Protecting Personal Data While Using AI: A Practical Guide for Small Businesses

Your team is probably already using AI tools. Drafting a proposal, summarising a spreadsheet, writing a reply to a customer e-mail. All legitimate work. The problem is that the text pasted into that box often contains a customer's name, phone number, or an entire contract.
The subject has become more concrete lately. Türkiye's Personal Data Protection Authority published a guide on generative AI and the protection of personal data in November 2025, followed by a document on agentic AI in July 2026. In other words, the regulator is now looking directly at the lifecycle of these tools, where they are used and what risks they create.
This article is for information only and is not legal advice. For the full scope of your obligations, rely on the current guides and decisions published on kvkk.gov.tr, and consult your own legal adviser for your specific situation.
Where the problem starts
This is unlike a classic IT risk. Nobody is breaking into your systems; we take the data out ourselves, and we do it in order to work better.
The typical scene: a salesperson wants to improve an e-mail to a customer and pastes the whole prior thread — name, phone number, order detail, price — into an AI chat. The result is an excellent draft. But that data now sits somewhere the company does not control.
The critical distinction: is the tool a free public version, or is it used under a business agreement? The difference between the two is where the data is stored, how long it is kept, and whether it is used for model training. Without knowing that, you cannot declare any tool "safe".
What counts as personal data?
A quick reminder: personal data is any information relating to an identified or identifiable natural person. Not just a name — phone numbers, addresses, e-mail, national ID numbers, order history, IP addresses, even fragments that mean nothing alone but point to a person when combined.
The three sets most often overlooked inside a company:
- Customer records. Order lists, contact details, complaint texts, call notes.
- Employee data. HR files, payroll, performance notes, health reports.
- Documents. Contracts, quotes, invoices, formal notices. These carry both personal data and trade secrets.
We covered the basic framework in our data privacy compliance guide for SMEs; AI does not remove that responsibility, it merely adds a new channel.

Six rules you can actually apply
These are not legal texts but business practice. Even a small team can put them in place within a week.
1. Keep a list of approved tools. Write down which tools may be used for work, and state who has to approve adding a new one. The list can be short; the point is to remove ambiguity. Banning everything does not work, because a ban does not end usage — it only makes it invisible.
2. Mask the data before you paste it. Most tasks do not need real data. "An overdue invoice for a customer" produces the same draft as naming the customer and the amount. When summarising a table, drop the name column and work with customer numbers instead. This single habit cuts most of the risk at source.
3. Consider a closed setup for sensitive work. If you will regularly work with sensitive sets such as health, HR or contract data, an arrangement that keeps the data inside your own infrastructure — or tightly bound by contract — is the better choice. For the infrastructure trade-offs behind that decision, cloud vs on-premise is a good starting point.
4. Keep a human in automated decisions. Outcomes that directly affect a person — rejecting a request, setting a price, screening a job application — should not be produced fully automatically. AI prepares the recommendation, a human makes the decision, and that is recorded.
5. Know your vendor and your transfers. Where is the data processed, how long is it kept, is it used for training? If data is transferred abroad, that has its own rules. Saying "we bought the business plan" is not a substitute for reading the agreement.
6. Write it down. Keep a one-page table of which process uses which tool with which data. When a question comes, your answer is that table rather than your memory. It is the same inventory logic we described in data security and backup.
What changes with agentic AI
Everything above assumed tools that work as "ask a question, get an answer". Agentic AI systems are different: they can carry out multi-step processes toward a goal, evaluate conditions, adapt to changing situations and initiate actions with varying degrees of autonomy. The authority's July 2026 document points precisely at this — that growing autonomy and data processing capacity open new areas of evaluation for data protection.
In business terms: you used to give AI a text and get a text back. Now you give it a task, and while performing it the system looks into your records, creates entries and sends e-mails. We described what that capability is good for in what are AI agents; on the data side, three things change:
- Scope widens. Once an agent is connected, it can reach everything that connection exposes. Starting with the narrowest permission — one table, read-only — is the only real protection.
- Tracing gets harder. In a multi-step task, reconstructing which data went where at which step is nearly impossible without logs. Turn on a record of the agent's actions from day one.
- Outward steps carry the risk. Keep a human approval step on hard-to-reverse actions such as sending an e-mail, updating a record or starting a payment. And if an automated system talks to customers, do not hide it — as we noted in AI in customer service, transparency builds trust rather than eroding it.
A one-week checklist
- Has anyone listed the AI tools the team actually uses?
- Which of those run under a business agreement, and which on personal accounts?
- Is there a written "never enter this" data list, and has everyone read it?
- Has the habit of working with masked or sample data taken hold in routine tasks?
- Is there still a human approval step in decisions that directly affect people?
- If an agent or automation is in place, is its data scope as narrow as possible and are its actions logged?
Filling this in as a team achieves more than a long training session. To strengthen the culture side, you can lift the usage-policy outline straight from our AI literacy guide.
Protecting data is not the same as not using AI
The two most common mistakes here are opposites: banning everything, and setting no rules at all. Both end in the same place — loss of control.
The right path sits between them: write down which work is done with which tool and which data, and keep it simple enough for the team to follow. A masking habit, a human approval step and a one-page tool inventory close most of the risk for most small businesses.
If you would like to design a setup that strips out sensitive data, narrows permissions and logs what happened as you open your processes to AI, get in touch; you can also look through our services to see how we work.
Frequently Asked Questions
- What data should never be entered into an AI tool?
- Customer and employee personal data (names, national ID numbers, phone numbers, addresses, e-mail), health and HR records, signed contracts, banking and payment details, and unpublished financial information should not be pasted into public AI tools. In most cases the same task can be done with masked or sample data instead.
- What has Türkiye's data protection authority published about AI?
- The Personal Data Protection Authority published a guide on generative AI and the protection of personal data in November 2025, and a document on agentic AI in July 2026. Both are available on kvkk.gov.tr; for your own situation, consult your legal adviser.
- Why does agentic AI need a human sign-off?
- Agentic AI systems do not just produce an answer; they run multi-step tasks on their own, make decisions based on conditions and initiate actions. As autonomy grows it gets harder to track which data went where. So keep a human approval step on every outward action — sending an e-mail, updating a record, starting a payment — and give the agent the narrowest data scope that still works.
Need help with this topic?
Contact Us