TÜRKIYE
Since November 2013
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Regulation on After-sale service (Satiş Sonrasi Hi̇zmetler Yönetmeli̇ği̇)
According to the Regulation on After-sale Service, products requiring after-sales services, such as advanced data processing equipment, office equipment and computers, cash registers, TV and video equipment, and wireless equipment, need an import permit from the Ministry of Trade. To obtain such a permit, importers must guarantee that they will provide service and spare parts either by establishing offices or by signing agreements with existing service/parts firms. Complaints have been raised by some companies in 2014 that a lack of transparency in Türkiye‘s import licensing system results in costly delays, demurrage charges, and other uncertainties that inhibit trade.
Coverage Digital products that require after sales services
Sources
- https://web.archive.org/web/20230805235033/https://ustr.gov/sites/default/files/2014%20NTE%20Report%20on%20FTB.pdf
- https://web.archive.org/web/20221124103258/https://www.mevzuat.gov.tr/File/GeneratePdf?mevzuatNo=19783&mevzuatTur=KurumVeKurulusYonetmeligi&mevzuatTertip=5
- https://web.archive.org/web/20210722021832/https://www.trade.gov/knowledge-product/turkey-import-requirements-and-documentation
- https://web.archive.org/web/20160821065929/http://www.globaltrade.net/f/business/text/Turkey/Trade-Policy-Import-Requirements-and-Documentation-in-Turkey.html
- Show more...
TÜRKIYE
Since September 2019
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Notification No. 2019/4 on Import Surveillance (İthalatta Gözetim Uygulamasına İlişkin Tebliğ (Tebliğ No: 2019/4))
According to the Notification No. 2019/4 on Import Surveillance of September 2019, the Turkish Ministry of Trade imposed a licensing requirement on the imports of LED lamps.
Coverage Light-emitting diode (LED) lamps
TÜRKIYE
Since May 2020
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Notification No. 2020/6 on Import Surveillance (İthalatta Gözetim Uygulamasına İlişkin Tebliğ (Tebliğ No: 2020/6))
According to the Notification No. 2020/6 on Import Surveillance of May 2020, the Turkish Ministry of Trade issued a licensing requirement on the imports of mobile phones.
Coverage Mobile phones
TÜRKIYE
Since October 2014
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Notification on Implementation of Tariff Quota in Imports of Printed Circuit Boards with LED Diodes used in the Production of Backlight Units (Arka Isik Ünitelerinin Imalinde Kullanilan LED Diyotlu Baskili Devre Kartlarinin Ithalatinda Tarife Kontenjani Uygulanmasi Hakkinda Karar)
According to the Communiqué on Implementation of Tariff Quota in Imports of Printed Circuit Boards with LED Diodes Used in the Production of Backlight Units, in October 2014, the government of Türkiye announced an altered import quota on printed circuit boards with LEDs used in the production of backlight units.
Coverage LED-printed circuit boards
TÜRKIYE
Reported in 2022, last reported in 2025
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Lack of transparency in customs
It is reported that Türkiye's documentation requirements for many imports are burdensome, inconsistent, and non-transparent, often causing shipments to be delayed at Turkish ports.
Coverage Horizontal
TÜRKIYE
Reported in 2024, last reported in 2026
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Export restrictions on ICT goods or online services
Reported export ban
It is reported that Türkiye suspended all exports to Israel with effect from 2 May 2024. It is further reported that, from August 2025, Turkish port authorities began requiring shipping agents to submit an electronic declaration confirming that the vessel’s owner, agent, or operator has no affiliation with Israel and that the vessel is not carrying military or hazardous cargo destined for Israel.
Coverage Exports to Israel
TÜRKIYE
Last reported in 2025
Pillar Technical standards applied to ICT goods and online services |
Indicator Self-certification for product safety
Supplier Declaration of Conformity allowed for foreign businesses
It is reported that Türkiye permits self‑certification for radio transmission, electromagnetic interference (EMI) and electromagnetic compatibility (EMC), allowing foreign manufacturers to demonstrate compliance through a Supplier’s Declaration of Conformity (SDoC). Under the conformity assessment procedure applied to EMC/EMI, the supplier or manufacturer declares that the equipment satisfies the relevant technical and administrative requirements; registration with the national regulator is not required, and testing by a recognised testing laboratory is not mandatory. Where testing is undertaken, the selection of the laboratory is at the discretion of the supplier or manufacturer; however, if harmonised standards are not applied or do not exist, an independent third‑party opinion is required.
Coverage Electronic products
TÜRKIYE
Since July 2020
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Information and Communication Security Guide (Bilgi ve İletişim Güvenliği Rehberi)
Section 4.3.1.7 of the Information and Communication Security Guide states that cloud operators must implement measures to ensure that domestic communication traffic remains within Türkiye. The Guide is directed at public institutions and providers of critical infrastructure services across a range of sectors, including telecommunications and electronic communications, water management, energy, essential public services such as healthcare, transportation, banking, and finance. The Guide defines critical infrastructure as systems whose compromise, through breaches of confidentiality, integrity, or availability, could result in large-scale harm, national security vulnerabilities, or significant disruption to public order.
Coverage Public sector and critical infrastructure
Sources
- https://web.archive.org/web/20240524103651/https://cbddo.gov.tr/SharedFolderServer/Genel/File/bg_rehber.pdf
- https://web.archive.org/web/20250901153145/https://www.lexology.com/library/detail.aspx?g=e132f92b-6691-45f8-a24c-3beef84be555
- https://web.archive.org/web/20250901154923/https://resourcehub.bakermckenzie.com/en/resources/global-data-and-cyber-handbook/emea/turkiye/topics/data-localization-and-regulation-of-non-personal-data
- https://www.dataguidance.com/notes/turkey-data-transfers
- Show more...
TÜRKIYE
Since November 1983, as amended in April 2014
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Law on State Intelligence Services and National Intelligence Organization No. 2937 (2937 Devlet İstihbarat Hizmetleri ve Milli İstihbarat Teşkilatı Kanunu)
According to Art. 6 of Law No. 2937, intelligence services are entitled to request any type of document/information from individuals and private/public entities while performing their duties. It is not clear whether a court order is needed.
Coverage Horizontal
Sources
- https://web.archive.org/web/20231021184721/https://www.mevzuat.gov.tr/MevzuatMetin/1.5.2937.pdf
- https://web.archive.org/web/20240721200117/https://www.dataguidance.com/notes/turkey-third-country-assessment
- https://web.archive.org/web/20230921001248/https://freedomhouse.org/country/turkey/freedom-net/2022
- https://www.sciencedirect.com/science/article/abs/pii/S0267364916300838?fr=RR-2&ref=pdf_download&rr=912601e6ad16ea5d
- Show more...
TÜRKIYE
Since December 2020, entry into force in June 2021
Since April 2016
Since July 2012, invalidated in January 2015
Since April 2016
Since July 2012, invalidated in January 2015
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Regulation on the Processing of Personal Data and the Protection of Confidentiality in the Electronic Communications Sector (Elektroni̇k Haberleşme Sektöründe Ki̇şi̇sel Veri̇leri̇n İşlenmesi̇ Ve Gi̇zli̇li̇ği̇n Korunmasina İli̇şki̇n Yönetmeli̇k)
Personal Data Protection Law No. 6698 (6698 sayılı Kişisel Verilerin Korunması Kanunu)
Regulation on Processing and Privacy of Personal Data in Electronic Communications Sector
Personal Data Protection Law No. 6698 (6698 sayılı Kişisel Verilerin Korunması Kanunu)
Regulation on Processing and Privacy of Personal Data in Electronic Communications Sector
The Regulation on the Processing of Personal Data and the Protection of Confidentiality in the Electronic Communications Sector reaffirms the data processing principles set out in Art. 4.2 of the Data Protection Law mandating that operators adhere to these principles when managing personal data. According to Art. 5 of the Regulation, cross-border transfer of traffic and location data is prohibited on the basis of national security concerns.
Data processing in the electronic communications sector was previously regulated by the Regulation on Processing and Privacy of Personal Data in the Electronic Communications Sector. The regulation imposed strict conditions on the transfer of personal data outside of Türkiye by telecommunications providers. However, the Constitutional Court invalidated the basis of this regulation, and as a result, the regulation was considered null and void.
Data processing in the electronic communications sector was previously regulated by the Regulation on Processing and Privacy of Personal Data in the Electronic Communications Sector. The regulation imposed strict conditions on the transfer of personal data outside of Türkiye by telecommunications providers. However, the Constitutional Court invalidated the basis of this regulation, and as a result, the regulation was considered null and void.
Coverage Electronic communications sector
Sources
- https://web.archive.org/web/20230328174629/https://www.resmigazete.gov.tr/eskiler/2020/12/20201204-13.htm
- https://web.archive.org/web/20201212030056/https://www.dataguidance.com/news/turkey-regulation-processing-personal-data-electronic
- https://web.archive.org/web/20211025140506/http://www.mondaq.com/turkey/privacy-protection/480822/turkey-completes-final-step-in-approving-data-protection-legislation
- https://web.archive.org/web/20170108225407/http://uk.practicallaw.com/7-520-1896#a350846
- https://web.archive.org/web/20220302173130/https://www.mevzuat.gov.tr/MevzuatMetin/1.5.6698.doc
- https://web.archive.org/web/20251220181835/https://gurkaynak.av.tr/docs/Privacy_Data_Protection_and_Cybersecurity_Law_Review.pdf
- https://web.archive.org/web/20240422224743/https://www.linklaters.com/en/insights/data-protected/data-protected---turkey#top
- Show more...
TÜRKIYE
Since May 2007, last amended in October 2022
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Law No. 5651 on Regulating Broadcasting in the Internet and Fighting Against Crimes Committed through Internet Broadcasting (5651 sayılı İnternet Ortamında Yapılan Yayınların Düzenlenmesi ve Bu Yaynlar Yoluyla İşlenen Suçlarla Mücadele Edilmesi Hakkında Kanun)
The Regulation of Publications on the Internet and Suppression of Crimes Committed by means of Such Publications (Internet Law) establishes a safe harbour regime for intermediaries for copyright infringements. According to Art. 4 of the law, a content provider is not responsible for the link to the content that belongs to someone else. However, if it is clear from the format of the presentation that the content in question it links to is embraced and intended to be reachable, the content provider is responsible according to the general provisions. Furthermore, hosting providers are only liable for removing unlawful content that they host, provided that they are notified, pursuant to Articles 8 and 9 of the Internet Law, that is, ensuring that they act according to a notice-and-takedown procedure.
Coverage Internet intermediaries
Sources
- https://web.archive.org/web/20230222140802/https://mbkaya.com/turkish-internet-law/
- https://web.archive.org/web/20220107233819/https://www.mevzuat.gov.tr/MevzuatMetin/1.5.5651.pdf?dil=tr-TR
- https://www.sciencedirect.com/science/article/abs/pii/S0267364916300838?fr=RR-2&ref=pdf_download&rr=912601e6ad16ea5d
- https://web.archive.org/web/20171213010147/http://cyberlaw.stanford.edu/page/wilmap-turkey
- Show more...
TÜRKIYE
Since January 2018
Since February 2019
Since February 2019
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Decision No. 2018/DK-YED/27 (Karar No 2018/DK-YED/27)
Decision No. 2019/DK-TED/053 (Karar No 2018/DK-YED/27)
Decision No. 2019/DK-TED/053 (Karar No 2018/DK-YED/27)
According to Decision No. 2018/DK-YED/27, the emergency call (eCall) in vehicles, along with servers that provide the communication system allowing for value-added services, are to be located in Türkiye, and personal data in such systems cannot be transferred abroad without explicit consent. To achieve this, it is mandatory for the SIM cards, electronic SIMs (eSIMs) or modules having SIM card properties to be procured from operators licensed to provide mobile electronic communication in Türkiye or to be programmable to allow them to be controlled by such operators.
With Decision No. 2019/DK-TED/053, the localisation requirements are no longer limited to eCall services only, encompassing all eSIM applications. Moreover, all infrastructure, system and storage units, including equipment and software related to the eSIM platform in GSMA standards, shall be established in Türkiye by a licensed local operator (or by a third party to be appointed by such local operators, but liability remaining with the local operator). The decision also states that all data should be kept within Turkish borders. Moreover, where the devices manufactured to be used in Türkiye or imported to the country have remotely programmable SIM (eUICC, eSIM/embedded SIM, etc.) technologies, their relevant modules are expected to be programmable only by local mobile operators and only local mobile operator profiles may be installed.
With Decision No. 2019/DK-TED/053, the localisation requirements are no longer limited to eCall services only, encompassing all eSIM applications. Moreover, all infrastructure, system and storage units, including equipment and software related to the eSIM platform in GSMA standards, shall be established in Türkiye by a licensed local operator (or by a third party to be appointed by such local operators, but liability remaining with the local operator). The decision also states that all data should be kept within Turkish borders. Moreover, where the devices manufactured to be used in Türkiye or imported to the country have remotely programmable SIM (eUICC, eSIM/embedded SIM, etc.) technologies, their relevant modules are expected to be programmable only by local mobile operators and only local mobile operator profiles may be installed.
Coverage eSIM applications
Sources
- https://web.archive.org/web/20230328191549/https://www.btk.gov.tr/uploads/boarddecisions/112-tabanli-arac-ici-acil-cagri-sistemi-e-call/027-05-112-tabanli-arac-ici-acil-cagri-sistemi-e-call-22-01-2018...
- https://web.archive.org/web/20230206152648/https://www.btk.gov.tr/uploads/boarddecisions/uzaktan-programlanabilir-sim-teknolojileri-esim/053-2019-web.pdf
- https://web.archive.org/web/20241203214650/https://www.mondaq.com/turkey/telecoms-mobile--cable-communications/1054068/turkey-has-introduced-its-national-esim-technology-but-why-is-it-important
- https://web.archive.org/web/20231210005618/https://www.dataguidance.com/notes/turkey-data-transfers
- https://web.archive.org/web/20231226161832/https://www.lexology.com/library/detail.aspx?g=f3ab713c-e76e-4006-ab83-6276e1aa9d64
- Show more...
TÜRKIYE
Since April 2021
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Regulation on Electric Scooters (Elektrikli Skuter Yönetmeliği)
Art. 8 of the Regulation on Electric Scooters stipulates that the servers hosting databases related to e-scooter operations must be located within the territory of the Republic of Türkiye and must provide unrestricted access to the competent Authority.
Coverage Electric scooter service providers
TÜRKIYE
Since July 2019
Since July 2020
Since July 2020
Pillar Cross-border data policies |
Indicator Local storage requirement
Presidential Circular on Information and Communication Security Measures No. 2019/12 (2019/12 Sayılı Cumhurbaşkanlığı Bilgi ve İletişim Güvenliği Tedbirleri Genelgesi)
Information and Communication Security Guide (Bilgi ve İletişim Güvenliği Rehberi)
Information and Communication Security Guide (Bilgi ve İletişim Güvenliği Rehberi)
According to Art. 1 of Circular 2019/12, critical information and data, including population statistics, health and communication records, as well as genetic and biometric data, must be securely stored within the territory of Türkiye. It is reported that it is generally understood that Art. 1 does not constitute a prohibition on cross-border data transfers; rather, it is interpreted primarily as imposing an obligation to maintain a domestic backup of the relevant data to ensure accessibility. Similarly, Section 4.3.1.1 of the Information and Communication Security Guide underscores the necessity of domestic storage of critical data when utilising cloud services.
Circular 2019/12 and the accompanying Guide are directed at public institutions and providers of critical infrastructure services across a range of sectors, including telecommunications and electronic communications, water management, energy, essential public services such as healthcare, transportation, banking, and finance. The Guide defines critical infrastructure as systems whose compromise, through breaches of confidentiality, integrity, or availability, could result in large-scale harm, national security vulnerabilities, or significant disruption to public order.
Circular 2019/12 and the accompanying Guide are directed at public institutions and providers of critical infrastructure services across a range of sectors, including telecommunications and electronic communications, water management, energy, essential public services such as healthcare, transportation, banking, and finance. The Guide defines critical infrastructure as systems whose compromise, through breaches of confidentiality, integrity, or availability, could result in large-scale harm, national security vulnerabilities, or significant disruption to public order.
Coverage Public sector and critical infrastructure
Sources
- https://web.archive.org/web/20241125195642/https://cbddo.gov.tr/en/presidential-circular-no-2019-12-on-information-security-measures
- https://web.archive.org/web/20240524103651/https://cbddo.gov.tr/SharedFolderServer/Genel/File/bg_rehber.pdf
- https://web.archive.org/web/20250901153145/https://www.lexology.com/library/detail.aspx?g=e132f92b-6691-45f8-a24c-3beef84be555
- https://web.archive.org/web/20250901154923/https://resourcehub.bakermckenzie.com/en/resources/global-data-and-cyber-handbook/emea/turkiye/topics/data-localization-and-regulation-of-non-personal-data
- https://www.dataguidance.com/notes/turkey-data-transfers
- Show more...
TÜRKIYE
Since July 2019
Since July 2020
Since July 2020
Pillar Cross-border data policies |
Indicator Local storage requirement
Presidential Circular on Information and Communication Security Measures No. 2019/12 (2019/12 Sayılı Cumhurbaşkanlığı Bilgi ve İletişim Güvenliği Tedbirleri Genelgesi)
Information and Communication Security Guide (Bilgi ve İletişim Güvenliği Rehberi)
Information and Communication Security Guide (Bilgi ve İletişim Güvenliği Rehberi)
Art. 3 of Circular 2019/12 stipulates that data relating to public institutions and organisations may not be stored on cloud services, except where such services are operated by the institution itself or by local service providers under its control. It is reported that it is generally understood that Art. 3 does not constitute a prohibition on cross-border data transfers; rather, it is interpreted primarily as imposing an obligation to maintain a domestic backup of the relevant data to ensure accessibility.
Coverage Public sector
Sources
- https://web.archive.org/web/20241125195642/https://cbddo.gov.tr/en/presidential-circular-no-2019-12-on-information-security-measures
- https://web.archive.org/web/20240524103651/https://cbddo.gov.tr/SharedFolderServer/Genel/File/bg_rehber.pdf
- https://web.archive.org/web/20250901153145/https://www.lexology.com/library/detail.aspx?g=e132f92b-6691-45f8-a24c-3beef84be555
- https://web.archive.org/web/20250901154923/https://resourcehub.bakermckenzie.com/en/resources/global-data-and-cyber-handbook/emea/turkiye/topics/data-localization-and-regulation-of-non-personal-data
- https://www.dataguidance.com/notes/turkey-data-transfers
- Show more...
