Cybersecurity 2026

TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal

In addition, the DPA’s “Recommendations on Data Protection in the Context of Artificial Intelligence” con - sists of data protection-related recommendations for developers, producers, service providers and deci - sion-makers vis-à-vis AI systems. Finally, the DPA has recently published the “Guidance on Generative AI and Personal Data Protection”, which includes recommendations related to matters such as: • using privacy by design and privacy by default approaches; • conducting impact assessments; • integrating privacy enhancing technologies; • diverse red teaming; • prioritising trusted data sources; and • regular validation checks. Regulations Determining the Authorities to Regulate AI On 25 December 2025, two presidential decrees were published, authorising two authorities to regulate AI. Accordingly, the General Directorate of National Technology and AI under the Ministry of Industry and Technology is authorised to regulate AI technologies in general, while the Cybersecurity Directorate is now authorised to regulate AI in the public sector. 6.3 Cybersecurity in the Healthcare Sector The Directive on the Information Security Policies of the Ministry of Health (“MoH InfoSec Directive”) and the Guideline for Information Security Policies (“MoH InfoSec Guideline”) The MoH InfoSec Directive and MoH InfoSec Guide - line were published by the Health Information Sys - tems General Directorate (HISGD) under the Ministry of Health, which was established to regulate informa - tion systems and communication technologies used in the healthcare sector. The MoH InfoSec Directive establishes the Information Security Management Commission and sub-commis - sions responsible for information security and cyber incident management across all central and provincial Ministry of Health organisations. It also establishes the sectoral CERT for the healthcare sector and requires the appointment of an information security officer. Moreover, the MoH InfoSec Directive tasks HISGD

with the management of information security breach - es and auditing information security. It includes some requirements related to information security, such as reporting information security breaches to the Ministry of Health through an online web portal. For details of the certification obligation, see 5.1 Key Supplementing the DP Law provisions on special categories of personal data, the By-Law on Personal Health Data provides for the specific procedure to be followed by healthcare providers while processing health data. It covers accessing, securing, rectifying, destroying and transferring health data. It requires taking the information security measures under the MoH InfoSec Directive and using KamuNet to transfer health data where feasible. The Guide on Protection of Personal Data in Pharmacovigilance Activities In the context of pharmaceutical R&D, the Turkish Medicines and Medical Devices Agency’s Guide on Protection of Personal Data in Pharmacovigilance Activities mandates specific technical and organisa - tional measures, such as: Cybersecurity Certification Legislation . The By-Law on Personal Health Data • using antivirus and antispam software; • removing vulnerable and unused software; • limiting access; • monitoring penetrations and unexpected move - ments in information networks; • keeping regular log records; • establishing an official reporting procedure; • reporting security issues to the data controller as quickly as possible; • ensuring security of environments containing per - sonal data; and • taking additional measures when storing in a cloud. • personnel training; • setting up a firewall; • using an internet gateway;

432 CHAMBERS.COM

Powered by