Türkiye’s digital regulatory map is being redrawn. Law No. 7590, published in the Official Gazette on 31 July 2026 (text), slips a heavy technology chapter in among pension and tax measures: the Cybersecurity Presidency’s powers expand, a set of authorities including internet domain names transfers from the ICTA, and a new urgent-measures mechanism arrives with a two-hour implementation window. This piece collects the changes and what is worth doing now.
Where the Presidency came from
The amendment continues a run of centralisation. The Presidency was established on 8 January 2025 by Presidential Decree No. 177 and placed on a statutory footing by Cybersecurity Law No. 7545, in force since 19 March 2025. On 28 March 2025 the Digital Transformation Office was abolished, with parts of the digital government remit passing to the Presidency, and at the first Cybersecurity Board meeting on 5 May 2026 fifteen sectors were designated critical infrastructure. The omnibus is, for now, the latest link in that chain.
The amendment in five headings
| Heading | Substance |
|---|---|
| Domain names | Strategy, policy and regulatory authority over internet domain names moves from the ICTA to the Presidency |
| Urgent measures | Where delay would be detrimental, the Presidency may order measures; operators, access providers, data centres, content and hosting providers must implement within 2 hours. Orders go to a criminal judgeship of peace within 24 hours and lapse automatically if no ruling comes within 48 |
| Fines | TRY 20,000 to 100,000 per violation for failures to comply |
| Consolidation | Powers over domain name management and communications detection and analysis are gathered in the Presidency across the Police Powers Law, Law No. 5651, the Electronic Communications Law and Law No. 7545 |
| Transition | ICTA assets, IT infrastructure and data centres transfer within 3 months; ICTA regulations stay in force until secondary legislation arrives, and references to the ICTA are read as the Presidency |
The startup question: the two-hour rule
The most operational line in the list is the urgent-measures mechanism. The circle of addressees is wide and includes data centres, hosting and content providers. Two hours does not care about office hours or on-call rosters; for a team that has not worked out in advance which channel an order arrives through, who sees it and how it is technically executed, the deadline is unmeetable even on paper. The safeguards cut both ways: the 24-hour judicial submission and the 48-hour automatic lapse build court review into the mechanism itself.
The second question is a change of counterpart: transferring supervision of the new gaming regime under Law No. 5651 and the social network obligations to the Presidency is on the table. Who your regulator is determines which secondary legislation reaches you and who you talk to; through this transition both institutions will need watching.
Who is directly caught?
The urgent-measures addressees are listed: telecom operators, access providers, data centres, content providers and hosting providers. The definitions are familiar from Law No. 5651 practice, and any SaaS product that lets users host content sits potentially within the hosting circle. Companies in the fifteen critical infrastructure sectors already carry Law No. 7545 obligations.
When does it enter into force?
The law was published on 31 July 2026 and the three-month transfer calendar is running. The real intensity of enforcement will be set by the Presidency’s secondary legislation. On the access-blocking side there is a second new threshold: by decision of the Council of Judges and Prosecutors, applications under Law No. 5651 go to specialised criminal judgeships of peace in larger courthouses as of 1 August.
Where to start
Three preparations can begin today: identify the official channels through which orders would reach you and set up a contact point reachable around the clock; write the runbook of technical actions executable within two hours, from access blocking to log delivery and traffic redirection; and check the compliance windows your infrastructure providers commit to in their contracts. When an order knocks, do not be reading the mechanism for the first time that day.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
Health AI: Medical Device or Wellness App? The Two-Track Map for Digital Health Startups
July 24, 2026Türkiye Writes Gaming into Law No. 5651: A Guide to the New Platform Regime
August 4, 2026The CASP Licence in Türkiye: An Application Guide in Build Order (Law 7518 / CMB III-35/B.1)
August 4, 2026Tax Due Diligence in Türkiye: What Buyers Check and How Sellers Prepare
August 3, 2026AI in Advertising Is Now a Disclosure Question in Türkiye: The Targeted Advertising and AI Rules in Force Since 1 August
August 3, 2026When the AI Acts for You: Agents, Authority and Who Bears the Mistake
July 31, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →US Company Formations & Flip-Ups
Delaware C-Corp, flip-up structures, SAFE/convertible notes, 83(b).
View service →Startup Law
Incorporation, founder agreements, ESOP, term sheets, regulatory matters.
View service →