Abdullah Bozkurt/Stockholm
Turkey has transferred far-reaching powers over wiretapping, internet access, communications infrastructure, online censorship and digital traffic from the country’s telecommunications regulator to the executive-controlled Cyber Security Presidency (Siber Güvenlik Başkanlığ), a sweeping restructuring that is designed to further empower President Recep Tayyip Erdogan and institutionalize censorship and digital surveillance under the guise of national security.
The changes were rushed through parliament and buried in a sprawling omnibus bill, Law No. 7590, which bundled together a wide range of unrelated measures from entirely different policy areas. The law was adopted on July 24, 2026, and published in the Official Gazette on July 31. Along with provisions dealing with matters as disparate as taxation, nuclear energy, education, transportation and postal services, the legislation fundamentally restructures the architecture through which the Turkish government manages and controls the internet, communications infrastructure and wiretapping-related authorities.
At the heart of the overhaul is a transfer of key powers previously exercised by the Information and Communication Technologies Authority (Bilgi Teknolojileri ve İletişim Kurumu, BTK), a regulatory body, to the Cyber Security Presidency, an institution directly embedded in Turkey’s executive-centered national security apparatus since it was established in January 2025 by a decree from Erdogan himself. .
The government’s own parliamentary justification leaves little doubt about the scale of the shift. It describes cybersecurity as no longer merely a technical issue but a matter of “digital sovereignty” and says powers concerning domain-name and internet infrastructure management as well as the detection and analysis of communications are to be concentrated under the Cyber Security Presidency. According to the justification, this consolidation is intended to bring together technical capability, cyberthreat intelligence and regulatory functions under one roof.
That language goes considerably beyond the conventional task of protecting computer networks against hackers. Under the new arrangement an agency established to counter cybersecurity threats will simultaneously acquire significant powers affecting judicial proceedings, prosecutorial investigations, domestic internet access, censorship decisions, communications analysis and the technical infrastructure used for interception and wiretapping.
A newly inserted Article 60/A of the Electronic Communications Law authorizes the Cyber Security Presidency to determine “measures” in urgent cases and allow it to act either on its own initiative or following a request from Turkey’s security or intelligence agencies.
Text of the new law that grants the Cyber Security Presidency sweeping powers over citizens’ access to internet sites, digital surveillance and wiretapping:
Once an order is issued, telecommunications operators, internet access providers, data centers, content providers and hosting companies are required to comply immediately and no later than two hours after notification.
The decision is then submitted to a judge within 24 hours. The judge has another 48 hours to rule, failing which the administrative measure automatically expires. The system therefore permits the government to impose the restriction first and obtain judicial authorization afterward.
A corruption story, opposition campaign, investigative report or politically sensitive social media post can lose most of its public impact during the period in which the administrative restriction remains in force. A court decision issued after the news cycle has passed may be incapable of repairing the damage.
Given the Erdogan government’s extensive control over the judiciary, there is little prospect that such administrative measures will be subjected to genuinely independent judicial scrutiny. In practice Turkish judges have repeatedly rubber-stamped similar government-imposed restrictions in the past, raising serious doubts about whether the nominal requirement for subsequent judicial review provides any meaningful safeguard against abuse.
The most significant legal ambiguity lies in the legislation’s use of the word “measure.” The law does not exhaustively define what interventions the Cyber Security Presidency may order under that authority. It does not clearly enumerate the technical measures available nor precisely establish their scope or limits.
That omission is particularly important because restrictions on constitutional rights are normally supposed to be foreseeable. Citizens, journalists, publishers and communications companies should be able to determine from the legislation what the state is authorized to do and under what circumstances.
Instead, the administration is given substantial discretion both to determine when intervention is necessary and to decide what form that intervention should take. These concerns were explicitly recorded in the Turkish parliament’s own committee report during consideration of the draft bill on July 14, yet they did not result in meaningful amendments to narrow the powers or introduce additional safeguards before the legislation was enacted.

The report said the scope and limits of the contemplated measures should be more clearly established and that criteria specifying the type and framework of permissible intervention should be concretely written into the law in accordance with the principle of legal certainty.
Even more significant, the report recorded concern that the government was eliminating the existing legal basis for bandwidth throttling and replacing it with a broadly defined and potentially open-ended power.
According to the report, abolishing the existing statutory basis for bandwidth throttling and substituting a measure whose boundaries were unclear could weaken freedom of expression and communication as well as safeguards for judicial review. It therefore stated that the criteria under which fundamental rights could be restricted should be explicitly established in legislation.
Under the previous framework, bandwidth throttling had an identifiable statutory basis. The legislation removes that provision while putting an unspecified authority to determine measures in the hands of the Cyber Security Presidency.
The government’s description of the change as a cybersecurity reorganization also understates the range of functions involved. The parliamentary report makes clear that the transfer goes far beyond managing domain names or protecting critical networks.
Among the functions being transferred from the BTK to the Cyber Security Presidency are responsibilities for implementing access-blocking decisions, executing content-removal orders, handling procedures involving designated catalog crimes and privacy violations and providing the technical capacity required for legally authorized interception and intervention — in practical terms, the wiretapping and communications-interception capabilities used in criminal investigations.
Those functions, along with corresponding IT systems, data centers, infrastructure and personnel, are being transferred from the telecommunications regulator to the cybersecurity agency. The transfer therefore creates an institution positioned at the intersection of cyber defense, censorship, telecommunications infrastructure, communications analysis and surveillance capabilities.

This is not merely a bureaucratic reassignment of cybersecurity personnel, as the government has portrayed it. Rather, it transfers some of the state’s most consequential powers over the domestic digital environment from an institution formally established as a telecommunications regulator to a security-oriented body with a much broader national security mandate.
The distinction between cybersecurity and surveillance is therefore becoming increasingly blurred. The legislation separately changes the definition of internet traffic information. Previously referring to “port information,” the definition is expanded to specify source and destination port information. Port information does not itself disclose the contents of a person’s communication, but it provides more granular metadata concerning how a device communicates with particular digital services.
When combined with other identifying and connection records, such metadata can potentially provide detailed insight into users’ online activity. The significance of metadata is often underestimated precisely because it does not contain the message, article or conversation itself.
Aggregated connection information can nevertheless reveal which services a person uses, when connections occurred and how different online activities relate to one another. The concern therefore is not merely whether the state can read what a person says but how comprehensively it can reconstruct the digital trail surrounding that person’s activities.

The parliamentary report further states that responsibility for providing the technical means necessary for lawful interception and intervention — commonly referred to as wiretapping — is among the functions being transferred from the BTK to the Cyber Security Presidency.
This means the same presidency will increasingly combine cybersecurity intelligence, communications-related infrastructure, implementation of internet restrictions and technical capabilities supporting lawful interception. Such concentration of functions creates a powerful centralized structure with unprecedented visibility over and leverage across Turkey’s digital communications ecosystem.
This is not the first time Erdogan has tried to control wiretapping authorities. Turkey previously used the Telecommunications Communication Presidency (Telekomünikasyon İletişim Başkanlığı, TİB) as a specialized technical intermediary for interception requests. Police, the National Intelligence Organization (MİT) and the gendarmerie would first obtain the required authorization from courts and then rely on the technical infrastructure controlled by TİB to implement the interception.
TİB used to verify whether a warrant existed and complied with applicable laws before allowing its infrastructure to be used for wiretapping as part of a criminal investigation. However after Erdogan was incriminated in massive corruption scandals in 2013 along with his family members and political and business associates, he disbanded TIB and replaced it with the BTK, putting a trusted man in charge of the BTK so that he could prevent confidential investigations into his unlawful conduct.
Nevertheless the BTK remained institutionally separate from the presidency, and law enforcement agencies and intelligence service can still independently use the BTK to wiretap targets. The latest restructuring removes that intermediary role from the BTK and places the relevant functions inside the Cyber Security Presidency, which is directly tied to the presidential hierarchy.
The significance is therefore broader than a change in which a government office maintains telecommunications equipment. In this new environment police, MİT and the gendarmerie may still initiate investigations and obtain the necessary legal authorization, but the technical implementation of interception will now depend on infrastructure controlled by an institution under the presidency.
That arrangement raises an additional concern that goes beyond ordinary privacy questions: Routing technical interception through a presidency-controlled institution could give the presidential hierarchy visibility into surveillance targets sought by the police, gendarmerie and even MİT. If so, investigations involving politically powerful figures could become known outside the investigative chain before or while they are being conducted. This weakens the operational autonomy of security institutions when investigations involve members of the governing elite.
In other words routing surveillance infrastructure through an Erdogan-controlled institution would significantly reduce the ability of prosecutors, police and intelligence officials to initiate or pursue sensitive investigations without the presidency becoming aware of them. It would effectively create an early-warning system for Erdogan, allowing him to know who is being investigated and for what reason, even in remote provinces, and giving the presidential apparatus an early opportunity to intervene, obstruct, redirect or otherwise shape an investigation according to political priorities.

The identity of the official placed at the center of the new structure adds another political dimension. Cyber Security President Ümit Önal built much of his career in the media and telecommunications sectors, including positions at the hard-line Islamist Kanal 7 network and the Erdogan-family-owned ATV channel. When the government seized the Koza İpek Media Group, then one of Turkey’s largest media conglomerates, in 2015 on what critics described as fabricated criminal charges, Önal was among the trustees appointed by the government to take control of the media empire.
The restructuring therefore involves not only a profound institutional shift but also personnel choices that reflect the increasingly tight grip Erdogan has established over the government’s surveillance, communications-monitoring and wiretapping capabilities.
With this new law, the BTK’s existing cybersecurity-related systems and infrastructure worth some 30 billion Turkish lira will be transferred to the new presidency. As a result, the Cyber Security Presidency is inheriting substantial state infrastructure that has already been developed to manage and monitor Turkey’s telecommunications and internet environment. The legislation provides for the transfer of information systems, data centers, equipment, property and relevant personnel.
But the same transfer does not apply to personnel. The new legislation notes that BTK personnel are not automatically transferred. Existing employees may request reassignment, but the Cyber Security Presidency must approve them. It also says the new presidency may employ contracted experts in numbers determined by the president, with qualifications and appointment conditions set by the Cyber Security Board, all of which means that the new agency will select a fresh, politically trusted staff rather than simply inheriting the BTK’s established workforce
Critics also objected to the way such consequential changes were legislated. The cybersecurity provisions were inserted into a sprawling omnibus package involving numerous unrelated subjects ranging from pensions and private schools to tourism, postal workers, aviation, taxes and nuclear energy. The parliamentary committee report itself records complaints that putting measures involving multiple specialized fields into the same bill undermined the efficiency and quality of legislative scrutiny.
It specifically notes that subjects requiring specialist expertise including cybersecurity would have benefited from first being considered by the relevant specialist parliamentary committes. The opposition argued that combining unrelated matters weakened parliamentary specialization and reduced the ability of lawmakers and specialist committees to properly scrutinize complex legislation.
Instead the bill was only debated at the Planning and Budget Committee, with the opposition motions to send specialized provisions to the appropriate committee for further consideration rejected by Erdogan’s ruling bloc.
Turkey has now transformed cybersecurity from a shield against external threats into an increasingly powerful instrument for controlling the digital space occupied by its own citizens and exerting undue influence over criminal investigations in which wiretapping, communications interception and digital surveillance are employed as investigative tools.










