Turkey algorithmic accountability

Turkey's Law No. 7590 Lets a Security Body Order Internet Blocks Before Any Judge Sees Them

Turkey moved blocking and content-removal powers from telecom regulator BTK to a presidential cybersecurity body, with courts reviewing only after enforcement.

Turkey's Restrict-First Blocking Regime People of Internet Research · Turkey 2 hours Platform compliance deadline Operators must execute SGB blockin… 24 hrs Judicial referral window Orders reach a criminal court of p… 48 hrs Auto-expiry if no ruling If the judge doesn't decide within… ₺20K–100K Non-compliance fine range Per-violation administrative penal… peopleofinternet.com
Turkey's Restrict-First Blocking Regim… People of Internet Research · Turkey 2 hours Platform compliance deadl… 24 hrs Judicial referral window 48 hrs Auto-expiry if no ruling ₺20K–100K Non-compliance fine range peopleofinternet.com

Key Takeaways

A New Enforcer, and a New Sequence

On July 24, 2026, Turkey's parliament adopted Law No. 7590, an omnibus bill covering everything from pension increases to nuclear-plant tax breaks. Buried in it, and published in Official Gazette No. 33326 on July 31, is Article 21, which inserts a new Article 60/A into the Electronic Communications Law (No. 5809), and Article 27, which amends the Internet Law (No. 5651). Together they strip the telecom regulator BTK of its authority to order internet access-blocking, content removal, and technical support for lawful interception, and hand it to the Cyber Security Presidency (SGB) — an institution created inside the Presidency's own executive structure by Decree No. 177 in January 2025 and formalized months later by Cyber Security Law No. 7545.

The operative mechanic is what changes the analysis. Under the new Article 60/A, when the SGB decides delay would cause harm, it can order operators, access providers, data centers, and hosting or content providers to act — and they must comply "immediately and in any event within two hours of notification." Only afterward does a judge enter the picture: the order goes to a criminal court of peace within 24 hours, and if the judge does not rule within 48 hours, the order lapses automatically. Non-compliance carries administrative fines of ₺20,000–100,000 per violation, collected through tax offices. This is a restrict-first, review-later model — the inverse of the pre-clearance courts previously exercised over BTK blocking requests.

The Case for Speed

The strongest argument for this design isn't hard to construct, and it deserves to be made honestly. Distributed denial-of-service floods, live disinformation campaigns during elections or unrest, and active data breaches move in minutes, not days. A regulator that must wait for a judge before it can order a data center to sever a malicious connection is, in a genuine crisis, a regulator that arrives after the damage is done. Many democracies — the US, the EU, India among them — already give some agencies limited emergency powers to act first and justify themselves after, precisely because courts are built for deliberation, not real-time incident response. If Turkey's law were narrowly scoped to verifiable cybersecurity incidents — active intrusions, infrastructure attacks — a short administrative window bounded by mandatory, fast judicial review would be a defensible trade-off.

Why the Design Still Fails the Test

The problem is that Law No. 7590 doesn't confine "urgency" to cybersecurity incidents. Article 60/A's blocking and removal powers sit inside the same general grant that already covers ordinary content disputes under Law No. 5651 — the statute Turkey has used for over a decade to block news sites, social platforms, and individual posts. The Freedom of Expression Association (İFÖD) warned lawmakers before passage that the bill's "open-ended wording could allow authorities to restrict access, throttle internet traffic, filter online communications or interfere with internet infrastructure before judicial approval is obtained" — and pointed out that the law simultaneously repealed Turkey's specific bandwidth-throttling rules, replacing defined conduct with an undefined "measures" power. When the same fast-track sits available for a DDoS attack and for a politically inconvenient news story, the emergency justification stops doing the work asked of it.

Institutional placement compounds this. BTK, whatever its faults, is a sectoral regulator with a defined statutory mandate and its own accountability channels. The Cyber Security Presidency reports directly into the Presidency and, per its founding decree, sits alongside intelligence and national-security functions — the same body that will now also hold the technical infrastructure for lawful interception, following an asset transfer analysts estimate at roughly ₺30 billion in BTK systems and data centers. Concentrating detection, blocking, and interception capability in one executive-controlled office is a different animal than distributing those functions across a regulator and the judiciary, even before a single order is issued.

The Post-Hoc Review Problem

The 24/48-hour judicial backstop looks like a safeguard on paper, but it inverts the sequence that makes judicial review meaningful. A court asked to bless a blocking order that has already been enforced for a full day is reviewing a fait accompli, not screening a proposed action — the content is down, the traffic is already throttled, and the political or commercial harm from a wrongful order is largely realized by the time a judge looks at the file. Courts under time pressure to rule within 48 hours or watch the order lapse automatically also face an asymmetric incentive: a hasty approval costs the judge nothing, while a hasty rejection of a security agency's stated urgency risks blame if something goes wrong later. That dynamic tends to produce rubber-stamping, not scrutiny — the opposite of what pre-enforcement court review was designed to prevent.

What Would Make This Proportionate

A narrower version of this law is easy to imagine: limit the two-hour administrative track to verified, technical cybersecurity incidents — active attacks on infrastructure, not content disputes — and require the SGB to log and publish aggregate order volumes, categories, and judicial outcomes, the way transparency reporting works for national-security requests elsewhere. Neither constraint appears in the text Turkey published on July 31. Until one does, the practical effect of Law No. 7590 is to remove the one structural check — a court that sees an order before it takes effect — that distinguished routine internet governance from emergency security powers, and to fold both into the same two-hour switch.

Sources & Citations

  1. Alomaliye — Law No. 7590 full text (Resmî Gazete 31 July 2026, No. 33326)
  2. Law No. 7590 statutory text summary (Alomaliye)
  3. Pekin Bayar Mizrahi legal analysis
  4. Nordic Monitor
  5. Middle East Forum analysis