is by definition continuous and part of the ordinary flow of operations.

  • Closed to public institutions: (a) explicit consent, (b) necessity for performance of a contract between the data subject and the controller or for pre-contractual measures, (c) necessity for the conclusion or performance of a contract with a third party in the data subject's interest.
  • Still available to public institutions: (ç) necessity for an overriding public interest, (d) necessity for the establishment, exercise or protection of a right, (e) protection of the life or physical integrity of a person who is unable to give consent due to factual impossibility, (f) transfer from a register open to the public or to persons with a legitimate interest.
  • The restriction applies only to activities subject to public law; it does not close these sub-paragraphs for an institution's activities governed by private law. Drawing that line is a matter for the institution's legal counsel.
  • The conclusion for public institutions: the third tier cannot be engineered into a legal basis for continuous AI usage.

The route that remains open: appropriate safeguards under Article 9(4)

For Turkish public institutions, the sustainable legal basis for a foreign generative AI service is the set of appropriate safeguards in Article 9(4) of Law No. 6698. The paragraph lists four safeguard types, and the precondition is the same for all of them: one of the processing conditions in Article 5 or Article 6 must be satisfied, and the data subject must be able to exercise their rights and pursue effective legal remedies in the destination country.

The first of the four, sub-paragraph (a), is written specifically for public bodies: an agreement that does not have the nature of an international convention, concluded between foreign public institutions or international organisations and Turkish public institutions or professional organisations with public institution status, together with authorisation of the transfer by the Board. This sub-paragraph cannot be used where the counterparty is a commercial company, so transfers to private-law entities such as OpenAI or Anthropic leave the standard contract and the written undertaking as the remaining options.

The standard contract is the only option that operates without waiting for Board authorisation, which is why it dominates in practice. By decision no. 2024/959 dated 4 June 2024 the Board adopted four standard contract templates covering different transfer scenarios. Under Article 9(5), the standard contract must be notified to the Authority by the data controller or data processor within five business days of signature.

The practical burden of the undertaking route is visible in the Authority's own figures. Between 7 April 2016, when Law No. 6698 entered into force, and 1 June 2024, when Article 34 of Law No. 7499 took effect, the Board received 86 applications based on written undertakings and approved only 10. Over the same period all 3 binding corporate rules applications were rejected for procedural and substantive deficiencies. An institution planning a route that requires Board authorisation should build its timetable around those ratios.

Public institutions occupy a distinct position on enforcement. Article 18(1)(d) prescribes an administrative fine of 50,000 to 1,000,000 Turkish lira for failing to comply with the notification obligation in Article 9(5); these statutory amounts are uprated annually by the revaluation rate and stand at 90,308 to 1,806,177 Turkish lira for 2026. Article 18(2), however, provides that this fine applies only to natural persons and private-law legal persons. Under Article 18(4), where the act is committed within a public institution, disciplinary proceedings are brought against the relevant public officials upon notification by the Board, and the outcome is reported back to the Board.

  • For the three options that require Board authorisation, transfers may not begin before authorisation is granted; the Authority's guide states that a transfer made while the assessment is pending would be unlawful.
  • A standard contract may be executed in more than one language, but the Turkish text adopted by the Board prevails.
  • Notification may be made physically, through a registered electronic mail (KEP) address, or through methods designated by the Board such as the Standard Contract Notification Module.
  • Each provider is a separate legal entity. One instrument will not cover OpenAI, Anthropic and Google; three separate legal steps are required.
The four appropriate safeguards under Article 9(4) of Law No. 6698 and their procedural burden (based on the statutory text, last checked 13 August 2026)
Safeguard typeSub-paragraphBoard authorisation required?Notification to the Authority
Agreement not having the nature of an international convention, between public institutions and professional organisations with public institution statusArt. 9(4)(a)Yes, the Board must authorise the transferPart of the authorisation process
Binding corporate rules within a group of undertakings engaged in a joint economic activityArt. 9(4)(b)Yes, the Board must approve the rulesPart of the approval process
Standard contract published by the BoardArt. 9(4)(c)No separate authorisation or accreditation is requiredNotified to the Authority within five business days of signature (Art. 9(5))
Written undertaking containing provisions ensuring adequate protectionArt. 9(4)(ç)Yes, the Board must authorise the transferPart of the authorisation process

Model selection is impossible without data classification

Public institutions often frame the wrong question. The question is not whether the institution may use AI, but which class of data will be processed in which architecture. Article 9 of Law No. 6698 governs transfers of personal data only; a prompt containing no personal data does not trigger the cross-border regime at all. The first step is therefore not legal but operational: a data inventory and a classification scheme.

Once classification is complete, three architectural options remain. The first is to process personal-data workloads on models hosted in Türkiye, in which case no cross-border transfer occurs and Article 9 does not apply. The second is to establish an appropriate safeguard for the specific provider where a foreign model must be used. The third, and the most realistic for most public institutions, is to run both in parallel according to data class.

A hybrid architecture only works if the administrative and technical sides use the same distinction. Work procured under headings such as AI software leasing (yapay zekâ yazılımı kiralama) or AI service procurement (yapay zekâ hizmet alımı) becomes unenforceable in production if the technical specification does not separate model identifiers, endpoint addresses, token consumption and API keys. The specification should state which data class is called with which model identifier, and how that separation is recorded.

Special categories of personal data warrant additional care. The Authority's generative AI guide notes that, because of the nature of such data, processing may produce outcomes that cause harm or discrimination to the data subject, and that the resulting risks must be carefully assessed with appropriate measures taken to minimise them.

  • No personal data: summarising legislation, generating template text, code generation, translating public documents. Use of a foreign model falls outside Article 9.
  • Contains personal data: citizen application texts, personnel records, correspondence content. Requires either a model hosted in Türkiye or an appropriate safeguard.
  • Special categories: health, biometric and criminal conviction data. Requires a separate internal risk assessment and a decision on additional measures.
  • Map the administrative vocabulary to the technical one: procurement line items for AI service procurement and AI software leasing should correspond to model identifier, endpoint and API key separation on the engineering side.

How LLMTR addresses this requirement

LLMTR serves the need to route by data class through a single OpenAI-compatible API surface. An institution sending personal-data workloads to a model hosted in Türkiye and non-personal-data workloads to a global provider changes only the model identifier; the base URL, authentication and request body stay the same. In other words, the data class distinction drawn by the compliance function collapses into a single routing decision in code.

On the Türkiye-hosted side the catalogue includes llmtr/gemma-4, llmtr/qwen3-6-35b, llmtr/medgemma-4b, llmtr/trendyol-7b, llmtr/magibu-11b-v8, llmtr/ornith-1-35b, llmtr/qwen3-5-4b and llmtr/embeddinggemma-300m. Models from global providers such as OpenAI, Anthropic, Google, xAI, Qwen and Mistral are callable from the same catalogue. Calling a global model does not change the legal analysis: if the prompt contains personal data, that is a cross-border transfer and the institution must already have an appropriate safeguard in place for that provider. LLMTR does not remove that obligation; it makes the split between the two sides separable and reportable.

Two platform properties bear directly on the audit and documentation needs of public institutions. First, user prompts and model response bodies are not written to the usage and billing database; what is recorded is the metadata required for usage and cost reporting. Second, customer API keys are stored as SHA-256 hashes rather than plain text, and provider API keys are held only in environment variables.

For internal authorisation, each unit can hold its own API key with its own rate limit, spending cap and usage report. This makes it possible, within one account, to restrict one department to models hosted in Türkiye while another uses global models for workloads that contain no personal data. Commercially, an 8% platform margin applies to credit top-ups; no margin is added to model prices, which are consumed at provider list rates.

LLMTR makes no claim to any official approval, accreditation or certification. The platform does not perform the institution's legal assessment; it makes the institution's own decision easier to implement technically.

Routing by data class: the client and base URL stay fixed, only the model identifier changes

import os

from openai import OpenAI

client = OpenAI(
    base_url="https://llmtr.com/v1",
    api_key=os.environ["LLMTR_API_KEY"],
)

# The institution's data classification decision lives in one mapping table.
MODEL_BY_DATA_CLASS = {
    # Prompts containing personal data: model hosted in Turkiye.
    "personal_data": "llmtr/gemma-4",
    # Prompts with no personal data: a global model may also be used.
    "public": "gpt-5.3",
}

def ask(data_class: str, prompt: str) -> str:
    response = client.chat.completions.create(
        model=MODEL_BY_DATA_CLASS[data_class],
        messages=[{"role": "user", "content": prompt}],
    )
    return response.choices[0].message.content

Sources

The legislative references in this article were verified against the primary sources listed below. Last checked: 13 August 2026.

This content is informational and does not constitute legal advice. The final assessment rests with the institution's own compliance and legal functions.

  • Law No. 6698 on the Protection of Personal Data (KVKK), Article 9 (as amended by Law No. 7499, Art. 34, dated 2 March 2024) — mevzuat.gov.tr
  • Law No. 6698 on the Protection of Personal Data (KVKK), Article 18 (as amended and supplemented by Law No. 7499, Art. 35, dated 2 March 2024) — mevzuat.gov.tr
  • Guide on Generative Artificial Intelligence and the Protection of Personal Data in 15 Questions (Üretken Yapay Zekâ ve Kişisel Verilerin Korunması Rehberi), Publication No. 113, November 2025, question 10, page 47 — kvkk.gov.tr
  • Guide on the Transfer of Personal Data Abroad (Kişisel Verilerin Yurt Dışına Aktarılması Rehberi), KVKK Publication No. 48, January 2025 — kvkk.gov.tr
  • Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelik), Official Gazette No. 32598 of 10 July 2024 — resmigazete.gov.tr
  • Personal Data Protection Board decision no. 2024/959 dated 4 June 2024 adopting four standard contract templates — kvkk.gov.tr
  • Administrative fine amounts under Law No. 6698 for 2026 (revaluation rate of 25.49 percent) — kvkk.gov.tr

Establishing a legal basis for foreign generative AI use in a Turkish public institution

The steps a Turkish public institution should follow to deploy ChatGPT, the OpenAI API or a comparable foreign generative AI service in line with Article 9 of Law No. 6698 (KVKK).

  1. Build a data inventory and classify workloads. Classify the workloads intended for AI processing as containing no personal data, containing personal data, or containing special categories of personal data. Workloads with no personal data fall outside the Article 9 transfer regime, so isolating that class narrows the scope of every subsequent step.
  2. Verify whether an adequacy decision exists. Check whether the Personal Data Protection Board has issued, and published in the Official Gazette, an adequacy decision covering the destination country, a sector within that country, or the relevant international organisation. Where an adequacy decision exists, satisfying one of the processing conditions in Article 5 or Article 6 is sufficient.
  3. Record that the derogations are closed. Under Article 9(7) of Law No. 6698, sub-paragraphs (a), (b) and (c) of paragraph 6 do not apply to activities of public institutions subject to public law. Document in the assessment file that a design relying on consent or on performance of a contract cannot be used for those activities, and set out why the four remaining sub-paragraphs do not support continuous usage.
  4. Select an appropriate safeguard and execute the instrument. Choose the option in Article 9(4) that fits the institution's situation. Sub-paragraph (a) is unavailable where the counterparty is a commercial company, leaving the standard contract or the written undertaking. For a standard contract, select the template matching the transfer scenario from the four adopted by the Board and treat the Turkish text as authoritative.
  5. Notify the Authority within the deadline. If you take the standard contract route, notify the Authority within five business days of completing the signatures, either physically, through a registered electronic mail address, or through the notification module designated by the Board. On the routes that require Board authorisation, do not begin transfers before authorisation is granted.
  6. Carry the technical separation into the specification and into production. Write the data class to model identifier mapping into the technical specification, issue a separate API key per unit, and retain usage reports in an auditable form. Evidence that the legal assessment is actually enforced in the production environment is the institution's primary defence in any subsequent inspection.

Frequently asked questions

Can staff at a Turkish public institution use ChatGPT for their work?

For prompts that contain no personal data, the cross-border transfer regime in Article 9 of Law No. 6698 (KVKK) is not triggered; summarising legislation or drafting template text falls into this category. Prompts containing personal data, such as citizen applications, personnel records or correspondence, do constitute a cross-border transfer, and the institution must have an appropriate safeguard in place for the relevant provider. Institutions are expected to draw this line in a written usage policy and communicate it to staff.

Can a public institution transfer citizen data to OpenAI on the basis of consent?

No. Article 9(7) of Law No. 6698 (KVKK) provides that sub-paragraphs (a), (b) and (c) of paragraph 6 do not apply to activities of public institutions that are subject to public law. Explicit consent is the excluded sub-paragraph (a). For its activities subject to public law, a public institution cannot base a cross-border transfer on consent and must instead rely on an adequacy decision or an appropriate safeguard.

Does a standard contract have to wait for Board authorisation after signature?

No. The standard contract under Article 9(4)(c) of Law No. 6698 (KVKK) is the only one of the four appropriate safeguards that does not require separate Board authorisation. However, under Article 9(5) the contract must be notified to the Authority by the data controller or data processor within five business days of signature. For the agreement, binding corporate rules and written undertaking routes, transfers may not begin before Board authorisation or approval is granted.

Is a public institution fined if it misses the notification obligation?

Article 18(1)(d) of Law No. 6698 (KVKK) prescribes an administrative fine of 50,000 to 1,000,000 Turkish lira for this breach, and the amounts applied for 2026 are 90,308 to 1,806,177 Turkish lira. Article 18(2), however, limits that fine to natural persons and private-law legal persons. Where the act occurs within a public institution, Article 18(4) provides that disciplinary proceedings are taken against the relevant public officials upon notification by the Board, with the outcome reported back to the Board. A contractor serving the institution is a private-law legal person and can therefore be subject to the fine.

Which countries have received an adequacy decision?

Adequacy decisions are issued by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), published in the Official Gazette (Resmî Gazete) and reviewed at least once every four years. The Authority's January 2025 Guide on the Transfer of Personal Data Abroad states that the countries deemed to provide adequate protection under the pre-amendment version of Article 9 had not yet been determined by the Board. Institutions should separately verify through the Official Gazette, as at the date of their own assessment, whether an adequacy decision covering the relevant country, sector or international organisation has been published.

Does using a model hosted in Türkiye solve the cross-border transfer problem entirely?

Where personal data does not leave the country, the transfer regime in Article 9 of Law No. 6698 (KVKK) does not apply, which removes the largest part of the legal burden. Other obligations continue, however: reliance on one of the processing conditions in Article 5 or Article 6, the transparency obligation in Article 10 and the data security measures in Article 12 all apply equally to models hosted in Türkiye. Public institutions are also subject to a separate information and communication security framework, which must be assessed independently.

Related posts