TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
must also impose internal control mechanisms for the same (eg, approval of senior staff). Cyber Incident Management and Reporting Obligations Cyber incident response measures include keeping a detailed record, preventing similar incidents, estab - lishing internal incident management mechanisms, and identifying the root causes. Certain details of cyber incidents must be reported to internal senior staff and the relevant institutions. In addition, regarding critical infrastructure, financial institutions must also follow the notification obliga - tions mentioned in 2.3 Incident Response and Noti- fication Obligations . Although the respective regulations require prompt notification, there is no general time frame for report - ing obligations, except for personal data breaches, as detailed under 2.3 Incident Response and Notifica - For other crucial obligations, see 3.2 ICT Service Pro- vider Contractual Requirements , 3.5 International Data Transfers and 3.6 Threat-Led Penetration Test- ing . 3.4 Operational Resilience Enforcement Enforcement of operational resilience obligations is shared by the BRSA, TRCB and CMB. Banking Regulation and Supervision Agency The BRSA is authorised to carry out examination of all books, records and documents, and to conduct on- site audits and ex officio inspections concerning the support service organisations. The By-Law ISBEBS also authorises BRSA to inspect banks’ ICT providers, mandating the submission of requested information and documents and the maintenance of records in a readable format. Moreover, the BRSA is authorised to impose admin - istrative fines in case of non-compliance, ranging between TRY1,919,682 and TRY19,197,873 for 2026. According to its 2024 Annual Report, BRSA has fined tion Obligations . Other Obligations
51 companies for non-compliance with the regula - tions on information security. Turkish Republic Central Bank The TRCB is authorised to audit banks, payment institutions, electronic money institutions and their branches, representatives or outsourced service pro - viders of the Post and Telegraph Organisation. The TRCB may request the payment institution and electronic money institution to take the necessary measures in relation to the issues identified. In case of failure to take these measures in a reasonable time, the TRCB may revoke the operating licence. Depending on the case, the TRCB may impose an administrative fine of between TRY825,996 and TRY2,065,087 for non-compliance with the regula - tions on payment services and electronic money institutions. Capital Markets Board The CMB has the authority to audit capital market activities of entities subject to the Capital Markets Law and other relevant real or legal persons. Auditors may request relevant documents and information. Failure to provide these and obscuring the audit are criminal - ised under the Capital Markets Law. Depending on the case, the CMB may impose an administrative fine of between TRY445,189 and TRY5,565,500 on persons who fail to comply with the Capital Markets Law and its secondary legislation. Of the decisions of the CMB that were published in 2025, 16 included administrative fines for non-compliance with the CMB Communiqué; most of these decisions concerned penetration testing and information secu - rity continuity requirements. 3.5 International Data Transfers Data Localisation Obligations The following entities must keep their primary and secondary information systems in Türkiye: • banks; • payment institutions and electronic money institu - tions;
427 CHAMBERS.COM
Powered by FlippingBook