Strategic Legal Solutions For A Global Business World
Strategic Legal Services Tailored for Modern Business — advisory and dispute resolution across intellectual property, media, technology, corporate and regulatory law, delivered by dedicated practice groups from Istanbul for clients around the world.
A Proven Legal Blueprint to Secure What You've Built.
Devin Law & IP is a boutique law firm with over 15 years of combined experience from its founders and partners. The firm operates on principles of transparency, integrity, and shared values, and delivers sustainable legal solutions through dedicated practice groups.
We serve diverse international clients by forming specialized teams with sector expertise. Long-term client relationships, diversity, continuous education and professional development are our core institutional values.
Founded on professionalism, transparency and long-term value creation, the firm combines sector expertise with strategic legal insight — providing clear, practical and result-oriented solutions for businesses and individuals.
Alongside its Istanbul headquarters, the firm manages trademark and patent portfolios across multiple jurisdictions through its attorneyship practice — handling filings, oppositions, renewals and enforcement before TÜRKPATENT, EUIPO and WIPO on behalf of local and international rights holders.
This dual structure — Legal Services on one side and Trademark / Patent Attorneyship Services on the other — allows the firm to combine contentious litigation strength with disciplined portfolio administration, so that every matter is handled by a team specialised in its own field.
02
Why Choose Us
Legal Expertise
Professionals with extensive knowledge across industries provide strategic advice and actionable insights. Every matter is staffed by a team with genuine sector experience, so our advice reflects commercial reality rather than abstract theory.
Client-Focused Approach
Personalized solutions tailored to specific client goals through collaborative engagement. We invest time in understanding each client's business model, risk appetite and priorities before shaping the legal strategy around them.
Innovative Legal Solutions
Leveraging modern legal technologies to develop creative, sustainable approaches. From portfolio automation to structured watch services, we use technology to deliver faster and more consistent outcomes.
Commitment to Sustainability
Supporting clients in adopting ethical practices that benefit both business and society. We help build compliance cultures that are durable, defensible and aligned with evolving international standards.
Strategic Perspective
Aligning legal solutions with business objectives for sustainable growth. Advice is always framed as a business decision — with clear options, realistic costs and measurable consequences.
03
Legal Services Tailored to Your Business
01
Industrial Property Law
Trademarks, patents & utility models and industrial designs — consultancy, prosecution and litigation before TÜRKPATENT, EUIPO and WIPO.
Explore →
02
Intellectual Property & Copyright Law
Copyright, software and related rights under FSEK No. 5846 — from ownership architecture and registration through to piracy enforcement.
Explore →
03
Media, Entertainment & Advertisement
Where creative expression meets complex regulation — advertising review, broadcasting compliance, production and talent agreements.
Explore →
04
Data Protection, Privacy & Cybersecurity
Defensible governance under KVKK and the GDPR — data mapping, cross-border transfers, breach response and defence before the Authority.
Explore →
05
IT & Technology Law
Software, SaaS and cloud contracts, gaming and e-sports, startup financing rounds, e-commerce and fintech regulation, and the legal architecture around artificial intelligence.
Explore →
06
Corporate Law & Commercial Advisory
Retainer counsel across every department, commercial contracts, general assemblies, board resolutions, capital structures and shareholder disputes.
Explore →
07
Dispute Resolution & Litigation
Commercial and contractual litigation, debt recovery and enforcement, labour defence, white-collar crime, shareholder disputes, lease actions, mediation and arbitration.
Explore →
08
Maritime, Yachting & Shipyard Law
Superyacht newbuilds and refits, shipyard operations, yacht design and IP, sale and purchase, flagging, chartering and crew, vessel arrests and marine casualties.
Explore →
"From the first spark of creativity to the global protection of your brand."
Advertising Board Decisions — Meeting No. 370: Transitional Period in Health Promotion Legislation, Use of Trademarks and Logos, Denigrating Advertising
5 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 371: Disparaging Advertising, Consistency Between the Principal Claim and Its Exceptions, and the Boundary Between News and Advertising
5 September 2026 — Read →
Data Protection
Turkish Data Protection Board Decisions — August 2026: Principle Decisions, Data Processing for Marketing Purposes and Workplace Surveillance
5 September 2026 — Read →
Competition
Turkish Competition Board Decisions — June–August 2026: Conditional Clearances, the Commitment Procedure and New Investigations
5 September 2026 — Read →
IP Litigation
Trademark Invalidity Actions in Türkiye: Grounds, Acquiescence and the Difference from Administrative Revocation
28 August 2026 — Read →
Maritime & IP
Collision in the Sea of Marmara: Civil and Criminal Liability in Maritime Casualties
15 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 366: Platform Liability, Trademark Use and Price Transparency
5 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 367: Right of Withdrawal, Comparative Claims and Health Connotations in Product Names
5 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 368: Sanctions for Repeated Infringements, Interface Design and Superiority Claims
Advertising Board Decisions — Meeting No. 370: Transitional Period in Health Promotion Legislation, Use of Trademarks and Logos, Denigrating Advertising
5 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 371: Disparaging Advertising, Consistency Between the Principal Claim and Its Exceptions, and the Boundary Between News and Advertising
5 September 2026 — Read →
Data Protection
Turkish Data Protection Board Decisions — August 2026: Principle Decisions, Data Processing for Marketing Purposes and Workplace Surveillance
5 September 2026 — Read →
Competition
Turkish Competition Board Decisions — June–August 2026: Conditional Clearances, the Commitment Procedure and New Investigations
5 September 2026 — Read →
IP Litigation
Trademark Invalidity Actions in Türkiye: Grounds, Acquiescence and the Difference from Administrative Revocation
28 August 2026 — Read →
Devin Law & IP · Practice Areas
Our Services
Comprehensive legal services combining sector expertise with strategic legal insight: clear, practical and result-oriented solutions for businesses and individuals. Eight dedicated practice groups cover intellectual property, media and advertising, data protection, technology, corporate matters, dispute resolution and maritime law, for multinational groups and early-stage ventures alike.
Comprehensive legal services combining sector expertise with strategic legal insight: clear, practical and result-oriented solutions for businesses and individuals. Eight dedicated practice groups cover intellectual property, media and advertising, data protection, technology, corporate matters, dispute resolution and maritime law, for multinational groups and early-stage ventures alike.
8 practice groups — move across the panels below to preview, click to open.
01Industrial Property Law
01
Industrial Property Law
Trademarks, patents & utility models and industrial designs, consultancy, prosecution and litigation before TÜRKPATENT, EUIPO and WIPO.
Explore →
02Intellectual Property & Copyright Law
02
Intellectual Property & Copyright Law
Copyright, software and related rights under FSEK No. 5846, from ownership architecture and registration through to piracy enforcement.
Explore →
03Media, Entertainment & Advertisement Law
03
Media, Entertainment & Advertisement Law
Where creative expression meets complex regulation, advertising review, broadcasting compliance, production and talent agreements.
Explore →
04Data Protection, Privacy & Cybersecurity
04
Data Protection, Privacy & Cybersecurity
Defensible governance under KVKK and the GDPR, data mapping, cross-border transfers, breach response and defence before the Authority.
Explore →
05IT & Technology Law
05
IT & Technology Law
Software, SaaS and cloud contracts, gaming and e-sports, startup financing rounds, e-commerce and fintech regulation, and the legal architecture around artificial intelligence.
Explore →
06Corporate Law & Commercial Advisory
06
Corporate Law & Commercial Advisory
Long-term external counsel for modern businesses, contracts, corporate governance and continuous regulatory compliance.
Explore →
07Dispute Resolution & Litigation
07
Dispute Resolution & Litigation
Strategic case planning and disciplined procedural management across commercial, administrative and enforcement proceedings.
Explore →
08Maritime, Yachting & Shipyard Law
08
Maritime, Yachting & Shipyard Law
Vessel finance, charter parties, cargo claims and marine insurance disputes, advisory across the full lifecycle of maritime operations.
Explore →
8 practice groups · hover to preview, click to openLegal Services · Trademark / Patent Attorneyship Services
Devin Law & IP
Our Team
Specialized legal teams handle each matter within their specific field of expertise. Partners, attorneys, specialists and trainees work together across practice groups — combining decades of courtroom experience with modern portfolio management.
Partners & Counsel
Uğurcan Tekin, LL.MPartner / Attorney at Law — Trademark Attorney
Intellectual & Industrial Property, Media Law, IT and Data Protection (KVKK). Legal 500 EMEA 2026 — Next Generation Partner; ranked individually in the WTR 1000 2026, and by IP STARS and Media Law International in both the 2026 and 2025 editions — representing multimedia companies and global brands in high-stakes IP and media litigation.
Profile →
Alican Tekin, LL.MPartner — Trademark Attorney
Co-Head of the IP Department — international trademark portfolio management and cross-border projects. Registered trademark attorney advising local and international clients on trademarks, designs and copyright.
Profile →
Kadir Karasu, MBAPartner
Intellectual Property, Mergers & Acquisitions and Project Finance. Senior-level advisory on complex, multi-jurisdictional matters, large-scale IP portfolios and advanced financing structures.
Profile →
Tevrat TekinCounsel / Attorney at Law
More than forty years of litigation experience — labour law, lease & tenancy, enforcement & bankruptcy and contractual claims before all levels of the Turkish courts.
Profile →
Attorneys & Specialists
İnci ÖzçilsalAttorney at Law
Corporate law, contracts, KVKK/GDPR compliance and intellectual property. Legal 500 EMEA 2026 — Key Lawyer; IP STARS 2026 — Rising Star; active in compliance projects, data inventories and trademark prosecution.
Profile →
Beyza ErdemirAttorney at Law
IP portfolio management, licensing, designs & patents; KVKK compliance and media law. Legal 500 EMEA 2026 — Key Lawyer. Advises national and international clients and takes an active role in enforcement strategy.
Profile →
Şevval Ezgi DemirAttorney at Law
Maritime & shipping law — vessel finance, charter parties, cargo claims and P&I / H&M insurance disputes. Also advises on company formation and commercial agreements across Turkish and foreign legal systems.
Profile →
Mehmet Kerem KüçükTrademark & Patent Specialist
Electrical & electronics engineering background — patent drafting, monitoring and evaluation. Combines technical knowledge with legal process across trademark and patent procedures.
Profile →
Berkay KizenFinance Specialist
Budget planning, financial analysis and reporting across the firm's operations — bringing an analytical, process-oriented discipline to financial management.
Profile →
Legal Trainees
Aleyna KalburcuLegal Trainee
Trademark procedures, KVKK compliance support and general litigation. Studies law on a full scholarship at Istanbul Commerce University.
Profile →
Sıla UçarLegal Trainee
Trademark applications, opposition processes and data protection compliance projects. Istanbul University Faculty of Law graduate supporting registration, opposition and defence strategies.
Profile →
Devin Law & IP — Istanbul
About Us
From the first spark of creativity to the global protection of your brand — a boutique law firm built on transparency, integrity and shared values, combining Legal Services with Trademark / Patent Attorneyship Services under one roof.
Who We Are
A strong professional culture grounded in transparency, integrity and shared values.
With more than 15 years of combined experience from its founders and solution partners, Devin Law & IP has built a strong professional culture grounded in transparency, integrity, and shared values. The firm concentrates on delivering sustainable legal solutions, forming teams with deep sector-specific expertise, and supporting clients across jurisdictions through a global perspective.
We serve a diverse client base from around the world, operating through dedicated practice groups led by experienced lawyers specializing in distinct areas of law. This structure enables a tailored, strategic approach to complex legal matters while ensuring efficiency and consistency in service delivery.
A strong emphasis is placed on long-term client relationships, supported by a highly qualified and collaborative team. In addition to legal excellence, the firm prioritizes diversity, continuous education and professional awareness — viewing these principles as essential to both institutional growth and responsible legal practice.
By combining experience, specialization and a client-focused mindset, Devin Law & IP positions itself as a trusted legal partner for businesses and individuals navigating today's evolving legal landscape. Alongside its Istanbul headquarters, the firm manages trademark and patent portfolios across multiple jurisdictions through its attorneyship practice — handling filings, oppositions, renewals and enforcement before TÜRKPATENT, EUIPO and WIPO.
Values
Why Choose Us
Legal Expertise
Our team brings a wealth of knowledge and experience across various industries, enabling strategic legal advice and actionable insights that help clients thrive in a competitive landscape.
Client-Focused Approach
We prioritize the unique legal needs and objectives of our clients, delivering personalized solutions tailored to their specific goals and challenges.
Innovative Legal Solutions
We embrace innovation and leverage modern legal technologies to develop creative solutions — staying ahead of industry trends so clients can seize new opportunities and overcome challenges.
Commitment to Sustainability
We are dedicated to helping clients adopt sustainable legal practices that benefit both their businesses and the world around them.
Strategic Perspective
We approach legal matters with a strategic mindset, aligning legal solutions with business objectives to support sustainable growth and informed decision-making.
"Smart approaches to legal solutions with exceptional service."
Articles and commentary from our team on intellectual property, media, data protection and regulatory developments — practical analysis of the decisions, legislation and market practice shaping Turkish and international law.
52 articles · 14 shown
202652 articles
Maritime & IP
Collision in the Sea of Marmara: Civil and Criminal Liability in Maritime Casualties
Taking the ship casualty off Silivri as its point of departure, this article examines the provisions governing collision, the scope of liability in damages, the operation of the criminal investigation, the administrative casualty investigation and the steps that must be taken in the first days following a casualty.
Şevval Ezgi Demir15 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 366: Platform Liability, Trademark Use and Price Transparency
A sectoral and thematic review of the decisions published in respect of the Advertising Board's meeting of 12 February 2026 and numbered 366, covering platform liability, price transparency, health and education promotions, and access-blocking decisions against illegal betting advertisements. The note assesses the compliance risks arising from the Board's administrative fines and suspension penalties.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 367: Right of Withdrawal, Comparative Claims and Health Connotations in Product Names
A sector-by-sector review of the decisions published in respect of the Advertising Board's meeting of 12 March 2026: e-commerce membership terminations tied to the right of withdrawal, comparative claims by crypto-asset platforms, and a three-month precautionary suspension for advertising continued despite prior sanctions. Compliance risks and administrative fines across the communications, finance, food, cosmetics and tourism sectors are assessed from a legal standpoint.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 368: Sanctions for Repeated Infringements, Interface Design and Superiority Claims
The decisions published in respect of the Advertising Board's meeting of 9 April 2026 and numbered 368 signal escalating sanctions: an advertiser that maintained its claims despite earlier penalties received an administrative fine of TRY 39,916,524. This note assesses the compliance risks arising for the communications, e-commerce, cosmetics, healthcare, finance and tourism sectors, from pre-selected payment options to indirect superiority claims.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
At its meeting of 14 May 2026 (No. 369), the Advertising Board imposed administrative fines exceeding TRY 7 million in total on three operators for 5G advertisements published before commercial launch, ruled on the merits in the 'Bank of the Mosts' campaign, and treated pre-selected paid services in online sales as an unfair commercial practice. This note assesses the sanctions across the communications, e-commerce, food, alcoholic beverage and health sectors from a compliance-risk perspective.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 370: Transitional Period in Health Promotion Legislation, Use of Trademarks and Logos, Denigrating Advertising
The Advertising Board's meeting of 11 June 2026, numbered 370, addressed the transitional application of the health promotion rules, e-commerce and retail campaign practices, denigrating advertisements and precautionary measures against visa intermediary services. With administrative fines reaching TRY 1,083,706, the decisions underline the need for a sector-by-sector review of advertising compliance.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 371: Disparaging Advertising, Consistency Between the Principal Claim and Its Exceptions, and the Boundary Between News and Advertising
At its meeting of 16 July 2026 (No. 371), the Advertising Board imposed a fine exceeding TRY 3.1 million on an operator's advertisement film found to disparage competitors through humour, scrutinised the consistency between spoken claims and subtitle exceptions, and continued to sanction the promotion of attorney-only services under the name of consultancy. This note assesses the decisions sector by sector, with a focus on compliance risks and sanctioning practice.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Data Protection
Turkish Data Protection Board Decisions — August 2026: Principle Decisions, Data Processing for Marketing Purposes and Workplace Surveillance
A thematic review of the Turkish Personal Data Protection Board's summer 2026 principle decisions and the decision summaries published on 10 August 2026, with a focus on compliance risk: the ban on biometric time tracking, administrative fines for marketing-related data processing, workplace camera surveillance, and data controllers' obligations in handling data subject applications.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Competition
Turkish Competition Board Decisions — June–August 2026: Conditional Clearances, the Commitment Procedure and New Investigations
An analysis of the Turkish Competition Board's decisions announced between June and August 2026: conditional clearances in the A101–CarrefourSA, Paramount–Warner Bros. Discovery and Cargill–PNS acquisitions, investigations concluded through the commitment and settlement procedures, and cartel fines exceeding TRY 3.6 billion in the automotive tyre sector. The note offers practice-oriented observations on merger notifications, the design of commitment packages and the management of investigation risk.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
IP Litigation
Trademark Invalidity Actions in Türkiye: Grounds, Acquiescence and the Difference from Administrative Revocation
A registered trademark is not always safe. A defect that existed at the moment of registration can lead to the mark being declared invalid by court judgment. The invalidity action is the vehicle for raising that defect. The Industrial Property Code No. 6769 governs the grounds of invalidity, the persons entitled to sue, and the loss of rights through acquiescence. This article examines the invalidity regime and how it differs from the administrative revocation route.
Uğurcan Tekin · İnci Özçilsal28 August 2026
Trademark
Proof of Use in Turkish Trademark Oppositions: The Five-Year Test
Under Article 19/2 of the Turkish Industrial Property Code, an opponent whose trademark has been registered for more than five years must, upon the applicant's request, prove genuine use of that mark in Türkiye. Where proof fails, the opposition fails with it. This article examines how the proof-of-use mechanism works, what counts as genuine use, and how both sides should prepare for it.
Uğurcan Tekin · Alican Tekin28 August 2026
Trademark
Trademark Licence Agreements under Turkish Law: Exclusive and Non-Exclusive Licences Compared
A trademark licence is the principal tool for monetising a mark without parting with it. Yet licence relationships built without regard to the licensing provisions of the Industrial Property Code No. 6769 expose both licensor and licensee to serious risk. This article covers the types of licence, the written-form requirement, recordal with the registry and the licensee's standing to sue.
Uğurcan Tekin · Alican Tekin28 August 2026
Trademark
Bad-Faith Trademark Filings in Türkiye: The True Owner's Toolkit
Those who try to register someone else's mark, a sign learned through a business relationship, or a name known in the market are treated as bad-faith applicants under Turkish trademark law. The Industrial Property Code No. 6769 keeps both the opposition and the invalidity route open against them. This article examines the concept of bad faith, its typical patterns, and the legal tools available to the true owner.
Uğurcan Tekin · İnci Özçilsal28 August 2026
Trademark
Protection of Well-Known Trademarks in Türkiye: When Does Protection Cross Class Boundaries?
Trademark protection is, as a rule, confined to the goods and services covered by the registration. For well-known marks, the Industrial Property Code No. 6769 crosses that boundary through two distinct mechanisms. This article examines the protection of well-known marks within the meaning of the Paris Convention and the beyond-class protection tied to reputation acquired in Türkiye, and sets out the differences between the two.
Uğurcan Tekin · Beyza Erdemir28 August 2026
Data Protection/Insights
Cybersecurity Law No. 7545: Centralised Governance, Audit and Sanctions Regime
In recent years, increasing cyber threats have placed cybersecurity at the heart of national security strategies. For states, it has evolved beyond the notion of “technical compliance” into a field shaped by institutional governance, service continuity, public order and sanction risk. In Türkiye, aligned with this approach, Cybersecurity Law No. 7545 was adopted on 12 March 2025 and entered into force upon its publication in the Official Gazette dated 19 March 2025, No. 32846.
Below, within a comparative framework alongside European Union regulations, the Law’s purpose, scope, institutional structure, obligations and sanctions regime are assessed in a practice-oriented manner.
Cybersecurity has moved from technical compliance to a governance domain linked to national security.
01
European Union Regulations: The EU Cybersecurity Act and the Cyber Resilience Act
In the European Union, the core framework in the field of cybersecurity has been built around two objectives: first, strengthening the institutional structure through Regulation (EU) 2019/881 and establishing an EU-wide common cybersecurity certification framework; and secondly, ensuring the security of products with digital elements — hardware and software — by design and throughout the product’s entire life cycle through the Cyber Resilience Act (Regulation (EU) 2024/2847).
Regulation (EU) 2019/881 — ENISA and the EU Cybersecurity Certification Framework. Regulation (EU) 2019/881 established ENISA as a permanent body; it provides that the Agency supports Member States in policy development and implementation processes, strengthens coordination in relation to cross-border threats, and monitors and assesses the impact of new technologies on cybersecurity. At the same time, an EU-wide European Cybersecurity Certification Framework was created; assurance levels — classified as “basic”, “substantial” and “high” — were defined for ICT products and services, thereby enabling stricter conformity assessment procedures to be applied for certain product and service categories.
Regulation (EU) 2024/2847 (CRA) — a horizontal regime focused on product security. The CRA centralises the product-security axis and introduces technology-neutral and objective-based minimum cybersecurity requirements for placing products with digital elements on the market; for manufacturers, it mandates that security be addressed from the design, development and production stages and be maintained throughout the product lifecycle. Within this scope, manufacturers are required to determine a support period for vulnerability management reflecting the product’s expected lifetime; as a rule, the support period is at least five years, and where the product’s expected lifetime is shorter than five years, it is limited accordingly. The CRA also provides for a CE marking mechanism for demonstrating conformity.
The CRA further adopts a tiered notification structure for vulnerabilities and security incidents: for vulnerabilities that are actively exploited and for “serious” incidents, the notification flow generally entails an early warning within twenty-four hours, a detailed incident notification within a specified period, and a separate final report within the scope of the relevant reporting obligations. In this process, a central reporting structure to be operated by ENISA comes to the fore.
With respect to the traceability of product components, the SBOM (Software Bill of Materials) approach gains importance under the CRA. In practice, however, the SBOM obligation should not be construed as an unconditional delivery requirement applicable in all cases; rather, it should be assessed together with the traceability and transparency obligations, in the sense that — where an SBOM is to be provided — the access and procurement mechanism for making it available must be clearly established.
As regards audits and sanctions, effective supervision is envisaged to be carried out through market surveillance authorities in the Member States; in the event of non-compliance, stringent sanctions are provided for, including administrative fines of up to EUR 15 million or 2.5% of the company’s worldwide annual turnover, and the principle that sanctions must be “effective, proportionate and dissuasive” is emphasised.
02
Common Purpose and Direction of the European Regulations
In the European Union, the CRA in particular aims to enhance cybersecurity resilience for products with digital elements across the EU and to establish a uniform legal framework applicable in all Member States. In this context, by eliminating the fragmented structure created by differing national regulations, it seeks to facilitate free movement within the internal market and to increase legal certainty regarding cybersecurity requirements for both manufacturers and users.
The CRA further addresses product security through a lifecycle approach; it envisages that products are placed on the market with fewer vulnerabilities, that manufacturers maintain updates and vulnerability management throughout the product’s lifetime, and that users are informed in a transparent manner about products’ security features and support periods. The overall direction of these regulations is to strengthen security throughout the supply chain, thereby reinforcing the EU’s strategic autonomy in this field and its role as an international standard-setter.
03
Purpose, Scope, Definitions and Fundamental Principles of Law No. 7545
Purpose. The primary objective of the Law is to prevent cyber threats, ensure an effective response to cyber incidents, protect critical digital infrastructures of the public and private sectors, and establish a comprehensive national cybersecurity strategy. The Law treats cybersecurity not merely as a set of technical measures, but as a governance domain directly linked to national security, public order and service continuity.
Within this framework, the Law is structured around an approach that sets out: the identification and elimination of existing and potential threats; the principles for reducing the possible impacts of cyber incidents; the adoption of regulations aimed at protection against cyberattacks; the determination of strategies and policies to strengthen the country’s cybersecurity; and the principles governing the establishment of the Cybersecurity Board.
Scope. In terms of scope, the Law envisages a broad field of application: it covers public institutions and organisations operating or maintaining a presence in cyberspace, as well as professional organisations having the status of public institutions; moreover, it also encompasses natural and legal persons and entities without legal personality. Accordingly, it expressly recognises that private actors — such as those involved in hosting, data processing, service provision, supply chains and infrastructure operation — form part of the national cybersecurity ecosystem.
On the other hand, the Law establishes a normative distinction between the civil and administrative cybersecurity regime and the domains of intelligence and military activities, by excluding from its scope intelligence activities conducted under specific laws and activities falling within the internal service regime of the Turkish Armed Forces.
Definitions. The definitions set out in the Law clarify the boundaries of the scope of application and the extent of the obligations:
“Cyberspace” refers to the environment consisting of information systems connected to the internet or to electronic communications and computer networks, and the networks linking them to one another.
“Information systems” are interpreted broadly, covering hardware, software, systems and all components.
“Cybersecurity” is a holistic field of activity encompassing safeguarding the confidentiality, integrity and availability of data, detecting attacks and incidents, operating response and alert mechanisms, and restoring systems to their pre-incident state.
“Cyber incident” refers to violations of confidentiality, integrity or availability.
“Cyberattack” refers to intentional acts aimed at such violations.
“Vulnerability” refers to an exploitable security flaw or weakness.
“Cyber threat” refers to a potential danger that may lead to a violation.
“Critical infrastructure” and “critical public service” refer to areas where a breach may result in loss of life, large-scale economic damage, disruption of public order or severe consequences for national security.
Fundamental principles. The Law underscores that cybersecurity is an integral part of national security and identifies as a core objective the creation of a secure cyberspace by protecting critical infrastructures and information systems. Conducting cybersecurity efforts on the basis of institutionalisation, continuity and sustainability; applying measures throughout the lifecycle of products and services; and prioritising domestic and national products are identified as guiding principles shaping implementation.
This approach, by extending obligations not only to public authorities but also to natural and legal persons, establishes a holistic regime of obligations across prevention and impact-mitigation processes; it is grounded in accountability and aims to keep strategy and policy development activities up to date through a continuous-improvement approach.
04
The Cybersecurity Directorate: Duties and Scope of Authority
The Cybersecurity Directorate established under the Law is designated as the central authority for determining and implementing Türkiye’s cybersecurity policies. The Directorate conducts activities aimed at increasing the cyber resilience of critical infrastructures and information systems, detecting attacks, preventing potential attacks and mitigating their effects; in this context, it institutionalises risk management by conducting or commissioning vulnerability and penetration tests and risk analyses relating to assets. The Directorate also strengthens operational capacity through its functions of obtaining, producing and sharing threat intelligence, conducting malware analysis activities and combating cyber threats.
The Directorate may identify critical infrastructures and make determinations regarding the relevant institutions and locations; it ensures that asset inventories of public institutions and critical infrastructures are maintained and that security measures are implemented in accordance with the criticality of assets, and it can manage the processes for establishing, causing the establishment of, and supervising Cyber Incident Response Teams. Within this framework, the Directorate’s remit also includes conducting exercises to assess response capabilities, coordinating with incident response teams of other countries, and encouraging the development of national cyber response tools.
In addition, the Directorate may lay down the procedures and principles to be complied with in the field of cybersecurity, assume the function of preparing standards and monitoring their implementation, and carry out certification and authorisation processes — coordinated with the relevant institutions — by establishing and operating testing and certification infrastructures for software, hardware, products, systems and services. As regards the practical implementation of these processes, secondary legislation will be determinative.
Standard-setting, certification, audit and incident response are brought together under a single coordination hub.
05
The Cybersecurity Board: A Strategic-Level Coordination Mechanism
With the Law, the Cybersecurity Board has been established as the highest-level decision-making mechanism, with the aim of determining cybersecurity-related policies and ensuring coordination.
Pursuant to Article 9 of the Law, the Board consists of the President of the Republic of Türkiye, the Vice President, the Minister of Justice, the Minister of Foreign Affairs, the Minister of Interior, the Minister of National Defence, the Minister of Industry and Technology, the Minister of Transport and Infrastructure, the Secretary General of the National Security Council, the Head of the National Intelligence Organisation, the President of Defence Industries and the Head of the Cybersecurity Directorate.
Where the President is unable to attend, the Vice President chairs the Board. Depending on the nature of the agenda, relevant ministers and individuals may be invited to Board meetings; where deemed necessary, the Board may establish commissions and working groups, and experts in the relevant field may be invited to participate in those groups.
The Board’s remit covers: setting policy and strategy; deciding on the nationwide implementation of the technology roadmap prepared by the Directorate; taking decisions on priority areas to be incentivised and on the development of human resources; determining critical infrastructure sectors; and acting as the decision-making authority in disputes that may arise between the Directorate and public institutions.
06
Cybersecurity Companies: Overseas Sales, Mergers and Transfers, and the Control Regime
The Law subjects transactions involving companies operating in the field of cybersecurity — such as mergers, demergers, share transfers or other transactions resulting in a change of control — to an approval and notification regime under the Directorate’s supervision. Transactions carried out without obtaining the Directorate’s approval do not acquire legal validity. In addition, the overseas sale of cybersecurity products, systems, software, hardware and services is made subject to procedures and principles to be determined by the Directorate; for products subject to authorisation, the Directorate’s approval is required.
These provisions serve the objectives of monitoring corporate transactions within the cybersecurity ecosystem from a national security perspective, keeping changes of control over critical technologies under administrative oversight, and ensuring supply chain security.
Critical infrastructure sectors are determined by the Board and mapped by the Directorate.
07
Obligations, Audit and the Critical Infrastructure Regime
Obligations. The Law imposes a range of cybersecurity obligations on persons and entities that provide services by means of information systems and collect and process data. Accordingly, the actors within the scope of the Law are responsible for:
Timely submitting to the Directorate the elements it requests, such as data, information, documents, hardware and software
Taking the measures prescribed by legislation
Reporting, without delay, any vulnerabilities or cyber incidents they detect
Procuring cybersecurity products and services to be used in public institutions and critical infrastructures from authorised and certified persons and entities
Implementing the necessary measures in line with the policies, strategies and action plans published by the Directorate
In addition, for companies carrying out activities subject to certification or authorisation, the Law provides for a mechanism requiring the Directorate’s approval before commencing operations.
Audit. From an audit perspective, the Directorate may audit acts and transactions falling within the scope of the Law where it deems necessary, and may conduct on-site inspections or have them conducted. Audit powers may be exercised not only by the Directorate’s personnel but also through authorised and certified independent auditors and independent audit firms. Those subject to audit are obliged to keep their devices, systems, software and hardware open to inspection, to provide the necessary infrastructure for the audit, and to take the measures required to keep that infrastructure operational.
Search, copying and seizure. For the purposes of national security, public order and preventing the commission of crimes or cyberattacks, the Law sets out the procedure under which searches, copying and seizure may be carried out in closed premises upon a judge’s decision; in cases where delay would be prejudicial, such measures may be taken pursuant to a written order of the public prosecutor. For these measures to be carried out in the data centres of authorised data centre operators, a judge’s decision is required.
Critical infrastructure regime. The Law defines as critical infrastructure those infrastructures hosting information systems where a breach of information or data security may lead to severe consequences such as loss of life, large-scale economic damage, security vulnerabilities or disruption of public order. It assigns to the Board the task of determining critical infrastructure sectors, and to the Directorate the tasks of identifying the institutions and locations of critical infrastructures, maintaining the asset inventory, and determining and ensuring the implementation of security measures based on criticality. Under existing practice, electronic communications, energy, water management, finance, transport and various public services are considered within the scope of critical infrastructure areas; within the Board’s power of determination, it is possible for these areas to be expanded.
08
Breaches and Sanctions: Criminal Provisions and Administrative Fines
The sanctions envisaged under the Law aim to ensure the effective fulfilment of obligations and establish a detailed framework covering both criminal sanctions and administrative fines. Under the Law, imprisonment and/or judicial fines are prescribed for: those who fail to provide, or who obstruct access to, information, documents, software, data or hardware requested by the competent authorities or audit officials; those who carry out activities without obtaining the required approvals, authorisations or permits; those who breach confidentiality obligations; those who unlawfully make accessible, disseminate or offer for sale data of a personal nature or data falling within the scope of critical public services; those who aim to create fear or panic in the public through false data-breach content; and those who commit cyberattacks against elements constituting Türkiye’s national power in cyberspace. Notable penalties in this context include:
Failure to provide, or obstruction of access to, information, documents, software, data or hardware requested by competent authorities or audit officials: one to three years’ imprisonment and a judicial fine of 500 to 1,500 day-units
Carrying out activities without the required approvals, authorisations or permits: two to four years’ imprisonment and a judicial fine of 1,000 to 2,000 day-units
Breach of confidentiality obligations: four to eight years’ imprisonment
Unlawfully making accessible, disseminating or selling personal data or data falling within the scope of critical public services: three to five years’ imprisonment
Aiming to create fear or panic through false data-leak content: two to five years’ imprisonment
Carrying out attacks against Türkiye’s national power in cyberspace, or keeping the obtained data in cyberspace: eight to twelve years’ imprisonment; disseminating, transmitting or selling such data: ten to fifteen years’ imprisonment
Violations of Article 12: three to five years’ imprisonment
Causing a data breach through abuse of duty or failure to take necessary measures: one to three years’ imprisonment
With respect to administrative fines, the Law provides for substantial administrative sanctions particularly in cases such as breaches of notification obligations, failure to comply with the requirement to procure certified and authorised products and services, non-compliance with procedural requirements for transactions subject to the Directorate’s approval or conformity assessment, failure to respond to requests for information, and failure to fulfil the obligation to cooperate during audits. In addition, the sanctions regime is complemented by procedural safeguards through provisions regulating the procedure for obtaining a defence statement, the possibility of escalation in the event of repeated misdemeanours, benefit- and loss-based increases, collection procedures, and recourse to administrative judicial review.
09
Conclusion and Assessment
The Law marks a clear shift towards eliminating institutional fragmentation in cybersecurity governance and consolidating authority under a central body. It is envisaged that cybersecurity activities previously carried out in a dispersed manner across different institutions will be brought together around the Directorate, and that the lack of coordination will be reduced through the implementation of a transition mechanism concerning the transfer of relevant assets and infrastructures. In this context, cybersecurity should no longer be regarded solely as a technical responsibility of IT units; rather, it should be assessed as a strategic governance domain that must be addressed at board level and is directly linked to corporate risk management, compliance and sustainability processes.
At the same time, the Law institutionalises the highest-level political and administrative coordination through the Board mechanism, so as to address cybersecurity at a strategic level; and it aims to strengthen uniform implementation across the public–private ecosystem and enhance rapid decision-making capacity by bringing standard-setting, certification, auditing and incident response functions together under a single coordination hub.
One of the Law’s most notable features is that it abandons a recommendation-based approach and establishes a sanctions regime with a high deterrent effect. In this framework, the explicit codification of notification and cooperation duties as binding obligations, the establishment and supervision of Cyber Incident Response Teams, and the combined regulation of administrative and criminal sanctions bring cyber risk management to the centre of the senior management agenda for companies.
Nevertheless, for the regulation to be effectively implemented in all its aspects, it will be decisive that the implementing regulations and secondary legislation are brought into force within the prescribed timeframes, so as to clarify the practical application of standardisation, certification and audit processes.
10
Our Recommendations
The Law introduces numerous obligations that directly address not only public institutions and organisations but also private-sector actors. In this context, in order for companies to avoid exposure to administrative and criminal sanctions and to establish an adequate level of compliance with cybersecurity legislation, it is important to create an institutional archiving and reporting infrastructure that enables information and documents to be duly retained and classified and, upon request, produced without delay; to measure the level of technical security by conducting vulnerability scans and penetration tests at regular intervals; and to minimise human-resource-related risks through periodic training programmes aimed at increasing employees’ cybersecurity awareness.
Likewise, keeping the asset inventory up to date and structuring risk analysis as an ongoing process, operationalising vulnerability and cyber-incident notification mechanisms, and ensuring compliance with certification and authorisation requirements for procured cybersecurity products and services will directly contribute to meeting the standards of the obligations set out under the Law.
In particular, for companies operating within the scope of critical infrastructure or critical public services, the following are decisive for mitigating the risk of sanctions arising from non-compliance: establishing a written procurement and supply policy and contractual framework that takes into account supply chain security and the prioritisation of domestic and national products; putting in place a documentation, record-keeping and traceability framework so as to be prepared for notification and audit processes; incorporating certification and authorisation requirements into supplier contracts through clear and binding provisions; and ultimately transforming all of these elements — under senior management oversight — into a sustainable cyber compliance programme.
Reach our team for your intellectual property portfolio, corporate needs or an ongoing dispute. We respond to every enquiry with a clear assessment of scope, timing and next steps — and we build specialized teams around each matter from day one.
Istanbul Office
Let's talk.
Our offices are located in the Ferko Signature building on Büyükdere Caddesi, at the heart of Istanbul's business district. Whether you are protecting a single trademark or restructuring an international portfolio, the first conversation is always with the team that will actually handle your matter.
For trademark and patent attorneyship services, our dedicated prosecution practice also operates through devinpatent.com — covering filings, renewals, oppositions and portfolio administration before TÜRKPATENT, EUIPO and WIPO.
On Büyükdere Caddesi — the spine of Istanbul's central business district — Ferko Signature places the firm minutes from the courts, TÜRKPATENT liaison offices and the headquarters of the companies we serve.
Transform Traditional Law with a Modern Vision — building your career at Devin Law & IP means leading through complex legal challenges and shaping the future of the industry.
Why Devin
Lead through complex legal challenges. Shape the future of the industry.
We invite you to be part of our innovative vision, create impact with strategic solutions, and elevate your professional journey to the highest level. Join us to demonstrate your legal expertise within a modern and dynamic platform.
At Devin Law & IP, junior colleagues work directly with partners on live matters from their first week — trademark oppositions, litigation strategy, KVKK compliance projects and international portfolio work. Mentoring is structured, feedback is continuous, and responsibility grows with demonstrated ability rather than seniority alone.
To apply, send your CV and a short note describing your interest in working with our firm to info@devinlaw.com.tr. Applications are reviewed on a rolling basis and every candidate receives a response.
Lawyers
Attorneys with litigation or IP prosecution experience who want to work on high-stakes, cross-border matters within specialized practice groups.
Internships
Legal internships for law students and graduates — hands-on exposure to trademark procedures, litigation and data protection projects alongside experienced mentors.
Business Services
Finance, administration and operations roles that keep a modern law firm running with precision.
Independent international directories consistently rank our team among the leading practitioners in intellectual property and media law in Türkiye. Our intellectual property and media practice has been recognised by The Legal 500 EMEA, the WTR 1000, Managing IP's IP STARS and Media Law International in both the 2026 and 2025 editions. Click any ranking below for the full details.
2026Current Edition
The rankings published for the current cycle — across intellectual property and media law.
Five Categories · 2026IP STARS — Managing IP
In the IP STARS 2026 rankings published by Managing IP, Devin Law & IP is ranked in five practice categories in Türkiye — with Uğurcan Tekin and İnci Özçilsal recognised among Türkiye's leading IP practitioners as Rising Stars, supported by eleven client testimonials on prosecution, enforcement and opposition work.
All Details →
Recommended · 2026WTR 1000
In the 2026 edition, World Trademark Review's WTR 1000 recognises Uğurcan Tekin individually for trademark protection and international IP strategies — identifying the world's leading trademark professionals through extensive research among clients and peers, including his work on global strategies for multinational corporations and proceedings before WIPO.
All Details →
Ranked · EMEA 2026The Legal 500 EMEA
Ranked in the Legal 500 EMEA 2026 edition in Intellectual Property and Media & Entertainment. Uğurcan Tekin is listed as a Next Generation Partner, with İnci Özçilsal and Beyza Erdemir recognised as Key Lawyers — supported by directory commentary and client testimonials on the team's patent, advertising and brand protection work.
All Details →
Tier 2 · 2026Media Law International
In its 2026 rankings, Media Law International places Devin Law & IP at Tier 2 of the Türkiye country chapter among the leading law firms for media law, with Uğurcan Tekin named among the Top 10 Recommended Media Lawyers in Turkey — reflecting expertise in digital media regulation, content management and broadcasting standards.
All Details →
2025Previous Edition
Recognitions earned in the preceding ranking cycle by the same intellectual property and media practice.
Ranked · EMEA 2025The Legal 500 EMEA
Ranked in the Legal 500 EMEA 2025 edition in Intellectual Property and Media & Entertainment, with Uğurcan Tekin as practice head. The editorial assessment highlighted advisory work for the full spectrum of media stakeholders — from multinational media companies to individual actors, directors and agents — and the team's depth in digital media, online content and data privacy.
All Details →
Ranked · 2025Media Law International
In its 2025 assessments, Media Law International recognised the practice as one of Türkiye's leading media law firms, with Uğurcan Tekin selected among the ten recommended media law practitioners in Türkiye.
All Details →
Recommended Firm · 2025IP STARS — Managing IP
In the IP STARS rankings published in 2025 by Managing IP, the practice was listed among the recommended firms in Türkiye — international recognition of the breadth of experience and strategic approach the team brings to intellectual property work.
All Details →
Recommended Firm · 2025WTR 1000
In the 2025 edition, World Trademark Review's WTR 1000 listed the practice among the recommended trademark firms in the Türkiye ranking — reflecting the team's work on filing strategy, portfolio management and contentious trademark matters for domestic and international clients.