TMT 2026

Last Updated February 19, 2026

Turkey

Law and Practice

Authors



Özay Law Firm offers high-quality legal services specifically tailored to the dynamic requirements of the modern business world. With a strong commitment to both commercial perception and immediate action, the firm provides effective, concrete legal solutions for local and multinational companies operating across Türkiye. Its team of specialised and collaborative attorneys offer comprehensive consultation and dispute resolution services. Özay Law Firm prides itself in its ability to manage complex projects, ranging from TMT, mergers and acquisitions to real estate development, both simultaneously and on short notice. Professional services are available in Turkish, English, and French. The firm combines academic rigour with practical application, ensuring a balance between theory and practice. Through an online document follow-up system, clients maintain full transparency, monitoring every stage of their case in real-time. Özay Law Firm transforms academic knowledge into actionable results for clients. The firm is composed of approximately 70 professionals.

Türkiye regulates the digital economy through sector-specific regimes, principally covering e-commerce, consumer protection, advertising, electronic communications, cybersecurity, data protection, crypto-assets and payment services.

E-Commerce

The principal legislation governing e-commerce activities and the sending of commercial electronic communications in Türkiye is Law No. 6563 on the Regulation of Electronic Commerce and its secondary legislation.

Following 2022 amendments, the Law imposes detailed obligations on service providers and intermediary service providers, alongside commercial electronic communications rules. The amended framework regulates online marketplaces through seller-agreement requirements, ranking and recommendation transparency, unfair-practice prohibitions and scale-based licensing obligations.

Commercial electronic communications are subject to consent, content and opt-out rules, with consents and withdrawals managed through the Message Management System (İYS).

Consumer Protection

Seller, platform and consumer relationships are primarily governed by Law No. 6502 on Consumer Protection and its secondary legislation. This framework covers distance sales terms, pre-contractual information, withdrawal and return rights, after-sales services and warranties.

Product Safety

Products sold through distance channels are subject to Law No. 7223 on Product Safety and Technical Regulations and its implementing legislation. Platform and seller obligations on product compliance, traceability and market surveillance should be assessed together with consumer protection and e-commerce rules.

Although Türkiye continues to align product safety rules with EU legislation, the existing framework remains the primary compliance basis.

Personal Data Protection

Personal data processing in the digital economy is primarily governed by Law No. 6698 on Personal Data Protection (KVKK) and its secondary legislation. The KVKK regulates controller and processor obligations, data security and cross-border transfer mechanisms. The 2024 KVKK amendments revised special-category data rules and introduced new transfer mechanisms, including standard contractual clauses, moving the regime closer to the EU model.

Advertising Law

Digital advertising is primarily regulated by Law No. 6502 on Consumer Protection and the Regulation on Commercial Advertising and Unfair Commercial Practices. Digital advertising must be accurate, transparent and not misleading, and is subject to regulatory oversight. Influencer marketing, personalised advertising, subscription models and dark patterns are current enforcement priorities.

Internet and Online Content Regulation

Law No. 5651 is the main online content law and imposes obligations on content, hosting, access and social network providers. Recent amendments impose additional obligations on social network providers, including appointing a local representative, publishing transparency reports, complying with content-removal requests and responding to certain administrative and judicial orders.

Domain names are another key component. The allocation and administration of ".tr" domain names are handled through TRABİS (".tr" Network Information System) and supervised by the Information and Communication Technologies Authority (BTK). Domain name disputes, particularly those involving trademarks or unfair use, may be resolved by authorised dispute resolution providers within the TRABİS framework.

Electronic Communications

Law No. 5809 on Electronic Communications regulates network and service authorisation, operator obligations and sector-specific data-processing rules. Operators are also subject to specific obligations on data protection, traffic data and confidentiality of communications, and must comply with national security, public order and lawful interception requirements where applicable.

Law No. 6112 and the online broadcasting regulation impose licensing and authorisation requirements on certain online broadcasting services, including VOD, internet radio and similar media services. On-demand audiovisual media providers such as Netflix, Disney+, BluTV and Exxen, and certain other online broadcasting platforms, may fall under the oversight of the Radio and Television Supreme Council (RTÜK).

Crypto-Assets

The first crypto-asset regulation was the Central Bank's 2021 Regulation on the Disuse of Crypto Assets in Payments, which prohibits using crypto-assets as a means of payment.

Law No. 7518 amended the Capital Markets Law in 2024 to establish Türkiye’s core crypto-asset regime and rules for crypto-asset service providers. Crypto-asset service providers are subject to authorisation, operational, governance and compliance obligations, with secondary legislation developing under the Capital Markets Board.

Payment Services and Digital Banking

Law No. 6493 regulates payment systems, payment services and electronic money institutions, including licensing, operational and compliance requirements.

Türkiye has also introduced frameworks governing open banking, Banking as a Service and digital banking, establishing the legal infrastructure for new digital business models in the banking and payments ecosystem. The framework now covers API-based financial services, account information services and payment initiation services.

Cybersecurity

The Cybersecurity Law No. 7545 establishes the principal legal framework for ensuring cybersecurity, preventing cyber threats, and protecting critical infrastructure and critical public services in Türkiye.

The 2025 law sets general cybersecurity obligations and supervisory powers, with secondary legislation expected to define sector-specific requirements, especially for critical infrastructure and essential services.

Artificial Intelligence

Türkiye has not yet adopted a comprehensive and directly applicable legislative framework for artificial intelligence comparable to the European Union's AI Act. AI systems are currently assessed under existing regimes, including data protection, consumer protection, product safety, cybersecurity, IP, e-commerce and sector-specific rules.

The principal legal challenge is generally not the absence of regulation, but the simultaneous application of multiple regimes and authorities to the same activity. Businesses must often manage overlapping e-commerce, data protection, consumer, advertising, content, payments, capital markets and cybersecurity obligations when designing digital products and services.

Cross-Border Personal Data Transfers

The 2024 amendments to Law No. 6698 significantly revised Türkiye's cross-border transfer regime, introducing a standard contractual clauses mechanism aligned more closely with the EU approach.

In practice, global technology companies may resist Turkish-law standard contractual clauses, so some cross-border transfer projects still face implementation difficulties despite a clearer legal basis.

Protection of Children and Age Verification

Child protection and age verification remain developing areas, with uncertainty around technical methods, platform responsibility and user privacy safeguards.

Crypto-Asset Service Providers

Crypto-asset service providers and custodial institutions face comprehensive licensing and compliance requirements. Minimum capital, corporate governance, custody infrastructure and internal control/risk management obligations may impose significant investment and compliance costs on domestic and foreign entrants.

Digital services and products are taxed under the general tax regime, VAT, digital services tax and, where applicable, withholding tax.

Digital services tax is governed by Law No. 7194 and applies to revenue from digital advertising, the sale of digital content, digital platform services and related intermediation. As of 1 January 2026, the rate is 5%.

VAT obligations may also arise for electronically supplied services, and non-resident providers may, in certain conditions, have to register for VAT and file in Türkiye. In practice, non-resident providers in particular must analyse whether a registration obligation arises, whether the service is deemed to be used or benefited from in Türkiye, and under which regime platform revenues fall.

Digital advertising services may also give rise to withholding tax obligations. Payments to persons providing internet advertising services, or acting as intermediaries, may be subject to withholding tax depending on the provider's status and characteristics.

Key compliance issues are:

  • service classification;
  • provider status; and
  • the tax treatment of cross-border arrangements among advertisers, agencies and platforms.

Digital advertising revenue may also fall within Digital Services Tax, so companies in the ecosystem often must assess withholding tax, VAT and Digital Services Tax obligations simultaneously.

The principal consumer protection legislation for digital products and services is Law No. 6502 on Consumer Protection, supplemented by the Regulation on Distance Contracts, the Regulation on Commercial Advertising and Unfair Commercial Practices and various secondary regulations.

E-commerce, platforms, apps, digital content and subscriptions must provide pre-contractual and mandatory information, transparent ordering and protection against unfair practices.

TMT companies should use clear terms, notices and support processes, with transparent pricing, renewal, cancellation, subscription and in-app purchase disclosures.

Consumer disputes are resolved through Consumer Arbitration Committees and Consumer Courts, with the forum depending on the monetary value of the dispute. The Ministry of Trade also holds supervisory and enforcement powers over consumer transactions and e-commerce.

Best practices include accessible support, prompt complaint handling, clear return and cancellation rules, adequate records and effective seller-consumer communication tools for platforms.

The liability regime for online marketplaces is set for a significant shift. By the decision dated 12 February 2026 (Case No. 2024/187 E., 2026/42 K.), the Constitutional Court annulled two provisions that had shielded intermediary service providers from consumer liability:

  • Article 48/6(d) of Law No. 6502 on Consumer Protection; and
  • Article 9/1 of Law No. 6563 on the Regulation of Electronic Commerce, a cornerstone of the platforms' “safe harbour”.

The Court held that platforms are no longer passive intermediaries, given their active role in seller onboarding, product listing, payment processing and ranking algorithms, and that blanket immunity is incompatible with consumer protection. The annulment does not impose automatic liability but removes the statutory bar, allowing courts and arbitration committees to assess platform responsibility case by case. It takes effect on 2 March 2027, by which date new legislation balancing consumer protection against the digital economy is expected.

Blockchain and crypto-assets are developing in Türkiye, particularly in fintech, digital assets, payments, digital identity and supply-chain applications. Türkiye's approach has evolved significantly; the Central Bank prohibited crypto-assets as payments in 2021, and 2024 amendments to the Capital Markets Law established the core framework for crypto-asset service providers and granted regulatory authority to the Capital Markets Board.

Key unresolved issues include cross-border transactions, asset protection, custody, AML, cybersecurity, smart contracts, DeFi, tokenisation and Web3 applications.

As noted in 1.2 Key Challenges, the capital, governance, internal control and compliance requirements on crypto-asset service providers and custodial institutions are extensive and may impose significant costs on domestic and foreign entrants.

Türkiye has no standalone cloud law; cloud and edge computing are regulated through data protection, cybersecurity, electronic communications, financial-sector, insurance and outsourcing rules, requiring assessment of data, continuity and audit-access issues.

For cloud processing of personal data, Law No. 6698 requires role analysis, data-processing terms, security measures, retention/deletion rules and cross-border transfer compliance, especially where global providers use foreign data centres or sub-processors.

More stringent requirements apply in regulated sectors. In banking, Banking Regulation and Supervision Agency (BRSA or BDDK) rules impose specific obligations on information systems, outsourcing, primary/secondary systems, business continuity, audit access and risk management. Banks may use cloud services, but private and community cloud models, domestic system requirements and BRSA expectations for critical systems warrant particular attention.

Cloud use by payment and electronic money institutions are also subject to specific Central Bank conditions. Under the relevant guidance, such institutions may procure cloud services established within Türkiye as an outsourced service, but additional scrutiny applies where personal, sensitive customer or competition-sensitive data are involved.

Cloud services in insurance, financial services, electronic communications and other critical-infrastructure sectors should likewise be assessed against outsourcing, data security, retention, access, audit and business continuity obligations. The Cybersecurity Law No. 7545 raises expectations on cyber resilience and incident management, particularly for critical infrastructure operators and service providers.

From a data protection perspective, the most significant issues relating to cloud and edge computing concern the location of data storage, the countries from which data may be accessed, the use of sub-service providers, log management practices, access control mechanisms, encryption measures, data deletion procedures and data breach notification processes.

Companies using cloud or edge computing in Türkiye, particularly in regulated sectors, should therefore assess not only personal data protection but also sector-specific outsourcing rules, cybersecurity, cross-border transfer and audit-access obligations.

AI Laws, Regulations, and Codes of Conduct

Türkiye does not yet have a single, comprehensive AI statute equivalent to the EU AI Act. The current framework is therefore fragmented and technology-neutral. AI systems are mainly assessed under the Personal Data Protection Law No. 6698, the Turkish Civil Code, Turkish Code of Obligations, Turkish Criminal Code, Industrial Property Law, Law on Intellectual and Artistic Works, Internet Law No. 5651, the Highway Traffic Law and civil aviation legislation. Key soft-law instruments include the National Artificial Intelligence Strategy 2021–2025 and Personal Data Protection Authority (DPA) guidance on AI, deepfakes, chatbots and generative AI. 

Türkiye also does not have a single AI regulator; sectoral regulators such as the DPA, BTK, Banking Regulation and Supervision Agency, Capital Markets Board, Competition Authority and Human Rights and Equality Institution may supervise AI use within their respective remits.

From a data protection perspective, AI systems must observe the general principles of lawfulness, fairness, accuracy, purpose limitation, data minimisation, storage limitation, security and accountability. The DPA's generative AI guide stresses that AI processing is not prohibited per se, but each activity needs a valid legal basis under Articles 5 or 6 of Law No. 6698. Anonymous data falls outside the law, but only where genuinely and irreversibly anonymised; the anonymisation process itself remains subject to data protection rules.

AI supply chains require careful controller/processor allocation, Article 9 compliance for foreign service providers and transparent Article 10 notices, particularly for automated decision-making. 

Deepfakes have no dedicated statute, but existing law offers several layers of protection. Unauthorised use of a person's face, voice, image or digital identity may infringe personality rights under Articles 24 and 25 of the Civil Code, allowing claims for prevention, cessation, declaration of unlawfulness and compensation. Article 86 of the Law on Intellectual and Artistic Works protects photographs and portraits even where they are not copyright works, requiring consent for disclosure or publication. Deepfakes may also trigger criminal liability for breach of privacy or unlawful recording, transfer or dissemination of personal data under the Criminal Code. Proposed transparency rules for AI-generated content, including labelling and sanctions for misleading synthetic content, remain draft mechanisms until enacted.

There is no bespoke autonomous-vehicle statute, so transport liability is assessed under existing regimes. For autonomous road vehicles, Article 85 of the Highway Traffic Law is central: the operator and, where applicable, its connected undertaking may be jointly and severally liable for damage from the vehicle's operation. For drones and other unmanned aerial vehicles, civil aviation rules apply, including registration, certification/permission and operational requirements under the SHT-İHA framework. Under the Civil Aviation Law, the operator may be strictly liable to third parties. Insurance is therefore key, but the treatment of autonomous systems, including recourse against software developers or manufacturers, remains an unresolved grey area.

Intellectual property law is also human-centred. Fully autonomous AI outputs are unlikely to attract copyright, since Turkish law requires a work bearing the author's personal characteristics, and case law links authorship to human creative contribution; where AI is merely a tool and the user makes substantial creative choices, protection may attach to the human contribution. Using copyrighted works for model training may raise infringement risks in the absence of permission or a statutory exception. Patent law similarly assumes a human inventor, so AI-generated inventions are patentable only where a human is named as inventor and the statutory criteria are met.

Overall, AI governance relies on general liability, data protection, IP, criminal and sectoral rules, with key risks around accountability, opacity, bias, cybersecurity, transfers, likeness, privacy and constitutional rights.

Türkiye has no standalone IoT law; IoT is regulated through electronic communications, device registration, M2M/SIM and eSIM, cybersecurity and data protection rules.

For IoT devices using mobile networks, a key layer is the regime for devices with electronic identity information, such as IMEI-bearing devices, registered under the rules on electronic identity-enabled devices and the Mobile Device Registry System (MCKS). Imported, manufactured or otherwise lawfully registered devices must be white-listed to receive electronic communications services.

For SIM/eSIM-based IoT and M2M devices, failure to register, white-list or match devices may interrupt connectivity; blacklisting can also arise from illegal import, loss/theft, IMEI alteration, cloning, export, disposal, unregistered use or inactivity.

A key issue for IoT/M2M deployments is the one-year inactivity rule. The 12 October 2023 amendment shortened the previous seven-year threshold: a device may be blacklisted if, after its last signal, it receives no electronic communications service for one uninterrupted year, after which operators must cut its connection within 24 hours. This especially affects low-frequency devices such as trackers, smart meters, industrial sensors and backup devices that may stay silent for long periods.

A further layer applies to M2M subscriptions from 1 April 2026. Although the exact BTK Board Decision text is not in a publicly indexed source, market notices indicate M2M lines are now subject to a device-line pairing structure. M2M lines benefiting from the M2M tax regime should not be used in general-purpose communication or internet-access devices such as phones, smartphones, tablets, computers or smart watches. Certain devices, including FCT devices, routers, radios, cameras, modems and multi-modems, may require one-to-one IMEI–IMSI matching, while closed-purpose M2M/IoT devices such as meters, POS devices and vehicle tracking units may be managed through one-to-one matching and/or approved TAC lists. Push-to-Talk over Cellular and radio-type systems are particularly affected.

Türkiye takes a restrictive localisation approach to eSIM. For devices manufactured, imported or brought into Türkiye for use there, BTK Decision No. 2019/DK-TED/053 requires that remote programmable SIM modules be programmable only under Turkish operator control and that Turkish operator profiles be loadable in Turkey. The core eSIM subscription-management infrastructure and related data must also be established, controlled and kept in Turkey. This creates friction for cross-border IoT models relying on global SIM/eSIM architecture, foreign subscription management or permanent roaming.

For connected vehicles, 112-based in-vehicle emergency call (eCall) systems are assessed separately. Under BTK Decision No. 2018/DK-YED/27, where a SIM, eSIM or SIM-like module is used only for eCall, it must be obtained from Turkish operators or be programmable under their control; no subscription agreement is required, but operators must ensure the module can call and be called back by 112. Where the system combines eCall with value-added services (e.g., connected-car services, telematics, remote diagnostics, infotainment or tracking), it is treated more strictly: the module must be obtained from Turkish authorised operators or be programmable under their control, and subscription procedures must follow the applicable legislation. The decision confirms such systems do not fall within the ordinary M2M device and subscription category.

Communications secrecy and data protection are governed by the Electronic Communications Law and the sectoral privacy regulation, which apply to operators’ processing for electronic communications services, including corporate subscriptions.

Except where legislation or court decisions permit, operators must not listen to, record, store, interrupt or monitor communications without all parties' consent. They may process traffic/location data for limited operational purposes such as traffic management, interconnection, billing, fraud detection and dispute resolution. Broader uses such as marketing or value-added services generally require anonymisation or explicit consent. Third-party sharing of traffic or location data requires separate, informed consent covering recipient, purpose, duration and, where relevant, destination country.

Operators must also adopt technical and administrative security measures, retain access logs and consent records for prescribed periods, and bear the burden of proving that notices and consents were properly obtained. In the event of a personal data breach, notification may be required not only to the Turkish Data Protection Authority but also to affected subscribers/users.

Compliance Challenges

As noted in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection, IoT is regulated through multiple regimes, so deployments must be assessed under electronic communications, device registration, M2M matching, eSIM localisation, data protection, communications secrecy and cybersecurity rules.

As outlined in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection, the first practical challenge for mobile-connected IoT/M2M devices is device eligibility and continuity of connectivity. IMEI-bearing devices must be registered and white-listed; blacklisting may follow loss/theft, cloned or altered IMEIs, unregistered use, export/disposal or inactivity, and MCKS-registered devices may be disconnected after one uninterrupted year without service.

A second challenge is the M2M line/device matching structure described in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection. From 1 April 2026, deployments must be assessed by line type and by the device used, verifying whether it is a general-purpose device unsuitable for M2M tax-exempt use, one requiring IMEI–IMSI pairing, or a closed-purpose device managed through pairing and/or TAC-based approval — relevant for smart meters, POS devices, vehicle tracking units, cameras, modems, professional radios, Push-to-Talk over Cellular and industrial IoT equipment.

A third challenge is eSIM architecture (see 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection): the restrictive approach to devices manufactured, imported or brought into Türkiye — Turkish operator control, Turkish operator profiles and localised subscription-management infrastructure/data — may conflict with global IoT models using foreign eSIM infrastructure or permanent roaming.

Connected vehicles require separate assessment under BTK's eCall decision (see 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection): eCall-only modules need local operator control/programming but no ordinary subscription, while eCall combined with value-added services requires a locally controlled module, completed subscription procedures, servers in Türkiye and no transfer of personal data abroad without explicit consent. This is difficult for automobile manufacturers which must replace globally controlled cross-border SIM modules with local ones.

A further challenge is privacy classification. Although IoT data may appear technical, device identifiers, SIM/eSIM data, location and traffic data, usage logs, subscriber-linked telemetry and user/device profiles may qualify as personal data. Where the connectivity layer is provided by an electronic communications operator, stricter sector-specific privacy and communications secrecy rules apply in addition to Law No. 6698.

Import and distribution processes should capture non-traditional connected devices with IMEI/eSIM/mobile functions, since missed registration, matching or localisation requirements can cause connectivity loss, reconfiguration, replacement, customer claims and warranty costs.

Finally, IoT deployments should increasingly be assessed against Türkiye’s Cybersecurity Law No. 7545, which entered into force in March 2025. Secondary legislation is still developing, but companies in critical or sensitive sectors should already be building cyber incident governance, auditability, supplier controls and regulator-facing documentation into their IoT compliance model.

Governance Frameworks

IoT governance should cover the following workstreams:

  • Regulatory classification and connectivity - assess mobile connectivity, IMEI/electronic identity, import/manufacture/activation in Türkiye, SIM/eSIM use, roaming, foreign profiles and local M2M subscriptions. 
  • MCKS/IMEI lifecycle management - track registered devices, white-list status, IMEI integrity, user assignments, replacement/resale flows and reactivation, with periodic signalling for low-frequency devices. 
  • M2M pairing and TAC governance - track SIM/IMSI, IMEI, TAC codes, device categories, tariff eligibility and replacements across procurement, logistics, maintenance and support. 
  • eSIM and connected-vehicle review - before launch, review whether the eSIM architecture, profile loading, subscription management platform and related data flows comply with BTK’s remote programmable SIM rules. For connected vehicles, separately assess whether the system is eCall-only or combines eCall with value-added services.
  • Privacy and communications secrecy - map content, traffic, location, telemetry, subscriber/user and anonymised data, with separate notice/consent flows for sensitive uses and third-party transfers. 
  • Security-by-design and vendor governance - apply access control, encryption, logging, vulnerability management, patch governance, secure provisioning, incident response and supplier due diligence. Contracts with connectivity providers, cloud providers, device manufacturers, analytics providers and maintenance vendors should allocate responsibility for data protection, cybersecurity, lawful instructions, audit rights and sub-processing.
  • Incident and breach response- maintain procedures for notifying the Personal Data Protection Authority, affected subscribers/users and, where applicable, BTK or cybersecurity authorities.

Key Legal Requirements

Türkiye has no general IoT data-sharing statute; data sharing is governed by personal data transfer rules, electronic communications rules, communications secrecy, confidentiality, cybersecurity and sector-specific obligations.

Under Law No. 6698 on the Protection of Personal Data, sharing personal data with another party constitutes a transfer and requires a valid legal basis. Domestic transfers are assessed under the ordinary processing conditions and, for special categories of personal data, the stricter Article 6 regime.

Cross-border transfers are governed by the amended Article 9 framework. Transfers abroad may be made where an Article 5 or 6 condition exists and there is an adequacy decision. In the absence of any current adequacy decision, companies generally rely on appropriate safeguards — most commonly Turkish standard contractual clauses, binding corporate rules or other statutory mechanisms — subject to the applicable conditions and notification requirements.

For electronic communications operators, traffic and location data are subject to stricter rules. As noted in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection, third-party sharing typically requires separate, informed consent covering recipient, purpose, duration and, where relevant, destination country. Additionally, operators bear the burden of proving notices and consents were obtained.

Communications secrecy is stricter than ordinary data protection. As noted in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection, communications may not be listened to, recorded, stored, interrupted or monitored without all parties' consent unless legislation or court decisions permit. This is particularly relevant for IoT solutions involving voice, video, messaging, connected vehicles, smart home systems, emergency devices, workplace monitoring or remote surveillance.

Thresholds and Companies Subject to the Requirements

There is no general revenue, employee-number or device-number threshold that triggers IoT data-sharing obligations as such. The requirements apply based on role and activity:

  • Electronic communications operators are directly subject to sector-specific privacy, traffic/location data, communications secrecy, retention, security and consent rules when processing data in connection with electronic communications services.
  • IoT service providers, platform providers, device manufacturers, importers and enterprise deployers are subject to Law No. 6698 where they determine the purposes and means of processing personal data or process personal data on behalf of another party.
  • Processors and vendors may be indirectly bound through data processing agreements, operator contracts, cybersecurity obligations, audit rights and cross-border transfer mechanisms.
  • Companies using SIM/eSIM/mobile-network devices are indirectly affected by MCKS, IMEI registration, M2M pairing, TAC management, blacklisting, inactivity and eSIM localisation rules, even if they are not themselves electronic communications operators.
  • Critical or regulated sectors may face additional cybersecurity or sectoral governance obligations, especially after Cybersecurity Law No. 7545 and the developing critical infrastructure framework.

Heightened Requirements for Specific Categories of Data

Türkiye has heightened requirements for several categories of data relevant to IoT:

  • Special categories of personal data - biometric data, genetic data, health data, sexual life data, criminal conviction/security measure data, and certain data revealing race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance, association/foundation/union membership are subject to Article 6 of Law No. 6698. IoT examples may include biometric access systems, health wearables, telemedicine devices, driver monitoring systems or workplace safety sensors.
  • Traffic and location data - under the electronic communications sector regime, these are treated with heightened sensitivity, especially for third-party sharing, marketing and value-added services.
  • Communications content and communications secrecy - interception, recording, monitoring or storage of communications is subject to the strict all-party consent/statutory authorisation framework.
  • Cross-border data transfers - all personal data transfers abroad require compliance with the amended Article 9 transfer mechanism. This is especially important for IoT solutions using foreign cloud hosting, foreign analytics platforms, global device management systems or foreign eSIM/subscription management infrastructure.
  • Security-relevant and critical infrastructure data - IoT deployments in telecoms, energy, transport, healthcare, finance, public services and similar sectors may be treated as higher-risk from a cybersecurity and continuity perspective, even where the data is not personal data.

Türkiye regulates audiovisual media services under Law No. 6112 and the Regulation on the Online Presentation of Radio, Television and On-Demand Broadcasts; there is no separate "streaming" regime. The decisive question is whether the service qualifies as a radio, television or on-demand broadcasting service under a media service provider's editorial responsibility — i.e., whether the provider selects and organises programmes through a linear schedule or on-demand catalogue.

Media service providers offering radio, television or on-demand services over the internet only must obtain an internet broadcasting licence from the Radio and Television Supreme Council (RTÜK) — İNTERNET-RD for radio, İNTERNET-TV for television and İNTERNET-İBYH for on-demand. A provider may offer one radio, one television and one on-demand service, each requiring a separate licence. Platform operators transmitting multiple such services through their own URL or app must obtain an internet broadcast transmission authorisation.

VOD/OTT services with curated catalogues under editorial responsibility, including Netflix/BluTV/Disney+-type services, are typically treated as internet on-demand broadcasting services requiring an İNTERNET-İBYH licence.

Audio streaming and podcast/music services require a more fact-specific assessment; RTÜK practice has treated Spotify as falling within the licensing framework. The analysis turns on whether the service presents organised audio programmes/catalogues under editorial responsibility rather than neutral hosting or interpersonal communication.

Video-sharing and UGC platforms are not licensed just for hosting audiovisual content, but professional channels, curated catalogues, "originals" or broadcasting-like services may be assessed separately where editorial responsibility is assumed. 

Multistreaming platforms follow the same functional distinction. A tool that only lets a creator simulcast the same stream to several platforms is normally not a RTÜK-licensed media service provider or platform operator; however, a service that aggregates or packages multiple broadcasting services and makes them available through its own app/URL may be treated as an internet broadcasting platform operator requiring transmission authorisation. Platform operators must also notify RTÜK of the services they transmit and stop transmitting unlicensed or licence-cancelled services upon RTÜK notice.

For licence applications, the media service provider must be a joint-stock company under the Turkish Commercial Code. Applications go to RTÜK with the prescribed forms and corporate documents, like:

  • trade registry records;
  • proof of paid-in capital;
  • shareholder/management information;
  • criminal-record declarations;
  • logo/call-sign; and,
  • authorised signatory documents.

Platform authorisation may be granted to a joint-stock or limited liability company, and BTK electronic communications authorisation is not required just to obtain the RTÜK transmission authorisation.

Foreign services may also fall within the regime. If an online broadcasting service is in Turkish and directed at Türkiye, or in another language but carrying commercial communications directed at Türkiye, RTÜK may require a licence or platform authorisation. If an unlicensed service continues, RTÜK may seek content removal and/or access blocking from the criminal judgeship of peace, which must decide within 24 hours without a hearing under Law No. 6112.

For 2026, RTÜK’s official public tariff sets 10-year internet licence fees at TRY116,232 for internet radio, TRY1,162,306 for internet television and TRY1,162,306 for internet on-demand broadcasting. The 2026 annual internet broadcast transmission authorisation fee for internet platform operators is also TRY1,162,306. In addition, providers offering services through conditional access must pay 1.5% of annual net salesto RTÜK by the end of July of the following year, subject to the deduction mechanism for certain declared commercial communication revenues.

Türkiye’s telecommunications framework is based on Law No. 5809 and BTK secondary legislation, covering electronic communications services, networks, infrastructure and relevant devices. Operators generally need notification or a right of use before regulated activity begins, depending on the service, spectrum, numbering, infrastructure or network element. 

Regulated services include fixed/mobile telephony, internet access, infrastructure, satellite, leased-line, virtual mobile and other signal-transmission services. OTT interpersonal communications may also fall within BTK’s jurisdiction, but the detailed authorisation regime continues to develop. 

Radio and wireless hardware is subject to pre-market conformity rules. Products such as mobile phones, base stations, cellular routers, IoT sensors and smart meters generally must comply with the Radio Equipment Regulation, CE marking and Türkiye-specific radio interface requirements, and importation may trigger TAREKS product safety controls before customs clearance. For SIM/eSIM or IMEI devices, companies should separately assess device registration, MCKS/IMEI listing, eSIM localisation and network compatibility; CE compliance alone may not suffice where frequency band, output power, channel spacing or national frequency plan requirements are unmet.

For M2M services, companies should also account for the BTK-driven M2M line/device pairing structure applicable from 1 April 2026, described in detail in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection. In broad terms, M2M lines benefiting from the M2M tax regime should not be used in general-purpose devices; certain equipment (FCT devices, wireless routers, cameras, radios, modems, multi-modems) may require IMEI–IMSI pairing, and closed-purpose M2M/IoT devices may be managed through pairing and/or approved TAC lists. This is especially relevant for push-to-talk over cellular and professional radio-type systems.

Pre-marketing checks for telecom-enabled products should therefore cover authorisation, radio conformity, CE/TAREKS, MCKS/IMEI, eSIM, M2M tariff eligibility, device category, IMEI/IMSI matching, TAC management and device-change procedures. Operators should also confirm before launch whether national security and lawful interception requirements apply. Electronic communications operators must establish technical infrastructure capable of meeting such requests before offering the service; failure to establish or update this has been treated in administrative case law as a serious compliance failure that may lead to cancellation of authorisation.

Security requirements are a central part of the regime. Operators must implement a network and information security governance structure — an Information Security Management System, risk assessment, physical and logical access controls, business continuity and incident response. Key obligations include retaining critical system access records and logs for at least two years; protecting critical infrastructure against unauthorised access, sabotage and environmental risks; establishing disaster recovery; and coordinating cyber incident handling through sectoral response structures and USOM/SOME processes.

Türkiye has no standalone EU-style net neutrality statute or general open-internet right equivalent to the EU Open Internet Regulation. The issue is instead addressed indirectly through authorisation conditions, consumer commitments, service-quality rules, transparency duties and competition law; misleading, discriminatory or anti-competitive traffic management may trigger scrutiny.

Traffic management is not prohibited per se; operators may manage networks for congestion, cybersecurity, emergency response, service integrity, quality of service, lawful orders or technical optimisation. With no statutory test for "reasonable traffic management", the boundary between legitimate management and discriminatory throttling is less clearly codified than elsewhere — a point of uncertainty for mobile operators, ISPs, zero-rating and sponsored-data offerings.

Access blocking or throttling may also serve as an enforcement tool, with sectoral and public-order powers permitting access restrictions or bandwidth measures in specific statutory contexts. Even so, operators remain subject to BTK supervision, consumer law, authorisation obligations and competition law.

Operators also use zero-rating or bundle-based practices where certain services do not count against users’ data caps. Absent a strict net neutrality rule, these are not automatically prohibited but may be problematic if they foreclose competing services, mislead consumers, exploit market power or create discriminatory access conditions. Therefore, dominant operators and vertically integrated telecom/content groups should assess zero-rating, prioritisation and bundled access models under competition law and consumer transparency principles.

Operators have flexibility to design differentiated packages, managed services and security-based interventions, but should document traffic-management rationale, disclose material limits, avoid unjustified discrimination and keep audit-ready policies.

For TMT companies that rely on telecom networks but are not operators, the absence of a robust net neutrality guarantee means that market access may depend partly on commercial arrangements with operators, CDN optimisation, local hosting, peering, network resilience and regulatory risk planning. For content platforms, streaming services, gaming platforms, cloud services and communications apps, Turkish market entry should therefore include both telecom regulatory review and practical network-distribution strategy.

Türkiye has no single next-generation telecom statute; 5G, IoT/M2M and AI are regulated through telecommunications, cybersecurity, device conformity, data protection, consumer and competition rules, often triggering multiple approvals and governance requirements at once.

5Gprimarily affects the legal landscape through spectrum management, infrastructure investment, network security and localisation policy. 5G services are grounded in the general authorisation and frequency allocation framework under the Electronic Communications Law, with BTK and the Ministry playing central roles in spectrum planning and operator authorisations. 5G is legally tied to BTK's authorisation and spectrum allocation powers, and operators must update network and information security, business continuity and incident response as complexity increases. For non-operator TMT companies, 5G is relevant where they provide private networks, edge computing, cloud infrastructure, network equipment, cybersecurity tools, industrial automation or connected-device services.

As noted in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection and 4.2 Compliance and Governance, IoT/M2M products require checks on mobile connectivity, IMEI, SIM/eSIM, radio equipment, numbering, roaming, MCKS registration, inactivity, localisation, M2M pairing and TAC-list requirements. 

For connected vehicles, the analysis should separately cover 112-based eCall systems under BTK Decision No. 2018/DK-YED/27, as detailed in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection. Connected vehicles are thus one of the highest-risk IoT categories in Türkiye, alongside eSIM-based fleets, smart mobility platforms and telematics.

AI affects telecommunications less through licensing and more through data, security, automation and accountability. Türkiye has no comprehensive AI Act yet, but the TBMM AI Commission Report signals a clear direction: mapping the existing framework, considering a general AI law, pursuing EU AI Act alignment, improving data governance and addressing liability, transparency and risk-management. Telecom AI use cases — network optimisation, fraud detection, predictive maintenance, customer scoring, eKYC, chatbots, segmentation, dynamic pricing and cybersecurity monitoring — should therefore already be treated as regulated risk areas before any dedicated statute.

As noted in 3.1 Liability, Data Protection, IP and Fundamental Rights, Law No. 6698 is the most immediate AI compliance layer: the KVKK's Generative AI Guide confirms AI systems must observe the general principles and emphasises transparency on data sources, legal basis and information notices, and that controller/processor roles, which are harder to determine across AI lifecycles, depend on who decides purposes, means, data categories, sharing and retention. For telecom companies this matters where vendors supply AI tools for call centres, customer analytics, network monitoring or identity verification.

Security is also central. The KVKK guide recommends privacy by design/default and risk-based technical and administrative safeguards for AI systems, while telecom operators separately remain subject to sectoral network and information security duties. Claims about "new technology" or AI-driven advantages should be technically substantiated to avoid misleading advertising or unfair competition risks.

TMT companies should use combined governance covering classification, BTK authorisation, spectrum/device conformity, MCKS/IMEI/eSIM/M2M, cybersecurity, DPIAs, vendor liability, audit rights, transfers, explainability, human oversight and consumer transparency.

Technology contracts are governed by the Turkish Code of Obligations and Turkish Commercial Code, alongside applicable data protection, cybersecurity, e-commerce, electronic communications, consumer and sector-specific rules.

A principal challenge is keeping contractual arrangements aligned with an increasingly complex regulatory framework. Data protection, information security, audit rights, service continuity and compliance obligations are among the key issues negotiated in cloud, SaaS, AI, outsourcing and managed service models.

Certain obligations are mandatory and cannot be waived or limited by contract. Those obligations arising from personal data protection, consumer protection, e-commerce legislation and sector-specific financial regulations apply regardless of contrary contractual provisions. Certain sectors also face specific requirements on data retention, record-keeping, regulatory audit access and outsourcing.

Another challenge is the rapid pace of regulatory change, with substantial recent legislation in e-commerce, cybersecurity, crypto-assets and digital platforms. Contractual provisions on regulatory change management, audit rights, allocation of compliance responsibilities and adaptation to new requirements have therefore become increasingly important.

Some sectors face more stringent requirements. Banks, payment institutions, electronic money institutions, insurers and electronic communications operators are subject to sector-specific rules on outsourcing, information systems, data security, business continuity and supervision, so technology providers serving them may have to accept more extensive security commitments, audit rights, business continuity obligations and regulatory co-operation requirements.

Liability allocation is among the most heavily negotiated aspects. How risks from data breaches, cybersecurity incidents, IP infringements, service interruptions and administrative fines are shared is frequently contested, with providers seeking liability caps and damage exclusions while customers seek broader indemnification and protection.

Finally, given these mandatory obligations, contractual freedom is not unlimited; technology contracts should be drafted with regard to both parties' commercial expectations and the applicable regulatory framework.

Telecommunications service agreements in Türkiye should be drafted as regulated, performance-based contracts rather than ordinary commercial service contracts. At a minimum, they should identify the parties, the authorised operator, the service type and scope, activation/connection periods, tariffs, taxes, invoicing and payment/default rules, service suspension procedures, fault handling, complaint channels, dispute resolution and termination rights. Consumer-facing services must also meet mandatory transparency and form requirements, including clear and legible language, delivery through a durable medium, identity verification and long-term retention of contract records.

A central element is the service level agreement (SLA). The agreement should define measurable KPIs rather than generic promises of “fast” or “reliable” service, including uptime, latency, packet loss, activation periods, fault response and repair periods, maintenance windows, reporting methodology and escalation procedures. Consequences of breach should also be clear, including service credits, invoice reductions, liquidated damages, escalation rights and termination for repeated or material failures. Performance expectations not clearly reflected in the contract may be difficult to enforce, so SLA standards should be concrete, objective and measurable.

Data protection and confidentiality provisions should separately address customer content, traffic data, location data, billing data and operational logs. The agreement should allocate controller/processor roles where relevant, regulate subcontractors, impose security and breach notification duties, and reflect sector-specific confidentiality and data localisation expectations, particularly for traffic and location data.

Companies can negotiate favourable terms by treating the operator’s template as a starting point rather than fixed text. In B2B contracts, the main leverage points are SLA measurements, remedies, liability allocation, unilateral suspension rights, maintenance windows, exit assistance and data portability. Customers should resist SLA calculations that start only when a ticket is opened, instead seeking proactive monitoring or acceptance of independent monitoring data, and ensuring remedies are meaningful rather than nominal invoice credits where downtime may cause material business loss.

Liability clauses should also be negotiated carefully. Operator liability caps should not eliminate remedies for confidentiality breaches, data protection breaches, wilful misconduct, gross negligence, IP infringement or regulatory penalties caused by the operator. Conversely, indemnities imposed on the customer for fraud traffic, CLI manipulation, numbering misuse or regulatory fines should be limited to cases attributable to the customer’s proven fault. Minimum commitment and take-or-pay clauses may be softened through volume bands, rollover rights, grace periods or adjustment mechanisms.

For interconnection agreements, TMT companies should consider regulatory compliance, technical interoperability and competitive sustainability. Agreements should define interconnection points, capacity, routing, numbering, signalling, testing, traffic forecasting, fault management, security, billing, reconciliation, audit rights and change-management procedures. Where the counterparty has significant market power, BTK-approved reference offers and cost-orientation, transparency and non-discrimination obligations provide baseline protections, and BTK intervention or reconciliation may operate as a practical lever if negotiations fail.

Interconnection pricing should be assessed against margin-squeeze risks, especially where a vertically integrated operator supplies wholesale access while competing downstream. Facility sharing, co-location, right-of-way, last-mile access, domestic routing, cybersecurity, confidentiality, regulatory change and termination migration should also be expressly regulated.

The primary legislation governing trust services and electronic signatures in Türkiye is the Electronic Signature Law No. 5070. A secure electronic signature has the same legal effect as a handwritten signature, and electronic certificate service providers — offering electronic certificates, qualified electronic certificates and time stamps — operate under the supervision of BTK.

The Registered Electronic Mail (REM or KEP) system is another key component of Türkiye’s secure electronic communication infrastructure, providing evidential value as to the transmission, delivery, content integrity and timing of communications. It is regulated under the Turkish Commercial Code and BTK secondary legislation.

The evidential value of different signature types is assessed in accordance with the Turkish Code of Obligations and the Code of Civil Procedure. While secure electronic signatures produce legal effects equivalent to handwritten signatures, certain transactions remain excluded from their scope, including marriage, real estate transfers, and suretyship agreements subject to specific formal requirements.

On digital identity, the Turkish Identity Card infrastructure, the e-Government Gateway, and the Central Civil Registration System (MERNIS)/Identity Sharing System (KPS) form the core of the national ecosystem. The BRSA and Central Bank of the Republic of Türkiye (CBRT) rules on remote identity verification and digital onboarding are also significant, particularly for banks, payment institutions and electronic money institutions, while certificate policies, technical standards and sector-specific guidelines serve as further reference points.

Personal data protection is another key compliance area. Digital identity and remote verification may involve processing identity information, contact details, transaction security data and, in some cases, biometric data, so requirements on lawful processing grounds, data minimisation, retention periods, access controls and security measures must be carefully assessed.

From an intellectual property perspective, contracts should clearly regulate ownership and usage rights in the software, algorithms, certificate infrastructures, user interfaces and technical documentation used in electronic signature and digital identity solutions. Where third-party technology providers are involved, licensing scope, subcontracting arrangements and liability for infringements should be expressly addressed.

Türkiye has no single consolidated gaming statute. The sector is regulated through a layered framework covering internet regulation, gambling, prize draws, consumer-facing monetisation, child protection and IP. The most gaming-specific rule is the very recent amendment to Law No. 5651, which defines “game”, “game developer”, “game distributor” and “game platform”, and requires platforms to provide clear parental control tools covering account settings and paid transactions such as purchases, rentals and subscriptions; age-based classification details will be set by the Information and Communication Technologies Authority in secondary regulation. Non-compliance carries layered penalties: administrative fines of TRY1 to 10 million, rising to TRY10 to 30 million for continued breach, and ultimately up to 50% bandwidth throttling, a penalty unique to Türkiye. Obligations fall mostly on platforms, with those exceeding 100,000 daily users facing additional requirements including establishing a representative company in Türkiye. The amendments take effect on 1 December 2026, and it remains unclear how age-based classification and rating will operate. Secondary regulations on their details are expected soon.

In-game purchases are generally lawful, but loot boxes and chance-based mechanics require careful assessment. A mechanic involving consideration, chance and a prize may be characterised as a lottery, betting or gambling element. Non-cash prize draws require prior National Lottery Administration permission, including online. Unauthorised draws may be stopped, publicised, referred to prosecutors and may lead to a two-year ban on further lottery permissions.

Sports betting is separately regulated under Law No. 7258. Unauthorised online betting, payment intermediation and advertising/encouragement are criminalised, and related assets may be confiscated. Access ban under Law No. 5651 also applies to such offences. Law No. 1072 also prohibits certain roulette/tilt-type machines in public places, with imprisonment and judicial fines.

The primary regulators are:

  • the Information and Communication Technologies Authority for digital gaming, internet, online platform, age-rating and access ban issues;
  • the National Lottery Administration for non-cash prize draws;
  • Spor Toto for sports betting;
  • prosecutors and criminal courts for gambling/betting offences; and
  • civil/IP courts and the Ministry of Culture and Tourism for copyright-related matters.

BTK may request information from game platforms regarding corporate structure, IT systems and data-processing mechanisms, and may impose administrative fines for platform non-compliance. Spor Toto has powers to regulate, supervise and take legal action in relation to sports betting, including direct applications to prosecutors and participation in criminal proceedings.

Recent examples include the August 2024 Roblox access block and 2025 action against more than 84,000 illegal betting websites and related social media accounts. 

Common IP challenges include unauthorised cloning and use of characters, music, source code, artwork, brands, mods, virtual items and user-generated content. Under Law No. 5846, games may involve multiple protected works, including software, visual works, music, audiovisual elements and derivative works. The law protects authors' moral and economic rights, including adaptation, reproduction, distribution, representation and communication to the public.

Digital and virtual assets require clear chain-of-title documentation, especially for employees, freelancers, sound designers, illustrators, voice actors and middleware providers. For software, lawful users may make backup copies and observe or test program operation, but interoperability exceptions cannot create substantially similar infringing software. Technological protection measures are protected; circumvention tools or services may trigger criminal liability.

Trademark law applies where names, logos, character names or branded virtual items act as source identifiers. UGC adds risk, as users may upload infringing characters, music, skins or branded assets. Developers should therefore include terms granting platform licences, moderation and takedown rights, IP warranties, repeat-infringer measures and clear ownership rules for player-created content.

Türkiye has no single social media law; Law No. 5651 is supplemented by social network provider, data protection, consumer, advertising, IP, criminal, cybersecurity and sector-specific access-blocking rules. Law No. 5651 defines a "social network provider" as a person enabling users to create, view or share content such as text, images, audio and location data for social interaction. It also regulates content, hosting and access providers, access blocking, content removal and the specific obligations of large social network providers. Foreign-based providers with over one million daily accesses from Türkiye must appoint at least one authorised representative in Türkiye. Above ten million daily accesses, a legal-entity representative must be established as a branch with full technical, administrative, legal and financial authority and responsibility.

The most significant recent amendment is the 2026 child-protection package under Law No. 7578. As of 1 November 2026, providers may not serve children under 15 and must take measures, including age verification, to prevent access. Providers must also offer differentiated services for children aged 15 and above, publish the measures taken, offer parental-control tools and act against deceptive advertising.

The 2026 amendments also introduce a stricter urgency rule for very large social network providers. As of 1 November 2026, providers with over ten million daily accesses must comply with urgent Article 8/A decisions immediately, and in any event within one hour. Otherwise, the general Article 8/A rule compliance period remains four hours.

Access blocking is fragmented: Article 8 covers catalogue crimes, while Article 8/A permits urgent removal or blocking for life, property, national security, public order, crime-prevention and public-health grounds. Sector-specific regimes may also trigger takedown or blocking for content involving illegal betting, unlawful health claims, capital markets violations, copyright, cultural property, unlawful sales or illegal excavation/treasure-hunting. 

Personality rights enforcement remains a major challenge: the Constitutional Court annulled Article 9 of Law No. 5651 without a replacement. This creates uncertainty for online defamation and reputation remedies, especially where the issue falls outside privacy under Article 9/A or another sector-specific access-blocking mechanism.

Data monetisation is regulated indirectly through data protection, consumer protection and advertising transparency rules, including advertising-library obligations for large social network providers covering ad content, advertiser, display period, target audience, targeting parameters and reach.

Influencer marketing is governed by the Guideline on Commercial Advertisement and Unfair Commercial Practices by Social Media Influencers. It requires influencer advertisements to be clearly identifiable, prohibits covert advertising, requires disclosure where the influencer receives material benefit, free products, discounts or other advantages, and imposes rules on filters, unsupported scientific claims, health claims and misleading impressions of personal purchase.

Regulatory and Compliance Issues for Social Media

Under Law No. 5651, BTK supervises social network provider obligations, representative notifications, certain blocking/removal decisions, administrative fines, advertising bans and bandwidth-throttling procedures.

Criminal judgeships of peace and courts are also central actors. They may issue content-removal and access-blocking decisions under Law No. 5651, approve urgent Article 8/A decisions and rule on objections. The Access Providers Union implements such decisions; decisions sent to it are considered notified to access providers.

BTK’s enforcement powers include administrative fines, notification-based enforcement, advertising bans, and applications to criminal judgeships of peace for bandwidth throttling. Under the Procedures and Principles, failure to comply with certain obligations, including local data-hosting, child-specific services, user rights, life and property safety, information requests and crisis plans, may result in administrative fines of up to 3% of the previous year's global turnover.

For representative-appointment failures, sanctions are staged: BTK may notify the provider, then impose fines, then an advertising ban, and ultimately seek bandwidth throttling. The Procedures and Principles set out the 50% and then up to 90% bandwidth-throttling mechanism.

The Advertising Board is the main authority for social media advertising and influencer marketing. Under the influencer guideline, advertisers, agencies, media organisations and influencers are each separately responsible, and later correction does not eliminate liability for the original violation.

The DPA is relevant where social media activities involve personal data processing, targeted advertising, profiling, cookies or cross-border transfers. The Turkish Competition Authority may also be relevant where platforms' data practices or advertising ecosystems raise competition concerns, especially regarding dominant platforms, data combination, self-preferencing or access to advertising infrastructure.

Recent examples of enforcement actions with respect to social media include enforcement over foreign social network provider representative obligations, advertising bans, bandwidth throttling, influencer advertising and access-blocking decisions under Article 8/A and other routes. 

Telecom data privacy is governed by the KVKK, Law No. 5809, Law No. 5651, BTK’s sectoral privacy regulation and, for infrastructure security and critical services, Cybersecurity Law No. 7545.

The KVKK transfer regime applies to telecoms, but traffic and location data are also subject to sector-specific localisation restrictions on national security grounds. Operators should therefore assess both KVKK transfer mechanisms and BTK restrictions, often favouring local or hybrid hosting for critical systems and sensitive data.

Telecom operators commonly use vendors for network management, CRM, billing, analytics, cybersecurity and cloud infrastructure, making data-processing terms, subcontractor controls, audit rights, breach notices, security obligations and transfer provisions essential.

Finally, data protection and cybersecurity developments directly shape telecom infrastructure design and new services. With the expansion of 5G, IoT, AI-enabled network management and cloud services, operators are increasingly expected to apply privacy-by-design and security-by-design from the earliest stages of system architecture. The Cybersecurity Law's heightened security and resilience expectations will further shape future technology investments and service models.

Digital media and streaming platforms must manage user-data protection, consent, cookies, advertising technologies and security, with KVKK compliance especially important for analytics, personalisation and targeted advertising.

To implement privacy-by-design and security-by-design, digital media providers typically rely on technical and organisational measures such as data minimisation, role-based access controls, encryption, log management, retention limits and secure development practices, integrating data protection requirements into the design of new products and features.

A significant practical challenge concerns advertising technologies and third-party analytics tools. Data sharing arrangements involving advertisers, analytics providers, software development kit (SDK) providers and cloud service providers may trigger additional obligations on consent, transparency, cross-border transfers and security, so platforms should carefully structure their vendor agreements, data processing provisions and cookie management mechanisms.

As regulatory expectations concerning data security, incident management, vendor oversight, cloud services and cyber resilience continue to increase, platforms are required to manage their security and compliance obligations more comprehensively at both the contractual and technical levels. In addition, depending on the nature of their activities, platforms must also consider the content management obligations and social network provider requirements set out under Law No. 5651.

Özay Law Firm

Kerim Bey Köşkü
Göztepe Mahallesi
Tanzimat Sokak 63/1
Kadıköy
İstanbul

+902166884642

+902166884643

info@ozay.av.tr ozay.av.tr
Author Business Card

Trends and Developments


Author



Özay Law Firm offers high-quality legal services specifically tailored to the dynamic requirements of the modern business world. With a strong commitment to both commercial perception and immediate action, the firm provides effective, concrete legal solutions for local and multinational companies operating across Türkiye. Its team of specialised and collaborative attorneys offer comprehensive consultation and dispute resolution services. Özay Law Firm prides itself in its ability to manage complex projects, ranging from TMT, mergers and acquisitions to real estate development, both simultaneously and on short notice. Professional services are available in Turkish, English, and French. The firm combines academic rigour with practical application, ensuring a balance between theory and practice. Through an online document follow-up system, clients maintain full transparency, monitoring every stage of their case in real-time. Özay Law Firm transforms academic knowledge into actionable results for clients. The firm is composed of approximately 70 professionals.

Critical Developments in Türkiye's TMT Sector

As we move through 2026, the regulatory landscape in Türkiye is undergoing a profound transformation, characterised by an increasingly assertive approach from the Turkish Data Protection Authority (DPA) and a strategic expansion of national cybersecurity mandates. The following compilation outlines the most critical developments that define this new era of compliance, reflecting a concerted effort to harmonise technological innovation with fundamental human rights.

Central to these developments is a shift toward heightened accountability for data controllers. The DPA’s recent interventions, ranging from the strict regulation of biometric attendance tracking to the mandatory modernisation of loyalty programme verification and the standardisation of explicit consent documentation, underscore a clear directive: convenience and efficiency no longer supersede the protection of sensitive personal data. Organisations are now expected to adopt a “Privacy by Design” philosophy, moving away from invasive practices and boilerplate compliance toward tailored, transparent, and secure management models.

Simultaneously, the legislative framework is evolving to address the realities of a digital-first society. The introduction of stringent protections for minors, including the formal regulation of social media and gaming platforms, marks a significant milestone in safeguarding the next generation. This proactive stance is mirrored in the cybersecurity sector, where the launch of the Presidency of Cybersecurity and the elevation of data sovereignty to a national security priority signal a shift toward robust, indigenous digital resilience. Furthermore, the formalisation of binding corporate rules for cross-border data transfers and the clarification of the right to be forgotten demonstrate that Türkiye is aligning its regulatory mechanisms with complex global standards.

For legal professionals and corporate leaders, these updates represent more than mere policy shifts, they constitute a comprehensive framework that necessitates immediate operational auditing. The era of shadow AI practices, unchecked public disclosure of financial data, and legacy authentication methods is drawing to a close. Instead, the focus has shifted toward inter-institutional coordination, critical infrastructure protection, and the meticulous safeguarding of digital identities. By internalising these requirements, organisations can move beyond a reactive stance and build more ethical, resilient, and compliant operational structures.

The following sections provide an essential guide to these pivotal shifts, serving as a roadmap for navigating the complexities of Türkiye’s modern data protection and cybersecurity ecosystem.

Strategic pillars of the 2026-2028 Medium-Term Program: navigating the digital and AI frontier

The 2026-2028 Medium-Term Program, formalised via Presidential Decree, establishes a definitive roadmap for Türkiye’s digital transformation and the development of its data economy. This policy framework prioritises the harmonisation of the Turkish DP Law with the EU’s GDPR signalling a commitment to a globally integrated legal standard. By establishing a National Data Strategy, the government aims to codify data ownership, sharing responsibilities and governance structures, effectively treating data as a critical economic asset.

Technological advancement remains a cornerstone of this agenda, with ambitious targets for infrastructure modernisation, including the nationwide deployment of 5G, fibre optics, and the exploration of quantum-secure cryptography. The programmme also heralds the development of a blockchain-based digital identity management system, aimed at streamlining e-government services and reinforcing integrated public authentication protocols.

In the realm of AI, the programme adopts a holistic, multi-faceted approach. Beyond enhancing computational infrastructure and domestic large language models, the state is institutionalising AI-driven market surveillance and capital market oversight to ensure systemic efficiency. Furthermore, the programme mandates the alignment of domestic legislation with the EU AI Act, bridging the gap between national regulatory frameworks and international compliance requirements.

Finally, the government has integrated AI and big data analytics into the bedrock of fiscal enforcement. By utilising advanced risk-analysis algorithms, authorities intend to bolster the fight against the informal economy, prevent tax evasion, and enhance tax compliance. Through these strategic investments in human capital, inter-institutional cooperation, and AI-driven oversight, Türkiye is positioning itself to leverage technology as a primary engine for sustainable national development.

Regulatory standards for mobile push notifications

The DPA has issued a significant public announcement regarding the processing of personal data through mobile application push notifications. This decision reinforces that while push notifications are a standard tool for digital engagement, they are subject to the fundamental principles of the Turkish DP Law, specifically transparency, proportionality, and purpose limitation.

The DPA emphasises that data controllers must provide users with clear, accessible, and granular information prior to enabling notification services. It is insufficient to bury consent within extensive privacy policies; instead, users must be explicitly informed about what data is being collected, the specific purposes for which notifications are sent, and the legal basis, whether explicit consent or legitimate interest, underpinning the activity.

Furthermore, the DPA highlights the principle of data minimisation. Controllers must not process excessive or unnecessary data under the guise of sending notifications. The collection of granular behavioral data or location tracking for notifications requires a strict necessity test, and organisations must ensure that users retain the absolute right to withdraw their consent or opt-out at any time with minimal technical friction.

Ultimately, this guidance serves as a stern reminder that digital convenience does not grant immunity from regulatory oversight. Controllers must implement Privacy by Design in their application architecture, ensuring that notification settings are not pre-checked or deceptively framed. Failure to adhere to these standards constitutes a violation of both the transparency and processing principles, exposing organisations to potential administrative sanctions and data protection audits.

New mandatory authentication requirements for loyalty programme transactions

The era of processing transactions at points of sale using only a telephone number has come to an end following a principal decision by the Turkish DPA. With this decision, a grace period has been granted until August 2026.

The Turkish DPA stated that loyalty cards could be utilised using telephone numbers or information belonging to third parties without proper verification. The DPA noted that this practice led to transactions occurring without the cardholder's consent, and resulted in invoices and purchase details being processed under the wrong individual’s account, thereby constituting unlawful data processing and violations of the principle of accuracy. To mitigate these risks, data controllers are now mandated to implement alternative identity verification methods, such as SMS verification, QR codes/barcodes, physical cards, PIN codes, or transaction-based authentication.

Guidance on safe and responsible use of AI in the workplace

The DPA has published a comprehensive guide outlining the risks and compliance standards regarding the use of AI tools in workplaces.

The guidance highlights the complex risks posed to data security, intellectual property, and corporate reputation by shadow AI applications — tools utilised within business processes without centralised oversight. Instead of adopting a prohibitive approach, organisations are advised to implement a secure and responsible management model centred on clear policies, data classification, and human oversight.

New guidelines on privacy policies and explicit consent documentation

The DPA has issued a new principal decision regarding the preparation of privacy policies and explicit consent texts. While the decision reinforces existing standards rather than introducing entirely new obligations, it emphasises specific requirements that data controllers must adhere to in their documentation.

  • No affirmative phrases - affirmative or approval statements (e.g., “I accept”) cannot be added to the end of a disclosure notice. However, neutral statements such as “I have read and understood” are permissible.
  • Avoid ambiguity - the language must be clear and precise, avoiding vague or generic terminology.
  • Conciseness - the text should not be overly detailed, convoluted, or unnecessarily long.
  • Customisation - each data controller must draft its own tailored documents; the practice of copying and pasting another controller’s text is strictly prohibited.
  • Specific data listing - personal data categories should not be used as broad labels; the specific types of personal data being processed must be explicitly listed.
  • Clear legal basis - the legal grounds for processing, as well as the specific legal bases for any data transfers, must be stated clearly and transparently.
  • Separation of documents - while disclosure notices and explicit consent texts may be presented within the same page or document, they must be physically separated and require distinct, individual declarations from the data subject.

New privacy rules for building financials

The DPA has ruled against the common practice of posting resident debt information (such as unpaid dues or advances) in public residential areas. The DPA has clarified that this transparency measure violates privacy regulations because it exposes financial details to unauthorised third parties.

Key takeaways from the decision include the following.

  • Broad definition of personal data - linking debt information to an apartment number is considered a disclosure of personal data, even if the resident's name is not explicitly mentioned.
  • Mandatory privacy measures - building administrations must move away from physical, public displays and utilise restricted, private communication channels to share financial updates.
  • Recommended compliance channels - to remain compliant, property managers should shift to secure alternatives such as closed-loop email lists, private messaging groups, or official building management software that ensures information is visible only to the concerned party.

Updates on digital child protection measures

Recent amendments to the Internet Law have introduced a formal ban on social media usage for children under 15. To enforce this, social network providers are now legally obligated to implement rigorous age-verification protocols, curate child-specific service environments, offer parental control features, and prevent deceptive advertising directed at minors.

The scope of the Internet Law has been expanded to explicitly regulate the gaming sector, including gaming developers, distributors, and platforms. These entities are now required to provide age-appropriate content ratings, filter out harmful material, and offer parental supervision tools. Additionally, international gaming platforms must now appoint a formal representative in Türkiye.

Failure to adhere to these mandates carries significant consequences: social networks face potential advertising bans and bandwidth throttling, while gaming platforms may be subjected to heavy administrative fines alongside similar connectivity restrictions. These new requirements will become enforceable six months following their official publication.

Additionally, the Turkish DPA has launched an ex officio investigation into TikTok, Instagram, Facebook, YouTube, X, and Discord to assess how these platforms process children's personal data and what measures are in place to protect them from potential digital risks, with the best interests of the child in mind.

Cybersecurity developments

The official website of the Presidency of Cybersecurity has been launched. Through this portal, users can now access essential resources, including procedures for reporting cyber incidents, information on malicious links, and security notifications. Furthermore, the site serves as the central hub for the SOME Communication Platform and provides comprehensive documentation on the Information and Communication Security Guide, alongside details concerning the institution’s organisational structure and operational scope.

Building upon this institutional foundation, the inaugural meeting of the Cybersecurity Board was held under the chairmanship of the President to set the nation’s strategic direction. During the session, it was emphasised that cybersecurity constitutes an integral component of national security, with “data sovereignty” identified as a distinct priority that underscores the strategic value of information. To translate this vision into action, the Board resolved to strengthen inter-institutional co-ordination, foster sustainable domestic capacity, and enhance overall readiness against emerging risks. As a critical step in this strategy, the Board officially designated 14 sectors — including Digital Infrastructures, Energy, Finance, Health, Defence, and Water Management, among others — as “Critical Infrastructure Sectors”.

In alignment with these strategic priorities, the Presidency of Cybersecurity has also updated the Information and Communication Security Guide and the Information and Communication Security Audit Guide. These revisions are a direct result of the institutional and structural transitions that followed the transfer of responsibilities from the now-defunct Digital Transformation Office to the new Presidency. Consequently, these updated guides now impose rigorous, updated compliance and audit obligations that are mandatory for all public institutions, whether they manage their own IT infrastructure or outsource these services, as well as for all operators within the newly designated critical infrastructure sectors.

Launch of the first-ever binding corporate rules application

In a significant regulatory milestone, the Turkish DPA has officially opened the application process for Binding Corporate Rules. This marks the first time such a mechanism has been introduced under the Turkish data protection framework, providing a structured pathway for multinational organisations to facilitate intra-group cross-border data transfers. By adopting these rules, companies can ensure a high standard of data protection across their global operations, offering a robust alternative for cross-border data flows that guarantees compliance with the law while simplifying complex internal data management processes.

The limits of biometric attendance: a regulatory reset for employers

The Turkish DPA’s principal decision establishes a strict regulatory framework for the use of biometric data in workplace attendance systems. Recognising biometric information as sensitive personal data, the DPA mandates that its processing must adhere strictly to the principle of proportionality. Employers can no longer rely on the convenience or efficiency of biometric tools; they must instead prove that less intrusive methods, such as physical key cards, passwords, or digital tokens, are insufficient to achieve their operational goals. The burden of proof lies entirely with the data controller to justify why biometric technology is an absolute necessity rather than a mere preference.

Furthermore, the decision addresses the inherent power imbalance within the employment relationship, which casts significant doubt on the validity of “explicit consent”. Since employees may feel compelled to agree to biometric collection to avoid professional disadvantage, the DPA emphasises that consent must be truly free, informed, and easily revocable. Consequently, if a less intrusive method exists, the use of biometrics is deemed unlawful, regardless of whether the employee has signed a consent form. Organisations are required to adopt a Privacy by Design approach, ensuring that data is encrypted to the highest standard and preferably stored locally on employee devices to prevent the risks associated with centralised data breaches.

Finally, the DPA imposes a rigid purpose limitation, prohibiting the use of attendance-related biometric data for other corporate objectives, such as security access or performance appraisals, without a separate legal basis. Businesses currently employing these systems must immediately audit their practices against these new standards. Failure to comply or to transition to less intrusive technologies may result in severe administrative sanctions and orders to cease processing, potentially disrupting workplace operations. Employers are strongly advised to prioritise data security and employee privacy to ensure long-term regulatory compliance.

Protecting privacy in the digital age: the right to be forgotten

The Turkish DPA has issued a critical public announcement clarifying the scope and application of the right to be forgotten within the Turkish legal framework. This announcement reaffirms that individuals have the right to request the deletion or de-indexing of personal data from search engines when such information is outdated, inaccurate, or no longer serves a legitimate public interest, even if the information was originally published lawfully.

The DPA emphasises that while this right is essential for protecting an individual's reputation and privacy, it is not absolute. When evaluating de-indexing requests, the Turkish DPA underscores the need for a delicate balancing test; the right to privacy must be weighed against the public’s right to access information, the freedom of the press, and the historical or scientific importance of the data.

Furthermore, the Turkish DPA clarified that search engine operators function as data controllers and are therefore responsible for evaluating these requests with due diligence. They must assess whether the processing of the data remains relevant and necessary. This guidance serves as a vital benchmark for digital service providers operating in Türkiye, requiring them to implement transparent and effective procedures for handling right to be forgotten petitions while ensuring that legal freedoms are not unfairly curtailed.

Özay Law Firm

Kerim Bey Köşkü
Göztepe Mahallesi
Tanzimat Sokak 63/1
Kadıköy
İstanbul

+902166884642

+902166884643

info@ozay.av.tr ozay.av.tr/
Author Business Card

Law and Practice

Authors



Özay Law Firm offers high-quality legal services specifically tailored to the dynamic requirements of the modern business world. With a strong commitment to both commercial perception and immediate action, the firm provides effective, concrete legal solutions for local and multinational companies operating across Türkiye. Its team of specialised and collaborative attorneys offer comprehensive consultation and dispute resolution services. Özay Law Firm prides itself in its ability to manage complex projects, ranging from TMT, mergers and acquisitions to real estate development, both simultaneously and on short notice. Professional services are available in Turkish, English, and French. The firm combines academic rigour with practical application, ensuring a balance between theory and practice. Through an online document follow-up system, clients maintain full transparency, monitoring every stage of their case in real-time. Özay Law Firm transforms academic knowledge into actionable results for clients. The firm is composed of approximately 70 professionals.

Trends and Developments

Author



Özay Law Firm offers high-quality legal services specifically tailored to the dynamic requirements of the modern business world. With a strong commitment to both commercial perception and immediate action, the firm provides effective, concrete legal solutions for local and multinational companies operating across Türkiye. Its team of specialised and collaborative attorneys offer comprehensive consultation and dispute resolution services. Özay Law Firm prides itself in its ability to manage complex projects, ranging from TMT, mergers and acquisitions to real estate development, both simultaneously and on short notice. Professional services are available in Turkish, English, and French. The firm combines academic rigour with practical application, ensuring a balance between theory and practice. Through an online document follow-up system, clients maintain full transparency, monitoring every stage of their case in real-time. Özay Law Firm transforms academic knowledge into actionable results for clients. The firm is composed of approximately 70 professionals.

Compare law and practice by selecting locations and topic(s)

{{searchBoxHeader}}

Select Topic(s)

loading ...
{{topic.title}}

Please select at least one chapter and one topic to use the compare functionality.