TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
and the relevant sectoral CERT (if applicable). See 1.3 Cybersecurity Regulators for more details. Conversely, an organisation that is not required to establish a CERT is not obliged to report (although
lined in the By-Law ISBEBS. Moreover, personal data specific to banking relationships is also considered customer secrets under the Banking Law. For spe - cific requirements, see 3.1 Scope of Financial Sector Operational Resilience Regulation . Health Sector See 6.3 Cybersecurity in the Healthcare Sector . Civil Aviation Sector The Cybersecurity Directive for Civil Aviation Enter - prises mandates that civil aviation enterprises imple - ment: • effective oversight of information systems; • regular risk and threat assessments for operational assets; • comprehensive policies, procedures and process documents; • mechanisms to detect, prevent and respond to breaches; • testing, auditing, monitoring and reporting cyberse - curity controls and structures; and • a continuity management process and plan. 2.3 Incident Response and Notification Obligations There are several incident response and notification obligations for businesses providing critical infrastruc - tures. Depending on the sector, persons/institutions can be subject to more than one notification obliga - tion. Since there are no specific provisions determin - ing the interplay between the relevant regulations, notifications must be made to each authority sepa - rately. Notification to CERTs One of the main obligations provided under the Presi - dency Decree for public institutions is adopting the necessary measures regarding cyber threat notifica - tions. If an organisation is required to establish a CERT, in principle, its CERT must report any cyber incident (which the Communiqué on CERTs defines as a “breach or attempted breach of confidentiality, integ - rity, or accessibility of industrial control or information systems or data processed thereby”) to the TR-CERT
voluntary reporting is allowed). Notification to the Directorate
Under the Cybersecurity Act, institutions and per - sons using information systems are required to notify the Directorate of any vulnerability or cyber incidents that they detect in their service area. Non-compli - ance is subject to an administrative fine of between TRY1,254,900 and TRY12,549,000. The Cybersecurity Act defines a “cyber incident” as “the violation of the confidentiality, integrity, or avail - ability of information systems or data”, whereas “vul - nerability” is defined as “weaknesses and security gaps in cyberspace assets that may be exploited by any cyber threat”. Since the Directorate has not yet become operation - al, there is no available channel for notification to the Directorate; the details that must be reported to the Directorate have also not yet been determined. Although prompt notification is required, the Cyber - security Act does not specify timelines for the notifi - cation. Personal Data Breach Notification Controllers must report to the DPA within 72 hours and notify the relevant data subjects within the shortest time possible in case of data breach. The notification must be made using the “Data Breach Notification Form” published by the DPA. This form must be sub - mitted to the DPA via email or through the web portal In the e-communications sector, the By-Law on NIS in the E-Communication Sector requires the operator to notify ICTA regarding security breaches affecting more than 5% of its subscribers and the circumstances interrupting the continuity of the business. The notifi - cation must include at least the time, nature, impact and duration of the breach, and the measures taken. available on the DPA’s website. Sectoral Notification Duties
424 CHAMBERS.COM
Powered by FlippingBook