Legal notice: This article is general information, not legal advice. Consult a lawyer or KVKK specialist for your specific case. Information reflects legislation in force as of July 2026.
Why is a business running a chatbot the "data controller"?
Under KVKK Article 3, a business that collects customer messages through an AI chatbot is the "data controller" because it determines the purpose and means of processing. The software vendor providing the chatbot is usually a "data processor." This distinction is decisive: fines and obligations fall on the business that signed the contract, not on the software. For international readers, KVKK mirrors GDPR's controller/processor logic, so this will feel familiar.
- Data controller: The business using the chatbot (SME, agency, e-commerce store). Disclosure, consent, and security are its responsibility.
- Data processor: The chatbot platform, processing on the controller's instructions; a data processing agreement must exist between them.
- Why it matters: Assuming "the vendor handles compliance" is wrong; the Board fines the business directly.
How is the disclosure obligation met inside a chatbot?
The disclosure obligation (KVKK Article 10) is met by telling the customer, before the conversation starts, who you are, why you process their data, and where you transfer it. In a chatbot this is delivered as a short notice in the first message plus a link to the full privacy notice. Disclosure is mandatory for every processing activity and is independent of consent.
Practical implementation
- First-contact message: An automatic opener such as "Your messages are processed by [Company] to answer your request. Details: [Privacy Notice link]."
- AI use must be stated: Board guidance stresses transparency in automated/AI-assisted processing; the customer should not be misled into thinking they are talking to a human.
- Disclosure is not consent: The KVKK Board considers merging disclosure and consent into a single checkbox ("I have read and I accept") improper; they must be presented separately.
When is explicit consent required? (Article 9 cross-border transfer)
Explicit consent is required only when no other legal basis in the law justifies the processing. Processing a customer's message to "answer their request" usually falls under the performance of a contract and needs no separate consent. However, if the data is processed by an AI model hosted abroad (such as OpenAI, Google, or Meta servers), the cross-border transfer requires an appropriate safeguard or explicit consent.
- Consent not needed: Answering a question the customer initiated (Article 5/2 – contract/legitimate interest). Data processed within Turkey needs no extra consent.
- Consent/safeguard needed: If the message content is sent to an AI model abroad, Article 9 requires an appropriate safeguard (standard contract) or explicit consent.
- Marketing permission: Reusing chatbot data for campaigns or ads later requires a separate, explicit consent (Turkey's Message Management System, İYS, plus KVKK Article 9).
What is the post-2024 standard-contract regime for cross-border transfers?
A regulation effective 10 July 2024 (Official Gazette No. 32598) moved Turkey to a GDPR-like transfer regime. Cross-border transfer is now possible via an adequacy decision, appropriate safeguards (standard contract, binding corporate rules, undertaking), or exceptions. If your AI chatbot data is processed on foreign servers, this regime applies to you directly.
Rules of the standard contract
- Cannot be altered: The Board-issued standard contract must be signed as-is, without modification.
- 5-business-day notification: You must notify the Board within 5 business days of signing; failing to notify is a separate administrative fine.
- Undertaking route: If the standard contract does not fit, the parties' own undertaking is submitted for the Board's approval.
Data retention and deletion: message content and "delete my data" requests
KVKK requires deleting, destroying, or anonymizing personal data once the purpose of processing ends (Article 7). Chatbot messages cannot be kept indefinitely; you must define a retention and destruction policy. Additionally, if a customer says "delete my data" under Article 11, you must respond and act within 30 days at the latest.
- Defined retention period: Set a reasonable period for each data category and record it in your policy; "I keep it forever" is unlawful.
- Deletion request (Article 11): A customer can say "delete my data" even inside the chatbot; this is a formal request and starts the 30-day response clock.
- Anonymization: Records that must be kept for 10 years under tax law (invoices) cannot be deleted; compliance is achieved by masking/anonymizing personal fields instead.
2026 penalty risk: how large are KVKK administrative fines?
For 2026, a revaluation rate of 25.49% was applied and KVKK administrative fines were updated. Failing to meet the disclosure obligation starts at 85,437 TL; for data-security breaches the ceiling exceeds 17 million TL. In automated systems like chatbots, gaps in transparency and security fall squarely under these sanctions.
| Violation type (2026) | Lower limit | Upper limit |
|---|---|---|
| Failure to meet the disclosure obligation | 85,437 TL | 1,709,200 TL |
| Failure to meet data-security obligations | 256,357 TL | 17,092,242 TL |
| Failure to comply with Board decisions | 427,263 TL | 17,092,242 TL |
| Breach of standard-contract notification duty | 90,308 TL | 1,806,177 TL |
Source: KVKK 2026 updated administrative fine amounts (in force for violations committed from 1 January 2026 and updated each year by the revaluation rate; USD equivalents vary with the exchange rate). Board decisions increasingly look at how the practice actually works, not merely whether a policy exists on paper.
Why does this matter at scale? The after-hours reality
KVKK compliance is not an abstract burden; the chatbot is already essential to the business. According to DoWaba platform data (January–June 2026), 57.6% of incoming WhatsApp messages arrive outside business hours (weekdays 09:00–18:00), and for Instagram DMs that figure rises to 65.8%. In other words, humans cannot keep up with most customers. Over six months, more than 26,700 incoming messages and 2,700+ voice calls were handled; the AI bot's median first-response time was 23 seconds, 67.5% of messages were answered within 60 seconds, and 75.5% within 2 minutes. In a channel with this much data flowing, KVKK compliance must be built in from the start, not bolted on later.
DoWaba's approach: designing for KVKK from day one
DoWaba, built specifically for the Turkish market, treats KVKK compliance as core architecture rather than an add-on. This differs from some foreign tools that process data abroad and wrap compliance around it afterward. To be honest: because AI models (such as Gemini) run abroad, message content is transferred internationally; so DoWaba does not hide the cross-border transfer but manages it through consent and disclosure gates.
- 90-day message retention: Message content is automatically deleted/anonymized after 90 days by default; no indefinite storage.
- Personal-data masking: A module to mask sensitive fields in content sent to the AI, supporting the data-minimization principle.
- "Delete my data" automation: When a customer sends a deletion request through the chatbot, it is treated as an Article 11 request and the deletion is automated.
- Automated disclosure notice: A disclosure notice and link can be added to the first-contact message, configured per channel.
- Turkey focus: Local requirements such as anonymizing (not deleting) invoice records (10-year tax retention), İYS integration, and 11 Turkish e-commerce integrations are considered from the start.
If you want to manage every channel — including WhatsApp, Instagram, and an AI voice call center — within a KVKK framework in a single panel, you can get started now, while agencies wanting to offer their clients a KVKK-compliant solution can explore the solution-partner program.
How do DoWaba and foreign chatbot platforms compare on KVKK?
As of July 2026, popular foreign chatbot tools offer strong automation but are not KVKK-specific; the business itself must close the Turkey-context gaps. The table below uses only verified information.
| Feature | Manychat | DoWaba |
|---|---|---|
| Starting price | From $14/mo (March 2026 new pricing; AI add-on charged separately) | TL-based plans (dowaba.com) |
| Compliance framework | GDPR + Data Privacy Framework; no KVKK-specific module stated | KVKK-focused (retention, masking, deletion automation) |
| Data processing location | US/EU servers (cross-border transfer is the business's responsibility) | Turkey-focused; AI transfer managed via consent/disclosure |
| Turkish / automatic language | No built-in automatic language detection; flows duplicated manually | Turkish interface + multilingual AI replies |
| Turkish e-commerce integrations | Not stated (not verified) | 11 Turkish platform integrations |
To be fair, Manychat is a mature, widely adopted product for flow-building and scale. But burdens such as the cross-border transfer safeguard KVKK requires, Turkish-language disclosure, and a local destruction policy must be carried by the business itself.
Frequently asked questions
Do I need to register with VERBİS if I use a chatbot?
If you process personal data with a chatbot, the VERBİS registration duty depends on thresholds such as your headcount and annual balance sheet. If you exceed those thresholds, registration is mandatory; small businesses may qualify for exemptions. Consult a KVKK specialist for a definitive assessment.
What should I do if a customer types "delete my data" to the chatbot?
Treat it as a request under KVKK Article 11, respond within 30 days at the latest, and delete the data unless a retention obligation (such as invoices) applies. In DoWaba this request can be processed automatically, reducing the risk of missed manual follow-up.
If the AI model is abroad, am I automatically violating KVKK?
No, the violation is not automatic. Cross-border transfer can be lawful with an appropriate safeguard (the 2024 standard-contract regime) or explicit consent. What matters is not hiding it, stating it in your privacy notice, and providing the required safeguard.
Must I show the privacy notice in every message?
Not in every message; informing the person once at first contact and providing an accessible link to the full privacy notice is enough. What matters is that the person is informed at the moment processing begins.