TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
In the banking sector, the By-Law ISBEBS requires banks to report cyber-events to the BRSA. A cyber-attack affecting a public company must be disclosed to the public as per the Communiqué on Material Events Disclosure. In the healthcare sector, as per the Directive on the Information Security Policies of the Ministry of Health, all information security breach incidents related to the Ministry of Health must be submitted to the central breach notification system thereof. In the civil aviation sector, the Cybersecurity Direc - tive for Civil Aviation Enterprises requires civil avia - tion enterprises to immediately report cyber incidents escalating into a crisis or affecting critical information systems or personal data to the GDCA. 2.4 State Responsibilities and Obligations According to the Cybersecurity Act, one of the duties of the Directorate is to obtain, generate and share cyber threat intelligence. The Directorate is also responsible for promoting co-operation between the public sector, the private sector and universities through working groups. The government and the pri - vate sector also co-operate to develop cybersecurity standards and procedures through initiatives such as the Türkiye Cybersecurity Cluster. For the allocation of duties and the details thereof, see 1.3 Cybersecurity Regulators . See also 2.1 Scope of Critical Infrastructure Cybersecurity Regulation and 2.2 Critical Infrastructure Cybersecurity Require- ments regarding the obligations provided for public institutions under the ICS Guide. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation No general legislation governs the Turkish financial sector’s operational resilience. Rather, relevant regula - tions of the BRSA, TRCB and CMB govern the man - agement of information systems for banks, payment
and electronic money institutions, and capital market institutions respectively. • The information systems of banks are regulated by the By-Law ISBEBS, which applies to banks established in Türkiye and to branches of foreign banks in Türkiye. • The information systems of payment and electronic money institutions are regulated by the Commu - niqué on Data-Sharing Services in the Payment Services Area of Payment and Electronic Money Institutions’ Information Systems and Payment Service Providers (“Communiqué on Payment Services”). The Communiqué covers an exhaustive list of payment and electronic money institutions that are established in Türkiye and authorised by the TRCB in accordance with the Law on Payment and Securities Settlement Systems, Payment Ser - vices, and Electronic Money Institutions. Therefore, although it does not apply to payment and elec - tronic money institutions located abroad, it applies to international transactions made through Turkish payment and electronic money institutions. • The CMB has a Communiqué on Information Sys - tems Management (“CMB Communiqué”), which took effect on 30 June 2025 by superseding a similar Communiqué. This Communiqué concerns stock exchanges, market operators and other organised marketplaces, publicly held corpora - tions, and capital market institutions (eg, invest - ment firms and crypto-asset service providers), among others. Since these institutions are required to be established in Türkiye, the Communiqué is not directly applicable to foreign institutions. How - ever, it may be applied to international transactions of the institutions in scope. • Crypto-asset service providers’ obligations under the CMB Communique are specified in “Criteria for Information Systems and Technology Infrastruc - tures of Crypto Asset Service Providers”, which was published by the Scientific and Technological Research Council of Türkiye (STRCT) on 8 May 2025.
425 CHAMBERS.COM
Powered by FlippingBook