Is Your Data Sitting in a Closed Safe?
Businesses keep their data in a safe. Like gold in a vault: secure, and doing nothing. Türkiye’s AI Action Plan is trying to change that habit. Through the Data Spaces programme, companies and public institutions will be able to share data in controlled fashion, voluntarily and on mutual-benefit terms, under common rules and legal safeguards. Secure working rooms, standard contracts, licensing models and anonymisation standards are all being built.
The question is simple: will your data stay in the safe or go into circulation? The answer is neither “all of it” nor “none of it”. The answer lies in knowing which data is which.
Why Is the Question Being Asked Now?
BU BÖLÜMÜN ÖZETİ
- The infrastructure for sharing is being built
- Incentives are coming for providers
- AI made data more valuable
- Data alone is not enough
Four developments brought the question to the table.
The infrastructure for sharing is being built
A business wanting to share data used to face two obstacles: legal uncertainty and technical difficulty. The plan targets both. Standard contracts, secure working rooms, anonymisation standards and data-protection coordination are designed together. Each institution will name a data product owner. In short, a ground with a known counterpart and written rules.
Incentives are coming for providers
Several incentives are listed for organisations that open data: tax and R&D deductions, compute and data credits, a formal trusted-provider status. So sharing shifts from goodwill to a revenue line. That distinction matters; programmes running purely on goodwill move slowly, incentivised ones move faster.
AI made data more valuable
Data used to feed reports. Now it trains models. Clean data specific to one sector is gold to whoever builds that sector’s model. That raises data’s price. The plan’s sectoral foundation-model target rests on the same idea: instead of general-purpose models, specialised ones in fields where the country holds a data advantage.
Data alone is not enough
One small business’s data will not train a model. Ten businesses’ data will. That simple fact builds the economics of sharing. Everyone reaches a result none could reach alone. Insurance, agriculture and maintenance have worked this way for years. What is new is how much more valuable AI makes the pooled version.
What Is Wrong?
BU BÖLÜMÜN ÖZETİ
- “Our data will reach competitors”
- “Nobody wants our data”
- “Sharing will get us in trouble with data protection”
- “Let’s get everything perfectly organised first”
Four assumptions block the road.
“Our data will reach competitors”
The most common fear. But sharing is not handing over. In secure data spaces the data stays where it is and only computation travels. In federated learning the model goes to the data, not the data to the model. Working the gold without opening the safe is possible. The plan lists these methods explicitly, alongside synthetic data and encrypted computation.
“Nobody wants our data”
The reverse assumption. Businesses think their own data is ordinary. But ordinary means ordinary to you. The field records you have kept for years, the fault history, the seasonal demand data — none of it exists anywhere else. A simple way to see the value: how many years would it take to collect this from scratch?
“Sharing will get us in trouble with data protection”
Not every share involving personal data is problematic. Anonymised, synthetic and aggregated data fall under different regimes. The plan foresees standards being developed here. The right question is not “may we share” but “in what form may we share”. Asking it that way also shortens the conversation with your lawyer.
“Let’s get everything perfectly organised first”
Wait for perfect data order and you never start. Sharing begins with a single dataset. That set gets cleaned, its rules written, the process tested. Scaling comes after. The plan’s own targets start modestly too: at least three pilot data spaces, at least 25 shared datasets.
The Real Mechanism
BU BÖLÜMÜN ÖZETİ
- Class one: core data
- Class two: shareable business data
- Class three: personal data
- Class four: dead data
Data splits into four classes. No decision can be made before classification.
Class one: core data
The source of your competitive advantage. Your customer list, your pricing logic, your proprietary process knowledge. This data is never shared, rented or lent. The test: what would you lose if a competitor saw it? It is the data-side counterpart of the core definition.
Class two: shareable business data
Ordinary to you, valuable to someone else. Fault records, production measurements, logistics timings, sector demand data. Anonymised, it carries no competitive risk. This is the class that goes to data spaces. In most businesses it is the largest part of the inventory and the least noticed.
Class three: personal data
A separate regime. Sharing is possible only through anonymisation, aggregation or explicit consent. The rule here is simple: if you are unsure, do not share; get legal advice first. Mistakes in this class bring regulatory consequences on top of reputational ones.
Class four: dead data
Held but unused. Records left from old systems, lists nobody updates. Two paths: clean it up into class two, or delete it. Storage has a cost and carries breach risk. Old unused records are often the files that do the most damage in a security incident.
Who Is Affected, and How?
BU BÖLÜMÜN ÖZETİ
- The manufacturer
- Retail and e-commerce
- Services and consulting
- Health and finance
Four profiles, four different calculations.
The manufacturer
The richest class-two data sits here. Machine logs, quality measurements, maintenance history. This is the fuel of predictive maintenance models. Building a shared pool with similar businesses gives access to a model none could reach alone. You can even share with a direct competitor, because a shared model lowers both parties’ downtime and never touches your customer list.
Retail and e-commerce
Demand data and seasonality are valuable. But customer data sits in class three and needs care. Draw the line clearly: basket behaviour can be aggregated, identity information is not shared. That line is a commercial decision, not a technical one, and it gets drawn at the management table.
Services and consulting
Data looks scarce but exists: project durations, job types, problem categories. These matter for sector benchmarking. Because they carry client confidentiality, anonymisation needs more care here. In small sectors a few details can make a client identifiable.
Health and finance
Sensitive fields. Their data does not go to the open library; it opens through secure data spaces, to authorised actors, under supervision. The plan defines separate regimes for these areas. The opportunity is large but the door is narrow and rule-bound.
Decision Order
BU BÖLÜMÜN ÖZETİ
- One: sort your data into four classes
- Two: put the core in writing
- Three: try one set
- Four: measure what you got back
Four steps, in order.
One: sort your data into four classes
Write a class next to every row of your inventory. Half a day, and it makes every later decision easier. Sharing debates held without classification go nowhere; everyone at the table argues about different data.
Two: put the core in writing
Write down which data never leaves. A written boundary protects you in a busy season and in front of an attractive offer. It is the first article of the sovereignty framework.
Three: try one set
Pick one class-two set. Clean it, anonymise it, write its sharing terms. Start small: a trade association, a supplier, a research project. The first share is not about revenue but about learning the method.
Four: measure what you got back
What did the sharing return? A shared model output, benchmark data, an incentive, a new business connection. Sharing whose return is unmeasured does not continue. Measured, moving to the second set becomes easy.
Where to Start?
BU BÖLÜMÜN ÖZETİ
- Classify the inventory
- Clean out the dead data
- Look for data initiatives in your sector
- Prepare one set
Four jobs in the first month.
Classify the inventory
Half a day. Four classes, one label per row. Do the labelling with someone who knows the business; a technical team alone cannot classify correctly.
Clean out the dead data
Either organise unused data or delete it. It frees space and lowers risk. Check statutory retention periods before deleting.
Look for data initiatives in your sector
Associations, clusters, university projects. In most sectors somebody has already started. Sharing usually begins in familiar circles.
Prepare one set
Choose a single set and make it shareable. A ready set is in your hand when the call opens. Those prepared when the data library launches will move first.
What Not to Do?
BU BÖLÜMÜN ÖZETİ
- Sharing without classifying
- Sharing without a contract
- Sharing for nothing
- Keeping data forever
Four traps.
Sharing without classifying
The most dangerous error. A share made without knowing what is what can carry the core outside. Classification comes before sharing.
Sharing without a contract
Well-meant collaborations suffer most here. If it is not written who uses what for which purpose, there is no way back when the relationship sours. The plan also foresees standard contract models being developed.
Sharing for nothing
Data is a valuable asset. Given away free, it distorts both your own and the sector’s price perception. The return need not be money: a shared model output, a benchmark report, access to incentives all count.
Keeping data forever
The opposite error. Unused data produces no value but does produce risk. Retention periods and deletion rules belong in writing.
A Solid Digital Foundation
BU BÖLÜMÜN ÖZETİ
- The classified inventory
- The written core list
- The sharing contract template
- The retention and deletion rule
Four stones.
The classified inventory
Every data row has a class. Reviewed once a year.
The written core list
What is never shared. Keep it short and clear.
The sharing contract template
Purpose, duration, scope, return and deletion terms. Prepared once, used every time.
The retention and deletion rule
Which data is kept how long, deleted when. The cheapest instrument in risk management.
Frequently Asked Questions
Sık Sorulan Sorular
Alone, usually not; combined, yes. That is the logic of data spaces: twenty small firms’ fault records mean nothing separately but suffice to build a predictive maintenance model together. The small firm’s advantage lies exactly here; it cannot match a large player’s data volume alone but can reach it through a pool.
What prevents regret is the contract. A good sharing agreement has four clauses: what purpose the data serves, for how long, with whom it may be shared, and what happens when the relationship ends. With those written, the risk is small. Without them, do not share.
Done properly, largely yes. But “we deleted the name column” is not anonymisation; a few columns combined can re-identify a person. That is why the plan foresees AI-focused anonymisation standards. If you are sharing sensitive data, get expert advice until standards arrive; synthetic data generation is also an option on the table.
Both are possible and it depends on your classification. Direct revenue is limited today; the real return arrives as incentives, shared model outputs and benchmark knowledge. But the direction is clear. As the data economy forms, the party with orderly, clean data sits at the negotiating table holding an asset. The one with scattered data just watches.
