Cybersecurity 2026

TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal

Institutional CERTs Institutional CERTs are established within public and private organisations. All organisations operating in the critical infrastruc - ture sectors must establish an institutional CERT. Furthermore, ICTA is authorised to order a public or private organisation to establish and maintain a CERT, regardless of its sector. Institutional CERTs also act in co-ordination with the TR-CERT and sectoral CERTs operating in the relevant sector, as applicable. The Personal Data Protection Authority (DPA) The DPA is the primary supervisory and regulatory authority for data protection matters. It is authorised to regulate data protection activities, to take measures to protect the rights of data subjects, and to receive data breach notices. The National Intelligence Agency (NIA) The NIA is entitled to collect and analyse data by using any method, tool and system regarding foreign intelligence, national defence, counterterrorism, inter - national crimes and cybersecurity, and to deliver the produced intelligence to the relevant institutions. The Turkish National Police Department of Cybercrime Prevention This department provides support in investigating crimes committed using information technology, and gathers forensic data to fight cybercrime. This depart - ment is also the 24/7 Contact Point of the Budapest Convention on Cybercrime. The Ministry of National Defence, the Presidency of Defence Industries, and the Turkish Armed Forces Cyber Defence Command These entities ensure cybersecurity from the perspec - tive of military and national defence. The Ministry of Interior Disaster and Emergency Management Presidency (AFAD) AFAD is responsible for crisis co-ordination and man - agement, to protect critical infrastructures in the event of disasters.

Others In addition to the above, sector-specific administra - tive institutions such as the Banking Regulation and Supervision Agency (BRSA), the Capital Markets Board (CMB), the Turkish Republic Central Bank (TRCB), the Energy Market Regulatory Authority (EMRA), the General Directorate of Civil Aviation (GDCA) and the Nuclear Regulatory Authority are entitled to regulate cybersecurity-related issues in their respective sec - tors. 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation General There is no framework legislation on critical infrastruc - ture cybersecurity. The Cybersecurity Act delegates the duty to deter - mine critical infrastructures and the organisations and locations to which they belong to the Directorate and the Cybersecurity Board. Currently, there is no precise scope for critical infrastructure cybersecurity regula - tion, and the relevant sectoral legislation must be consulted. The applicable legal texts are policy docu - ments of authorised institutions and sector-specific by-laws. The DTO’s Information and Communication Security Guide (“ICS Guide”) The ICS Guide published by the DTO defines “criti - cal infrastructures” as “ infrastructures that incorpo- rate information technologies which may cause loss of life, economic harm of large-scale, national secu- rity gaps and public disorder when the confidentiality, integrity and availability of data/information therein are disrupted ”. The ICS Guide applies to public entities and busi - nesses providing critical infrastructure services. It sets out general security measures and those specific to the energy and e-communication sectors. It defines, among other things, the asset groups, their critical - ity level, measures, the application process, and their respective compliance plans.

421 CHAMBERS.COM

Powered by