Turkey VPN bans and restrictions

Turkey's Law No. 7590 Moves Internet Blocking From a Telecom Regulator to the President's Cybersecurity Agency

A new statute lets Turkey's presidentially-controlled Cybersecurity Presidency order two-hour internet blocks before any judge reviews them.

Turkey's Internet Blocking Regime, Before and After … People of Internet Research · Turkey 2 hours ISP compliance deadline Operators, ISPs, data centers and … 24-48 hrs Judicial review window Urgent orders reach a judge within… 17 VPN services blocked, 2023 BTK ordered ISPs to block 17 VPN s… 311,000+ Websites blocked in 2024 A record year for blocks, ~29% abo… peopleofinternet.com
Turkey's Internet Blocking Regime, Bef… People of Internet Research · Turkey 2 hours ISP compliance deadline 24-48 hrs Judicial review window 17 VPN services blocked, 2023 311,000+ Websites blocked in 2024 peopleofinternet.com

Key Takeaways

A Regulator Loses Its Reflexes, a President Gains Them

Turkey's Grand National Assembly adopted Law No. 7590 on July 24, 2026, and published it in the Official Gazette (Issue No. 33326) on July 31, 2026. Buried inside a 32-article omnibus bill that also touches pensions, driver-training rules and tourism subsidies is the most consequential change to Turkish internet governance since the 2007 Internet Law No. 5651 first gave regulators blocking powers: authority over access restrictions, bandwidth throttling, content-removal orders and domain-name administration moves from the Information and Communication Technologies Authority (BTK) to the Cybersecurity Presidency (Siber Güvenlik Başkanlığı, SGB) — an agency created under the 2025 Cybersecurity Law No. 7545 and answerable directly to the presidency, not to an independent regulatory board.

What the Law Actually Does

Under the new framework, the SGB can order "necessary measures" — access blocks, throttling, filtering — either at the request of security and intelligence agencies or on its own initiative, whenever grounds under Article 22 of the Constitution (the privacy-of-communication clause) exist and delay would be prejudicial. Operators, internet access providers, data centers, content hosts and hosting companies must comply within two hours of notification. Only after enforcement does a judge see the order: urgent decisions go to a criminal judgeship of peace for approval within 24 hours, and if the judge doesn't rule within 48 hours, the measure lapses automatically. Non-compliance draws administrative fines of TRY 20,000–100,000, appealable to an administrative court — but the block itself is already in effect by then. BTK's remaining assets, contracts, records and relevant personnel are due to transfer to the SGB within three months of publication.

The Case for Speed

To be fair to the drafters, urgent-blocking regimes exist across democracies for good reason: a live ransomware campaign, an active DDoS attack on hospital or grid infrastructure, or a coordinated disinformation operation during an election doesn't wait for a hearing date. A regulator with genuine national-security responsibilities needs some mechanism to act in hours, not weeks, and pairing that speed with mandatory judicial review within 48 hours — rather than no review at all — is at least a formal check that many emergency-powers statutes lack entirely. If the SGB used this authority narrowly, against genuine cyber-incidents, the design would be defensible.

Where the Design Breaks Down

The problem is what the law replaces and who now holds the pen. BTK, whatever its flaws, was a telecommunications regulator with a public mandate and institutional memory. The SGB is a security body embedded in the presidency, and the same institution that increasingly houses cybersecurity intelligence and lawful-interception infrastructure now also decides, unilaterally and in the first instance, when to throttle a platform or block a domain. The Freedom of Expression Association (İFÖD) — which reviewed the bill before passage — objected specifically to the ex officio trigger and to replacing a previously narrower, defined bandwidth-throttling provision with open-ended "measures" language, warning it could sweep in filtering and infrastructure interference with no advance judicial check at all. Turkey has already shown what that discretion looks like in practice: in March 2025, access to X, YouTube, Instagram and WhatsApp was throttled for roughly 42 hours following the detention of Istanbul Mayor Ekrem İmamoğlu, according to İFÖD's own monitoring. Blocking volume, meanwhile, is not shrinking under BTK's stewardship — it's accelerating. İFÖD's EngelliWeb report counted more than 311,000 websites blocked in Turkey in 2024 alone, a record and roughly 29% above 2023's 240,857, bringing the cumulative total since 2007 past 1.26 million domains. Handing a faster, less accountable trigger to a more centralized agency is not obviously a fix for that trend; it's an accelerant.

VPNs Are the Next Pressure Point

This matters specifically for circumvention tools. When Turkish authorities throttle platforms, VPN demand spikes immediately — Proton VPN has previously logged four-digit percentage sign-up surges within a day of prior blocking events. Regulators have responded not just to platforms but to the workaround itself: Freedom House documents that BTK ordered ISPs to block 17 VPN services in November 2023, part of a pattern stretching back to 2016. A cybersecurity-branded agency with a two-hour compliance mandate and ex officio authority is structurally better positioned than a telecom regulator to move quickly against VPN providers the next time a blocking order triggers a circumvention wave — collapsing the gap between "block the platform" and "block the exit" that has historically given Turkish users a few hours of breathing room.

A Proportionate Alternative Exists

None of this requires abandoning a rapid-response capability for genuine cybersecurity incidents. It requires keeping the trigger narrow — tied to defined technical threats, not open-ended "measures" — and keeping the check meaningfully ex ante rather than a 48-hour rubber stamp after the fact. Pairing SGB's technical capacity with BTK's institutional separation, rather than merging both under one presidentially-controlled body, would preserve speed without collapsing the independence that made the prior arrangement at least contestable. As written, Law No. 7590 trades a flawed but distinct regulator for a faster, more centralized one — a change in velocity, not in restraint.

Sources & Citations

  1. BTK official site
  2. Cybersecurity Presidency (SGB) official site
  3. Freedom House, Turkey: Freedom on the Net 2024
  4. Pekin Bayar Mizrahi, Law No. 7590 analysis
  5. Nordic Monitor
  6. Bianet, record 2024 web blocking