Data security and privacy training for AI use: no tool without a rule
Full day (about 7 hours) Up to 10 people On site in Istanbul or online 49.900 TL + VAT
Data security and privacy
What is this program?
Data security and privacy training for AI use is a full-day program in which companies' employees learn hands-on which data they may enter into AI tools under which conditions, the difference between corporate and personal accounts, the shadow AI risk, and responsibilities under Turkish data protection law (KVKK) and the EU AI Act, and leave at the end of the day with their own written AI usage policy. This program is practical training, not legal advice.
Most companies do not have a single written rule on AI use. Employees paste customer lists, contracts and financial statements into free personal accounts, nobody knows about it and because nobody asks, the problem is invisible. This is called shadow AI, and one day it becomes visible through a data leak, a customer complaint or an audit.
The program teaches setting rules instead of banning. Which data class may go into which tool under which conditions, what a corporate account provides, how anonymisation is done, where output is verified and who is responsible. The day ends with the writing of the company's own one-page AI usage policy.
Who is it for?
Compliance, data protection and legal officers
Those tasked with writing and implementing the company's AI policy.
IT and information security teams
Teams that manage tool access, accounts and data flows.
Management and HR
Those who will approve the policy and roll it out to all employees.
Program flow: six modules
Talking takes at most a fifth of the day. The rest is hands-on production on your own files, each module ending with a piece of real work.
Shadow AI: assessing the current situation
Who in the company uses which tool and how. A quick inventory method and a risk map. Visibility instead of a ban.
Data classification
Personal data, sensitive personal data, trade secrets, customer information, public information. An AI rule for each class.
Tool and account types
The data policies of free, personal paid, corporate and API accounts. Data not used for training, retention period, server location, data processing agreements.
KVKK and the EU AI Act
The controller and processor relationship, explicit consent, cross-border transfer, the duty to inform. The EU act's effect on Turkish companies. At an implementation level, not legal advice.
Anonymisation and safe working methods
How data is cleaned before it is given to a tool, working with sample rows, local tools, output verification and record keeping.
The company AI usage policy
Writing the one-page policy draft during the day: permitted tools, data rules, approval points, breach procedure, responsible people. An announcement text for employees.
Real work scenarios
The kind of tasks the day is built around. Yours replace these after the discovery call.
A customer list was pasted into ChatGPT
What happened, what the risk is, what to do, how to prevent it next time.
HR is having a candidate's CV summarised
Making it safe with the anonymisation method and the corporate account rule.
Finance uploaded a spreadsheet
The rule for the trade secret class and an alternative working method.
Tool selection
Comparing the data policies of three different tools and choosing the right one for the company.
Updating the privacy notice
How AI use is reflected in the privacy notice, together with the legal team.
The policy announcement
A clear and workable policy announcement that goes to all employees.
Tools used
Skills come before tools. The current model comparison with prices is on the AI models page.
What the team leaves with
- An inventory and risk map of current AI use in the company
- A written usage rule by data class
- A comparison table for tool and account selection
- Anonymisation and safe working methods
- A one-page company AI usage policy and announcement text
Format and what is included
- Discovery call: your industry, the team's daily work and the three targets of the day
- Content built on your own files, not a generic slide deck
- Full day (about 7 hours) hands-on, on site in Istanbul or online
- Team playbook with everything built during the day
- 30 days of Q&A support after the training
- Certificate of participation
Scopes beyond the standard package (more than 10 people, several locations, half-day or multi-day formats, integration work) are quoted separately.
The same standard package for every program.
How it works
15-minute call
We talk about the team, the work and whether this program fits. No commitment.
Discovery and preparation
A short session with the team lead. The day is built on your real tasks.
Training day
Everyone on their own laptop, on their own work, the whole day.
30 days of support
Questions that come up while actually using AI at work get answered.
Your trainer
Sefa Aydın
AI trainer and consultant. Years of producing design, advertising and software for the Türkiye projects of world-renowned luxury brands, founder of the agency Rebel Co. Group. I use these tools on real client work every day, and I teach what I use.
About me →Frequently asked questions
Does this training replace legal advice?
No. The program is practical training and contains no legal opinion. KVKK and EU regulations are covered at an implementation level, and working together with the company's legal team or lawyer is recommended. The policy draft should pass legal approval.
Is it not safer to ban AI use?
A ban makes use invisible, it does not stop it. Employees keep using it from their personal phones and the company loses control completely. The program teaches setting up visible, rule-based use instead of a ban.
How much does data security and privacy training cost?
The standard package is a full day for up to 10 people at 49,900 TL plus VAT. The discovery call, content preparation for the company, the policy draft and 30 days of Q&A support are included. Multiple companies or a group structure are scoped by proposal.
If we buy a corporate account, is the problem solved?
Most of it, but not all. A corporate account ensures data is not used for training, but which data is entered, how output is verified and the rules of responsibility still depend on the company's written policy. The program sets up both together.
Does the EU AI Act affect Turkish companies?
It affects Turkish companies that offer products or services to the EU market under certain conditions. The program covers which situations fall within scope at an implementation level. The August 2026 developments are summarised in the article on the EU AI Act.
What happens after the policy is written?
The policy is a living document. The program also provides a quarterly review routine and a method for updating it when a new tool appears. The literacy training complements it for rolling out to employees.
Teams choosing this program also look at
Guides on this topic
Last updated: 14 September 2026
Request a proposal for your team
Tell me the team size and what you want to solve. I reply the same day.