Unauthorised disclosure of identity details, customer records or health information may raise criminal liability as well as data protection concerns. Article 136 of the Turkish Criminal Code concerns unlawful disclosure, dissemination or acquisition of personal data. The information, method, legal basis and intent require separate examination.
Conduct and personal data
Acquiring data unlawfully, giving it to another person and disseminating it are alternative forms of conduct. All three need not occur together. Initial permission to access information does not automatically authorise subsequent disclosure.
Information relating to an identified or identifiable individual may constitute personal data, including contact details, attributable financial records and health information. Public availability does not create unlimited permission to reuse it. Equally, a data protection violation does not automatically establish every element of a crime.
Unlawfulness and intent
The legal basis and scope of access or disclosure must be examined. Consent for a specific transaction does not necessarily cover a different purpose. Statutory powers and obligations may also provide a legal basis. A data leak alone does not establish the responsibility of every employee: access permissions, responsibilities, intent and attributable conduct must be investigated.
Penalties and aggravating circumstances
Article 136(1) prescribes imprisonment of two to four years for the basic offence. Under Article 137, the sentence is increased by one half where a public official abuses powers conferred by office or an offender takes advantage of facilities provided by a profession or trade. Occupational status alone is insufficient; the relevant connection must be established.
This overview is limited to the basic offence and Article 137. Special recording categories, sentence enforcement, suspension and other sentencing mechanisms require separate case-specific and legislative examination.
Complaint and limitation
Under Article 139, prosecution is not dependent on a victim’s complaint. Prosecutors may act on learning of the suspected offence. Withdrawing a report does not, by itself, terminate proceedings. This does not permit proceedings indefinitely: limitation depends on legal classification, dates and relevant procedural events.
Evidence and investigation
Identify what was disclosed, when, by whom and to which recipients. Preserve original messages, links, account identifiers, timestamps and correspondence. Screenshots may require corroboration. Workplace access logs, export records and permissions can be requested through competent authorities. Do not break into accounts or republish exposed information to gather evidence.
Criminal proceedings and data protection remedies
Criminal proceedings examine individual liability, while data protection proceedings concern the controller’s activities and obligations. A prior Board decision is not required to approach prosecution authorities.
For a complaint to the Board, an application to the controller is normally required first. The controller must respond within 30 days. Following rejection, an inadequate response or no response, consider the 30-day period from learning of the response and the overall 60-day period from the application. The calculation depends on whether and when a response was received.
Compensation may also be available where its conditions are met. Criminal, administrative and civil remedies differ; commencing one does not guarantee success in another.
Frequently asked questions
Can disclosure to one person be sufficient?
Yes. Giving data to another person is covered without widespread publication, but unlawfulness and all other elements still require examination.
Does workplace access authorise sharing?
No. Access permission and disclosure permission are distinct. Work-related access does not automatically authorise personal use or disclosure to an unauthorised recipient.
Does deleting a post erase liability?
Removal may reduce the consequences but does not automatically erase completed conduct. Its effect depends on the case.
Does every photograph or message fall under Article 136?
No. Depending on the content and circumstances, privacy or confidentiality of communications provisions may instead be relevant. The factual account and evidence matter more than selecting one statutory provision.
Official sources and scope
Reviewed on 19 September 2026. Articles 136(1), 137 and 139 were checked against the Personal Data Protection Authority’s March 2025 Implementation Guide, pages 146–147. Administrative remedies were checked against its Right to Complaint guidance and June 2025 publication on data subjects’ remedies. This states the accessible source coverage, not a guarantee of an exhaustive legislative update search. This article is general information, not individual advice or a guarantee of outcome.

