Independent LegalIndependent Legal

Information Technology Law

Information Technology Law

Reporting and Complaint in Information Technology Offences: Application Routes, Securing Evidence and Limitation

Offences committed through information systems are as a rule investigated of the prosecutor’s own motion; yet the prosecution service most often learns of the incident only through the victim’s report. We address how and where the application is to be made, the methods of identifying the offender and the limitation periods.

Published 11 August 2026Practice Area Information Technology LawReading time 10 min

The dizzying pace of technological advance has moved information systems to the very centre of criminal activity, and a distinct category known as the information technology offence has emerged. The Turkish Penal Code No. 5237 has not remained indifferent to that development and has provided for a new section under the heading "Offences in the Field of Information Technology". In scholarship and in practice, various designations such as "cyber offence", "computer offence", "virtual offence", "internet offence" or "high-technology offence" are used for these acts; in the Turkish criminal law literature, however, the designation information technology offence predominates.

These types of offence, as regulated in the statute, are not subject to complaint for the purposes of investigation and prosecution. The public prosecutor who learns of the act must act of his own motion, gather the evidence and, if the findings obtained are sufficient, draw up an indictment.

Yet it is not possible in practice for the prosecution service to learn of its own accord of the countless acts that take place daily in the digital environment, the greater part of which are committed through personal accounts. An investigation can be opened of the prosecutor’s own motion only in respect of striking incidents that attract wide public attention. For that reason, the prosecution service most often learns of an incident through a report made by the victim or by third parties who witnessed it.

As the uses of the internet have diversified and spread, the number of acts committed through information systems has also increased steadily. Given that anyone may at any moment become the victim of one of these offences, it is of great importance to know which forms of conduct fall within this scope and what steps must be taken for them to be punished.

The Concept of an Information Technology Offence

The concept of the information technology offence, which entered the legal literature in parallel with the rapid development of information technologies, is generally accepted to have first emerged in the United States of America. There is today no terminology agreed upon at international level. Under designations that vary from country to country, these acts are rendered by expressions such as "computer offence", "internet offence", "virtual offence", "high-technology offence" or "cyber offence". As regards Turkish criminal law, it may be said that the term "information technology offence" has largely become established.

No more than unity of terminology has unity of definition been achieved; neither in international law nor in Turkish law is there a single agreed definition. Information technologies are transformed from one second to the next, new forms of conduct amenable to criminal use continually multiply, and new types of offence may appear at any moment. In the face of that variability, setting out a clear definition does not appear realistic at present. Indeed, both in international instruments and in national legislation, the method adopted has been to draw the boundaries by identifying the acts falling within the scope one by one, rather than by giving a general definition. The Turkish Penal Code No. 5237 has followed the same scheme and, without giving a general definition, has regulated specific acts as offences under the heading "Offences in the Field of Information Technology".

If a framework definition is nevertheless required, information technology offences may be expressed as "offences in which information systems and/or data are used, or which are committed against information systems or their data".

Information Technology Offences Listed in the Turkish Penal Code

The legislature has regulated acts in the field of information technology specifically and has provided for the following conduct as offences:

  • Unlawfully accessing an information system, or continuing to remain there after having entered
  • Unlawfully monitoring, by technical means and without accessing the system, data transfers within an information system or between systems
  • Impairing or disrupting the operation of a system; destroying, deleting, altering or rendering inaccessible the data in the system; adding data to the system or redirecting existing data elsewhere
  • Obtaining an unjust benefit for oneself or for another by using an information system as a means
  • Obtaining a bank or credit card belonging to another by whatever means and using it without the cardholder’s consent
  • Manufacturing counterfeit bank or credit cards, or selling, transferring, buying or accepting them
  • Securing a benefit for oneself or for another by using a card that has been counterfeited or forged
  • Manufacturing, importing, dispatching, transporting, storing, accepting, selling, offering for sale, buying, giving to others or possessing a device, a computer program, a password or any other security code prepared for the purpose of committing information technology offences or other offences capable of being committed by using information systems as a means

Alongside these acts, which are separately regulated in the statute, the commission through information systems of offences such as theft, fraud, insult, threat and sexual harassment constitutes the aggravated form of the offence concerned. Insulting, threatening or sexually harassing a person, or inciting the public to hatred and hostility, through social media accounts or websites are among the acts made subject to sanctions of imprisonment and a judicial fine. Some users turn to conduct of this kind by creating fake accounts, believing that they cannot be traced; our legislation, however, also provides for criminal liability in respect of offences committed through fake accounts.

How Is a Complaint Lodged?

Offences may be divided into those whose prosecution is subject to a complaint and those that are not.

In other words, in some acts the ability to investigate and prosecute depends on the complaint of the victim, whereas in others no such condition is required; the prosecution service begins the investigation of its own motion the moment it obtains information about the offence.

It is not, however, in the ordinary course of events for the prosecution service to learn of every act committed. For an investigation to begin, a report must therefore be made to the prosecution service or to law enforcement. Depending on the particular circumstances, the report takes the form either of a complaint or of a report of an offence. The application may be submitted by a written petition, or it may equally be made orally by having the statement entered in a record. Preparing a written text is accordingly not mandatory; having an oral account taken down in a record is also a valid method of application.

Where a petition is preferred, care should be taken to ensure that the elements it must contain are set out in full. In that framework, the petition must state the office of the chief public prosecutor to which the application is made, the identity and contact details of the applicant, the name and surname of the offender if known, the date on which the act took place, an account of the incident, the information, documents and evidence relating to the incident, and a section setting out the conclusion and the request. Where the identity of the offender is not known, it is appropriate to request in the conclusion and request section that the suspect be identified.

We have noted that the information, documents and evidence relating to the incident must be annexed to the application. WhatsApp correspondence, used intensively in daily life for rapid communication, socialising and business relations, sometimes also contains material capable of contributing to the clarification of an offence. Whether such correspondence carries evidential value is, however, one of the most debated headings in practice and one on which differing views are advanced; the conditions under which WhatsApp correspondence may be used as evidence is a matter that requires separate assessment.

Upon a complaint or report, the prosecution service will open an investigation and will seek to establish the act and the offender. One of the most critical items of evidence resorted to at this stage is the identification of the IP address from which the post constituting the offence was made. Whether the IP address is on its own sufficient to reveal the offender is, however, a separate matter for examination.

To Which Authorities May an Application Be Made?

Under the Turkish Penal Code No. 5237, reports or complaints concerning an offence may be addressed to

  • offices of the chief public prosecutor
  • law enforcement units (police headquarters, gendarmerie)

Making the application to these authorities is the principal method laid down in the statute; the requirements of the particular situation may, however, make it possible to use a different route. In that context, an application may also be made to

  • governorships
  • district governorships
  • courts
  • the overseas missions of Türkiye, that is to say embassies and consulates, in respect of acts that occur abroad but must be pursued within the country

as well.

In short, as with other offences, even though it is possible in information technology offences to apply to various authorities, the ultimate addressee is the prosecution service, since under our law the power to conduct an investigation is conferred on the public prosecutor’s office.

Methods Used to Identify the Offender

Acts Committed by E-mail and Message

Clarifying offences in this field requires technical knowledge and expertise; many different methods come into play in the course of detection. In acts committed by message or e-mail, the first step is to obtain the e-mail address or the mobile telephone number from which the transmission was made. If the act took place through a social media account, a website, a platform or an application, the identity details relating to the space in which the post was made, the user name, the date of the post and the content itself are the matters sought to be established.

Acts Committed by Telephone

In information technology offences carried out by telephone, the communication traffic records (HTS) obtained from the Information and Communication Technologies Authority play a decisive role. Establishing the number of the mobile line from which the transmission was made, the date and time of the transmission and the content transmitted is of great importance for the course of the investigation.

Identification Through the IP Address

Identifying the IP address and the person using that address is a critical source of evidence in information technology offences. The IP address, port details and time particulars are requested from the hosting provider; information is then requested as to whom that address was allocated and as to that person’s identity, address and communication data. The person concerned is asked to give a statement; where a defence is advanced that the modem was used without a password, the modem’s usage history and password status are examined. The offence is not, however, detected on the basis of IP data alone. In some incidents the IP information cannot be obtained at all, the modem may be in shared use by more than one person, or the fact that the hosting provider is located abroad may make access to personal data difficult. For that reason, the presence of supporting evidence to complete the picture takes on importance.

The Profile Analysis Method

In profile analysis, the users the account follows and the content it posts are analysed in an attempt to arrive at the person’s identity. Once the suspect has been identified, a search and seizure decision is obtained; devices such as computers or mobile telephones are examined. At the end of these steps, an attempt is made to establish both the act and the offender.

Where, as a result of the investigation and the technical examination, the offender has been identified and the elements of the offence are made out, the prosecution service draws up an indictment and sends the file to the court with subject-matter and territorial jurisdiction. In some files the suspect cannot be traced and a standing search decision is issued. Since websites and social media platforms based abroad do not retain IP address information, the retention period, set at 90 days, may be extended when an official request reaches them; on the expiry of 180 days, by contrast, the data are deleted and obtaining fresh evidence becomes difficult. For access providers in Türkiye, the retention period for internet traffic information is 1 year; since these records are deleted once 1 year has passed from the date on which the act was committed, the possibility of requesting the information also disappears. In files of this kind, a decision of "no grounds for prosecution" is most often given.

Evidence and Proof in Information Technology Offences

In these offences, evidence may be obtained by both conventional and technical methods. During the investigation stage, conducted of the prosecutor’s own motion or upon a complaint, evidence may be reached through the following examinations:

  • Identification of the IP address: The Internet Protocol is a distinct item of identity data that makes digital devices visible on an internet connection or on a local network. These addresses carry information about the location of the device and make it possible to reach it.
  • Examination of HTS records: Through HTS (Historical Traffic Search) records, meaning a search of past traffic, operators retain the calling and called numbers, the time and duration of the call, the place where it was made, the location and the base station from which the signal was received.
  • Examination of system records: The analysis of records documenting the activity taking place on a computer or over a network.
  • Examination of server files: The scanning and analysis of files hosted on servers.
  • Recovery of deleted files: The restoration of deleted data and their submission to examination.
  • Examination of temporary files: The analysis of files created and stored temporarily.
  • Examination of identity data in digital images: Research into digital information of the metadata type contained within photographs and videos.
  • Examination of internet history: Review of the pages visited by the device or the user through the browser and of the search records.
  • Examination of e-mail files: Research into the messages and attachments in electronic mail accounts.
  • Examination of conversation records: The analysis of voice or written communication records.
  • Examination of wireless network connections: Examination of the connections made to wireless networks and of the activity during those connections.

Alongside these, proof may be secured by many methods, such as the seizure and examination of computers and mobile telephones during the investigation, or the establishment of identity by reference to the other posts made from the account through which the post constituting the offence was published.

Although the fact that the greater part of social media platforms, websites and widely used applications (twitter, whatsapp, facebook, instagram) are based abroad makes it difficult to obtain the suspect’s identity details, the law enforcement units specialising in information technology assigned during the investigation stage are able to contribute to proving the offence by gathering evidence with their technical competence.

Time Limit for Complaint and Limitation for Prosecution

The information technology offences set out in the Turkish Penal Code No. 5237 are not among the offences whose investigation and prosecution depend on a complaint. When the public prosecutor learns that the act has been committed, he must open an investigation of his own motion. There is accordingly no binding time limit for complaint in respect of these types of offence. As with every type of offence, however, the limitation period for prosecution runs here too. Accordingly:

  • In offences requiring less than 5 years of imprisonment or a judicial fine, the period is 8 years,
  • In offences for which imprisonment of more than 5 years but less than 20 years is laid down, the period is 15 years.

In criminal proceedings brought after the expiry of these periods, a decision to discontinue the case is given.

In information technology offences, the element that determines the outcome is more often the securing of the evidence in time than the legal characterisation. Because the retention periods for traffic records and IP data are limited, reports made late are in practice left without result. For that reason, even where the offence is one not subject to complaint, it is decisive in practice that the victim should apply at an early stage rather than wait.

In conducting the process, it is also important to plan together, alongside the criminal investigation, parallel legal avenues such as the removal of content, the blocking of access and damages. Otherwise the harmful content may remain online while the criminal file proceeds.

In a particular case we recommend that the following points be addressed as a matter of priority:

  • Recording screenshots, the link address and the date details without delay and in a verifiable manner
  • Determining whether the act is an independent information technology offence or the aggravated form of another offence
  • Ensuring that traffic and IP records are requested from the relevant institutions before their retention periods expire
  • Expressly requesting the identification of the suspect in the complaint petition where the offender is unknown
  • Verifying whether the digital data were obtained by lawful methods
  • Assessing the options of content removal and damages simultaneously with the criminal process

Independent Legal provides advisory and litigation services throughout the whole of the process in disputes in the field of information technology law, from the preparation of the complaint to the follow-up of the investigation and the trial stage.

Disclaimer — This document has been prepared for general information purposes only and does not constitute legal advice or the provision of legal services. Its content reflects the legislation and settled practice in force at the date of preparation and may cease to be current as a result of legislative amendments or judicial decisions. Professional legal advice should always be obtained before acting on any specific matter.

Call Now