{"id":2167,"date":"2026-03-05T09:27:17","date_gmt":"2026-03-05T09:27:17","guid":{"rendered":"https:\/\/fepartners.com.tr\/?p=2167"},"modified":"2026-03-05T09:29:43","modified_gmt":"2026-03-05T09:29:43","slug":"the-turkish-dpa-published-a-guideline-on-the-use-of-generative-ai-tools-in-the-workplace","status":"publish","type":"post","link":"https:\/\/fepartners.com.tr\/en\/the-turkish-dpa-published-a-guideline-on-the-use-of-generative-ai-tools-in-the-workplace\/","title":{"rendered":"The Turkish DPA Published a Guideline on the Use of Generative AI Tools in the Workplace"},"content":{"rendered":"<p><strong>Recent Development<\/strong><\/p>\n<p>On 5 March 2026, the Turkish Personal Data Protection Authority (the \u201c<strong>DPA<\/strong>\u201d) published its guideline titled \u201cUse of Generative Artificial Intelligence Tools in the Workplace\u201d (the \u201c<strong>Guideline<\/strong>\u201d). The Guideline addresses the key risks related to employees\u2019 use of third-party, publicly accessible generative artificial intelligence (\u201c<strong>GAI<\/strong>\u201d) tools in business processes, and aims to raise awareness among companies, institutions and organizations and to promote informed use.<\/p>\n<p>Although the Guideline is not binding, it constitutes an important reference source in terms of the DPA\u2019s expectations and assessment criteria in this field.<\/p>\n<p><strong>What Does the Guideline Cover?<\/strong><\/p>\n<p><strong><em>The Phenomenon of Shadow AI and Its Risks<\/em><\/strong><\/p>\n<p>The main focus of the Guideline is the phenomenon referred to as \u201cShadow AI\u201d, defined as employees\u2019 incorporation of GAI tools into business processes without the organization\u2019s knowledge, approval or corporate oversight. While associating this practice with the previously discussed concept of \u201cShadow IT\u201d, the Guideline underlines that GAI entails separate and additional risks due to its data processing capacity and its direct impact on decision-making mechanisms.<\/p>\n<p>In this framework, the risks highlighted in the Guideline are listed as follows: difficulties in ensuring accountability and auditability for GAI outputs that remain outside corporate oversight mechanisms; decision quality risks stemming from hallucinations and biased outputs; intellectual property risks arising from the sharing of source codes, business strategies and trade secrets with third-party tools; corporate reputational losses resulting from the use of content whose reliability has not been verified; cybersecurity threats occurring through unmanaged integrations; and the risk of unlawful processing of personal data and unauthorized access.<\/p>\n<p><strong><em>Emphasis under Law No. 6698<\/em><\/strong><\/p>\n<p>The Guideline expressly states that the Personal Data Protection Law No. 6698 (the \u201c<strong>Law<\/strong>\u201d) applies, irrespective of the technology used, in all cases where personal data is processed, and that data processing activities carried out through GAI systems also fall within this scope. In this respect, the DPA recommends that the Guideline be evaluated together with its previously published \u201cGenerative Artificial Intelligence and Personal Data Protection Guideline (in 15 Questions)\u201d.<\/p>\n<p><strong><em>Points to Be Considered<\/em><\/strong><\/p>\n<p>In the Guideline, it is recommended to adopt a corporate approach based on guidance, balance and awareness, rather than prohibitive approaches; accordingly, the following points are highlighted:<\/p>\n<ul>\n<li>Establishing a clear corporate policy or guidance framework that sets out which GAI tools may be used for which purposes and under which conditions, which types of information may be shared through such tools, and the principles governing risk management.<\/li>\n<li>Raising employees\u2019 awareness so that they do not share corporately sensitive information and personal data with GAI tools; and, during interactions with such tools, preferring anonymous and generalized expressions as much as possible.<\/li>\n<li>Considering the risk of \u201cautomation bias\u201d arising from excessive reliance on GAI outputs and assessing the generated outputs under human oversight as supporting elements, rather than using them as the sole basis for final decisions.<\/li>\n<li>Assessing data security and access control mechanisms\u2014where necessary including role-based restrictions\u2014based on the principle that employees should access only those tools designated by the organization and whose terms of use have been defined.<\/li>\n<li>Sharing policies regarding the use of GAI tools within the organization, ensuring that employees can easily access these documents, and maintaining regular information and training activities.<\/li>\n<\/ul>\n<p><strong>Conclusion<\/strong><\/p>\n<p>Although the Guideline does not impose binding obligations on data-processing organizations, it sets out the DPA\u2019s assessment approach and expectations in this area. Organizations where employees widely use third-party GAI tools in business processes are advised to review their existing corporate policies in line with this Guideline, establish a clear framework on data processing and information security covering the use of GAI, and effectively communicate this framework to employees.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Turkish DPA has published a guideline on the use of third-party generative AI tools in the workplace. The guideline summarizes Shadow AI risks and sets out recommendations on internal policies, employee awareness, and access controls.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[88],"tags":[777,793,799,784,794,790,788,779,774,795,776,785,791,796,768,783,775,780,786,789,772,668,766,771,778,797,798,787,770,417,792,765,773,781,782,769,767],"class_list":["post-2167","post","type-post","status-publish","format-standard","hentry","category-alert","tag-access-control","tag-ai-governance","tag-automation-bias","tag-biased-outputs","tag-compliance","tag-corporate-governance","tag-corporate-reputation-risk","tag-cybersecurity","tag-data-protection","tag-data-protection-guideline","tag-data-security","tag-decision-quality-risk","tag-employee-awareness","tag-generative-ai-and-personal-data-protection-guideline-15-questions","tag-generative-ai-tools","tag-hallucinations","tag-information-security","tag-integration-risks","tag-intellectual-property-risk","tag-internal-policy","tag-law-no-6698","tag-personal-data-processing","tag-personal-data-protection-authority","tag-publicly-accessible-ai-tools","tag-role-based-access","tag-shadow-ai","tag-shadow-it","tag-source-code-disclosure","tag-third-party-ai-tools","tag-trade-secrets","tag-training-and-awareness-programs","tag-turkish-dpa","tag-turkish-personal-data-protection-law","tag-unauthorized-access","tag-unlawful-processing-of-personal-data","tag-use-of-ai-in-the-workplace","tag-workplace-generative-ai"],"_links":{"self":[{"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/posts\/2167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/comments?post=2167"}],"version-history":[{"count":1,"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/posts\/2167\/revisions"}],"predecessor-version":[{"id":2168,"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/posts\/2167\/revisions\/2168"}],"wp:attachment":[{"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/media?parent=2167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/categories?post=2167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fepartners.com.tr\/en\/wp-json\/wp\/v2\/tags?post=2167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}