Yapay Zekâ Sistemlerinin Veri İşleme Faaliyetleri Karşısında KVKK: 2024 Reformu Sonrası Güncel Sorunlar ve Hukuki Gelecek
The Personal Data Protection Law (KVKK) in the Face of AI Systems' Data Processing Activities: Current Issues and the Legal Future After the 2024 Reform
Yapay zekâ sistemlerinin veri işleme kapasitesi arttıkça kişisel verilerin korunması hukuku yeni bir sınavla karşı karşıya. 6698 sayılı Kanun'da 7499 sayılı Kanun'la yapılan 2024 değişiklikleri, bu tartışmayı güncel bir zemine taşıyor.
Özet
Yapay zekâ teknolojileri son yıllarda kamu ve özel sektör faaliyetlerinin merkezine yerleşmiş; büyük veri, makine öğrenmesi ve üretken yapay zekâ sistemleri kişisel verilerin işlenme yöntemlerini dönüştürmüştür. Bu çalışmada yapay zekâ sistemlerinin veri işleme faaliyetleri, 6698 sayılı Kişisel Verilerin Korunması Kanunu ve bu Kanun'da 7499 sayılı Kanun (RG 12.03.2024; yürürlük 01.06.2024) ile yapılan değişiklikler çerçevesinde değerlendirilmekte; veri sorumlularının yükümlülükleri, otomatik karar verme süreçleri, kişisel verilerin yurt dışına aktarımının yeni rejimi ve AB Yapay Zekâ Tüzüğü'nün (AI Act) olası etkileri incelenmektedir.
Anahtar Kelimeler: KVKK, yapay zekâ, AI Act, otomatik karar verme, veri sorumlusu, yurt dışı aktarım, 7499 sayılı Kanun.
I. Giriş
Dijital ekonominin temel üretim faktörlerinden biri veridir. Yapay zekâ teknolojilerinin gelişmesiyle veri işleme faaliyetlerinin kapsamı ve yoğunluğu önemli ölçüde artmış; yapay zekâ modelleri öğrenme süreçlerini sürdürebilmek için çok büyük veri kümelerine ihtiyaç duyar hâle gelmiştir. Bu durum bireylerin kişisel verilerinin işlenmesini neredeyse kaçınılmaz kılmaktadır.
Teknolojinin hızına karşılık hukuki düzenlemelerin aynı tempoda gelişememesi, kişisel veri koruması bakımından ciddi riskler doğurur. Türkiye'de bu alandaki temel düzenleme 6698 sayılı Kanun'dur. Kanun, bireylerin temel hak ve özgürlüklerini korumayı amaçlamakta ve veri işleyen gerçek ve tüzel kişilere önemli yükümlülükler yüklemektedir. 2024 yılında 7499 sayılı Kanun'la yapılan değişiklikler ise, Kanun'un Avrupa Birliği Genel Veri Koruma Tüzüğü (GDPR) ile uyumlaştırılması yolunda atılan ilk adımdır.
II. Yapay Zekâ ve Veri İşleme Faaliyetinin Niteliği
KVKK m.3'te kişisel veri, "kimliği belirli veya belirlenebilir gerçek kişiye ilişkin her türlü bilgi" olarak tanımlanmıştır. Bu kapsamda ad-soyad, T.C. kimlik numarası, telefon, e-posta, konum verileri, IP adresi, biyometrik veriler ve davranışsal veriler kişisel veri niteliği taşır.
Modern yapay zekâ sistemleri yalnızca doğrudan kimlik bilgilerini değil; bireyin davranış kalıplarını, tercihlerini ve psikolojik eğilimlerini de analiz edebilir. Örneğin bir e-ticaret platformu, kullanıcının hangi ürünleri görüntülediğini, hangi sayfada ne kadar kaldığını ve hangi saatlerde alışveriş yaptığını tespit ederek kapsamlı bir dijital profil oluşturabilir. Bu, klasik veri işlemenin ötesinde bir gözetim kapasitesi anlamına gelir.
III. KVKK'nın Temel İlkeleri Açısından Yapay Zekâ
KVKK m.4, veri işlemede uyulması gereken genel ilkeleri düzenler. Yapay zekâ bağlamında bu ilkelerin uygulanması özel zorluklar barındırır.
A. Hukuka ve dürüstlük kurallarına uygunluk
Yapay zekâ sistemlerinin veri toplama yöntemleri kullanıcılar tarafından çoğu zaman tam olarak anlaşılamaz. İnternet üzerindeki açık kaynaklardan veri kazıma (scraping) yoluyla toplama yapılırken, verilerin hangi amaçla kullanılacağına dair yeterli bilgilendirme yapılmaması bu ilkeyi tartışmalı kılar.
B. Belirli, açık ve meşru amaç
Veri işleme açık ve belirli amaçlara dayanmalıdır. Oysa yapay zekâ sistemlerinde toplanan veriler çoğu kez "ileride ortaya çıkabilecek" belirsiz amaçlar için saklanır; bu da amaçla bağlılık ilkesinin ihlaline yol açabilir.
C. Amaçla bağlantılı, sınırlı ve ölçülü olma (veri minimizasyonu)
Bu ilke, veri işlemenin amaç için gerekli olanla sınırlı kalmasını gerektirir. Birçok yapay zekâ sistemi ise ihtiyaç duyduğundan çok daha fazla veri toplamaktadır. Ölçülülük ve veri minimizasyonu, KVKK m.4 kapsamında iç içe geçse de, yapay zekâ projelerinin tasarımdan itibaren (privacy by design) bu ilkeye göre kurgulanması en önemli uyum tedbirlerinden biridir.
IV. İşleme Şartı ve Hukuka Uygunluk Sebebi Sorunu
Yapay zekâ tartışmalarının çoğu ilkelere odaklanır; oysa uygulamada asıl mesele hangi işleme şartına dayanıldığıdır. KVKK m.5, kişisel verilerin işlenmesini kural olarak açık rızaya bağlar; açık rıza yoksa kanunilik, sözleşmenin ifası, hukuki yükümlülük, alenileştirme, bir hakkın tesisi/kullanımı/korunması ve veri sorumlusunun meşru menfaati hâllerinden birinin bulunması gerekir. Özel nitelikli veriler için m.6'daki şartlar uygulanır.
Yapay zekâ modellerinin eğitiminde milyonlarca kişiden tek tek açık rıza almak çoğu zaman fiilen imkânsızdır. Bu nedenle tartışma "meşru menfaat" şartının yapay zekâ eğitimi için uygulanıp uygulanamayacağı; uygulanacaksa ilgili kişinin hak ve özgürlükleriyle yapılacak menfaat dengesi (denge testi) etrafında yoğunlaşmaktadır. Aydınlatma yükümlülüğü (m.10) ve ilgili kişinin hakları (m.11) ise her hâlde geçerliliğini korur.
V. Otomatik Karar Verme Sistemleri ve "Kara Kutu" Sorunu
Yapay zekânın en tartışmalı yönü otomatik karar verme mekanizmalarıdır. Bugün kredi değerlendirmesi, işe alım, sigorta risk analizi ve reklam hedefleme gibi süreçler büyük ölçüde algoritmalarla yürütülmektedir. Bu sistemlerin temel sorunu "kara kutu" niteliğidir: kararın hangi verilere ve kriterlere dayandığı çoğu zaman açıklanamaz. Bir kredi başvurusunun reddinde hangi verilerin kullanıldığının ve kararın nasıl oluştuğunun bilinememesi, hukuk devletinin şeffaflık unsuruyla çelişir.
VI. Veri Sorumlusunun Hukuki ve İdari Sorumluluğu
KVKK kapsamında veri sorumlusu sıfatı taşıyan kurumlar önemli yükümlülükler altındadır:
VII. Kişisel Verilerin Yurt Dışına Aktarımının Yeni Rejimi (m.9)
Yapay zekâ hizmetlerinin büyük bölümü bulut altyapıları ve sınır ötesi veri akışlarıyla çalıştığından, yurt dışına aktarım rejimi yapay zekâ uyumu açısından kritik öneme sahiptir. 7499 sayılı Kanun, m.9'u GDPR mantığına yaklaştırarak kademeli bir sistem getirmiştir:
Değişiklik 01.06.2024'te yürürlüğe girmiş; m.9'un eski birinci fıkrası bir geçiş dönemi için 01.09.2024 tarihine kadar uygulanmaya devam etmiştir.
VIII. AB Yapay Zekâ Tüzüğü (AI Act) ve Türk Hukukuna Olası Etkileri
Avrupa Birliği'nin kabul ettiği Yapay Zekâ Tüzüğü, alandaki ilk kapsamlı yatay düzenlemedir ve risk temelli bir yaklaşım benimser: yasaklanan uygulamalar, yüksek riskli sistemler, sınırlı riskli (şeffaflık yükümlülüğü) ve asgari riskli sistemler. Tüzük ayrıca genel amaçlı yapay zekâ modelleri (GPAI) için ayrı yükümlülükler ve insan denetimi mekanizmaları öngörür. Yükümlülükler kademeli bir takvimle yürürlüğe girmekte; yasaklı uygulamalara ilişkin hükümler erken, yüksek riskli sistemlere ilişkin yükümlülükler ise daha geç bir tarihte uygulanmaya başlamaktadır.
Türkiye'nin AB uyum süreci ve KVKK'nın GDPR'a yaklaştırılma yönündeki 2024 reformu birlikte değerlendirildiğinde, yapay zekâya özgü benzer düzenlemelerin yakın gelecekte Türk hukukunda da gündeme gelmesi beklenmektedir.
IX. Sonuç ve Değerlendirme
Yapay zekâ teknolojileri veri işlemenin kapsamını ve etkisini köklü biçimde değiştirmiştir. 6698 sayılı Kanun'un mevcut hükümleri ve 2024 reformu önemli bir koruma sağlamakla birlikte, otomatik karar verme bakımından GDPR m.22 ölçüsünde açık bir hak tanımaması, yapay zekâya özgü bir düzenleme ihtiyacını ortaya koymaktadır. Önümüzdeki dönemde algoritmik şeffaflık, yapay zekâ denetimi, otomatik karar süreçlerinin sınırlandırılması ve veri minimizasyonu uygulamaları kişisel verilerin korunması hukukunun temel gündem maddeleri olacaktır.
Kurumlar açısından öneri nettir: yapay zekâ projeleri, tasarımdan itibaren hukuka uygunluk (privacy by design), doğru işleme şartının belirlenmesi, aydınlatma, veri minimizasyonu ve sınır ötesi aktarımda m.9'un yeni rejimine uyum ekseninde kurgulanmalıdır.
As the data processing capacity of AI systems grows, personal data protection law faces a new test. The 2024 amendments made to Law No. 6698 by Law No. 7499 bring this debate onto a contemporary footing.
Abstract
In recent years, artificial intelligence technologies have moved to the heart of both public- and private-sector operations; big data, machine learning, and generative AI systems have transformed the ways in which personal data are processed. This study assesses the data processing activities of AI systems within the framework of the Personal Data Protection Law No. 6698 and the amendments made to that Law by Law No. 7499 (Official Gazette 12.03.2024; effective 01.06.2024), examining the obligations of data controllers, automated decision-making processes, the new regime for cross-border transfers of personal data, and the potential effects of the EU Artificial Intelligence Act (AI Act).
Keywords: KVKK, artificial intelligence, AI Act, automated decision-making, data controller, cross-border transfer, Law No. 7499.
I. Introduction
Data is one of the fundamental factors of production in the digital economy. With the advance of AI technologies, the scope and intensity of data processing activities have increased significantly; AI models have come to require very large datasets in order to sustain their learning processes. This makes the processing of individuals' personal data all but inevitable.
The inability of legal regulation to develop at the same pace as technology creates serious risks for personal data protection. In Türkiye, the principal instrument in this field is Law No. 6698. The Law aims to protect individuals' fundamental rights and freedoms and imposes significant obligations on natural and legal persons who process data. The amendments made in 2024 by Law No. 7499, in turn, mark the first step toward harmonizing the Law with the European Union's General Data Protection Regulation (GDPR).
II. The Nature of Artificial Intelligence and Data Processing Activity
Under Article 3 of the KVKK, personal data is defined as "any information relating to an identified or identifiable natural person." Within this scope, full name, Turkish ID number, telephone, e-mail, location data, IP address, biometric data, and behavioral data all qualify as personal data.
Modern AI systems can analyze not only direct identity information but also an individual's behavioral patterns, preferences, and psychological tendencies. For example, an e-commerce platform can build a comprehensive digital profile by determining which products a user views, how long they stay on a given page, and at what times they shop. This entails a surveillance capacity that goes beyond conventional data processing.
III. Artificial Intelligence in Light of the Fundamental Principles of the KVKK
Article 4 of the KVKK sets out the general principles to be observed in data processing. Applying these principles in the context of AI poses particular challenges.
A. Compliance with the law and the rules of good faith
The data collection methods of AI systems are often not fully understood by users. When data is gathered by scraping from open sources on the internet, the failure to provide adequate information about the purposes for which the data will be used renders this principle contentious.
B. Specific, explicit, and legitimate purpose
Data processing must rest on explicit and specific purposes. Yet in AI systems, the data collected is frequently retained for indeterminate purposes that "may arise in the future," which can lead to a breach of the principle of purpose limitation.
C. Relevance, limitation, and proportionality (data minimization)
This principle requires that data processing remain limited to what is necessary for the purpose. Many AI systems, however, collect far more data than they need. Although proportionality and data minimization are intertwined under Article 4 of the KVKK, designing AI projects in accordance with this principle from the outset (privacy by design) is one of the most important compliance measures.
IV. The Problem of the Processing Condition and Lawful Basis
Most discussions of AI focus on the principles; in practice, however, the real issue is which processing condition is relied upon. Article 5 of the KVKK makes the processing of personal data conditional, as a rule, on explicit consent; where there is no explicit consent, one of the following grounds must exist: statutory authorization, performance of a contract, legal obligation, data made public, the establishment/exercise/protection of a right, and the legitimate interest of the data controller. For special categories of personal data, the conditions in Article 6 apply.
In training AI models, obtaining explicit consent individually from millions of people is often practically impossible. For this reason, the debate centers on whether the "legitimate interest" condition can be applied to AI training and, if so, on the balancing of interests against the rights and freedoms of the data subject (the balancing test). The obligation to inform (Article 10) and the rights of the data subject (Article 11), however, remain valid in all cases.
V. Automated Decision-Making Systems and the "Black Box" Problem
The most contentious aspect of artificial intelligence is its automated decision-making mechanisms. Today, processes such as credit assessment, recruitment, insurance risk analysis, and advertising targeting are largely conducted by algorithms. The core problem with these systems is their "black box" character: the data and criteria on which a decision rests often cannot be explained. Being unable to know which data was used in rejecting a credit application and how the decision was reached conflicts with the transparency element of the rule of law.
VI. The Legal and Administrative Liability of the Data Controller
Institutions that qualify as data controllers under the KVKK are subject to significant obligations:
VII. The New Regime for Cross-Border Transfers of Personal Data (Article 9)
Because the greater part of AI services operate through cloud infrastructures and cross-border data flows, the cross-border transfer regime is of critical importance for AI compliance. Law No. 7499 has introduced a tiered system, bringing Article 9 closer to the logic of the GDPR:
The amendment entered into force on 01.06.2024; the former first paragraph of Article 9 continued to apply, for a transitional period, until 01.09.2024.
VIII. The EU Artificial Intelligence Act (AI Act) and Its Potential Effects on Turkish Law
The Artificial Intelligence Act adopted by the European Union is the first comprehensive horizontal regulation in the field and adopts a risk-based approach: prohibited practices, high-risk systems, limited-risk systems (subject to transparency obligations), and minimal-risk systems. The Regulation also provides for separate obligations for general-purpose AI models (GPAI) and for human oversight mechanisms. The obligations enter into force on a staggered timetable; the provisions concerning prohibited practices apply earlier, while the obligations concerning high-risk systems begin to apply at a later date.
When Türkiye's EU accession process and the 2024 reform aimed at bringing the KVKK closer to the GDPR are considered together, similar AI-specific regulations are expected to come onto the agenda of Turkish law in the near future.
IX. Conclusion and Assessment
Artificial intelligence technologies have radically changed the scope and impact of data processing. While the existing provisions of Law No. 6698 and the 2024 reform provide significant protection, the fact that they do not confer an explicit right regarding automated decision-making to the extent of Article 22 of the GDPR reveals the need for AI-specific regulation. In the coming period, algorithmic transparency, AI oversight, the limitation of automated decision-making processes, and data minimization practices will be among the principal agenda items of personal data protection law.
For institutions, the recommendation is clear: AI projects should be designed around compliance from the outset (privacy by design), the determination of the correct processing condition, informing data subjects, data minimization, and, for cross-border transfers, alignment with the new regime under Article 9.
Bu yazı genel hukuki bilgilendirme amacı taşır; somut durumunuz bakımından avukatlık hizmeti yerine geçmez.
This article is for general legal information only and does not substitute for legal counsel on your specific situation.