Strategic Legal Solutions For A Global Business World
Strategic Legal Services Tailored for Modern Business — advisory and dispute resolution across intellectual property, media, technology, corporate and regulatory law, delivered by dedicated practice groups from Istanbul for clients around the world.
A Proven Legal Blueprint to Secure What You've Built.
Devin Law & IP is a boutique law firm with over 15 years of combined experience from its founders and partners. The firm operates on principles of transparency, integrity, and shared values, and delivers sustainable legal solutions through dedicated practice groups.
We serve diverse international clients by forming specialized teams with sector expertise. Long-term client relationships, diversity, continuous education and professional development are our core institutional values.
Founded on professionalism, transparency and long-term value creation, the firm combines sector expertise with strategic legal insight — providing clear, practical and result-oriented solutions for businesses and individuals.
Alongside its Istanbul headquarters, the firm manages trademark and patent portfolios across multiple jurisdictions through its attorneyship practice — handling filings, oppositions, renewals and enforcement before TÜRKPATENT, EUIPO and WIPO on behalf of local and international rights holders.
This dual structure — Legal Services on one side and Trademark / Patent Attorneyship Services on the other — allows the firm to combine contentious litigation strength with disciplined portfolio administration, so that every matter is handled by a team specialised in its own field.
02
Why Choose Us
Legal Expertise
Professionals with extensive knowledge across industries provide strategic advice and actionable insights. Every matter is staffed by a team with genuine sector experience, so our advice reflects commercial reality rather than abstract theory.
Client-Focused Approach
Personalized solutions tailored to specific client goals through collaborative engagement. We invest time in understanding each client's business model, risk appetite and priorities before shaping the legal strategy around them.
Innovative Legal Solutions
Leveraging modern legal technologies to develop creative, sustainable approaches. From portfolio automation to structured watch services, we use technology to deliver faster and more consistent outcomes.
Commitment to Sustainability
Supporting clients in adopting ethical practices that benefit both business and society. We help build compliance cultures that are durable, defensible and aligned with evolving international standards.
Strategic Perspective
Aligning legal solutions with business objectives for sustainable growth. Advice is always framed as a business decision — with clear options, realistic costs and measurable consequences.
03
Legal Services Tailored to Your Business
01
Industrial Property Law
Trademarks, patents & utility models and industrial designs — consultancy, prosecution and litigation before TÜRKPATENT, EUIPO and WIPO.
Explore →
02
Intellectual Property & Copyright Law
Copyright, software and related rights under FSEK No. 5846 — from ownership architecture and registration through to piracy enforcement.
Explore →
03
Media, Entertainment & Advertisement
Where creative expression meets complex regulation — advertising review, broadcasting compliance, production and talent agreements.
Explore →
04
Data Protection, Privacy & Cybersecurity
Defensible governance under KVKK and the GDPR — data mapping, cross-border transfers, breach response and defence before the Authority.
Explore →
05
IT & Technology Law
Software, SaaS and cloud contracts, gaming and e-sports, startup financing rounds, e-commerce and fintech regulation, and the legal architecture around artificial intelligence.
Explore →
06
Corporate Law & Commercial Advisory
Retainer counsel across every department, commercial contracts, general assemblies, board resolutions, capital structures and shareholder disputes.
Explore →
07
Dispute Resolution & Litigation
Commercial and contractual litigation, debt recovery and enforcement, labour defence, white-collar crime, shareholder disputes, lease actions, mediation and arbitration.
Explore →
08
Maritime, Yachting & Shipyard Law
Superyacht newbuilds and refits, shipyard operations, yacht design and IP, sale and purchase, flagging, chartering and crew, vessel arrests and marine casualties.
Explore →
"From the first spark of creativity to the global protection of your brand."
Advertising Board Decisions — Meeting No. 370: Transitional Period in Health Promotion Legislation, Use of Trademarks and Logos, Denigrating Advertising
5 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 371: Disparaging Advertising, Consistency Between the Principal Claim and Its Exceptions, and the Boundary Between News and Advertising
5 September 2026 — Read →
Data Protection
Turkish Data Protection Board Decisions — August 2026: Principle Decisions, Data Processing for Marketing Purposes and Workplace Surveillance
5 September 2026 — Read →
Data Protection
Lawyers' Data Protection Obligations and Breaches at Data Processors
28 September 2026 — Read →
Competition
Competition Law Developments in Türkiye: September 2026
28 September 2026 — Read →
Maritime & IP
Collision in the Sea of Marmara: Civil and Criminal Liability in Maritime Casualties
15 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 366: Platform Liability, Trademark Use and Price Transparency
5 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 367: Right of Withdrawal, Comparative Claims and Health Connotations in Product Names
5 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 368: Sanctions for Repeated Infringements, Interface Design and Superiority Claims
Advertising Board Decisions — Meeting No. 370: Transitional Period in Health Promotion Legislation, Use of Trademarks and Logos, Denigrating Advertising
5 September 2026 — Read →
Media & Advertising
Advertising Board Decisions — Meeting No. 371: Disparaging Advertising, Consistency Between the Principal Claim and Its Exceptions, and the Boundary Between News and Advertising
5 September 2026 — Read →
Data Protection
Turkish Data Protection Board Decisions — August 2026: Principle Decisions, Data Processing for Marketing Purposes and Workplace Surveillance
5 September 2026 — Read →
Devin Law & IP · Practice Areas
Our Services
Comprehensive legal services combining sector expertise with strategic legal insight: clear, practical and result-oriented solutions for businesses and individuals. Eight dedicated practice groups cover intellectual property, media and advertising, data protection, technology, corporate matters, dispute resolution and maritime law, for multinational groups and early-stage ventures alike.
Comprehensive legal services combining sector expertise with strategic legal insight: clear, practical and result-oriented solutions for businesses and individuals. Eight dedicated practice groups cover intellectual property, media and advertising, data protection, technology, corporate matters, dispute resolution and maritime law, for multinational groups and early-stage ventures alike.
8 practice groups — move across the panels below to preview, click to open.
01Industrial Property Law
01
Industrial Property Law
Trademarks, patents & utility models and industrial designs, consultancy, prosecution and litigation before TÜRKPATENT, EUIPO and WIPO.
Explore →
02Intellectual Property & Copyright Law
02
Intellectual Property & Copyright Law
Copyright, software and related rights under FSEK No. 5846, from ownership architecture and registration through to piracy enforcement.
Explore →
03Media, Entertainment & Advertisement Law
03
Media, Entertainment & Advertisement Law
Where creative expression meets complex regulation, advertising review, broadcasting compliance, production and talent agreements.
Explore →
04Data Protection, Privacy & Cybersecurity
04
Data Protection, Privacy & Cybersecurity
Defensible governance under KVKK and the GDPR, data mapping, cross-border transfers, breach response and defence before the Authority.
Explore →
05IT & Technology Law
05
IT & Technology Law
Software, SaaS and cloud contracts, gaming and e-sports, startup financing rounds, e-commerce and fintech regulation, and the legal architecture around artificial intelligence.
Explore →
06Corporate Law & Commercial Advisory
06
Corporate Law & Commercial Advisory
Long-term external counsel for modern businesses, contracts, corporate governance and continuous regulatory compliance.
Explore →
07Dispute Resolution & Litigation
07
Dispute Resolution & Litigation
Strategic case planning and disciplined procedural management across commercial, administrative and enforcement proceedings.
Explore →
08Maritime, Yachting & Shipyard Law
08
Maritime, Yachting & Shipyard Law
Vessel finance, charter parties, cargo claims and marine insurance disputes, advisory across the full lifecycle of maritime operations.
Explore →
8 practice groups · hover to preview, click to openLegal Services · Trademark / Patent Attorneyship Services
Devin Law & IP
Our Team
Specialized legal teams handle each matter within their specific field of expertise. Partners, attorneys, specialists and trainees work together across practice groups — combining decades of courtroom experience with modern portfolio management.
Partners & Counsel
Uğurcan Tekin, LL.MPartner / Attorney at Law — Trademark Attorney
Intellectual & Industrial Property, Media Law, IT and Data Protection (KVKK). Legal 500 EMEA 2026 — Next Generation Partner; ranked individually in the WTR 1000 2026, and by IP STARS and Media Law International in both the 2026 and 2025 editions — representing multimedia companies and global brands in high-stakes IP and media litigation.
Profile →
Alican Tekin, LL.MPartner — Trademark Attorney
Co-Head of the IP Department — international trademark portfolio management and cross-border projects. Registered trademark attorney advising local and international clients on trademarks, designs and copyright.
Profile →
Kadir Karasu, MBAPartner
Intellectual Property, Mergers & Acquisitions and Project Finance. Senior-level advisory on complex, multi-jurisdictional matters, large-scale IP portfolios and advanced financing structures.
Profile →
Tevrat TekinCounsel / Attorney at Law
More than forty years of litigation experience — labour law, lease & tenancy, enforcement & bankruptcy and contractual claims before all levels of the Turkish courts.
Profile →
Attorneys & Specialists
İnci ÖzçilsalAttorney at Law
Corporate law, contracts, KVKK/GDPR compliance and intellectual property. Legal 500 EMEA 2026 — Key Lawyer; IP STARS 2026 — Rising Star; active in compliance projects, data inventories and trademark prosecution.
Profile →
Beyza ErdemirAttorney at Law
IP portfolio management, licensing, designs & patents; KVKK compliance and media law. Legal 500 EMEA 2026 — Key Lawyer. Advises national and international clients and takes an active role in enforcement strategy.
Profile →
Şevval Ezgi DemirAttorney at Law
Maritime & shipping law — vessel finance, charter parties, cargo claims and P&I / H&M insurance disputes. Also advises on company formation and commercial agreements across Turkish and foreign legal systems.
Profile →
Mehmet Kerem KüçükTrademark & Patent Specialist
Electrical & electronics engineering background — patent drafting, monitoring and evaluation. Combines technical knowledge with legal process across trademark and patent procedures.
Profile →
Berkay KizenFinance Specialist
Budget planning, financial analysis and reporting across the firm's operations — bringing an analytical, process-oriented discipline to financial management.
Profile →
Legal Trainees
Aleyna KalburcuLegal Trainee
Trademark procedures, KVKK compliance support and general litigation. Studies law on a full scholarship at Istanbul Commerce University.
Profile →
Sıla UçarLegal Trainee
Trademark applications, opposition processes and data protection compliance projects. Istanbul University Faculty of Law graduate supporting registration, opposition and defence strategies.
Profile →
Devin Law & IP — Istanbul
About Us
From the first spark of creativity to the global protection of your brand — a boutique law firm built on transparency, integrity and shared values, combining Legal Services with Trademark / Patent Attorneyship Services under one roof.
Who We Are
A strong professional culture grounded in transparency, integrity and shared values.
With more than 15 years of combined experience from its founders and solution partners, Devin Law & IP has built a strong professional culture grounded in transparency, integrity, and shared values. The firm concentrates on delivering sustainable legal solutions, forming teams with deep sector-specific expertise, and supporting clients across jurisdictions through a global perspective.
We serve a diverse client base from around the world, operating through dedicated practice groups led by experienced lawyers specializing in distinct areas of law. This structure enables a tailored, strategic approach to complex legal matters while ensuring efficiency and consistency in service delivery.
A strong emphasis is placed on long-term client relationships, supported by a highly qualified and collaborative team. In addition to legal excellence, the firm prioritizes diversity, continuous education and professional awareness — viewing these principles as essential to both institutional growth and responsible legal practice.
By combining experience, specialization and a client-focused mindset, Devin Law & IP positions itself as a trusted legal partner for businesses and individuals navigating today's evolving legal landscape. Alongside its Istanbul headquarters, the firm manages trademark and patent portfolios across multiple jurisdictions through its attorneyship practice — handling filings, oppositions, renewals and enforcement before TÜRKPATENT, EUIPO and WIPO.
Values
Why Choose Us
Legal Expertise
Our team brings a wealth of knowledge and experience across various industries, enabling strategic legal advice and actionable insights that help clients thrive in a competitive landscape.
Client-Focused Approach
We prioritize the unique legal needs and objectives of our clients, delivering personalized solutions tailored to their specific goals and challenges.
Innovative Legal Solutions
We embrace innovation and leverage modern legal technologies to develop creative solutions — staying ahead of industry trends so clients can seize new opportunities and overcome challenges.
Commitment to Sustainability
We are dedicated to helping clients adopt sustainable legal practices that benefit both their businesses and the world around them.
Strategic Perspective
We approach legal matters with a strategic mindset, aligning legal solutions with business objectives to support sustainable growth and informed decision-making.
"Smart approaches to legal solutions with exceptional service."
Articles and commentary from our team on intellectual property, media, data protection and regulatory developments — practical analysis of the decisions, legislation and market practice shaping Turkish and international law.
54 articles · 14 shown
202654 articles
Data Protection
Lawyers' Data Protection Obligations and Breaches at Data Processors
This note examines the Implementation Guide on the Protection of Personal Data in the Professional Activities of Lawyers, published by the Personal Data Protection Authority on 22 September 2026, the processor-originated breach notifications announced by the Board's decisions of 16 and 23 September 2026, and three ransomware decisions of 2024 appearing among the published decision summaries. The guide and decisions examined concern the determination of controller and processor status for each activity, the documentation of the source of data, the processing and transfer of documents uploaded to generative AI tools, and the allocation of liability for breaches at a data processor.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir28 September 2026
Competition
Competition Law Developments in Türkiye: September 2026
This note examines the developments announced on the Turkish Competition Authority's website in September 2026: the labour market investigation opened in the automotive supply industry by the Board's decision No. 26-29/831-M of 13 August 2026, the oral hearing announcements in the maritime pilotage and towage file and the MDF and particleboard file, the workshop held on 21 September 2026 as part of the pharmaceutical sector inquiry, the merger and acquisition decisions taken at the meeting of 20 August 2026, and the reappointments to the Competition Board. The developments are assessed in the light of the Guidelines on Competition Infringements in Labour Markets and the relevant statutory provisions.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir28 September 2026
Maritime & IP
Collision in the Sea of Marmara: Civil and Criminal Liability in Maritime Casualties
Taking the ship casualty off Silivri as its point of departure, this article examines the provisions governing collision, the scope of liability in damages, the operation of the criminal investigation, the administrative casualty investigation and the steps that must be taken in the first days following a casualty.
Şevval Ezgi Demir15 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 366: Platform Liability, Trademark Use and Price Transparency
A sectoral and thematic review of the decisions published in respect of the Advertising Board's meeting of 12 February 2026 and numbered 366, covering platform liability, price transparency, health and education promotions, and access-blocking decisions against illegal betting advertisements. The note assesses the compliance risks arising from the Board's administrative fines and suspension penalties.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 367: Right of Withdrawal, Comparative Claims and Health Connotations in Product Names
A sector-by-sector review of the decisions published in respect of the Advertising Board's meeting of 12 March 2026: e-commerce membership terminations tied to the right of withdrawal, comparative claims by crypto-asset platforms, and a three-month precautionary suspension for advertising continued despite prior sanctions. Compliance risks and administrative fines across the communications, finance, food, cosmetics and tourism sectors are assessed from a legal standpoint.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 368: Sanctions for Repeated Infringements, Interface Design and Superiority Claims
The decisions published in respect of the Advertising Board's meeting of 9 April 2026 and numbered 368 signal escalating sanctions: an advertiser that maintained its claims despite earlier penalties received an administrative fine of TRY 39,916,524. This note assesses the compliance risks arising for the communications, e-commerce, cosmetics, healthcare, finance and tourism sectors, from pre-selected payment options to indirect superiority claims.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
At its meeting of 14 May 2026 (No. 369), the Advertising Board imposed administrative fines exceeding TRY 7 million in total on three operators for 5G advertisements published before commercial launch, ruled on the merits in the 'Bank of the Mosts' campaign, and treated pre-selected paid services in online sales as an unfair commercial practice. This note assesses the sanctions across the communications, e-commerce, food, alcoholic beverage and health sectors from a compliance-risk perspective.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 370: Transitional Period in Health Promotion Legislation, Use of Trademarks and Logos, Denigrating Advertising
The Advertising Board's meeting of 11 June 2026, numbered 370, addressed the transitional application of the health promotion rules, e-commerce and retail campaign practices, denigrating advertisements and precautionary measures against visa intermediary services. With administrative fines reaching TRY 1,083,706, the decisions underline the need for a sector-by-sector review of advertising compliance.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Media & Advertising
Advertising Board Decisions — Meeting No. 371: Disparaging Advertising, Consistency Between the Principal Claim and Its Exceptions, and the Boundary Between News and Advertising
At its meeting of 16 July 2026 (No. 371), the Advertising Board imposed a fine exceeding TRY 3.1 million on an operator's advertisement film found to disparage competitors through humour, scrutinised the consistency between spoken claims and subtitle exceptions, and continued to sanction the promotion of attorney-only services under the name of consultancy. This note assesses the decisions sector by sector, with a focus on compliance risks and sanctioning practice.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Data Protection
Turkish Data Protection Board Decisions — August 2026: Principle Decisions, Data Processing for Marketing Purposes and Workplace Surveillance
A thematic review of the Turkish Personal Data Protection Board's summer 2026 principle decisions and the decision summaries published on 10 August 2026, with a focus on compliance risk: the ban on biometric time tracking, administrative fines for marketing-related data processing, workplace camera surveillance, and data controllers' obligations in handling data subject applications.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
Competition
Turkish Competition Board Decisions — June–August 2026: Conditional Clearances, the Commitment Procedure and New Investigations
An analysis of the Turkish Competition Board's decisions announced between June and August 2026: conditional clearances in the A101–CarrefourSA, Paramount–Warner Bros. Discovery and Cargill–PNS acquisitions, investigations concluded through the commitment and settlement procedures, and cartel fines exceeding TRY 3.6 billion in the automotive tyre sector. The note offers practice-oriented observations on merger notifications, the design of commitment packages and the management of investigation risk.
Uğurcan Tekin · İnci Özçilsal · Beyza Erdemir5 September 2026
IP Litigation
Trademark Invalidity Actions in Türkiye: Grounds, Acquiescence and the Difference from Administrative Revocation
A registered trademark is not always safe. A defect that existed at the moment of registration can lead to the mark being declared invalid by court judgment. The invalidity action is the vehicle for raising that defect. The Industrial Property Code No. 6769 governs the grounds of invalidity, the persons entitled to sue, and the loss of rights through acquiescence. This article examines the invalidity regime and how it differs from the administrative revocation route.
Uğurcan Tekin · İnci Özçilsal28 August 2026
Trademark
Proof of Use in Turkish Trademark Oppositions: The Five-Year Test
Under Article 19/2 of the Turkish Industrial Property Code, an opponent whose trademark has been registered for more than five years must, upon the applicant's request, prove genuine use of that mark in Türkiye. Where proof fails, the opposition fails with it. This article examines how the proof-of-use mechanism works, what counts as genuine use, and how both sides should prepare for it.
Uğurcan Tekin · Alican Tekin28 August 2026
Trademark
Trademark Licence Agreements under Turkish Law: Exclusive and Non-Exclusive Licences Compared
A trademark licence is the principal tool for monetising a mark without parting with it. Yet licence relationships built without regard to the licensing provisions of the Industrial Property Code No. 6769 expose both licensor and licensee to serious risk. This article covers the types of licence, the written-form requirement, recordal with the registry and the licensee's standing to sue.
Uğurcan Tekin · Alican Tekin28 August 2026
Data Protection/Insights
Lawyers' Data Protection Obligations and Breaches at Data Processors
Avukatların KVKK Yükümlülükleri ve Veri İşleyen Kaynaklı İhlaller
This note examines the Implementation Guide on the Protection of Personal Data in the Professional Activities of Lawyers, published by the Personal Data Protection Authority on 22 September 2026, the processor-originated breach notifications announced by the Board's decisions of 16 and 23 September 2026, and three ransomware decisions of 2024 appearing among the published decision summaries. The guide and decisions examined concern the determination of controller and processor status for each activity, the documentation of the source of data, the processing and transfer of documents uploaded to generative AI tools, and the allocation of liability for breaches at a data processor.
Key takeaway · Kilit sonuç
The Guide treats the lawyer as a data controller as a rule, while the breach announcements and ransomware decisions examined show that a security vulnerability at a data processor does not relieve the controller of its notification obligation or of the risk of sanction.
The three sources of this note and their common outcomeFigure 1
Implementation GuidePDPA Publication No. 115 · 22 September 2026
Breach notificationsBoard announcements · 16 and 23 September 2026
Data security: joint responsibilityArticle 12(2) · determination of status · source of data · processor agreement · access logs · 72 hours
The principal development of the period is the 158-page Implementation Guide, prepared by the Authority with the opinions and contributions of the Union of Turkish Bar Associations and published as PDPA Publication No. 115. The Guide addresses the status under the PDPL of those involved in legal practice, from the individual lawyer to the law partnership and from the substituted colleague to trainee lawyers and office staff. Separate chapters examine the legal bases for obtaining and disclosing data, transfers abroad, the use of artificial intelligence tools, the obligations of the data controller and data security. The Guide refers to the decisions the Board has rendered to date concerning lawyers and supports its explanations with those decisions.
In the same period, the Board announced breach notifications that began with the exploitation of a vulnerability in a third-party software library on a data processor's server and affected numerous data controllers in the retail, apparel, cosmetics and electronics sectors. The decision summaries published by the Authority also include three decisions of 2024 in which, following a ransomware attack, the controller's contradictory statements and the technical measures it had failed to take formed the basis of an administrative fine.
01
The Status of Lawyers and Law Partnerships under the PDPLAvukatların ve Avukatlık Ortaklıklarının KVKK Kapsamındaki Sıfatı
The longest chapter of the Guide is devoted to whether a lawyer is a data controller or a data processor. Rather than giving a single answer, the Authority recalls that the concept of data controller is functional and that status must be examined “separately for each personal data processing activity”. The Guide states that the principal obligation under a legal services agreement is “to provide specific legal assistance”; the processing of personal data is an ancillary obligation necessary for performing it. A legal services agreement therefore does not become a “personal data processing agreement”, and a lawyer is not a data processor merely because the lawyer is bound by the client's instructions.
The Guide's explanationRehberdeki açıklama
A lawyer practising independently is, as a rule, the data controller for the data of clients and third parties; it is ultimately the lawyer who decides which data will be processed and for what purpose. Lawyers working together in the same office are, notwithstanding the shared office, separate natural-person data controllers for their own clients. In a law partnership, the status belongs to the partnership, which has legal personality; the lawyers within the partnership are not separately regarded as data controllers. The relationship between the substituting lawyer and the substituted lawyer is, as a rule, one of data controller and data processor. Employed lawyers, trainee lawyers and office staff remain within the data controller's organisation and hold neither data controller nor data processor status.
Independent Lawyers and Law PartnershipsBağımsız Avukat ve Avukatlık Ortaklığı
The Board's decision No. 2023/437 dated 22 March 2023 shows that the characterisation used in the contract is not decisive on its own. Although the agreement between the partnership and the company described the partnership as a “data processor”, the Board treated it as the data controller on the ground that “it is seen that the partnership manages the processing activities to be carried out on the personal data transferred to it by the company, and that, accordingly, within the framework of its legal practice, the law partnership has the authority to decide freely in respect of its personal data processing activities”. In two other decisions, however, the Board treated the lawyer or law partnership as a data processor. In decision No. 2021/115 dated 9 February 2021, a lawyer conducting enforcement proceedings on a bank's instructions was regarded as a data processor. In decision No. 2023/78 dated 19 January 2023, the same conclusion was reached for a law partnership that sent a single text message for debt collection and had no means of verifying the numbers. The Guide positions these decisions as exceptions confined to cases in which the lawyer “has been given clear, detailed and specific instructions to process personal data on behalf of the client” and has no control over the purposes and means.
Substitution, Employed Lawyers and Trainee LawyersTevkil, Bağlı Çalışan ve Stajyer Avukatlar
A substituted lawyer may process data only on the instructions of the colleague who granted the authority and solely for the stated purpose. In the Guide's example, a lawyer substituted for a hearing who uses immovable property information learned from the case file to offer the client representation in other matters exceeds the limits of the instruction and becomes a data controller for that activity. A similar distinction is drawn for the employed lawyer. Even where authorised by substitution, the employed lawyer is deemed to act within the organisation of the employing lawyer; where the employed lawyer takes on files under the mandatory defence counsel scheme, however, the Guide treats them as an independent data controller for those files. In view of this distinction, it is recommended that files taken on by employed lawyers through bar association assignment be kept separate from the office's data inventory.
ActorStatusBasis / limit
Independent lawyerData controller (as a rule)The lawyer ultimately decides purposes and means
Lawyers sharing an officeEach a separate natural-person data controllerFor their own clients
Law partnershipThe partnership (legal person) is the data controllerLawyers within the partnership are not separate controllers
Substituted lawyerData processor (as a rule)Becomes data controller if instructions are exceeded
Employed lawyer, trainee, office staffNeither data controller nor data processorWithin the data controller's organisation
Employed lawyer as mandatory defence counselIndependent data controller for those filesBar assignment; separate inventory recommended
Status under the pdpl: summary by actor
02
Obtaining and Disclosing Personal DataKişisel Verilerin Elde Edilmesi ve Açıklanması
The Guide also addresses how lawyers obtain third-party personal data, namely the sources from which, and the limits within which, data relating to persons other than the client may be collected. The Authority accepts the obligation of the institutions listed in the third paragraph of Article 2 of the Attorneyship Law to provide information and documents to lawyers as “a provision permitting transfer” within the meaning of Article 8 of the PDPL. Decisions of both the Council of State and the Board show, however, that this authority is not unlimited.
The Guide's explanationRehberdeki açıklama
The information and documents a lawyer “needs” do not, as stated in the decision of the First Chamber of the Council of State No. 2002/26 E., 2002/52 K., extend to “the will to demand something arbitrarily and without any reason whatsoever”; the concept coincides with the principle in Article 4 of the PDPL that processing be relevant, limited and proportionate to the purpose. Article 2 of the Attorneyship Law is a general provision and does not confer authority to access ex officio data protected by special legislation, such as criminal records. Using software that queries identity and contact information from data collected by unlawful means is, under Principle Decision No. 2019/308, contrary to Article 12 of the PDPL for lawyers as well.
Obtaining Data through UYAP and TAKPASUYAP ve TAKPAS Üzerinden Veri Elde Edilmesi
According to the Board's decisions No. 2021/511-512-513 dated 20 May 2021, a creditor's counsel who queries on UYAP, once the enforcement proceedings have become final, the files in which the debtor is in turn a creditor relies on the condition of processing being “expressly provided for by law”; the distribution office's provision of this information to the lawyer is lawful under Article 2 of the Attorneyship Law. The Guide also cites, as a legitimate example under the condition that “processing is necessary for the protection of a right”, obtaining from TAKPAS the immovable property information of the defendant former spouse in an action to remove child maintenance. On health data, the Guide contains a reminder: Article 10 of the Regulation on Personal Health Data, which required special authority in the power of attorney, was repealed by the amendment of 3 December 2025. In the Guide's malpractice example, the hospital is expected to hand over the discharge summary and surgical notes to the lawyer without requiring special authority.
Criminal Records and Unlawful Query SoftwareAdli Sicil Kaydı ve Hukuka Aykırı Sorgulama Yazılımları
In decision No. 2021/1111 dated 2 November 2021, the Board imposed an administrative fine on a lawyer, stating that Article 2 of the Attorneyship Law is a “general provision” as against the “special provision” in Article 7 of the Criminal Records Law and that it “does not confer on lawyers the authority to access ex officio the criminal record information of data subjects”. The Guide adds two further examples. In decision No. 2020/429 dated 28 May 2020, obtaining the telephone numbers of the data subject's relatives and colleagues “on the basis of probabilities and in a manner that cannot be conclusively proven” resulted in an administrative fine. In decision No. 2021/228 dated 11 March 2021, sending messages about enforcement proceedings to an unrelated company attracted the same sanction. By contrast, in decision No. 2022/655 dated 7 July 2022, no infringement was found, because membership of the dissolved company's board of directors was public in the Trade Registry Gazette and the lawyer had obtained the data “through lawful platforms operating in accordance with Turkish legislation”.
Publicly Available Sources and Data Made PublicKamuya Açık Kaynaklar ve Alenileştirme
According to the Guide, submitting as evidence in divorce proceedings photographs shared publicly on social networks is lawful under Article 5(2)(d) of the PDPL. Two limits are noted, however: making data public requires “the existence of the person's intention to make it public”, and the data may not be used for a purpose other than that for which it was made public. The same principle applies to information on authorised signatories taken from the Trade Registry Gazette or the company's website; such data may be used only for the conduct of the legal process, to the extent necessary and in a proportionate manner.
Disclosure of Debt Information to Third PartiesBorç Bilgisinin Üçüncü Kişilere Açıklanması
In decision No. 2019/166 dated 31 May 2019, the Board found the sending of the debtor's name, surname and service number to a line belonging to the complainant, understood to be the debtor's nephew or niece, contrary to Article 12(1)(a) of the PDPL. In decision No. 2021/111 dated 9 February 2021, sending a text message to a number known to belong to a relative was found contrary to the same provision; an administrative fine of TRY 50,000 was imposed in each file. The Guide also notes that not all disclosures to third parties are unlawful. Sending a garnishment notice under Article 89 of the Enforcement and Bankruptcy Law, or disclosing the principal debtor's data to the creditor in order to protect the rights of a client who is an ordinary surety, may rest on the condition of “the establishment, exercise or protection of a right”.
03
Transfers Abroad and Generative AI ToolsYurt Dışına Aktarım ve Üretken Yapay Zekâ Araçları
The Guide sets out the three-tier system in Article 9, as amended by Law No. 7499 (adequacy decision, appropriate safeguards, and cases of incidental transfer). It then considers the data transfer implications of uploading client documents to generative AI tools such as ChatGPT, Claude or Gemini.
The Guide's explanationRehberdeki açıklama
Uploading a document containing personal data to an AI tool “should not be regarded merely as obtaining technical support or conducting legal research”. Having regard to the country in which the service provider is resident, the location of the servers and the location of sub-service providers, this operation may constitute a transfer abroad within the meaning of Article 9 of the PDPL. Even where the provider is located within Türkiye, the transfer of documents to it is a transfer within the scope of Article 8 of the PDPL.
Data Security Measures for Generative AI UseÜretken Yapay Zekâ Kullanımında Veri Güvenliği Tedbirleri
In its data security chapter, the Guide offers a concrete list of measures for AI tools. These include masking or anonymising personal data wherever possible, not uploading special categories of personal data to the system, and sharing only the minimum data required for the purpose. The Guide further recommends reading the data retention, model training, human review and sub-processor policies of the tool used, and laying down written rules of use within the office. In this chapter the Authority also refers to its earlier publications, such as the February 2026 publication on the Use of Generative AI Tools in the Workplace and the November 2025 Guide on Generative AI and the Protection of Personal Data.
04
Obligations of the Lawyer as Data ControllerVeri Sorumlusu Avukatın Yükümlülükleri
The Guide explains the scope of the exemption from registration. The exemption of lawyers from registration with the Data Controllers' Registry by the Board's decision No. 2018/32 dated 2 April 2018 has been understood in practice as meaning that “lawyers have no obligations under Law No. 6698”. The Authority emphasises that this understanding is incorrect and that the exemption is confined to registration with, and notification to, the Registry.
The Guide's explanationRehberdeki açıklama
Where data has not been obtained directly from the data subject, the privacy notice must be provided at the latest at the moment of first contact or first transfer, and applied in stages from receipt of the request for legal assistance through to the advisory process. Requests for erasure and destruction must be assessed together with the three-year document retention obligation under Article 39 of the Attorneyship Law and possible liability proceedings; where a request is refused, the basis and duration of the retention obligation must be set out clearly in writing to the data subject. Since most complaints reaching the Board centre on “wishing to know by what means their personal data was obtained by lawyers”, being able to document the source of the data both to the data subject and to the Board is important.
Data Subject Applications and Accessibilityİlgili Kişi Başvuruları ve Erişilebilirlik
In the Guide's example, when a person against whom enforcement proceedings have been initiated applies to the creditor's counsel, the lawyer is expected to explain whether the data was obtained “from the client, from the enforcement file, from public institutions or from publicly available sources”. The Guide also addresses keeping contact details current: offices with a website must keep the contact details on the site up to date, and lawyers without one must keep the details on the bar association roll up to date. Otherwise, the thirty-day period for responding may be missed because the application never reaches the lawyer.
Data Breach Notification and the Announcement PeriodVeri İhlali Bildirimi ve İlan Süresi
Using the example of a case file lost on the way back from the courthouse, the Guide explains that the lawyer must assess the affected persons and data categories and notify the Board within seventy-two hours under Board decision No. 2019/10. It also recalls that, by the Board's decision No. 2025/2451 dated 25 December 2025, breach announcements are limited to sixty days and are removed where it is documented that the data subjects were notified earlier. The Guide states the range of administrative fines applicable in 2026 for breach of the data security obligation as TRY 256,357 to TRY 17,092,242.
05
Breaches at Data Processors and Ransomware DecisionsVeri İşleyen Kaynaklı İhlaller ve Fidye Yazılımı Kararları
By its decision No. 2026/2039 dated 16 September 2026 and its decision No. 2026/2081 dated 23 September 2026, the Board announced on the Authority's website the breach notifications of a large number of data controllers affected by unauthorised access to the systems of a shared data processor. Most of the notifications contain the same wording: the breach occurred as a result of “unauthorised access to a server in the data processor's systems through the exploitation of a security vulnerability in a third-party software library in use”, and the data controllers learned of it on 10 September 2026 through the data processor's notification.
Where personal data is processed on behalf of the controller by a data processor, the controller and the processor are jointly responsible for taking the necessary security measures (Article 12(2) of the PDPL). The obligation to notify the breach to the Board and to the data subjects rests, under Article 12(5), with the data controller; in a breach originating from a shared processor, the affected controllers therefore each notify separately for their own data subjects. The administrative fine for breach of the data security obligation is, under Article 18, imposed on data controllers that are natural persons or private-law legal persons.
The Board's assessmentKurulun değerlendirmesi
In the ransomware decisions examined, the Board treated the controller's contradictory statements about the affected persons and data categories, its failure to submit to the Authority sample documents affected by the breach and its personal data processing inventory, the unavailability of log records and the absence of network segmentation as facts showing that the technical and organisational measures required by Article 12 of the PDPL had not been taken.
Mass Breach Notifications in Retail and E-CommercePerakende ve E-Ticaret Sektöründe Toplu İhlal Bildirimleri
The most extensive notification is that of Yeni Mağazacılık A.Ş., covering 6,263,305 persons among Eve Kozmetik customers. The notification states that, although Eve Mağazacılık had merged with Yeni Mağazacılık, the systems were kept separate and the breach covered only the name, surname, e-mail and telephone details of Eve Kozmetik customers. Shaya Mağazacılık A.Ş. reported that the name, surname, e-mail and address details of 2,298,726 employees and customers were affected. Samsonite Seyahat Ürünleri disclosed that, in addition to identity and contact details, “account authentication information (stored password values)” had been leaked. Desa Deri, Bilen Mağazaları, Locco Elektronik and numerous apparel, cosmetics and electronics retailers made notifications arising from the same source. In the authors' assessment, these notifications call for controllers that outsource their e-commerce infrastructure to examine how the security, audit and breach notification clauses of their data processor agreements are performed in practice.
Notifications by a Controller Established Abroad and a Professional AssociationYurt Dışında Yerleşik Veri Sorumlusu ve Meslek Kuruluşu Bildirimleri
Canva Pty Ltd reported that, following unauthorised access to a third-party tool, data associated with 424 organisations in Türkiye had been affected; the affected data comprised the business e-mail addresses and telephone numbers of customer employees together with contracts, invoices and data protection agreements. The Board resolved to announce the notification by its decision No. 2026/2037 dated 16 September 2026. The notification of the Association of Tax Inspectors, announced by decision No. 2026/2082 dated 23 September 2026, states that the Turkish identity numbers, dates of birth, passwords and contact details of up to 9,462 members were affected following unauthorised access to data processor systems. In membership structures where the identity number and the password are held in the same system, a security vulnerability at the processor concerns an area for which the controller is jointly responsible under Article 12(2) of the PDPL. In the authors' assessment, the controller's oversight of the processor's security measures carries particular weight in such structures.
Contradictory Statements and Measures Not Taken in Ransomware AttacksFidye Yazılımı Saldırılarında Çelişkili Beyanlar ve Alınmayan Tedbirler
The ransomware decisions examined in this note date from 2024 and appear among the decision summaries published by the Authority. In the incident that was the subject of the Board's decision No. 2024/2196 dated 26 December 2024, the systems of a company manufacturing plastic household goods were encrypted by ransomware. In its initial notification the company stated that employee and customer data had been affected; in subsequent letters it declared that no personal data had been affected; and in its criminal complaint it admitted that the data had been seized by the attackers. Considering these three statements together, the Board identified the contradiction. Recalling that “where data belonging to a legal person identifies or renders identifiable any natural person, such data is likewise protected under the Law”, the Board stated that the claim that invoice details were not personal data could not be accepted without sample documents being submitted. The penetration of the system despite a vulnerability test producing no findings was attributed to the inadequacy of the test; the enabling of two-factor authentication only after the breach, and the fact that nine companies were affected at once, were attributed to the absence of network segmentation. The Board resolved to impose an administrative fine of TRY 250,000 on the data controller.
Publicly Accessible Folders and Remote Desktop ServicesHerkese Açık Klasörler ve Uzak Masaüstü Servisleri
In decision No. 2024/1899 dated 7 November 2024, the marketing user account of a company providing corporate support services to its group companies in Europe was compromised from a blacklisted IP address. The attacker accessed folders set to “public” and the FTP server, and the data of approximately 70,000 persons was affected. The Board treated the inability to determine even the start date of the breach, and the retention of access logs for only ninety days before the breach, as a deficiency in monitoring and control, and resolved to impose an administrative fine of TRY 700,000. Decision No. 2024/1898 of the same date concerns a company in the pharmaceutical and health products field. In that incident the server was encrypted by ransomware; the decision summary states that 520 persons were affected. Having regard to the possibility that entry was gained by brute force through a remote desktop service that should not have been exposed to the internet, and to the deletion of the server log records, an administrative fine of TRY 350,000 was imposed. In both decisions, the log-keeping, access authorisation matrix and strong password principles under the heading “Monitoring of Personal Data Security” in the Personal Data Security Guide served as the concrete criteria for the sanction.
FileDecisionAffectedOutcome
Yeni Mağazacılık (Eve Kozmetik)2026/2039 – 2026/20816,263,305 personsAnnounced; processor-originated
Shaya Mağazacılık2026/2039 – 2026/20812,298,726 employees and customersAnnounced; processor-originated
Canva Pty Ltd2026/2037424 organisations in TürkiyeAnnounced; third-party tool
Association of Tax Inspectors2026/2082Up to 9,462 membersAnnounced; identity number and password
Plastic household goods manufacturer2024/2196Employee and customer dataTRY 250,000; contradictory statements, no segmentation
Corporate support company2024/1899Approximately 70,000 personsTRY 700,000; public folders, short log retention
Pharmaceutical and health products company2024/1898520 personsTRY 350,000; remote desktop, deleted logs
Processor-originated breach announcements and ransomware decisions
06
The Authority's Other AnnouncementsKurumun Diğer Duyuruları
The Authority's Selected Recent Developments bulletin of 10 September 2026 records the following developments. The Medium-Term Programme (2027–2029), published in the Official Gazette of 6 September 2026, envisages that the alignment of Law No. 6698 with the European Union General Data Protection Regulation will be completed in the third quarter of 2027. The Authority has also published the Guide on Compliance with the Personal Data Protection Law for Public Institutions and Organisations and Professional Organisations with Public Institution Status. The circular on the Türkiye Artificial Intelligence Action Plan (2026–2030) appeared in the Official Gazette of 18 August 2026. In the Board decision summaries and principle decisions sections, there has been no new content since the publication of 10 August 2026.
07
Assessment and ConclusionGenel Değerlendirme ve Sonuç
“Read together, the Guide and the decisions examined point to two priority compliance steps: documenting the source of the data a lawyer processes, and monitoring in practice the security and notification clauses of data processor agreements.”
The Guide addresses the data processing operations involved in legal practice together with the Board's existing decisions and explains systematically matters ranging from the lawyer's status to the use of AI tools. In the authors' assessment, one consequence of the Guide that stands out for practice is its express statement that exemption from registration does not mean exemption from other obligations. In the light of that statement, law firms are advised to set their privacy notice, retention and destruction, application and breach notification processes down in written policies. Since the complaints reaching the Board concentrate on the source of the data, those policies should give priority to a record-keeping system that shows where each item of data was obtained. For generative AI tools, converting the Guide's list of measures into written in-house rules is regarded as a sufficient starting point.
The breach announcements and the 2024 ransomware decisions examined in this note show how liability is allocated for breaches at data processors. Although the controller and the processor are jointly responsible for security measures, the notification obligation and the administrative fine fall on the controller; in the decisions examined, contradictory statements, unsubmitted inventories and documents, and missing log records were the grounds for the fine. In the authors' assessment, this places data processor agreements and incident response plans among the priority elements of a compliance programme. In conclusion, law firms are advised to translate the Guide's explanations into written policies and a record-keeping system that shows the source of the data. Controllers that outsource their e-commerce or membership infrastructure would do well to review their processor audits, network segmentation, log retention periods and seventy-two-hour notification workflow in the light of the decisions examined in this note.
Legislation and Decisions CitedAtıf Yapılan Mevzuat ve Kararlar
Law No. 6698 on the Protection of Personal Data, Arts. 4, 5/2(d), 8, 9, 12/1(a), 12/2, 12/5, 18 · Law No. 7499 · Attorneyship Law No. 1136, Arts. 2/3, 39 · Criminal Records Law No. 5352, Art. 7 · Enforcement and Bankruptcy Law No. 2004, Art. 89 · Regulation on Personal Health Data, Art. 10 · PDPA Publication No. 115 (Implementation Guide) · Board decisions 2018/32, 2019/10, 2019/166, 2019/308 (Principle Decision), 2020/429, 2021/111, 2021/115, 2021/228, 2021/511-512-513, 2021/1111, 2022/655, 2023/78, 2023/437, 2024/1898, 2024/1899, 2024/2196, 2025/2451, 2026/2037, 2026/2039, 2026/2081, 2026/2082 · Council of State, 1st Chamber, E. 2002/26, K. 2002/52
This article has been prepared for general information purposes only and does not constitute legal advice. The board decisions, guides and announcements referred to are based on sources published on the relevant authorities' websites as at the date of publication; findings recorded in decision summaries are those of the Boards and do not reflect the views of Devin Law & IP. This article does not create an attorney-client relationship and contains no undertaking as to its updating. 28 September 2026.
Full briefing noteDownload the bilingual PDF version of this briefing note, with tables and decision summaries.
Reach our team for your intellectual property portfolio, corporate needs or an ongoing dispute. We respond to every enquiry with a clear assessment of scope, timing and next steps — and we build specialized teams around each matter from day one.
Istanbul Office
Let's talk.
Our offices are located in the Ferko Signature building on Büyükdere Caddesi, at the heart of Istanbul's business district. Whether you are protecting a single trademark or restructuring an international portfolio, the first conversation is always with the team that will actually handle your matter.
For trademark and patent attorneyship services, our dedicated prosecution practice also operates through devinpatent.com — covering filings, renewals, oppositions and portfolio administration before TÜRKPATENT, EUIPO and WIPO.
On Büyükdere Caddesi — the spine of Istanbul's central business district — Ferko Signature places the firm minutes from the courts, TÜRKPATENT liaison offices and the headquarters of the companies we serve.
Transform Traditional Law with a Modern Vision — building your career at Devin Law & IP means leading through complex legal challenges and shaping the future of the industry.
Why Devin
Lead through complex legal challenges. Shape the future of the industry.
We invite you to be part of our innovative vision, create impact with strategic solutions, and elevate your professional journey to the highest level. Join us to demonstrate your legal expertise within a modern and dynamic platform.
At Devin Law & IP, junior colleagues work directly with partners on live matters from their first week — trademark oppositions, litigation strategy, KVKK compliance projects and international portfolio work. Mentoring is structured, feedback is continuous, and responsibility grows with demonstrated ability rather than seniority alone.
To apply, send your CV and a short note describing your interest in working with our firm to info@devinlaw.com.tr. Applications are reviewed on a rolling basis and every candidate receives a response.
Lawyers
Attorneys with litigation or IP prosecution experience who want to work on high-stakes, cross-border matters within specialized practice groups.
Internships
Legal internships for law students and graduates — hands-on exposure to trademark procedures, litigation and data protection projects alongside experienced mentors.
Business Services
Finance, administration and operations roles that keep a modern law firm running with precision.
Independent international directories consistently rank our team among the leading practitioners in intellectual property and media law in Türkiye. Our intellectual property and media practice has been recognised by The Legal 500 EMEA, the WTR 1000, Managing IP's IP STARS and Media Law International in both the 2026 and 2025 editions. Click any ranking below for the full details.
2026Current Edition
The rankings published for the current cycle — across intellectual property and media law.
Five Categories · 2026IP STARS — Managing IP
In the IP STARS 2026 rankings published by Managing IP, Devin Law & IP is ranked in five practice categories in Türkiye — with Uğurcan Tekin and İnci Özçilsal recognised among Türkiye's leading IP practitioners as Rising Stars, supported by eleven client testimonials on prosecution, enforcement and opposition work.
All Details →
Recommended · 2026WTR 1000
In the 2026 edition, World Trademark Review's WTR 1000 recognises Uğurcan Tekin individually for trademark protection and international IP strategies — identifying the world's leading trademark professionals through extensive research among clients and peers, including his work on global strategies for multinational corporations and proceedings before WIPO.
All Details →
Ranked · EMEA 2026The Legal 500 EMEA
Ranked in the Legal 500 EMEA 2026 edition in Intellectual Property and Media & Entertainment. Uğurcan Tekin is listed as a Next Generation Partner, with İnci Özçilsal and Beyza Erdemir recognised as Key Lawyers — supported by directory commentary and client testimonials on the team's patent, advertising and brand protection work.
All Details →
Tier 2 · 2026Media Law International
In its 2026 rankings, Media Law International places Devin Law & IP at Tier 2 of the Türkiye country chapter among the leading law firms for media law, with Uğurcan Tekin named among the Top 10 Recommended Media Lawyers in Turkey — reflecting expertise in digital media regulation, content management and broadcasting standards.
All Details →
2025Previous Edition
Recognitions earned in the preceding ranking cycle by the same intellectual property and media practice.
Ranked · EMEA 2025The Legal 500 EMEA
Ranked in the Legal 500 EMEA 2025 edition in Intellectual Property and Media & Entertainment, with Uğurcan Tekin as practice head. The editorial assessment highlighted advisory work for the full spectrum of media stakeholders — from multinational media companies to individual actors, directors and agents — and the team's depth in digital media, online content and data privacy.
All Details →
Ranked · 2025Media Law International
In its 2025 assessments, Media Law International recognised the practice as one of Türkiye's leading media law firms, with Uğurcan Tekin selected among the ten recommended media law practitioners in Türkiye.
All Details →
Recommended Firm · 2025IP STARS — Managing IP
In the IP STARS rankings published in 2025 by Managing IP, the practice was listed among the recommended firms in Türkiye — international recognition of the breadth of experience and strategic approach the team brings to intellectual property work.
All Details →
Recommended Firm · 2025WTR 1000
In the 2025 edition, World Trademark Review's WTR 1000 listed the practice among the recommended trademark firms in the Türkiye ranking — reflecting the team's work on filing strategy, portfolio management and contentious trademark matters for domestic and international clients.