KVKK and Pupil Data: An AI Guide for School Leaders

KVKK and Pupil Data: An AI Guide for School Leaders

A headteacher decides to trial a new AI tool. The teachers are pleased, the pupils are engaged, the results are positive. Then a parent emails: “Which company is storing my child’s data, and where? Is this even legal?”

That question now sits on every school leader’s desk. Purchasing or rolling out an AI tool without knowing the answer carries serious responsibility.

This article summarises pupil data and AI use under KVKK (Turkish data protection law) in three parts: which data counts as personal data, what obligations apply, and which questions a school leader should ask when choosing a tool.

When does pupil data count as personal data?

Law No. 6698 on the Protection of Personal Data (KVKK) defines personal data as “any information relating to an identified or identifiable natural person”. In an education setting, that definition covers a remarkably wide field:

  • Name, surname, national identity number

  • School number, class information

  • Marks, exam results, performance data

  • Homework, essays, audio recordings, photographs, video

  • Behaviour records, counselling notes

  • Family circumstances, health information (special category data)

Uploading a pupil’s essay to an AI tool for analysis counts as processing personal data, even if the name has been removed. The content, writing style or context of the text can still make the person identifiable.

The Ministry of National Education (MoNE) Ethical Guidelines for AI Applications in Education is clear on this point: when pupil data is processed by AI, the Ethical Declaration Form is mandatory, even if the data has been anonymised.

A school leader’s obligations under KVKK

When a school uses an AI tool, it takes on four core obligations:

1. Data minimisation. Only the minimum data necessary for the educational purpose may be collected. Hoarding extra data “in case it comes in handy” breaches KVKK.

2. Explicit consent and disclosure. Parents and pupils must be told clearly which data is collected and why, how long it will be kept and with whom it will be shared. Written explicit consent is required for data such as photographs, audio and video.

3. Where and how long data is stored. The school must know which servers, and which country, hold the data. The retention period must be defined in advance.

4. Limits on third-party sharing. Data must not be shared with third parties for model training or marketing. Where sharing is unavoidable, there must be clear safeguards and a legal basis.

Is the data stored within EU borders?

This is the most critical question a school leader should ask. Most widely used AI tools (ChatGPT, Gemini, Claude) process data on servers in the United States. Transferring data from Türkiye to the EU is possible under certain conditions within the GDPR framework, whereas transfers to the US are far more restricted.

Sending a pupil’s essay to a server in the US:

  • requires an assessment of compliance with KVKK’s cross-border data transfer provisions,

  • requires the parent’s explicit consent to that transfer,

  • requires clarity on which legal framework protects the data.

For data stored within EU borders, the picture is simpler: the GDPR framework applies, Türkiye-EU reciprocity is already defined, and the explicit consent process can follow a standard flow.

Madlen’s data governance

Madlen was built on infrastructure compliant with both KVKK and the GDPR. Two fundamental decisions underpin its data security:

The Infercom partnership. Madlen runs on infrastructure from Infercom, based in the European Union. All teacher and pupil data is stored on servers in Germany, within EU borders. No data is transferred to the US.

ISO 27001:2022 and certifications. The Infercom infrastructure is certified under the ISO 27001:2022 information security standard. Data encryption, access control and regular security audits are standard practice.

No third-party sharing. Data processed on Madlen is not used for model training and is not shared for advertising or marketing purposes. It remains the property of the data subject.

This architecture was designed to meet the protection standards required by the “Privacy, Confidentiality and Data Governance” principle of the MoNE Ethical Guidelines.

Questions a school leader should ask when choosing an AI tool

When evaluating a new EdTech tool, this checklist earns its keep:

  1. In which country is the data stored?

  2. Are there official documents demonstrating KVKK and GDPR compliance?

  3. Is there an ISO 27001 or similar security certification?

  4. Is the data used for model training?

  5. Is it shared with third parties? Under what conditions?

  6. How does a data deletion request work?

  7. Are the parent disclosure notice and explicit consent form ready?

  8. What is the notification process if a data breach occurs?

Using a tool that cannot give clear answers to all eight of these questions in a school setting is risky, both legally and ethically.

Sources:

  • Law No. 6698 on the Protection of Personal Data (2016).

  • Guidance documents of the Personal Data Protection Authority (KVKK).

  • General Data Protection Regulation (GDPR), EU 2016/679.

  • MoNE (2026). Ethical Guidelines for AI Applications in Education. Board of Education and Discipline, Ankara.

  • ISO/IEC 27001:2022 Information Security Management System Standard.