Turkey enacted a standalone Cybersecurity Law, Law No. 7545 (adopted 12 March 2025, published in the Official Gazette No. 32846 on 19 March 2025, and in effect from that date), separate from the Personal Data Protection Law (KVKK)'s own security-of-processing clause.
The Law creates a Cybersecurity Directorate (Siber Güvenlik Başkanlığı) under the Presidency and transfers to it the national cybersecurity functions its own transitional provisions describe as previously exercised by the Information and Communications Technologies Authority (BTK), including BTK's contracts, personnel, and assets; the Law's own vocabulary for a computer-incident-response team is SOME (Siber Olaylara Müdahale Ekibi), and the pre-2025 national CERT acronym USOM does not appear in the primary text reviewed here, so its formal continuation or retirement under the new Directorate is not confirmed.
Article 7(1) binds any entity that uses information systems to provide services or to collect and process data within the Law's scope, public institutions, professional bodies of a public-institution character, and natural and legal persons alike, with police, coast guard, gendarmerie, intelligence, and armed-forces internal-service activities excluded under Article 2(2), to report a detected vulnerability or cyber incident to the Directorate without delay, to cooperate with Directorate information requests, and, for public institutions and critical infrastructure, to procure cybersecurity products only from Directorate-certified providers; failing the first three of those duties carries an administrative fine of 1,000,000 to 10,000,000 Turkish lira under Article 16(10).
The Law's own text sets no numeric clock for the reporting duty, leaving concrete technical measures to implementing regulations it directs the Presidency to issue within one year of publication, whose current status is not confirmed in the primary text reviewed.
A separate, narrower regime (Arts. 6 and 18) requires a cybersecurity product, system, or service, and the company supplying it, to be certified or authorized by the Directorate before that company may supply public institutions or critical infrastructure, and gates the export of cybersecurity products, systems, software, hardware, and services on Presidency-set procedures; no declared activity in this corpus's vocabulary expresses being a cybersecurity-product vendor or an export party, so this regime is recorded here rather than raised against a guess, the same treatment this profile gives regimes whose bound party is a designated status.
Critical infrastructure itself is a sector-by-sector, case-by-case government designation the Cyber Security Council makes under Article 9(4); the operator duties that designation triggers likewise bind a status no declared activity can express and are not flagged.
Obstructing an authorized inspector's information request carries one to three years' imprisonment and a judicial fine (Art. 16(1)), and other named offenses in the Law carry their own criminal exposure, but the Article 7(1)(a)-(c) duties raised in the instrument below are enforced only by administrative fine.
KVKK Article 12(1)-(4), the comprehensive privacy regime's own security-of-processing clause requiring a data controller to take technical and organizational measures for an appropriate level of security, and Article 12(5), the duty to notify the data subject and the Personal Data Protection Board of a personal-data breach with no fixed statutory clock, both stay in the privacy topic rather than here, the same place General Data Protection Regulation (GDPR) Article 32 sits; the privacy topic's own row already records Article 12(5) as a breach-notification instrument.
Turkish Penal Code Articles 135 through 140's personal-data offenses and the Articles 243-244 information-system offenses bind the person attacking a system rather than the operator or manufacturer, so they belong to the scraping topic's computer-misuse family and are not restated as a security-topic presence here.
Law No. 7590 (24 July 2026) added a further transitional article continuing the transfer of national cybersecurity functions and assets from BTK and the Telecommunications Communication Presidency to the Cybersecurity Directorate, evidence the institutional build-out remains active more than a year after enactment.