Cybersecurity 2026

TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal

6.2 Cybersecurity and AI Currently, Türkiye has no specific AI legislation. How - ever, on 5 October 2024, the Turkish Parliament estab - lished a parliamentary research commission to estab - lish a legal infrastructure in this field and to determine measures to prevent the risks of AI. The commission’s work remains undisclosed. In addition, a proposal for an AI Act was submitted to parliament on 25 June 2024, focusing on risk manage - ment and auditing. Although its approval is unlikely, it is the first legislative initiative in this field. Another pro - posal aimed at regulating AI was submitted to parlia - ment on 7 November 2025. It included cybersecurity requirements for AI system service providers. There are recommended security measures concern - ing AI under the following documents. The DTO’s Report on Chatbot Applications and the Case of ChatGPT The report provides information on security risks and • end-to-end encryption; • self-deleting messages; • configuration access controls; and • secure history storage. Recommendations by the DPA The DPA’s informational document on chatbots high - lights: • the importance of transparency in AI chatbot appli - cations; • the potential risks, such as over-sharing of person - al data by the data subjects and cyber incidents; and • the need for minor protection. The following measures are suggested to be taken while developing a chatbot application: • complying with international standards, having cer - tificates, and ensuring privacy by default; and • in data communication, preferring secure methods for transmitting inputs. methods to reduce them, including: • authentication and authorisation;

• CMMI certificate at a minimum of the third level, which is obtained from institutions or companies with CMMI lead auditor. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Data controllers must provide an appropriate level of security for the personal data they process, and ensure their processors provide a level of security for personal data that is at least equivalent to their own. To enforce this, they may conduct or commission the necessary audits on their processors’ systems con - taining personal data, review the results, and inspect the data processor on-site. The DPA issued the Guideline on Personal Data Protection (Technical and Organisational Measures) (“Measures Guideline”) in 2018, which lists and details the technical and administrative measures to be taken by data controllers, such as: • using a firewall and internet gateway; • patch management; • software updates; • limiting access to systems containing personal data; • using strong passwords for such systems; • creating an access control matrix; and • using brute force algorithm (BFA). There are stricter requirements for the processing of special categories of data, per DPA Decision No 2018/10. The DPA may also specify case-specific measures in its published decisions. Administrative fines for failure to take the neces - sary technical and organisational measures (inter - preted very broadly, including unlawful data transfer abroad and violation of fundamental principles) range between TRY256,357 and TRY17,092,242 for 2026. See also 2.3 Incident Response and Notification Obligations regarding the data breach notification duty.

431 CHAMBERS.COM

Powered by