International Legal Advice

Are you looking for a law firm with international expertise? GEMS Schindhelm supports you with its international teams, providing competent, committed, and hands-on legal advice backed by valuable local experience. Find out more online about a wide range of topics in international business law.

 

Cybersecurity Law in Turkey: Law No. 7545

With the Cybersecurity Law No. 7545, in force since 19 March 2025, Turkey has for the first time created a self-standing, cross-sectoral cybersecurity regime. The law establishes a central authority in the Cybersecurity Presidency, subjects companies to notification, cooperation and security duties, tightens the requirements for operators of critical infrastructure and introduces substantial fines and prison sentences. It is thus in line with international developments such as the European NIS-2 Directive – but takes its own, sometimes stricter, paths on individual points. Companies with IT operations in Turkey should adjust their security and compliance organisation to the new regime..

Table of contents

  • What does the law regulate and to whom does it apply?
  • What are the tasks of the Cybersecurity Presidency and the Cybersecurity Council?
  • What obligations apply to all companies concerned?
  • What additional obligations apply to critical infrastructure?
  • What applies to audits, service providers and product certification?
  • What sanctions apply?
  • How does the law relate to the KVKK, Law No. 5651 and sectoral supervisory law?
  • How does Law No. 7545 compare with the NIS-2 Directive?
  • What should companies do now?
  • How are employee-caused data breaches assessed in practice?
  • Conclusion

What does the law regulate and to whom does it apply?

Law No. 7545 frames cybersecurity as a task of the state as a whole and covers far more than critical infrastructure in its scope: it applies to public institutions and – with graduated obligations – to legal and natural persons who provide services, operate systems or process data in cyberspace. In principle, therefore, any company with IT-based business operations in Turkey can be within scope; the focus of the operational duties lies with service providers and the critical sectors determined by the Cybersecurity Council. The detailed rules are being developed step by step through the new Presidency's secondary legislation – the legal situation is thus dynamic and should be monitored continuously.

What are the tasks of the Cybersecurity Presidency and the Cybersecurity Council?

The central authority is the Cybersecurity Presidency ("Siber Güvenlik Başkanlığı"), directly attached to the President of the Republic, which develops strategies and standards, coordinates incidents, conducts audits, certifies service providers and products, and steers the national and sectoral incident response teams (the SOME/USOM structure). Alongside it, the Cybersecurity Council ("Siber Güvenlik Kurulu"), chaired by the President of the Republic, sets the policy guidelines and decides on the classification of critical infrastructure sectors. For companies, the Presidency will henceforth be the central point of contact – from incident notification to certification.

What obligations apply to all companies concerned?

  • Provision of information: upon request, the data, documents and system information required for its tasks must be transmitted to the Presidency – a far-reaching cooperation duty whose implementation requires internal responsibilities and review processes.
  • Immediate notification of cyber incidents and identified vulnerabilities to the competent bodies, and adoption of the necessary countermeasures.
  • Implementation of the security standards, guidelines and measures determined by the Presidency, including the principles of secure development and procurement.
  • Toleration of and support for audits; for certain providers: commencement of activity only with the prescribed authorisations and certificates.

A reputation-relevant criminal offence also deserves emphasis: whoever falsely claims that a data leak has occurred and disseminates such content commits a criminal offence – conceived as protection against scaremongering, but in practice also requiring careful attention when communicating about real or suspected incidents. Crisis communication after security incidents therefore belongs imperatively in legally supervised channels.

What additional obligations apply to critical infrastructure?

Following its meeting of May 2026, the Cybersecurity Council officially determined fifteen critical infrastructure sectors: digital infrastructures, digital services, electronic communications, energy, finance, food and agriculture, manufacturing industry, public services, media and crisis communication, post and cargo, health, defence industry, water management, transport and space. Operators in these sectors face tightened requirements: the establishment of their own or connection to sectoral incident response teams (SOME), regular vulnerability analyses and penetration tests, the prioritisation of domestic and national products in security-relevant procurement, and special notification and audit regimes. Transactions can also become relevant: for certain transfers of shares and control in cybersecurity companies, the law provides for authorisation requirements of the Presidency – a point that should be examined early in M&A transactions in the technology sector.

What applies to audits, service providers and product certification?

The Presidency can conduct audits itself or through commissioned, authorised bodies; the audited companies must grant access, records and support. Providers of cybersecurity services and products are subject to authorisation, certification and standardisation requirements under the secondary legislation; violations can lead to withdrawal of the authorisation in addition to fines. For foreign security vendors with Turkish business, this creates a distinct market access regime whose development – including possible localisation expectations – should be followed.

What sanctions apply?

The law combines criminal and administrative offence law: prison sentences are provided, among other things, for providing services subject to authorisation without authorisation, for breaches of confidentiality and data duties, for attacks on elements of critical infrastructure – here the ranges reach up to twelve years – and for the aforementioned dissemination of false data leak claims. Administrative fines target in particular breaches of the notification, information and audit cooperation duties; under the law they reach amounts in the millions of lira and can additionally be assessed by reference to turnover for companies. The consistent sanctioning underscores that this is not "soft" programmatic law but hard supervisory law.

How does the law relate to the KVKK, Law No. 5651 and sectoral supervisory law?

The Cybersecurity Law stands alongside the existing regimes and does not displace them: data breaches involving personal data remain additionally notifiable under the KVKK – a single incident may thus require parallel notifications to the Presidency and the Data Protection Authority, whose deadlines and contents must be coordinated. Internet law duties under Law No. 5651, the sectoral security regimes – such as banking supervision with its strict outsourcing and localisation rules, or telecommunications supervision – and the general IT offences of the Criminal Code continue to apply. Compliance organisations should therefore consolidate the notification paths in an integrated incident response plan.

How does Law No. 7545 compare with the NIS-2 Directive?

For European groups already aligning their security organisation with the NIS-2 Directive, a structural comparison is worthwhile: both regimes combine incident notifications, risk management duties and substantial sanctions, and cover large parts of the economy. The Turkish law, however, goes its own way – supervision is centralised in a single authority attached to the presidency rather than distributed sectorally; the duty to give priority to domestic and national products in critical infrastructure has no equivalent in the EU framework and affects foreign vendors directly; the criminal offence of false data leak claims is internationally unusual; and market access and transaction controls for cybersecurity companies go beyond the European model. In practical terms: NIS-2-compliant group programmes provide a good technical basis but must be supplemented for Turkey with the specific notification, authorisation and procurement requirements – a mere extension of EU directive compliance is not enough.

What should companies do now?

  • Impact analysis: assess the law's applicability to the company's own services and possible classification as critical infrastructure; monitor secondary legislation continuously.
  • Update the incident response plan: integrate notification paths to the Presidency, USOM and the Data Protection Authority with deadlines, responsibilities and communication approvals.
  • Security standards and evidence: map existing certifications (such as ISO 27001) against the forthcoming Turkish standards; document test and audit cycles.
  • Adapt contracts: include notification and support duties, standard conformity and audit rights in IT, cloud and security service provider agreements.
  • Communication discipline: establish internal approval processes for every public statement on security incidents – with a view to the criminal offence of false leak claims.
  • For M&A in the tech sector: include authorisation requirements for transactions with a cybersecurity dimension in due diligence.

How are employee-caused data breaches assessed in practice?

The judgment of the Court of Cassation (9th Civil Chamber, judgment of 20 January 2025, E. 2024/13450, K. 2025/700) makes clear that not every employee error leading to a data incident supports summary dismissal by itself. In the specific case, an employee of a financial company had mistakenly generated and forwarded the account statement of another customer; the employment relationship was terminated under social security exit code 49. The employer, however, could not prove that the employee had knowingly violated the data security rules, had previously been warned, or had persistently refused to fulfil his duties. The first-instance court, the Regional Court of Appeal and the Court of Cassation therefore held that the dismissal could not be classified under code 49 and that the exit code had to be corrected.

The decision shows that security and data breaches frequently originate not from company management but from carelessness or a lack of awareness among employees – while the legal and administrative responsibility remains overwhelmingly with the company as controller. It is therefore not enough to adopt policies: companies should include data protection and security clauses in employment contracts, obtain confidentiality and data protection undertakings from employees, and provide regular training in particular to staff handling personal data. In the compliance projects we run for our clients, we observe that this preventive approach considerably reduces both the risk of data incidents and the potential for employment and customer-related disputes.

Conclusion

With Law No. 7545, Turkey has transformed cybersecurity from a scattered sectoral subject into a centrally supervised field of law with its own authority, hard sanctions and a broad scope. Notification and cooperation duties also apply to companies outside critical infrastructure; the detailed requirements are emerging continuously through secondary legislation.

Companies operating IT-based businesses in Turkey should analyse their exposure now, set up incident response and notification paths in an integrated manner and institutionalise the monitoring of regulatory developments – the law is young, supervisory practice is taking shape, and early compliance is considerably cheaper than late retrofitting under the pressure of sanctions.

The IP/IT team at GEMS Schindhelm advises companies on implementing the Cybersecurity Law No. 7545 – from impact analysis through incident response and notification processes to contract drafting and representation before the Cybersecurity Presidency.