What Changed
Law No. 7590 — a 32-article omnibus that also touches pensions, nuclear-plant tax breaks and tourism subsidies — was adopted by parliament on July 24, 2026, and published in the Official Gazette (Issue No. 33326) on July 31, entering into force the same day. Buried in the unrelated provisions is a rewrite of Turkey's internet governance architecture: domain-name policy, electronic communications infrastructure oversight, the technical framework for lawful interception, and regulatory authority over social media and gaming platforms all move from the Information and Communication Technologies Authority (BTK) to the Cybersecurity Presidency (Siber Güvenlik Başkanlığı) — a body created under the March 2025 Cybersecurity Law No. 7545 and attached directly to the presidency. BTK's relevant personnel, information systems and roughly ₺30 billion in infrastructure transfer with the functions.
The Mechanism
The operative change sits in a new Article 60/A inserted into the Electronic Communications Law No. 5809. It gives the Cybersecurity Presidency power to order "security measures" on telecom operators, internet access providers, data centers, hosting firms and content providers, who "must comply immediately and no later than two hours after notification." Judicial oversight comes after the fact: the statute requires the order be "submitted within twenty-four hours to a peace criminal judge, who must rule within forty-eight hours, failing which the order automatically lapses." In practice, a website can be blocked, an account suspended, or a domain reassigned up to three days before a judge weighs in at all — and even then, the judge is ruling on whether an already-executed measure may continue, not whether it should have happened.
The Case For It
Credit where due: Turkey has a real, named fraud problem that moves faster than courts do. "Polis/savcı taklit dolandırıcılığı" — police- and prosecutor-impersonation fraud — is a well-documented pattern in which scammers hijack a victim's contact's WhatsApp account or spoof an official caller ID, then pressure the target with claims of a pending arrest or frozen account to extract an urgent wire transfer. Turkish legal guides describe thousands of such cases a year, disproportionately targeting older, less tech-familiar victims. Once money moves through a mule network, it can be laundered in minutes; a takedown order that waits for conventional pre-enforcement judicial review is often already too late to matter. A regulator that can force a hosting provider or access provider to act within two hours has a genuine tool against that specific harm, and centralizing the technical execution of lawful interception in one body could plausibly reduce the coordination failures that come from splitting cyber functions across a telecom regulator and separate security agencies.
Where the Justification Runs Out
The problem is that Article 60/A's two-hour/forty-eight-hour mechanism isn't limited to active fraud. It's a general "measures" power that also governs domain-name administration, platform oversight and content-related enforcement of catalog-crime removals — categories with none of the time-sensitivity that justifies bypassing prior judicial review for a live scam call. The digital rights group İFÖD has flagged a specific regression: the amendment repeals a narrower provision that specifically regulated bandwidth throttling and replaces it with the broader, undefined "measures" authority, making it harder to know what action was taken or under what legal basis. Turkey's chambers of computer and electrical engineers have called the change a form of digital censorship, and the digital rights group Engelli Web warned in Turkish press coverage that it opens the door to an "uncontrolled end-to-end censorship and surveillance backbone."
The post-hoc judicial check is also structurally weak by design. A judge who rules within 48 hours is not conducting the kind of adversarial, evidence-tested review that precedes a warrant — the record shows the measure already executed, and reversing it doesn't restore the traffic, revenue or political-speech window a blocked platform lost in the interim. For a fraud hotline that's a tolerable trade-off. For a domain seizure or a platform-wide access order during, say, an election period, it converts judicial review into a formality.
Institutional Design Matters
BTK, whatever its faults, was a multi-member regulator whose cybersecurity mandate traced to a 2014 statutory amendment passed through the ordinary sector-specific legislative process. The Cybersecurity Presidency answers to the president alone. Concentrating domain administration, platform oversight, wiretap technical execution and access-blocking inside one presidentially-controlled body — while narrowing pre-enforcement judicial review to a rubber stamp — removes the separation between the actors who order a measure and the actors positioned to contest it before it happens. That's a bigger structural shift than the fraud-prevention rationale requires.
The Proportionate Fix
A pro-innovation, evidence-based approach would keep the emergency two-hour clock for the narrow class of harm that actually justifies it — live financial fraud, imminent safety threats — while restoring genuine ex-ante judicial review, not a 48-hour after-the-fact ratification, for domain policy, platform oversight and general content removal. Turkey had a real scam problem to solve. Law No. 7590 solved it by rewriting the rules for everything else on the internet too.