Türkiye centralises key digital governance functions under the Cybersecurity Presidency
Key contacts
The Amendments significantly change Türkiye’s digital regulatory framework, including changes to the Electronic Communications Law No. 5809 (Electronic Communications Law), Cybersecurity Law No. 7545 (Cybersecurity Law), and Internet Law No. 5651 (Internet Law). In particular, the Amendments transfer and consolidate a range of regulatory, supervisory and enforcement functions under the Cybersecurity Presidency previously exercised by the Information and Communication Technologies Authority (BTK) and other authorities, which further centralises Türkiye's cybersecurity and digital governance framework.
Scope
The Amendments may apply to a range of public and private entities operating in or providing services through digital infrastructure in Türkiye, including content providers, electronic communications operators, data centre operators, hosting providers, social network providers, gaming platforms, internet-access providers and cloud-service providers.
Key changes introduced by the Amendments
- Amendments to the Electronic Communications Law
The Amendments introduce changes to the Electronic Communications Law, including a new definition of the “Presidency”, referring to the Cybersecurity Presidency, and a new Article 60/A. Under Article 60/A, the authority to determine strategies and policies regarding internet domain names and to adopt related regulatory measures is transferred to the Cybersecurity Presidency. These responsibilities were previously exercised by the Ministry of Transport and Infrastructure and BTK and are now vested in the Cybersecurity Presidency.
Where one or more of the grounds listed under Article 22 of the Turkish Constitution exist and where delay would be prejudicial, Article 60/A also provides that the Cybersecurity Presidency can, upon request of security or intelligence institutions or on its own initiative, determine and order the implementation of necessary measures. To implement measures, the Cybersecurity Presidency may notify operators, access providers, data centres, and relevant content and hosting providers. Recipients of such decisions are required to comply immediately and, in any event, within two hours. The decision must be submitted to the criminal judgeship of peace for approval within twenty-four hours and the judge must issue a decision within forty-eight hours, or the measure automatically ceases to have effect.
Article 60(10), which regulated a similar mechanism, is repealed. The Amendments also authorise the Cybersecurity Presidency to impose administrative fines ranging from TRY 20,000 to TRY 100,000 for each act constituting a violation where the relevant persons fail to fulfil their obligations concerning the duties and powers regulated under the Electronic Communications Law. Administrative fines and other administrative sanctions imposed by the Cybersecurity Presidency under this provision may be challenged before the competent administrative court, and all cases brought against the Cybersecurity Presidency's decisions are treated as priority matters.
While the emergency measures regime under Article 60/A mirrors powers that already existed under the former Article 60(10) of the Electronic Communications Law, the amendments are not purely institutional. Beyond the transfer and centralisation of these powers under the Cybersecurity Presidency, the Amendments introduce a distinct administrative fine regime enforceable by the Presidency, and consolidate the internet domain name policy-making authority under a single body.
- Amendments to the Cybersecurity Law
The Amendments introduce a new Provisional Article 2 to the Cybersecurity Law. Under this provision, existing secondary legislation relating to the functions transferred to the Cybersecurity Presidency by Law No. 7590 will remain in force until the Cybersecurity Presidency issues its own implementing regulations, while references in this secondary legislation to BTK and the former Telecommunications Communication Presidency will be deemed to refer to the Cybersecurity Presidency.
The provision governs the transfer within three months of BTK’s movable assets, IT infrastructure and systems, data centres, vehicles, equipment and materials, all records and documents (whether physical or electronic), rights and obligations relating to the transferred functions. The provision also provides for the temporary secondment of BTK personnel involved in those functions to the Cybersecurity Presidency for up to one year and, where they so request and are approved by the Cybersecurity Presidency, their subsequent appointment to permanent positions within the Cybersecurity Presidency. Furthermore, judges and prosecutors may be temporarily seconded to the Cybersecurity Presidency while public officials and academic personnel may be employed as contracted expert personnel.
The Amendments also amend the Cybersecurity Law to authorise the Cybersecurity Presidency to provide technical capabilities and make necessary regulations in relation to lawful interception and intervention carried out by institutions authorised under applicable laws, transferring a function previously exercised by BTK. In addition, entities that fail to provide data, information, documents, hardware, software, or other contributions requested by the Cybersecurity Presidency in connection with its duties and activities are now subject to administrative fines ranging from TRY 1 million to TRY 10 million.
The changes introduced by these amendments are primarily organisational and transitional in nature, serving to consolidate cybersecurity-related powers, resources and personnel under the Cybersecurity Presidency and to ensure continuity in the exercise of the transferred functions. No new substantive obligations are imposed on regulated entities. The extension of the fine regime, however, from TRY 1 million to TRY 10 million to cover non-compliance with information and cooperation requests (an obligation previously not subject to this sanction) represents a notable strengthening of the Cybersecurity Presidency's enforcement toolkit.
- Amendments to the Internet Law
The Amendments to the Internet Law are largely intended to align the existing framework with the broader transfer of powers from BTK to the Cybersecurity Presidency, although they also introduce substantive changes, such as the expanded definition of traffic data.
As far as the institutional changes are concerned, a broad range of existing functions and responsibilities under the Internet Law are now exercised by the Cybersecurity Presidency, which includes those relating to safer internet use, content removal and access-blocking measures, administrative enforcement, coordination with content, hosting and access providers, online content monitoring, technical infrastructure and support to competent authorities, approval and oversight of the by-laws and operational framework of the Access Providers Association.
In addition, the Amendments introduce a new definition of "Presidency" in reference to the Cybersecurity Presidency, and repeal the former definition of "Ministry", reflecting the transfer of oversight responsibilities away from the Ministry. Administrative fines imposed by the Cybersecurity Presidency under the Internet Law can be challenged before the administrative courts.
The Amendments also introduce two important procedural changes. First, the revocation of an access provider's authorisation by BTK for failure to implement a content removal or access-blocking order now requires a prior request from the Cybersecurity Presidency, which adds a gatekeeping step that did not previously exist. Secondly, the reference to "the Ministry of Transport" has been replaced with "the Ministries", broadening the scope of coordination to multiple ministries.
Separately from the institutional and procedural amendments described above, the Amendments expand the definition of traffic data under the Internet Law, by inserting the words “source and destination” before “port information” in the definition of traffic data under the Internet Law.
This has two practical consequences. First, the character of the retained dataset changes given that it indicates the nature of a user’s activity rather than merely their identity. Secondly, a destination port exists only in relation to an individual connection. Hence, capturing it requires records to be created for each connection rather than only for the allocation of addresses, which is susceptible to materially increase the volume of data generated and stored across the applicable retention period.
Providers subject to the retention obligations under the Internet Law should review their logging configurations, storage capacity and retention practices with the precise fields and formats to be clarified in the secondary legislation from the Cybersecurity Presidency.
The Amendments also align the social network provider framework under Additional Article 4 of the Internet Law with the broader institutional transfer. The Cybersecurity Presidency replaces BTK as the competent authority for a range of existing obligations, including representative appointments, content removal response requirements, reporting, data localisation, children's safety measures, and algorithmic transparency and accountability. The existing sanctions framework, including administrative fines, advertising bans, restrictions on new advertising contracts, and bandwidth throttling, remains substantively unchanged with the Cybersecurity Presidency replacing BTK as the enforcing authority. The Cybersecurity Presidency will also be responsible for coordinating the implementation of bandwidth-throttling decisions through the Access Providers Association and may challenge related judicial decisions before the courts.
These obligations for social network providers are not newly introduced by the Amendments, but were enacted by earlier legislation and are already in force. The contribution of the Amendments is limited to replacing institutional references.
Separately, obligations applicable to gaming platforms, developers, distributors and platform operators were introduced under a new Additional Article 5 of the Internet Law by Law No. 7578 and are scheduled to enter into force on 1 November 2026. Those provisions are not amended by the Omnibus Law, but may in practice be affected by the broader institutional reorganisation where enforcement responsibilities under the Internet Law shift to the Cybersecurity Presidency.
As a practical matter, the change in the competent authority for both frameworks should not be regarded as nominal. The Cybersecurity Presidency may adopt different interpretative, supervisory and enforcement approaches from those historically followed by BTK. Affected businesses including social network providers, gaming platforms and other digital service providers should therefore monitor the institutional transition, forthcoming secondary legislation, and the Cybersecurity Presidency's emerging enforcement practice.
Conclusion
The Amendments are principally institutional in character, consolidating a broad range of cybersecurity, electronic communications and internet governance functions under the Cybersecurity Presidency. In most areas, the underlying obligations applicable to regulated entities remain unchanged. However, certain changes (e.g. the introduction of a standalone administrative fine regime under the Electronic Communications Law, the extension of administrative fines to information and cooperation requests under the Cybersecurity Law, and the expansion of the traffic data definition under the Internet Law) go beyond institutional re-organisation and may have direct compliance implications. With the Cybersecurity Presidency now assuming the role of primary regulator across these frameworks, affected businesses should review their existing compliance arrangements, monitor the issuance of implementing secondary legislation, and prepare for a potentially different regulatory and enforcement approach.
For more information on the Amendments and their implications in Türkiye, contact the experts who contributed to this article: [email protected], [email protected], and [email protected].