March 18, 2026, 2:35 p.m.
Turkey Cybersecurity Law (Law No. 7545)
The Grand National Assembly of Turkey has initiated a new era in the field of cybersecurity in our country with Cybersecurity Law No. 7545 adopted on March 12, 2025. The purpose of the Law is to identify and eliminate threats to the elements constituting the Republic of Turkey's national power in cyberspace, to determine the principles for reducing the effects of cyber incidents, and to regulate the provisions regarding the establishment of the Cybersecurity Presidency.
Scope of the Law
The Law covers all public and private organizations that have a presence, operate, or provide services in cyberspace:
- Public institutions and organizations
- Professional organizations with public institution status
- Natural and legal persons
- Organizations without legal personality
Note: Intelligence activities and operations within the scope of the Turkish Armed Forces are excluded from this Law.
New Structure: Cybersecurity Presidency
The Cybersecurity Presidency has been established with the Law. National cybersecurity activities under BTK and the Digital Transformation Office will be transferred to this Presidency within 6 months from the publication of the Law. Administrative fines imposed are also among the Presidency's revenues.
Penalties in the Law — Actual Penalty Amounts (Article 16)
Both imprisonment and administrative fines are stipulated for violations under the Law:
Prison Sentences
- Those who do not provide information/documents/software/hardware requested by authorized authorities or obstruct this: 1 to 3 years imprisonment + judicial fine
- Those who operate without obtaining the necessary approval, authorization or permission: 2 to 4 years imprisonment + judicial fine
- Those who fail to fulfill confidentiality obligations: 4 to 8 years imprisonment
- Those who expose personal data resulting from data breaches to unauthorized access: 3 to 5 years imprisonment
- Those who create/cause the dissemination of false data breach content: 2 to 5 years imprisonment
- Those who conduct cyber attacks: 8 to 12 years imprisonment
- Individuals who disseminate/sell data obtained through attacks: 10 to 15 years imprisonment
Administrative Fines
- 100,000 TL – 1,000,000 TL: Those who fail to fulfill reporting/compliance obligations under Article 8. For commercial companies, an additional penalty of up to 5% of gross sales revenue may be applied.
- 1,000,000 TL – 10,000,000 TL: Those who fail to fulfill duties and responsibilities under Article 7 (critical infrastructure operators, etc.)
- 10,000,000 TL – 100,000,000 TL: Those who fail to fulfill obligations under Article 18 (those who conduct transactions in the sale of cybersecurity products/services without obtaining Presidency approval)
⚠️ Important: If the offense is committed by a public official, the penalty is increased by 1/3, if committed by multiple persons by 1/2, and if committed within the framework of an organization's activities, up to 2 times.
New Obligations for Cybersecurity Products and Services (Article 18)
Cybersecurity Presidency approval becomes mandatory for companies selling cybersecurity products, systems, software, hardware and services abroad. In addition, mergers, divisions, share transfers and sales transactions of cybersecurity companies must also be reported to the Presidency. Administrative fines of 10 million to 100 million TL will be applied to those who fail to comply with these obligations.
What Should Your Business Do?
- Scope Assessment: Identify which articles of the Law directly affect your business
- SOME Establishment: Establish a Cyber Incident Response Team (SOME) or review your existing structure
- GAP Analysis: Compare your current security status with Law requirements
- Authorized Audit: Plan periodic security audits with an accredited firm
- Policy Update: Bring your corporate cybersecurity policies and procedures into compliance with the Law
Prepare for Compliance with Nordis Global
Nordis Global ensures your business is ready for the legal framework with GAP Analysis and Cybersecurity Law No. 7545 Compliance Consulting services. Our TSE and ISO 27001 accreditations are the guarantee of the consulting we provide.
Similar Posts