The wish to be visible on digital platforms results in people voluntarily carrying their own information onto the network. The transfer of personal data to social media accounts and similar digital environments in turn opens the way to that information being reached by unlawful means. Files in which information and material obtained by entering an account without permission is turned, in the hands of ill-intentioned persons, into a tool of blackmail or fraud are frequently encountered in practice.
Acts of this nature are defined as an offence in Article 243 of the Turkish Penal Code under the heading “entering an information system” and are attached to various criminal sanctions. The purpose behind the provision is to protect both confidence in information systems and the privacy of private life. A report or complaint may be made to the Chief Public Prosecutor’s Office or to the law enforcement units against a person who obtains unauthorised access to another’s social media account.
The spread of social media use has not merely given rise to a debate about addiction; it has also made ordinary a risky form of conduct, namely the opening of personal data to third-party access by the data subject in person.
Personality Rights and Personal Data
The Personal Data Protection Act No. 6698 (KVKK) defines personal data as “any information relating to an identified or identifiable natural person”. Within the framework of that definition, name and surname, date and place of birth, telephone number, motor vehicle registration plate, social security number and passport number may be given as examples of personal data. Curriculum vitae information, images, video and voice recordings, fingerprints and genetic information, IP address and e-mail address, device identifiers, a person’s preferences and the persons with whom they interact are assessed within the same scope.
The protection of personal data must be approached within the framework of the personality right. The protection afforded by the personality right forms a functional line of defence against unjust attacks directed at such data. Technological development and digitalisation have required the existing general legal norms to be read afresh from the perspective of the protection of personal data; the concept of personality, personality values, the personality right and the means of protecting that right have in this process returned to the agenda.
Our legislation also treats the unauthorised recording and dissemination of another person’s personal data as an offence and attaches a criminal sanction to it. For the detail of this subject, the note entitled “The Offence of Recording and Disseminating Personal Data Through the Internet” may be consulted.
Non-Material Personal Assets
This group consists of a person’s rights over their non-material assets. Honour, dignity and reputation; the sphere of private life; name, image and voice; and a person’s freedoms may be given as examples of non-material personal assets. Other interests and values of the person falling outside these may also, depending on the circumstances, fall within the scope of the personality right.
Material Personal Assets
A person’s rights over their body and bodily integrity are gathered under the heading of material personal assets. The rights in this group essentially constitute the person’s special personality rights over their material assets.
A person’s rights over their body and organs, their life and their physical and mental health are counted among the rights over material personal assets.
Our law protects a person’s material and non-material rights together. Within this framework, the tendency to characterise personal data too as a personality right and to subject it to the protective regime applicable to personality rights is growing stronger.
Unauthorised Entry into Information Systems Under the Turkish Penal Code
The Turkish Penal Code No. 5237 regulates offences committed in the field of information technology in Articles 243 to 246. That section covers the headings of the application of security measures to legal persons, prohibited devices or programs, misuse of bank or credit cards, obstructing or impairing a system and destroying or altering data, and entering an information system.
Unauthorised access to social media accounts is assessed under the heading of “entering an information system”.
Turkish Penal Code Art. 243 – Entering an information system
“(1) A person who unlawfully enters the whole or part of an information system, or continues to remain there, shall be sentenced to imprisonment for up to one year or to a judicial fine.
(2) Where the acts defined in the paragraph above are committed in respect of systems that may be used for a fee, the penalty to be imposed shall be reduced by up to one half.
(3) Where, as a result of this act, the data contained in the system is destroyed or altered, a sentence of imprisonment from six months to two years shall be imposed.
(4) (Added: 24/3/2016-6698/Art. 30) A person who, without entering the system, unlawfully monitors by technical means the transfers of data taking place within an information system or between information systems shall be sentenced to imprisonment from one year to three years.”
In the reasoning of the article, an information system is defined as magnetic systems that make it possible, after data has been collected and stored, to subject that data to automatic processing. Entering an information system may be expressed as unlawfully entering the whole or a part of a system, or continuing to remain there.
For the offence to arise it is sufficient that a person’s digital platform has been entered without their consent. Beyond that, no further fact is required to occur; access to the system contrary to the will of its holder constitutes the offence on its own. Under the provision in force, it is of no significance whether the person continued to remain in the system or whether the data was used.
In the period before the Personal Data Protection Act No. 6698 (KVKK) came into force in 2016, by contrast, in order to speak of the offence of “entering an information system” the system had both to have been entered and to have been remained in. With the amendment made to the Code, “unlawfully entering the system” and “continuing to remain in the system” were framed as two separate types of offence. Indeed, logging into a person’s e-mail account without the permission of its holder is regarded as sufficient for the application of Art. 243 of the Turkish Penal Code, and the perpetrator may be punished on account of that act alone.
The first paragraph of the article covers the basic form of the offence. Under that provision, a perpetrator who enters an information system without permission may be sentenced to imprisonment for up to one year and a judicial fine.
The second and third paragraphs set out the aggravated forms. As regards the second paragraph, where the act is committed in respect of systems that may be used for a fee, the penalty to be imposed is reduced by one half. Websites used on payment of a fee, electronic newspapers opened to access in return for a subscription, and electronic libraries may be given as examples of such systems. It is provided that where those systems are entered without permission, the penalty is to be reduced.
The third paragraph, for its part, sets out the form of the offence aggravated by its result. Where, following unauthorised entry, the data in the system is destroyed or altered, the perpetrator is sentenced to imprisonment from six months to two years.
The act of entering an information system or remaining there may also serve as an instrumental offence in the commission of the target offences set out in the Code. For instance, on the path to the offence of “obstructing or impairing a system, destroying or altering data”, entering an information system is in most cases instrumental in nature. Likewise, the offences of “violation of the privacy of private life” and “unlawful acquisition of personal data” are also seen to be committed alongside this offence. Where a person’s Facebook account is entered without permission and their data taken, both the offence of entering an information system and the offence of unlawful acquisition of personal data will arise.
Infringements That May Occur Through Service Providers
Unlawfully recording, acquiring, disseminating or transferring personal data to another constitutes an offence. As regards social media accounts, it must be addressed separately that these infringements may be carried out not only by third parties but also by service providers.
Violation of the Confidentiality of Personal Data
Under Article 135 of the Turkish Penal Code, a person who unlawfully records personal data is sentenced to imprisonment from six months to three years. The same penalty applies to a person who records as personal data information relating to individuals’ racial origin, political, philosophical or religious opinions, or unlawfully to their moral inclinations, sexual life, state of health or trade union connections.
Although it is unavoidable that the processing of personal data be permitted under certain conditions, our Code prohibits the recording of such data by unlawful means and punishes that act.
Use of Personal Data for Advertising and Commercial Purposes
Under Article 136 of the Turkish Penal Code, a person who unlawfully gives personal data to another, disseminates it or acquires it is sentenced to imprisonment from one year to four years. By that provision, the transfer of data to third parties and its conversion into a commercial instrument is defined as an independent offence, irrespective of whether the data was lawfully recorded. Accordingly, a service provider’s sharing of visitor information with advertising companies or with intelligence units will constitute a separate offence even if the data was lawfully recorded at the outset.
Infringements Directed at Social Media Accounts by Third Parties
Another picture frequently encountered today is that of cyber attacks directed at social media accounts by third parties. Entering an account without permission, the hacking or theft of the account, and the sharing of the data held in the account are the most common forms of these infringements.
Unauthorised Entry into an Account
Unauthorised access to an account is punished within the scope of the offence of entering an information system. Entering an information system means reaching all or part of the data held in a system, either physically or remotely by means of another device. That access may be obtained by taking advantage of lax security measures in the system, or it may equally occur through the exploitation of gaps in the security measures in place. Entering a person’s social media account without permission likewise satisfies the conduct element of the offence within this framework.
Recording and Sharing of the Information in the Account
The recording and sharing of the information in the account following unauthorised entry brings other offences into play alongside the offence of entering an information system. The recording of the data constitutes the offence of unlawfully recording personal data set out in Article 135 of the Turkish Penal Code; the sharing of that data constitutes the offence of unlawfully disseminating personal data set out in Article 136. The perpetrator is punished separately for each of those offences. The sharing of data held in social media accounts is also framed as an offence under Article 244 of the Turkish Penal Code.
Rendering the Account Unusable
Turkish Penal Code Art. 244
“(1) A person who obstructs or impairs the operation of an information system shall be sentenced to imprisonment from one year to five years.
(2) A person who impairs, destroys, alters or renders inaccessible the data in an information system, who places data in the system or who sends existing data elsewhere shall be sentenced to imprisonment from six months to three years.
(3) Where these acts are committed in respect of an information system belonging to a bank or credit institution or to a public institution or organisation, the penalty to be imposed shall be increased by one half.
(4) Where, by the commission of the acts defined in the paragraphs above, the person secures an unjust benefit for themselves or for another and this does not constitute another offence, a sentence of imprisonment from two years to six years and a judicial fine of up to five thousand days shall be imposed.”
Where accounts on platforms such as Facebook, Instagram or Twitter, or persons’ e-mail addresses, are entered and the passwords changed, the offence of obstructing a system or rendering it inaccessible arises. Altering the data appearing on the profile, for its part, constitutes the offence of destroying or altering data. Sending the information, documents and photographs held in the account to another address is also assessed within the scope of the same provision.
Theft of the Account
The situation expressed in everyday language as the “theft of the account” is that in which the perpetrator enters the information system without permission, changes the password, and the rightful holder is left unable to reach their own social media account. That act too constitutes the offence of obstructing a system or rendering it inaccessible, defined in Article 244 of the Turkish Penal Code.
Entering a Spouse’s Social Media Account Without Permission
Access by Means of Recording and a Router
Access to an information system may be obtained by reaching data from a computer that is switched on, and it may equally take place over networks and the internet. As regards the arising of the offence, whether the connection is wired or wireless, and whether the distance is short or long, has no effect on the outcome. Even if the perpetrator enters the system and leaves without carrying out any operation, the offence is treated as complete; in that respect this offence is characterised as an offence of endangerment. Since the Code provides no separate exception for spouses, where the conduct element occurs the offence arises between spouses as well. By means of recording and the use of a router, this offence may be committed between spouses too.
Depending on the features of the concrete case, the act may also constitute the offence of violating the confidentiality of communications between persons, set out in Art. 132 of the Turkish Penal Code. That offence is committed by learning the content of communications between particular persons; the means by which the communication took place is of no importance as regards the arising of the offence. Spouses entering each other’s social media accounts for the purpose of obtaining evidence does not constitute an exception to this offence. Spouses learning the content of communications in this way will satisfy the conduct element of the offence.
Use of Information So Obtained as Evidence
In the decisions of the Court of Cassation, where spouses enter each other’s social media accounts to obtain evidence, it is debated whether consent is present. That spouses know each other’s account passwords may in some decisions be interpreted as “implied consent”. By contrast, the Court of Cassation has also given decisions treating the evidence submitted as unlawful, on the ground that accepting the existence of such implied consent between spouses in the course of divorce proceedings is incompatible with the ordinary course of life.
A further matter concerns the conditions under which a recording may be used as evidence. The decisions of the Court of Cassation state that such a recording may be made in suddenly developing situations where it is not possible to obtain the proof by any other means and where there is no possibility of applying to the competent authorities.
Complaint and Trial Process
Investigation Stage
This offence, set out in Art. 243 of the Turkish Penal Code, is not among the offences whose prosecution depends on a complaint. Investigation and prosecution steps may therefore be carried out even where there is no complaint.
A person who learns that their account has been entered without permission may report the matter to the Chief Public Prosecutor’s Office or to the law enforcement authorities, or may lodge a complaint. The victim’s statement may be submitted in writing or made orally to be entered in a record. For the detail of the legal routes open to the victim of this offence, the note entitled “How Is a Complaint Made in Information Technology Offences?” may be consulted.
The Public Prosecutor who learns, through a report or otherwise, that the offence has been committed carries out the necessary enquiries and decides whether there are grounds for opening a public prosecution.
In parallel with the spread of social media use, further provisions and measures on the subject are being introduced into the legislation. For assessments of the relevant amendments, the note entitled “The Innovations Introduced by the New Social Media Act” may be examined.
Prosecution Stage
Court with subject-matter jurisdiction:
The trial of the basic form of the offence of entering an information system, and of its aggravated forms and forms aggravated by their result, is conducted in the Criminal Courts of First Instance.
Court with territorial jurisdiction:
Territorial jurisdiction lies with the court of the place where the offence was committed. The moving and continuing nature of the offence requires that the court of the place where that continuity was broken be treated as having jurisdiction. Where the offence remained at the stage of attempt, the place where the last act of execution occurred determines jurisdiction. In the case of a successive offence, the court of the place where the last act was committed has jurisdiction.
In offences in which information systems are used as an instrument, the court of the victim’s place of residence is also accepted as having jurisdiction alongside the court with primary jurisdiction.
Limitation
Under Article 66 of the Turkish Penal Code, the limitation period for prosecution is set at 8 years “in offences requiring imprisonment of not more than five years or a judicial fine”. Accordingly, in the offence of entering an information system the limitation period for prosecution is eight years from the date on which the act was committed.
Sanctions Under Each Paragraph of the Offence
A perpetrator who commits the offence set out in paragraph 1 of Article 243 of the Turkish Penal Code is subject to imprisonment for up to one year or a judicial fine. Since the conjunction “or” is used in the text of the provision, the judge imposes only one of the alternative penalties.
- paragraph provides that, where the act is committed in respect of systems that may be used for a fee, the penalty to be imposed is to be reduced by up to one half. The judge has no discretion as regards the application of that reduction.
- paragraph, the sanction prescribed for the form aggravated by its result is imprisonment from six months to two years. The application of that paragraph is conditional on the data in the system being destroyed or altered after the system has been entered. Moreover, unlike in the basic form of the offence, no judicial fine is provided in that paragraph as an alternative penalty.
- paragraph, the sanction for the offence of unlawfully monitoring by technical means, without entering the system, the transfers of data taking place within an information system or between information systems is imprisonment from one year to three years. Where the first three paragraphs are infringed, the perpetrator is punished under paragraph 3.
Frequently Asked Questions
How does the destruction or alteration of data affect the penalty?
The third paragraph of Article 243 of the Turkish Penal Code sets out the aggravated form requiring a heavier penalty. It provides that where, as a result of the commission of the offence, the data in the system is destroyed or altered, a sentence of imprisonment from six months to two years is to be imposed.
In which cases is the penalty reduced?
The second paragraph of the article concerns the qualified form requiring a lesser penalty. Where the acts of unlawfully entering an information system or remaining there are committed in respect of systems that may be used for a fee, the penalty to be imposed on the perpetrator is reduced by up to one half.
Does the offence depend on a complaint?
The offence of entering an information system is not listed in the Code among the offences subject to complaint. Investigation and prosecution are therefore carried out of the authorities’ own motion. Withdrawal of a complaint likewise produces no consequence as regards the continuation of the process.
Do the conciliation provisions apply?
Conciliation means that the person under criminal accusation and the victim reach agreement by communicating through a conciliator. Since the offence of entering an information system is not among the offences within the scope of conciliation, the prosecution continues without the conciliation procedure being operated.
What technical examinations are carried out at trial?
According to the case law, the computers of the complainant and of the accused are seized and their hard disks examined; it is determined whether there is any connection and data flow between the devices. If any text or image has been sent from the address that was compromised to another address, the persons having knowledge of the incident and the holders of the addresses reached using that address should, if any, be heard as witnesses.
Independent Legal Assessment
Files concerning unauthorised access to a social media account, although apparently resting on a single act, most often bring several types of offence into play at once. Entering the account may constitute the offence of entering an information system, while the recording and dissemination of the data held there may constitute separate offences relating to personal data. Making the correct legal characterisation of the incident at the outset of the investigation therefore determines both the scope of the victim’s claims and the severity of the sanction the perpetrator will face.
In disputes between spouses the matter takes on a further dimension. Access carried out for the purpose of submitting evidence in a divorce file may give rise to separate liability in criminal law and also carries the risk that the material obtained will be treated as unlawfully obtained evidence. The headings to be assessed in a concrete case are as follows:
- Establishing the date and the method of the access, for the purposes of the limitation and jurisdiction rules
- Securing technical evidence such as screenshots, log records and device examination without delay
- Determining whether the act falls solely within the scope of Art. 243 of the Turkish Penal Code, or whether it also produces consequences under Art. 132, Art. 135, Art. 136 or Art. 244
- Having regard to the fact that the use of the material obtained as evidence in other proceedings will be subject to review for lawfulness
- Planning compensation and content-removal routes based on personality rights together with the criminal investigation
Independent Legal provides advisory and litigation services throughout the entire process in disputes arising from information technology law, from the complaint and investigation stage to the conclusion of the prosecution.

