Judicial Information, User Data and User Rights Obligations¶
With the introduction of Supplemental Article 4/5 to Law No. 5651 (via Article 34 of Law No. 7418 on 13 October 2022), the legal landscape for social media platforms shifted dramatically. No longer mere intermediaries, platforms were imposed with a strict obligation to provide information to judicial authorities regarding specific crimes listed in the Turkish Penal Code (TCK).46
-
Sexual abuse of children (TCK 103);
-
Publicly disseminating misleading information (TCK 217/A);
-
Disrupting the unity of the state and the integrity of the country (TCK 302);
-
Crimes against the constitutional order (TCK 309–316);
-
Crimes against state secrets and espionage (TCK 328–337).
This provision transforms platform representatives in Türkiye from passive recipients of content removal notices into active agents of the state’s surveillance apparatus. They are now legally compelled to cooperate in identifying perpetrators.
The Mechanism: Cooperation or Obliteration¶
To identify users creating or disseminating content related to these crimes, the platform’s representative must submit necessary user information upon the request of the public prosecutor (during investigation) or the competent court (during prosecution).
Should the platform fail to comply, the consequences are existential. The Chief Public Prosecutor may apply to the Ankara Criminal Judgeship of Peace for a sanction of bandwidth throttling by 90 per cent. Once issued, this decision is transmitted via the BTK to access providers and must be implemented within four hours. This effectively renders the platform unusable in Türkiye, a technical equivalent of a total ban. The sanction is lifted only if the platform capitulates and surrenders the requested data.
Of particular concern is the weaponisation of the crime of “publicly disseminating misleading information” (TCK 217/A). This norm is perilously ambiguous. The distinction between “real” and “misleading” is often dictated by political power, particularly during election periods or crises. Demanding user data based on such a fluid definition creates a severe risk of censorship and surveillance.
The Reality of Compliance: Meta vs. Google¶
While the state provides no public audit mechanism regarding the implementation of this obligation, an analysis of global transparency reports reveals a stark divergence in how platforms have responded to this “existential threat.”
An examination of Meta’s (Facebook & Instagram) global transparency reports47 reveals a striking level of compliance with requests from Türkiye. As Table 6 demonstrates, following the introduction of the “obligation to provide information” in 2022, Meta’s compliance rate surged.
| Period | No. of Requests |
Partial Data Provided | Compliance Rate (%) |
Legal Context |
|---|---|---|---|---|
| 2021-1 | 7.825 | 4.622 | 59% | Pre-Law No. 7418 |
| 2021-2 | 8.488 | 4.477 | 53% | Pre-Law No. 7418 |
| 2022-1 | 8.513 | 6.954 | 82% | Pre-Law No. 7418 |
| 2022-2 | 4.818 | 3.894 | 81% | Law No. 7418 in Force |
| 2023-1 | 4.288 | 3.316 | 77% | Law No. 7418 in Force |
| 2023-2 | 4.095 | 3.271 | 80% | Law No. 7418 in Force |
| 2024-1 | 3.529 | 2.626 | 74% | Law No. 7418 in Force |
| 2024-2 | 4.121 | 3.360 | 82% | Law No. 7418 in Force |
Consequently, Meta’s overwhelmingly positive response to user data requests from Türkiye points to a policy of “High Compliance and Obedience”. Notably, in 2022 and beyond, as legal pressures intensified, Meta’s compliance rate surged to levels exceeding 80%, a marked increase compared to previous periods. For instance, in the second half of 2024 alone, data was shared in response to 3.360 of 4.121 requests (82%). The rise in Meta’s data sharing rate from the 67% to the 80%, following the entry into force of the legal representation, information provision, and bandwidth throttling regulations in 2022, demonstrates that these legal instruments have achieved the desired effect of “compliance” on the platform.
Conversely, an examination of Google’s global transparency reports48 reveals an approach as distinct from Meta’s as night and day. Google’s data indicates that the new legal regulations, especially post-2022 did not trigger a radical break in its data sharing policy, even as administrative authorities began to actively utilise the new legal tools at their disposal (specifically, requests via the local office).
In this context, the most concrete shift in Google’s data is the emergence of a new category titled “Requests for data of local subsidiary” as of 2022. This reflects the obligation for social media platforms to establish a representative office in Türkiye as no such category existed in Google transparency reports prior to this date. However, an analysis of local subsidiary data requests post-2022 paints a picture of steadfast resistance:
-
2022: 28 requests (Positive response to only 4%)
-
2023: 124 requests (Positive response to none - 0%)
-
2024: 72 requests (Positive response to none - 0%)
These figures indicate that while Turkish authorities have started demanding information by addressing the local company established under the new law, Google has resisted these requests, even when channelled through the local Office and has refused to share data.
Furthermore, Google’s stance in the “Other Legal Requests” category has remained unchanged post-2022. The general trend, despite thousands of requests since 2010, is that Google provides a positive response to 0% (zero) of the requests in this category. Thus, despite threats of severe sanctions such as bandwidth throttling, it appears that Google has maintained its “non-disclosure” policy in standard legal processes throughout the 2022–2024 period, continuing its “zero-yield” stance.
The sole exception to this approach is found in “Emergency Disclosure Requests,” where Google does share data with Turkish authorities. These requests generally cover life-threatening situations (terrorism, suicide, kidnapping, etc.). For example, in 2023, data was shared in response to 62% of the 26 emergency requests received. This rate demonstrates that while Google cooperates when the “life safety” criterion is met, it keeps the door firmly shut against political or judicial requests.
In conclusion, Meta (Facebook/Instagram) transparency data reveals that the platform follows a “high compliance” strategy regarding the Obligation to Provide Information to Judicial Authorities in Türkiye, in stark contrast to Google. The data sharing rate, which sat at 67% prior to 2022, climbed above 80% after legal sanctions were aggravated in 2022. The fact that the volume of requests directed by Turkish authorities to Meta is approximately 10 times higher than that directed to Google, combined with the fact that the vast majority of these requests are met, indicates that Meta does not resist administrative requests regarding user data in Türkiye and has effectively bowed to legal pressures.
When assessed collectively, it is clear that the state has elevated its position from a regulator merely demanding the “blocking or removal of content” to an authority that mandates access to the “identity of the perpetrator producing the content.” It is an authority capable of rendering a social media platform functionally obsolete via bandwidth throttling sanctions if it fails to provide this access. Driven by commercial concerns, social media platforms appear, for now, to have adapted to and indeed submitted to this system.
Obligation to Host User Data in Türkiye¶
Under the framework of Law No. 5651 and its secondary legislation, both domestic and foreign-sourced social media platforms with more than one million daily accesses from Türkiye are mandated to take the necessary technical and administrative measures to host user data within the country’s borders.49
Originally, Article 13 of the Procedures and Principles (effective 29 September 2020)50 stipulated that platforms must “prioritise measures to host basic user information and data... in Türkiye.”51 Furthermore, it explicitly required platforms to report their practices regarding data localisation to BTK during every reporting period.52
Crucially, however, the 2023 update to the regulations silently excised this reporting obligation.53 Consequently, the mandate to retain user data in Türkiye has become nebulous, and the audit mechanism significantly weakened. The rationale for this regression remains unexplained.
Moreover, a close examination of both the Law54 and the current Procedures and Principles55 reveals a gaping legal void. It is not explicitly specified which types of user data must be hosted in Türkiye, on what technical grounds, for how long, or for whom. Similarly, no rule or limitation exists regarding how this data is to be shared with the BTK or other public bodies.
The silence from both the platforms and the BTK on this matter creates serious concerns regarding data security, transparency, and auditing. Whether this obligation, introduced under the guise of data localisation paves the way for covert data transfer mechanisms remains a question entirely beyond the reach of public oversight.
Obligation to Provide Differentiated Services Specific to Children¶
With the introduction of Supplemental Article 4(7) on 13 October 2022, social media platforms were legally compelled to implement differentiated services for children. This obligation was further codified in Article 14 of the BTK’s Procedures and Principles.
Platforms are now required to act in accordance with fundamental principles such as age-based differentiation, privacy, and the “best interests of the child”. Specifically, strict adherence to the following is mandatory regarding content, advertisements, and services offered to minors:
-
Developmental Appropriateness: Services must align with the child’s age and developmental level.
-
Best Interests: The child’s best interests must be observed at every stage.
-
Holistic Protection: Physical, psychological, and emotional development must be safeguarded.
-
Risk Mitigation: Special protection mechanisms must be deployed against sexual abuse and commercial exploitation.
-
Data Minimisation: High-level privacy must be ensured, processing only the absolute minimum amount of personal data.
-
Clarity: Terms of use and privacy policies must be presented in clear, plain language that a child can understand.
While this regulation represents a positive step on paper towards mitigating digital risks for children in Türkiye, significant gaps remain in its execution. To date, platforms have failed to share any concrete policies regarding how their age-verification algorithms operate or how they determine data processing levels. Likewise, the BTK’s failure to publish audit results points to a distinct lack of transparency. It is imperative that the practical effectiveness of these “differentiated services” be monitored platform-by-platform and shared with the public, rather than remaining a black box.
Protection of User Rights and the Obligation to Inform¶
Supplemental Article 4(13) (added 13 October 2022) imposed a broad obligation on platforms to comply with BTK regulations regarding user rights. This was detailed in Article 15 of the Procedures and Principles, establishing a comprehensive framework of obligations:
-
i. Impartiality: The platform must treat all users equally and impartially.
-
ii. User Control: Users must be offered the opportunity to change content recommendation preferences and limit the use of their personal data.
-
iii. Security Breach Notification: In the event of a significant security breach affecting users in Türkiye, the platform must notify both the BTK and the users within 72 hours, in clear Turkish.
-
iv. Service Updates: Users must be provided with easy access to platform updates affecting their rights.
-
v. Algorithmic Transparency: The platform must explain, in a transparent and accessible manner on its website, which parameters drive its content recommendations.
-
vi. Account Recovery: A clear, Turkish-language application mechanism must be established for compromised or impersonated accounts, with applications concluded within a reasonable time.
-
vii. Regulatory Compliance: The platform is obliged to comply with all future regulations issued by the BTK regarding user rights.
At first sight, this framework appears to be a robust step towards a safer digital environment. However, without concrete reports from the platforms on how they are implementing algorithmic transparency or breach notifications, these rules risk becoming a dead letter. Similarly, the BTK has shared no data regarding auditing or violation rates. The protection of user rights requires not merely the goodwill of corporations, but a transparent, auditable, and publicly reported oversight mechanism. From this perspective, the practical implications and effectiveness of the relevant regulations remain insufficiently clear.
Obligation to Establish an Application Mechanism for Hashtags and Featured Content¶
The introduction of Supplemental Article 4(15) to Law No. 5651 on 13 October 2022 imposed a specific mandate on social media platforms regarding the removal of unlawful hashtags and featured content. This obligation was further codified in Article 16 of the relevant Procedures and Principles.
Under this regime, platforms are obliged to establish, in cooperation with the BTK, an effective “notice-and-takedown” mechanism specifically for hashtags and featured content. Furthermore, they must report on the operation of these mechanisms to the Institution during every reporting period.
Crucially, this provision extends liability beyond the mere hosting of content to the manner in which it is presented. Upon notification of unlawful content related to a crime committed via hashtags or featured posts, platforms must remove such content immediately and within a maximum of four hours. Failure to meet this tight deadline renders them directly liable for the content in question.56
This effectively strips platforms of their status as passive intermediaries. Instead, they assume liability based on their algorithmic choices, such as highlighting or tagging content. In other words, the fact that content has spread indirectly via a hashtag or recommendation algorithm does not absolve the provider; rather, it triggers an obligation of active intervention. However, the requirement to adjudge the legality of content within a four-hour window significantly heightens the risk of excessive self-censorship, particularly regarding freedom of expression. This creates a burdensome legal risk for platforms regarding content moderation.
To date, no information has been disclosed to the public regarding the mechanics of these systems, the types of content they cover, or the criteria underpinning decisions. Nor does any data appear in the transparency reports shared with the public. This opacity creates serious uncertainty, fuelling concerns that these mechanisms could be weaponised for arbitrary or political ends.
Obligation to Share Content Endangering Life and Property Safety with Law Enforcement¶
Supplemental Article 4(16), added on 13 October 2022, imposes a duty of “urgent intervention” regarding content that endangers the safety of life and property. This provision, mirrored in Article 17 of the Procedures and Principles, dictates that if a platform becomes aware of such content and where delay would be detrimental, it must share the content and the creator’s details with law enforcement without delay.
Transcending standard notice-and-takedown procedures, this regulation introduces a mandate for proactive data sharing. However, the legal concept of “safety of life and property” remains dangerously vague and open to broad interpretation. Neither the statute nor the secondary legislation clarifies how such safety is deemed endangered. Equally opaque is the definition of “cases where delay is detrimental”. As the Constitutional Court has noted in its judgments regarding Article 8/A of Law No. 5651, the existence of a situation where delay is detrimental is rarely demonstrated in access blocking decisions taken by administrative bodies or judges.57 Moreover, while Article 8/A at least ostensibly requires judicial approval, Supplemental Article 4(16) bypasses judicial validation entirely.
Furthermore, although platforms bear no general obligation to monitor content, this regulation envisages an ambiguous “obligation to become aware”. How this obligation arises or is implemented remains undefined. Additionally, unlike Supplemental Article 4(5), which outlines clear procedures for providing information to judicial authorities for specific catalogue crimes, the obligation in Supplemental Article 4(16) is indefinite in both scope and application, lacking any robust legal safeguards.
Finally, the BTK has yet to offer any public explanation or report regarding the fulfilment of this obligation, the frequency of notifications to law enforcement, or the auditing of these processes.
In this respect, the regulation appears to have been enacted without striking the necessary constitutional balance between public security and fundamental rights. Questions regarding compliance methods, judicial review, and data security measures remain entirely unanswered. Consequently, the evaluation of content and the sharing of personal data based on broad, interpretive concepts like “safety of life and property” engenders serious concerns regarding freedom of expression, data protection, and the presumption of innocence.
The BTK’s Authority to Request Information and Conduct On-Site Inspections¶
Supplemental Article 4(18), added to Law No. 5651 on 13 October 2022, alongside Article 18 of the Procedures and Principles, arms the BTK with sweeping powers to audit and request information from social media platforms. To assess compliance, the BTK may demand comprehensive data covering:
-
Corporate structure,
-
IT systems,
-
Algorithms,
-
Data processing mechanisms,
-
Commercial conduct.
Platforms are strictly obliged to respond to these requests within three months of notification.
Crucially, the regulation goes further. If deemed necessary, the BTK is authorised to conduct on-site inspections at all facilities of the social media platform.58 This expands the BTK’s remit significantly, moving beyond technical audits to encompass the managerial and commercial operations of the company.
Consequently, this regulation grants the BTK not merely regulatory oversight but de facto audit authority. The power to demand information on competition-sensitive areas such as algorithms and commercial conduct, poses severe risks regarding the exposure of trade secrets and the security of user data. Furthermore, ill-defined concepts like “commercial conduct” and “data processing mechanisms” blur the boundaries of the Institution’s reach. This erodes legal certainty for platforms, raising the risk that oversight may mutate into arbitrary intervention rather than fostering transparency.
The Geographic Paradox¶
The authority to conduct “on-site inspections at all facilities” harbours serious practical uncertainties. Its geographical limits and scope remain undefined. Given that the primary technical and managerial infrastructure of global platforms is located abroad, the effectiveness of this authority is questionable. Access by the BTK to head offices or data centres in foreign jurisdictions appears neither legally nor practically feasible.
Put simply, it is impossible for the BTK to physically conduct on-site audits at the headquarters of giants like X, Meta, and TikTok in the USA, Ireland, or elsewhere. This logistical impossibility weakens predictability for platforms and limits the impact of public oversight.
To date, total radio silence has been maintained regarding the use of these powers. No explanation or report has been published indicating which platforms have been queried, the scope of such requests, or whether any on-site inspections have actually taken place.
-
Also see Procedures and Principles Regarding Social Media Platforms, Article 29. ↩
-
See https://transparency.meta.com/reports/government-data-requests/ ↩
-
See https://transparencyreport.google.com/user-data/overview?hl=en ↩
-
Law No. 5651, Supp. Art. 4(6). ↩
-
Information and Communication Technologies Authority, 2020/DK-İD/274, 29.09.2020. ↩
-
Procedures and Principles Regarding Social Media Platforms, Article 13(2). ↩
-
Procedures and Principles Regarding Social Media Platforms, Article 13(2). ↩
-
Information and Communication Technologies Authority, 2023/DK-İD/119, 28.03.2023, Article 13. ↩
-
Supp. Art. 4(6). ↩
-
Procedures and Principles Regarding Social Media Platforms, Article 13. ↩
-
Law No. 5651, Supp. Art. 4(15). ↩
-
See Birgün İletişim ve Yayıncılık Ticaret A.Ş. Application, App. No: 2015/18936, 22.05.2019, § 71. ↩
-
Also see Procedures and Principles Regarding Social Media Platforms, Article 35. ↩