Skip to content
0553 774 93 58

Bar Registration No. 74199

Practice Areas

Data Protection & Cybercrime Lawyer in Istanbul, Turkey

As an English-speaking IT and data protection lawyer in Istanbul, Turkey, our office advises foreign individuals, expats and local and foreign businesses on online problems connected to Turkey, and represents clients in cybercrime and online personality-rights matters. Information technology law covers a broad field: the protection of personal data, offences against information systems, defamation and privacy violations committed online, requests for the removal of content, account freezes in online-fraud investigations and e-commerce disputes. The processing of personal data is governed by the Personal Data Protection Law No. 6698, known by its Turkish initials KVKK, which sets out data controllers' duty to inform, the conditions for processing data and the obligation to notify data breaches.

Acts such as unlawfully accessing an information system, obstructing or disrupting a system, or destroying or altering data are offences under Articles 243 to 245 of the Turkish Penal Code (TCK). Article 9 of Law No. 5651, which governed removal and access blocking for online violations of personality rights, was annulled by the Constitutional Court, with effect from 10 October 2024; for violations of privacy, the application route under Article 9/A of the same Law remains available. Since Law No. 7590 of July 2026, the authority under Law No. 5651 is the Cyber Security Presidency (Siber Güvenlik Başkanlığı), which took over this role from the Information and Communication Technologies Authority (BTK).

This page explains in plain English the routes the law provides when content about a person appears on Turkish websites or social media, how KVKK applies to foreign companies, what happens when an account is hacked or a bank or crypto account is frozen, and how digital evidence is preserved. It describes the legal framework only; what applies in a particular case depends on the facts and documents of that file.

IT and Internet Lawyer in Istanbul, Turkey: What the Office Handles

An IT lawyer in Turkey advises on KVKK (data protection) compliance, responds to data breaches and regulatory notifications, brings or defends cybercrime complaints, and pursues the removal of unlawful online content. For a foreign or multinational business, a data protection lawyer in Istanbul also typically advises on how KVKK compliance interacts with the company's obligations under other jurisdictions' data protection laws, such as the GDPR.

Individuals usually come to an internet lawyer in Istanbul with a specific problem: a defamatory post or review on a Turkish site, private photos shared without consent, a hacked social media or e-mail account, money lost to an online scam, a bank or crypto account frozen during a fraud investigation, or a dispute with an online seller. Many of these files have both a criminal side, a complaint to the prosecutor, and a civil side, a court action for removal or compensation, and the two can run in parallel.

How Do You Remove Content About You from Turkish Websites and Social Media?

The answer depends on what the content is. Where a post, photo or video violates private life, a fast administrative and judicial route still exists under Article 9/A of Law No. 5651, explained in the next section. Where the problem is defamation, insult, false allegations or an unfair article that harms a person's reputation, the former fast-track route under Article 9 of the same Law is no longer available. The routes that remain are a request to the website or platform, a civil action under the Turkish Civil Code with an interim injunction, and a criminal complaint.

Why the Old Fast-Track Removal Route Ended in October 2024

Until 2024, a person whose personality rights were violated online could apply directly to a criminal judge of peace (sulh ceza hakimliği) for removal of the content or for access blocking under Article 9 of Law No. 5651. The Constitutional Court annulled that article by its decision of 11 October 2023 (E.2020/76, K.2023/172), and the annulment took effect on 10 October 2024. Older guides that still describe the Article 9 procedure are therefore out of date.

Since then, removal of defamatory content has been pursued mainly through the civil courts, while the separate privacy route in Article 9/A remains in force.

Asking the Website, Platform or Author First

Law No. 5651 still defines a notice method (uyarı yöntemi): a person who claims that online content violates his or her rights contacts the content provider first and, if no result is obtained within a reasonable time, the hosting provider, using their published contact addresses (Article 2). Most platforms also run their own reporting forms.

In practice, a written notice identifies the exact address (URL) of the content, explains why it is unlawful and keeps a dated record of the request. Even where the platform does not act, the notice documents that it was informed, which can matter later for liability.

Court Action to Stop an Online Attack on Personality Rights

Under Article 24 of the Turkish Civil Code (TMK), a person whose personality rights are unlawfully attacked can ask the judge for protection. Article 25 lists what the claimant can ask for: prevention of a threatened attack, an end to an ongoing attack, and a declaration that a past attack was unlawful where its effects continue, together with notification to third parties or publication of a correction or of the judgment. Claims for pecuniary and non-pecuniary damages, and for handing over profits made from the attack, are preserved. The action can be filed at the claimant's own domicile or at the defendant's domicile.

Non-pecuniary damages (manevi tazminat) are governed by Article 58 of the Code of Obligations (TBK); instead of or in addition to money, the judge can order another form of redress, such as a decision condemning the attack and its publication. Compensation claims are time-barred two years after the person learns of the damage and of the person liable, and in any case ten years after the act, unless criminal law provides a longer period (TBK Article 72). Compensation claims in general are covered on our compensation law page.

Interim Injunction: Blocking Content While the Case Continues

Because a court case takes time, the claimant can ask for an interim injunction (ihtiyati tedbir) where a change in the current situation would make obtaining the right significantly harder or impossible, or where delay would cause a disadvantage or serious harm (Code of Civil Procedure, HMK, Article 389). The request is made before the lawsuit to the court competent for the main case, or afterwards to the court hearing it. The applicant states the ground and type of measure and shows the claim to be approximately proven, and in urgent cases the judge can decide without hearing the other side (Article 390).

Enforcement of the injunction has to be requested within one week of the decision being served or announced (Article 393). If the injunction was granted before the lawsuit, the main action has to be filed within two weeks of the request for enforcement; otherwise the injunction lapses automatically (Article 397). Where the injunction was granted without hearing the other side, that side can object within one week of its enforcement or of service of the enforcement record (Article 394).

Private Photos, Videos or Personal Details Posted Online in Turkey: The Privacy Route

Where online content violates private life, for example intimate images, private messages or personal details published without consent, Article 9/A of Law No. 5651 allows the person concerned to apply directly to the Cyber Security Presidency and ask for access to the content to be blocked. Until Law No. 7590 of July 2026, these applications were made to the Information and Communication Technologies Authority (BTK).

The privacy route blocks access from Turkey; it does not decide compensation or punishment. A criminal complaint for violation of privacy, and a civil action for damages, can run alongside it.

What the Privacy Application Must Contain

The application states the full address (URL) of the publication that violates the right, explains in what respects private life is violated, and includes information proving the applicant's identity; an incomplete application is not processed (Article 9/A(2)). Blocking applies only to the specific publication, section, picture or video, in the form of URL-based blocking (Article 9/A(4)).

The President of the Cyber Security Presidency notifies the request immediately to the Access Providers' Union, and access providers implement it immediately and at the latest within four hours (Article 9/A(3)).

The 24-Hour and 48-Hour Deadlines in Privacy Cases

The law then requires the applicant to submit the blocking request to the criminal judge of peace within 24 hours of making it. The judge assesses whether private life has been violated and announces a decision within 48 hours at the latest, sending it directly to the Presidency; otherwise the blocking measure is lifted automatically (Article 9/A(5)). If the content is removed from publication, the judge's decision becomes void by itself (Article 9/A(7)).

In urgent cases, the President can order blocking directly. That order is submitted for a judge's approval within 24 hours, and the judge announces a decision within 48 hours (Article 9/A(8) and (9)).

Do Social Media Platforms Have to Answer Complaints in Turkey?

Law No. 5651 places special duties on social network providers, defined as those that allow users to create, view or share content such as text, images, sound and location for social interaction (Article 2). Most of these duties apply to providers with more than one million daily accesses from Turkey and are set out in Additional Article 4.

The Turkish Representative of Large Social Networks

A foreign-based social network provider with more than one million daily accesses from Turkey appoints at least one authorised representative in Turkey to deal with notifications and requests from the Presidency, the Access Providers' Union and judicial or administrative authorities, and to answer applications made by individuals under the Law. The representative's contact details are displayed on the provider's website. If the representative is a natural person, he or she has to be a Turkish citizen resident in Turkey (Additional Article 4/1).

Where daily access exceeds ten million, the representative is fully authorised and responsible in technical, administrative, legal and financial terms, and a legal-entity representative has to be a branch established directly by the provider as a capital company. Separately, every social network provider with more than one million daily accesses from Turkey, domestic or foreign, takes measures to host the data of users in Turkey within Turkey (Additional Article 4/6).

The 48-Hour Answer Duty and Liability After a Court Decision

Social network providers with more than one million daily accesses from Turkey, whether based in Turkey or abroad, answer individuals' applications concerning content within the scope of Articles 9 and 9/A within 48 hours at the latest, positively or negatively; a negative answer has to give reasons (Additional Article 4/3). Since Article 9 has been annulled, this duty is now relevant mainly for privacy applications.

Where content has been found unlawful by a judge or court and the decision is notified to a social network provider, a provider that does not remove the content or block access within 24 hours is liable for the resulting damage. The injured person does not have to pursue or sue the content provider first (Additional Article 4/14).

Is Online Defamation or Insult a Crime in Turkey?

Insult (hakaret) is punishable by three months to two years' imprisonment or a judicial fine, including where it is committed through a written, voice or video message addressed to the victim (TCK Article 125). Where it is committed publicly, for example in a post open to everyone, the penalty is increased by one sixth. Except for insult against a public official because of his or her duty, insult is prosecuted only on the victim's complaint (Article 131).

The complaint has to be filed within six months of learning of the act and the offender and, for insult, in any case within two years of the act (TCK Article 73). Insult is excluded from victim-offender conciliation (CMK Article 253/3) and, except for insult against a public official because of his or her duty, falls within advance payment (önödeme): if the suspect pays the amount notified by the prosecutor, no public prosecution is brought (TCK Article 75). The criminal route therefore does not by itself remove the post; the civil route described above is used for that.

Online Threats, Stalking and Blackmail

Threatening a person with an attack on life, body or sexual integrity is punishable by six months to two years' imprisonment (TCK Article 106). Persistently trying to contact someone through communication tools, information systems or third parties, in a way that causes serious unease or fear for safety, is the offence of stalking, punishable by six months to two years and prosecuted on complaint (Article 123/A); stalking, like insult, is excluded from conciliation.

Threatening to reveal matters that would damage a person's honour or reputation in order to obtain a benefit, as in so-called sextortion cases, is punished as blackmail with one to three years' imprisonment and a judicial fine of up to 5,000 days (Article 107/2). Where intimate images have already been published, the privacy route above and the offence of disclosing images of private life can also arise.

Which Country's Law Applies to Online Defamation or Data Misuse Involving Turkey?

For a foreigner living abroad who is targeted on a Turkish website, two questions arise: whether a Turkish court can hear the case, and which country's law it applies. The international jurisdiction of Turkish courts is determined by the domestic venue rules (Law No. 5718 on International Private and Procedural Law, known as MÖHUK, Article 40). For torts, the court of the place where the act was committed, where the damage occurred or may occur, or where the injured person is domiciled is competent (HMK Article 16), and personality-rights actions can also be filed at the defendant's domicile (TMK Article 25).

On applicable law, claims arising from violations of personality rights through the press, radio, television, the internet or other mass media are governed, at the injured person's choice, by the law of the injured person's habitual residence or the law of the country where the damage occurred, in both cases if the wrongdoer could have known that the damage would occur there, or by the law of the country of the wrongdoer's place of business or habitual residence (MÖHUK Article 35). The same rule applies to claims arising from violations of personality through the processing of personal data (Article 35/3).

Does Turkey's Data Protection Law (KVKK) Apply to Foreign Companies?

KVKK applies to natural persons whose personal data is processed and to the natural and legal persons who process that data wholly or partly by automated means, or by non-automated means as part of a filing system (Article 2). Unlike the GDPR, the law does not contain a separate article on territorial reach. Whether a foreign company's processing falls under KVKK is therefore assessed on the facts, for example where it collects data from people in Turkey, has customers or employees in Turkey, or receives data from a Turkish group company. The secondary legislation on the data controllers' registry expressly provides for data controllers not established in Turkey.

KVKK protects only natural persons: personal data means any information relating to an identified or identifiable natural person (Article 3). Company information as such is not personal data, but the names and contact details of employees and contact persons are. Questions of group structure and intra-group agreements are also covered on our corporate law page.

When Personal Data Can Be Processed Without Consent

The starting point in KVKK is that personal data cannot be processed without the data subject's explicit consent (Article 5/1). Consent is not required where one of the following applies: the processing is expressly provided for by law; it is necessary to protect the life or physical integrity of a person who cannot give consent; it is necessary for the conclusion or performance of a contract with the data subject; it is necessary for the controller's legal obligation; the data has been made public by the data subject; it is necessary to establish, exercise or protect a right; or it is necessary for the controller's legitimate interests, provided the data subject's fundamental rights are not harmed (Article 5/2).

Special Categories of Data After the 2024 Amendment

Data on race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data are special categories of personal data (KVKK Article 6/1). Since the amendment by Law No. 7499, in force from 1 June 2024, their processing is prohibited unless one of the listed conditions applies, such as explicit consent, an express legal provision, the protection of life or physical integrity, data made public by the data subject in line with that intention, the establishment or protection of a right, health services by persons under a duty of confidentiality, or legal obligations in employment, occupational safety and social security. Adequate measures set by the Board are also required (Article 6/3 and 6/4).

KVKK Compliance Checklist for Businesses in Turkey

In practice, KVKK compliance means knowing what personal data is held, informing the people concerned, having a legal basis for each processing activity, keeping the data secure and, unless exempt, registering with the Data Controllers' Registry (VERBİS). Data that was lawfully processed has to be deleted, destroyed or anonymised once the reasons for processing no longer exist, either on the controller's own initiative or at the data subject's request (Article 7). Employee data is a frequent source of disputes, and its employment side is covered on our labour law page.

Data Inventory and the Privacy Notice

The first step in compliance is drawing up an inventory showing the categories of personal data processed, the purpose of processing, the retention period and the third parties to whom data is transferred. Based on this inventory, a privacy notice is prepared and made available to data subjects.

When personal data is collected, the law requires the controller to tell the people concerned the identity of the controller and of any representative, the purposes of processing, to whom and why the data may be transferred, the method and legal ground of collection, and their rights under Article 11 (Article 10).

When Explicit Consent Is Required

Where none of the other statutory grounds for processing applies, personal data may be processed only with the data subject's explicit consent, which the law defines as consent that is specific to a particular matter, based on information and freely given (Article 3). Explicit consent reflects a genuine choice by the data subject, not a pre-printed, generic form, and it is separate from the privacy notice.

Data Security Measures and Service Providers

The controller takes all necessary technical and administrative measures to prevent unlawful processing of and unlawful access to personal data and to ensure that it is preserved (Article 12/1). Where another person processes data on the controller's behalf, such as a cloud, payroll or IT provider, the controller is jointly responsible with that processor for these measures (Article 12/2). The controller also carries out or commissions the necessary audits, and controllers and processors cannot disclose personal data they learn or use it for other purposes, a duty that continues after they leave their position (Article 12/3 and 12/4).

VERBİS Registration in Turkey: Who Must Register and Who Is Exempt

Under Article 16 of KVKK, natural and legal persons who process personal data register with the Data Controllers' Registry before they start processing, unless the Board has exempted them on objective criteria such as the nature and number of the data, whether processing arises from law, or transfers to third parties. The registration states the identity and address of the controller and any representative, the purposes of processing, the groups of data subjects and data categories, the recipients, data planned to be transferred abroad, the security measures taken and the maximum retention period; changes are notified immediately (Article 16/3 and 16/4).

The exemptions are set by Board decisions, not by the law itself. Among other exemptions, under Board Decision No. 2018/87 as amended by Decision No. 2025/1572 published in the Official Gazette on 1 October 2025, controllers with fewer than 50 employees a year and an annual balance-sheet total below 100 million Turkish lira are exempt if their main activity is not processing special categories of data; where the main activity is processing special categories of data, the exemption applies only below 10 employees and a balance-sheet total of 10 million Turkish lira. Failing to register when required is a separate ground for an administrative fine (Article 18/1-ç).

Foreign Data Controllers and the Representative in Turkey

Under the regulation on the Data Controllers' Registry, a data controller not established in Turkey registers through a data controller representative, which has to be either a legal entity established in Turkey or a natural person who is a Turkish citizen. The representative deals with the Authority on the controller's behalf and receives data subjects' applications. For a foreign group, the choice of representative is usually considered together with the group's existing structure in Turkey.

Transferring Personal Data Out of Turkey After the 2024 Amendment

Article 9 of KVKK on transfers abroad was rewritten by Law No. 7499 and has applied since 1 June 2024; the old rule could still be used alongside the new one until 1 September 2024 (Provisional Article 3). The new system has three layers. First, data can be transferred where one of the processing conditions in Articles 5 or 6 exists and the Board has issued an adequacy decision for the country, sectors within it or the international organisation (Article 9/1). Adequacy decisions are published in the Official Gazette and reviewed at least every four years.

Second, without an adequacy decision, data can be transferred where a processing condition exists, the data subject can exercise his or her rights and has effective remedies in the destination country, and one of the appropriate safeguards is provided: an agreement between public bodies approved by the Board, binding corporate rules approved by the Board, a standard contract announced by the Board, or a written undertaking with the Board's permission (Article 9/4). These rules apply to data controllers and to data processors.

Standard Contracts and the Five-Business-Day Notification

A standard contract is notified to the Personal Data Protection Authority by the data controller or processor within five business days of signature (Article 9/5). Failing to make this notification carries its own administrative fine, which can be imposed on data controllers or processors that are natural persons or private-law legal entities (Article 18/1-d and 18/2).

Occasional Transfers When No Safeguard Exists

Where there is neither an adequacy decision nor an appropriate safeguard, data can be transferred only occasionally and only in listed cases, such as the data subject's explicit consent after being informed of the possible risks, necessity for a contract with the data subject or for pre-contractual steps at his or her request, necessity for a contract concluded in the data subject's interest, an overriding public interest, the establishment, exercise or protection of a right, or the protection of life or physical integrity (Article 9/6). The rules also cover onward transfers from the recipient abroad (Article 9/8).

KVKK vs GDPR: Key Differences for International Companies

KVKK was modelled on European data protection law, so an international company with a GDPR programme already has much of the structure in place. In broad terms, the main differences are these: KVKK contains no separate territorial-scope article; a public registry of data controllers (VERBİS) exists, with exemptions set by Board decisions; a data subject can complain to the Board only after first applying to the data controller (Article 14/2); and the controller answers requests within 30 days (Article 13/2).

Breach notification to individuals is not limited by a high-risk threshold in the text of KVKK (Article 12/5), and the 72-hour period for notifying the Board comes from a Board decision rather than from the law. Cross-border transfers follow the Turkish list of safeguards, including the Board's own standard contract and its notification within five business days. Administrative fines are set in Turkish lira within ranges in the law, increased every year by the revaluation rate, rather than as a percentage of turnover.

What Are Your Rights Under Turkey's Data Protection Law?

Everyone can apply to a data controller and exercise the rights listed in Article 11 of KVKK: to learn whether personal data about him or her is processed; to request information if it is; to learn the purpose of processing and whether data is used accordingly; to know the third parties in Turkey or abroad to whom data is transferred; to request correction of incomplete or inaccurate data; to request deletion or destruction under the conditions in Article 7; to request that corrections and deletions be notified to the third parties who received the data; to object to an adverse result produced exclusively by automated analysis; and to claim compensation for damage caused by unlawful processing.

Those whose personality rights are violated also keep their right to compensation under the general provisions (Article 14/3), which links data protection disputes to the civil-court route described above.

How Does a KVKK Request or Complaint Work? The 30-Day and 60-Day Deadlines

The KVKK procedure has two stages, and the second cannot be skipped: a complaint to the Board cannot be made before the application to the data controller has been made (Article 14/2).

Applying to the Data Controller First

The data subject sends the request to the data controller in writing or by other methods determined by the Board (Article 13/1). The controller concludes the request as soon as possible according to its nature and within thirty days at the latest, free of charge; if the action involves an additional cost, a fee from the Board's tariff can be charged. The controller accepts the request or rejects it with reasons and informs the applicant in writing or electronically; if the request is accepted, the controller carries it out (Article 13/2 and 13/3).

Complaining to the Personal Data Protection Board

If the application is rejected, the answer is found insufficient or no answer is given in time, the data subject can complain to the Personal Data Protection Board within thirty days of learning the controller's answer and in any event within sixty days of the application date (Article 14/1). Complaints that do not meet the basic requirements of the Petition Law, such as the applicant's name, signature and address, are not examined (Article 15/2).

The controller sends the documents requested by the Board within fifteen days (Article 15/3). If the Board does not answer a complaint within sixty days, the request is deemed rejected (Article 15/4). Where a violation is found, the Board orders the controller to remedy it, and the decision is complied with without delay and at the latest within thirty days (Article 15/5). In cases of irreparable harm and clear unlawfulness, the Board can also order processing or a transfer abroad to stop (Article 15/7).

Data Breach Notification in Turkey: Where Does the 72-Hour Rule Come From?

Article 12/5 of KVKK provides that, where processed personal data is obtained by others through unlawful means, the data controller notifies the person concerned and the Board as soon as possible, and the Board can announce the breach on its website or by another method if necessary. The law itself does not mention 72 hours. The 72-hour period comes from the Board's Decision No. 2019/10 of 24 January 2019 on the procedures for breach notification.

Timing and Content of Notification to the Board

Under the Board's decision, the data controller notifies the Board without delay and at the latest within 72 hours of learning of the breach. Where the information in the notification form cannot be provided all at once, it can be provided in stages without undue delay, and where the notification cannot be made within 72 hours for a justified reason, the reasons for the delay are explained with the notification.

The notification describes, among other points, the nature of the breach, the categories of data and the number of people affected, and the measures taken or planned.

Notifying the Individuals Concerned

The law requires notification to the persons concerned as well as to the Board, and the Board's decision calls for them to be informed within the shortest reasonable time. Unlike the GDPR, the text of KVKK does not limit this duty to high-risk breaches. In practice, a clear message usually explains what happened, which data was affected and what protective steps the person can take, such as changing a password.

Consequences of Failing to Notify

Breach notification is part of the data security obligations in Article 12, and failing to meet those obligations is a ground for an administrative fine (Article 18/1-b). Failing to inform the individuals concerned can also weigh against the data controller in a later compensation claim, since a data subject can claim damages for unlawful processing (Article 11/1-ğ).

KVKK Fines in 2026: How They Are Set and How They Are Challenged

Article 18 of KVKK provides administrative fines for failing to meet the duty to inform (Article 10), failing to meet data security obligations (Article 12), failing to comply with Board decisions (Article 15), breaching the registry obligations (Article 16) and failing to notify a standard contract (Article 9/5). The Board sets the amount within the range for each category, and the ranges are increased every year by the revaluation rate (Misdemeanours Law No. 5326, Article 17/7); the current figures can be checked with our KVKK fine lookup. Where the violation occurs within a public body or a professional organisation with public-body status, disciplinary proceedings are taken against the officials concerned on the Board's notification (Article 18/4).

Since 1 June 2024, administrative fines imposed by the Board are challenged before the administrative courts (Article 18/3, added by Law No. 7499). The general period for an administrative lawsuit is sixty days from written notification (Administrative Procedure Law, İYUK, Article 7). Applications that were already pending before criminal judgeships of peace on 1 June 2024 continued to be heard there (Provisional Article 3). The old rule of a fifteen-day objection to the criminal judgeship of peace therefore no longer applies to new KVKK fines.

Is Misusing Someone's Personal Data a Crime in Turkey?

Yes. KVKK refers criminal liability to Articles 135 to 140 of the Turkish Penal Code (KVKK Article 17). Unlawfully recording personal data is punishable by one to three years' imprisonment, increased by half where the data concerns political, philosophical or religious views, racial origin, sexual life, health or trade-union connections (TCK Article 135). Unlawfully giving personal data to another person, spreading it or obtaining it is punishable by two to four years (Article 136). Failing to destroy data in the system after the legal periods have expired is punishable by one to two years (Article 138), and KVKK applies this offence to those who do not delete or anonymise data as required (KVKK Article 17/2).

Violating a person's private life is punishable by one to three years, doubled where it is done by recording images or sounds, and unlawfully disclosing images or sounds of a person's private life is punishable by two to five years (TCK Article 134). These penalties increase by half where the offence is committed by a public official abusing his or her authority or by using the advantages of a profession (Article 137). Violation of privacy under Article 134 is prosecuted on complaint, while the data offences in Articles 135, 136 and 138 are prosecuted ex officio (Article 139).

Hacked Social Media or E-mail Account in Turkey: Which Offences Apply?

Taking over someone's social media, e-mail or cloud account without permission is usually examined as unlawful access to an information system. Where the account is then used to ask the person's contacts for money, qualified fraud through information systems can also arise. Legal support is provided both to victims and, as defence, to suspects and defendants in such files; in both roles, the way the digital evidence was collected and kept is often central.

Unauthorised Access and Illegal Monitoring

Unlawfully entering the whole or part of an information system, or remaining in it, is punishable by up to one year's imprisonment or a judicial fine (TCK Article 243/1). Actually copying or using the data is not required for the offence to be complete. If data in the system is destroyed or altered as a result, the penalty is six months to two years (Article 243/3). Unlawfully monitoring data transfers within or between information systems by technical means, without entering the system, is punishable by one to three years (Article 243/4).

Damaging, Deleting or Locking Data, Including Ransomware

Hindering or disrupting the functioning of an information system is punishable by one to five years' imprisonment (TCK Article 244/1). Damaging, destroying, altering or making data inaccessible, placing data in a system or sending existing data elsewhere is punishable by six months to three years (Article 244/2); where these acts target a system of a bank, credit institution or public body, the penalty increases by half (Article 244/3). If the acts bring an unjust benefit and do not constitute another offence, the penalty is two to six years and a judicial fine of up to 5,000 days (Article 244/4).

Producing, importing, selling, possessing or giving to others devices, programs, passwords or security codes created exclusively for committing these offences is punishable by one to three years and a judicial fine (Article 245/A).

Online Fraud in Turkey: Penalties and How a Complaint Is Filed

Fraud committed by using information systems, banks or credit institutions as a tool, or by a person presenting himself or herself as a public official or as an employee of a bank, insurance company or credit institution, is qualified fraud punishable by three to ten years' imprisonment and a judicial fine of up to 5,000 days (TCK Article 158/1-f and l). In these cases the minimum prison term is four years and the judicial fine cannot be less than twice the benefit obtained (Article 158/1, last sentence). The penalty increases by half where three or more people act together and doubles where the offence is committed within a criminal organisation (Article 158/3). Theft committed by using information systems, such as moving money out of someone's online banking, is qualified theft punishable by five to ten years (Article 142/2-e).

A complaint can be made to the chief public prosecutor's office or to the police, in writing or orally to be recorded (CMK Article 158/1 and 158/5). For offences committed by using information systems, banks or credit institutions, or bank or credit cards, the courts of the victim's place of residence are also competent (CMK Article 12/6). The wider criminal procedure is explained on our criminal law page.

Misuse of Bank or Credit Cards

Using another person's bank or credit card, or having it used, without the consent of the cardholder or of the person to whom the card should be given, to obtain a benefit is punishable by three to six years' imprisonment and a judicial fine of up to 5,000 days (TCK Article 245/1). Producing, selling or accepting fake cards linked to other people's accounts is punishable by three to seven years (Article 245/2), and obtaining a benefit by using a fake or falsified card by four to eight years (Article 245/3). The provisions on effective remorse for property offences apply to the first paragraph (Article 245/5).

The victim can notify the bank to prevent further loss and lodge a complaint to join the criminal proceedings.

Lending or Selling Your Bank Account: The 2026 Change

Handing over a card, account details or the access information of a bank, payment or crypto account, often for a small payment, can lead to an investigation for participation in fraud when the account is used to move scam proceeds. Under Article 158/4, added by Law No. 7589 of 16 July 2026, where a person's participation is limited to giving such payment instruments or access details to someone else to obtain an unjust benefit, the penalty is reduced by half. It remains a criminal offence, and the account involved is usually frozen.

Bank or Crypto Account Frozen in a Fraud Investigation in Turkey: The 48-Hour Rule

Since Law No. 7571 of 24 December 2025, where there is reasonable suspicion of theft through information systems, fraud through information systems or banks, fraud by impersonating officials or bank staff, or misuse of bank cards, a bank, payment service provider or crypto-asset service provider can suspend any account used in the offence for up to 48 hours (CMK Article 128/A(1)). The suspension and the account movements are reported immediately to the chief public prosecutor's office, and the account holder is also informed. The account holder can apply to the prosecutor to lift the suspension, and the prosecutor decides within 24 hours (Article 128/A(2)).

During the suspension, the proceeds of the offence in the account can be seized by a judge's decision or, where delay would be harmful, by the prosecutor's written order; a seizure without a judge's decision is submitted for approval within 24 hours, and if the judge does not decide within 48 hours the seizure is lifted automatically (Article 128/A(4)). Proceeds found to belong to the victim are returned during the investigation or trial (Article 128/A(5)). Separately, the Financial Crimes Investigation Board (MASAK) can suspend transactions suspected of money laundering or terrorist financing for seven business days on the Minister's authority (Law No. 5549, Article 19/A), and a judge can order the seizure of assets for listed offences under CMK Article 128.

An objection to a judge's seizure decision is filed within two weeks of learning of it (CMK Article 268). The practical side for foreigners is covered in Bank Account Frozen in Turkey.

Crypto Exchanges and Crypto Disputes in Turkey After the 2024 Law

Law No. 7518 of 26 June 2024 brought crypto-asset service providers under the Capital Markets Law No. 6362. A crypto-asset service provider needs the permission of the Capital Markets Board (SPK) to be established and to operate (Article 35/B). Contract terms that remove or limit the provider's liability towards its customers are invalid, and platforms set up internal mechanisms to resolve customers' objections and complaints (Article 35/C(1)). Disputes between platforms and their customers are subject to the general provisions, a licence from the Board does not mean that transactions are under public assurance, and crypto assets are not covered by the investor compensation scheme (Article 35/C(4)).

A foreign platform's activities directed at people resident in Turkey, for example through a workplace in Turkey, a Turkish-language website or promotion in Turkey, count as unauthorised crypto-asset service provision (Article 99/A(1)), and the Board can order removal or access blocking of related online content (Article 99/A(3)). Operating as a crypto-asset service provider without permission is punishable by three to five years' imprisonment and a judicial fine of 5,000 to 10,000 days (Article 109/A). Peer-to-peer crypto trades that lead to bank account freezes are explained in Crypto P2P Trades and Frozen Bank Accounts in Turkey.

Online Shopping and E-Commerce Disputes in Turkey

In online sales to consumers, the seller informs the consumer before the contract on the matters set out in the regulation, and the burden of proving that this was done lies with the seller (Consumer Protection Law No. 6502, Article 48/2). Except for goods prepared to the consumer's specifications, the seller delivers within the promised time and in any event within thirty days, failing which the consumer can terminate the contract (Article 48/3). Marketplaces that act as intermediaries are jointly liable with the seller for pre-contractual information, its confirmation and proof (Article 48/6-a).

Consumer disputes below an amount updated every year go to consumer arbitration committees (tüketici hakem heyeti), where an application is compulsory (Article 68). Above that amount, they go to the consumer courts, and mediation is a precondition before filing (Article 73/A). Consumer rights in general are covered on our consumer law page; disputes between businesses, such as a seller's dispute with a marketplace, fall under commercial law.

The 14-Day Right of Withdrawal

A consumer can withdraw from a distance contract within fourteen days without giving any reason and without paying a penalty; sending the withdrawal notice to the seller within that period is enough (Article 48/4). For goods, the period runs from receipt of the goods under the Distance Contracts Regulation. If the consumer was not properly informed about the right of withdrawal, the fourteen-day period does not bind him or her, but the right ends in any case one year after the end of the withdrawal period. Certain goods and services, such as those made to the consumer's specifications or perishable items, fall outside the right of withdrawal.

Online Sellers' Duties and Unwanted Marketing Messages

Under the E-Commerce Law No. 6563, a service provider gives buyers up-to-date identifying information, the technical steps to conclude the contract, information on whether the contract text is stored, the tools for correcting data-entry errors, and its privacy rules before a contract is concluded electronically (Article 3). Commercial electronic messages can be sent only with the recipient's prior consent, given in writing or by electronic means; tradespeople and merchants can receive them without prior consent (Article 6).

An intermediary platform is not, as a rule, liable for unlawful content offered by sellers, but once it becomes aware of unlawful content it removes it without delay and informs the relevant authorities; on a documented complaint of an intellectual property infringement, it removes the product and informs both sides (Article 9).

Is a Website Blocked in Turkey? Who Orders a Block and How It Is Challenged

For content that gives sufficient suspicion of certain listed offences, such as encouraging suicide, child sexual abuse, facilitating drug use, obscenity, prostitution, providing a place for gambling and illegal betting, a judge (or the court at trial) orders removal of the content or access blocking. In urgent cases the prosecutor can order it, subject to a judge's approval within 24 hours. These decisions are implemented within four hours at the latest (Law No. 5651, Article 8). A blocking decision given as a protective measure can be challenged by objection under the Code of Criminal Procedure (Article 8/2).

Other bodies also order blocks under their own laws, for example the Capital Markets Board for unauthorised crypto or investment services (Law No. 6362, Article 99/A). The route to challenge a block therefore depends on who ordered it and on what basis; decisions of administrative bodies are generally challenged before the administrative courts.

How Is Digital Evidence Preserved for a Case in Turkey?

Under the Code of Civil Procedure, data in electronic form, photographs, images and sound recordings are documents capable of proving facts (HMK Article 199). Screenshots that show the URL, date, time and the profile or account name, together with saved links and original files, are the usual starting point. Evidence obtained unlawfully cannot be taken into account by a civil court (HMK Article 189/2), and in criminal cases the accusation can be proven only with lawfully obtained evidence (CMK Article 217/2). Evidence gathered by secretly recording private conversations or by entering someone else's account can therefore be excluded, and gathering it that way can itself be an offence.

In criminal investigations, computers, programs and files can be searched and copied only on a judge's decision, or on the prosecutor's order where delay would be harmful, with that order submitted to a judge within 24 hours. When devices are seized, all data is backed up and a copy of the backup is given to the suspect or the lawyer (CMK Article 134). Hosting providers keep traffic data, such as IP records, for a period set by regulation of not less than one and not more than two years (Law No. 5651, Article 5/3).

Notarised Determination and Court Evidence Determination

Notaries can determine and record the condition and form of a thing (Notaries Law No. 1512, Article 61), and in practice this is used to record the state of a web page or social media post on a given date. Before or during a lawsuit, a party can also ask a court for evidence determination (delil tespiti), such as an inspection or an expert examination, where there is a legal interest; that interest is presumed where the evidence may be lost or become much harder to present (HMK Article 400). Online content can be deleted at any time, so these steps are often considered at the very beginning of a file.

Electronic Signatures and E-Documents as Evidence

A secure electronic signature has the same legal effect as a handwritten signature, except for transactions requiring an official form or special ceremony and certain security contracts (teminat sözleşmeleri) (Electronic Signature Law No. 5070, Article 5). Electronic data created with a secure electronic signature in the proper manner has the force of a written instrument (senet), and the court examines of its own motion whether a document was created with a secure electronic signature (HMK Article 205/2 and 205/3).

Can a Foreigner File a Cybercrime Complaint in Turkey from Abroad?

A victim does not have to be in Turkey to start a criminal file. A complaint is filed with the chief public prosecutor's office or the police, and can be made through a Turkish lawyer acting under a power of attorney (CMK Article 158). For offences committed abroad that have to be prosecuted in Turkey, a complaint can also be made at Turkish embassies and consulates (Article 158/3). A power of attorney is usually issued at a Turkish consulate or before a local notary with an apostille and a sworn translation, depending on the country.

A foreigner can also be on the other side of an online file, as a suspect. In that case the file can lead to police questioning, a travel ban or effects on a residence permit; see Arrested in Turkey as a Foreigner, Exit Ban in Turkey and our foreigners law page.

How Long Does an Internet Law Case Take in Turkey, and What Does It Cost?

Some steps have statutory deadlines measured in hours, such as the 24-hour and 48-hour periods in the privacy route and the 48-hour bank suspension. Other steps have no fixed duration: a KVKK complaint, a criminal investigation into an anonymous account or a civil action for removal and compensation can take months or longer, depending on the court, expert examinations and whether information has to be obtained from platforms abroad. It depends on the file, and no realistic estimate can be given before the documents are reviewed. Once a court gives judgment, the periods for appeal run from service of the reasoned decision, and the appeal deadline calculator gives a first estimate of the last day.

Costs typically include court fees and expenses, expert fees in civil cases, notary or translation costs, and the lawyer's fee. Lawyers' fees in Turkey are subject to the minimum fee tariff prepared by the Union of Turkish Bar Associations, and fees below the tariff are not allowed (Attorneyship Law No. 1136, Articles 164 and 168). The fee is agreed in writing before work begins.

Data Protection and Cybercrime Lawyer in Ankara and Across Turkey

The Personal Data Protection Authority is based in Ankara (KVKK Article 19/3), and the Access Providers' Union that implements blocking decisions also has its seat in Ankara (Law No. 5651, Article 6/A). Since 1 June 2024, KVKK fines are challenged before the administrative courts within sixty days of notification (KVKK Article 18/3; İYUK Article 7); as a general rule, the competent administrative court is the one where the authority that made the decision is located (İYUK Article 32), which for the Board means Ankara. Cybercrime cases are heard where the offence was committed (Article 12 of the Code of Criminal Procedure), and for offences committed through information systems, banks or cards the courts of the victim's residence are also competent.

Our office is in Istanbul. As a data protection lawyer in Istanbul, the office follows files before the authorities and courts in Ankara through UYAP, the national e-filing system, and attends hearings there as needed. A data protection lawyer in Turkey registered with a Turkish bar can act in every city, so there is no need to find a separate lawyer in Ankara for each step. The range of KVKK fines can be checked with our KVKK fine lookup.

Ways to Remove or Block Online Content in Turkey Compared

RouteTypical useWho decidesKey time limitsLegal basis
Notice to the content or hosting providerAny content claimed to be unlawful; first contact with the site or platformThe provider itselfLarge social networks answer privacy applications within 48 hoursLaw No. 5651, Art. 2 and Additional Art. 4/3
Privacy application to the Cyber Security PresidencyIntimate images, private details, other violations of private lifeThe Presidency, then the criminal judge of peaceBlocking within 4 hours; applicant goes to the judge within 24 hours; judge decides within 48 hoursLaw No. 5651, Art. 9/A
Civil action for personality rightsDefamation, false allegations, damage to reputationCivil court of first instance (asliye hukuk)Damages: 2 years from knowledge, 10 years at most from the actTMK Arts. 24-25; TBK Arts. 58 and 72
Interim injunction (ihtiyati tedbir)Blocking or removal while the case continuesThe court competent for the main caseEnforcement requested within 1 week; lawsuit within 2 weeks if granted before filingHMK Arts. 389-397
Criminal complaintInsult, threats, blackmail, privacy and data offences, hackingProsecutor, then the criminal courtInsult: 6 months from learning, at most 2 years from the actTCK Arts. 73 and 125; CMK Art. 158
Blocking for listed offencesObscenity, gambling, illegal betting and other listed offencesJudge or court; prosecutor in urgent casesImplemented within 4 hours; prosecutor's order to a judge within 24 hoursLaw No. 5651, Art. 8

KVKK Rights and Deadlines at a Glance

Right or stepWhat the law providesLegal basis
Information and accessLearn whether data is processed, request information, learn the purpose and whether data is used accordinglyKVKK Art. 11/1-a, b, c
RecipientsKnow the third parties in Turkey or abroad who received the dataKVKK Art. 11/1-ç
Correction and deletionCorrect incomplete or inaccurate data; delete or destroy it under the statutory conditionsKVKK Arts. 11/1-d, e and 7
Notifying recipientsHave corrections and deletions passed on to third parties who received the dataKVKK Art. 11/1-f
Automated decisionsObject to an adverse result produced exclusively by automated analysisKVKK Art. 11/1-g
CompensationClaim compensation for damage from unlawful processingKVKK Arts. 11/1-ğ and 14/3
Controller's answerAs soon as possible and within 30 days; free unless an extra cost arisesKVKK Art. 13
Complaint to the BoardWithin 30 days of learning the answer, at most 60 days from the application; prior application requiredKVKK Art. 14
Board's answerNo answer within 60 days counts as rejection; a remedy order is complied with within 30 daysKVKK Art. 15/4 and 15/5
Breach notificationTo the Board without delay and within 72 hours; to individuals within the shortest reasonable timeKVKK Art. 12/5; Board Decision 2019/10
Standard contract for transfers abroadNotified to the Authority within 5 business days of signatureKVKK Art. 9/5
Challenging a fineAdministrative court, 60 days from notificationKVKK Art. 18/3; İYUK Art. 7

Cyber Crime and Privacy Offences in Turkey: Penalties in the Law

OffencePenaltyLegal basis
Unlawfully entering or remaining in an information systemUp to 1 year or a judicial fineTCK Art. 243/1
Unlawful access that destroys or alters data6 months to 2 yearsTCK Art. 243/3
Illegally monitoring data transfers1 to 3 yearsTCK Art. 243/4
Hindering or disrupting a system1 to 5 yearsTCK Art. 244/1
Damaging, deleting, altering or locking data6 months to 3 yearsTCK Art. 244/2
Obtaining an unjust benefit through these acts2 to 6 years and a judicial fineTCK Art. 244/4
Misuse of another person's bank or credit card3 to 6 years and a judicial fineTCK Art. 245/1
Using a fake or falsified card4 to 8 years and a judicial fineTCK Art. 245/3
Devices or programs made for cyber offences1 to 3 years and a judicial fineTCK Art. 245/A
Theft through information systems5 to 10 yearsTCK Art. 142/2-e
Fraud through information systems or banks3 to 10 years and a judicial fine; at least 4 yearsTCK Art. 158/1-f
Violating private life1 to 3 years; doubled if by recording images or soundsTCK Art. 134/1
Disclosing images or sounds of private life2 to 5 yearsTCK Art. 134/2
Unlawfully recording personal data1 to 3 yearsTCK Art. 135
Unlawfully giving, spreading or obtaining personal data2 to 4 yearsTCK Art. 136
Insult, including by message3 months to 2 years or a judicial fineTCK Art. 125
Stalking, including online6 months to 2 yearsTCK Art. 123/A
Blackmail1 to 3 years and a judicial fineTCK Art. 107

Account Freezes in Fraud and Cyber Crime Files: Timelines

MeasureWho decidesTime limitsLegal basis
Suspension by the bank, payment or crypto providerThe financial institutionUp to 48 hours; reported to the prosecutor immediately; account holder informedCMK Art. 128/A(1)-(2)
Application to lift the suspensionProsecutorDecision within 24 hoursCMK Art. 128/A(2)
Seizure of proceeds during the suspensionJudge; prosecutor's written order in urgent casesOrder submitted to a judge within 24 hours; decision within 48 hours, otherwise liftedCMK Art. 128/A(4)
Return of proceeds to the victimProsecutor or courtDuring the investigation or trial, once ownership is establishedCMK Art. 128/A(5)
Information requests to banks and crypto providersProsecutor, judge or courtAnswer within 10 daysCMK Art. 128/A(7)
MASAK transaction suspensionMinister, who may delegate to a deputy minister7 business daysLaw No. 5549, Art. 19/A
Objection to a judge's seizure decisionThe reviewing judge or court2 weeks from learning of the decisionCMK Art. 268

Digital Evidence in Turkey: Types and How They Are Used

EvidenceHow it is usually obtainedPoints to noteLegal basis
Screenshots and screen recordingsBy the person concerned, showing URL, date and accountElectronic data is a document; unlawfully obtained evidence is disregardedHMK Arts. 199 and 189/2
Notarised determinationA notary records the state of a page or postFixes the content on a given dateNotaries Law No. 1512, Art. 61
Court evidence determinationCourt-ordered inspection or expert examinationAvailable before or during a case where evidence may be lostHMK Art. 400
Documents with a secure e-signatureSigned with a qualified electronic certificateSame effect as a handwritten signature, with exceptionsLaw No. 5070, Art. 5; HMK Art. 205
Device search and copyingJudge's decision, or prosecutor's order in urgent casesCopy of the backup given to the suspectCMK Art. 134
Bank, payment and crypto recordsRequest by the prosecutor, judge or courtInstitution answers within 10 daysCMK Art. 128/A(7)
Traffic data such as IP recordsHeld by hosting providersKept for 1 to 2 years under the regulationLaw No. 5651, Art. 5/3

Matters Handled in This Area

  • Managing data protection compliance and drafting privacy notices
  • VERBİS registration and data controller representative arrangements for foreign companies
  • Cross-border data transfer structures, standard contracts and Board notifications
  • Data breach notifications and proceedings before the Personal Data Protection Board
  • KVKK requests to data controllers and complaints to the Board
  • Lawsuits against KVKK administrative fines
  • Complaints and defence in cybercrime matters (system intrusion, data corruption, etc.)
  • Content removal and access-blocking requests for online violations of personality rights
  • Privacy applications for intimate images and personal details published online
  • Personality-rights actions, interim injunctions and compensation claims for online content
  • Legal support in social media account breaches and digital fraud
  • Objections concerning bank and crypto account suspensions and seizures
  • Counsel on e-commerce and distance-selling contracts
  • Preservation of digital evidence through notaries and court evidence determination
  • Managing the legal process following a cyberattack or data theft

Frequently Asked Questions

How can I have content about me removed from Turkish websites or social media?

For content that violates a person's privacy, an application can be made to the Cyber Security Presidency for access blocking, and the applicant takes the request to the criminal judge of peace within 24 hours (Law No. 5651, Article 9/A). For defamation and other violations of personality rights, Article 9 of Law No. 5651 has not been in force since 10 October 2024; a notice to the platform, a criminal complaint and an action under Articles 24-25 of the Civil Code with an interim injunction and compensation claims are considered instead.

Can I still apply to a criminal judge of peace to remove a defamatory post in Turkey?

Not under the old Article 9 procedure. The Constitutional Court annulled Article 9 of Law No. 5651 (decision of 11 October 2023), and the annulment took effect on 10 October 2024. The criminal judge of peace route remains only for privacy violations under Article 9/A. Defamatory content is now pursued mainly through the civil courts.

Someone posted my private photos online in Turkey. What does the law provide?

Article 9/A of Law No. 5651 allows a direct application to the Cyber Security Presidency with the URL, an explanation of the privacy violation and identity information. Access providers apply the block within four hours, the applicant submits the request to a criminal judge of peace within 24 hours, and the judge decides within 48 hours. Disclosing images of private life is also an offence punishable by two to five years (TCK Article 134/2).

Who receives privacy applications under Law No. 5651 now, BTK or the Cyber Security Presidency?

Since Law No. 7590 of July 2026, Law No. 5651 refers to the Cyber Security Presidency (Siber Güvenlik Başkanlığı) as the Presidency. Applications under Article 9/A that used to be made to the Information and Communication Technologies Authority (BTK) are now made to the Presidency.

Do social media platforms have to respond to complaints from users in Turkey?

Social network providers with more than one million daily accesses from Turkey answer applications concerning content under Articles 9 and 9/A within 48 hours, giving reasons for a negative answer (Law No. 5651, Additional Article 4/3). Foreign-based providers of that size also appoint a representative in Turkey (Additional Article 4/1).

Is a platform liable if it does not remove content after a court decision?

Yes. Where a judge or court has found content unlawful and the decision is notified to a social network provider, a provider that does not remove the content or block access within 24 hours is liable for the resulting damage, and the injured person does not have to pursue the content provider first (Law No. 5651, Additional Article 4/14).

Is online insult a crime in Turkey, and how long is there to complain?

Yes. Insult, including by written, voice or video message, is punishable by three months to two years' imprisonment or a judicial fine (TCK Article 125). It is prosecuted on complaint, filed within six months of learning of the act and the offender and, for insult, at most two years after the act (Article 73). Most forms fall within advance payment (Article 75).

Can I sue someone in Turkey for defamation if I live abroad?

Turkish courts' international jurisdiction follows the domestic venue rules (MÖHUK Article 40). A personality-rights action can be filed at the claimant's or the defendant's domicile (TMK Article 25), and tort claims also where the act was committed or the damage occurred (HMK Article 16). The case can be followed through a Turkish lawyer acting under a power of attorney.

Which law applies to an online defamation claim involving Turkey and another country?

At the injured person's choice: the law of his or her habitual residence or of the country where the damage occurred, if the wrongdoer could have known the damage would occur there, or the law of the wrongdoer's place of business or habitual residence (MÖHUK Article 35). The same rule applies to violations through the processing of personal data.

Does KVKK apply to my foreign company?

KVKK applies to those who process personal data of natural persons (Article 2) and has no separate territorial-scope article like the GDPR, so the answer depends on the facts, such as data collected from people in Turkey or transferred from a Turkish entity. Foreign data controllers that register with VERBİS do so through a representative in Turkey.

Is KVKK the same as the GDPR?

No. KVKK follows European principles but differs in practice: a public registry (VERBİS) with Board-set exemptions, a 30-day answer period, a prior application to the controller before a Board complaint, breach notification to individuals without a high-risk threshold in the text, its own cross-border transfer system and fines in Turkish lira ranges.

Who has to register with VERBİS?

Data controllers register before processing unless exempted by the Board (KVKK Article 16). Under Board Decision No. 2018/87 as amended in 2025, controllers with fewer than 50 employees and a balance-sheet total below 100 million Turkish lira are exempt if their main activity is not processing special categories of data; if it is, the thresholds are 10 employees and 10 million Turkish lira.

Can personal data be transferred from Turkey to servers abroad?

Since 1 June 2024, a transfer abroad needs a processing condition plus either an adequacy decision of the Board, or an appropriate safeguard such as a standard contract, binding corporate rules or a written undertaking approved by the Board. Without either, only occasional transfers in listed cases are allowed (KVKK Article 9).

Is there a deadline for notifying the KVKK standard contract?

Yes. The data controller or processor notifies the standard contract to the Personal Data Protection Authority within five business days of signature (KVKK Article 9/5). Failing to do so is a separate ground for an administrative fine (Article 18/1-d).

How can I ask a company to delete my personal data?

Under Article 11 of KVKK, the data subject can apply to the data controller in writing, or by any other method determined by the Board, to request deletion of the data. The data controller concludes the request within thirty days at the latest (Article 13); if the answer is negative, insufficient or not given in time, a complaint can be filed with the Board within thirty days of the answer and at most sixty days from the application (Article 14).

What happens if the KVKK Board does not answer my complaint?

If the Board does not answer within sixty days of the complaint, the request is deemed rejected (KVKK Article 15/4). Where the Board finds a violation, it orders the controller to remedy it, and the controller complies within thirty days of notification (Article 15/5).

When must a data breach be notified under the data protection law?

The law requires notification to the persons concerned and to the Board as soon as possible (KVKK Article 12/5). Under the Board's Decision No. 2019/10, the Board is notified without delay and at the latest within 72 hours of learning of the breach, and affected individuals within the shortest reasonable time. Information can be completed in stages, and a late notification explains the reasons for the delay.

What are the KVKK fines in 2026?

Article 18 sets ranges for failures to inform, data security failures, ignoring Board decisions, registry breaches and standard contract notification. The ranges are updated every year, so a fixed figure is not given here; the current ranges can be checked with the KVKK fine lookup calculator on this site.

Our company received a KVKK fine from the authority in Ankara. Can a data protection lawyer in Istanbul challenge it?

Yes. Since 1 June 2024, KVKK fines are challenged before the administrative courts (KVKK Article 18/3), within the general sixty-day period from notification (İYUK Article 7), as a rule at the court where the Board is located in Ankara. A data protection lawyer in Istanbul or anywhere in Turkey registered with a Turkish bar can file the case through UYAP.

Is sharing someone's personal data without permission a crime in Turkey?

It can be. Unlawfully giving personal data to another person, spreading it or obtaining it is punishable by two to four years' imprisonment (TCK Article 136), and unlawfully recording personal data by one to three years (Article 135). These offences are prosecuted ex officio, without a complaint (Article 139).

What offence is committed if my social media account is hacked?

Unauthorised access to a social media account may constitute unlawful access to an information system, punishable by up to one year or a judicial fine, or six months to two years where data is destroyed or altered (TCK Article 243). Where the account is then used to commit fraud, the qualified fraud provisions (Article 158/1-f) may also apply.

What is the penalty for online fraud in Turkey?

Fraud using information systems, banks or credit institutions is punishable by three to ten years' imprisonment and a judicial fine; the minimum prison term is four years and the fine cannot be less than twice the benefit obtained (TCK Article 158/1-f and last sentence). Theft through information systems is punishable by five to ten years (Article 142/2-e).

Is ransomware or deleting someone's data a crime in Turkey?

Yes. Damaging, deleting, altering or making data inaccessible is punishable by six months to three years (TCK Article 244/2), hindering or disrupting a system by one to five years (Article 244/1), and obtaining an unjust benefit through such acts by two to six years and a judicial fine (Article 244/4). Penalties increase by half for bank and public-body systems.

What is the penalty for misusing someone's bank card in Turkey?

Using another person's bank or credit card without consent to obtain a benefit is punishable by three to six years' imprisonment and a judicial fine of up to 5,000 days (TCK Article 245/1). Using a fake or falsified card carries four to eight years (Article 245/3).

My bank account was frozen in an online fraud investigation in Turkey. How long can the bank keep it suspended?

A bank, payment service provider or crypto-asset service provider can suspend an account used in listed fraud, theft or card offences for up to 48 hours and reports this to the prosecutor immediately. The account holder can apply to the prosecutor, who decides within 24 hours; seizure beyond that needs a judge's decision (CMK Article 128/A). MASAK suspensions (seven business days) and court seizures follow other rules.

Is a foreign crypto exchange legal for people in Turkey?

Crypto-asset service providers need the Capital Markets Board's permission (Law No. 6362, Article 35/B). A foreign platform targeting residents of Turkey, for example with a Turkish website or local promotion, counts as unauthorised (Article 99/A), and unauthorised activity is punishable by three to five years (Article 109/A). Disputes with platforms are subject to the general provisions.

How long is the right of withdrawal in an online purchase in Turkey?

A consumer can withdraw from the contract within fourteen days, without giving any reason (Law No. 6502, Article 48/4). If the seller did not properly inform the consumer of this right, the fourteen-day period does not apply, but the right ends one year after the end of the withdrawal period. Goods made to the consumer's specifications and perishable items are among the exceptions.

Are screenshots accepted as evidence in Turkish courts?

Electronic data, images and recordings are documents under HMK Article 199, so screenshots can be submitted, and their weight depends on how reliably they show the content, date and account. Notarised determination (Notaries Law, Article 61) or court evidence determination (HMK Article 400) is used where the authenticity of online content may be disputed. Unlawfully obtained evidence is not taken into account (HMK Article 189/2).

Can I file a cybercrime complaint in Turkey without travelling there?

Yes. A complaint can be filed with the prosecutor through a Turkish lawyer acting under a power of attorney (CMK Article 158), and for offences committed through information systems, banks or cards the courts of the victim's residence in Turkey are also competent (Article 12/6). For offences committed abroad that must be prosecuted in Turkey, Turkish consulates also accept complaints (Article 158/3).

Can I get an English-speaking IT lawyer in Turkey for a data protection or cybercrime matter?

Yes. Our office advises English-speaking individuals and businesses on KVKK compliance and represents clients in cybercrime, online content and account-freeze matters in Turkey, as an IT lawyer in Istanbul following files in other cities as well.

Who handles IT and data protection matters at the office, and in which languages?

Av. Ömer Faruk Doğan holds an IELTS score of 7, pursued graduate legal studies and research in Italy and Poland, and has experience advising international companies on Turkish data protection and technology matters. Clients can be advised in English as well as Turkish.

Do I need a separate cybercrime lawyer in Ankara if the case is heard there?

No. Cybercrime cases are heard where the offence was committed, and for offences through information systems or banks also at the victim's residence (CMK Article 12). A cybercrime lawyer in Turkey registered with a Turkish bar can act before all courts; the office is in Istanbul and follows files in Ankara through UYAP, attending hearings as needed.

How much does an internet or data protection case cost in Turkey?

It depends on the work involved: court fees, expert fees, notary and translation costs and the lawyer's fee. Lawyers' fees cannot be below the minimum tariff prepared by the Union of Turkish Bar Associations (Attorneyship Law, Articles 164 and 168), and the fee is agreed in writing before work starts.