AI-built projects

Legal review for projects built with AI

Project-specific legal texts, KVKK (Turkish data protection law) compliance and a lawyer's pre-launch review for websites and mobile apps built with AI tools.

Hands working on a laptop at night

12 questions before launch

12 questions under four topics. Answer each for your project; the panel on the right shows the risk level and priority gaps instantly. It takes about three minutes. The check is based on Turkish law.

Data and transparency

01

Is there a list showing which personal data the project collects, on which screen and for what purpose?

Why it matters, what to do

The privacy notice, retention periods and transfers all rely on this list. Without it, texts are written by guesswork. If health, biometric or children's data is involved, the requirements are much stricter.

What to do: Review all forms, database tables, file uploads and chat fields to build a data inventory; flag special category data separately.

KVKK Arts. 4, 6, 10 · VERBİS Regulation

02

Does the privacy notice name the actual individual or company acting as data controller, with a full address?

Why it matters, what to do

A privacy notice must state the identity of the data controller. Templates often refer to a non-existent “our company”.

What to do: Add the name or trade name, address and contact channel of the individual or company operating the project.

KVKK Art. 10/1-a · Communiqué on the Duty to Inform

03

Are all third-party services used (hosting, database, email, payment, analytics, AI API) listed in the text?

Why it matters, what to do

Who personal data is transferred to is a mandatory element of the privacy notice. In AI-built projects most providers are never mentioned.

What to do: Add every service provider with the purpose of the transfer; keep the data processing agreements (DPAs) on file.

KVKK Arts. 8, 10/1-c

04

Is explicit consent for processing that requires it (marketing, profiling, special category data) collected separately and optionally?

Why it matters, what to do

Explicit consent must be specific and freely given. Making membership conditional on consent, or collecting consent for everything in one box, may not be valid.

What to do: Separate the notice from consent; collect marketing and commercial message permissions with separate, unticked boxes and register with İYS.

KVKK Arts. 3, 5, 6 · Law No. 6563 · İYS

05

Is it written down how long each type of data is kept and how it is deleted when that period ends?

Why it matters, what to do

Data must be deleted once its purpose ends, yet some records such as commercial books (10 years) and traffic logs (1-2 years) must legally be kept. “Everything is deleted when you delete your account” is often untrue.

What to do: Prepare a retention schedule by data type; build the account deletion flow and backups according to it.

Regulation on Erasure, Destruction or Anonymisation · Turkish Commercial Code Art. 82 · Law No. 5651

Transfers and security

06

Has a legal basis been established for transferring data abroad and, where required, has a standard contract been signed and notified to the Authority?Critical

Why it matters, what to do

Sending personal data to a server, database or AI API abroad is a cross-border transfer. The standard contract must be notified to the Authority within 5 business days of signing.

What to do: Identify where providers' servers are, choose the appropriate safeguard, sign and notify the standard contract in time and reflect it in the text.

KVKK Art. 9 (as amended by Law No. 7499) · Cross-Border Transfer Regulation

07

Does the cookie banner offer a “Reject” option, and are analytics/advertising tools prevented from loading before consent?

Why it matters, what to do

Non-essential cookies require active consent. “By using the site you accept cookies” and tracking code loaded in advance are contrary to the guidelines.

What to do: Make Reject as visible as Accept; load analytics and advertising scripts only after consent.

KVKK Guidelines on Cookie Practices

08

Are API keys kept out of the browser, and are database access rules enabled and tested?Critical

Why it matters, what to do

AI-written code often contains secret keys embedded in the client, disabled access rules and public storage. The data controller must take appropriate technical measures.

What to do: Move secret keys server-side and rotate them; enable row-level security (RLS) and storage access rules and test them with another user account.

KVKK Art. 12

09

Is it clear who does what in a data breach and how the Board is notified within 72 hours?

Why it matters, what to do

A data breach must be notified to the Board within 72 hours at the latest and to data subjects within a reasonable time. Without a plan, the deadline is often missed.

What to do: Write a short breach response procedure: responsible person, logging, assessment, draft notifications to the Board and individuals.

KVKK Art. 12/5 · Board decision No. 2019/10

Contracts and consumers

10

Were the terms of use written in line with Turkish law and consumer legislation?

Why it matters, what to do

Clauses like “we are not liable under any circumstances”, “US courts have jurisdiction” or “we may change these terms without notice” are largely invalid against users in Türkiye.

What to do: Rewrite the terms for the users you serve; bring liability, jurisdiction and amendment clauses in line with the law.

Turkish Code of Obligations Arts. 20-25, 115 · Consumer Protection Law No. 6502 Arts. 5, 73

11

If products, services or subscriptions are sold, have pre-contractual information, the right of withdrawal and the cancellation flow been set up?

Why it matters, what to do

Distance sales require a pre-contractual information form and agreement; for digital content, separate consent is needed to apply the withdrawal exception. Subscription renewal and cancellation must be clear.

What to do: Add the pre-contractual information form and distance sales agreement to checkout, build the withdrawal and cancellation flow, and register with ETBİS if required.

Distance Contracts Regulation · Consumer Protection Law No. 6502 · ETBİS

Ownership

12

Is there a written agreement and IP assignment with whoever wrote the code, and has a trademark search been done?

Why it matters, what to do

Economic rights must be assigned in writing with each right specified. Otherwise it may turn out during an investment or sale that the source code or trademark does not belong to you.

What to do: Sign a written agreement and IP assignment with the developer, check open-source licences, search and file your trademark with TÜRKPATENT.

Law No. 5846 Arts. 18, 52 · Industrial Property Law No. 6769

0/12 answeredResult ↓
Ask a question