Trust and compliance · 2026-08-13
Can Turkish public data be stored in the cloud? Circular 2019/12 and AI
How Article 3 of Presidential Circular No. 2019/12 limits cloud storage of Turkish public sector data, whether an LLM API call falls within that limit, and how institutions decide by data class.
What does Circular No. 2019/12 say about storing public data in the cloud?
Presidential Circular No. 2019/12 on Information and Communication Security Measures (Bilgi ve İletişim Güvenliği Tedbirleri) was published in the Official Gazette (Resmî Gazete) of 6 July 2019, issue 30823. The circular contains 21 articles and imposes direct obligations on Turkish public institutions covering data storage, network configuration, procurement and communications.
The operative cloud provision is Article 3. Its Turkish original reads: “Kamu kurum ve kuruluşlarına ait veriler, kurumların kendi özel sistemleri veya kurum kontrolündeki yerli hizmet sağlayıcılar hariç bulut depolama hizmetlerinde saklanmayacaktır.” In unofficial English translation: data belonging to public institutions and organizations shall not be stored in cloud storage services, except in the institutions' own dedicated systems or with domestic service providers under the institution's control.
The circular's opening paragraph frames the purpose as securing critical data whose loss of confidentiality, integrity or availability could threaten national security or disrupt public order. That purpose clause governs how the remaining articles are read.
- Circular date: 5 July 2019. Official Gazette publication: 6 July 2019, issue 30823.
- Number of articles: 21.
- Subject: Information and Communication Security Measures (Bilgi ve İletişim Güvenliği Tedbirleri).
- Addressees: public institutions and organizations, plus operators providing critical infrastructure services.
Is Article 3 a ban or a conditional permission? Reading the word “except”
The sentence structure of Article 3 does not impose a blanket ban on cloud usage by Turkish public institutions. The provision states a general rule and two carve-outs: institutional data shall not be stored in cloud storage services, except in the institutions' own dedicated systems and except with domestic service providers under the institution's control.
The two conditions in the second carve-out are cumulative, not alternative. A provider being domestic is not sufficient on its own; the service must also be under the institution's control. Equally, a claim of control is not sufficient without the provider being domestic.
This reading places the burden of proof on the institution. An institution using a cloud-based service must be able to document that the service falls within a carve-out; a vendor describing itself as domestic in marketing material does not substitute for that documentation.
- First carve-out: the institution's own dedicated systems, where hardware, operation and access authorization remain with the institution.
- Second carve-out: domestic service providers under the institution's control. Both conditions must hold together.
- Control is not a contractual label. Where the data physically sits, who can access it, who holds the access logs, and how data is destroyed at end of service must all be documentable.
- General-purpose cloud storage services hosted outside Turkey fall into neither carve-out.
- A control assessment is not complete until the subcontractor chain has been examined.
Can a public institution use an LLM? Processing versus storage
An LLM API call and a cloud storage service are not the same thing, but the boundary between them is set by the provider's logging behavior. When a request is sent, text is processed and a response is generated; that operation alone is not a storage activity.
Storage begins the moment the provider persists request and response bodies. If prompt content is written to a database, a debug record, a model improvement pool, or an audit log held indefinitely, then institutional data is being stored on that provider's systems and Article 3 becomes relevant to the assessment.
The circular's text mentions neither artificial intelligence nor language models. It dates from 2019, before this technology became common in Turkish public institutions. An institution therefore has to construct and write down its own reasoning by analogy rather than find a directly applicable provision; the distinction drawn in this article is one proposed analogy, not a binding interpretation.
The right question is not whether AI usage is prohibited, but whether institutional data becomes persistent on the provider's side during the call. The questions an institution should put to a provider are technical and answerable.
- Are request and response bodies persisted on the provider's side, and if so for how long?
- In which country does processing actually occur, and is the call routed to a subcontractor or an overseas region?
- Is submitted content used for model training or improvement?
- Do debug, rate-limiting and billing records contain the prompt text itself, or only counters?
- How are records destroyed when the contract ends, and can the institution verify that destruction?
Decision table by data classification
The correct starting point for a Turkish public institution is a data inventory. Circular No. 2019/12 does not impose a single uniform rule; it defines progressively stricter obligations by data type, so each use case inside the institution must be classified separately.
The strictest obligation is in Article 1: “Nüfus, sağlık ve iletişim kayıt bilgileri ile genetik ve biyometrik veriler gibi kritik bilgi ve veriler yurtiçinde güvenli bir şekilde depolanacaktır.” In unofficial translation: critical information and data such as population, health and communication records, together with genetic and biometric data, shall be stored securely within Turkey. This article defines no exception.
Article 2 adds a network-level condition for critical data, requiring it to be kept on a secure network that is disconnected from the internet and physically secured, with controlled device access and tamper-protected log retention. A system running on an air-gapped network cannot, by definition, call an external API.
- Do not downgrade a data class on an untested anonymization claim; assess re-identification risk first.
- If several data classes flow through one application, classify at request level rather than at application level.
- Record the classification decision and its reasoning. An audit asks for the reasoning, not the decision alone.
| Data class | Basis in the circular | Must remain in Turkey? | Suitable architecture |
|---|---|---|---|
| Population, health and communication records; genetic and biometric data | Article 1 | Yes, with no exception | In-house system or a Turkey-hosted model, with processing location fixed by contract |
| Classified critical data | Article 2 | Yes, plus an air-gapped secure network requirement | Model running inside the institution's network; no outbound API calls |
| Institutional data (unclassified administrative and operational records) | Article 3 | Not storable in cloud storage, except in the institution's own systems or with a domestic provider under its control | Turkey-hosted model, or a domestic provider that documents it meets the carve-out conditions |
| Public sector email content | Article 18 | Yes; servers must be located in Turkey and under the institution's control | Email bodies are not sent to an external provider; if summarization is needed, a Turkey-hosted model is used |
| Published legislation, open data, anonymized statistics | No specific restriction in the circular | No | A global provider model may be used; the institution's own internal policy governs |
Guide compliance and audit now sit with the Cyber Security Directorate
Circular No. 2019/12 delegates implementation detail to a separate document, the Information and Communication Security Guide (Bilgi ve İletişim Güvenliği Rehberi). The circular states that the guide will contain differentiated security levels and makes compliance mandatory: all public institutions and operators providing critical infrastructure services must follow the guide's procedures and principles in newly established information systems.
The circular also imposes an audit obligation on institutions. Institutions must establish audit mechanisms for implementation of the guide and audit that implementation at least once a year; duties and activities carried out for national security and confidentiality purposes are excluded from this audit.
When the circular was published, this audit report went to the Presidency's Digital Transformation Office (Cumhurbaşkanlığı Dijital Dönüşüm Ofisi), but the addressee has changed. Presidential Decree No. 177, published in the Official Gazette of 8 January 2025, issue 32776, established the Cyber Security Directorate (Siber Güvenlik Başkanlığı) under the Presidency. Provisional Article 1 of Law No. 7545 (Siber Güvenlik Kanunu), published in the Official Gazette of 19 March 2025, issue 32846, required the Digital Transformation Office's assets, rights and obligations used exclusively for national cyber security activities to be transferred to the Cyber Security Directorate within six months of the law's publication.
A large share of published material still names the Digital Transformation Office as the addressee. Compliance, audit and oversight activities for the guide are today carried out within the Cyber Security Directorate, and institutions should update the addressee named in their internal directives accordingly.
On the procurement side, Articles 12 and 13 of the circular apply directly. Where an AI software service or rental procurement is being run, both articles belong in the technical specification.
- Article 12: suppliers and/or manufacturers must provide, as far as possible, a written undertaking that procured software or hardware contains no feature outside its intended use and no backdoor vulnerability.
- Article 13: procured or developed software must pass security testing before being put into use.
- Article 18: public sector email servers must be located in Turkey and under the institution's control, with encrypted server-to-server communication.
- Audit frequency: at least once per year.
- Turkish tender documents typically describe the subject as AI software rental or service procurement rather than in API terms; processing location and log policy must be specified separately in the technical requirements.
- Use the current version of the Information and Communication Security Guide for compliance work, and confirm the version directly with the competent authority.
Where LLMTR fits in this decision chain
LLMTR is a gateway platform that provides access to both Turkey-hosted and global models through a single OpenAI-compatible API. For an institution trying to operationalize the distinction in Article 3, the practical requirement is to split model selection by data class at the code level and make that split auditable.
The catalog separates Turkey-hosted models from global provider models explicitly. Turkey-hosted models are processed inside Turkey; global provider models can be called through the same API surface, but the respective provider's own data-processing terms additionally apply to them. Making that distinction deliberately is the institution's responsibility, not the architecture's.
On the data path, LLMTR applies the following technical boundaries: user prompts and model response bodies are not written to the usage and billing database, which holds usage counters only. Customer API keys are stored as SHA-256 hashes rather than plaintext. Provider API keys exist only in environment variables. Each unit can hold a separate API key with its own rate limit, spending cap and usage report, which lets a multi-unit institution separate consumption by unit.
On the commercial side the distinction is clear: an 8% platform margin applies to credit top-ups, and no margin is added to model prices. This matters for procurement units preparing a budget line and needing to compute cost in advance.
No claim is made that LLMTR holds any public sector approval, accreditation, certification or official partnership. Whether the description “domestic service provider under the institution's control” in Article 3 applies to a specific service is an assessment for the institution's own compliance and legal units. The purpose of this article is to set out the technical questions and decision criteria that assessment requires.
Routing by data class. Apart from the base URL and the model ID, OpenAI SDK usage is unchanged.
import os
from openai import OpenAI
client = OpenAI(
base_url="https://llmtr.com/v1",
api_key=os.environ["LLMTR_API_KEY"],
)
# Data class -> model mapping. The decision comes from the inventory,
# not from the architecture.
MODEL_BY_CLASS = {
# Institutional data under Articles 1 and 3: Turkey-hosted processing
"critical": "llmtr/gemma-4",
"institutional": "llmtr/qwen3-6-35b",
# Public or anonymized data: a global provider model may be used
"public": "openai/gpt-5.5",
}
def ask(data_class: str, text: str) -> str:
model = MODEL_BY_CLASS[data_class]
response = client.chat.completions.create(
model=model,
messages=[{"role": "user", "content": text}],
)
return response.choices[0].message.content
# Classify at request level, not at application level.
summary = ask("institutional", "Summarize this minute in three bullet points.")
Sources
The legislative references in this article were verified against the primary sources listed below. Last checked: 13 August 2026.
This content is informational and does not constitute legal advice. The final assessment rests with the institution's own compliance and legal units.
- Presidential Circular No. 2019/12 on Information and Communication Security Measures, Official Gazette of 6 July 2019, issue 30823 — resmigazete.gov.tr
- Presidential Decree No. 177 on the Cyber Security Directorate (Siber Güvenlik Başkanlığı), Official Gazette of 8 January 2025, issue 32776 — resmigazete.gov.tr
- Law No. 7545 (Siber Güvenlik Kanunu), adopted 12 March 2025, Official Gazette of 19 March 2025, issue 32846 — resmigazete.gov.tr
- Announcement on the transfer of Information and Communication Security Guide compliance, audit and oversight activities to the Cyber Security Directorate, 5 February 2026 — bid.deu.edu.tr
Assessing LLM usage in a Turkish public institution under Circular No. 2019/12
Sequential steps for a public institution to assess language model usage against the circular's articles, from data inventory through to audit reporting.
- Build and classify the data inventory. Classify the data that will flow through the use case against Articles 1, 2 and 3 of the circular. Population, health and communication records together with genetic and biometric data must be flagged as a separate class.
- Put logging and processing-location questions to the provider in writing. Obtain written answers on whether request and response bodies are persisted, for how long, in which country processing occurs, whether subcontractors are used, and whether content is used for training.
- Write the data class to model mapping into the architecture. Fix in application code and architecture documentation which model is called for each data class. Make the routing decision at request level rather than leaving it at application level.
- Add the circular's articles to procurement documents. Include the Article 12 undertaking that the product contains no backdoor vulnerability and the Article 13 requirement for security testing before use. Make processing location and log policy separate specification items.
- Document the decision and its reasoning. Record in writing which data class is processed under which architecture and the reasoning applied to the Article 3 carve-out. An audit will ask for the reasoning behind the decision, not only the decision.
- Plan the annual audit and reporting. The circular requires implementation to be audited at least once a year. Keep the audit calendar, the corrective and preventive action record, and the name of the receiving authority current in your internal directive.
Frequently asked questions
Can Turkish public institutions use cloud services?
Article 3 of Circular No. 2019/12 sets a conditional limit rather than a blanket ban. Institutional data is not to be stored in cloud storage services, with the institutions' own dedicated systems and domestic service providers under institutional control excluded from that rule. The burden of documenting that a given service falls within a carve-out rests with the institution.
Does Circular No. 2019/12 mention artificial intelligence or language models?
No. The circular was published on 6 July 2019 and its text contains no reference to artificial intelligence or language models. Rather than looking for a directly applicable provision, institutions must apply the existing articles to their own use cases by analogy and record that reasoning in writing.
Does an LLM API call count as cloud storage?
The provider's logging behavior is decisive. Processing text and returning a response is not in itself a storage activity, but if the provider persists request and response bodies then institutional data is being stored on that provider's systems and Article 3 enters the assessment. The first question to ask a provider is therefore about retention period and log content.
Which data must be stored within Turkey?
Article 1 of the circular names them explicitly: critical information and data such as population, health and communication records, together with genetic and biometric data, must be stored securely within Turkey. The article defines no exception. Article 2 additionally requires critical data to sit on a physically secured network that is disconnected from the internet.
Which authority now receives the guide compliance and audit report?
Compliance, audit and oversight activities for the Information and Communication Security Guide are carried out within the Cyber Security Directorate (Siber Güvenlik Başkanlığı). The Directorate was established by Presidential Decree No. 177, published in the Official Gazette of 8 January 2025, issue 32776, and Provisional Article 1 of Law No. 7545 required transfer of the relevant Digital Transformation Office assets within six months.
Is LLMTR an approved or certified provider for Turkish public institutions?
No. LLMTR holds no public sector approval, accreditation, certification or official partnership, and makes no such claim. LLMTR offers Turkey-hosted and global models through a single OpenAI-compatible API; the decision on which model may be used for which data class belongs to the institution's compliance and legal units.