With the spread of computer systems and internet access into every area of daily life, information technology offences have become a heading that occupies an ever greater place in legal practice. A great many offences of differing character may be committed through information systems; infringements directed at personal data, attacks on computer systems and fraudulent activity are the most visible examples of this broad spectrum. The environments in which such offences are committed include internet applications and web services, computers, mobile telephones, tablets and even electronic systems such as POS devices.
These acts, also known as cybercrime, are regulated in two separate places in the Turkish Penal Code No. 5237: under the heading "Offences in the Field of Information Technology" in Articles 243 to 246, and under the heading "Offences Against Private Life and the Secret Sphere of Life" in Articles 135, 136 and 138. In this study we examine the types of information technology offence, the sanctions laid down in the statute and the fundamental concepts of the field; we also offer a framework for understanding the present-day importance of these offences.
One of the adverse consequences of the steady expansion of the information technology sector is the phenomenon of cybercrime, which causes a great many people to suffer harm. Children, who encounter the internet, mobile telephones and computers at a very early age, may at times find themselves the victims of these offences and at other times the perpetrators, owing to untrained and unaware use. Capable of being committed on a global scale without regard to borders, these acts may present themselves in an extremely wide variety of forms.
The Concept of Information Technology Offences (Cybercrime)
An information technology offence denotes an offence committed by using computers or the tools of digital technology. Obtaining unauthorised access to information, using personal data without consent and misusing software are the principal forms these offences take. The breadth and complexity of the digital environment allow these offences to arise in very different fields; and with the rapid transformation of technology, new types are constantly emerging.
In Turkish criminal law, information technology offences are regulated under two separate categories, namely "Offences in the Field of Information Technology" and "Offences Against Private Life and the Secret Sphere of Life". In addition, the commission of certain types of offence through information systems is laid down in our statute as the aggravated form of that offence. Both these categories and the provisions regulated as aggravated forms are examined in detail below.
Offences in the Field of Information Technology
The situations regulated as distinct types of offence in the section of the Turkish Penal Code No. 5237 headed Offences in the Field of Information Technology are examined below.
Accessing or Remaining in an Information System
The offence of accessing an information system, set out in paragraphs 1 to 3 of Article 243 of the Turkish Penal Code No. 5237, may be regarded as the most widespread of the cyber offences and may be committed in a great many different ways. Contrary to common belief, the offence does not require that the victim’s computer be physically seized. The offence arises where accounts accessible over the internet, such as a social media account or an e-mail address, are entered by circumventing security measures, or where the offender remains in those accounts, without the victim’s consent. The only ground of justification capable of preventing this conduct — which results in a third party gaining access to personal accounts — from constituting an offence is the victim’s consent.
A person who carries out this conduct is sentenced to imprisonment of up to 1 year or to a judicial fine. Where the act is committed in respect of systems that may be used against payment, the sentence to be imposed is reduced by one half. Where the conduct results in the destruction or alteration of data within the system, the sanction to be applied is imprisonment of between six months and two years.
No special condition is required by the statute as to the character of the offender; accordingly, anyone may commit this offence. The offender’s level of digital knowledge and expertise is likewise immaterial, so the offender may be an advanced hacker or equally a person with the most basic knowledge of the internet.
The Offence of Interception
Although the offence of interception also appears in Article 243 of the Turkish Penal Code No. 5237, it constitutes a type of offence separate and independent from the offence of accessing or remaining in an information system set out in the first paragraph of that Article. The conduct element of this offence, regulated in the fourth paragraph, is the unlawful monitoring, by technical means and without accessing the system, of data transmissions taking place within an information system or between information systems. This form of conduct is termed "interception" in legal scholarship and in the European Convention on Cybercrime, to which our country is also a party. An example of data transfers within a system is the interception and monitoring of data as they are transmitted from a computer to a printer or from a computer to a storage device.
The subject matter of the offence is transmissible data; whether or not those data are of a personal character does not alter the outcome. For the offence to arise it is sufficient that the data are merely monitored, without any access being made to the information system. Since this offence, which may only be committed intentionally, presents no distinguishing feature as regards the offender or the victim, anyone may be in the position of offender or victim.
Hindering or Disrupting a System and Destroying or Altering Data
This offence, regulated in paragraphs 1 and 2 of Article 244 of the Turkish Penal Code No. 5237, is among the offences with alternative conduct elements. The alternative forms of conduct laid down by the statute are as follows:
- Corrupting, destroying, altering or rendering inaccessible the data held in the system,
- Introducing data into the system or sending existing data elsewhere,
- Hindering or disrupting the functioning of the information system.
A person who hinders or disrupts an information system is sentenced to imprisonment of between one and five years. The corresponding sentence for the conduct of corrupting, destroying, altering or rendering inaccessible the data in the system is imprisonment of between six months and three years. Our legislation lays down the same sentencing range for the conduct of introducing data into the system or sending existing data elsewhere. In this type of offence, too, no special quality is required as regards the offender or the victim.
Where the conduct in question is committed in respect of an information system belonging to a bank or credit institution, or to a public authority or body, this constitutes the aggravated form of the offence; in that event the sentence to be imposed is increased by one half.
Obtaining an Unjust Benefit Through an Information System
The obtaining of an unjust benefit by means of an information system is regulated as an independent type of offence in paragraph 4 of Article 244 of the Turkish Penal Code No. 5237.
The conduct element of this offence is the offender securing an unjust benefit for himself or for another by committing one of the following acts: hindering or disrupting the functioning of the system; corrupting, destroying, altering or rendering inaccessible the data in the system; introducing data into the system or sending existing data elsewhere. It is necessary, however, that this conduct should not constitute another offence. Where the conditions are met, the offender is sentenced to imprisonment of between two and six years and to a judicial fine of up to five thousand days.
Misuse of Bank and Credit Cards
Obtaining and Using a Card Belonging to Another Without Consent
A person who by any means obtains or holds a bank or credit card belonging to another is punished where, by using that card or allowing it to be used without consent, he secures a benefit for himself or for another. For the offence to arise, it is required that a benefit has been obtained by using the card, or allowing it to be used, without the permission of the cardholder or of the person to whom the card was to be delivered. The sanction laid down for this conduct in Art. 245(1) of the Turkish Penal Code No. 5237 is imprisonment of between three and six years and a judicial fine of up to five thousand days.
Producing, Selling, Transferring, Buying or Accepting Counterfeit Cards
The sanction to be applied to a person who produces, sells, transfers, buys or accepts a counterfeit bank or credit card by linking it to bank accounts belonging to others is regulated in Art. 245(2) of the Turkish Penal Code No. 5237. The sentence our legislation lays down for this offence is imprisonment of between three and seven years and a judicial fine of up to ten thousand days.
Using a Counterfeit or Forged Card
A person who, by using a bank or credit card that has been counterfeited or forged, secures a benefit for himself or for another is likewise regarded as having committed an offence. Unless it constitutes another offence requiring a heavier sentence, this conduct is met with imprisonment of between four and eight years and a judicial fine of up to five thousand days.
Use of Prohibited Devices or Programs – Turkish Penal Code Art. 245/A
Various devices and programs make it easier to commit offences in the field of information technology. The creation of such tools for the purpose of committing information technology offences is regulated as an offence under Art. 245/A of the Turkish Penal Code No. 5237. The conduct constituting the offence here is the making or creation of a device, a computer program, a password or any other security code for the purpose of committing information technology offences or other offences capable of being committed by using information systems as a means. By contrast, devices and programs that do not carry the purpose of committing an information technology offence — for example, those developed in order to test the security of a system — fall outside the scope of this offence. Where a program capable of copying bank card details and of being fitted to an ATM device is developed, however, the purpose of committing an information technology offence is present and the offence under Art. 245/A of the Turkish Penal Code No. 5237 may be said to arise. The offender of this offence, which may only be committed intentionally, may be any person. The sanction laid down is imprisonment of between one and three years and a judicial fine of up to five thousand days.
Other Offences That May Be Committed Using Information Systems
The following types of offence are among the acts that may also be committed by using information systems:
| Offence | Statutory provision (Turkish Penal Code No. 5237) |
|---|---|
| Insult | Art. 125 |
| Insulting the President | Art. 299 |
| Threat | Art. 106 |
| Blackmail | Art. 107 |
| Sexual harassment | Art. 105 |
| Violation of the confidentiality of communications | Art. 132 |
| Listening to and recording private conversations | Art. 133 |
| Violation of the privacy of private life | Art. 134 |
| Aggravated theft committed through the use of information systems | Art. 142(2)(e) |
| Fraud | Arts. 157 and 158 |
| Obscenity | Art. 226 |
| Providing a place and facilities for gambling | Art. 228 |
| Praising an offence and an offender | Art. 215 |
| Inciting the public to hatred and hostility or denigrating them | Art. 216 |
| Disclosing information required to remain secret | Art. 330 |
| Disclosing prohibited information for the purpose of political or military espionage | Art. 337 |
Information Technology Offences Against Private Life
Recording Personal Data – Turkish Penal Code Art. 135
The unlawful recording of personal data is regulated as an offence under Art. 135 of the Turkish Penal Code No. 5237. This type of offence also falls among the information technology offences and is addressed in legal scholarship under the heading of "general information technology offences". What is punished here is the act of recording in itself, irrespective of whether the personal data recorded without the consent of the data subject are subsequently used.
Unlawfully Disclosing or Obtaining Personal Data – Turkish Penal Code Arts. 136-137
Where personal data are unlawfully given to another, disseminated or obtained, the offence regulated in Art. 136 of the Turkish Penal Code No. 5237 arises. The conduct element of the offence consists of these alternative forms of conduct enumerated in the provision. This type of offence is likewise assessed within the scope of "general information technology offences".
Offences in Which Information Systems Are Used as a Means
Alongside the acts explained above, which are defined directly as offences in the field of information technology, our legislation also lays down a great many different types of offence in which information systems serve as a means. The offences of insult, threat, sexual harassment, blackmail, theft, fraud, obscenity and violation of the privacy of private life may be given as examples of this group. Cyber offences do not constitute the basic form of these offences; but where they are committed using information systems, the system is regarded as a means of committing the offence. As regards theft and fraud, the use of information systems constitutes the aggravated form of the offence.
- Theft committed using an information system: Under Art. 142(2)(e) of the Turkish Penal Code No. 5237, where the offence of theft is committed through the use of information systems, imprisonment of between five and ten years is imposed. The statute lays this down as an aggravated form requiring an increase in the sentence for theft. The subject matter of the offence is data. Since the legal interest protected by the offence of theft is property, the data must represent a value forming part of a person’s assets; otherwise, the offence of sending data from one place to another under Art. 244(2) of the Turkish Penal Code No. 5237 comes into play. There is no distinguishing feature as regards the offender or the victim.
- Fraud committed using an information system: Art. 158(1)(f) of the Turkish Penal Code No. 5237 provides that where the offence of fraud is committed by using information systems, or banks or credit institutions, as a means, imprisonment of between three and ten years and a judicial fine of up to five thousand days are to be imposed. The statute likewise treats this as an aggravated form requiring an increase in the sentence for the basic offence of fraud. The Court of Cassation requires the offender to have obtained an unjust benefit through deceitful conduct directed at a real person. The form most frequently encountered in practice is the taking over of a person’s social media account and the requesting of money from those on the friends list while pretending to be the account holder.
- Sexual harassment committed using an information system: The commission of the offence of sexual harassment in the digital environment is regulated as an aggravated form under Art. 105(2) of the Turkish Penal Code No. 5237. In providing, in sub-paragraph (d) of that Article, that "(d) where it is committed by taking advantage of the facility afforded by postal or electronic communication tools, … the sentence to be imposed under the preceding paragraph shall be increased by one half.", the statute has attached a heavier sanction to sexual harassment committed by taking advantage of the facility afforded by digital systems. Since physical contact is not required for the offence to arise, writing messages of a sexual nature to people on social media platforms, or making proposals of that content, is sufficient for the offence to be made out.
- Insult committed using an information system: The offence of insult may be committed through information systems; this is not, however, regulated as an aggravated form increasing the sentence. In the offence of insult, which has two distinct forms — in the presence of and in the absence of the victim — insulting a person by sending messages through social media accounts is assessed as an insult committed in that person’s presence. For further detail, the study entitled "The Offence of Insult Committed over the Internet and Social Media and Its Sentence" may be consulted.
Detecting Information Technology Offences
The methods of obtaining evidence and of detection in information technology offences differ from those in customary criminal investigations. In the first place, there are software organisations whose assistance is sought in detecting offences committed over the internet; Microsoft Corporation is one of them. Depending on the nature of the offence to be detected, the IP address is first identified; the computer of the suspect to whom that address is found to belong is then seized and an examination is begun. The uncovering of the offence is not confined to technological examination alone; the hearing of witnesses and other types of evidence may also be used for this purpose.
Preventive Measures That May Be Applied
With a view to preventing the commission of information technology offences, it is possible to resort to preventive measures in the form of the blocking of access and the removal of content. For more detailed information on these two institutions, the study entitled "Removal of Internet and Social Media Content" may be consulted.
Removal of Content
In cases where delay would be prejudicial, a person harmed by content is afforded the opportunity to request its removal in order to prevent the commission of an offence.
Blocking of Access
The blocking of access, like the removal of content, arises upon request. Where such a decision is given, the blocking is applied not to the website as a whole but only to the part in which the infringement occurred.
Limitation in Information Technology Offences
Under the Turkish Penal Code No. 5237, the general limitation period for prosecution is 8 years. Once that period has expired, no investigation or prosecution may be conducted on the basis of a report made thereafter.
Investigation and Prosecution
Complaint
Information technology offences are among the areas in which the prosecution service is under a duty to investigate of its own motion. Even if the victim lodges no complaint, the prosecution service is obliged to conduct an investigation; nor does the withdrawal of a complaint result in the discontinuance of the case.
The Investigation Stage
The investigation, the first phase of criminal proceedings, is conducted by the public prosecutor’s office. In information technology offences, the prosecutor who receives a report that an offence has been committed acts immediately and carries out the inquiries directed at establishing the material truth. The first matter to be clarified in these offences is whether access to the information system in question was obtained remotely or physically.
The Prosecution Stage
Court with subject-matter jurisdiction:
The court with subject-matter jurisdiction to try the basic form of the offence of accessing an information system, as well as its aggravated forms and those aggravated by their result, is the Criminal Court of First Instance.
Court with territorial jurisdiction:
Territorial jurisdiction lies with the court of the place where the offence was committed. The conduct-based and continuing nature of the offence requires that the court of the place where that continuity was interrupted be regarded as having jurisdiction. If the offence remained at the stage of attempt, the place where the last act of execution occurred determines jurisdiction. In the case of successive offences, the court of the place where the last act was committed has jurisdiction.
In offences in which information systems are used as a means, the court of the victim’s place of residence may also be accepted as having jurisdiction, alongside the court with primary jurisdiction.
The Limitation Period for Prosecution
Under Article 66 of the Turkish Penal Code No. 5237, the limitation period for prosecution is set at 8 years "for offences requiring imprisonment of not more than five years or a judicial fine". Accordingly, in the offence of accessing an information system the limitation period for prosecution is eight years from the date on which the act was committed.
Independent Legal Assessment
The first element that determines the outcome in files concerning information technology offences is the correct identification of the provision under which the conduct falls. Within the same course of events, accessing an information system, obtaining data and securing an unjust benefit may all occur together; in that event, which offences arise separately and which are to be assessed as aggravated forms must be worked out with care. An error in the characterisation directly affects the sentencing range laid down and the legal protection the victim may claim.
The second decisive element is the security of the evidence. Because records in the digital environment can change rapidly, the proper securing of evidence at the reporting and complaint stage often determines the fate of the file. The points to be given priority in disputes in this field are as follows:
- Establishing clearly the date on which the conduct took place, for the purposes of the limitation period for prosecution
- Placing technical evidence such as log records, IP data and device examinations under protection without delay
- Distinguishing whether the act is an offence in the field of information technology or an offence in which an information system is used as a means
- Having regard to the effect of the possibilities of successive offences and of attempt on the determination of the court with jurisdiction
- Assessing the avenues of removal of content and blocking of access in parallel with the criminal investigation
- Planning claims for damages separately where there is an infringement of personality rights
Independent Legal provides advisory and litigation services throughout the whole of the process, from the investigation stage to the appellate remedies, in disputes arising from information technology law.

