A written acceptable-use policy is strongly advisable for any company whose staff use ChatGPT-like generative AI tools. Without one, employees can paste customer data, trade secrets and personal data into external tools whose terms may permit further processing, creating exposure under Türkiye’s Personal Data Protection Law (KVKK, Law 6698) and, for EU-facing data, the GDPR. A concise policy typically defines approved tools, prohibited data categories, human review of outputs, and a record of who may use what. Pairing it with short staff training is a practical and comparatively low-cost compliance step, and it lays the groundwork for the transparency and oversight duties the EU AI Act attaches to higher-risk uses. We can draft the policy and align it with your existing data-protection framework.
Shall we apply this matter to your situation?
Tell us your specific situation in a few sentences; we'll assess it with the right team.