Law / Turkey

Turkish Penal Code, Information System Crimes

Law No. 5237 (Turkish Penal Code), Arts. 243-244 (Bilişim Alanında Suçlar)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 June 2005.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not enter, or continue to unlawfully remain within, the whole or part of a computer system located in Turkey without authorisation.
  • Do not obstruct or disrupt a computer system's operation, or corrupt, destroy, alter, or render inaccessible the data it holds, or insert or transmit its data without authorisation, regardless of whether the data taken is personal.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Art. 244(1): obstructing or disrupting a computer system's operation carries imprisonment of one to five years. Art. 244(2): corrupting, destroying, altering, or rendering inaccessible data within a system, inserting data into it, or transmitting its data elsewhere carries imprisonment of six months to three years. Art. 244(3): the penalty for either offence is increased by half where committed against a bank, credit institution, or public institution's system. Art. 244(4): where the offender derives an unlawful benefit for self or another through these acts and no more serious offence is constituted, imprisonment of two to six years plus a judicial fine of up to 5,000 days applies. Art. 243(3): unauthorised entry that causes the system's data to be destroyed or altered carries imprisonment of six months to two years. Art. 243(4): unlawfully intercepting data transfers within or between systems by technical means without entering the system carries imprisonment of one to three years.

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 243(1) criminalises unlawfully entering the whole or part of a computer system, or unlawfully continuing to remain there, an offence punishable by imprisonment or a judicial fine and last revised by Law No. 7413 (23 June 2022).

Where such entry causes the system's data to be destroyed or altered, Art. 243(3) sets imprisonment of six months to two years, and Art. 243(4), added in 2016, separately punishes unlawfully intercepting data transfers within or between computer systems by technical means without entering the system, at one to three years.

Article 244 punishes obstructing or disrupting a computer system's operation with imprisonment of one to five years (para. 1), and corrupting, destroying, altering, or rendering inaccessible the data within a system, inserting data into it, or transmitting its data elsewhere, with imprisonment of six months to three years (para. 2); the penalty is increased by half where a bank, credit institution, or public institution's system is affected (para. 3), and where the offender derives an unlawful benefit for self or another through these acts and no more serious offence is constituted, imprisonment rises to two to six years plus a judicial fine of up to 5,000 days (para. 4).

The offence is triggered by unauthorised access to, or interference with, a system rather than by the act of copying its content, so reading a public, unauthenticated page without defeating an access control falls outside a plain reading of these provisions.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

official statute text, Turkish Presidency Legislation Information System (Mevzuat Bilgi Sistemi) consolidated text of Law No. 5237

Back to the example  ·  Lint your app