SONUÇ AI
Pilotu incele
Tüm yazılar

Mevzuat / Regulation · 14.09.2026 · 8 dk / 8 min

Turkish data law, AI and international transfers: why server location is not enough

Hosting in Türkiye does not eliminate a transfer when data is sent to a foreign model API. The actual flow, party roles and transfer mechanism must be assessed together.

Map the real data flow first

A document may remain on a Turkish server while all or part of its content is sent to a model provider abroad. Logs, backups, support access and subprocessors may also become part of the transfer chain.

The assessment therefore goes beyond storage location. It must identify purpose, recipient, country, retention period and subprocessors.

Roles and legal mechanism

Controller and processor roles follow actual purpose and authority, not merely the label used in a contract. The appropriate mechanism under Article 9 of the Turkish Personal Data Protection Law must be selected for the real flow.

Where standard contractual clauses are used, the correct party module, annexes and signatures matter. The Authority’s guide states that the standard contract must be notified within five business days after signature.

Implementation checklist

A general NDA does not legalise every processing operation. Legal and technical design should work from the same data inventory.

  • Data categories, data-subject groups and purpose
  • Provider, region, subprocessors and retention
  • Masking, minimisation and access logs
  • Transfer mechanism, notification and change control
  • Return, verified deletion and access revocation on exit

Scope note

This article is general information and is not a legal opinion for any specific data set, sector or transfer arrangement.