A-

A+

Evaluation of Camera-Based Artificial Intelligence Systems Under the KVKK (Personal Data Protection Law)

1. Introduction

The public announcements published by the Personal Data Protection Authority ("Authority") on June 8, 2026, regarding the use of security camera systems in workplaces and residential buildings, establish the legal boundaries of personal data processing activities carried out through camera systems.

According to the aforementioned announcements, it is observed that the Authority's approach requires the processing of personal data via cameras to be based on specific, explicit, and legitimate purposes; the processing activity to be relevant, limited, and proportionate to the purposes; the data subjects to be informed via privacy notices, the security of the records to be ensured, and the records to be retained only for the necessary period.

In this framework, camera-based artificial intelligence systems, whose areas of use have recently expanded significantly across different sectors and for various purposes, must also be evaluated separately. The legal compliance of AI-supported video analytics systems is determined by criteria such as the purpose for which the system is used, the areas it covers, the data it processes, its capacity to identify or profile individuals, the retention period of the records, access authorizations, and the level of transparency provided to the data subjects.

Therefore, the determining factor regarding camera-based artificial intelligence systems is not whether the technology is used, but whether this technology is designed, implemented, and managed in compliance with the principles of the right to privacy and the protection of personal data.

2. Fundamental Legal Risk in Camera-Based Artificial Intelligence Systems

Conventional camera systems are generally based on recording images and monitoring them when necessary. However, in most models, camera-based artificial intelligence systems not only record the images but also automatically analyze events, movements, density, zone violations, risky behaviors, or specific objects within the footage.

Consequently, it is evaluated that the fundamental legal risk in these systems is their transformation into a continuous and comprehensive surveillance tool, rather than remaining limited to security or occupational health and safety purposes.

For instance;

  • Continuous measurement of employees' individual productivity,
  • Creating behavioral profiles of individuals,
  • Performing facial recognition or biometric identification,
  • Recording audio,
  • Making intrusive inferences such as emotion, attention, or fatigue analysis,
  • Monitoring areas where individuals have a high expectation of privacy,

can render camera-based AI solutions severely risky from a legal perspective.

In contrast, configuring the system solely to detect specific risks—such as identifying entry into hazardous areas, lack of personal protective equipment, fall risks, unauthorized zone violations, capacity/density exceedance, safety anomalies like fire/smoke, or limited events related to common area security—is considered to create a more defensible legal ground.

3. The Distinction Between "Prohibited Surveillance" and "Video Analytics"

Regarding camera-based artificial intelligence technologies, the distinction between whether the system is a surveillance mechanism that "continuously monitors people" or a security/operational analytics tool that "detects specific risks on an event basis" is deemed highly important for the lawful use of the system.

For lawful use, it is also crucial that the system is designed with the following approach:

  • The system should focus on the event rather than the individual as much as possible. The objective should not be to continuously track the behavior of a specific person, but to detect predefined security risks, occupational health and safety violations, or events related to common area security.
  • The system should generate event-based alerts rather than relying on continuous human monitoring as much as possible. For example, instead of constant monitoring of camera feeds by human eyes, sending an alert to the authorized person only when a specific risk or violation occurs is evaluated as a more appropriate model in terms of data minimization.
  • The system should generate results without identification as much as possible. Functions such as facial recognition, biometric verification, or the automatic determination of individuals' identities should not be default features as a rule, as they may create the risk of processing special categories of personal data.
  • The system should analyze the necessary area rather than the entire image as much as possible. For this purpose, it is important to keep camera viewing angles narrow, mask unnecessary areas, perform zone-based analysis, and retain the images for the shortest possible duration.

4. Legal Basis: Explicit Consent is Not Always the Safest Path

It is evaluated that one of the common mistakes in practice regarding camera systems is the assumption that obtaining the explicit consent of data subjects will be sufficient for processing activities.

However, under the framework of the Personal Data Protection Law No. 6698 ("KVKK"), explicit consent is not the sole legal basis. Depending on the specific circumstances of the case, legal grounds such as the fulfillment of a legal obligation by the data controller, the establishment, exercise, or protection of a right, or the legitimate interest of the data controller—provided that this does not harm the fundamental rights and freedoms of the data subject—may apply.

Particularly in employment relationships, since whether explicit consent is based on free will can be highly controversial, establishing a model solely based on explicit consent for camera-based AI systems is not always deemed sound. Instead, a separate assessment of purpose, legal basis, necessity, and proportionality must be conducted for each use case scenario.

Furthermore, if the system includes functions that could lead to facial recognition, biometric identification, or the processing of special categories of personal data, the legal evaluation becomes much more sensitive. Since such functions differ from standard security camera usage and are significantly more intrusive, they should not be utilized without a clear and strong legal basis.

5. Privacy-Oriented Approach in Technical Design

Since compliance in camera-based AI systems cannot be achieved solely through legal documents, the technical architecture of the system must also be designed in accordance with data protection principles (Privacy by Design).

In this context, the following technical approaches are of critical importance:

  • Data minimization must be the fundamental principle of the system. The system should not process, store, or transfer to third parties any footage that is not necessary to achieve its purpose.
  • Image processing should be performed on a local device or within a closed-circuit customer environment as much as possible. Unnecessarily transferring images to the cloud may increase the risks of cross-border data transfer and unauthorized third-party access.
  • Analytical outputs that do not directly identify individuals should be preferred. For instance, an event output stating "entry into a hazardous area detected" is considered a more proportionate data processing model compared to a continuous behavior log enriched with a specific individual's identity information.
  • Features such as masking, blurring, zone restriction, defining motion areas, technically blocking areas to be excluded from recording, and automatic destruction/deletion should be provided as default in the system (Privacy by Default).
  • What data the system generates, stores, and transfers must be technically auditable. Black-box systems, whose operations cannot be explained or controlled, are evaluated to create significant compliance risks for data controllers.

6. Determination of Data Controller and Data Processor Roles

In camera-based AI systems, the service is often provided by a technology provider; while the system itself is used by employers, residential/estate management, factories, logistics centers, retail businesses, or facility managers.

At this point, correctly determining the roles of the parties under the KVKK is considered to be of critical importance.

The party that decides on the installation of the camera system, the purpose of its use, which areas will be monitored, how long the data will be retained, and who will have access to it will, in most cases, be the data controller. If the system provider merely operates the system in accordance with the customer's instructions, does not use the data for its own independent purposes, and does not determine the purposes of the processing itself, it is evaluated that the provider will possess the title of data processor.

In this scenario, the issue of using data specifically for model training purposes must be evaluated separately and independently. Under the KVKK, there is a significant distinction between processing camera footage obtained from the customer environment solely for providing the service, conducting security analyses, or operating the system, versus the technology provider using this footage to develop, improve, or retrain its own AI model, or to enhance overall product performance.

Indeed, the use of camera footage in the technology provider's own model development activities may go beyond executing the service on behalf of and under the instructions of the customer. If this use is structured as a default, automatic, or contractually pre-accepted practice, whether the technology provider is acting solely as a "data processor" may become highly debatable. Therefore, it is evaluated that it must be separately examined whether camera footages are used for model training purposes, and if so, on what legal basis this relies, whether the privacy notice provided to the data subjects clearly and comprehensibly covers this activity, whether the data is anonymized, whether the anonymization process is irreversible, and whether the customer exercises actual and legal control over this usage.

7. Conclusion

The Authority's camera announcements, rather than imposing a prohibition, provide a crucial compliance framework demonstrating the conditions under which camera systems can be used lawfully.

It is evaluated that camera-based artificial intelligence systems can be used in compliance with the KVKK provided they are utilized for specific, explicit, and legitimate purposes, respect the expectation of privacy, are designed proportionately, do not process unnecessary data, avoid heavily intrusive functions such as facial recognition and audio recording, retain records for short periods, restrict access, and transparently inform the data subjects.