Strategic Legal Solutions For A Global Business World
Strategic Legal Services Tailored for Modern Business — advisory and dispute resolution across intellectual property, media, technology, corporate and regulatory law, delivered by dedicated practice groups from Istanbul for clients around the world.
Ranked inIP STARS·WTR 1000·THE LEGAL 500·MEDIA LAW INTERNATIONAL
Scroll
0Years of Combined Experience
0Practice Areas
0Professionals
0International Rankings
01
Who We Are
A Proven Legal Blueprint to Secure What You've Built.
Devin Law & IP is a boutique law firm with over 15 years of combined experience from its founders and partners. The firm operates on principles of transparency, integrity, and shared values, and delivers sustainable legal solutions through dedicated practice groups.
We serve diverse international clients by forming specialized teams with sector expertise. Long-term client relationships, diversity, continuous education and professional development are our core institutional values.
Founded on professionalism, transparency and long-term value creation, the firm combines sector expertise with strategic legal insight — providing clear, practical and result-oriented solutions for businesses and individuals.
Alongside its Istanbul headquarters, the firm manages trademark and patent portfolios across multiple jurisdictions through its attorneyship practice — handling filings, oppositions, renewals and enforcement before TÜRKPATENT, EUIPO and WIPO on behalf of local and international rights holders.
This dual structure — Legal Services on one side and Trademark / Patent Attorneyship Services on the other — allows the firm to combine contentious litigation strength with disciplined portfolio administration, so that every matter is handled by a team specialised in its own field.
02
Why Choose Us
Legal Expertise
Professionals with extensive knowledge across industries provide strategic advice and actionable insights. Every matter is staffed by a team with genuine sector experience, so our advice reflects commercial reality rather than abstract theory.
Client-Focused Approach
Personalized solutions tailored to specific client goals through collaborative engagement. We invest time in understanding each client's business model, risk appetite and priorities before shaping the legal strategy around them.
Innovative Legal Solutions
Leveraging modern legal technologies to develop creative, sustainable approaches. From portfolio automation to structured watch services, we use technology to deliver faster and more consistent outcomes.
Commitment to Sustainability
Supporting clients in adopting ethical practices that benefit both business and society. We help build compliance cultures that are durable, defensible and aligned with evolving international standards.
Strategic Perspective
Aligning legal solutions with business objectives for sustainable growth. Advice is always framed as a business decision — with clear options, realistic costs and measurable consequences.
03
Legal Services Tailored to Your Business
01
Industrial Property Law
Trademarks, patents & utility models and industrial designs — consultancy, prosecution and litigation before TÜRKPATENT, EUIPO and WIPO.
Explore →
02
Intellectual Property & Copyright Law
Copyright, software and related rights under FSEK No. 5846 — from ownership architecture and registration through to piracy enforcement.
Explore →
03
Media, Entertainment & Advertisement
Where creative expression meets complex regulation — advertising review, broadcasting compliance, production and talent agreements.
Explore →
04
Data Protection, Privacy & Cybersecurity
Defensible governance under KVKK and the GDPR — data mapping, cross-border transfers, breach response and defence before the Authority.
Explore →
05
IT & Technology Law
Software, SaaS and cloud contracts, gaming and e-sports, startup financing rounds, e-commerce and fintech regulation, and the legal architecture around artificial intelligence.
Explore →
06
Corporate Law & Commercial Advisory
Retainer counsel across every department, commercial contracts, general assemblies, board resolutions, capital structures and shareholder disputes.
Explore →
07
Dispute Resolution & Litigation
Commercial and contractual litigation, debt recovery and enforcement, labour defence, white-collar crime, shareholder disputes, lease actions, mediation and arbitration.
Explore →
08
Maritime, Yachting & Shipyard Law
Superyacht newbuilds and refits, shipyard operations, yacht design and IP, sale and purchase, flagging, chartering and crew, vessel arrests and marine casualties.
Explore →
"From the first spark of creativity to the global protection of your brand."
New Rules on the Classification of Goods and Services in Trademark Applications
26 February 2026 — Read →
Regulatory
Amendment on Fees Chargeable to Consumers in Food and Beverage Services
16 February 2026 — Read →
Devin Law & IP · Practice Areas
Our Services
Comprehensive legal services combining sector expertise with strategic legal insight: clear, practical and result-oriented solutions for businesses and individuals. Eight dedicated practice groups cover intellectual property, media and advertising, data protection, technology, corporate matters, dispute resolution and maritime law, for multinational groups and early-stage ventures alike.
01Industrial Property LawTrademarks, patents & utility models and industrial designs, consultancy, prosecution and litigation before TÜRKPATENT, EUIPO and WIPO.
02Intellectual Property & Copyright LawCopyright, software and related rights under FSEK No. 5846, from ownership architecture and registration through to piracy enforcement.
03Media, Entertainment & Advertisement LawWhere creative expression meets complex regulation, advertising review, broadcasting compliance, production and talent agreements.
04Data Protection, Privacy & CybersecurityDefensible governance under KVKK and the GDPR, data mapping, cross-border transfers, breach response and defence before the Authority.
05IT & Technology LawSoftware, SaaS and cloud contracts, gaming and e-sports, startup financing rounds, e-commerce and fintech regulation, and the legal architecture around artificial intelligence.
06Corporate Law & Commercial AdvisoryLong-term external counsel for modern businesses, contracts, corporate governance and continuous regulatory compliance.
07Dispute Resolution & LitigationStrategic case planning and disciplined procedural management across commercial, administrative and enforcement proceedings.
08Maritime, Yachting & Shipyard LawVessel finance, charter parties, cargo claims and marine insurance disputes, advisory across the full lifecycle of maritime operations.
Devin Law & IP
Our Team
Specialized legal teams handle each matter within their specific field of expertise. Partners, attorneys, specialists and trainees work together across practice groups — combining decades of courtroom experience with modern portfolio management.
Partners & Counsel
Uğurcan Tekin, LL.MPartner / Attorney at Law — Trademark Attorney
Intellectual & Industrial Property, Media Law, IT and Data Protection (KVKK). Legal 500 EMEA 2026 — Next Generation Partner; ranked individually in the WTR 1000 2026, and by IP STARS and Media Law International in both the 2026 and 2025 editions — representing multimedia companies and global brands in high-stakes IP and media litigation.
Profile →
Alican Tekin, LL.MPartner — Trademark Attorney
Co-Head of the IP Department — international trademark portfolio management and cross-border projects. Registered trademark attorney advising local and international clients on trademarks, designs and copyright.
Profile →
Kadir Karasu, MBAPartner
Intellectual Property, Mergers & Acquisitions and Project Finance. Senior-level advisory on complex, multi-jurisdictional matters, large-scale IP portfolios and advanced financing structures.
Profile →
Tevrat TekinCounsel / Attorney at Law
More than forty years of litigation experience — labour law, lease & tenancy, enforcement & bankruptcy and contractual claims before all levels of the Turkish courts.
Profile →
Attorneys & Specialists
İnci ÖzçilsalAttorney at Law
Corporate law, contracts, KVKK/GDPR compliance and intellectual property. Legal 500 EMEA 2026 — Key Lawyer; IP STARS 2026 — Rising Star; active in compliance projects, data inventories and trademark prosecution.
Profile →
Beyza ErdemirAttorney at Law
IP portfolio management, licensing, designs & patents; KVKK compliance and media law. Legal 500 EMEA 2026 — Key Lawyer. Advises national and international clients and takes an active role in enforcement strategy.
Profile →
Şevval Ezgi DemirAttorney at Law
Maritime & shipping law — vessel finance, charter parties, cargo claims and P&I / H&M insurance disputes. Also advises on company formation and commercial agreements across Turkish and foreign legal systems.
Profile →
Mehmet Kerem KüçükTrademark & Patent Specialist
Electrical & electronics engineering background — patent drafting, monitoring and evaluation. Combines technical knowledge with legal process across trademark and patent procedures.
Profile →
Berkay KizenFinance Specialist
Budget planning, financial analysis and reporting across the firm's operations — bringing an analytical, process-oriented discipline to financial management.
Profile →
Legal Trainees
Aleyna KalburcuLegal Trainee
Trademark procedures, KVKK compliance support and general litigation. Studies law on a full scholarship at Istanbul Commerce University.
Profile →
Sıla UçarLegal Trainee
Trademark applications, opposition processes and data protection compliance projects. Istanbul University Faculty of Law graduate supporting registration, opposition and defence strategies.
Profile →
Devin Law & IP — Istanbul
About Us
From the first spark of creativity to the global protection of your brand — a boutique law firm built on transparency, integrity and shared values, combining Legal Services with Trademark / Patent Attorneyship Services under one roof.
Who We Are
A strong professional culture grounded in transparency, integrity and shared values.
With more than 15 years of combined experience from its founders and solution partners, Devin Law & IP has built a strong professional culture grounded in transparency, integrity, and shared values. The firm concentrates on delivering sustainable legal solutions, forming teams with deep sector-specific expertise, and supporting clients across jurisdictions through a global perspective.
We serve a diverse client base from around the world, operating through dedicated practice groups led by experienced lawyers specializing in distinct areas of law. This structure enables a tailored, strategic approach to complex legal matters while ensuring efficiency and consistency in service delivery.
A strong emphasis is placed on long-term client relationships, supported by a highly qualified and collaborative team. In addition to legal excellence, the firm prioritizes diversity, continuous education and professional awareness — viewing these principles as essential to both institutional growth and responsible legal practice.
By combining experience, specialization and a client-focused mindset, Devin Law & IP positions itself as a trusted legal partner for businesses and individuals navigating today's evolving legal landscape. Alongside its Istanbul headquarters, the firm manages trademark and patent portfolios across multiple jurisdictions through its attorneyship practice — handling filings, oppositions, renewals and enforcement before TÜRKPATENT, EUIPO and WIPO.
Values
Why Choose Us
Legal Expertise
Our team brings a wealth of knowledge and experience across various industries, enabling strategic legal advice and actionable insights that help clients thrive in a competitive landscape.
Client-Focused Approach
We prioritize the unique legal needs and objectives of our clients, delivering personalized solutions tailored to their specific goals and challenges.
Innovative Legal Solutions
We embrace innovation and leverage modern legal technologies to develop creative solutions — staying ahead of industry trends so clients can seize new opportunities and overcome challenges.
Commitment to Sustainability
We are dedicated to helping clients adopt sustainable legal practices that benefit both their businesses and the world around them.
Strategic Perspective
We approach legal matters with a strategic mindset, aligning legal solutions with business objectives to support sustainable growth and informed decision-making.
"Smart approaches to legal solutions with exceptional service."
Articles and commentary from our team on intellectual property, media, data protection and regulatory developments — practical analysis of the decisions, legislation and market practice shaping Turkish and international law.
Data Protection · 18 June 2026
Workplace CCTV Systems: The Authority's Public Announcement of 8 June 2026
In its Public Announcement of 8 June 2026 the Personal Data Protection Authority drew a clear line between camera use for security purposes and surveillance directed at employee performance, efficiency or conduct. Assessed alongside Board decisions, Council of State case law and European data protection standards, the announcement operates as a compliance guide requiring data controllers to reassess existing systems.
Uğurcan Tekin · İnci Özçilsal · Beyza ErdemirDevin Law & IP
Read Article →
Data Protection · 16 June 2026
The Constitutional Court’s Viennalife Judgment: Publicly Disclosed Personal Data and the Principle of Legality
The Constitutional Court did not rule on whether the Data Protection Board’s “intention to disclose” doctrine is right or wrong as a matter of data protection law. It held something narrower and far more consequential: a criterion that does not appear in the statute cannot, through interpretation alone, be turned into the basis of an administrative fine.
Uğurcan Tekin · İnci ÖzçilsalDevin Law & IP
Read Article →
Regulatory · 14 June 2026
Türkiye’s First Climate Law Adopted by the Grand National Assembly
Türkiye has enacted its inaugural Climate Law — a major legislative achievement in the pursuit of environmental sustainability and reduced carbon emissions. The Law restructures existing environmental and energy policy, establishes the Climate Change Presidency as a central coordinating body, assigns substantial responsibilities to municipal authorities, and introduces an Emission Trading System together with a Carbon Border Adjustment Mechanism.
Uğurcan Tekin · İnci ÖzçilsalDevin Law & IP
Read Article →
Data Protection · 31 March 2026
Sharing Data With Third Parties and the Rules Governing Debt Payment Processes
Debt information is not merely economic data; it discloses an individual’s financial position and is therefore private information requiring legal protection. Being a spouse, parent, sibling or friend does not alter third-party status before a data controller — and a third party’s right to pay a debt is not a right to learn its amount.
Uğurcan Tekin · İnci ÖzçilsalDevin Law & IP
Read Article →
Corporate · 26 March 2026
Expulsion of a Shareholder in Two-Shareholder Limited Companies After the Constitutional Court's Judgment of 17 March 2026
The Constitutional Court annulled, in respect of two-shareholder limited companies, the provisions making an application for expulsion dependent on a general assembly resolution taken by an aggravated quorum — restoring an effective remedy where the decision-making mechanism was structurally deadlocked.
Uğurcan Tekin · İnci Özçilsal · Beyza ErdemirDevin Law & IP
Read Article →
Data Protection · 24 March 2026
Cybersecurity Law No. 7545: Centralised Governance, Audit and Sanctions Regime
Cybersecurity Law No. 7545 abandons a recommendation-based approach and establishes a centralised governance structure with a high-deterrence sanctions regime. Assessed alongside the EU Cybersecurity Act and the Cyber Resilience Act, the Law brings cyber risk management from the IT department to the board agenda.
Uğurcan Tekin · İnci ÖzçilsalDevin Law & IP
Read Article →
Data Protection · 19 March 2026
Generative Artificial Intelligence in the Workplace: Risks, Responsibilities and Compliance Strategies
Data entered into generative AI tools generally constitutes personal data processing and frequently a cross-border transfer. Prohibition-led policies push employees toward 'Shadow AI'; the Authority's guidance favours clear boundaries, technical and administrative measures, human oversight and training.
Uğurcan Tekin · İnci Özçilsal · Beyza ErdemirDevin Law & IP
A sectoral analysis of the decisions taken at the meeting of the Advertising Board of the Ministry of Trade dated 13 January 2026 and numbered 365 — covering communication services, consumer durables and technology, food and food supplements, and a broad range of other goods and services.
Uğurcan Tekin · İnci Özçilsal · Beyza ErdemirDevin Law & IP
Read Article →
Trademark · 26 February 2026
New Rules on the Classification of Goods and Services in Trademark Applications
TÜRKPATENT Communiqué No. 2026/2, published in the Official Gazette of 26 February 2026, repeals the 2024 Communiqué and reassigns a series of goods between classes. The amendments directly affect filing strategy in the optical, textile, automotive, sanitary-ware and technology sectors.
Uğurcan Tekin · Alican Tekin · Mehmet Kerem KüçükDevin Law & IP
Read Article →
Regulatory · 16 February 2026
Amendment on Fees Chargeable to Consumers in Food and Beverage Services
The Regulation Amending the Price Tag Regulation, published in the Official Gazette of 30 January 2026, expressly prohibits service charges, table charges, cover charges and similar items in restaurants, cafés and comparable establishments — and the Ministry has already begun sanctioning indirect circumvention.
Uğurcan Tekin · Beyza Erdemir · Sıla UçarDevin Law & IP
Read Article →
Trademark · 14 February 2026
Opinions and Criticisms on the Practical Application of Article 6/3 of the Industrial Property Code
Article 6/3 of the Industrial Property Code is a narrow but vital exception to the registration principle, protecting the genuine right holder who has actually used an unregistered sign in trade. In practice, however, court-appointed experts increasingly extend that protection far beyond the classes in which the sign has ever been used — effectively legislating from the expert report and eroding the legal certainty of registered proprietors.
Uğurcan Tekin · Alican Tekin · İnci ÖzçilsalDevin Law & IP
Read Article →
Data Protection · 14 February 2026
The Turkish Data Protection Board’s Ex Officio and On-Site Inspection Powers
The Turkish Data Protection Board does not depend on complaints. Drawing on its own findings, press reports, notifications and social media, it opens investigations of its own motion — and, where written submissions fall short, it goes on site. This article maps both powers through the Board’s published decisions and sets out what data controllers should have ready before an inspection begins.
Uğurcan Tekin · İnci ÖzçilsalDevin Law & IP
Read Article →
Copyright · 14 February 2026
Protection of Unregistered Copyright Against Trademark Applications
Copyright arises the moment a work is created — registration is a means of proof, not a condition of the right. Yet in opposition proceedings a registration certificate is still routinely demanded. The Ankara Regional Court of Appeal’s finalised TOSPİK judgment breaks with that formalism and opens the way for creators without certificates to defend their characters against opportunistic trademark filings.
Uğurcan Tekin · Alican Tekin · Beyza ErdemirDevin Law & IP
Read Article →
E-Commerce & IP · 14 February 2026
Intellectual and Industrial Property Infringements on E-Commerce Platforms
The forty-eight-hour takedown mechanism introduced by the E-Commerce Law and its implementing Regulation gives right holders speed that litigation cannot match. It also hands competitors a weapon: an intermediary service provider that is not equipped to adjudicate a trademark dispute may nevertheless be obliged to remove a listing on the strength of a certificate alone.
Uğurcan Tekin · Alican Tekin · Beyza ErdemirDevin Law & IP
Read Article →
Unfair Competition · 14 February 2026
Misleading Statements and Unfair Competition Based on Non-Finalized TÜRKPATENT Decisions
A decision of the Turkish Patent and Trademark Office being final is not the same as its being conclusive. Statements, filings and commercial claims built on a decision that has not yet become conclusive can distort competition, mislead consumers and expose the maker to civil and criminal liability for unfair competition under the Turkish Commercial Code.
Uğurcan Tekin · Beyza ErdemirDevin Law & IP
Read Article →
Trademark · 14 February 2026
Trademark Infringement Through Internet Domain Names and the Litigation Process
A domain name is the most visible use a trademark makes of the digital environment. This article sets out the cumulative conditions under which use of a sign in a domain name amounts to trademark infringement, the loss of rights through acquiescence, and the full range of interim, civil and criminal remedies available to the proprietor before the Turkish courts.
Uğurcan Tekin · Beyza ErdemirDevin Law & IP
Read Article →
Trademark · 14 February 2026
The Court of Cassation’s Approach to Trademark Registrations with a High Degree of Genericness
The Court of Cassation’s RUBY judgment restates a principle that practice too often forgets: so long as a mark remains on the register, it confers absolute and exclusive protection — even where the shared element is said to have become generic. Yet the Office continues to treat weakly distinctive registrations as though they did not exist, and the resulting contradiction is driving a steady rise in annulment actions.
Uğurcan Tekin · Alican Tekin · Beyza ErdemirDevin Law & IP
Read Article →
Data Protection · 12 February 2026
Push Notifications in Mobile Applications Under the Personal Data Protection Law
Bundling an order-tracking notification together with a marketing notification behind a single consent box does not produce valid explicit consent. Following the Board’s Principle Decision No. 2025/1072, granular consent is no longer a design preference for mobile application providers — it is a legal obligation.
Uğurcan Tekin · İnci ÖzçilsalDevin Law & IP
Read Article →
Data Protection · 6 February 2026
Establishing an Internal Personal Data Protection Board Within the Company
Written policies alone no longer demonstrate compliance. An internal Personal Data Protection Board that meets on a defined cycle, records its decisions in minutes and reports to management turns accountability from a stated principle into documented evidence — and, in an investigation, into a defensible position.
Uğurcan Tekin · İnci ÖzçilsalDevin Law & IP
Read Article →
Media & Advertising · 4 February 2026
Advertising Board Decisions — Meeting No. 364: Current Legal Assessments
A sectoral and thematic analysis of the decisions published in respect of the Advertising Board's meeting of 11 December 2025 and numbered 364 — covering the healthcare sector, tourism, and the automotive, e-commerce, platform services and digital interface sectors.
Uğurcan Tekin · İnci Özçilsal · Beyza ErdemirDevin Law & IP
Cybersecurity Law No. 7545: Centralised Governance, Audit and Sanctions Regime
In recent years, increasing cyber threats have placed cybersecurity at the heart of national security strategies. For states, it has evolved beyond the notion of “technical compliance” into a field shaped by institutional governance, service continuity, public order and sanction risk. In Türkiye, aligned with this approach, Cybersecurity Law No. 7545 was adopted on 12 March 2025 and entered into force upon its publication in the Official Gazette dated 19 March 2025, No. 32846.
Below, within a comparative framework alongside European Union regulations, the Law’s purpose, scope, institutional structure, obligations and sanctions regime are assessed in a practice-oriented manner.
Cybersecurity has moved from technical compliance to a governance domain linked to national security.
European Union Regulations: The EU Cybersecurity Act and the Cyber Resilience Act
In the European Union, the core framework in the field of cybersecurity has been built around two objectives: first, strengthening the institutional structure through Regulation (EU) 2019/881 and establishing an EU-wide common cybersecurity certification framework; and secondly, ensuring the security of products with digital elements — hardware and software — by design and throughout the product’s entire life cycle through the Cyber Resilience Act (Regulation (EU) 2024/2847).
Regulation (EU) 2019/881 — ENISA and the EU Cybersecurity Certification Framework. Regulation (EU) 2019/881 established ENISA as a permanent body; it provides that the Agency supports Member States in policy development and implementation processes, strengthens coordination in relation to cross-border threats, and monitors and assesses the impact of new technologies on cybersecurity. At the same time, an EU-wide European Cybersecurity Certification Framework was created; assurance levels — classified as “basic”, “substantial” and “high” — were defined for ICT products and services, thereby enabling stricter conformity assessment procedures to be applied for certain product and service categories.
Regulation (EU) 2024/2847 (CRA) — a horizontal regime focused on product security. The CRA centralises the product-security axis and introduces technology-neutral and objective-based minimum cybersecurity requirements for placing products with digital elements on the market; for manufacturers, it mandates that security be addressed from the design, development and production stages and be maintained throughout the product lifecycle. Within this scope, manufacturers are required to determine a support period for vulnerability management reflecting the product’s expected lifetime; as a rule, the support period is at least five years, and where the product’s expected lifetime is shorter than five years, it is limited accordingly. The CRA also provides for a CE marking mechanism for demonstrating conformity.
The CRA further adopts a tiered notification structure for vulnerabilities and security incidents: for vulnerabilities that are actively exploited and for “serious” incidents, the notification flow generally entails an early warning within twenty-four hours, a detailed incident notification within a specified period, and a separate final report within the scope of the relevant reporting obligations. In this process, a central reporting structure to be operated by ENISA comes to the fore.
With respect to the traceability of product components, the SBOM (Software Bill of Materials) approach gains importance under the CRA. In practice, however, the SBOM obligation should not be construed as an unconditional delivery requirement applicable in all cases; rather, it should be assessed together with the traceability and transparency obligations, in the sense that — where an SBOM is to be provided — the access and procurement mechanism for making it available must be clearly established.
As regards audits and sanctions, effective supervision is envisaged to be carried out through market surveillance authorities in the Member States; in the event of non-compliance, stringent sanctions are provided for, including administrative fines of up to EUR 15 million or 2.5% of the company’s worldwide annual turnover, and the principle that sanctions must be “effective, proportionate and dissuasive” is emphasised.
Common Purpose and Direction of the European Regulations
In the European Union, the CRA in particular aims to enhance cybersecurity resilience for products with digital elements across the EU and to establish a uniform legal framework applicable in all Member States. In this context, by eliminating the fragmented structure created by differing national regulations, it seeks to facilitate free movement within the internal market and to increase legal certainty regarding cybersecurity requirements for both manufacturers and users.
The CRA further addresses product security through a lifecycle approach; it envisages that products are placed on the market with fewer vulnerabilities, that manufacturers maintain updates and vulnerability management throughout the product’s lifetime, and that users are informed in a transparent manner about products’ security features and support periods. The overall direction of these regulations is to strengthen security throughout the supply chain, thereby reinforcing the EU’s strategic autonomy in this field and its role as an international standard-setter.
Purpose, Scope, Definitions and Fundamental Principles of Law No. 7545
Purpose. The primary objective of the Law is to prevent cyber threats, ensure an effective response to cyber incidents, protect critical digital infrastructures of the public and private sectors, and establish a comprehensive national cybersecurity strategy. The Law treats cybersecurity not merely as a set of technical measures, but as a governance domain directly linked to national security, public order and service continuity.
Within this framework, the Law is structured around an approach that sets out: the identification and elimination of existing and potential threats; the principles for reducing the possible impacts of cyber incidents; the adoption of regulations aimed at protection against cyberattacks; the determination of strategies and policies to strengthen the country’s cybersecurity; and the principles governing the establishment of the Cybersecurity Board.
Scope. In terms of scope, the Law envisages a broad field of application: it covers public institutions and organisations operating or maintaining a presence in cyberspace, as well as professional organisations having the status of public institutions; moreover, it also encompasses natural and legal persons and entities without legal personality. Accordingly, it expressly recognises that private actors — such as those involved in hosting, data processing, service provision, supply chains and infrastructure operation — form part of the national cybersecurity ecosystem.
On the other hand, the Law establishes a normative distinction between the civil and administrative cybersecurity regime and the domains of intelligence and military activities, by excluding from its scope intelligence activities conducted under specific laws and activities falling within the internal service regime of the Turkish Armed Forces.
Definitions. The definitions set out in the Law clarify the boundaries of the scope of application and the extent of the obligations:
“Cyberspace” refers to the environment consisting of information systems connected to the internet or to electronic communications and computer networks, and the networks linking them to one another.
“Information systems” are interpreted broadly, covering hardware, software, systems and all components.
“Cybersecurity” is a holistic field of activity encompassing safeguarding the confidentiality, integrity and availability of data, detecting attacks and incidents, operating response and alert mechanisms, and restoring systems to their pre-incident state.
“Cyber incident” refers to violations of confidentiality, integrity or availability.
“Cyberattack” refers to intentional acts aimed at such violations.
“Vulnerability” refers to an exploitable security flaw or weakness.
“Cyber threat” refers to a potential danger that may lead to a violation.
“Critical infrastructure” and “critical public service” refer to areas where a breach may result in loss of life, large-scale economic damage, disruption of public order or severe consequences for national security.
Fundamental principles. The Law underscores that cybersecurity is an integral part of national security and identifies as a core objective the creation of a secure cyberspace by protecting critical infrastructures and information systems. Conducting cybersecurity efforts on the basis of institutionalisation, continuity and sustainability; applying measures throughout the lifecycle of products and services; and prioritising domestic and national products are identified as guiding principles shaping implementation.
This approach, by extending obligations not only to public authorities but also to natural and legal persons, establishes a holistic regime of obligations across prevention and impact-mitigation processes; it is grounded in accountability and aims to keep strategy and policy development activities up to date through a continuous-improvement approach.
The Cybersecurity Directorate: Duties and Scope of Authority
The Cybersecurity Directorate established under the Law is designated as the central authority for determining and implementing Türkiye’s cybersecurity policies. The Directorate conducts activities aimed at increasing the cyber resilience of critical infrastructures and information systems, detecting attacks, preventing potential attacks and mitigating their effects; in this context, it institutionalises risk management by conducting or commissioning vulnerability and penetration tests and risk analyses relating to assets. The Directorate also strengthens operational capacity through its functions of obtaining, producing and sharing threat intelligence, conducting malware analysis activities and combating cyber threats.
The Directorate may identify critical infrastructures and make determinations regarding the relevant institutions and locations; it ensures that asset inventories of public institutions and critical infrastructures are maintained and that security measures are implemented in accordance with the criticality of assets, and it can manage the processes for establishing, causing the establishment of, and supervising Cyber Incident Response Teams. Within this framework, the Directorate’s remit also includes conducting exercises to assess response capabilities, coordinating with incident response teams of other countries, and encouraging the development of national cyber response tools.
In addition, the Directorate may lay down the procedures and principles to be complied with in the field of cybersecurity, assume the function of preparing standards and monitoring their implementation, and carry out certification and authorisation processes — coordinated with the relevant institutions — by establishing and operating testing and certification infrastructures for software, hardware, products, systems and services. As regards the practical implementation of these processes, secondary legislation will be determinative.
Standard-setting, certification, audit and incident response are brought together under a single coordination hub.
The Cybersecurity Board: A Strategic-Level Coordination Mechanism
With the Law, the Cybersecurity Board has been established as the highest-level decision-making mechanism, with the aim of determining cybersecurity-related policies and ensuring coordination.
Pursuant to Article 9 of the Law, the Board consists of the President of the Republic of Türkiye, the Vice President, the Minister of Justice, the Minister of Foreign Affairs, the Minister of Interior, the Minister of National Defence, the Minister of Industry and Technology, the Minister of Transport and Infrastructure, the Secretary General of the National Security Council, the Head of the National Intelligence Organisation, the President of Defence Industries and the Head of the Cybersecurity Directorate.
Where the President is unable to attend, the Vice President chairs the Board. Depending on the nature of the agenda, relevant ministers and individuals may be invited to Board meetings; where deemed necessary, the Board may establish commissions and working groups, and experts in the relevant field may be invited to participate in those groups.
The Board’s remit covers: setting policy and strategy; deciding on the nationwide implementation of the technology roadmap prepared by the Directorate; taking decisions on priority areas to be incentivised and on the development of human resources; determining critical infrastructure sectors; and acting as the decision-making authority in disputes that may arise between the Directorate and public institutions.
Cybersecurity Companies: Overseas Sales, Mergers and Transfers, and the Control Regime
The Law subjects transactions involving companies operating in the field of cybersecurity — such as mergers, demergers, share transfers or other transactions resulting in a change of control — to an approval and notification regime under the Directorate’s supervision. Transactions carried out without obtaining the Directorate’s approval do not acquire legal validity. In addition, the overseas sale of cybersecurity products, systems, software, hardware and services is made subject to procedures and principles to be determined by the Directorate; for products subject to authorisation, the Directorate’s approval is required.
These provisions serve the objectives of monitoring corporate transactions within the cybersecurity ecosystem from a national security perspective, keeping changes of control over critical technologies under administrative oversight, and ensuring supply chain security.
Critical infrastructure sectors are determined by the Board and mapped by the Directorate.
Obligations, Audit and the Critical Infrastructure Regime
Obligations. The Law imposes a range of cybersecurity obligations on persons and entities that provide services by means of information systems and collect and process data. Accordingly, the actors within the scope of the Law are responsible for:
Timely submitting to the Directorate the elements it requests, such as data, information, documents, hardware and software
Taking the measures prescribed by legislation
Reporting, without delay, any vulnerabilities or cyber incidents they detect
Procuring cybersecurity products and services to be used in public institutions and critical infrastructures from authorised and certified persons and entities
Implementing the necessary measures in line with the policies, strategies and action plans published by the Directorate
In addition, for companies carrying out activities subject to certification or authorisation, the Law provides for a mechanism requiring the Directorate’s approval before commencing operations.
Audit. From an audit perspective, the Directorate may audit acts and transactions falling within the scope of the Law where it deems necessary, and may conduct on-site inspections or have them conducted. Audit powers may be exercised not only by the Directorate’s personnel but also through authorised and certified independent auditors and independent audit firms. Those subject to audit are obliged to keep their devices, systems, software and hardware open to inspection, to provide the necessary infrastructure for the audit, and to take the measures required to keep that infrastructure operational.
Search, copying and seizure. For the purposes of national security, public order and preventing the commission of crimes or cyberattacks, the Law sets out the procedure under which searches, copying and seizure may be carried out in closed premises upon a judge’s decision; in cases where delay would be prejudicial, such measures may be taken pursuant to a written order of the public prosecutor. For these measures to be carried out in the data centres of authorised data centre operators, a judge’s decision is required.
Critical infrastructure regime. The Law defines as critical infrastructure those infrastructures hosting information systems where a breach of information or data security may lead to severe consequences such as loss of life, large-scale economic damage, security vulnerabilities or disruption of public order. It assigns to the Board the task of determining critical infrastructure sectors, and to the Directorate the tasks of identifying the institutions and locations of critical infrastructures, maintaining the asset inventory, and determining and ensuring the implementation of security measures based on criticality. Under existing practice, electronic communications, energy, water management, finance, transport and various public services are considered within the scope of critical infrastructure areas; within the Board’s power of determination, it is possible for these areas to be expanded.
Breaches and Sanctions: Criminal Provisions and Administrative Fines
The sanctions envisaged under the Law aim to ensure the effective fulfilment of obligations and establish a detailed framework covering both criminal sanctions and administrative fines. Under the Law, imprisonment and/or judicial fines are prescribed for: those who fail to provide, or who obstruct access to, information, documents, software, data or hardware requested by the competent authorities or audit officials; those who carry out activities without obtaining the required approvals, authorisations or permits; those who breach confidentiality obligations; those who unlawfully make accessible, disseminate or offer for sale data of a personal nature or data falling within the scope of critical public services; those who aim to create fear or panic in the public through false data-breach content; and those who commit cyberattacks against elements constituting Türkiye’s national power in cyberspace. Notable penalties in this context include:
Failure to provide, or obstruction of access to, information, documents, software, data or hardware requested by competent authorities or audit officials: one to three years’ imprisonment and a judicial fine of 500 to 1,500 day-units
Carrying out activities without the required approvals, authorisations or permits: two to four years’ imprisonment and a judicial fine of 1,000 to 2,000 day-units
Breach of confidentiality obligations: four to eight years’ imprisonment
Unlawfully making accessible, disseminating or selling personal data or data falling within the scope of critical public services: three to five years’ imprisonment
Aiming to create fear or panic through false data-leak content: two to five years’ imprisonment
Carrying out attacks against Türkiye’s national power in cyberspace, or keeping the obtained data in cyberspace: eight to twelve years’ imprisonment; disseminating, transmitting or selling such data: ten to fifteen years’ imprisonment
Violations of Article 12: three to five years’ imprisonment
Causing a data breach through abuse of duty or failure to take necessary measures: one to three years’ imprisonment
With respect to administrative fines, the Law provides for substantial administrative sanctions particularly in cases such as breaches of notification obligations, failure to comply with the requirement to procure certified and authorised products and services, non-compliance with procedural requirements for transactions subject to the Directorate’s approval or conformity assessment, failure to respond to requests for information, and failure to fulfil the obligation to cooperate during audits. In addition, the sanctions regime is complemented by procedural safeguards through provisions regulating the procedure for obtaining a defence statement, the possibility of escalation in the event of repeated misdemeanours, benefit- and loss-based increases, collection procedures, and recourse to administrative judicial review.
Conclusion and Assessment
The Law marks a clear shift towards eliminating institutional fragmentation in cybersecurity governance and consolidating authority under a central body. It is envisaged that cybersecurity activities previously carried out in a dispersed manner across different institutions will be brought together around the Directorate, and that the lack of coordination will be reduced through the implementation of a transition mechanism concerning the transfer of relevant assets and infrastructures. In this context, cybersecurity should no longer be regarded solely as a technical responsibility of IT units; rather, it should be assessed as a strategic governance domain that must be addressed at board level and is directly linked to corporate risk management, compliance and sustainability processes.
At the same time, the Law institutionalises the highest-level political and administrative coordination through the Board mechanism, so as to address cybersecurity at a strategic level; and it aims to strengthen uniform implementation across the public–private ecosystem and enhance rapid decision-making capacity by bringing standard-setting, certification, auditing and incident response functions together under a single coordination hub.
One of the Law’s most notable features is that it abandons a recommendation-based approach and establishes a sanctions regime with a high deterrent effect. In this framework, the explicit codification of notification and cooperation duties as binding obligations, the establishment and supervision of Cyber Incident Response Teams, and the combined regulation of administrative and criminal sanctions bring cyber risk management to the centre of the senior management agenda for companies.
Nevertheless, for the regulation to be effectively implemented in all its aspects, it will be decisive that the implementing regulations and secondary legislation are brought into force within the prescribed timeframes, so as to clarify the practical application of standardisation, certification and audit processes.
Our Recommendations
The Law introduces numerous obligations that directly address not only public institutions and organisations but also private-sector actors. In this context, in order for companies to avoid exposure to administrative and criminal sanctions and to establish an adequate level of compliance with cybersecurity legislation, it is important to create an institutional archiving and reporting infrastructure that enables information and documents to be duly retained and classified and, upon request, produced without delay; to measure the level of technical security by conducting vulnerability scans and penetration tests at regular intervals; and to minimise human-resource-related risks through periodic training programmes aimed at increasing employees’ cybersecurity awareness.
Likewise, keeping the asset inventory up to date and structuring risk analysis as an ongoing process, operationalising vulnerability and cyber-incident notification mechanisms, and ensuring compliance with certification and authorisation requirements for procured cybersecurity products and services will directly contribute to meeting the standards of the obligations set out under the Law.
In particular, for companies operating within the scope of critical infrastructure or critical public services, the following are decisive for mitigating the risk of sanctions arising from non-compliance: establishing a written procurement and supply policy and contractual framework that takes into account supply chain security and the prioritisation of domestic and national products; putting in place a documentation, record-keeping and traceability framework so as to be prepared for notification and audit processes; incorporating certification and authorisation requirements into supplier contracts through clear and binding provisions; and ultimately transforming all of these elements — under senior management oversight — into a sustainable cyber compliance programme.
Reach our team for your intellectual property portfolio, corporate needs or an ongoing dispute. We respond to every enquiry with a clear assessment of scope, timing and next steps — and we build specialized teams around each matter from day one.
Istanbul Office
Let's talk.
Our offices are located in the Ferko Signature building on Büyükdere Caddesi, at the heart of Istanbul's business district. Whether you are protecting a single trademark or restructuring an international portfolio, the first conversation is always with the team that will actually handle your matter.
For trademark and patent attorneyship services, our dedicated prosecution practice also operates through devinpatent.com — covering filings, renewals, oppositions and portfolio administration before TÜRKPATENT, EUIPO and WIPO.
On Büyükdere Caddesi — the spine of Istanbul's central business district — Ferko Signature places the firm minutes from the courts, TÜRKPATENT liaison offices and the headquarters of the companies we serve.
Transform Traditional Law with a Modern Vision — building your career at Devin Law & IP means leading through complex legal challenges and shaping the future of the industry.
Why Devin
Lead through complex legal challenges. Shape the future of the industry.
We invite you to be part of our innovative vision, create impact with strategic solutions, and elevate your professional journey to the highest level. Join us to demonstrate your legal expertise within a modern and dynamic platform.
At Devin Law & IP, junior colleagues work directly with partners on live matters from their first week — trademark oppositions, litigation strategy, KVKK compliance projects and international portfolio work. Mentoring is structured, feedback is continuous, and responsibility grows with demonstrated ability rather than seniority alone.
To apply, send your CV and a short note describing your interest in working with our firm to info@devinlaw.com.tr. Applications are reviewed on a rolling basis and every candidate receives a response.
Lawyers
Attorneys with litigation or IP prosecution experience who want to work on high-stakes, cross-border matters within specialized practice groups.
Internships
Legal internships for law students and graduates — hands-on exposure to trademark procedures, litigation and data protection projects alongside experienced mentors.
Business Services
Finance, administration and operations roles that keep a modern law firm running with precision.
Independent international directories consistently rank our team among the leading practitioners in intellectual property and media law in Türkiye. Our intellectual property and media practice has been recognised by The Legal 500 EMEA, the WTR 1000, Managing IP's IP STARS and Media Law International in both the 2026 and 2025 editions. Click any ranking below for the full details.
2026Current Edition
The rankings published for the current cycle — across intellectual property and media law.
Five Categories · 2026IP STARS — Managing IP
In the IP STARS 2026 rankings published by Managing IP, Devin Law & IP is ranked in five practice categories in Türkiye — with Uğurcan Tekin and İnci Özçilsal recognised among Türkiye's leading IP practitioners as Rising Stars, supported by eleven client testimonials on prosecution, enforcement and opposition work.
All Details →
Recommended · 2026WTR 1000
In the 2026 edition, World Trademark Review's WTR 1000 recognises Uğurcan Tekin individually for trademark protection and international IP strategies — identifying the world's leading trademark professionals through extensive research among clients and peers, including his work on global strategies for multinational corporations and proceedings before WIPO.
All Details →
Ranked · EMEA 2026The Legal 500 EMEA
Ranked in the Legal 500 EMEA 2026 edition in Intellectual Property and Media & Entertainment. Uğurcan Tekin is listed as a Next Generation Partner, with İnci Özçilsal and Beyza Erdemir recognised as Key Lawyers — supported by directory commentary and client testimonials on the team's patent, advertising and brand protection work.
All Details →
Tier 2 · 2026Media Law International
In its 2026 rankings, Media Law International places Devin Law & IP at Tier 2 of the Türkiye country chapter among the leading law firms for media law, with Uğurcan Tekin named among the Top 10 Recommended Media Lawyers in Turkey — reflecting expertise in digital media regulation, content management and broadcasting standards.
All Details →
2025Previous Edition
Recognitions earned in the preceding ranking cycle by the same intellectual property and media practice.
Ranked · EMEA 2025The Legal 500 EMEA
Ranked in the Legal 500 EMEA 2025 edition in Intellectual Property and Media & Entertainment, with Uğurcan Tekin as practice head. The editorial assessment highlighted advisory work for the full spectrum of media stakeholders — from multinational media companies to individual actors, directors and agents — and the team's depth in digital media, online content and data privacy.
All Details →
Ranked · 2025Media Law International
In its 2025 assessments, Media Law International recognised the practice as one of Türkiye's leading media law firms, with Uğurcan Tekin selected among the ten recommended media law practitioners in Türkiye.
All Details →
Recommended Firm · 2025IP STARS — Managing IP
In the IP STARS rankings published in 2025 by Managing IP, the practice was listed among the recommended firms in Türkiye — international recognition of the breadth of experience and strategic approach the team brings to intellectual property work.
All Details →
Recommended Firm · 2025WTR 1000
In the 2025 edition, World Trademark Review's WTR 1000 listed the practice among the recommended trademark firms in the Türkiye ranking — reflecting the team's work on filing strategy, portfolio management and contentious trademark matters for domestic and international clients.