Information Note on Chatbots such as ChatGPT Published

12.11.2024 Melis Ünlü
% 0

On 08.11.2024, the Personal Data Protection Authority published an Information Note on Chatbots (Example: Chatgpt) (Information Note).

According to the Information Note, a chatbot is software that attempts to simulate human conversation with the end-user through an interface, performing tasks and instructions given by the user. Accordingly, chatbots like ChatGPT, Siri, Alexa, and Gemini provide quick solutions to users in areas such as customer support, information retrieval, text creation, code writing, translation, and sentiment analysis.

AI-powered chatbots, which require large amounts of data to improve their performance, may process various personal data such as users' names, contact information, social media information, and IP addresses for purposes like providing services, improving user experience, ensuring information security, fulfilling legal obligations, and developing new services. Within this framework, the Information Note emphasizes that developers, manufacturers, service providers, and decision-makers must fulfill their legal obligations, with a particular emphasis on the following points:

  • Before collecting data, users must be transparently informed about how personal data is used, with whom it is shared, for what purposes it will be processed, the retention period, the identity of the data controller, and the rights of the individuals concerned.
  • Given that chatbots may also be used by children, proactive measures must be taken to ensure age verification and prevent negative experiences. Raising awareness among users is important to prevent data breaches and cybersecurity risks that may arise due to low user awareness.
  • While developing Chatbot applications, a risk assessment should be conducted before starting to process personal data, activities should comply with the accountability principle and personal data processing activities should be carried out by the general principles and legal bases set out in Law No. 6698 on the Protection of Personal Data (KVKK). If personal data is being processed, the legal basis for this should be explicitly stated.
  • Data security requires necessary technical and administrative measures. In this context, it is important to comply with certain internationally accepted standards to ensure privacy and data security and to have relevant certifications. Additionally, chatbots should use secure methods for storing and transmitting data inputs, such as text, audio, speech, and images, in secure environments.
  • Attention should be paid to the Recommendations on the Protection of Personal Data in the Field of Artificial Intelligence set by the Personal Data Protection Boards, and obligations under the KVKK should be fulfilled.

All rights of this article are reserved. This article may not be used, reproduced, copied, published, distributed, or otherwise disseminated without quotation or Erdem & Erdem Law Firm's written consent. Any content created without citing the resource or Erdem & Erdem Law Firm’s written consent is regularly tracked, and legal action will be taken in case of violation.

Other Contents

Public Announcement Regarding the Standard Contract Notification Module
Legal Developments
Public Announcement Regarding the Standard Contract Notification Module

By Article 9 of the Law No. 6698 on the Protection of Personal Data (the "Law"), titled "Transfer of Personal Data Abroad," significant amendments have been made by the Law on Amendments to the Criminal Procedure Code No. 7499 and Certain Other Laws. Within the scope of these amendments, "standard...

Personal Data Protection 28.10.2024
A Public Announcement on Personal Data Processing Activities of Research Companies by Dialing Random Numbers was published
Legal Developments
A Public Announcement on Personal Data Processing Activities of Research Companies by Dialing Random Numbers was published

On 26.08.2024, the Personal Data Protection Authority published a Public Announcement on “Personal Data Processing Activities of Research Companies Using ‘Random Number Dialing and Telephone Interview Method’ for Statistical Research”...

Personal Data Protection 27.08.2024
Latest Developments Regarding Personal Data Transfers Abroad
Legal Developments
Latest Developments Regarding Personal Data Transfers Abroad

The Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad (Regulation) entered into force through publication in the Official Gazette dated 10.07.2024 and numbered 32598. Important regulations are as follows...


Personal Data Protection 10.07.2024
Public Announcement on the Draft Documents Regarding Standard Contracts and Binding Corporate Rules
Legal Developments
Public Announcement on the Draft Documents Regarding Standard Contracts and Binding Corporate Rules

On 17.05.2024, the Turkish Personal Data Protection Authority (Authority) released the draft documents concerning standard contracts and binding corporate rules, which are stipulated as appropriate safeguards for cross-border transfer under the amendments to the Law No. 6698 on the Protection of Personal Data...

Personal Data Protection 17.05.2024
Public Announcement on the Draft Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad
Legal Developments
Public Announcement on the Draft Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad

On 09.05.2024, the Turkish Personal Data Protection Authority (Authority) published the Draft Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad (Draft) and opened the Draft for public opinion and assessment. In this context, opinions and suggestions regarding the...

Personal Data Protection 16.05.2024
Cooperation Protocol Signed between the Turkish Personal Data Protection Authority and the Personal Data Protection Board of the Turkish Republic of Northern Cyprus
Legal Developments
Cooperation Protocol Signed between the Turkish Personal Data Protection Authority and the Personal Data Protection Board of the Turkish Republic of Northern Cyprus

On 18.04.2024, it was announced that a cooperation protocol (Protocol) was signed between the Turkish Personal Data Protection Authority and the Personal Data Protection Board of the Turkish Republic of Northern Cyprus...

Personal Data Protection 25.04.2024
Amendment to the Law on the Protection of Personal Data
Legal Developments
Amendment to the Law on the Protection of Personal Data

The Law on Amendments to the Code of Criminal Procedure and Certain Acts numbered 7499 (Law), including Amendments to the Law on Personal Data Protection numbered 6698 (LPDP) was published in the Official Gazette dated 12.03.2024 and numbered 32487...

Personal Data Protection 12.03.2024
Law Amendment Proposal on the Law on the Protection of Personal Data Submitted to the Turkish Grand National Assembly
Legal Developments
Law Amendment Proposal on the Law on the Protection of Personal Data Submitted to the Turkish Grand National Assembly

On 16.02.2024, the Justice Committee of the Turkish Grand National Assembly (TBMM) received the bill (Bill) on the long-awaited amendment to the Law on Personal Data Protection No. 6698 (LPDP). It can be said that the Bill, which introduces regulations similar to the European Union General Data Protection...

Personal Data Protection 20.02.2024
Information Note on Processing of Personal Data on the Legal Ground of Being Stipulated by Laws was Published
Legal Developments
Information Note on Processing of Personal Data on the Legal Ground of Being Stipulated by Laws was Published

On 12.02.2024, the Information Note on Processing of Personal Data on the Legal Ground of Being Stipulated by Laws (Information Note) was published. The Information Note aims to clarify the scope and meaning of the personal data processing legal ground of “being expressly stipulated by law” in Article 5/2(a) of...

Personal Data Protection 15.02.2024
Guidelines on the Protection of Personal Data in Election Activities
Legal Developments
Guidelines on the Protection of Personal Data in Election Activities

On 24.01.2024, the Personal Data Protection Authority published the Guidelines on the Protection of Personal Data in Election Activities (Guidelines). The Guidelines aim to remind public administrations, political parties, candidates, and voters involved in election activities of their obligations or rights under...

Personal Data Protection 26.01.2024
Deepfake Information Note by Turkish Personal Data Protection Authority
Legal Developments
Deepfake Information Note by Turkish Personal Data Protection Authority

On 19.01.2024, the Personal Data Protection Authority published the Deepfake Information Note (Information Note). The purpose of the Information Note is to provide a better understanding of what Deepfake technology is, which is formed from the words deep learning and fake. The key points in the Information Note...

Personal Data Protection 22.01.2024
Guidelines on the Processing of Republic of Türkiye Identity Numbers Published
Legal Developments
Guidelines on the Processing of Republic of Türkiye Identity Numbers Published

On 16.01.2024, the Personal Data Protection Authority published Guidelines on the Processing of Republic of Türkiye Identity Numbers (Guidelines). The purpose of the Guidelines are to provide guidance to data controllers by setting out the provisions of the legislation envisaging the processing of Turkish...

Personal Data Protection 19.01.2024
The Decision of the Personal Data Protection Board Regarding the Exemption of Village Public Legal Entities from the Registration Obligation in the Data Controllers Registry
Legal Developments
The Decision of the Personal Data Protection Board Regarding the Exemption of Village Public Legal Entities from the Registration Obligation in the Data Controllers Registry

The Decision of the Personal Data Protection Board Regarding the Exemption of Village Legal Entities from the Registration Obligation in the Data Controllers Registry, dated 14/12/2023 and numbered 2023/2135 (Decision) is published in the Official Gazette dated 12.01.2024 and numbered 32427... 

Personal Data Protection 12.01.2024
The Announcement Regarding Personal Data Processed to Send Verification Code via SMS During Store Shopping
Legal Developments
The Announcement Regarding Personal Data Processed to Send Verification Code via SMS During Store Shopping

The Personal Data Protection Authority has published a public announcement dated 13.11.2023 regarding the personal data processed in order to send a verification code via SMS to the data subjects during the transactions at the cash register following shopping. You may find a brief explanation of the...

Personal Data Protection 15.11.2023
Personal Data Protection Board Amends the Exception Criteria for the Obligation to Register with the Data Controllers Registry
Legal Developments
Personal Data Protection Board Amends the Exception Criteria for the Obligation to Register with the Data Controllers Registry

With the decision of the Personal Data Protection Board (Board) dated 06.07.2023 and numbered 2023/1154, the “annual financial balance sheet total” adopted by the Board as an exception criteria to the obligation to register to the Data Controllers’ Registry has been increased from 25 million Turkish Liras to...

Personal Data Protection 26.07.2023
Record Fine in GDPR History: Irish Data Protection Commission’s Meta Decision
Legal Developments
Record Fine in GDPR History: Irish Data Protection Commission’s Meta Decision

The decision by the Irish Data Protection Authority (Authority) dated 12.05.2023 on Meta Platforms Ireland Limited (Meta Ireland) (Decision) has been announced on 22.05.2023. Pursuant to the Decision, an administrative fine of 1.200.000.000 Euros was imposed on Meta Ireland...

Personal Data Protection 31.05.2023
The Regulation on the Collection, Storage and Sharing of Insurance Data Entered into Force
Legal Developments
The Regulation on the Collection, Storage and Sharing of Insurance Data Entered into Force

The Regulation on the Collection, Storage and Sharing of Insurance Data (Regulation) entered into force through publication in the Official Gazette dated 18.10.2022 and numbered 31987. Some of the important provisions introduced by the Regulation are summarized...


Personal Data Protection 24.10.2022
Guideline on Banking Sector Best Practices Regarding Personal Data Protection Has Been Published
Legal Developments
Guideline on Banking Sector Best Practices Regarding Personal Data Protection Has Been Published

On 05.08.2022, the Personal Data Protection Authority (“Authority”), published Guideline on Banking Sector Good Practices Regarding the Personal Data Protection (“Guideline”). The purpose of the Guideline is guiding data controller banks regarding the personal data processing activities carried out...

Personal Data Protection 09.08.2022
Briefing for the Impact Assessment of Data Act Has Been Published
Legal Developments
Briefing for the Impact Assessment of Data Act Has Been Published

On 14.07.2022, the European Parliament Research Service published a briefing (“Briefing”) for the impact assessment (“IA”) of the regulation of the European Parliament and the European Council on harmonised rules on fair access to and use of data (“Data Act”), submitted on 23.02.2022...

Personal Data Protection 20.07.2022
Regulation on Processing of Land Registry and Cadastre Data and Transactions Held in Electronic Environment has been Published
Legal Developments
Regulation on Processing of Land Registry and Cadastre Data and Transactions Held in Electronic Environment has been Published

The Regulation on Processing of Land Registry and Cadastre Data and Transactions Held in Electronic Environment regulating the procedure and principles regarding the process of the data in the Central Database of the General Directorate of Land Registry and the transactions held in electronic...

Personal Data Protection 16.06.2022
The Regulation on Processing and Protection of Personal Data by the Social Security Institution was Published
Legal Developments
The Regulation on Processing and Protection of Personal Data by the Social Security Institution was Published

The Regulation on Process and Protection of Personal Data by the Social Security Institution (“Regulation”) entered into force through its publication in the Official Gazette dated 19.02.2022 and numbered 31755.

Personal Data Protection 23.02.2022
Regulation on Processing of Personal Data and Protection of Confidentiality in the Electronic Communications Sector was Published
Legal Developments
Regulation on Processing of Personal Data and Protection of Confidentiality in the Electronic Communications Sector was Published

Regulation on Processing of Personal Data and Protection of Confidentiality in the Electronic Communications Sector was Published

Personal Data Protection 4.12.2020
The Personal Data Protection Board Ex-Officio Initiated An Investigation against WhatsApp
Legal Developments
The Personal Data Protection Board Ex-Officio Initiated An Investigation against WhatsApp

The Personal Data Protection Board Ex-Officio Initiated An Investigation against WhatsApp

Personal Data Protection 13.01.2021
The Personal Data Protection Authority’s New Resolution
Legal Developments
The Personal Data Protection Authority’s New Resolution

The Personal Data Protection Authority’s New Resolution

Personal Data Protection 19.01.2021
The Board’s Decision Regarding Registration Obligation of Commercial Enterprises Affiliated to Associations, Foundations and Unions to the VERBIS has been Published
Legal Developments
The Board’s Decision Regarding Registration Obligation of Commercial Enterprises Affiliated to Associations, Foundations and Unions to the VERBIS has been Published

The Board’s Decision Regarding Registration Obligation of Commercial Enterprises Affiliated to Associations, Foundations and Unions to the VERBIS has been Published

Personal Data Protection 25.06.2021
The Personal Data Protection Board Announced Its Decision Regarding the WhatsApp Investigation Initiated Ex-Officio
Legal Developments
The Personal Data Protection Board Announced Its Decision Regarding the WhatsApp Investigation Initiated Ex-Officio

The Personal Data Protection Board Announced Its Decision Regarding the WhatsApp Investigation Initiated Ex-Officio

Personal Data Protection 8.09.2021

For creative legal solutions, please contact us.