Law / Turkey

Turkey

14 of 18 named instruments researched to a stage, across all six areas of law we track: 14 in force. As of 14 September 2026.

When they take effect14 of 14 carry a date. Earlier is before 2014.
Before 2014: 4 instruments (4 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 4 instruments (4 in force) 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 1 instrument (1 in force) 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 1 instrument (1 in force) 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (173 words)

Turkey has no comprehensive, binding artificial-intelligence statute. The National Artificial Intelligence Strategy 2024-2025 Action Plan, a Presidential coordination document assigning priority actions across government and industry, is a policy plan rather than a law and imposes no obligation on a private actor.

A comprehensive, EU AI Act-modelled bill (TBMM Bill No. 2/2234, submitted 24 June 2024) and a narrower bill amending the Penal Code and the Internet Law to require labelling of AI-generated content and to create a rapid takedown mechanism for it (TBMM Bill No. 2/3358, submitted 7 November 2025) both remain under parliamentary review as of this review and have not been enacted.

The Personal Data Protection Authority (KVKK Kurumu) has issued non-binding guidance addressing generative AI (November 2025) and agentic AI systems (12 March 2026), construing the existing Personal Data Protection Law rather than creating new obligations. The one binding, sector-specific instrument located is a July 2026 amendment to the Ministry of Trade's advertising regulation, which requires disclosure of AI use in advertising and bars a deceptive AI deepfake endorsement.

AI prohibited practices

Commercial Advertising Regulation, AI Deepfake Endorsement Ban

Art. 18/12, Ticari Reklam ve Haksız Ticari Uygulamalar Yönetmeliği (RG No. 33297, 1 Temmuz 2026)official regulation text, Official Gazette (Resmi Gazete) No. 33297, Ministry of Trade

In force 53 days, effective 1 August 2026. Binds private bodies.

What this law does

The same July 2026 amendment adds a paragraph 12 to Article 18 of the Commercial Advertising and Unfair Commercial Practices Regulation, prohibiting an advertisement in which a digital copy of a real person, created using artificial intelligence technologies, is presented, contrary to fact, as having personally experienced or used a good or service, or as having recommended it.

What it requires

AI transparency

Commercial Advertising Regulation, AI Disclosure Duty

Art. 18/8, Ticari Reklam ve Haksız Ticari Uygulamalar Yönetmeliği (RG No. 33297, 1 Temmuz 2026)official regulation text, Official Gazette (Resmi Gazete) No. 33297, Ministry of Trade

In force 53 days, effective 1 August 2026. Binds private bodies.

What this law does

A regulation amending the Ministry of Trade's Commercial Advertising and Unfair Commercial Practices Regulation, published in the Official Gazette on 1 July 2026 and in force from 1 August 2026, adds a paragraph 8 to Article 18 requiring that where an advertisement uses artificial intelligence or other software in a way that significantly affects a consumer's economic behaviour regarding a good or service, or presents a digital character generated with artificial intelligence technologies that cannot be distinguished from a human being, this fact must be stated clearly, understandably, and in a manner distinguishable from the rest of the advertisement.

What it requires

Privacy law6 instruments, 6 in force

Research summary (153 words)

Turkey's comprehensive personal-data statute is KVKK, Law No. 6698 (7 April 2016), substantially amended by Law No. 7499 (2 March 2024), which rebuilt the special-categories lawful-basis structure and replaced the near-blanket-consent cross-border transfer regime with an adequacy-first mechanism backed by standard contracts and binding corporate rules, fully in force from 1 September 2024 once the transitional Provisional Art. 3 window closed.

KVKK lists biometric and genetic data as special-category data at Art. 6(1) but supplies no statutory definition of biometric data, voiceprint, or faceprint anywhere in the Act, so a captured identifier is treated inclusively as special-category data without any modality-specific rule. Breach notification (Art. 12(5)) requires notice to the affected subject and the Board within the shortest time, with no numeric statutory deadline in the Act's own text.

The private right of action (Art. 11(1)(g)) requires proof of damage from unlawful processing, unlike a no-proof-of-damage statutory-damages mechanism found elsewhere in this region.

Breach notification

Personal Data Protection Law (KVKK), breach notification

Law No. 6698, Art. 12(5)official statute text, KVKK Kurumu consolidated English translation

In force since 7 April 2016. Binds public and private bodies.

What this law does

Art. 12(5) requires a controller to notify the affected data subject and the Board within the shortest time where personal data has been obtained unlawfully by others; the Board may make the breach public. KVKK's own text sets no numeric deadline. Any numeric standard would sit in KVKK Board secondary guidance, which is not described here.

What it requires

Comprehensive regime

Personal Data Protection Law (KVKK), comprehensive regime and lawful basis

Law No. 6698 (7 April 2016), as amended by Law No. 7499 (2 March 2024), Arts. 1, 3, 5, 7-8, 10official statute text, KVKK Kurumu (Personal Data Protection Authority) consolidated English translation with inline amendment markers

In force since 7 April 2016. Binds public and private bodies.

What this law does

KVKK is Turkey's single omnibus personal-data statute, broadly General Data Protection Regulation (GDPR)-modeled, covering both public institutions and private-sector data controllers. Art. 5 sets the lawful bases: explicit consent by default, or one of six alternative grounds (a legal provision, vital-interest necessity, contract necessity, a legal obligation, the data subject's own publication of the data, the controller's legitimate interest, or establishment or exercise of a right).

Controller and processor are defined at Art. 3(g)/(i). Law No. 7499 (2 March 2024) amended the special-categories and cross-border transfer articles without changing this general lawful-basis structure.

What it requires

Cross border transfer

Personal Data Protection Law (KVKK), cross-border transfer

Law No. 6698, Art. 9, as amended by Law No. 7499 (2 March 2024), Provisional Art. 3official statute text, KVKK Kurumu consolidated English translation

In force since 1 September 2024. Binds public and private bodies.

What this law does

Post-2024 Art. 9 requires an Art. 5/6 lawful basis for the underlying processing plus a cross-border mechanism: a Board adequacy decision published in the Official Gazette for the destination, or, absent adequacy, Board-approved binding corporate rules, a Board-published standard contract, a Board-approved written commitment, or an international convention Turkey is party to.

A party relying on the standard-contract route must notify the Authority within 5 business days of signature (Art. 9(5)); failure carries its own fine tier added by the 2024 amendment. The pre-2024 near-blanket explicit-consent requirement remained in force in parallel until 1 September 2024 under Provisional Art. 3, so the amended, adequacy-first regime described here is genuinely in effect only from that date. No data localization is compelled.

What it requires

Data subject rights

Personal Data Protection Law (KVKK), data subject rights

Law No. 6698, Art. 11official statute text, KVKK Kurumu consolidated English translation

In force since 7 April 2016. Binds public and private bodies.

What this law does

Art. 11 gives a data subject the right to learn whether their data is processed, to request information on processing, to learn its purpose and whether use matches that purpose, to know the data's domestic and foreign transferees, to request rectification, to request erasure or destruction under Art. 7, to have those operations reported to prior transferees, to object to a result produced solely through automated analysis, and, at Art. 11(1)(g), to claim compensation for damage from unlawful processing.

What it requires

Enforcement supervision

Personal Data Protection Law (KVKK), enforcement and compensation

Law No. 6698, Arts. 11(1)(g), 18official statute text, KVKK Kurumu consolidated English translation

In force since 7 April 2016. Binds public and private bodies.

What this law does

The Personal Data Protection Board (KVKK) enforces the Act with tiered administrative fines under Art. 18: 5,000 to 100,000 TL for notice failures, 15,000 to 1,000,000 TL for security failures, 25,000 to 1,000,000 TL for noncompliance with a Board decision, 20,000 to 1,000,000 TL for registry failures, and, added by Law No. 7499 in 2024, 50,000 to 1,000,000 TL for Art. 9(5) transfer-notification failures; fines are now appealable to administrative courts under Art. 18(3), also added in 2024.

Art. 11(1)(g) lets a data subject claim compensation for the damage arising from the unlawful processing, which requires proof of damage, unlike a no-proof-of-damage statutory-damages tort found elsewhere in this region.

What it requires

Sensitive categories

Personal Data Protection Law (KVKK), special categories and biometric data

Law No. 6698, Art. 6, as amended by Law No. 7499 (2 March 2024)official statute text, KVKK Kurumu consolidated English translation

In force since 2 March 2024. Binds public and private bodies.

What this law does

Art. 6(1) lists biometric and genetic data, alongside race, ethnic origin, political opinion, philosophical belief, religion, health, sexual life, criminal convictions, and trade-union or association membership, as special-category data.

Processing requires one of the Art. 6(3) grounds added by the 2024 amendment: explicit consent, a legal provision, vital-interest necessity, the subject's own publication of the data consistent with the subject's intention to make it public, rights establishment, public health necessity, employment or social security law, or a closed list of nonprofit-association member data; the pre-2024 text instead required near-universal explicit consent.

KVKK gives no statutory definition of biometric data, voiceprint, or faceprint anywhere in the Act, so the term must be read inclusively: a voiceprint or faceprint captured for identification falls within the undefined biometric data category and triggers this special-category regime, even though no provision names either modality or sets a biometric-specific retention rule.

What it requires

Scraping law2 instruments, 2 in force

Research summary (301 words)

Turkey has no scraping-specific statute, so general law governs each dimension separately. The Penal Code's information-system-crimes chapter criminalises unauthorised entry into a computer system and obstructing or corrupting the data or operation of one, but its trigger is unauthorised access rather than the act of copying content, so a scraper reading a public, unauthenticated page without defeating an access control falls outside a plain reading of these provisions.

No reported Turkish decision addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper; the general contract-formation rules of the Turkish Code of Obligations (Law No. 6098) would govern such a claim, but no scraping-specific application of them has been located.

The Law on Intellectual and Artistic Works (Law No. 5846) permits fair-practice quotation and a narrow personal-use reproduction right, but Turkey has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the general quotation and personal-use grounds if they can be stretched to fit; the same Law confers a sui generis database producer right on a substantial investment in a database's content, independent of copyright in the individual contents.

The Personal Data Protection Law (KVKK), Law No. 6698, applies to personal data without a general carve-out for information the data subject has not made public; its narrow exception for data the subject has manifestly published (Art. 5(2)(d)) is a lawful-basis ground rather than a scope exclusion, so scraped public personal data remains subject to KVKK's purpose-limitation, security, and cross-border-transfer duties, and biometric identifiers drawn from scraped content fall within the special-category regime.

No Turkish statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine beyond the general unfair-competition provisions of the Turkish Commercial Code (Law No. 6102), and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Turkish Penal Code, Information System Crimes

Law No. 5237 (Turkish Penal Code), Arts. 243-244 (Bilişim Alanında Suçlar)official statute text, Turkish Presidency Legislation Information System (Mevzuat Bilgi Sistemi) consolidated text of Law No. 5237

In force since 1 June 2005. Binds public and private bodies.

What this law does

Article 243(1) criminalises unlawfully entering the whole or part of a computer system, or unlawfully continuing to remain there, an offence punishable by imprisonment or a judicial fine and last revised by Law No. 7413 (23 June 2022).

Where such entry causes the system's data to be destroyed or altered, Art. 243(3) sets imprisonment of six months to two years, and Art. 243(4), added in 2016, separately punishes unlawfully intercepting data transfers within or between computer systems by technical means without entering the system, at one to three years.

Article 244 punishes obstructing or disrupting a computer system's operation with imprisonment of one to five years (para. 1), and corrupting, destroying, altering, or rendering inaccessible the data within a system, inserting data into it, or transmitting its data elsewhere, with imprisonment of six months to three years (para. 2); the penalty is increased by half where a bank, credit institution, or public institution's system is affected (para. 3), and where the offender derives an unlawful benefit for self or another through these acts and no more serious offence is constituted, imprisonment rises to two to six years plus a judicial fine of up to 5,000 days (para. 4).

The offence is triggered by unauthorised access to, or interference with, a system rather than by the act of copying its content, so reading a public, unauthenticated page without defeating an access control falls outside a plain reading of these provisions.

What it requires

Database right

Law on Intellectual and Artistic Works, Database Producer Right

Law No. 5846, Ek Madde 8 (added by Law No. 5101, 3 March 2004)official statute text, Turkish Presidency Legislation Information System (Mevzuat Bilgi Sistemi) consolidated text of Law No. 5846

In force since 12 September 2004. Binds public and private bodies.

What this law does

Additional Article 8, added to the Law on Intellectual and Artistic Works by Law No. 5101 and in force since 12 September 2004, gives the producer of a database who makes a substantial investment, qualitatively or quantitatively, in creating, verifying, or presenting its content the exclusive right to permit or prohibit the permanent or temporary transfer of a substantial part or all of that content to another medium by any means, and its distribution, sale, rental, or communication to the public by any means, subject to the exceptions the Law lists and to exceptions required for public security or administrative or judicial proceedings.

Protection runs for fifteen years from the date the database is disclosed, and a substantial new investment that brings about a substantial qualitative or quantitative change in the database's content earns its own fifteen-year term.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (616 words)

Turkey enacted a standalone Cybersecurity Law, Law No. 7545 (adopted 12 March 2025, published in the Official Gazette No. 32846 on 19 March 2025, and in effect from that date), separate from the Personal Data Protection Law (KVKK)'s own security-of-processing clause.

The Law creates a Cybersecurity Directorate (Siber Güvenlik Başkanlığı) under the Presidency and transfers to it the national cybersecurity functions its own transitional provisions describe as previously exercised by the Information and Communications Technologies Authority (BTK), including BTK's contracts, personnel, and assets; the Law's own vocabulary for a computer-incident-response team is SOME (Siber Olaylara Müdahale Ekibi), and the pre-2025 national CERT acronym USOM does not appear in the primary text reviewed here, so its formal continuation or retirement under the new Directorate is not confirmed.

Article 7(1) binds any entity that uses information systems to provide services or to collect and process data within the Law's scope, public institutions, professional bodies of a public-institution character, and natural and legal persons alike, with police, coast guard, gendarmerie, intelligence, and armed-forces internal-service activities excluded under Article 2(2), to report a detected vulnerability or cyber incident to the Directorate without delay, to cooperate with Directorate information requests, and, for public institutions and critical infrastructure, to procure cybersecurity products only from Directorate-certified providers; failing the first three of those duties carries an administrative fine of 1,000,000 to 10,000,000 Turkish lira under Article 16(10).

The Law's own text sets no numeric clock for the reporting duty, leaving concrete technical measures to implementing regulations it directs the Presidency to issue within one year of publication, whose current status is not confirmed in the primary text reviewed.

A separate, narrower regime (Arts. 6 and 18) requires a cybersecurity product, system, or service, and the company supplying it, to be certified or authorized by the Directorate before that company may supply public institutions or critical infrastructure, and gates the export of cybersecurity products, systems, software, hardware, and services on Presidency-set procedures; no declared activity in this corpus's vocabulary expresses being a cybersecurity-product vendor or an export party, so this regime is recorded here rather than raised against a guess, the same treatment this profile gives regimes whose bound party is a designated status.

Critical infrastructure itself is a sector-by-sector, case-by-case government designation the Cyber Security Council makes under Article 9(4); the operator duties that designation triggers likewise bind a status no declared activity can express and are not flagged.

Obstructing an authorized inspector's information request carries one to three years' imprisonment and a judicial fine (Art. 16(1)), and other named offenses in the Law carry their own criminal exposure, but the Article 7(1)(a)-(c) duties raised in the instrument below are enforced only by administrative fine.

KVKK Article 12(1)-(4), the comprehensive privacy regime's own security-of-processing clause requiring a data controller to take technical and organizational measures for an appropriate level of security, and Article 12(5), the duty to notify the data subject and the Personal Data Protection Board of a personal-data breach with no fixed statutory clock, both stay in the privacy topic rather than here, the same place General Data Protection Regulation (GDPR) Article 32 sits; the privacy topic's own row already records Article 12(5) as a breach-notification instrument.

Turkish Penal Code Articles 135 through 140's personal-data offenses and the Articles 243-244 information-system offenses bind the person attacking a system rather than the operator or manufacturer, so they belong to the scraping topic's computer-misuse family and are not restated as a security-topic presence here.

Law No. 7590 (24 July 2026) added a further transitional article continuing the transfer of national cybersecurity functions and assets from BTK and the Telecommunications Communication Presidency to the Cybersecurity Directorate, evidence the institutional build-out remains active more than a year after enactment.

Vulnerability and incident reporting

Cybersecurity Law, Reporting and Cooperation Duties

Law No. 7545 (12 March 2025), Art. 7official statute text, mevzuat.gov.tr consolidated legislation portal

In force since 19 March 2025. Binds public and private bodies.

What this law does

Article 7(1) of Turkey's Cybersecurity Law binds any entity that uses information systems to provide services or to collect and process data within the Law's scope. It must report a detected vulnerability or cyber incident to the Cybersecurity Directorate without delay. It must also supply the Directorate with any data or documentation the Directorate requests.

Where it serves public institutions or critical infrastructure, it must source cybersecurity products only from Directorate-certified providers. Failing the reporting, cooperation, or procurement duties in items (a) through (c) carries an administrative fine of 1,000,000 to 10,000,000 Turkish lira under Article 16(10); the Law's own text sets no numeric clock for the reporting duty itself.

A related item (ç) requires a certified cybersecurity company to obtain the Directorate's approval before beginning operations, a licensing duty that binds the narrower class of cybersecurity-product and service vendors rather than a general software or app developer, and is not itself covered by the Article 16(10) fine named above.

What it requires

Age gating law2 instruments, 2 in force

Research summary (222 words)

Turkey has no adult-content age-verification statute or app-store age-verification requirement. The Penal Code's obscenity article (Law No. 5237, Art. 226) criminalises giving, showing, displaying, selling, renting, distributing, or advertising obscene material where a child (defined at Art. 6(1)(b) as a person who has not completed eighteen years) could obtain, see, or be shown it, and separately criminalises child sexual abuse material at a materially higher penalty tier.

That is a criminal prohibition running to any person, not an age-verification or age-gating obligation placed on a service. Two more targeted duties do impose that kind of obligation. The Law on Regulation of Internet Publications (Law No. 5651) requires a social network provider with more than one million daily accesses from Turkey to take measures providing a service specifically differentiated for children, enforceable by a fine of up to three percent of the provider's global turnover.

The Radio and Television Broadcasting Law (Law No. 6112) requires an on-demand broadcasting service provider to present content that could adversely affect the physical, mental, or moral development of children and young people so that they would not normally encounter it. Law No. 5651's children's-service duty is itself subject to a further amendment (Law No. 7578, 22 April 2026) that takes effect on 1 November 2026 and had not yet altered the operative text as of this review.

Age-appropriate design code

Radio and Television Broadcasting Law, On-Demand Service Minor Protection

Law No. 6112 (Radio and Television Broadcasting Law), Art. 8/3official statute text, Turkish Presidency Legislation Information System (Mevzuat Bilgi Sistemi) consolidated text of Law No. 6112

In force since 3 March 2011. Binds private bodies.

What this law does

Article 8(3) of the Radio and Television Broadcasting Law requires an on-demand broadcasting service provider (an audiovisual streaming or video-on-demand service within the Radio and Television Supreme Council's jurisdiction) to ensure that a broadcast service of a nature that could adversely affect the physical, mental, or moral development of children and young people is presented in a way that they would not normally hear or see under ordinary conditions.

A parallel duty at Art. 8(2), strengthened by Law No. 7077 in 2018, separately bars broadcasting such content during time periods children could watch even where a protective symbol is used, for linear radio and television broadcasting rather than on-demand services.

Note and primary source

Social media and minors

Law on Regulation of Internet Publications, Social Network Providers' Duty to Children

Law No. 5651, Ek Madde 4, as amended by Law No. 7418 (13 October 2022)official statute text, Turkish Presidency Legislation Information System (Mevzuat Bilgi Sistemi) consolidated text of Law No. 5651

In force since 13 October 2022. Binds private bodies.

What this law does

Additional Article 4 of the Law on Regulation of Internet Publications applies to a social network provider, Turkish or foreign, with more than one million daily accesses from Turkey. Paragraph 7, added by Law No. 7418 (13 October 2022), requires the social network provider to take the measures necessary to offer a service specifically differentiated for children.

Paragraph 20, added by the same Law, makes a provider that fails this duty, along with several other duties in the same article, liable to an administrative fine of up to three percent of its global turnover in the preceding calendar year, imposed by the head of the enforcing authority; the authority responsible for enforcing this Law was renamed the Cybersecurity Presidency (Siber Güvenlik Başkanlığı), succeeding the Information and Communication Technologies Authority (BTK), by Law No. 7590 (24 July 2026).

A further amendment, Law No. 7578 (22 April 2026), makes additional changes to this article effective 1 November 2026, which had not yet altered the operative text described here as of this review.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (152 words)

Turkey has no press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates; the Law on Intellectual and Artistic Works (Law No. 5846) grants related rights only to performers, phonogram producers, film producers, and broadcasting organisations, not to print or online news publishers. There is no mandatory platform-to-publisher bargaining code.

The Law's own provisions for daily news and press content, rather than a separate hot-news or misappropriation doctrine, are the operative privilege: no unfair-competition or misappropriation claim distinct from this copyright framework has been identified for time-sensitive factual reporting. No statute or reported Turkish decision addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer.

The Law predates the concept of a machine-readable text-and-data-mining reservation, and no amendment through the most recent (2021) amending Act adds one, so no text and data mining (TDM) opt-out mechanism of that kind exists.

Snippet reproduction

Law on Intellectual and Artistic Works, Quotation and Press Exceptions

Law No. 5846, Arts. 35-37official statute text, Turkish Presidency Legislation Information System (Mevzuat Bilgi Sistemi) consolidated text of Law No. 5846

In force since 1 January 1952. Binds public and private bodies.

What this law does

Article 35 permits quotation from a work in four settings: taking some sentences or passages of a disclosed work into an independent scientific or literary work; taking mostly theme, motif, passage, or idea elements of a published composition into an independent musical work; including disclosed fine-art works and other published works in a scientific work to the extent justified for illustrating its content; and displaying disclosed fine-art works by projection in scientific conferences or lectures, each conditioned on the quotation being clearly identifiable and, in scientific works, on naming the source and the author.

Article 36 lets daily news and reports disseminated by the press or radio be freely quoted.

It also lets articles or columns on daily social, political, or economic matters be taken as-is or in adapted form by other newspapers or magazines, and disseminated by radio or otherwise, unless the quotation right has been expressly reserved; even where it has been reserved, such articles or columns may still be taken in shortened, press-summary form and disseminated, provided the source publication or agency, its date and issue number, and the author's name, pen name, or mark are cited.

Article 37, rewritten in 2001, allows incorporating parts of intellectual and artistic works into media conveying signs, sound, or images in connection with daily events, for news purposes and not exceeding the scope of informing the public; material so incorporated may be freely reproduced, distributed, performed, or broadcast, provided this freedom is not used in a way that harms the rightsholder's legal interests or conflicts with normal exploitation of the work.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.