Law / Turkey

Cybersecurity Law, Reporting and Cooperation Duties

Law No. 7545 (12 March 2025), Art. 7

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 19 March 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds any entity that uses information systems to provide services, collect data, or process data within the Cybersecurity Law's own broad scope, with no revenue or user threshold gating this particular duty; a separate, narrower certification and export-approval duty binds only cybersecurity product and service vendors and is not raised here.
  • Report a detected vulnerability or cyber incident in the area of service provided to the Cybersecurity Directorate without delay; the Law's own text sets no numeric reporting clock.
  • Provide the Cybersecurity Directorate promptly with any data, information, document, hardware, software, or other contribution it requests in connection with its duties.
  • Where cybersecurity products, systems, or services are procured for use in a public institution or in critical infrastructure, source them only from a provider the Directorate has certified or authorized.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 16(10) enforces the Article 7(1)(a)-(c) duties raised here only by administrative fine. Elsewhere in the same Law, obstructing an authorized inspector's information request is punished by one to three years' imprisonment plus a judicial fine (Art. 16(1)), and a public official or a person who abuses a position of trust in connection with certain other offenses in the Law faces increased penalties; those provisions bind different conduct than the reporting, cooperation, and procurement duties described in this row.

Penalty structure

Art. 16(10) sets an administrative fine of 1,000,000 to 10,000,000 Turkish lira for failing the Art. 7(1)(a), (b), or (c) duties described in this row (cooperation, incident/vulnerability reporting, and certified-vendor procurement). The same subsection sets a separate, higher tier of 10,000,000 to 100,000,000 Turkish lira for failing the Art. 18 cybersecurity-product export and company-certification duties, which are not this row's duty and are not flagged on any declared activity.

Rule
Fixed only
As of
14 September 2026
Currency
TRY
Fixed cap
10,000,000

Who enforces it

Enforcement body

Siber Güvenlik Başkanlığı (Cybersecurity Directorate), established under the Presidency by this Law

Settledness

As of
14 September 2026
Open questions
  • Have the implementing regulations this Law directs the Presidency to issue within one year of publication (due by 19 March 2026) been issued, and do they set a numeric clock for the Art. 7(1)(b) vulnerability/incident reporting duty?
  • Law No. 7590 (24 July 2026) added a new transitional article continuing the transfer of national cybersecurity functions and assets from the Information and Communications Technologies Authority (BTK) and the Telecommunications Communication Presidency to the Cybersecurity Directorate: has any amendment of this kind also changed Article 7's substantive duties?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 7(1) of Turkey's Cybersecurity Law binds any entity that uses information systems to provide services or to collect and process data within the Law's scope. It must report a detected vulnerability or cyber incident to the Cybersecurity Directorate without delay. It must also supply the Directorate with any data or documentation the Directorate requests.

Where it serves public institutions or critical infrastructure, it must source cybersecurity products only from Directorate-certified providers. Failing the reporting, cooperation, or procurement duties in items (a) through (c) carries an administrative fine of 1,000,000 to 10,000,000 Turkish lira under Article 16(10); the Law's own text sets no numeric clock for the reporting duty itself.

A related item (ç) requires a certified cybersecurity company to obtain the Directorate's approval before beginning operations, a licensing duty that binds the narrower class of cybersecurity-product and service vendors rather than a general software or app developer, and is not itself covered by the Article 16(10) fine named above.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

official statute text, mevzuat.gov.tr consolidated legislation portal
Turkish only, no official English translation was located

Back to the example  ·  Lint your app