KVKK
The Turkish data-protection framework that must be considered when AI assistants process personal data.
TL;DR
Turkey’s personal data protection law; relevant for SME AI deployments.
Quick facts
- Category
- AI & knowledge management
- Product tie-in
- KobiGPT RAG platform
- Related
- See compare and tools pages
- Locale
- TR and EN site
Why teams choose KobiGPT
- Understand terms before evaluating vendors.
- Link concepts to KobiGPT features (RAG, Kobi Kredi).
- Share glossary links with procurement and legal.
- Explore assistant use cases next.
Product facts
- Ücretsiz plan
- 100 doküman · 2 departman · 120 Kobi/ay(PLAN_CONFIG)
- Starter
- 1000 doküman · 5 departman · 1000 Kobi/ay(PLAN_CONFIG)
- Pro
- 12500 doküman · 25 departman · 12500 Kobi/ay(PLAN_CONFIG)
- KVKK
- Use-case-specific legal review and access scoping are required for assistants processing personal data.
Why KVKK appears in AI projects
When payroll, customer, candidate, or contract files containing personal data are connected to an AI assistant, a processing activity may be introduced. The question is not only what the model answers; collection, storage, access, and transfers to external services matter together.
Before launching an assistant, inventory which files contain personal data and which users need to see them. Keep a company-wide knowledge base separate from a restricted legal or HR assistant.
Scope and access controls
In KobiGPT, company and department scope helps keep personal-data documents out of every user’s retrieval space. The role model defines super_admin, admin, manager, and viewer levels; those roles do not replace a data-protection policy.
Citations also support governance. Seeing which document passage supports an answer makes an incorrect scope or stale file easier to detect; it does not automate a legal-compliance decision.
A practical review checklist
Data minimisation, retention, access rights, and supplier agreements should be settled with the legal team. Supplying an assistant only with the folders it actually needs reduces technical and organisational risk at the same time.
KVKK is not a product badge; the assessment depends on the use case. KobiGPT’s citations and scope controls provide technical support, while notices, legal basis, and retention decisions require qualified advice.
Applying Why KVKK appears in AI projects in a controlled workflow
A useful way to evaluate kvkk is to follow one real question from the source document to the final answer. Record which file was selected, what context reached the model, and what a reviewer would need to verify. This turns a definition into an operational check and makes the result comparable across teams.
The same check should include ownership and change management. Decide who updates the relevant documents, how an outdated result is reported, and which access boundary applies. KobiGPT can provide the assistant and the cited document context, but the organisation still owns the source material, permissions, and the decision made from the answer.
FAQ
What is KVKK in practice?
Turkey’s personal data protection law; relevant for SME AI deployments.
Does KobiGPT use this?
See product docs and feature pages for implementation details.
More reading?
Visit our blog and FAQ.
Accuracy disclaimer?
Educational content; verify for compliance decisions.
Is KVKK compliance just choosing a role?
No. Roles and department scope are technical controls; purpose, legal basis, retention, and notices need separate review.
Can every personal-data file go into the general assistant?
No. Identify the purpose and intended audience, and use a separate restricted assistant when necessary.
Comparison
| Feature | KobiGPT | Alternative |
|---|---|---|
| SME focus | Yes | N/A |
| Citations | When using RAG | N/A |
| Glossary depth | Growing | N/A |
| Tools | Interactive | N/A |