Türkiye's data authority publishes a guide for lawyers, and generative AI is one of its listed headings
The Personal Data Protection Authority announced on September 22, 2026 that it has published its Guide on the Protection of Personal Data in the Professional Activities of Lawyers, prepared drawing on the opinions and contributions of the Union of Turkish Bar Associations. The headings listed in the announcement cover processing conditions, domestic and cross-border transfers, data security and the use of generative AI tools.
The regulator and the bar association produced a profession-specific guide together
In an announcement dated Tuesday, September 22, 2026, Türkiye's Personal Data Protection Authority said it had published the Guide on the Protection of Personal Data in the Professional Activities of Lawyers. The first sentence of the announcement states that the guide was prepared drawing on the opinions and contributions of the Union of Turkish Bar Associations, and the announcement also refers explicitly to the scope of Law No. 6698 on the Protection of Personal Data. The guide is available as a PDF from the announcement page on the Authority's website.
Turkish outlets picked the text up the same day: IGF Haber's report carries a September 22, 2026 timestamp of 15:02. The launch event for the guide was held the same day in the Authority's Conference Hall. That detail does not appear on the page announcing the publication of the guide; it comes from the Authority's separate page on the launch event, which we have added to the sources below.
The headings are known, what sits under them is not
According to the announcement, the guide addresses the status of lawyers, substitute lawyers appointed on their behalf, law office employees and data subjects under Law No. 6698, and it sets out the legal bases for the personal data processing that lawyers carry out. The listed headings are: the conditions for processing personal data, domestic and cross-border transfers, the use of generative AI tools, general principles, the obligations of the data controller and data security. The announcement also says the guide offers solutions to problems that arise in applying the law, along with examples of good practice.
An honest caveat belongs here: this article is based on the announcement, not on the full text of the guide. The page count, the chapter structure and the version number are not stated in the announcement. What sits under the generative AI heading is equally unknown: whether specific tools are named, whether entering client data into a cloud-based model is ruled out, and whether explicit consent or some other legal basis is required cannot be established from the announcement. Those questions can only be answered by reading the PDF, so we are not quoting provisions from inside the guide.
Balance rather than tension: the framing set at the launch event
According to the news report covering the launch event, the opening speeches were delivered by Authority President Prof. Dr. Faruk Bilir and Union of Turkish Bar Associations President Av. R. Erinç Sağkan. The same report says Sağkan described the relationship between data protection and the right to defense 'not as a tension but as a balance', and said data protection rules are used as a pretext, particularly by public administrations. This account comes from the news report we have added to the sources below, not from the Authority's own announcement.
What matters most, though, is what has not been announced. The binding force of the guide is unclear: the announcement does not say whether it can lead to administrative sanctions or whether it is advisory in nature. No compliance timetable, transition period or deadline has been given to lawyers, and no administrative fine amounts or new sanction regime for non-compliance have been set out.
An entirely domestic instrument, but its signal is not limited to law firms
This story is specific to Türkiye from start to finish. The publisher is the country's data protection authority, the legal basis is Law No. 6698, and the audience is lawyers, substitute lawyers, law office employees and data subjects. The sources contain no international comparison, no reference to European Union law and no foreign implementation example; cross-border transfer appears only as one heading within the Law No. 6698 regime. We looked at how the Authority shapes day-to-day data protection practice in our September 16, 2026 article on KVKK data breach notifications.
For businesses outside the legal profession, the signal is this: in a guide the regulator prepared for one occupation, the use of generative AI tools appears as a separate heading. For accounting, consulting, healthcare and agency firms that work with client data, that makes the document worth reading. This is an inference, however, and the announcement does not state whether the guide binds data controllers other than lawyers, such as companies outside law firms or in-house legal departments. Whether an English version exists, or a section addressed to international firms, is also unknown.
The UNALSOFT view
Our reading is that generative AI is becoming a standing heading in regulatory texts, which turns the question from "should we use it" into "with which data, on which legal basis, and on a model running where". In our Agentic AI work, the flows we build define from the outset which data reaches a model, where it is stored and who can access it; this guide shows a regulator asking the same questions of one profession. For businesses in Türkiye that handle client data, the practical step is not banning tools but writing the data flow down. Until the full text of the guide is read, no one can say which concrete obligations it creates, and this article does not fill that gap.
Ready to put your team's AI use on a written data flow?
Let's map together which data goes to which tool, where it is stored and who can reach it. A short conversation is enough to start.