Skip to content

Practice Areas / Technology, Data & IP / xix. Technology, AI and Data Protection Law

Technology, AI and Data Protection Law

Technology law determines the legal framework of relationships established and data processed in the digital environment. As Günser + Partners, we provide legal advisory services in compliance work under the Personal Data Protection Law No. 6698, data breach management, offences committed via the internet, content removal and access-blocking applications, and software and technology contracts.

Topics Covered

The matters we handle within the framework of the Personal Data Protection Law No. 6698, the Law No. 5651 on the Regulation of Publications on the Internet and the cybercrime provisions of the Turkish Penal Code No. 5237:

  • Compliance work under the Turkish data protection law and the GDPR, data inventories and policy drafting
  • Privacy notices, explicit consent processes and cookie policies
  • Controller–processor agreements and data controllers' registry obligations
  • Transfers of personal data abroad and the legal mechanisms available for such transfers
  • Employee data, personnel files and workplace camera recordings
  • Health data, biometric data and special categories of personal data
  • Data breach notification, breach management and actions for annulment of Board decisions
  • Compensation claims arising from unlawful processing of personal data
  • Unauthorised access to information systems, unlawful acquisition of data and bank card offences
  • Offences of insult, threat and blackmail committed via the internet
  • Content removal, access blocking and right-to-be-forgotten applications
  • Compromised social media accounts and digital evidence procedures
  • Software development, maintenance, cloud computing and service level agreements
  • Liability, data use and transparency obligations in artificial intelligence applications
  • E-commerce, electronic signature and electronic contract disputes
  • Cybersecurity obligations and incident management following a cyberattack
  • Liability of digital platforms and platform–user relationships
  • Gaming and e-sports law; disputes over digital content and virtual items
  • Direct marketing, commercial electronic messages and related obligations
  • Liability in algorithmic decision-making and solely automated processing
  • Legal assessment of crypto assets and blockchain-based applications

Scope of Services

In our work in this field, the Law No. 6698 on the Protection of Personal Data is taken into account above all, together with the rules on internet publications, electronic commerce, electronic signatures, cybercrime, cybersecurity, consumer law and intellectual property. Legal risk in this area often arises from the gap between written policies and actual practice; for this reason, processes are assessed not only through contracts and policy texts but also through the business model, the technical infrastructure, user flows and actual data movements.

Within the scope of data protection compliance, human resources, sales, marketing, accounting, call centre, camera, mobile application, website, supplier management and IT processes are examined separately. The personal data processed, the legal basis for processing, retention periods, access authorisations, recipient groups and transfer channels abroad are identified, and for data controllers subject to registration, the consistency between the Data Controllers' Registry (VERBİS) notification and the actual processing activities is reviewed.

Privacy notices and explicit consent processes are prepared specifically for employees, job applicants, customers, visitors, cameras, cookies, mobile applications, campaigns and suppliers. The duty to inform and explicit consent are not the same act; explicit consent comes into consideration only where no other processing condition provided by law exists. Requests from data subjects for access, rectification or erasure are examined on a case-by-case basis so that they can be answered in time and on record.

In the processing of employee data, corporate e-mail, internet use, location, performance, entry and exit records, biometric data and camera recordings are assessed in terms of purpose, necessity, proportionality and prior notification. Where cloud, CRM, human resources, analytics or artificial intelligence services are used, whether personal data is transferred abroad and which legal mechanism the transfer relies on are determined, and supplier contracts are reviewed with respect to breach notification, sub-processors, audit rights, deletion and allocation of liability.

Software development, licence, SaaS, maintenance, hosting, API and digital platform contracts, corporate artificial intelligence use policies, the legal assessment of crypto asset and blockchain-based projects, commercial electronic messages, as well as content removal, access blocking, account takeover and cybercrime matters, also fall within our field of practice.

Frequently Encountered Matters

Among the matters most frequently encountered in practice are data protection compliance limited to a privacy notice on a website, explicit consent obtained unnecessarily or bundled into a single approval box, cloud services that transfer data abroad contrary to what company policy states, and camera systems installed for security but used for the continuous monitoring of employees.

Data breaches may arise from an e-mail sent to the wrong person, a lost device, a compromised user account, ransomware, a database left open to the internet or a former employee's continuing system access. Not every technical incident has the same legal consequence; however, concluding without investigation that no data has leaked is equally incorrect. Log records must be preserved, affected systems and data groups identified and the date on which the incident was discovered recorded.

In the use of artificial intelligence, the fact that a tool is purchased externally or run through a publicly available service does not remove the responsibility of the company using it. Systems used in recruitment, customer scoring, advertising, content generation or decision support are assessed together in terms of personal data, discrimination, consumer law, intellectual property, trade secrets and contractual liability.

In technology contracts, leaving acceptance testing, service levels, liability for outages, data loss, source code, intellectual property rights and post-termination data access unaddressed may lead to serious disputes. In account takeover, fake profile, unauthorised image, online fraud or commercial reputation matters, the priority is the preservation of evidence, since content may be deleted and platform records may become harder to obtain over time.

How the Process Works

The process begins with understanding how the incident or the system actually works before turning to the legal texts. The software used, data sources, suppliers, contracts, screenshots, access records, logs, correspondence relating to applications and the dates of the events are examined together.

The applicable legislation, critical time limits, available evidence and the responsibilities of the parties are then determined. In compliance projects, an applicable task plan is prepared covering the data inventory, privacy notices, retention and access rules, supplier contracts and transfer mechanisms, so that compliance is managed in practice rather than on paper.

In the event of a data breach or cyber incident, coordination is established with the technical team, the digital forensics specialist, the insurer and the communications unit. The preservation of evidence, the preparation of notification texts, informing the data subjects concerned and the recording of corrective measures taken after the incident are carried out in this framework.

In disputes, administrative applications, litigation, criminal complaints, content removal and access-blocking applications, notices, the determination of evidence and compensation claims are assessed separately, as each remedy is subject to different conditions and serves a different purpose. The client is regularly informed about the stages of the process, the possible risks and the legal remedies that may be pursued.

Legal Disclaimer

This content is for general information only; the facts of each case may differ. The explanations here do not constitute legal advice. Missing a deadline may result in loss of rights; please obtain professional legal assessment for your own matter.