TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
The Cybersecurity Act The Cybersecurity Act provides a dedicated legal framework for the responsibilities of institutions, natural and legal persons who operate in cyberspace and the powers and duties of the recently established Directorate. It also establishes the Cybersecurity Board and determines its duties. Certain actions are criminalised, such as: • failure to provide information, documents and data to the audit personnel; • causing a data breach due to a failure to fulfil the duties regarding the protection of critical infrastruc - ture against cyber-attacks; • distributing, sharing or selling leaked data; and • creating and disseminating false content regard - ing data breaches in cyberspace, with the intent to incite anxiety, fear and panic. There are also specific requirements for companies producing cybersecurity products and services. The purpose section includes a provision regard - ing the identification and elimination of existing and potential threats, both internal and external, directed in cyberspace against all elements constituting the national power of Türkiye. However, the Cybersecu - rity Act’s territorial scope is not explicitly specified, so must be determined by general rules of criminal law or international public/private law, depending on the context. For more information on the Cybersecurity Act, see 1.3 Cybersecurity Regulators , 2.1 Scope of Critical Infrastructure Cybersecurity Regulation , 2.2 Criti- cal Infrastructure Cybersecurity Requirements , 4.1 Cyber-Resilience Legislation , 4.2 Key Obligations Under Legislation and 5.1 Key Cybersecurity Certi- fication Legislation . The Law on Regulation of Publications via the Internet and Combating Crimes Committed by Means of Such Publications No 5651 (“Internet Law”) The Internet Law aims to regulate the obligations and responsibilities of content, hosting, social network and access providers to combat crimes committed via the
• reporting on strategies to expand the qualified cybersecurity workforce; and • expanding cybersecurity higher education. Recently Enacted Regulations Establishment of the Cybersecurity Directorate and the Cybersecurity Act Aiming at providing a standalone institution for cyber - security, on 8 January 2025, Presidential Decree No 177 on the Cybersecurity Directorate established the Cybersecurity Directorate (“Directorate”). The powers and duties of the Directorate were later determined by the Cybersecurity Act. For detailed information, see 1.2 Cybersecurity Laws and 1.3 Cybersecurity Regulators . Other regulations The Communiqué on Information Systems Manage - ment took effect on 30 June 2025 and covers the security of information systems used in the capital markets sector. For detailed information, see 3. Oper- ational Resilience in the Financial Sector . 1.2 Cybersecurity Laws On 19 March 2025, the Cybersecurity Act was pub - lished in the official gazette and entered into force. According to the Cybersecurity Act’s provisory arti - cles, secondary regulations will be made within one year. Until then, current regulations that are not con - trary to the Cybersecurity Act will continue to be in force. General Regulations The Constitution of the Turkish Republic The Constitution does not explicitly address cyber - security. However, as cybersecurity also covers data protection, it can be considered that cybersecurity is partly and indirectly covered by Article 20 (3) of the Constitution, which provides for the right to protection of personal data. Additionally, Article 22 recognises freedom of communication as an individual right. Furthermore, because the Cybersecurity Act defines cybersecurity as an integral part of national security, many constitutional rights can be restricted on this basis.
417 CHAMBERS.COM
Powered by FlippingBook