Selen IBRAHIMOGLU GURES Attorney at Law / Managing Partner
Omer KUCUKORDU Associate
[email protected]
06 October 2026
A-
A+
1. Introduction
The public announcements published by the Personal Data Protection Authority ("Authority") on June 8, 2026, regarding the use of security camera systems in workplaces and residential buildings, establish the legal boundaries of personal data processing activities carried out through camera systems.
According to the aforementioned announcements, it is observed that the Authority's approach requires the processing of personal data via cameras to be based on specific, explicit, and legitimate purposes; the processing activity to be relevant, limited, and proportionate to the purposes; the data subjects to be informed via privacy notices, the security of the records to be ensured, and the records to be retained only for the necessary period.
In this framework, camera-based artificial intelligence systems, whose areas of use have recently expanded significantly across different sectors and for various purposes, must also be evaluated separately. The legal compliance of AI-supported video analytics systems is determined by criteria such as the purpose for which the system is used, the areas it covers, the data it processes, its capacity to identify or profile individuals, the retention period of the records, access authorizations, and the level of transparency provided to the data subjects.
Therefore, the determining factor regarding camera-based artificial intelligence systems is not whether the technology is used, but whether this technology is designed, implemented, and managed in compliance with the principles of the right to privacy and the protection of personal data.
2. Fundamental Legal Risk in Camera-Based Artificial Intelligence Systems
Conventional camera systems are generally based on recording images and monitoring them when necessary. However, in most models, camera-based artificial intelligence systems not only record the images but also automatically analyze events, movements, density, zone violations, risky behaviors, or specific objects within the footage.
Consequently, it is evaluated that the fundamental legal risk in these systems is their transformation into a continuous and comprehensive surveillance tool, rather than remaining limited to security or occupational health and safety purposes.
For instance;
can render camera-based AI solutions severely risky from a legal perspective.
In contrast, configuring the system solely to detect specific risks—such as identifying entry into hazardous areas, lack of personal protective equipment, fall risks, unauthorized zone violations, capacity/density exceedance, safety anomalies like fire/smoke, or limited events related to common area security—is considered to create a more defensible legal ground.
3. The Distinction Between "Prohibited Surveillance" and "Video Analytics"
Regarding camera-based artificial intelligence technologies, the distinction between whether the system is a surveillance mechanism that "continuously monitors people" or a security/operational analytics tool that "detects specific risks on an event basis" is deemed highly important for the lawful use of the system.
For lawful use, it is also crucial that the system is designed with the following approach:
4. Legal Basis: Explicit Consent is Not Always the Safest Path
It is evaluated that one of the common mistakes in practice regarding camera systems is the assumption that obtaining the explicit consent of data subjects will be sufficient for processing activities.
However, under the framework of the Personal Data Protection Law No. 6698 ("KVKK"), explicit consent is not the sole legal basis. Depending on the specific circumstances of the case, legal grounds such as the fulfillment of a legal obligation by the data controller, the establishment, exercise, or protection of a right, or the legitimate interest of the data controller—provided that this does not harm the fundamental rights and freedoms of the data subject—may apply.
Particularly in employment relationships, since whether explicit consent is based on free will can be highly controversial, establishing a model solely based on explicit consent for camera-based AI systems is not always deemed sound. Instead, a separate assessment of purpose, legal basis, necessity, and proportionality must be conducted for each use case scenario.
Furthermore, if the system includes functions that could lead to facial recognition, biometric identification, or the processing of special categories of personal data, the legal evaluation becomes much more sensitive. Since such functions differ from standard security camera usage and are significantly more intrusive, they should not be utilized without a clear and strong legal basis.
5. Privacy-Oriented Approach in Technical Design
Since compliance in camera-based AI systems cannot be achieved solely through legal documents, the technical architecture of the system must also be designed in accordance with data protection principles (Privacy by Design).
In this context, the following technical approaches are of critical importance:
6. Determination of Data Controller and Data Processor Roles
In camera-based AI systems, the service is often provided by a technology provider; while the system itself is used by employers, residential/estate management, factories, logistics centers, retail businesses, or facility managers.
At this point, correctly determining the roles of the parties under the KVKK is considered to be of critical importance.
The party that decides on the installation of the camera system, the purpose of its use, which areas will be monitored, how long the data will be retained, and who will have access to it will, in most cases, be the data controller. If the system provider merely operates the system in accordance with the customer's instructions, does not use the data for its own independent purposes, and does not determine the purposes of the processing itself, it is evaluated that the provider will possess the title of data processor.
In this scenario, the issue of using data specifically for model training purposes must be evaluated separately and independently. Under the KVKK, there is a significant distinction between processing camera footage obtained from the customer environment solely for providing the service, conducting security analyses, or operating the system, versus the technology provider using this footage to develop, improve, or retrain its own AI model, or to enhance overall product performance.
Indeed, the use of camera footage in the technology provider's own model development activities may go beyond executing the service on behalf of and under the instructions of the customer. If this use is structured as a default, automatic, or contractually pre-accepted practice, whether the technology provider is acting solely as a "data processor" may become highly debatable. Therefore, it is evaluated that it must be separately examined whether camera footages are used for model training purposes, and if so, on what legal basis this relies, whether the privacy notice provided to the data subjects clearly and comprehensibly covers this activity, whether the data is anonymized, whether the anonymization process is irreversible, and whether the customer exercises actual and legal control over this usage.
7. Conclusion
The Authority's camera announcements, rather than imposing a prohibition, provide a crucial compliance framework demonstrating the conditions under which camera systems can be used lawfully.
It is evaluated that camera-based artificial intelligence systems can be used in compliance with the KVKK provided they are utilized for specific, explicit, and legitimate purposes, respect the expectation of privacy, are designed proportionately, do not process unnecessary data, avoid heavily intrusive functions such as facial recognition and audio recording, retain records for short periods, restrict access, and transparently inform the data subjects.
Publications