The Turkish Competition Authority Published the Preliminary Report on the Pharmaceutical Sector Inquiry
The Turkish Competition Authority (“Authority”) published the Preliminary Report on the Pharmaceutical Sector Inquiry (“Preliminary Report”) in August 2026, which was prepared within the scope of the sector inquiry initiated by the decision of the Competition Board (“Board”) dated 08.12.2021 and numbered 21-59/844-M, with a view to examining the regulations governing the Turkish pharmaceutical sector and the current structure of the sector, identifying competitive concerns, and making recommendations for the enhancement of competition. Within the scope of the sector inquiry, information and documents were obtained from undertakings engaged in manufacturing, supply and distribution, sector representatives and public institutions; on-site inspections were also conducted at various undertakings operating in the sector.
The Preliminary Report assesses competitive dynamics across the pharmaceutical value chain, from the development of a pharmaceutical product through to its delivery to patients,, with respect to the production, market entry and distribution stages.
The Preliminary Report does not constitute a final decision and is a study through which the Authority aims, at this stage, to share its findings and assessments with the public.
I. General Overview of the Pharmaceutical Sector
The Preliminary Report states that the pharmaceutical sector is a strategic sector requiring substantial investment, technology and R&D, and that it differs from other markets due to its demand structure and extensive regulation. The fact that, in the pharmaceutical sector, the parties using a pharmaceutical product, deciding on its use and bearing its cost often consist of different actors, together with the low price elasticity of demand for pharmaceuticals, is considered among the key characteristics of the sector.
While the sales value of the pharmaceutical market in Türkiye was TRY 56 billion in 2020, it reached TRY 479 billion in 2025. In 2025, pharmaceutical products manufactured in Türkiye accounted for 89.98% of the total market in terms of units sold and 59.59% in terms of sales value.
This growth trend indicates that the pharmaceutical sector will continue to remain among the areas subject to the Authority’s supervision and monitoring. Indeed, the Preliminary Report was prepared as a result of a systematic inquiry covering the sector as a whole and contains structural findings concerning a large number of market participants.
II. Activities of the Authority Relating to the Pharmaceutical Sector
The Preliminary Report states that the pharmaceutical sector is one of the Authority’s priority areas of activity and assesses the Board’s decisions issued over the past ten years.
With respect to merger and acquisition control, it is stated that, under the regulation concerning technology undertakings, undertakings operating in the field of pharmacology are also subject to the special notification regime, and that the relevant regulations aim to prevent the early-stage concentration of market power in innovative and R&D-intensive sectors. The Authority also notes that, in merger and acquisition notifications, the submission of information regarding the parties’ potential competitive relationship may contribute to the faster completion of the review process.
This approach demonstrates that, in the pharmaceutical sector, the Authority focuses not only on the existing market structure, but also on the prospective competitive effects of the transaction. The expectation that information regarding potential competition be submitted at the notification stage indicates that pharmaceutical companies may need to structure their competition law analysis earlier and in a more comprehensive manner in M&A processes.
Although the ATC-3 and ATC-4 classifications are considered important reference points in the definition of the relevant product market, they are not regarded as determinative on their own; factors such as the therapeutic characteristics of the pharmaceutical product, prescribing habits, effects on patient groups, off-label use, pricing and reimbursement conditions should also be taken into account.
III. Competition at the Production Stage
In the Preliminary Report, competition at the production stage is addressed within the framework of the relationship between patent rights and competition law. The Authority states that certain unusual practices in the acquisition and exercise of patent rights may give rise to consequences under competition law. In this context, the Preliminary Report refers to conduct such as providing false or misleading information to patent authorities, using divisional patent applications in a manner that produces anticompetitive effects, patent clusters, withholding certain information from courts in preliminary injunction proceedings, disparaging competing products, and threatening competitors with litigation.
The Preliminary Report also addresses compulsory licensing as a mechanism serving to strike a balance between the exclusivity conferred by patent rights, on the one hand, and the public interest and the protection of competition, on the other. It is stated that, under Industrial Property Law No. 6769, compulsory licensing may arise where the patented invention is not used, where the public interest so requires on grounds of public health or national security, or where the patent holder exercises the patent right in a manner that prevents, distorts, or restricts competition. The Authority assesses that this mechanism may contribute to addressing competition concerns such as barriers to market entry and market foreclosure.
In addition, the Preliminary Report states that the Bolar exemption is a mechanism facilitating the market entry of generic pharmaceuticals following the expiry of patent protection; increasing access to patent information and transparency, as well as enhancing cooperation between the Turkish Patent and Trademark Office and the Authority, are also identified among the areas open to further consideration.
The Preliminary Report also examines the potential competition law implications of patent settlement agreements. In this context, the Authority reviewed approximately 350 patent lawsuits initiated since 2015 and conducted more detailed assessments and on-site inspections with respect to 26 identified cases. The reviews did not reveal any indication of the existence in Türkiye of “pay-for-delay” agreements involving payments in exchange for delaying market entry; however, the Authority stated that this area should be regarded as one of the priority areas requiring close monitoring.
The Authority’s express identification of this area as one that “should be monitored as a priority” suggests that the possibility of the pay-for-delay issue becoming the subject of a standalone investigation in the future should not be disregarded. In the European Union, infringement decisions issued by the European Commission in cases where patent settlement agreements were found to constitute pay-for-delay arrangements were most recently upheld by the Court of Justice of the European Union in 2023.
With respect to patent settlement agreements, it is considered that the terms of such agreements should be based on rational grounds, such as the patent term, uncertainties relating to the dispute, technical assessments, or fair licensing terms; should not involve disproportionate outcomes resulting in delayed market entry or financial benefits that cannot be explained by litigation costs; and should be limited solely to the patents subject to the dispute and the geographic market in which such patents provide protection.
The Authority also identifies increasing sector-wide transparency regarding information on patent disputes and enhancing cooperation between the Turkish Patent and Trademark Office and judicial authorities as areas open to further consideration.
At this point, the proposal to increase patent transparency should be assessed not only from a public policy perspective, but also in terms of its potential function of expanding the Authority’s data pool in the future.
IV. Competition at the Market Entry Stage
The Preliminary Report states that, while the licensing and reimbursement regulations applicable to the pharmaceutical sector serve legitimate objectives, in certain circumstances they may be used strategically to hinder competitors’ entry into the market or their activities in the market.
In the context of the pharmaceutical sector, the Preliminary Report expressly reaffirms a well-established principle of general competition law practice: formal compliance with sector-specific regulations, including licensing, pricing, and reimbursement mechanisms, does not, in itself, mean compliance with competition law; these two areas of compliance are assessed independently from one another. Indeed, as specifically emphasized in the Preliminary Report, the fact that conduct forming part of a strategy aimed at preventing competitors from entering or expanding in the market may appear to comply with sector-specific regulations will not preclude such conduct from being separately reviewed under the competition rules.
This finding demonstrates that even strategic conduct that appears to comply with applicable regulations may be scrutinized under the competition rules where it serves to exclude competitors or restrict competition. Accordingly, it is of significant importance for pharmaceutical companies to assess their strategic choices regarding licensing, pricing, and reimbursement processes not only from the perspective of sector-specific legislation, but also concurrently from a competition law perspective.
In this context, product hopping practices are addressed separately. The possibility that an originator pharmaceutical manufacturer may withdraw its existing pharmaceutical product from the market shortly before the expiration of patent protection, thereby preventing a generic pharmaceutical manufacturer from relying on that product as a reference in its own marketing authorization application, is assessed. The Authority states that the cancellation of a marketing authorization will not, in itself, be considered anticompetitive; rather, the market structure, the undertaking’s objective and other conduct, the economic and therapeutic benefits of the new product, and its effects on the conditions for generic pharmaceuticals’ market entry should be assessed together.
Product hopping strategies are among the practices examined by the Authority within the framework of its “holistic conduct” approach. The statement that a single cancellation of a marketing authorization will not, in itself, constitute an infringement should not be read as an assurance, but rather as a delineation of the scope requiring careful assessment: it is understood that the Authority will conduct a holistic assessment based on the relevant product market, the undertaking’s overall strategy, and the effects on generic competitors.
Within this framework, it is recommended that the legislation governing marketing authorization cancellation procedures be reviewed in light of product hopping strategies and, where deemed necessary, that consideration be given to a regulation allowing the relevant toxicological and pharmacological tests and clinical trial results to be used in generic pharmaceutical marketing authorization applications for a certain period even after the marketing authorization for the reference pharmaceutical product has been cancelled at the request of the marketing authorization holder.
With respect to reimbursement, it is identified that the continued presence in the reimbursement system of the lowest-priced pharmaceuticals that are not actually available on the market may prevent other pharmaceuticals from entering the fast-track reimbursement process. The Authority therefore recommends that the process for inclusion in the reimbursement list and the internal reference pricing system be reviewed by taking actual availability into account.
It is also assessed that the 1% market share threshold under the internal reference pricing system is not, by itself, sufficient to demonstrate a pharmaceutical product’s geographic distribution, continuity of supply, and availability in pharmacies or hospitals, and it is recommended that this threshold be set at a more meaningful level.
These recommendations appear to target the structure that results in a price reference that does not actually exist in the market being maintained at an unrealistically low level. Revising the dynamics of the reimbursement list and the threshold under the internal reference pricing system may have significant implications, particularly for initial market-entry pricing strategies.
The Preliminary Report specifically emphasizes that compliance with sector-specific regulations does not, in itself, mean compliance with the competition rules. Internalizing this distinction requires pharmaceutical companies to apply a competition law perspective in parallel when conducting their regulatory compliance processes.
V. Competition at the Distribution Stage
The Preliminary Report examines pharmaceutical distribution separately with respect to the retail pharmacy channel and the tender channel. It states that a limited number of large pharmaceutical warehouses hold high market shares in the retail pharmacy channel, and that economies of scale, purchasing power, logistics infrastructure, and financial capacity contribute to the persistence of this structure. Pharmacist cooperatives and regional warehouses are considered to constitute competitive counterweights to large pharmaceutical warehouses.
The Preliminary Report quantifies this concentration: among the wholesalers active in the retail pharmacy channel, the top two hold approximately two-thirds of the market by share, and the top five hold approximately 90 percent. The Preliminary Report also states that this concentration in the wholesale pharmacy market should be taken into account in requests for exemption of vertical agreements containing exclusivity between manufacturers and wholesalers.
- DMO Health Market Program
This shift in the distribution landscape is also reflected in the Authority’s own enforcement record: since 2021, the Board has issued markedly fewer exemption and negative clearance decisions in the sector, a trend the Preliminary Report attributes largely to the centralization of public pharmaceutical procurement under the Health Market Program. Because that program built the single-distributor requirement directly into the tender process, undertakings that previously sought individual exemptions for exclusivity arrangements in public tenders have had far less occasion to do so, reshaping the touchpoints between the pharmaceutical industry and the Authority.
With respect to public pharmaceutical procurement, the DMO Health Market Program and the province-based single authorized distributor model introduced within the scope of this program are examined in detail. The Authority states that, given the centralized and electronic structure of the Health Market Program, certain efficiencies previously claimed to have been achieved through the use of exclusive pharmaceutical warehouses are now largely provided by the system itself and that, therefore, the single authorized distributor requirement should be reassessed.
In this context, and noting that EU practice imposes no comparable single-
distributor requirement following the 2022 amendment to the EU Vertical Block
Exemption Regulation (VBER), it is recommended that, instead of a province-based single authorized distributor model, a shared exclusivity arrangement allowing up to five authorized distributors to be appointed per province be adopted, provided that authorized distribution rights for competing products are not concentrated in the same pharmaceutical warehouse.
The Authority also reviewed more than 50,000 procurement items relating to 175 active substances in 2022 and 2023 and found that discount rates increased in tenders with a higher number of participants; in this context, it assessed that intra-brand competition may generate consumer benefits.
- Exclusivities in the Private Hospital Channel
With respect to exclusive distribution agreements in the private hospital channel, it is assessed that, under the current circumstances, exclusivity has a limited impact on the high market shares of pharmaceutical warehouses. However, it is stated that the proliferation of such agreements or their concentration among a limited number of pharmaceutical warehouses may raise concerns under competition law.
The Authority also states that, in the exemption assessment of exclusive distribution agreements, general or hypothetical efficiency claims will not, in themselves, be sufficient; the efficiencies put forward must be supported by concrete data and elements that can be substantiated in detail.
- Public Institution Discount
The Preliminary Report identifies certain issues arising from the fact that the Public Institution Discount (“PID”) mechanism does not clearly regulate which market participant is responsible for applying the discount and at which stage it should be applied. It is stated that two different practices exist: applying the PID upfront to all products, and applying it retroactively after the pharmaceutical product has been delivered to the patient. The first method is stated to create additional costs for suppliers, while the second results in administrative burden and uncertainty for pharmacies.
It is also assessed that the retroactive application may raise concerns regarding the security of personal data and trade secrets, as well as the sharing of competitively sensitive information.
This point also warrants particular attention: the integrated data-sharing infrastructure to be established between MEDULA and the Pharmaceutical Track and Trace System for the operation of the retroactive PID process would create a systemic flow of data. Whether such infrastructure could affect the security of personal data and trade secrets, and whether it could create a risk of access to competitively sensitive information, constitutes a separate compliance consideration for the undertakings that will participate in this infrastructure.
For this reason, the Authority recommends that the PID be applied only to prescriptions reimbursed by the Social Security Institution and approved through the MEDULA system, that it be expressly regulated that the financial responsibility rests with the supplier undertaking the PID obligation, and that the verification process be carried out through the integrated data-sharing infrastructure to be established between MEDULA and the Pharmaceutical Track and Trace System.
With respect to the non-application or under-application of the PID, it is further recommended that a security account be established before the Social Security Institution and used to compensate pharmacies for losses incurred, and that sanction and incentive mechanisms be developed.
VI. Conclusion
The assessments set out in the Preliminary Report are grouped under three main headings: (i) atypical competition law infringements that may be carried out by taking advantage of regulatory frameworks such as patent, marketing authorization, and reimbursement legislation, (ii) exclusivity practices between pharmaceutical manufacturers and pharmaceutical warehouses, and (iii) regulatory improvements aimed at enhancing the competitive structure without fundamentally changing the existing legal, administrative, and financial framework.
In this context, the Authority recommends strengthening the regulations of the Turkish Medicines and Medical Devices Agency and the Social Security Institution against potential abuses, enabling intra-brand competition in the Health Market Program through shared exclusivity, and addressing the issues arising from the PID mechanism through measures such as a security account and an integrated data-sharing infrastructure.
Although the Preliminary Report is not yet final in nature, it constitutes a source that should be closely monitored, as it systematically sets out the Authority’s findings and recommendations concerning the pharmaceutical sector. If the proposed regulatory approach and potential legislative amendments are implemented, the operations and practices of market participants in the pharmaceutical supply chain, including manufacturers and suppliers, pharmaceutical warehouses, and pharmacies, may be directly affected.
It is important for undertakings operating in the sector to closely monitor these developments and assess their practical implications within the framework of their own business models.
Competition Newsletter / July 2026
Regulatory Updates
- The European Commission announced that, as of July 1, 2026, the customs duty exemption for e-commerce consignments valued below EUR 150 has been abolished as part of efforts to ensure fairer competition between EU businesses and non-EU online sellers. Under the new regime, goods purchased online from third countries and shipped directly to consumers in the EU are subject to a EUR 3 customs duty per item, with the duty being collected from platforms or other businesses involved in the sale and transport rather than from consumers. The measure forms part of the broader EU Customs Reform and aims to address competitive imbalances created by low-value imports, while also strengthening consumer protection and improving compliance with EU product safety rules. The transitional regime will remain in place until July 2028, when the EU Customs Data Hub becomes operational and standard customs rules begin to apply.
Miscellaneous Developments
- The Turkish Competition Authority (“TCA”) imposed an interim measure requiring Haribo to allocate 30% of the visible area of its confectionery stands to competing soft-candy brands at traditional retail outlets with a sales area of 200 square meters or less. The allocated space must be arranged vertically as a single block and marked with a label stating that it is reserved for competing products, giving rival brands without their own stands access to shelf space while the underlying investigation continues. Haribo is required to implement and document compliance with the measure within one month, or risk an administrative fine.
- The Turkish Competition Board concluded its investigation into Coca-Cola Satış Dağıtım A.Ş. (“CCSD”) after accepting a comprehensive set of commitments aimed at addressing competition concerns in the non-alcoholic beverages market. Under the commitments, 35% of the visible space in each Coca-Cola cooler at retail outlets will be reserved for competing products, while CCSD will be prohibited from directing which rival products may be placed in the allocated area or restricting their visibility. CCSD will also discontinue minimum annual purchase requirements linked to cooler supply, revise its bonus and incentive systems, remove certain financial support practices for dealer employees and introduce objective and category-specific criteria for discounts and commercial support. The commitments will be implemented in stages between the service of the Board’s decision and the end of 2027, while CCSD’s existing obligations arising from previous Competition Board decisions will remain in force.
- The European Commission issued two sets of binding specification measures to Google LLC (“Google”) under the Digital Markets Act (“DMA”) on AI interoperability on Android and the sharing of Google Search data. The first set of measures aims to ensure that competing AI services can compete with Google’s own services, such as Gemini, by obtaining equal access to key features on Android devices. The measures will allow users to activate their preferred third-party AI assistants through voice commands and use them to perform actions in apps, subject to safeguards for privacy, device integrity and security. The second set of measures specifies how Google should share search data with third-party search engines, including AI chatbots offering search functionalities, in order to support the development of competing search services and privacy-focused alternatives. The Commission also set out anonymization safeguards, a pricing formula for shared data and a transparent access process with search-data sharing due to begin in January 2027 and Android interoperability measures expected from July 2027.
- The European Commission hosted a stakeholder roundtable as part of its ongoing market investigation into cloud computing services under Article 19 of the Digital Markets Act (“DMA”) bringing together cloud providers, business users, software providers and technical experts Discussions focused on interoperability and technical features, financial conditions, and contractual and commercial practices, with particular emphasis on measures that could reduce switching barriers, facilitate interoperability and strengthen customer choice. The input will contribute to the Commission’s assessment of whether the current DMA obligations adequately address unfair or anti-competitive practices in the cloud sector with a report due by May 2027 at the latest.
- The European Commission fined Google LLC (“Google”) a total of EUR 890 Million for breaches of the Digital Markets Act (“DMA”). The Commission adopted two non-compliance decisions, imposing a EUR 460 Million fine for Google’s self-preferencing of its own services on Google Search and a EUR 430 Million fine for restrictions imposed on app developers’ ability to direct users to alternative purchase channels on Google Play. The Commission found that Google gave preferential treatment to its own services, including shopping, hotels, transport and sports results, by displaying them more prominently in search results than comparable third-party services. It also found that Google prevented app developers from freely communicating and promoting alternative offers and concluding contracts with users through channels of their choice, including third-party app stores. As part of the decisions, the Commission ordered Google to bring the non-compliance to an end.
- The European Commission approved Paramount Skydance Corporation’s (“Paramount”) proposed acquisition of Warner Bros. Discovery (“Warner”) under the EU Merger Regulation, subject to commitments. The Commission found that sufficient competitors would remain in the European Economic Area (“EEA”) at the film production level, including major U.S. studios, smaller U.S. studios and European studios. However, it identified competition concerns at the film distribution level in EEA countries where Paramount has a structural partnership with Universal through the United International Pictures (“UIP”) joint venture, as the transaction could have resulted in Warner’s films also being distributed through UIP and led to worse rental and distribution terms for cinema operators. To address these concerns, Paramount committed to terminate its stake in UIP in the EEA within 13 months from closing and, for 10 years, not to enter into arrangements with Universal to jointly co-distribute films in the EEA or shift certain film distribution activities to distributors also handling Universal or Disney films in the relevant UIP countries.
- The European Commission is reported to be considering whether ChatGPT and Roblox should be designated under the enhanced oversight regime of the European Union’s Digital Services Act (“DSA”), following disclosures that both services exceeded the relevant user threshold. According to the report, both services disclosed user numbers above the relevant threshold that may trigger additional obligations applicable to the largest online services under the DSA. The Commission has not announced a formal decision but indicated that the possibility remains under consideration and that any designation would be assessed on a case-by-case basis. If designated, ChatGPT and Roblox would become subject to additional regulatory obligations aimed at strengthening platform accountability, risk assessment, transparency and oversight. The development reflects the Commission’s continued focus on bringing large digital services, including artificial intelligence tools and online platforms with significant user bases, within the scope of the DSA’s enhanced compliance framework.
- The European Data Protection Board (“EDPB”) and the European Commission opened a call for expressions of interest for a remote stakeholder event on the forthcoming guidelines concerning the interplay between competition law and data protection. The event will take place on October 15, 2026, and is intended to allow individuals and organizations with relevant expertise to contribute to the ongoing work. The initiative reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation under the Helsinki Statement and its 2024-2027 Strategy. Applications will remain open until August 28, 2026.
- The Court of Justice of the European Union (“CJEU”) upheld the power of competition authorities to seize business-related employee and executive emails during antitrust inspections without prior judicial authorization, provided that adequate procedural safeguards and judicial review mechanisms are available. The ruling arose from legal challenges brought in Portugal by companies contesting measures taken by the Portuguese Competition Authority during antitrust investigations. The CJEU rejected the argument that seizing emails without prior court authorization necessarily violates fundamental rights under EU law, finding that effective competition enforcement may justify such investigative measures where appropriate legal safeguards exist.
- The Court of Justice of the European Union dismissed Google LLC (“Google”)’s final appeal, making final a EUR 4.1 billion antitrust fine over the company’s Android business practices. The judgment upheld findings that Google abused its dominant position by requiring smartphone manufacturers to pre-install Google Search and Chrome and by restricting the use of alternative versions of Android. The ruling concludes nearly eight years of litigation that began after the European Commission (“Comission”) imposed a EUR 4.34 billion fine in 2018, which was later reduced to EUR 4.1 billion by the General Court in 2022.
- The General Court of the European Union upheld Apple Inc. (“Apple”)’s designation as a gatekeeper under the Digital Markets Act (“DMA”), maintaining regulatory obligations for iOS and the App Store. In its July 8, 2026 ruling, the court rejected Apple’s arguments that its app stores should be treated as separate services and dismissed its challenge regarding iMessage, finding that the messaging service was not subject to additional obligations under the DMA. Apple stated that it may appeal the decision to the Court of Justice of the European Union, arguing that the requirements are disproportionate and could undermine user privacy and security.
- The UK Competition and Markets Authority (“CMA”) launched an investigation into Microsoft Corporation (“Microsoft”) over concerns that customers may have been misled about Microsoft 365 Personal and Family subscription plans, including the addition of Copilot and other new features. From January 2025, Microsoft gave existing customers access to the new features at no extra cost for the remainder of their subscription period, but customers were automatically rolled onto higher-priced plans unless they selected another plan or ended their subscription. The CMA will examine whether Microsoft’s pre-renewal communications gave customers sufficient information to make an informed decision, and has not reached any conclusion on whether Microsoft breached the law, while competition authorities in Australia and Italy are separately investigating Microsoft entities in relation to similar subscription renewal practices.
- The UK Competition and Markets Authority (“CMA”) published its Annual Report and Accounts for the 2025–2026 financial year, covering the period from April 1, 2025 to March 31, 2026. The report provides an overview of the CMA’s performance, including its work to promote economic growth, improve household prosperity and enforce competition and consumer protection rules.
- The French Competition Authority ordered Meta Platforms, Inc. (“Meta”) to resume negotiations with French press organizations DVP and APIG regarding compensation for the use of journalistic content and to provide the information needed to assess its payment framework within 15 days. The Authority’s preliminary assessment indicated that Meta’s negotiating conduct, including its proposed payment methodology and the information shared with publishers, may raise competition concerns. The dispute relates to the European Union’s neighboring rights framework, which allows news publishers to seek payment when digital platforms reuse or display portions of their journalistic content. Meta disagreed with the Authority’s conclusions but stated that it would continue participating in the process.
- The French Competition Authority is reported to be close to deciding whether to formally accuse NVIDIA Corporation (“Nvidia”) of anticompetitive conduct in connection with competition concerns in artificial intelligence infrastructure. The potential statement of objections would mark a significant step in the authority’s investigation and could open an adversarial phase in the case, although no public details have been provided on the specific allegations and the conclusion of the investigation does not necessarily mean that Nvidia will face sanctions. The investigation stems from broader concerns over competition in cloud computing and artificial intelligence infrastructure, including dependence on Nvidia’s CUDA software ecosystem and the relationships between chip suppliers, cloud providers and artificial intelligence developers. The development reflects increasing regulatory scrutiny of whether concentration in semiconductors, cloud computing and foundational artificial intelligence models could limit market entry and innovation.
- The Belgian Competition Authority (“BCA”) launched a formal antitrust investigation into Google LLC (“Google”) over suspected conduct in the online advertising sector following a preliminary assessment that found indications of a possible breach of Belgian and European competition rules on abuse of dominance. The inquiry focuses on Google’s role across multiple layers of the online advertising supply chain, including advertising exchanges and tools used by advertisers to purchase digital ads. The BCA will assess whether Google’s contractual terms governing certain advertising intermediation services, as well as potential differences in how those services are provided, may have disadvantaged customers or competing businesses. The opening of formal proceedings does not prejudge the outcome of the investigation.
News From Private Sector
- Google LLC (“Google”) reached a settlement with the Russian Federal Antimonopoly Service (“FAS”) to resolve a long-running antitrust dispute concerning its Android business practices. Under the settlement, Google will no longer require exclusivity for its applications on Android devices sold in Russia and will allow competing search services and applications to be pre-installed on smartphones. The company also agreed to pay a fine of RUB 438 Million, equivalent to approximately USD 7.8 Million. The case originated from a complaint filed by Yandex in 2015, alleging that Google’s licensing practices restricted competition in the mobile software market by tying access to Google Play and other services to the pre-installation of Google’s own applications. The settlement also includes a search selection mechanism allowing Russian Android users to choose their preferred default search engine, with the measures intended to expand consumer choice and improve access for competing software providers and online services.
- Google LLC (“Google”) reportedly asked a UK court to exclude aspects of the European Commission’s recent Digital Markets Act (“DMA”) non-compliance decision from evidence in a multibillion-pound damages lawsuit brought by rival comparison shopping services. The request relates to ongoing private enforcement litigation in the United Kingdom following regulatory findings concerning Google’s conduct in digital markets. The development reflects the growing interaction between public enforcement under the DMA and follow-on damages actions brought by competitors alleging harm from large digital platforms’ market practices.
- Apple Inc. (“Apple”) and the U.S. Department of Justice (“DOJ”) reportedly began preliminary settlement discussions in the federal antitrust case concerning Apple’s alleged dominance in the smartphone market. The lawsuit, filed in March 2024 by the DOJ and a coalition of states, alleges that Apple used restrictions within its ecosystem to suppress competition, increase switching costs and reinforce customer dependence on the iPhone. The complaint focuses on practices affecting messaging interoperability, cloud gaming services, digital wallets, smartwatches and “super apps.” Apple has denied the allegations and maintains that its ecosystem policies are designed to protect user privacy, security and product quality. The reported discussions remain at an early stage, with no certainty that they will result in a settlement, while the case continues to be viewed as a significant test of how U.S. antitrust law addresses platform gatekeeping, interoperability and market concentration in digital ecosystems.
- A U.S. federal judge approved Anthropic PBC’s (“Anthropic”) USD 1.5 Billion settlement with a group of authors in a major artificial intelligence copyright case with broader implications for competition in the artificial intelligence sector. The settlement resolves claims alleging that Anthropic improperly copied millions of copyrighted books, including pirated works, to develop its Claude chatbot. Although the case is primarily a copyright matter rather than an antitrust case, disputes over lawful access to large-scale training datasets may affect the competitive structure of the artificial intelligence sector. The case also comes amid wider scrutiny by competition authorities in the United States, the United Kingdom and the European Union of partnerships between major technology companies and leading artificial intelligence developers, including concerns that access to proprietary data, cloud infrastructure and distribution channels may create barriers for smaller developers.
Data Protection Obligations of Foreign Data Controllers in Türkiye, Mainly VERBIS and Data Access Laws
1. Introduction
This article has been prepared within the scope of the Turkish Personal Data Protection Law (“Law”) and the jurisdiction of the Law, with a view to identifying the foreign data controllers’ obligation for the registration to Data Controllers’ Registry (“Registry” or “VERBIS”) and the future steps that can be taken to ensure compliance with the Law for the data processing activities undertaken.
The Law defines the data controller as “the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system”, while the data processor is defined as “the natural or legal person who processes personal data on behalf of the data controller upon its authorization”. As can be seen from the definitions provided, the data controller and data processor concepts are identical to those provided under the European Union’s General Data Protection Regulation (“GDPR”). Consequently, any data controller/data processor assessments made under Law will be also identical to those that have been made within EU jurisdiction.
2. Registration Obligation with Registry
Within the scope of Article 16 of the Law and the Regulation on the Data Controllers Registry (“Regulation”), non-resident data controllers that process personal data of data subjects located in Türkiye are under the obligation to register to the VERBIS before initiating such personal data processing activities.
Therefore, in order to comply with this registration obligation, foreign data controllers must fulfill the following steps before starting processing data of those located in Türkiye:
- Appointing a data controller representative who must be either a Turkish national or a legal entity established in Türkiye ,
- Filling out the sign-up form,
- Applying for a username and password,
- Appointing contact person and registration to VERBIS,
- Upon the preparation of a personal data processing inventory, uploading the required information.
2.1. Appointing a data controller representative who must be either a Turkish national or a legal entity established in Türkiye
• A representative of the data controller should be appointed in order to ensure communication with the Data Protection Authority (“Turkish DPA”) regarding the obligations under the Law and the secondary regulations to be issued on the basis of this Law.
• This representative can be a natural or legal person residing in Türkiye.
2.2. Carry out the initial registration request from the system (requesting a username and password from the Turkish DPA)
- The application form should be filled in on the VERBIS registration screen on the website of the Turkish DPA.
- If the registered electronic mail (KEP) address is provided when the application form is issued, the information form in PDF format must be sent to the Turkish DPA via the KEP address provided.
- If the KEP address is not indicated on the application form, the information form in PDF format must be printed out and sent to the Turkish DPA by post. Applications sent by this method must be wet signed and stamped.
- Once the PDF of the relevant application form has been sent to the Turkish DPA, the Turkish DPA will send a username and password to the email address provided by the data controller representative in the form.
2.3. Preparation of a personal data processing inventory
- In subparagraph (h) of Article 4 of the Regulation, personal data processing inventory is defined as “the inventory in which data controllers detail the personal data processing activities they carry out depending on their business processes by associating them with the purposes and legal grounds for processing personal data, the data category, the transferred recipient group and the data subject group and by explaining the maximum retention period required for the purposes for which personal data are processed, the personal data foreseen to be transferred to foreign countries and the measures taken regarding data security”.
- Article 5 of the relevant Regulation states that “Data controllers who are obliged to register with the Registry are obliged to prepare a Personal Data Processing Inventory. The information to be disclosed to the Registry in the registry applications shall be prepared based on the Personal Data Processing Inventory.”
- Accordingly, a personal data processing inventory must be prepared by foreign data controllers. Based on the information contained in the relevant inventory, the relevant information should be registered to VERBIS on a categorical basis.
3. Intersection of Standard Contractual Clauses and the Registry
According to the Law, standard contractual clauses signed between the data exporters and data importers are notified to the Turkish DPA within 5 (five) business days of its signing. This creates a practical risk for controllers who are not registered to the Registry but are parties to these standard contractual clauses.
There are four modules of standard contractual clauses that can be signed according to the Law. These are:
- Controller-Controller (Module 1)
- Controller-Processor (Module 2)
- Processor-Processor (Module 3)
- Processor-Controller (Module 4)
Regarding modules 1 and 4, the foreign entity signs a standard contractual clause stating that it is acting as a controller according to the Law. Since these standard contractual clauses are notified to the Turkish DPA, the Turkish DPA can cross-check its records on the Registry and initiate an investigation to the foreign controller who is not registered. Therefore, if the foreign entity will sign modules 1 and 4 of standard contractual clauses in Türkiye, it is advised for these entities to also conduct the necessary operations in order to register to VERBIS.
We would like to note that non-compliance with the VERBIS registration obligation might result in an administrative fine from TRY 341.809 (approx. EUR 6.424) up to TRY 17.092.242 (approx. EUR 321.077). Additionally, according to 2025 Activity Report of the Turkish DPA, a total of TRY 818.567.000 (approx. EUR 15,386,597) administrative fine has been issued to local and foreign data controllers who did not have a registration in the Registry.
Regarding the detection of the registration obligation, please see the graph below:

4. The Likelihood of Turkish Regulators Asking for Access to Personal Data
4.1. Government Access to Personal Data Held by Companies
The Turkish legal system often grants broad powers to public authorities to request information and documents from private entities (such laws will be referred as “Data Access Laws”). Hereinafter, we will discuss the potential practical impact of these Data Access Laws in relation to routine business operations of private entities:
4.2. Likely Practical Risk of Receiving Data Access Requests
Most Turkish companies do not handle any information of interest to the Turkish intelligence agency, namely, the National Intelligence Organization and are not likely to receive requests based on the State Intelligence Services and the National Intelligence Organization Law No. 2937. Companies engaged in providing ordinary commercial products or services, and whose EU-TR transfers of personal data involve ordinary commercial information like employee, customer, or sales records, would have no basis to believe the Turkish intelligence agency would seek to collect this data.
Additionally, requests from the police (Law No. 2559 on the Duties and Authorities of Police), gendarmerie (Law No. 2803 on the Organization Duties and Powers of Gendarmerie) and courts (Criminal Procedure Law No. 5271) are only likely to be in question in case of a pending lawsuit or a criminal investigation directly concerning the persons whose personal data are requested.
As for the rest of the authorities, their requests are mainly limited to their own field of operation, such as protection of competition, combatting money laundering etc. To the extent that, under the respective specific laws these government authorities may request disclosure or seek access to personal data, the access requests are generally only incidental to the sector specific investigations and only occur in single regulated cases in the specific market or sector. Therefore, these laws are no concern of disproportionate access to personal data since powers granted to public authorities to request disclosure or seek access to data are based on clear and precise rules accessible to the public and do not exceed what is necessary and proportionate in a democratic society to safeguard national security, defense and public security. In particular, these laws do not empower government authorities to access personal data arbitrarily and without any limitations in scope and purposes of data access and requests. Also, these laws provide for independent and impartial oversight systems and effective rights and remedies are available to the affected individuals.
However, it is important to note that when any information is of interest to any of the authorities mentioned they may tend to request more information than necessary and fail to make the reasoning of their requests very clear in practice. Within this scope the Turkish DPA has rendered decisions stating that real or legal persons who are faced with requests from governmental authorities must only provide information and comply with the requests of these authorities to the extend necessary and must refrain from providing excessive amounts of personal data within this framework in line with the Law. Turkish DPA’s stance against excessive data request is a positive sign in terms of the protection of personal and also non-personal information held by private entities and real persons.
4.3. Public Body Specific Considerations
- (i) Judicial Instances: Courts and prosecutors have a very wide authority to request all kinds of information from private entities and real persons. Basically, such request should be made written and based on a procedure prescribed within the criminal or civil procedure laws. Therefore, we can say that information requests to be made by such authorities are subject to strict regulations. However, in practice, the authorities may tend to issue information requests that are not well described or unproportionate considering the objective of such requests. In case of such request, all entities and real persons have the right to object to such request stating that the information request should be rendered in a proportionate way which is strictly limited with purposes of the relevant criminal or civil investigation or procedure.
- (ii) Security Forces: Information request to be rendered by security forces (police, intelligence service and military police (gendarmerie) may be the most problematic issue in terms of the daily practices of the private entities and real persons. Security forces, while fulfilling their duties vested by the relevant legislation and court decisions, need to carry out certain investigation activities which certainly may require information gathering tools. Security forces may conduct some legal interception (monitoring/surveillance) activities that need to be grounded on court decisions. These monitoring activities generally regard voice calls and correspondences. Monitoring should be limited with a certain time period and information should be gathered only with respect to the purposes of the subject matter investigation. Security forces may also make written information requests, similar to other authorities. We need to note that such requests may tend to be too broad and challenging in certain ways. Firstly, depending on the nature of the investigation, security forces may request a very broad scope or time period, for instance, particularly with terror investigations, they may be looking for the integrality of a certain database consisting of monetary transactions or purchase of certain goods. They may also be looking for digital activity records (logs) and/or IPs of certain people who are suspected of committing certain crimes. In any cases, private entities and real persons located in Turkey, are obliged to comply with such request provided that the requests are issued in compliance with the procedure laws and they are drafted in a proportionate and reasonable manner. On case of failure to comply with such a request, security forces are well equipped with legal instruments allowing them to enforce their requests by collecting digital copies of evidence or confiscating relevant hardware.
- (iii) Other Public Entities: Other public entities are also entitled to make information requests depending on their scope of activities; for instance, the Revenue Administration may issue formal requests in order to ask for records relating to taxpayers. In each specific case, a detailed assessment should be carried out to determine whether the requesting authority is entitled to ask for this specific information. In case of excess of their legal capacity, private entities and real persons, may object to such request.
Anonymization: Whether Objective or Subjective Anonymization Is Still Considered Personal Data Under Data Protection Legislation
I. Introduction
Anonymization is a critical concept in data protection law, particularly when determining whether certain datasets fall within the scope of “personal data.” The Turkish data protection legislation defines anonymization as “anonymization is the process of rendering personal data impossible to link with an identified or identifiable natural person, even through matching them with other data” and it states that “to anonymize the personal data, personal data shall be rendered impossible to relate to identified or identifiable person, even through using appropriate techniques in respect of the recording medium and relevant field of activity, such as recovery of data by the data controller, recipient or recipient groups and matching data with other data.”
The legal assessment of whether anonymized data is still personal data becomes nuanced when the data is transferred between two parties and the transferor party can still identify the person behind the data while the transferred party cannot. This article aims to discuss this issue.
II. Views of Various Data Protection Authorities on the Matter
For the sake of discussion, it is assumed that the data transferor party removes the identification aspects of the personal data and transfers the remaining data points to the transferred party. In this relationship, the transferred party has no other means to identify the person(s) behind the data it receives; however, the data transferor party still has this ability. This means that the data is subjectively anonymized (the data is unidentifiable only by the transferred party but could still be linked to an individual by the transferor party) as opposed to being objectively anonymized (the data is rendered irreversibly unidentifiable by anyone).
This is a highly controversial issue globally. One view on the matter states that as long as data transferor has the information that “the data corresponds to a data subject, this transfer of data is not an anonymous transfer (because data transferor has control over the content of the data = objectively this data is not anonymous) while the other states that it is an anonymous data transfer (because the data transferred party will never be able to determine who this data belongs to = subjectively anonymous data).
Although there is no decision from the Turkish Data Protection Authority (“Turkish DPA”) on this debate, the European Data Protection Supervisor (“EDPS”) and the Irish DPA consider that there is a transfer of personal data unless there is objective anonymization, while the UK DPA and the Court of Justice of the European Union (“CJEU”) consider that there is no transfer of personal data in the case of subjective anonymization.
Based on the definition of pseudonymization in the GDPR, for personal data to be pseudonymized, it must be treated in such a way that it is no longer possible to attribute the information to a specific data subject without the use of separate additional information. Thus, it must be theoretically possible to link this information and the additional information. However, the European Data Protection Board (“EDPB”), in its Guidelines 01/2025 on pseudonymisation, adopted on 16 January 2025, states that “if pseudonymised data and additional information could be combined having regard to the means reasonably likely to be used by the controller or by another person, then the pseudonymised data is personal. Even if all additional information retained by the pseudonymising controller has been erased, the pseudonymised data becomes anonymous only if the conditions for anonymity are met.”
On the other hand, the relevant rulings of the CJEU clearly point out that there needs to be a link between the one with such additional information and the controller. For example, in the Breyer Judgement, it is stated that “the fact that the additional data necessary to identify the user of a website are held not by the online media services provider, but by that user’s internet service provider does not appear to be such as to exclude that dynamic IP addresses registered by the online media services provider constitute personal data within the meaning of Article 2(a) of Directive 95/46. However, it must be determined whether the possibility to combine a dynamic IP address with the additional data held by the internet service provider constitutes a means likely reasonably to be used to identify the data subject.” In the concrete case, as long as data transferor does not share any additional information with the data transferred party, there will be no link between such additional information and the data importer.
Additionally, in the case numbered T-557/20 – SRB v. EDPS, the General Court stated that “It must be stated that, in the revised decision, the EDPS concluded that the fact that the SRB held additional information enabling the authors of the comments to be re-identified was sufficient to conclude that the information transmitted to Deloitte was personal data, while acknowledging that the identification data received during the registration phase had not been communicated to Deloitte.
Accordingly, it is apparent from the revised decision that the EDPS merely examined whether it was possible to re-identify the authors of the comments from the SRB’s perspective and not from Deloitte’s.
It is apparent from paragraph 45 of the judgment of 19 October 2016, Breyer (C‑582/14, EU:C:2016:779), cited in paragraph 92 above, that it was for the EDPS to determine whether the possibility of combining the information that had been transmitted to Deloitte with the additional information held by the SRB constituted a means likely reasonably to be used by Deloitte to identify the authors of the comments.
Therefore, since the EDPS did not investigate whether Deloitte had legal means available to it which could in practice enable it to access the additional information necessary to re-identify the authors of the comments, the EDPS could not conclude that the information transmitted to Deloitte constituted information relating to an ‘identifiable natural person’ within the meaning of Article 3(1) of Regulation 2018/1725.”
In parallel with the General Court’s decision above, the CJEU made similar assessments in the Scania judgment. In the relevant judgment, the CJEU stated that “”When third parties reasonably have the means to link a VIN to an identified or identifiable natural person—which it is up to the referring court to verify—that VIN constitutes personal data for them.” and “the concept of “processing” under Article 4(2) of the GDPR (…) encompasses any form of enabling access to a VIN by the data controller when that VIN makes it possible to identify a natural person.”
Lastly, in the case numbered C-413/23 P, which is the appeal of case numbered T-557/20 mentioned above, CJEU determined that “Accordingly, provided that such technical and organisational measures are actually put in place and are such as to prevent the data in question from being attributed to the data subject, in such a way that the data subject is not or is no longer identifiable, pseudonymisation may have an impact on whether or not those data are personal.”
III. Views of Turkish Authorities
As mentioned above, the Turkish DPA has not made a decision on anonymization directly. However, the Turkish Data Protection Board (the “Board”) and the Banking Regulation and Supervision Agency (the “BRSA”) have concluded in various decisions that personal data does not lose its personal data features when processed or transferred by hashing or masking.
In its decision dated 20/05/2020 and numbered 2020/404, the Board stated that “biometric data do not lose their characteristics as biometric data when stored using the hash method; therefore, in the absence of explicit consent, biometric data may only be processed in accordance with the conditions set out in the laws specified in Article 6 of the Law”. It can therefore be concluded that the Board interpreted the hash method as a technical measure.
According to Circular 2022/1 of BRSA regarding “Sharing of Information that are Considered as Secret” it is stated that “Transferring confidential data to the other party in an encrypted form, or implementing access controls to prevent unauthorised access, constitutes a “technical measure”. Claiming that the recipient was prevented from learning the content of the transferred data through the implementation of these technical measures does not mean that the confidential data was not shared with the other party. On the contrary, the confidential information is deemed to have been shared.”. Therefore, although the Turkish DPA does not have a clear view on the matter, certain authorities in other sectors, such as BRSA – banking, consider anonymization as only objective anonymization and not subjective.
IV. Conclusion
Anonymization is not a binary concept—it exists on a spectrum between subjective and objective standards. Given the regulatory uncertainty and divergent interpretations across jurisdictions, organizations should be vary of the technical and organizational measures regarding personal data.
Accordingly, if the data transferred party has no reasonable means to associate the pseudonymized data transferred by the data transferor with an identified or identifiable natural person, it may be assumed that this data does not constitute personal data for the data transferred party. In other words, if the data transferred party has no legal means available to it which could, in practice, enable it to access the additional information necessary to re-identify the data transferor’s data subjects and if the data transferred party has no way of combining the information provided to it with additional information held by data transferor, it can be concluded that there is no transfer of personal data.
However, it is recommended that the agreement signed with the data transferred party should include a statement that the relevant transfer does not constitute a transfer of personal data. The measures suggested in paragraph 114 of the EDPB guidance should also be considered. These can be listed as follows: (i) Whenever the pseudonymization domain is to consist of a defined set of recipients, the responsibilities of all parties involved should be defined by an arrangement, preferably in contractual form. (ii) Those arrangements should reflect the need to keep the pseudonymized data within the pseudonymization domain, and to limit the inflow of or access to information that might allow attribution of pseudonymized data to data subjects, including among the recipients. (iii) Whenever relevant, the arrangements should regulate the process to be followed when assumptions about the pseudonymization domain need to be adapted. (iv) It should be noted that such arrangements on their own are not sufficient to ensure a proper separation of the pseudonymization domain from additional data without corresponding effective enforcement.
Presidential Decrees on Cybersecurity Presidency & General Directorate of National Technology and Artificial Intelligence
I. What Happened?
On December 25, 2025, two Presidential Decrees have been published in the Official Gazette:
- Presidential Decree No. 192, amending the institutional framework governing the Cybersecurity Presidency, which was established at the beginning of 2025. The Decree primarily covers amendments to:
- Reorganize the institutional structure of the Cybersecurity Presidency,
- Expand its mandate to explicitly cover digital government,
- Establish new general directorates, and
- Redefine its duties, powers, and staffing structure.
- Presidential Decree No. 191 introduced significant structural changes to the Ministry of Industry and Technology to centralize the governance of AI and digital infrastructure.
II. Reorganization of the Cybersecurity Presidency Structure
As part of the restructuring of service units, the following general directorates were newly established:
- Public Artificial Intelligence General Directorate,
- Digital Government General Directorate,
- Management Services General Directorate,
- Strategy Development Department,
- Office of the Private Secretary.
III. New Duties and Responsibilities of the Cybersecurity Presidency
In general, the amendments clarify that responsibilities previously falling within the duties of the Presidency’s Digital Transformation Office (“DTO”), such as the delivery of public services through digital channels (i.e. e-Government), the digitalization of the public sector, the public sector’s use of artificial intelligence, and data governance, have now been transferred to and consolidated under the Cybersecurity Presidency.
Accordingly, in addition to the duties assumed for the cybersecurity field, now, the Cybersecurity Presidency is tasked with the following duties:
- IT Procurement and Use of Public Institutions and Organizations:
- Determining procedures, principles and standards regarding administrative, financial, and technical characteristics of IT products, services and systems that will be supplied or developed by public institutions and organizations.
- Determining project management principles, procedures and principles regarding the IT projects of public institutions and organizations and providing opinions to the Strategy and Budget Presidency on their financial and technical aspects.
- AI & Data:
- Contributing to national policies, strategies and actions plans to be prepared in the field of AI.
- Contributing to the works on the harmonization of the national legislation with international regulations.
- Conducting legislative work on public-sector AI applications, which indicates that Türkiye is beginning to differentiate between regulatory expectations for public administrations and those that may later apply to the private sector.
- Establishing principles, procedures, and standards for data governance covering the management of data in the context of digital government and the use of AI technologies in the public sector, from its creation to its destruction.
- Pioneering AI applications in the public sector, identifying the relevant requirements in collaboration with the relevant institutions, implementing a common data infrastructure, determining the quality criteria and standards for data to be used in applications, and ensuring compliance with these criteria and standards.
- Digital Government:
- Conducting legislative work in the field of digital government, preparing national strategies and action plans, and coordinating and monitoring their implementation.
- Establishing the digital government institutional architecture.
- Developing and operating the e-Government Gateway and determining principles and standards for system integration and service delivery.
IV. General Directorate of National Technology and Artificial Intelligence of the Ministry of Industry and Technology
Presidential Decree No. 191 renames the “General Directorate of National Technology” as the “General Directorate of National Technology and Artificial Intelligence” (“Directorate”), which is granted with expanded mandates to oversee the strategic development of AI, data center and cloud ecosystems in Türkiye.
The responsibilities of the newly restructured Directorate include the following duties:
- AI:
- Establishing necessary legislative regulations for AI.
- Ensuring that AI technologies are developed and utilized in accordance with reliable and ethical principles.
- Developing and implementing national policy proposals and strategies
- Enhancing data, infrastructure and human resource capacity for the advancement of AI technologies
- Providing support for startups and R&D activities within the field of AI
- Developing international cooperation frameworks for AI
- Ensuring governance and coordination at a national scale, including contributing to AI projects conducted across various public institutions.
- Data Center and Cloud:
- Undertaking the development of data center and cloud computing infrastructure in the country, formulating and implementing policy recommendations and strategies in this field, establishing criteria and standards for data centers, and implementing regulations for certification and authorization.
Part II – Evaluation of Connected Car Processes Within the Scope of Relevant Areas of Turkish Legislation
As detailed under part one of this article series, connected cars must be assessed by conducting analyses on multiple legislation such as consumer, data protection and telecommunication. This part will continue to analyze connected cars according to Turkish legislation.
Consumer Law & E-commerce
According to Turkish legislation, the online purchase and sale of products and services is classified as e-commerce. Therefore, online services provided through connected cars, such as purchases made via the connected car’s app or store, will be subject to this legislation. If connected car functions are provided via electronic commerce channels, the provider will be considered a “service provider” for these channels and will be required to comply with certain transparency and information provision requirements.
These include (i) displaying mandatory information under “contact” section within the stores, (ii) displaying mandatory information under “transaction guide” section within the stores (and if such section is not present on the website, to add one), (iii) designing the checkout process in line with the procedural requirements indicated in the e-commerce regulations, (iv) retaining records relating to e-commerce activities for at least 3 years and present them to the Ministry of Trade, when requested and (v) registering with the Electronic Commerce Information System (“ETBIS”) registry. The “Contact” section on stores should display the following information: e-mail address, telephone number, business name or registered brand name, trade name, head office address, membership to trade association and to sectoral institutions, if any, along with the relevant code of conduct (and how to electronically reach them).
Additionally, service providers are obliged to include the following information under the title of “transaction guide” on the home page, in a way that can be accessed directly through the website: (a) technical steps showing procedures such as choosing the goods, entering the delivery and payment information, and confirming the order for the contract with the customer to be established; (b) information on whether the contract for electronic commerce will be stored electronically, whether it will be possible for the consumer to access this contract later from the same website, and for how long this access will be provided; (c) information on the provision of technical tools, such as a summary order form and a “back” button, to help consumers identify and correct errors in data entry before placing an order, (d) alternative dispute resolution mechanisms, if any, in case of disagreement with the consumer.
Procedural requirements relating to checkout processes include the following obligations: During the confirmation of the order placed over the website and before entering the payment information, the total price to be paid by the consumer, including tax and delivery costs, and other terms of the contract must be clearly shown to the consumer; If the total cost of the good, the method of calculating the price and the delivery costs cannot be determined in advance, the consumer should be informed that additional costs may be paid; before order confirmation, an order summary should be provided so that consumers can identify data entry errors and appropriate, effective and easily accessible technical tools such as undo and change should be provided to correct these errors; contract terms and general transaction conditions should be sent to the consumer physically or electronically so that they can be viewed again; The information that the order has been received must be notified to the consumer without delay via the network where the transaction is made and also by at least one of the tools such as e-mail, short message, telephone call, fax (the order and confirmation of the receipt of the order will be deemed to have been realized as soon as the parties can access the aforementioned statements).
As for the ETBIS registration, requirements are as follows: Service providers conducting e-commerce activities are expected to register with the ETBIS; the registration should be concluded before the e-commerce platform starts to operate; the registration process can be completed online and it generally takes 1 – 2 hours if all information to be uploaded is at the ready; the registration is more of a notification than a permit/licensing by the and it allows the visitors to verify the identity of the service provider’s website through an online registration list: see https://www.eticaret.gov.tr/sirketsorgula.
In addition to above requirements, the service provider must present the consumer facing documentation (e.g. T&Cs, distance sales contracts in Turkish language.) According to the Turkish consumer protection regulations, every distance sales transaction must be concluded via an individual distance sales agreement that contains details of the goods/services purchased for every instance.
Pursuant to the Article 4 of the Consumer Protection Law numbered 6502, contracts and notifications to be provided to the consumers, such as terms and conditions, shall be drafted in a comprehensible language and in a clear, simple, and legible form. Similarly, data protection legislation in Türkiye requires any privacy notifications that are presented to the data subjects to be easily understandable, therefore the privacy policies presented to Turkish citizens in general must be in Turkish. As for the paid services of the service provider, according to the Distant Sales Regulation, a “preliminary information form” must be provided before the distance sales contract[1] is formed (on the purchase screen, before the consumer becomes under the payment obligation). The form may be presented on the checkout screen with an unchecked checkbox and must include the mandatory content[2] specified under Article 5 of the Distant Sales Regulation.
Lastly, the service provider must display the following information separately and in a clear and transparent manner on the checkout screen, right before the checkout: a) The basic characteristics of the goods or services subject to the contract, b) The total price of the goods or services including all taxes, c) information concerning right of withdrawal including information on the conditions, duration, procedure for exercising this right, d) information on the conditions under which the consumer will not benefit from the right of withdrawal.
As a side note, if the structure of the connected car services store allows the connected car service provider to facilitate other service providers in concluding contracts for the provision of such services, (e.g., individual consumption, e-charge services, entertainment services, digital assistants etc.) or to place orders (e.g., displaying information about the order summary, option to add or remove products/services), the connected car service provider will be considered as an electronic commerce intermediary service provider (“ECISP”) within the scope of local e-commerce regulations and be subject to the provisions of the Regulation on Electronic Commerce Intermediary Service Providers and Electronic Commerce Service Providers (“E-Commerce Regulation”) (such as signing an intermediary agreement with other service providers, allowing the distance contract and preliminary information form to be submitted by other service providers).
It is recommended that connected car service models offered in Türkiye are evaluated in light of the above legislation. Documents should be localized and ETBIS registration completed. If the connected car service provider is classified as an ECISP, the necessary procedural measures should be carried out with other service providers.
Other
AML/KYC Obligations
According to Article 4/1-o and 4/1-y of Regulation on Measures for the Prevention of Laundering Proceeds of Crime and Financing of Terrorism (“AML Regulation”), “Those engaged in the purchase and sale of all types of marine, air, and land transportation vehicles, including construction machinery, and those acting as intermediaries in such transactions” and “Medium, large, or very large-scale electronic commerce intermediary service providers, limited to transactions carried out with electronic commerce service providers” are obliged with the AML/KYC obligations stated in the relevant legislation. These obligations include but are not limited with (i) carrying out KYC obligations, (ii) notifying suspicious transactions to the Financial Crimes Investigation Board, (iii) carrying out a compliance program and appointing a compliance officer, and (iv) maintaining adequate record keeping procedures.
In terms of “those engaged in the purchase and sale of all types of marine, air, and land transportation vehicles, including construction machinery, and those acting as intermediaries in such transactions”, it is observed that connected car providers typically collaborate with distributors and/or authorized dealers in Türkiye to sell these vehicles to end customers. In that case, the distributor or authorized dealer engaging in the purchase and sale of these connected cars will be directly obliged under the AML Regulation. Although the obligation rests with distributors and/or authorized dealers, it is advisable for connected car providers to ensure that these parties are complying with their local obligations, in order to avoid complaints and/or official investigations.
In terms of “medium, large, or very large-scale electronic commerce intermediary service providers, limited to transactions carried out with electronic commerce service providers”, where the connected car service provider is classified as a ECISP, its activities, limited to the transactions carried out with electronic commerce service providers, will be directly in the scope of AML Regulation if this electronic commerce intermediary service provider is a medium, large, or very large-scale ECISP.
The scale of an ECISP is determined annually by the Ministry of Trade based on net transaction volume and number of transactions, adjusted each year by the annual re-evaluation rate. For the year 2025, the classification thresholds are as follows:
| Net Transaction Volume (2025)[3] | Number of Transactions (Excluding Cancellations/Returns) | Classification |
| Below TRY 53.475.366.450EUR 1.102.929,03 | Any number | ECISP |
| Above TRY 53.475.366.450EUR 1.102.929,03 | Any number | Medium-Scale ECISP |
| Above TRY 160.426.099.350EUR 3.308.788.299,09 | Less than 100,000 | Medium-Scale ECISP |
| Above TRY 160.426.099.350EUR 3.308.788.299,09 | More than 100,000 | Large-Scale ECISP |
| Above TRY 320.852.198,700EUR 6.617.576,60 | More than 100,000 | Very Large-Scale ECISP |
Therefore, before and during the engagement of connected car services in Türkiye, it is highly advised for the providers to check above thresholds and if the provider is classified as a medium, large or very large ECISP, it should adapt its services so that the obligations arising from AML Regulation are fulfilled.
Cyber Security Law No. 7545
As is known, the Cyber Security Law entered into force upon its publication in the Official Gazette dated Wednesday, March 19, 2025, and numbered 32846. The Cyber Security Law covers public institutions and organizations, professional organizations with public institution status, natural and legal persons, and entities without legal personality that operate, provide services, or maintain a presence in cyberspace.
Within this scope, parties who “provide services, collect or process data, or engage in similar activities through the use of information systems” are subject to the following obligations:
- To submit promptly and as a priority to the Cyber Security Presidency (“Presidency“) any data, information, documents, hardware, software, or other contributions requested by the Presidency in the course of its duties and activities,
- To take the measures stipulated by legislation for the purposes of national security, public order, or the proper conduct of public services, and to report without delay to the Presidency any vulnerabilities or cyber incidents identified in the area of service,
- To procure cybersecurity products, systems, and services to be used in public institutions and critical infrastructure only from cybersecurity experts, manufacturers, or companies certified and authorized by the Presidency,
- To obtain the approval of the Presidency, in accordance with existing regulations, prior to commencing operations if operating as a cybersecurity company subject to certification, authorization, or accreditation,
- To implement the necessary measures and fulfill the obligations set out in policies, strategies, action plans, and other regulatory instruments issued by the Presidency aimed at increasing cyber maturity.
To mitigate potential risks and ensure compliance with the upcoming secondary legislation, we recommend taking the following steps:
- Closely monitor whether “connected cars” are classified as “critical” infrastructure and the development of secondary legislation, which will define the practical scope and enforcement of the Cyber Security Law.
- Adopt a cooperative and solution-oriented approach with officials in the event of an inspection.
- Establish a reliable and well-functioning communication channel with the relevant authorities in order to address requests for information and documents. While it may not always be possible to fulfil certain requests due to technical or legal constraints, maintaining open communication is key to avoiding sanctions.
- Any cyber security incident that could potentially impact Türkiye must be evaluated with regard to reporting in the country.
- If cyber security related products or services are provided, ensure that all the necessary certifications and authorizations have been obtained in accordance with the applicable regulations.
The Concepts of FOTA and OTA
FOTA (Firmware Over-The-Air) and OTA (Over-The-Air) refer to the transmission of software or firmware updates to vehicle systems via wireless communication. Technically, FOTA mainly covers firmware updates at the hardware level, while OTA includes software and application-based updates.
In this regard, the Addendum 155 – UN Regulation No. 156 (“Regulation”) issued by the United Nations Economic Commission for Europe (UNECE), which serves as an international point of reference, defines OTA updates under Article 2.9 as “any method that transfers data wirelessly rather than using a cable or other local connection.”
Although the term FOTA is not explicitly used within the Regulation, Articles 7.1.1.8 and 7.1.1.9 indicate that all types of software updates fall within its scope. In particular, it is stated that modifications which may affect type-approved systems should be specifically assessed, and we are of the opinion that updates at the firmware level would also fall within this scope.
Therefore, it can be concluded that the technical distinction between FOTA and OTA updates does not give rise to a difference in legal obligations. Both types of updates should be evaluated under the same legal principles and security standards.
Under Turkish law, the provision of OTA and FOTA services for the purposes of ensuring the systemic functionality of vehicles, implementing safety and cybersecurity measures, and improving or enhancing the functions of digital services does not present any legal non-compliance. When evaluated within the scope of the DP Law, the delivery of such services entails personal data processing activities. Accordingly, the data subjects whose data will be processed must be duly informed, and their explicit consent must be obtained where necessary. Additionally, if cross-border data transfers are conducted, please note that they must comply with the provisions of Article 9 of the DP Law.
According to Article 7.2.2.2 of the Regulation, drivers must be informed about an update before the update is executed. The information made available shall contain:
- The purpose of the update. This could include the criticality of the update and if the update is for recall, safety and/or security purposes,
- Any changes implemented by the update on vehicle functions,
- The expected time to complete execution of the update,
- Any vehicle functionalities which may not be available during the execution of the update,
- Any instructions that may help the vehicle user safely execute the update.
Additionally, under Article 7.2.2.3, in the situation where the execution of an update whilst driving may not be safe, the vehicle manufacturer should demonstrate how they will:
- Ensure the vehicle cannot be driven during the execution of the update,
- Ensure that the driver is not able to use any functionality of the vehicle that would affect the safety of the vehicle or the successful execution of the update.
Following the update, Article 7.2.2.4 requires:
- The driver is able to be informed of the success (or failure) of the update,
- The driver is able to be informed about the changes implemented and any related updates to the user manual (if applicable).
In light of the above provisions, we believe that a single general notice provided at the time of the initial contract phase may not be sufficient for compliance. Therefore, we recommend that, where operationally feasible, separate and specific notifications be provided prior to each update, addressing the above-listed points. These notifications may be delivered via email or through in-vehicle applications. Moreover, in cases where the update is of high importance or involves safety-critical actions, obtaining active consent from the driver before proceeding with the update may be considered a prudent risk mitigation measure.
Although the secondary legislation specifying the measures required under the Cyber Security Law has not yet been published, we are of the opinion that the document titled “Cybersecurity Best Practices for the Safety of Modern Vehicles“, issued by the U.S. National Highway Traffic Safety Administration (NHTSA), may serve as an important reference point for the sector. With respect to OTA updates, the said document recommends concrete technical measures such as:
- Maintaining the integrity of update servers and the transmission mechanism,
- Taking into account, when designing security measures, the risks associated with compromised servers, against server attacks, insider threats, and men-in-the-middle attacks,
- Ensuring that firmware modifications are carried out only by authorized parties,
- Taking measures to limit firmware rollback attacks.
As stated above, although no binding list of measures has yet been defined under the Cyber Security Law, we believe that the measures outlined above can be taken as a reference point in terms of compliance with international standards and the adoption of the best sectoral practices.
Activities Subject to License/Permit/Authorizations
In addition to the above, certain activities of connected car providers may be subject to licenses/permits/authorizations from the relevant authorities. For charging stations, if the connected car provider will also provide its own charging stations, according to Regulation on Charging Services, this action is subject to a license by the Energy Market Regulations Authority. For vehicles that will be used in transportation of goods or people, an approval must be obtained from the Ministry of Industry and Technology according to Regulation on Type Approval and Market Surveillance and Audit of Motor Vehicles And Their Trailers, And Of Systems, Components And Separate Technical Units Intended For Such Vehicles. It should be noted that this regulation on type approval is highly parallel with its European counterpart – Regulation (EU) 2018/858.
[1] If the contract is based on a subscription model, the distance sales contract can be prepared to include the subscription terms.
[2] a) The essential characteristics of the goods or services covered by the contract,
- b) The name or title of the seller or supplier and the intermediary service provider, their MERSIS number or tax identification number,
- c) The consumer’s ability to quickly contact the seller or provider and the intermediary service provider through clear address, phone number, and similar contact information, as well as the identity and address of the person acting on behalf of or for the account of the seller or provider, if applicable,
ç) If the seller or provider and the intermediary service provider have different contact information for the consumer to submit complaints than those specified in paragraph (c), information regarding such contact information,
- d) The total price of the goods or services, including all taxes, or if the price cannot be calculated in advance due to the nature of the goods or services, the method of calculating the price, and information on any additional costs such as shipping, delivery, or similar expenses, as well as information on the possibility of paying such additional costs if they cannot be calculated in advance,
- e) If the cost of using the remote communication tool during the contract formation stage cannot be calculated based on the standard tariff, the additional cost imposed on consumers,
- f) The delivery or performance period consistent with the period promised in commercial advertisements and promotions, other information regarding delivery and performance, and any commitments related thereto, as well as the complaint resolution methods of the seller or supplier and the intermediary service provider,
- g) In cases where the right of withdrawal applies, the conditions, duration, and procedure for exercising this right, information regarding the carrier designated by the seller for return, and the amount of return costs, which shall not exceed the delivery costs, and which party shall bear such costs, and if the return is made using a carrier other than the one designated, the consumer shall bear the return costs.
ğ) The clear address, fax number, or email address where the withdrawal notice must be sent,
- h) Information on the circumstances under which the right of withdrawal cannot be exercised, or the conditions under which the consumer loses the right of withdrawal,
ı) If applicable, any deposits or other financial guarantees that the consumer must pay or provide at the seller’s or supplier’s request, along with the conditions applicable to such deposits or guarantees,
- i) Technical protection measures that may affect the functionality of digital content,
- j) Information regarding the hardware or software with which the digital content is compatible, as known to the seller or supplier or as reasonably expected to be known,
- k) Information regarding the consumer’s right to submit complaints regarding disputes to the Consumer Court or the Consumer Arbitration Board.
[3] The EUR equivalents indicated above have been calculated based on the indicative EUR/TRY exchange rate as of 21 May 2025. These figures are approximate and provided for reference purposes only; they do not constitute binding thresholds in foreign currency.
Part I – Evaluation of Connected Car Processes Within the Scope of Relevant Areas of Turkish Legislation
Introduction
The rapid evolution of connected car technologies has introduced significant legal challenges and regulatory considerations across jurisdictions, including Türkiye. As vehicles become increasingly embedded with sensors, communication modules, and data-driven functionalities, their classification transcends traditional automotive frameworks, which necessitates a multidisciplinary legal analysis to assess compliance and risk management obligations under Türkiye’s legal landscape.
In the Turkish context, connected cars interact with various legislative regimes. From a telecommunications law perspective, their use of embedded SIMs (eSIMs), from a data protection perspective, the collection, processing, and potential transfer of personal data generated by drivers and passengers. Moreover, the increasing integration of consumer-facing digital services within vehicles brings Turkish consumer protection law, cybersecurity law and product liability regulations into scope.
This article provides a structured legal analysis of connected car technologies in Türkiye, examining their implications across key regulatory domains. By identifying overlapping obligations and enforcement trends, it aims to assist connected car providers, operators and software developers in navigating the legal and operational complexities of these emerging mobility solutions.
Legal Analysis Regarding Telecommunications Law
For connected cars, the first issue regarding telecommunications law would be the usage of eSIM technologies. Although there is no direct legal prohibition against the deployment of in-vehicle connectivity solutions, the telecommunications regulatory authority in Türkiye, Information and Communication Technologies Authority (“ICTA”), has introduced significant compliance obligations.
ICTA has issued two key decisions regarding eSIM, one in January 2018 and another in February 2019. The core requirement established by both decisions is strict data localization: connected car services must use SIM profiles provided by local mobile network operators, and traffic data must remain within Türkiye.
Further clarification came with ICTA’s decision dated April 2022, which set forth detailed requirements concerning the network architecture for connected vehicles. This decision introduced two main obligations: (i) a localization requirement for “connection servers” that support communication systems enabling value-added services beyond eCall; and (ii) a mechanism allowing users to opt in or out of such services via the e-Government (e-Devlet) platform. For the e-Government option, currently there is no definitive implementation available and yet the local authorities have requested the development of an interface that would allow users in Türkiye to terminate their connectivity and disconnect their internet connection at any time. This demand arises from summaries of meetings with sector representatives. Industry representatives note that if such an option is made available, the various internet services associated with the vehicle may become inaccessible. However, without any official regulation or draft on the issue, a clear statement cannot be made yet.
ICTA appears to permit the use of international infrastructure for value-added services, provided that regulatory supervision and user control mechanisms are preserved. This illustrates Türkiye’s cautious regulatory approach to connected vehicle data flows. In line with this, it should be mentioned that, according to Regulation Regarding the Registration of Devices with Electronic Identity Information, permanent roaming is restricted and if a registration is not made within 120 days of entering to Türkiye, that device’s communication is restricted by the ICTA.
Beyond eSIM, the centralized eCall system in Türkiye introduces further compliance dimensions. With the Regulation on Emergency Call Services in Electronic Communications Sector and Regulation on Type Approval Requirements for the Deployment of the eCall In-Vehicle System based on the 112 Service, Türkiye has opted for a centralized eCall model, where all eCall signals are routed through a national platform before being dispatched to emergency services. Consequently, any vehicle manufacturer or connectivity provider operating in Türkiye must ensure compatibility with the centralized eCall architecture.
Lastly, for electronic communications, it should be mentioned that Türkiye enforces strict rules on the localization of metadata and location data. Pursuant to Regulation on Protection of Confidentiality and Processing of Personal Data in Electronic Communications Sector, operators should retain metadata and location data, including data generated by connected vehicles, within Türkiye’s borders. These requirements are justified in national security and public order grounds. Metadata such as IP logs, call/SMS activity, and session identifiers are thus subject to local retention.
Due to the above, any stakeholder offering in-vehicle connectivity in Türkiye, such as connected car providers, operators, or service providers must navigate a highly structured regime that prioritizes data localization and centralized regulatory oversight.
Geographical Data
In Türkiye, processing geographical data is specifically regulated under Geographical Information Systems Law (“GIS Law”) numbered 7221. According to GIS Law and its secondary legislation, geographical data subject to permit is defined as “data containing location information, data that can be linked to a digital map base or address data, data collected online or offline from the field using sensors specified in data definition documents” and both natural and private legal persons require a permit from the Ministry of Environment, Urbanization and Climate Change in order to collect, produce, share or sell geographical data in Türkiye. Activities involving the collection, production, sharing and sale of geographical data are sufficient to be subject to the GIS Law. Therefore, as long as the services include geographical data collected from within Türkiye, these services will most likely be considered subject to the permit obligation.
For the permit fee, the fee is calculated according to the procedure stated in article 1(2) of GIS Law, which takes into account the (i) number of geographical data themes, (ii) area of operation, (iii) permit duration and (iv) net sales amount in the income statement attached to the income or corporate tax return for the most recent accounting period as of the application date or the sales revenue amount in the summary of operating account.
For the duration, a permit will be valid for at least one year and at most five years. In addition to permits, the GIS Law mandates that the geographical data produced must be shared with the Ministry of Environment, Urbanization and Climate Change free of charge before and after disasters and emergencies to be used as part of disaster and emergency management efforts.
As per the GIS Law, if it is determined that the activities are being carried out without obtaining geographical data permit, the authorities will grant the operator engaging in geographical data activities a period for which the operator can apply for a permit. If there is no application during this period, administrative fines shall be imposed on operators who engage in geographical data activities without authorization.
As a last note regarding geographical data, it should be noted that the GIS Law was amended in 2024, but the auxiliary regulations were not updated according to this amendment. Due to this, there are certain ambiguities between GIS Law and its secondary regulations, and it is expected for an amendment in these secondary regulations in order to harmonize the GIS Law and the relevant legislation.
Data Protection
This section will analyze the data protection aspects of connected vehicles. Data protection in Türkiye is mainly regulated by Law on Protection of Personal Data, numbered 6698 (“DP Law“), which was modeled after Directive 95/46/EC and therefore bears similarities with its EU counterpart, mainly GDPR.
Firstly, data subjects must be presented with a privacy notice in accordance with Article 10 of the DP Law. This notice must clearly outline the purposes and legal basis for processing, recipient groups, and the data subject’s rights. Controllers must also ensure that data subjects can exercise their rights under Article 11, which, while similar to GDPR Articles 12–22, differs slightly in scope and form (e.g., absence of the right to data portability). For global connected car providers, the privacy notices prepared in accordance with EU generally can be used in Türkiye with minor localizations.
Secondly, different from EU, Turkish data protection legislation requires all foreign controllers who process the personal data of Turkish data subjects to be registered with the Data Controllers’ Registry (“VERBİS”). Pursuant to Article 16 of the DP Law and the Regulation on Data Controllers Registry, controllers must keep a detailed Personal Data Processing Inventory, which outlines the types of data collected, processing purposes, legal bases, data categories, recipient groups, retention periods, international transfers, and security measures. This inventory is conceptually similar to the GDPR’s Record of Processing Activities (RoPA). However, in Türkiye, based on this inventory, a registration to VERBİS must be made.
Regarding VERBİS, a specific requirement exists for non-resident controllers, such as foreign connected car providers, which is the appointment of a “data controller representative” in Türkiye. This representative acts as the point of contact for the Turkish Data Protection Authority (“DP Authority”) and for any data subject asserting rights under the DP Law. Therefore, for foreign connected car providers, appointment of a representative and registering to VERBİS is highly advised before launching the products/services in Türkiye.
In addition to above, the cross-border data transfer rules should be assessed regarding the usage of connected car services by Turkish data subjects. In the past, unlike EDPB, the DP Authority accepted direct collections from Turkish data subjects by the foreign controllers as a “transfer”. The view of the DP Authority changed recently and currently, direct collections from Turkish data subjects does not constitute a “transfer” but this processing activity is in the scope of DP Law. Therefore, if the connected car provider directly obtains the data from Turkish data subjects and transfers this data to its processors, all of these activities are also in the scope of DP Law and the transfer to the processor would constitute a cross-border data transfer in terms of DP Law. Additionally, if the connected car provider obtains the data from another controller/processor in Türkiye (e.g. local dealers), then the transfer from the local controller/processor to the foreign connected car provider would be in the scope of cross border data transfer regime.
According to article 9 of the DP Law, which is the main article that regulates the cross-border data transfers in Türkiye, similar to GDPR, personal data may only be transferred abroad if:
- the receiving country/sector/international organization provides adequate protection,
- one of the appropriate safeguards are in place
- for incidental transfers, one of the derogations exists for such transfer
To date, the DP Authority has not recognized any country, including EU member states or the U.S., as providing adequate protection so the first option is unusable in Türkiye at this point. The other three safeguards (an agreement between public bodies, binding corporate rules and a written undertaking) require the prior approval of the DP Authority, whereas the standard contractual clauses only require notification of the DP Authority in order to rely on that mechanism. Therefore, in practice, standard contractual clauses are widely used since they only require notification to the DP Authority, rather than approval. For this reason, foreign service providers who obtain personal data from a Turkish controller or processor are advised to use one of the appropriate safeguards for continuous transfers (e.g. standard contractual clauses).
With regard to data security obligations, Article 12 of the DP Law requires data controllers to take “all necessary technical and organizational measures” to prevent unauthorized access to, or processing of, or loss of, personal data. The DP Authority’s Data Security Guide provides further clarification of these obligations and recommends measures aligned with GDPR standards. Therefore, compliance with GDPR security protocols (e.g. encryption, pseudonymization, access control and logging) is generally considered sufficient for Turkish standards, although documentation and localized governance (via the local representative) remain essential.
Managing Associate Melis Mert ‘s Latest Article at OneTrust DataGuidance
Summary
Turkey’s Personal Data Protection Law No. 6698 was amended in March 2024, with changes effective from June 2024, aligning Turkish cross-border data transfer rules with the EU’s GDPR. The By-Law on the Transfer of Personal Data Abroad and Turkish standard contracts and binding corporate rules were published in July 2024. Turkish Standard Contractual Clauses (SCCs) require KVKK notification and approval, and cannot be used for multiple recipients, necessitating a clear understanding of data flow. Intra-group data transfers also require KVKK approval, and any changes to Turkish SCCs must be notified within five business days. A guideline from the KVKK is expected to provide further insights on the procedural steps and transfers.
You can view the full article here: https://lnkd.in/dp-suKz7
What’s New on Türkiye’s Artificial Intelligence Agenda?
What happened
Although Türkiye does not have a specific law regulating artificial intelligence (AI), there are certain sector-specific rules and mainly governmental strategies. The latest one is National AI Strategy Action Plan 2024-25 (“Action Plan”), published on the website of Digital Transformation Office of the Presidency of the Republic of Türkiye (“DTO”) on July 24, 2024. The aim of the Action Plan, which is introduced based on “National Artificial Intelligence Strategy 2021-2025”, is to address the new needs arising from the current developments in the generative AI technologies.
Action Plan includes 71 actions, with the following highlights.
- Legislation: National legislation will be introduced in compliance with international norms regulating the development and use of AI systemhttps://cbddo.gov.tr/uyzss and the placing of AI systems on the market. While there is no adoption yet, the EU Artificial Intelligence Act comes to mind. In addition to the DTO, Ministry of Industry and Technology & Ministry of Trade will be taking role here.
- New Committees: An expert committee will be established to set technical and ethical standards for generative AI models (LLM, LAM, etc.) to be developed domestically and to manage such process. Ministry of Industry and Technology will be supported by the Scientific and Technological Research Council of Türkiye (TÜBITAK). On the other hand, Ministry of Foreign Affairs & Ministry of Foreign Affairs Directorate for EU Affairs shall be responsible for “International AI Studies Monitoring and Coordination Committee” to track international studies in the field of AI and to ensure effective participation and contribution of Türkiye to these studies.
- Intellectual Property: Guidelines will be prepared to clarify the intellectual property rights regarding the content generated by AI and standardization efforts will be made regarding the patentability of AI products. Turkish Patent and Trademark Office will be the responsible institution.
- Cybersecurity: Efforts to develop the related policies and legislation will be undertaken to centralize the detection, prevention and mitigation of new generation cyber threats, especially those powered by AI, directed against Türkiye’s presence in cyberspace.
- Trust & Certification: Turkish Standards Institution’s “AI Risk Management System Certification Program” will be introduced to enable risk-based assessment of AI products. Also, a “Trusted AI Stamp” will be created in accordance with the certification mechanism for encouraging the audit and legal compliance of AI applications.
- AI Institute: The institutional capacity of TÜBITAK’s AI Institute will be improved to support the entire ecosystem and a Core AI Research Group will be established within the Institute.
- R&D Support: A “Central Public Data Space” will be established by preparing an inventory of the data owned by public institutions and organizations, and mechanisms will be developed to make these data available to researchers and technology developers. A special mechanism will be also designed for global technology companies to carry out their R&D activities in the field of AI in Türkiye. Last but not least, under the responsibility of the Small and Medium Enterprises Development Organization of Türkiye, a support program will be implemented to encourage the use of AI products and solutions, which are developed through R&D activities carried out in Türkiye, by SMEs.
Background
Presidential Circular No. 2021/18 on the “National Artificial Intelligence Strategy 2021-2025” was prepared in cooperation with the DTO and the Ministry of Industry and Technology. Right after that, “National Artificial Intelligence Strategy 2021-2025” was published on the website of DTO on August 24, 2021. The Strategy determines the measures that will put Türkiye’s efforts in the field of AI between the years 2021-2025 on a common ground and the governance mechanism that will be established to implement these measures. In the Strategy, “AI” is defined generally as the ability of a computer or computer-controlled robot to perform various activities in a similar way to intelligent creatures. The term AI is used for systems equipped with human cognitive abilities such as reasoning, discovery of meaning, generalization or learning from past experiences in dynamic and uncertain environments.
General Overview of Türkiye’s Legislative Atmosphere
As mentioned, Türkiye does not have a comprehensive legislative tool directly regulating AI. Similar to many jurisdictions, personal data protection and cybersecurity laws are the most commonly applied. There are also specific rules for certain AI-related activities.
- Recommendations on the Protection of Personal Data within the Field of Artificial has been published on the official website of the Personal Data Protection Authority on September 15, 2021. This Guide provides recommendations on the protection of personal data in AI applications in a way including developers, manufacturers, service providers and decision makers in the field of AI. The structure and recommendations are mostly adapted from the Council of Europe’s Guidelines on Artificial Intelligence and Data Protection.
- The use of AI has also affected advertising rules. Advertising Board, established under the Ministry of Trade, has included advertisements created using AI on its agenda for the first time in September 2023. Accordingly, regardless of the way they are created or the medium in which they are published, these contents created by AI, which directly or indirectly affect the purchasing decisions of consumers, have been examined by the Advertising Board. In this context, administrative sanctions were imposed on 3 files related to advertisements created by “ChatGPT”, as these advertisements included statements creating the perception of superiority over competing products or companies and which were not based on objective research results.
- Under the electronic communication legislation, certain criteria are determined for AI to be used in identity authentication processors in order to verify the identities of applicants who wish to receive certain electronic communication services.
- In the finance sector, pursuant to the Regulation on Remote Identification Methods to be Used by Financial Leasing, Factoring, Financing and Savings Finance Companies and Establishment of Contractual Relationship in Electronic Environment, for transactions not exceeding a certain amount, the Banking Regulation and Supervision Agency is authorized to determine the principles regarding the transactions to be performed by the customer representative as referred to in this regulation with AI-based methods. Similarly, pursuant to the Regulation on Remote Identification Methods to be Used by Banks and Establishment of Contractual Relationship in Electronic Environment, they are authorized to determine the procedures and principles regarding the transactions to be performed by AI-based methods, which are stated to be performed by the customer representative in this regulation.
- In addition, there are soft laws and various guidelines that establish principles. For example, Council of Higher Education developed “Ethical Guidelines on the Use of Generative Artificial Intelligence in Scientific Research and Publication Activities of Higher Education Institutions” to address the ethical considerations arising from the integration of AI into higher education processes.
What are the updates on the Turkish cross-border data transfer rules and how do they affect you?
The Turkish Personal Data Protection Law was amended in March 2024, with the new regime taking effect in June 2024. This amendment, long anticipated in line with Türkiye’s goals to harmonize with EU standards and enhance effective protection, addresses issues with cross-border personal data transfers, clarifies legal conditions for processing special personal data categories, and designates administrative courts as the appeal authority for Personal Data Protection Board decisions. We will focus on the first item.
Q1: What happened? What are the highlights?
The Turkish Personal Data Protection Law (Law) was amended in March 2024. With the new regime,
- Türkiye still has the adequacy decision option, but now such decisions can be granted for international organizations and sectors as well.
- Personal Data Protection Authority (DPA) approval will no longer be required for the standard contracts, leading to the introduction of “Turkish Standard Contractual Clauses (SCCs)” with some Türkiye-specific features.
- Contracts other than those published by the DPA can still be used but require DPA approval.
- Binding corporate rules (BCRs) are specifically regulated.
- Data processors are now within the scope of the Turkish cross-border data transfer rules.
- Onward transfers are also subject to these rules.
- Derogations for one-off transfers have been introduced for cases where there is no adequacy decision or appropriate safeguard.
Details are provided under the Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad (Regulation) & Public Announcement on Documents Regarding Standard Contracts and Binding Corporate Rules.
Q2: Why the change?
The previous mechanism was inefficient for several reasons:
- International agreements and other laws didn’t cover enough cases.
- Türkiye hadn’t designated any safe countries for free data transfer, making all countries inadequate.
- Ad hoc approval from the DPA was mandatory for all contract-based cases, even if the contract used was the standard one published by the DPA.
- Explicit consent from data subjects wasn’t a reliable basis.
Q3: What is the new framework for international data transfers under Turkish law?
The new framework includes the following, but only for continuous transfers. Please see Q7 to find out more about incidental transfers:
- Adequacy Decision: Adequacy decisions will be rendered by the DPA and can apply to a country, international organization, or sectors within a country. Due to Türkiye’s reciprocity principle among other criteria, such decisions are not expected to be made swiftly.
- Safeguards: A transfer under safeguards is possible if (i) there is a legal basis for the transfer under the Law, and (ii) data subjects have the possibility to exercise their rights and have recourse to effective remedies in the country of transfer. Although Türkiye does not have a transfer impact assessment concept yet, this second element may require one in the future.
- Instruments: These include agreements for public institutions with DPA permission, Turkish BCRs for group companies with DPA permission, Turkish SCCs for bilateral transfers with DPA notification, and specific agreements with DPA permission.
Q4: What are the peculiarities of the Turkish SCC regime?
To ensure lawful transfer via Turkish SCCs:
- The executed documents must be submitted to the DPA within 5 business days.
- Turkish SCCs lack a docking clause and cannot be incorporated into other contracts by the parties.
- They must be used and signed verbatim.
- They can be bilingual, but the Turkish text will prevail.
- There should be an initial notification once the Turkish SCC is executed, notifications for any changes in the annexes (data type, purpose, onward transfer, etc.), and notification upon termination.
After the submission of a duly prepared Turkish SCC, the transfer directly becomes legalized (i.e. no waiting period).
Q5: What is required for agreements other than Turkish SCCs?
Specific agreements, such as intra-group data transfer agreements or Turkish BCRs, require DPA approval. BCRs have their own mandatory content, forms, guidelines, and secondary legislation. Specific agreements offer a relatively more relaxed structure but still need to ensure appropriate security. If the SCC text is not used as-is, the DPA will initiate an investigation. Therefore, any changes to the Turkish SCCs should be submitted for approval and not as SCCs. The downside is the waiting period for the DPA’s decision and the inability to transfer data until approval is granted.
Q6: What are the requirements for onward transfers under the new regime?
For onward transfers, recipients must ensure one of the safeguards too (i.e., another SCC execution and notification) or the following conditions apply:
- Establishment, exercise, or defense of legal claims in the context of specific administrative or judicial proceedings.
- Explicit consent.
- Vital interests or physical integrity of the data subject or another person if the data subject is unable to express consent due to a physical impossibility or if the data subject’s consent is not deemed legally valid.
For sub-processors, Turkish SCCs has separate regime – mostly in line with the EU’s SCCs.
Q7: What are the available derogations for incidental data transfers?
The available derogations for incidental (“not regular, occurs only once or a few times, is not continuous and is not in the ordinary course of business”) transfers are as follows:
- Explicit consent where data subjects are informed of the possible risks (as for continuous transfers, valid until September 2024).
- Necessity for the performance of the contract between the data controller and the data subject or for the implementation of pre-contractual measures taken at the data subject’s request.
- Necessity for the establishment or performance of a contract between the data controller and another person for the benefit of the data subject.
- Necessity for an outstanding public interest.
- Necessity for the for the establishment, exercise, or defense of legal claims.
- Necessity for the protection of the vital interests of the data subject or of other persons where the data subject is physically or legally incapable of giving consent.
- Where the transfer is made from a register, which is open to the public or persons with legitimate interests, provided that the conditions required to access the registry in the relevant legislation are met and the person with a legitimate interest request it.
Q8: What are the responsibilities of data processors when transferring personal data abroad?
Previously, data processor transfers were not regulated, and the old cross-border data transfer article only mentioned Turkish data controllers transferring data outside of Türkiye. Now, data processors are explicitly within the scope:
- There are “processor to processor” and “processor to controller” Turkish SCCs.
- There is “binding corporate rules for data processors”.
- There is a new administrative fine for processors (also for controllers, where applicable) for not making the Turkish SCC notification to the DPA.
On the other hand, generally speaking; data processors must act on behalf of the data controller and in accordance with their instructions. They must take all necessary technical and administrative measures to ensure appropriate security levels to prevent unlawful processing and access, and to ensure the protection of personal data. Importantly, the data controller retains responsibility to ensure compliance with the Law and Regulation and that adequate safeguards are provided.
Q9: How does the new regime treat direct collection cases?
The new international data transfer rules do not specifically mention direct collection cases. However, the wording of the new article and secondary legislation suggests that direct collection is not considered a data transfer, aligning with the European Data Protection Board’s Guidelines 05/2021. The DPA’s interpretation should be monitored.
Q10: What are the penalties for non-compliance with the new data transfer rules?
In cases of non-compliance, the DPA may give instruction decision, render administrative fine up to TRY 9,463,213, fine the controller or processor up to TRY 1,000,000 for failing to notify the DPA about Turkish SCCs. The DPA may also publish penalty decisions on its official website, potentially resulting in reputational risks; and/or to decide to cease transfer abroad if it could lead to irreparable harm or are clearly unlawful, though this is a rare penalty. (The monetary fines are for year 2024.)
Q11: What proactive steps should companies take to ensure compliance with the new regime?
Companies that transfer personal data of those residing in Türkiye to entities located abroad (and to the extent this regard the lawfulness of the data collected by the foreign recipient, the recipient) should:
- Define the specifics of the data being transferred from Türkiye.
- Select the appropriate data transfer instrument based on the relationship between the Turkish entity and the recipient entity (e.g., Turkish SCCs, BCRs, or specific agreements such as intra-group data transfer agreements).
- Carefully evaluate the pros and cons of these mechanisms, especially for continuous transfers between group companies, JV structures, licensor-licensee relationships, etc.
- Obtain DPA permission for transfers involving BCRs and specific agreements.
- Manage timeframes effectively for DPA notifications when using Turkish SCCs & re-notify the DPA of any updates or terminations when using Turkish SCCs.
- For those having Data Controllers’ Registry (VERBIS) account, ensure that the declarations there are aligned with the those submitted to the DPA.
- Inform and train employees on the new requirements, update privacy-related documents and monitor ongoing data transfers for compliance.