TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
curity Act remains unclear as both have broad scopes and lack a prevailing clause. See 6.1 Cybersecurity and Data Protection for further information. The Turkish Criminal Code (TCrC) No 5237 The TCrC prescribes imprisonment of between six months and eight years for cybersecurity offences, including: • unlawful access; • blocking or bricking the cyber-system, or destroy - ing, modifying or making inaccessible the data within; • misuse of debit or credit cards; • trafficking devices or software used to bypass security for criminal purposes; • committing theft or fraud via cyber-systems; • unlawful recording, transfer, publication or acquisi - tion of personal data; and • failure to destroy personal data after the legal retention periods. The Communiqué on the Procedures and Principles for Connecting to and Auditing the KamuNet Network (“Communiqué on KamuNet”) KamuNet (loosely translated as PublicNet) is a closed- circuit, isolated virtual network infrastructure for public institutions and organisations in their service, transac - tion and data traffic transfers. Hence, it is more secure against physical and cyber-attacks. All public insti - tutions and organisations must utilise the KamuNet network. The Communiqué on KamuNet sets the requirements for public entities integrated into KamuNet, such as having a TS ISO/IEC 27001 certificate. In addition, it authorises the MTI to determine which public entities are to be integrated and to assess their suitability.
• conducting operations to increase cyber-resilience (eg, by penetration tests or risk analysis); • determining critical infrastructures; • ensuring keeping of the asset inventory for public institutions and critical infrastructures; • establishing and auditing CERTs; • determining the procedures and principles to be followed by those operating in the field of cyberse - curity; • establishing and operating the necessary infra - structure for the cybersecurity of public institutions and critical services, providing secure hosting ser - vices, and defining the procedures and principles thereof; • determining the standards for cybersecurity; • carrying out testing and certification procedures for cybersecurity; • conducting cybersecurity audits and imposing sanctions; and • determining the technical criteria for cybersecurity products and services to be used in public institu - tions and critical infrastructures. Amendments made to Presidential Decree No 177 on the Cybersecurity Directorate on 25 December 2025 provided some additional powers and duties on standardising, governing and operating the national digital infrastructure and AI ecosystem. The Directorate is also authorised to conduct audits and on-site inspections for activities of all persons and institutions subject to the Cybersecurity Act. For reasons of national security, public order or the pre - vention of crime or cyber-attacks, and pursuant to a judicial decision or, in cases of urgency, a written order from a public prosecutor, it may also search and seize in residences, workplaces and other non-public indoor spaces. However, the Directorate’s duties will continue to be performed by the existing relevant public institutions and organisations until the relevant units within the Directorate are established and become operational. On 24 October 2025, the head of the Directorate was appointed. On 25 December 2025, the following additional units were formally established under the Directorate:
1.3 Cybersecurity Regulators The Cybersecurity Directorate
The Directorate has been designated as a general authority on cybersecurity matters. Its main duties and powers are as follows:
419 CHAMBERS.COM
Powered by FlippingBook