Named a Leader in the Gartner® Competitive Landscape: Conversational Solutions™, 2025Get the report

Debt Collection Regulation and AI Compliance

Calling hours, data protection and debtor rights: the compliance frame around a collections conversation.

Collections is a process that touches the consumer directly and is framed by regulation. When artificial intelligence enters that process the compliance responsibility does not disappear; it becomes part of the design. This page describes, at a general level, the topics that are taken into account in collections conversations.

What follows is for information and is not legal advice. How your institution applies these points is determined by your own legal and compliance teams.

What does regulation frame in a collections call?

Calling hours and frequency

The timing and frequency of contact with a consumer are not unrestricted. Calls are expected to stay within reasonable hours and the same person is not to be called at a frequency that becomes intrusive. In TAHSİLDAR these limits run as rules defined by the institution: the calling window and the number of attempts are taken into account when the queue is built.

The disclosure at the start of the call

At the opening of the conversation, who is calling, on behalf of which institution and for what purpose are expected to be stated. The notice approved by the institution's legal team is read at the start of the call and this step cannot be skipped.

What is watched from a data protection perspective?

Purpose, boundary and audit trail

Clarity of processing purpose. The personal data processed during the call is limited to carrying out the collections process. Use beyond that purpose is not part of the design.

Role based access. Who can reach which data is defined. This applies to the AI agent as much as to human representatives: which fields the digital employee can see and which it can change are set out in advance.

An auditable record. Every interaction leaves a trace. Which data was accessed, which step was taken and at which point the call was handed to a person can all be reviewed afterwards. We cover the governance side on our AI governance and safety page.

In Turkey these requirements are set out under KVKK, the country's personal data protection law; institutions operating in other markets apply the equivalent regime in their own jurisdiction.

How are the debtor's rights protected?

No debt discussion before identity is verified

This is the most basic rule. No amount, due date or delinquency information is shared until it is confirmed that the person who answered is the debtor. Disclosing debt information to a third party is both a legal and a reputational risk.

Disputes and complaints

When a customer disputes the debt or raises a complaint, the conversation does not simply continue on its automated path. These situations are flagged according to the flow the institution has defined and handed to a human representative where required. Defining in advance the points where the decision must stay with a person is the essence of governance; we describe the standards frame on our ISO 42001 page.

Recording and transparency

Whether calls are recorded and how customers are informed about it depends on the institution's policy. TAHSİLDAR applies that policy; it does not set it on its own.

You can find how TAHSİLDAR is built on institutional rules on the TAHSİLDAR page.