Turkish Law in EnglishTÜRKİYE
Law No. 5070

Electronic Signature Law No. 5070

Elektronik İmza Kanunu

Regulates the legal and technical aspects and use of electronic signatures, the activities and liability of electronic certificate service providers, qualified electronic certificates, and electronic seals.

Part One: Purpose, Scope and Definitions

Article 1Purpose

Link to this article ↗

The purpose of this Law is to regulate the principles governing the legal and technical aspects and the use of electronic signatures.

Original Turkish text

MADDE 1 · Amaç

Bu Kanunun amacı, elektronik imzanın hukukî ve teknik yönleri ile kullanımına ilişkin esasları düzenlemektir.

This Law covers the legal structure of electronic signatures, the activities of electronic certificate service providers and transactions relating to the use of electronic signatures in all fields.

Original Turkish text

MADDE 2 · Kapsam

Bu Kanun, elektronik imzanın hukukî yapısını, elektronik sertifika hizmet sağlayıcılarının faaliyetlerini ve her alanda elektronik imzanın kullanımına ilişkin işlemleri kapsar.

Article 3Definitions

Link to this article ↗

For the purposes of this Law, the following terms shall mean:

a) Electronic data: records generated, transmitted or stored by electronic, optical or similar means,

b) Electronic signature: electronic data that is attached to other electronic data or logically associated with electronic data and used for the purpose of authentication,

c) Signatory: the natural person who uses a signature creation device for the purpose of creating an electronic signature,

d) Signature creation data: data, such as passwords and cryptographic private keys, which belong to the signatory, are used by the signatory for the purpose of creating an electronic signature and are unique,

e) Signature creation device: the software or hardware device that uses signature creation data in order to create an electronic signature,

f) Signature verification data: data, such as passwords and cryptographic public keys, used to verify an electronic signature,

g) Signature verification device: the software or hardware device that uses signature verification data for the purpose of verifying an electronic signature,

h) Time stamp: the record, verified with an electronic signature by an electronic certificate service provider, for the purpose of determining the time at which an item of electronic data was generated, modified, sent, received and/or recorded,

ı) Electronic certificate: the electronic record that links the signatory's signature verification data and identity information to each other,

j) Authority: the Telecommunications Authority,

(as defined above).

Original Turkish text

MADDE 3 · Tanımlar

Bu Kanunda geçen;

a) Elektronik veri: Elektronik, optik veya benzeri yollarla üretilen, taşınan veya saklanan kayıtları,

b) Elektronik imza: Başka bir elektronik veriye eklenen veya elektronik veriyle mantıksal bağlantısı bulunan ve kimlik doğrulama amacıyla kullanılan elektronik veriyi,

c) İmza sahibi: Elektronik imza oluşturmak amacıyla bir imza oluşturma aracını kullanan gerçek kişiyi,

d) İmza oluşturma verisi: İmza sahibine ait olan, imza sahibi tarafından elektronik imza oluşturma amacıyla kullanılan ve bir eşi daha olmayan şifreler, kriptografik gizli anahtarlar gibi verileri,

e) İmza oluşturma aracı: Elektronik imza oluşturmak üzere, imza oluşturma verisini kullanan yazılım veya donanım aracını,

f) İmza doğrulama verisi: Elektronik imzayı doğrulamak için kullanılan şifreler, kriptografik açık anahtarlar gibi verileri,

g) İmza doğrulama aracı: Elektronik imzayı doğrulamak amacıyla imza doğrulama verisini kullanan yazılım veya donanım aracını,

h) Zaman damgası: Bir elektronik verinin, üretildiği, değiştirildiği, gönderildiği, alındığı ve / veya kaydedildiği zamanın tespit edilmesi amacıyla, elektronik sertifika hizmet sağlayıcısı tarafından elektronik imzayla doğrulanan kaydı,

ı) Elektronik sertifika: İmza sahibinin imza doğrulama verisini ve kimlik bilgilerini birbirine bağlayan elektronik kaydı,

j) Kurum: Telekomünikasyon Kurumunu,

ifade eder.

Part Two: Secure Electronic Signature and Certificate Services

Chapter One: Secure Electronic Signature, Secure Electronic Signature Creation and Verification Devices

Article 4Secure electronic signature

Link to this article ↗

A secure electronic signature is an electronic signature which:

a) Is uniquely linked to the signatory,

b) Is created with a secure electronic signature creation device kept under the sole control of the signatory,

c) Enables the identification of the signatory on the basis of a qualified electronic certificate,

d) Enables the detection of whether any subsequent change has been made to the signed electronic data,

(conditions which shall be met cumulatively).

Original Turkish text

MADDE 4 · Güvenli elektronik imza

Güvenli elektronik imza;

a) Münhasıran imza sahibine bağlı olan,

b) Sadece imza sahibinin tasarrufunda bulunan güvenli elektronik imza oluşturma aracı ile oluşturulan,

c) Nitelikli elektronik sertifikaya dayanarak imza sahibinin kimliğinin tespitini sağlayan,

d) İmzalanmış elektronik veride sonradan herhangi bir değişiklik yapılıp yapılmadığının tespitini sağlayan,

elektronik imzadır.

Article 5Legal effect and scope of application of the secure electronic signature

Link to this article ↗

A secure electronic signature shall produce the same legal effect as a handwritten signature.

Legal transactions which laws subject to an official form or a special ceremony, and security (guarantee) contracts other than bank letters of guarantee and surety bonds issued by insurance companies established in Türkiye, may not be executed with a secure electronic signature.

Original Turkish text

MADDE 5 · Güvenli elektronik imzanın hukukî sonucu ve uygulama alanı

Güvenli elektronik imza, elle atılan imza ile aynı hukukî sonucu doğurur.

Kanunların resmî şekle veya özel bir merasime tabi tuttuğu hukukî işlemler ile banka teminat mektupları ve Türkiye’de yerleşik sigorta şirketleri tarafından düzenlenen kefalet senetleri dışındaki teminat sözleşmeleri, güvenli elektronik imza ile gerçekleştirilemez.

Article 6Secure electronic signature creation devices

Link to this article ↗

Secure electronic signature creation devices are signature creation devices which ensure:

a) That the electronic signature creation data they generate are unique among themselves,

b) That the electronic signature creation data recorded on them can in no way be extracted from the device, and the confidentiality of such data,

c) That the electronic signature creation data recorded on them cannot be obtained or used by third parties, and that the electronic signature is protected against forgery,

d) That the data to be signed cannot be altered by anyone other than the signatory, and that such data can be seen by the signatory before the signature is created,

(as stated above).

Original Turkish text

MADDE 6 · Güvenli elektronik imza oluşturma araçları

Güvenli elektronik imza oluşturma araçları;

a) Ürettiği elektronik imza oluşturma verilerinin kendi aralarında bir eşi daha bulunmamasını,

b) Üzerinde kayıtlı olan elektronik imza oluşturma verilerinin araç dışına hiçbir biçimde çıkarılamamasını ve gizliliğini,

c) Üzerinde kayıtlı olan elektronik imza oluşturma verilerinin, üçüncü kişilerce elde edilememesini, kullanılamamasını ve elektronik imzanın sahteciliğe karşı korunmasını,

d) İmzalanacak verinin imza sahibi dışında değiştirilememesini ve bu verinin imza sahibi tarafından imzanın oluşturulmasından önce görülebilmesini,

sağlayan imza oluşturma araçlarıdır.

Article 7Secure electronic signature verification devices

Link to this article ↗

Secure electronic signature verification devices are signature verification devices which:

a) Display to the verifying person, without alteration, the data used for verification of the signature,

b) Execute the signature verification process reliably and with certainty and display the verification results to the verifying person without alteration,

c) Where necessary, ensure that the signed data are displayed reliably,

d) Reliably establish the accuracy and validity of the electronic certificate used for verification of the signature and display the results to the verifying person without alteration,

e) Display the identity of the signatory to the verifying person without alteration,

f) Enable the detection of changes that would affect the conditions relating to verification of the signature,

(as stated above).

Original Turkish text

MADDE 7 · Güvenli elektronik imza doğrulama araçları

Güvenli elektronik imza doğrulama araçları;

a) İmzanın doğrulanması için kullanılan verileri, değiştirmeksizin doğrulama yapan kişiye gösteren,

b) İmza doğrulama işlemini güvenilir ve kesin bir biçimde çalıştıran ve doğrulama sonuçlarını değiştirmeksizin doğrulama yapan kişiye gösteren,

c) Gerektiğinde, imzalanmış verinin güvenilir bir biçimde gösterilmesini sağlayan,

d) İmzanın doğrulanması için kullanılan elektronik sertifikanın doğruluğunu ve geçerliliğini güvenilir bir biçimde tespit ederek sonuçlarını değiştirmeksizin doğrulama yapan kişiye gösteren,

e) İmza sahibinin kimliğini değiştirmeksizin doğrulama yapan kişiye gösteren,

f) İmzanın doğrulanması ile ilgili şartlara etki edecek değişikliklerin tespit edilebilmesini sağlayan,

imza doğrulama araçlarıdır.

Chapter Two: Electronic Certificate Service Provider, Qualified Electronic Certificate and Foreign Electronic Certificates

Article 8Electronic certificate service provider

Link to this article ↗

Electronic certificate service providers are public institutions and organisations, and natural persons or legal persons governed by private law, that provide services relating to electronic certificates, time stamps and electronic signatures. An electronic certificate service provider shall commence its activities two months after the notification it makes to the Authority.

In its notification, the electronic certificate service provider shall demonstrate in detail that it fulfils the conditions relating to:

a) Using secure products and systems,

b) Conducting the service reliably,

c) Taking all kinds of measures to prevent the imitation and falsification of certificates,

(as listed above).

If the Authority determines that any of the above conditions is lacking or has not been fulfilled, it shall grant the electronic certificate service provider a period not exceeding one month to remedy such deficiencies, and shall suspend the activities of the electronic certificate service provider during that period. If the deficiencies are not remedied by the end of the period, it shall terminate the activities of the electronic certificate service provider. These decisions of the Authority may be objected to in accordance with the provisions of the second paragraph of Article 19.

The provisions of the paragraph above shall also apply where electronic certificate service providers cease to meet the conditions set out in this Article while their activities continue.

Electronic certificate service providers shall comply with the lower and upper limits of fees to be determined by the Authority.

Original Turkish text

MADDE 8 · Elektronik sertifika hizmet sağlayıcısı

Elektronik sertifika hizmet sağlayıcısı, elektronik sertifika, zaman damgası ve elektronik imzalarla ilgili hizmetleri sağlayan kamu kurum ve kuruluşları ile gerçek veya özel hukuk tüzel kişilerdir. Elektronik sertifika hizmet sağlayıcısı, Kuruma yapacağı bildirimden iki ay sonra faaliyete geçer.

Elektronik sertifika hizmet sağlayıcısı yapacağı bildirimde;

a) Güvenli ürün ve sistemleri kullanmak,

b) Hizmeti güvenilir bir biçimde yürütmek,

c) Sertifikaların taklit ve tahrif edilmesini önlemekle ilgili her türlü tedbiri almak,

ile ilgili şartları sağladığını ayrıntılı bir biçimde gösterir.

Kurum, yukarıdaki şartlardan birinin eksikliğini veya yerine getirilmediğini tespit ederse, bu eksikliklerin giderilmesi için, elektronik sertifika hizmet sağlayıcısına bir ayı geçmemek üzere bir süre verir, bu süre içinde elektronik sertifika hizmet sağlayıcısının faaliyetlerini durdurur. Sürenin sonunda eksikliklerin giderilmemesi halinde elektronik sertifika hizmet sağlayıcısının faaliyetine son verir. Kurumun bu kararlarına karşı 19 uncu maddenin ikinci fıkrası hükümleri gereğince itiraz edilebilir.

Elektronik sertifika hizmet sağlayıcılarının faaliyetlerinin devamı sırasında bu maddede gösterilen şartları kaybetmeleri hâlinde de yukarıdaki fıkra hükümleri uygulanır.

Elektronik sertifika hizmet sağlayıcıları, Kurumun belirleyeceği ücret alt ve üst sınırlarına uymak zorundadır.

Article 9Qualified electronic certificate

Link to this article ↗

A qualified electronic certificate shall contain:

a) A statement that the certificate is a "qualified electronic certificate",

b) The identity information of the certificate service provider and the name of the country in which it is established,

c) Identity information by which the signatory can be identified,

d) The signature verification data corresponding to the electronic signature creation data,

e) The start and end dates of the certificate's period of validity,

f) The serial number of the certificate,

g) Where the certificate holder acts on behalf of another person, information on such authority,

h) The professional or other personal information of the certificate holder, if the certificate holder so requests,

ı) Information on the conditions of use of the certificate, if any, and on the material limitations in the transactions in which it will be used,

j) The secure electronic signature of the certificate service provider verifying the information contained in the certificate,

(all of the above being mandatory).

Original Turkish text

MADDE 9 · Nitelikli elektronik sertifika

Nitelikli elektronik sertifikada;

a) Sertifikanın "nitelikli elektronik sertifika" olduğuna dair bir ibarenin,

b) Sertifika hizmet sağlayıcısının kimlik bilgileri ve kurulduğu ülke adının,

c) İmza sahibinin teşhis edilebileceği kimlik bilgilerinin,

d) Elektronik imza oluşturma verisine karşılık gelen imza doğrulama verisinin,

e) Sertifikanın geçerlilik süresinin başlangıç ve bitiş tarihlerinin,

f) Sertifikanın seri numarasının,

g) Sertifika sahibi diğer bir kişi adına hareket ediyorsa bu yetkisine ilişkin bilginin,

h) Sertifika sahibi talep ederse meslekî veya diğer kişisel bilgilerinin,

ı) Varsa sertifikanın kullanım şartları ve kullanılacağı işlemlerdeki maddî sınırlamalara ilişkin bilgilerin,

j) Sertifika hizmet sağlayıcısının sertifikada yer alan bilgileri doğrulayan güvenli elektronik imzasının,

bulunması zorunludur.

Article 10Obligations of the electronic certificate service provider

Link to this article ↗

The electronic certificate service provider shall be obliged:

a) To employ personnel of the qualifications required by the service,

b) Amended: 14/1/2016, Law No. 6661, Art. 7 To identify reliably the identity of the persons to whom it issues qualified certificates on the basis of official documents or remotely by means of the identity card of the Republic of Türkiye,

c) Where the certificate holder's authority to act on behalf of another person, or his or her professional or other personal information, is included in the certificate, to determine such information reliably on the basis of official documents as well,

d) Where the signature creation data are generated by the certificate service provider, or by the person requesting the certificate at premises belonging to the certificate service provider, to ensure the confidentiality of this process, or, where they are generated with devices supplied by the certificate service provider, to ensure the security of this process,

e) Amended: 14/1/2016, Law No. 6661, Art. 7 Without prejudice to the limitations provided for in laws, to inform the requesting person, before delivery of the certificate, of the characteristics relating to the use of the certificate, the conditions relating to the means of dispute resolution and the fact that a secure electronic signature is equivalent to a handwritten signature,

f) Amended: 14/1/2016, Law No. 6661, Art. 7 To inform the certificate holder not to allow others to use the signature creation data corresponding to the signature verification data contained in the certificate,

g) To retain all records relating to the services it provides for the period determined by regulation,

h) To notify the Authority and the electronic certificate holder of the situation at least three months before the date on which it will terminate its activities,

(as listed above).

The electronic certificate service provider may not take a copy of the signature creation data generated, nor may it store such data.

Added paragraph: 28/1/2021, Law No. 7263, Art. 11 Where the electronic certificate service provider has reliably identified remotely, by means of the identity card of the Republic of Türkiye, the identity information of the persons to whom it issues qualified certificates, it may reliably load the qualified certificate onto the identity card remotely.

Original Turkish text

MADDE 10 · Elektronik sertifika hizmet sağlayıcısının yükümlülükleri

Elektronik sertifika hizmet sağlayıcısı;

a) Hizmetin gerektirdiği nitelikte personel istihdam etmekle,

b) (Değişik: 14/1/2016-6661/7 md.) Nitelikli sertifika verdiği kişilerin kimliğini resmî belgelere göre veya Türkiye Cumhuriyeti kimlik kartı vasıtasıyla uzaktan güvenilir bir biçimde tespit etmekle,

c) Sertifika sahibinin diğer bir kişi adına hareket edebilme yetkisi, meslekî veya diğer kişisel bilgilerinin sertifikada bulunması durumunda, bu bilgileri de resmî belgelere dayandırarak güvenilir bir biçimde belirlemekle,

d) İmza oluşturma verisinin sertifika hizmet sağlayıcısı tarafından veya sertifika talep eden kişi tarafından sertifika hizmet sağlayıcısına ait yerlerde üretilmesi durumunda bu işlemin gizliliğini sağlamak veya sertifika hizmet sağlayıcısının sağladığı araçlarla üretilmesi durumunda, bu işleyişin güvenliğini sağlamakla,

e) (Değişik: 14/1/2016-6661/7 md.) Kanunlarda öngörülen sınırlamalar saklı kalmak üzere sertifikanın kullanımına ilişkin özellikler, uyuşmazlıkların çözüm yolları ile ilgili şartlar ve güvenli elektronik imzanın elle atılan imza ile eşdeğer olduğu hakkında talep eden kişiyi sertifikanın tesliminden önce bilgilendirmekle,

f) (Değişik: 14/1/2016-6661/7 md.) Sertifikada bulunan imza doğrulama verisine karşılık gelen imza oluşturma verisini başkasına kullandırmaması konusunda, sertifika sahibini bilgilendirmekle,

g) Yaptığı hizmetlere ilişkin tüm kayıtları yönetmelikle belirlenen süreyle saklamakla,

h) Faaliyetine son vereceği tarihten en az üç ay önce durumu Kuruma ve elektronik sertifika sahibine bildirmekle,

yükümlüdür.

Elektronik sertifika hizmet sağlayıcısı üretilen imza oluşturma verisinin bir kopyasını alamaz veya bu veriyi saklayamaz.

(Ek fıkra:28/1/2021-7263/11 md.) Elektronik sertifika hizmet sağlayıcısı, nitelikli sertifika verdiği kişilerin kimlik bilgilerini Türkiye Cumhuriyeti kimlik kartı vasıtasıyla uzaktan güvenilir bir biçimde tespit etmiş ise nitelikli sertifikayı kimlik kartına uzaktan güvenilir bir biçimde yükleyebilir.

Article 11Revocation of qualified electronic certificates

Link to this article ↗

The electronic certificate service provider shall immediately revoke the qualified electronic certificates it has issued in the event of:

a) A request by the holder of the qualified electronic certificate,

b) The discovery that the information in the database relating to the qualified electronic certificate it has provided is false or incorrect, or a change in such information,

c) Learning that the capacity to act of the holder of the qualified electronic certificate has been restricted, or of his or her bankruptcy, absence or death,

(any of the above circumstances).

The electronic certificate service provider shall establish a record which allows the exact time at which qualified electronic certificates were revoked to be determined and which third parties can access quickly and securely.

Where the electronic certificate service provider terminates its activities and the use of the qualified electronic certificates it has issued by another electronic certificate service provider cannot be ensured, it shall immediately revoke the qualified electronic certificates it has issued.

Where the activities of an electronic certificate service provider are terminated by the Authority, the Authority shall decide on the transfer of the qualified electronic certificates issued by the electronic certificate service provider whose activities have been terminated to another electronic certificate service provider, and shall announce the situation to the persons concerned.

The electronic certificate service provider may not revoke a qualified electronic certificate retroactively.

Original Turkish text

MADDE 11 · Nitelikli elektronik sertifikaların iptal edilmesi

Elektronik sertifika hizmet sağlayıcısı;

a) Nitelikli elektronik sertifika sahibinin talebi,

b) Sağladığı nitelikli elektronik sertifikaya ilişkin veri tabanında bulunan bilgilerin sahteliğinin veya yanlışlığının ortaya çıkması veya bilgilerin değişmesi,

c) Nitelikli elektronik sertifika sahibinin fiil ehliyetinin sınırlandığının, iflâsının veya gaipliğinin ya da ölümünün öğrenilmesi,

Durumunda vermiş olduğu nitelikli elektronik sertifikaları derhâl iptal eder.

Elektronik sertifika hizmet sağlayıcısı, nitelikli elektronik sertifikaların iptal edildiği zamanın tam olarak tespit edilmesine imkân veren ve üçüncü kişilerin hızlı ve güvenli bir biçimde ulaşabileceği bir kayıt oluşturur.

Elektronik sertifika hizmet sağlayıcısı, faaliyetine son vermesi ve vermiş olduğu nitelikli elektronik sertifikaların başka bir elektronik sertifika hizmet sağlayıcısı tarafından kullanımının sağlanamaması durumunda vermiş olduğu nitelikli elektronik sertifikaları derhâl iptal eder.

Elektronik sertifika hizmet sağlayıcısının faaliyetine Kurum tarafından son verilmesi halinde Kurum, faaliyetine son verilen elektronik sertifika hizmet sağlayıcısının vermiş olduğu nitelikli elektronik sertifikaların başka bir elektronik sertifika hizmet sağlayıcısına devredilmesine karar verir ve durumu ilgililere duyurur.

Elektronik sertifika hizmet sağlayıcısı geçmişe yönelik olarak nitelikli elektronik sertifika iptal edemez.

Article 12Protection of information

Link to this article ↗

The electronic certificate service provider:

a) May not request from the person requesting an electronic certificate any information other than the information necessary for issuing the electronic certificate, and may not obtain such information without the person's consent,

b) May not keep the certificate in environments accessible to third parties without the permission of the electronic certificate holder,

c) Shall prevent third parties from obtaining personal data without the written consent of the person requesting the electronic certificate. It may not transmit such information to third parties or use it for other purposes without the approval of the certificate holder.

Original Turkish text

MADDE 12 · Bilgilerin korunması

Elektronik sertifika hizmet sağlayıcısı;

a) Elektronik sertifika talep eden kişiden, elektronik sertifika vermek için gerekli bilgiler hariç bilgi talep edemez ve bu bilgileri kişinin rızası dışında elde edemez,

b) Elektronik sertifika sahibinin izni olmaksızın sertifikayı üçüncü kişilerin ulaşabileceği ortamlarda bulunduramaz,

c) Elektronik sertifika talep eden kişinin yazılı rızası olmaksızın üçüncü kişilerin kişisel verileri elde etmesini engeller. Bu bilgileri sertifika sahibinin onayı olmaksızın üçüncü kişilere iletemez ve başka amaçlarla kullanamaz.

Article 13Legal liability

Link to this article ↗

The liability of the electronic certificate service provider towards the electronic certificate holder shall be subject to the general provisions.

The electronic certificate service provider shall be obliged to compensate damage it causes to third parties through a breach of the provisions of this Law or of regulations issued on the basis of this Law. No obligation to pay compensation shall arise if the electronic certificate service provider proves that it was not at fault.

The electronic certificate service provider shall also be liable for the damage where the breach of obligation in question is based on the conduct of persons it employs, and the electronic certificate service provider may not be released from this liability by adducing exculpatory evidence of the kind provided for in Article 55 of the Code of Obligations.

Except for the limitations relating to use and material scope contained in the qualified electronic certificate, any condition that removes or limits the liability of the electronic certificate service provider towards third parties and towards the holder of the qualified electronic signature shall be invalid.

The electronic certificate service provider shall be obliged to take out certificate financial liability insurance for the purpose of covering damage arising from its failure to fulfil its obligations under this Law. The procedures and principles relating to the insurance shall be determined by a regulation to be issued by the Authority after obtaining the opinion of the Undersecretariat of Treasury.

The certificate financial liability insurance provided for in this Article shall be underwritten by insurance companies authorised to operate in the relevant branch in Türkiye. These insurance companies shall be obliged to underwrite certificate financial liability insurance. Insurance companies that fail to comply with this obligation shall be imposed an administrative fine of eight billion liras by the Undersecretariat of Treasury. The provisions of Article 18 shall apply to the collection of this fine and to the procedure for objecting to the fine.

The electronic certificate service provider shall be obliged to deliver the qualified electronic certificate to the electronic signature holder with insurance coverage.

Original Turkish text

MADDE 13 · Hukukî sorumluluk

Elektronik sertifika hizmet sağlayıcısının, elektronik sertifika sahibine karşı sorumluluğu genel hükümlere tâbidir.

Elektronik sertifika hizmet sağlayıcısı, bu Kanun veya bu Kanuna dayanılarak çıkarılan yönetmelik hükümlerinin ihlâli suretiyle üçüncü kişilere verdiği zararları tazminle yükümlüdür. Elektronik sertifika hizmet sağlayıcısı kusursuzluğunu ispat ettiği takdirde tazminat ödeme yükümlülüğü doğmaz.

Elektronik sertifika hizmet sağlayıcısı, söz konusu yükümlülük ihlâlinin istihdam ettiği kişilerin davranışına dayanması hâlinde de zarardan sorumlu olup, elektronik sertifika hizmet sağlayıcısı, bu sorumluluğundan, Borçlar Kanununun 55 inci maddesinde öngörülen türden bir kurtuluş kanıtı getirerek kurtulamaz.

Nitelikli elektronik sertifikanın içerdiği kullanım ve maddî kapsamına ilişkin sınırlamalar hariç olmak üzere, elektronik sertifika hizmet sağlayıcısının üçüncü kişilere ve nitelikli elektronik imza sahibine karşı sorumluluğunu ortadan kaldıran veya sınırlandıran her türlü şart geçersizdir.

Elektronik sertifika hizmet sağlayıcısı, bu Kanundan doğan yükümlülüklerini yerine getirmemesi sonucu doğan zararların karşılanması amacıyla sertifika malî sorumluluk sigortası yaptırmak zorundadır. Sigortaya ilişkin usul ve esaslar Hazine Müsteşarlığının görüşü alınarak Kurum tarafından çıkarılacak yönetmelikle belirlenir.

Bu maddede öngörülen sertifika malî sorumluluk sigortası Türkiye'de ilgili branşta çalışmaya yetkili olan sigorta şirketleri tarafından yapılır. Bu sigorta şirketleri sertifika malî sorumluluk sigortasını yapmakla yükümlüdürler. Bu yükümlülüğe uymayan sigorta şirketlerine Hazine Müsteşarlığınca sekizmilyar lira idarî para cezası verilir. Bu para cezasının tahsilinde ve cezaya itiraz usulünde 18 inci madde hükümleri uygulanır.

Elektronik sertifika hizmet sağlayıcısı, nitelikli elektronik sertifikayı elektronik imza sahibine sigorta ettirerek teslim etmekle yükümlüdür.

Article 14Foreign electronic certificates

Link to this article ↗

The legal effects of electronic certificates issued by an electronic certificate service provider established in a foreign country shall be determined by international agreements.

Where electronic certificates issued by an electronic certificate service provider established in a foreign country are accepted by an electronic certificate service provider established in Türkiye, such electronic certificates shall be deemed qualified electronic certificates. The electronic certificate service provider in Türkiye shall also be liable for damage arising from the use of such electronic certificates.

Original Turkish text

MADDE 14 · Yabancı elektronik sertifikalar

Yabancı bir ülkede kurulu bir elektronik sertifika hizmet sağlayıcısı tarafından verilen elektronik sertifikaların hukukî sonuçları milletlerarası anlaşmalarla belirlenir.

Yabancı bir ülkede kurulu bir elektronik sertifika hizmet sağlayıcısı tarafından verilen elektronik sertifikaların, Türkiye'de kurulu bir elektronik sertifika hizmet sağlayıcısı tarafından kabul edilmesi durumunda, bu elektronik sertifikalar nitelikli elektronik sertifika sayılır. Bu elektronik sertifikaların kullanılması sonucunda doğacak zararlardan, Türkiye'deki elektronik sertifika hizmet sağlayıcısı da sorumludur.

Part Three: Supervision and Penal Provisions

Article 15Supervision

Link to this article ↗

Supervision of the activities and transactions of electronic certificate service providers relating to the implementation of this Law shall be carried out by the Authority.

The Authority may audit electronic certificate service providers whenever it deems necessary. During the audit, electronic certificate service providers and the persons concerned shall be obliged to comply with requests by the officials authorised to conduct the audit for the submission of all kinds of books, documents and records, for entry into management premises, buildings and their annexes, for obtaining written and oral information, for taking samples and for auditing transactions and accounts.

Original Turkish text

MADDE 15 · Denetim

Elektronik sertifika hizmet sağlayıcılarının bu Kanunun uygulanmasına ilişkin faaliyet ve işlemlerinin denetimi Kurumca yerine getirilir.

Kurum, gerekli gördüğü zamanlarda elektronik sertifika hizmet sağlayıcılarını denetleyebilir. Denetleme sırasında, denetleme yapmaya yetkili görevliler tarafından her türlü defter, belge ve kayıtların verilmesi, yönetim yerleri, binalar ve eklentilerine girme, yazılı ve sözlü bilgi alma, örnek alma ve işlem ve hesapları denetleme isteminin elektronik sertifika hizmet sağlayıcıları ve ilgililer tarafından yerine getirilmesi zorunludur.

Article 16Unauthorised use of signature creation data

Link to this article ↗

Amended: 23/1/2008, Law No. 5728, Art. 525

Persons who, for the purpose of creating an electronic signature and without the consent of the person concerned, obtain, give, copy or recreate signature creation data or a signature creation device, and persons who create an unauthorised electronic signature using signature creation devices obtained without authorisation, shall be punished with imprisonment from one to three years and a judicial fine of not less than fifty days.

If the offences set out in the paragraph above are committed by employees of an electronic certificate service provider, these penalties shall be increased by up to one half.

Original Turkish text

MADDE 16 · İmza oluşturma verilerinin izinsiz kullanımı

(Değişik: 23/1/2008 – 5728/525 md.)

Elektronik imza oluşturma amacı ile ilgili kişinin rızası dışında; imza oluşturma verisi veya imza oluşturma aracını elde eden, veren, kopyalayan ve bu araçları yeniden oluşturanlar ile izinsiz elde edilen imza oluşturma araçlarını kullanarak izinsiz elektronik imza oluşturanlar bir yıldan üç yıla kadar hapis ve elli günden az olmamak üzere adlî para cezasıyla cezalandırılırlar.

Yukarıdaki fıkrada belirtilen suçlar elektronik sertifika hizmet sağlayıcısı çalışanları tarafından işlenirse bu cezalar yarısına kadar artırılır.

Article 17Forgery of electronic certificates

Link to this article ↗

Amended: 23/1/2008, Law No. 5728, Art. 526

Persons who create a wholly or partly false electronic certificate, or who imitate or falsify validly created electronic certificates, and persons who knowingly use such electronic certificates, shall be punished with imprisonment from two to five years and a judicial fine of not less than one hundred days.

If the offences set out in the paragraph above are committed by employees of an electronic certificate service provider, these penalties shall be increased by up to one half.

Original Turkish text

MADDE 17 · Elektronik sertifikalarda sahtekârlık

(Değişik: 23/1/2008 – 5728/526 md.)

Tamamen veya kısmen sahte elektronik sertifika oluşturanlar veya geçerli olarak oluşturulan elektronik sertifikaları taklit veya tahrif edenler ile bu elektronik sertifikaları bilerek kullananlar, iki yıldan beş yıla kadar hapis ve yüz günden az olmamak üzere adlî para cezasıyla cezalandırılır.

Yukarıdaki fıkrada belirtilen suçlar elektronik sertifika hizmet sağlayıcısı çalışanları tarafından işlenirse bu cezalar yarısına kadar artırılır.

Article 18Administrative fines

Link to this article ↗

Amended: 23/1/2008, Law No. 5728, Art. 527

An administrative fine shall be imposed by the Telecommunications Board, under this Law:

a) On an electronic certificate service provider that fails to fulfil any of the obligations under Article 10, from fifteen thousand Turkish Liras to thirty thousand Turkish Liras,

b) On an electronic certificate service provider that fails to fulfil any of the obligations under Article 11, from twelve thousand Turkish Liras to twenty thousand Turkish Liras,

c) On those who act in breach of the provisions of Article 12, from fifteen thousand Turkish Liras to thirty thousand Turkish Liras,

d) On an electronic certificate service provider that fails to fulfil the obligations under the fifth and seventh paragraphs of Article 13, from twelve thousand Turkish Liras to twenty thousand Turkish Liras,

e) On an electronic certificate service provider that acts in breach of the provisions of Article 15, from thirty thousand Turkish Liras to fifty thousand Turkish Liras,

(as set out above). The upper limit of the administrative fine to be imposed on the legal person concerned under the provisions of this Article shall be seventy-five thousand Turkish Liras.

Original Turkish text

MADDE 18 · İdarî para cezaları

(Değişik: 23/1/2008 – 5728/527 md.)

Bu Kanunun;

a) 10 uncu maddesindeki yükümlülüklerinden herhangi birini yerine getirmeyen elektronik sertifika hizmet sağlayıcısına onbeşbin Türk Lirasından otuzbin Türk Lirasına kadar,

b) 11 inci maddesindeki yükümlülüklerden herhangi birini yerine getirmeyen elektronik sertifika hizmet sağlayıcısına onikibin Türk Lirasından yirmibin Türk Lirasına kadar,

c) 12 nci maddesi hükümlerine aykırı hareket edenler hakkında onbeşbin Türk Lirasından otuzbin Türk Lirasına kadar,

d) 13 üncü maddesinin beşinci ve yedinci fıkralarındaki yükümlülükleri yerine getirmeyen elektronik sertifika hizmet sağlayıcısına onikibin Türk Lirasından yirmibin Türk Lirasına kadar,

e) 15 inci maddesi hükümlerine aykırı hareket eden elektronik sertifika hizmet sağlayıcısına otuzbin Türk Lirasından ellibin Türk Lirasına kadar,

idarî para cezası Telekomünikasyon Kurulu tarafından verilir. Bu madde hükümlerine göre ilgili tüzel kişi hakkında verilecek olan idarî para cezasının üst sınırı yetmişbeşbin Türk Lirasıdır.

Article 19Security measures specific to legal persons

Link to this article ↗

Amended: 23/1/2008, Law No. 5728, Art. 528

For the offences defined in this Law, security measures specific to legal persons shall be ordered against the legal persons concerned in accordance with the provision of Article 60 of the Turkish Criminal Code.

Where acts requiring an administrative fine are committed for the third time within three years, counting back from the date on which they were committed, the Authority shall decide to revoke the activity permit of the electronic certificate service provider legal person.

Original Turkish text

MADDE 19 · Tüzel kişilere özgü güvenlik tedbirleri

(Değişik: 23/1/2008 – 5728/528 md.)

Bu Kanunda tanımlanan suçlar dolayısıyla ilgili tüzel kişiler hakkında Türk Ceza Kanununun 60 ıncı maddesi hükmüne göre tüzel kişilere özgü güvenlik tedbirlerine hükmolunur.

İdarî para cezasını gerektiren eylemlerin işlendikleri tarihten itibaren geriye doğru üç yıl içinde üçüncü kez işlenmesi hâlinde Kurum tarafından elektronik sertifika hizmet sağlayıcısı tüzel kişinin faaliyet izninin iptaline karar verilir.

Part Four: Miscellaneous Provisions

Article 20Regulations

Link to this article ↗

Amended: 28/1/2021, Law No. 7263, Art. 12

The procedures and principles relating to the implementation of this Law shall be regulated by regulations to be issued by the Authority after obtaining the opinions of the relevant institutions and organisations.

Original Turkish text

MADDE 20 · Yönetmelik

(Değişik:28/1/2021-7263/12 md.)

Bu Kanunun uygulanmasına ilişkin usul ve esaslar, ilgili kurum ve kuruluşların görüşü alınarak Kurum tarafından çıkarılacak yönetmeliklerle düzenlenir.

Article 21Provisions not applicable to public institutions and organisations

Link to this article ↗

Amended: 28/1/2021, Law No. 7263, Art. 13

The provision of Article 19 of this Law shall not apply to public institutions and organisations that carry out the activity of providing electronic certificate services.

Original Turkish text

MADDE 21 · Kamu kurum ve kuruluşları hakkında uygulanmayacak hükümler

(Değişik:28/1/2021-7263/13 md.)

Bu Kanunun 19 uncu maddesi hükmü, elektronik sertifika hizmet sağlama faaliyeti yerine getiren kamu kurum ve kuruluşları hakkında uygulanmaz.

Relates to the Code of Obligations No. 818 dated 22.4.1926 and has been incorporated into the relevant place therein.

Original Turkish text

MADDE 22

(22.4.1926 tarihli ve 818 sayılı Borçlar Kanunu ile ilgili olup yerine işlenmiştir.)

Relates to the Code of Civil Procedure No. 1086 dated 18.6.1927 and has been incorporated into the relevant place therein.

Original Turkish text

MADDE 23

(18.6.1927 tarihli ve 1086 sayılı Hukuk Usulü Muhakemeleri Kanunu ile ilgili olup yerine işlenmiştir.)

Relates to the Radio Law No. 2813 dated 5.4.1983 and has been incorporated into the relevant place therein.

Original Turkish text

MADDE 24

(5.4.1983 tarihli ve 2813 sayılı Telsiz Kanunu ile ilgili olup yerine işlenmiştir.)

Additional Article 1Electronic seal

Link to this article ↗

Added: 28/1/2021, Law No. 7263, Art. 14

An electronic seal is electronic data that is attached to other electronic data or logically associated with electronic data and used for the purpose of verifying the information of the seal holder.

Electronic seal holders are the public institutions and organisations, public administrations, professional organisations having the status of public institutions and their higher organisations, public and private law legal persons, judicial authorities and notary offices that create the electronic seal.

An electronic seal is an evidentiary record that guarantees that the electronic document or data was created by the seal holder, as well as the origin and integrity of the document or data.

An electronic seal has the same legal nature as any kind of physical seal, including an official seal.

Persons who, for the purpose of creating an electronic seal and without the consent or request of the seal holder concerned, obtain, give, copy or recreate seal creation data or a seal creation device, and persons who create an unauthorised electronic seal using seal creation devices obtained without authorisation, shall be punished with imprisonment from one to three years and a judicial fine of not less than fifty days. If the offence is committed by employees of an electronic certificate service provider, these penalties shall be increased by up to one half.

The provisions in laws relating to electronic signatures shall also apply by analogy to electronic seals.

The rights, powers and obligations of electronic certificate service providers relating to electronic signatures under laws shall also apply to electronic seals. The administrative fines specified in Article 18 shall be applied to electronic certificate service providers that act in breach of these obligations.

Original Turkish text

EK MADDE 1 · Elektronik mühür

(Ek:28/1/2021-7263/14 md.)

Elektronik mühür, başka bir elektronik veriye eklenen veya elektronik veriyle mantıksal bağlantısı bulunan ve mühür sahibinin bilgilerini doğrulama amacıyla kullanılan elektronik veridir.

Elektronik mühür sahibi; elektronik mührü oluşturan kamu kurum ve kuruluşları, kamu idareleri, kamu kurumu niteliğindeki meslek kuruluşları ve üst kuruluşları, kamu ve özel hukuk tüzel kişileri ile yargı mercileri ve noterliklerdir.

Elektronik mühür, elektronik belgenin veya verinin mühür sahibi tarafından oluşturulduğunu, belgenin veya verinin kaynağını ve bütünlüğünü garanti eden delil kaydıdır.

Elektronik mühür, resmî mühür dâhil her türlü fiziki mühür ile aynı hukuki niteliği haizdir.

Elektronik mühür oluşturma amacı ile ilgili mühür sahibinin rızası veya talebi dışında; mühür oluşturma verisi veya mühür oluşturma aracını elde eden, veren, kopyalayan ve bu araçları yeniden oluşturanlar ile izinsiz elde edilen mühür oluşturma araçlarını kullanarak izinsiz elektronik mühür oluşturanlar bir yıldan üç yıla kadar hapis ve elli günden az olmamak üzere adlî para cezasıyla cezalandırılırlar. Suçun elektronik sertifika hizmet sağlayıcısı çalışanları tarafından işlenmesi halinde, bu cezalar yarısına kadar artırılır.

Kanunlarda yer alan elektronik imzaya ilişkin hükümler, kıyasen elektronik mühür hakkında da uygulanır.

Elektronik sertifika hizmet sağlayıcılarının kanunlarda yer alan elektronik imza ile ilgili hak, yetki ve yükümlülükleri, elektronik mühür hakkında da uygulanır. Bu yükümlülüklere aykırı hareket eden elektronik sertifika hizmet sağlayıcıları hakkında 18 inci maddede belirtilen idari para cezaları uygulanır.

Additional Article 2Website authentication certificate and other electronic certificates

Link to this article ↗

Added: 28/1/2021, Law No. 7263, Art. 15

A website authentication certificate is an electronic record that links a website with the information of the natural or legal person who owns that website.

Other electronic certificates using similar infrastructure are certificates generated by electronic certificate service providers by means of public key infrastructure for use for purposes such as encrypting electronic data or determining the integrity, non-repudiation and origin of data.

The provisions of laws concerning electronic signatures shall also apply, by analogy, to website authentication certificates and other electronic certificates using similar infrastructure.

The rights, powers and obligations of electronic certificate service providers relating to electronic signatures under laws shall also apply with respect to website authentication certificates and other electronic certificates using similar infrastructure. The administrative fines specified in Article 18 shall be imposed on electronic certificate service providers acting in breach of these obligations.

Original Turkish text

EK MADDE 2 · İnternet sitesi kimlik doğrulama sertifikası ve diğer elektronik sertifikalar

(Ek:28/1/2021-7263/15 md.)

İnternet sitesi kimlik doğrulama sertifikası, bir internet sitesi ile bu sitenin sahibi olan gerçek veya tüzel kişinin bilgilerini birbirine bağlayan elektronik kayıttır.

Benzer altyapıyı kullanan diğer elektronik sertifikalar, elektronik veriyi şifreleme veya verinin bütünlüğünü, inkâr edilemezliğini ve kaynağını belirleme gibi amaçlarla kullanılmak üzere elektronik sertifika hizmet sağlayıcıları tarafından açık anahtar altyapısı vasıtasıyla üretilen sertifikalardır.

Kanunlarda yer alan elektronik imzaya ilişkin hükümler, kıyasen internet sitesi kimlik doğrulama sertifikası ve benzer altyapıyı kullanan diğer elektronik sertifikalar hakkında da uygulanır.

Elektronik sertifika hizmet sağlayıcılarının kanunlarda yer alan elektronik imza ile ilgili hak, yetki ve yükümlülükleri, internet sitesi kimlik doğrulama sertifikası ve benzer altyapıyı kullanan diğer elektronik sertifikalar hakkında da uygulanır. Bu yükümlülüklere aykırı hareket eden elektronik sertifika hizmet sağlayıcıları hakkında 18 inci maddede belirtilen idari para cezaları uygulanır.

Article 25Entry into force

Link to this article ↗

This Law shall enter into force six months after the date of its publication.

Original Turkish text

MADDE 25 · Yürürlük

Bu Kanun yayımı tarihinden altı ay sonra yürürlüğe girer.

Article 26Execution

Link to this article ↗

The provisions of this Law shall be executed by the Council of Ministers.

Original Turkish text

MADDE 26 · Yürütme

Bu Kanun hükümlerini Bakanlar Kurulu yürütür.

No article matches your search.

Unofficial translation for information only. The Turkish text published in the Official Gazette is the only authoritative version. This page is not legal advice.