Turkey autonomous vehicle data policy

Turkey Folds Vehicle Cybersecurity Into Registration Law, Then Gives Automakers 13 Days to Comply

A June 2026 gazette amendment ties car registration to software-update and cybersecurity compliance, with almost no transition period.

Turkey's Vehicle Software Mandate, By the Numbers People of Internet Research · Turkey 13 days Compliance window Gazette No. 33290 entered into for… M, N, O Vehicle categories covered Passenger cars, buses, vans, truck… ~19 months Months since ADS type-approval rule Turkey's Dec 1, 2024 autonomous-dr… peopleofinternet.com
Turkey's Vehicle Software Mandate, By … People of Internet Research · Turkey 13 days Compliance window M, N, O Vehicle categories cover… ~19 months Months since ADS type-approval ru… peopleofinternet.com

Key Takeaways

A registration rule becomes a cybersecurity mandate

On June 24, 2026, Turkey's Ministry of Industry and Technology published an amendment to its motor-vehicle type-approval regulation — the rule that implements EU Regulation 2018/858 domestically — in Official Gazette No. 33290. The amendment does two things at once. First, it digitizes the conformity certificate that every new vehicle needs to be registered: manufacturers must now transmit certificates electronically, in XML format, through the Vehicle Registry and Registration System directly to the Türkiye Noterler Birliği (Turkish Union of Notaries), replacing paper documents. Second, and more consequentially, it makes that registration conditional on cybersecurity and software-update compliance. Article 2 of the amendment states that from July 7, 2026, M-category (passenger cars, buses) and N-category (vans, trucks) vehicles that don't meet software-update requirements cannot be registered, sold, or put into traffic; O-category vehicles (trailers, semi-trailers) face equivalent restrictions on production (Official Gazette No. 33290; Hürriyet Daily News).

The gap between publication and enforcement is 13 days.

Building on a year-and-a-half-old foundation

This isn't Turkey's first move into vehicle software governance. In December 2024, the same ministry published the country's first type-approval regulation for autonomous driving systems (ADS), covering M- and N-category vehicles equipped with ADS for designated-area transport, fixed-route operation, and autonomous parking (Official Gazette No. 32739, in force December 1, 2024). That rule required manufacturers to assign a software version identification number (SWIN) to each ADS configuration and to collect in-service monitoring data — evidence of how the system performs in the field — as a condition of type approval (Official Gazette No. 32739; Pekin Bayar Mizrahi). The June 2026 amendment extends that same logic — software identity, traceability, continuous compliance — from a narrow ADS type-approval niche to the entire mass-market vehicle fleet, and links it to the one gate every car in Turkey has to pass through: registration.

Read together, the two rules describe a deliberate strategy rather than a one-off. Turkey is building a data and software-governance backbone for its vehicle fleet, using type-approval and registration law as the enforcement lever, roughly 19 months apart.

The case for it

The strongest argument for this rule is straightforward: connected and software-defined vehicles are now genuine attack surfaces, and the international regulatory baseline already treats cybersecurity and software-update management as type-approval requirements, not optional extras. UN Regulation No. 155 requires a Cybersecurity Management System and UN Regulation No. 156 requires a Software Update Management System as preconditions for vehicle type approval across the EU, UK, Japan, and South Korea; manufacturers who don't comply lose the ability to get new vehicle types approved in those markets at all. A car that can't receive a verified, tamper-resistant software update is a car that stays vulnerable to a known exploit indefinitely — that's not a hypothetical, it's the exact failure mode CSMS/SUMS requirements were written to close. Since Turkish type-approval law already tracks EU Regulation 2018/858, extending it to cover software and cybersecurity keeps Turkish vehicles fungible with EU-approved ones and avoids creating a bespoke, costly parallel compliance track for manufacturers who already build to the UN baseline for European sale. Digitizing the conformity certificate, similarly, is a defensible efficiency move — it closes a paper-based vector for fraud in vehicle registration that has nothing to do with cybersecurity policy per se but benefits from riding the same reform.

Where it goes wrong

The problem isn't the substance — it's the sequencing. The EU phased UN R155/R156 in over roughly two years (mandatory for new vehicle types from July 2022, extended to all new vehicles by July 2024), giving manufacturers a runway to build cybersecurity management systems, get them audited, and integrate software-update pipelines. Turkey's amendment gives manufacturers 13 days between gazette publication and enforcement. That is not a compliance window; it's a rounding error. A regulation of this technical weight — cybersecurity management systems, software-update management systems, digital certificate transmission through a notary network that itself has to be ready to receive machine-readable XML at scale — cannot be safely stood up in under two weeks. The more likely outcomes are either de facto non-enforcement while the market quietly catches up, or real disruption to new-vehicle registration for manufacturers who were compliant with EU rules on paper but hadn't mapped that compliance onto Turkey's specific transmission and certification pathway in time.

A compressed timeline also has a distributive effect regulators should reckon with: it favors large multinational OEMs who already run CSMS/SUMS programs for EU sale and can flip a switch, while penalizing smaller domestic assemblers and importers who don't have that infrastructure sitting ready. That's a real competition question, not a technicality.

What's still missing

Neither the June 2026 amendment nor the December 2024 ADS rule, as published, spells out how the vehicle telemetry, SWIN records, and in-service monitoring data now flowing to the Vehicle Registry interact with Turkey's data protection authority, KVKK, which has its own jurisdiction over personal data processing. Centralizing software-compliance and safety-performance data from an entire national vehicle fleet is a legitimate regulatory goal, but it's also the kind of large-scale data infrastructure that deserves an explicit data protection framework attached to it — not one inferred after the fact. Turkey should keep building this backbone. It should also give manufacturers, notaries, and its own registry systems the lead time to make it work, and say clearly who is responsible for the data once it's centralized.

Sources & Citations

  1. Official Gazette No. 33290 (June 24, 2026 amendment)
  2. Official Gazette No. 32739 (Dec 1, 2024 ADS type-approval rule)
  3. Hürriyet Daily News: Vehicle documents go digital
  4. Bazaar Times: Türkiye digitizes vehicle registration, tightens software rules
  5. Pekin Bayar Mizrahi: First regulation on autonomous vehicles published