Employee Responsibility for Unlicensed Software Systems Installed Upon Leaving the Company
Employee Responsibility for Unlicensed Software Systems Installed Upon Leaving the Company
Who is responsible for unlicensed software systems installed by a former employee? This comprehensive guide examines company and employee liability in detail under Turkish law, including the Labor Law, Turkish Code of Obligations, Turkish Commercial Code, and aspects related to penalties and compensation.
In companies, the risk of unlicensed software is often perceived simply as "using pirated software." However, in practice, one of the most dangerous scenarios is unlicensed systems, or systems that violate licensing terms, that an employee installs while on duty but the company continues to use after their departure. This system might be a cracked accounting program, an unauthorized CAD package, an ERP module used by multiple users with a single-user license, or a subscription software activated through the employee's personal account instead of the company's. The problem becomes apparent when the employee leaves the company because while the company continues to use the system to keep it running, copyright, contract, data security, and even criminal law risks arise simultaneously. In Turkish law, this situation is not explained solely by the fault of the former employee; the Copyright Law, the Turkish Code of Obligations, the Labor Law, the Turkish Commercial Code, and, where necessary, the Turkish Criminal Procedure Code are considered together.
In Turkish law, computer programs are explicitly protected as works. Law No. 5846 on Intellectual and Artistic Works considers computer programs as scientific and literary works; furthermore, the installation, viewing, execution, transmission, and storage of a program are also considered within the scope of the right of reproduction. Therefore, the legal risk is not limited to pirated CD copying; unlicensed installation, use with a forged license key, reproduction exceeding the license limit, multiple user access with a single account, or unauthorized storage can also give rise to infringement disputes. The fact that an employee installed the system does not render the program's use in company operations a "personal error," because its actual use has become part of the commercial organization.
Therefore, the real question is broader than simply "who installed the program?". The main issue is under what licensing regime the software was used, whether the company was aware of this system, whether it continued to use it after learning about it, whether the managers fulfilled their supervisory responsibilities, and who will be held liable under which legal avenue if damage occurs. In other words, in unlicensed systems installed by a former employee, liability is often layered: external liability to the rights holder, internal recourse liability, labor law consequences, criminal risk, and data security consequences may all arise simultaneously.
What legal obligations might an employee who installs an unlicensed system be violating?
According to Article 396 of the Turkish Code of Obligations, an employee is obligated to perform their assigned work diligently and to act faithfully in protecting the employer's legitimate interests. The same article stipulates that the employee must use the employer's machinery, tools, equipment, technical systems, and facilities properly; that they cannot use or disclose production and business secrets learned during their employment for their own benefit while the employment relationship continues; and that they are obligated to maintain confidentiality even after the termination of the employment relationship to the extent necessary to protect the employer's legitimate interests. An employee's actions such as installing unlicensed systems on behalf of the employer, using forged licenses, exposing the company to future copyright infringement risks, or transferring the system without license documents upon leaving, can seriously conflict with this duty of diligence and loyalty.
If an employee knowingly installed unlicensed software, concealed it, used a forged key, deceived the company, or configured the system in a way inaccessible to the company through their personal email and accounts, the incident may be considered not merely a technical error but a breach of the duty of loyalty. The employee's fault is aggravated, especially if they knew the program was unlicensed and yet failed to inform their employer, making the system an essential part of their operations. In this case, if the incident is discovered while the employment contract is still in effect, termination for just cause may be considered under Article 25/II-e of the Labor Law, which addresses "abuse of the employer's trust" and "conduct inconsistent with honesty and loyalty." This clause in the Labor Law provides examples; it covers not only theft but also similar behaviors that undermine the relationship of trust.
An employee's responsibility does not completely disappear even after they leave their job. The last paragraph of Article 396 of the Turkish Code of Obligations stipulates that an employee is obligated to retain information learned during their employment, such as production and trade secrets, even after the termination of the employment relationship, if it is in the employer's legitimate interest. If the employee not only installs an unlicensed system but also, upon leaving, withholds administrator passwords, installation methods, license source, integration structures, and critical access information, or fails to provide information in a way that effectively forces the company to use the system, then not only their past installation actions but also their post-termination behavior becomes legally significant. This scenario is also debatable in terms of both contractual damages and tort liability.
Does the company become absolved of liability to the rights holder?
In most cases, no. Under the Copyright Law (FSEK), the rights holder can claim that their financial and moral rights have been violated and demand a stay of use, compensation, and certain specific demands. Specifically, Article 68 of the FSEK allows the rights holder to demand up to three times the price they would have demanded if a contract had been made, or the market value, for the work used without permission. Article 70 of the FSEK addresses the claims of the person whose financial rights have been violated, including compensation if there is fault, and the transfer of profits earned. In terms of these regulations, the rights holder often first looks at the actual user; that is, the company using the program in its business processes becomes the direct target. The defense of "a former employee installed it" does not always provide a protective shield against the rights holder.
The reason is simple: when assessing copyright infringement, it is crucial whether the act was committed within a commercial organization. If the company continues to use the system after the employee leaves, utilizes it in the production of products or services, conducts customer business through this infrastructure, and does not shut down the system even after learning of the unlicensed use, its liability is significantly strengthened from that point onward. In many cases, the fault of the original founding employee and the fault of the employer who knowingly continued to use the system are considered together. Therefore, the critical threshold for the company is the moment it learns of the unlicensed use. Continuing the use after learning of the unlicensed use often weakens the "former employee's action" defense. This conclusion is consistent with the structure of the Turkish Copyright Law (FSEK) which penalizes unauthorized use and the general fault-based liability in the Turkish Code of Obligations (TBK).
Article 66 of the Turkish Code of Obligations creates a significant loophole against the company. According to this article, an employer is liable for damages caused to others by an employee during the performance of their assigned work; however, they can be absolved if they prove they exercised due diligence in selecting, instructing, supervising, and monitoring the employee. Furthermore, a company cannot escape liability if it cannot prove that its operational procedures were suitable for preventing the damage. Even if an employee installed an unlicensed system, the argument for organizational fault under Article 66 of the Turkish Code of Obligations is strengthened if the company lacks a software inventory, does not conduct license checks, does not verify installation authorizations, and does not have a technical handover procedure during the employee's departure process.
Furthermore, according to Article 116 of the Turkish Code of Obligations, even if the debtor entrusts the performance of the debt or the exercise of the right arising from the debt relationship to auxiliary persons, they are still obliged to compensate the other party for the damage caused by these persons while carrying out the work. If the software infrastructure, accounting services, design services, or production system offered by the company to the customer is based on unlicensed software installed by an employee, the company's "employee did it" defense will have limited effect in the contractual relationship with the customer. This is especially important in SaaS, outsourced accounting, engineering drawing, architecture, production automation, and e-commerce infrastructures. Because an unlicensed system creates performance and compliance risks not only against the rights holder but also against the customers.
Can the company seek recourse from the former employee?
As a rule, yes, but not automatically. If the company is obliged to pay the rights holder, settle the matter, cover compensation, bear the cost of system conversion, or compensate for customer losses, and the former employee's fault and unlawful conduct contributed to these losses, the company may raise the issue of recourse against them. Article 49 of the Turkish Code of Obligations states that a person who causes harm to another through a culpable and unlawful act is obligated to compensate for the damage. Article 112 of the Turkish Code of Obligations stipulates that if a debt is not properly fulfilled, the debtor is obligated to compensate the creditor for the damage unless they prove their innocence. If the employee installed an unlicensed system despite their employment contract, job description, company policies, or clear instructions, these articles can form the basis of a recourse argument regarding internal company damages.
However, in recourse cases, the employer's own fault is always considered. The company's use of the system for years without supervision, its failure to request license documents, its lack of procurement-IT coordination, its failure to obtain a handover receipt upon departure, and its continued use after the risk emerged, can weaken the claims against the former employee. In other words, even if the company has made full payments to external parties, the court will discuss the link between its own lack of supervision and the resulting increase in damages in order to potentially pursue recourse against the former employee. In practice, the success of recourse increases the clearer the scenario that "the employee was grossly negligent and the employer was reasonably careful" can be established. This assessment is also consistent with the logic of exoneration evidence in Article 66 of the Turkish Code of Obligations.
When does the responsibility of managers and company bodies come into play?
The issue may not be limited solely to the employer-employee relationship. Article 369 of the Turkish Commercial Code requires board members and those responsible for management to perform their duties with the diligence of a prudent manager and to protect the company's interests in accordance with the rules of honesty. Article 553 of the Turkish Commercial Code stipulates that founders, board members, managers, and liquidators who violate their obligations arising from the law and the articles of association through their negligence shall be liable to the company, shareholders, and company creditors. Therefore, even if the person who sets up the unlicensed system is an employee, if the managers remain inactive after learning about the risk, fail to establish a compliance mechanism, and continue to operate the company in a clear state of violation, the internal liability dispute may escalate to the level of the relevant organs.
Especially in companies that are receiving investment, undergoing audits, preparing for an IPO, or entering merger and acquisition processes, software license compliance is no longer a classic "IT detail." Because inheriting an unlicensed system from a departing employee is not, in itself, an excuse; it raises questions about when management learned of it, what they did, and why they delayed. If company management knew that the former employee was running critical processes using licenses linked to their personal account and yet failed to provide corporate licenses, the fault can shift from the individual technical staff to the management level. The duty of care and responsibility regime in the Turkish Commercial Code becomes crucial at this point.
Will this incur criminal liability?
Yes, depending on the specific case. Article 71 of the Law on Intellectual and Artistic Works (FSEK) stipulates imprisonment or a fine for those who, without the written permission of the copyright holder, process, reproduce, distribute, represent, publicly transmit, or possess or store illegally reproduced copies of a work for commercial purposes. Article 72 of the FSEK also contains a separate threat of punishment for software or technical hardware designed to disable additional programs created to prevent the illegal reproduction of computer programs. The use of cracks, keygens, license bypass modules, fake activation tools, or scripts that break the protective mechanism may trigger this area, depending on the specifics of the case.
The key point here is that criminal responsibility is personal. According to Article 20 of the Turkish Penal Code, criminal responsibility is personal; no one can be held responsible for the actions of another, and no criminal sanctions are applied to legal entities, although security measures prescribed by law are reserved. Therefore, in a criminal case, the defendant is, as a rule, a real person: the employee who set up the system, the person who used the crack tool, the manager who gave the instructions, or the decision-maker who knowingly allowed it to continue. However, even if the company does not receive a penalty, it becomes central to the investigation; because the devices on which the program was installed, the servers, log records, activation data, and email chains become evidence.
If digital evidence is to be collected during the investigation phase, Article 134 of the Code of Criminal Procedure comes into play. This article stipulates that in cases of strong suspicion based on concrete evidence and the inability to obtain evidence otherwise, computers and computer programs can be searched, copied, and, if necessary, seized. In practice, this means that the unlicensed system established by the former employee may not remain merely a matter of compensation; if the prosecution process begins, company devices, license servers, backups, and user records may be subject to forensic digital examination.
How should evidence be managed in unlicensed systems that emerge after a business relationship ends?
The biggest mistake in dealing with these files is panicking and deleting data. However, the legally and technically correct approach is to first determine the current situation. Article 199 of the Code of Civil Procedure considers data in electronic form as documents; therefore, server logs, license activation records, installation dates, internal company messages, emails, user logs, and backups can be considered as evidence in legal proceedings. Conversely, Article 189/2 of the Code of Civil Procedure stipulates that evidence obtained illegally cannot be taken into account. Therefore, the company should not collect evidence by illegally accessing the personal data of former employees; it should properly protect the data existing in its own systems.
The first step in evidence management is to inventory the affected systems. It's crucial to quickly determine which programs are installed on which devices, whose name the license is registered under, which email address was used for activation, whether the license key is forged, whether a single-user license has been converted to multiple users, whether a crack tool is present on the server, and whether the installation dates coincide with the employee's tenure. The second step is the protection of critical data such as logs and disk images. The third step is conducting a simultaneous internal technical and legal review. Work done solely by the IT department, solely by the legal department, or solely by an external consultant is often incomplete. This is because both the chain of evidence and the legal classification must be established simultaneously. This outcome is consistent with the evidence regime in the Code of Civil Procedure and the importance given to digital evidence in Article 134 of the Code of Criminal Procedure.
Why is the GDPR aspect important?
An unlicensed system established by a former employee often creates not only copyright infringement but also data security risks. According to Article 12 of Law No. 6698, the data controller is obliged to take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data and to ensure the preservation of personal data. The same article stipulates that if personal data is processed by another natural or legal person on behalf of the data controller, these persons are also jointly responsible for data security measures. If the unlicensed system established by the departing employee also processes customer data, employee data, or trade secrets, the issue goes beyond copyright disputes and creates a risk under the Turkish Personal Data Protection Law (KVKK).
Especially cracked software, license circumvention tools, and unauthorized third-party plugins often create systems that don't receive updates, carry the risk of malicious code, or cause uncontrolled data flow. By continuing to use this infrastructure established by a former employee, the company may also find itself in a vulnerable position in terms of data security. What is critical here is what technical and administrative measures the company took from the moment it learned that the system was unlicensed. In other words, the incident cannot be simply viewed as "a former employee deceived us"; the company's own security measures as the data controller must also be evaluated.
What should companies do in practice?
The first step is to immediately subject the system to a controlled legal review. Upon discovering the software infrastructure established by a former employee, the company should immediately create a license inventory, determine the scope of active use, isolate the system if necessary, and establish a strategy for contacting the rights holder. The aim is not to conceal evidence, but to clarify the legal position without escalating the damage. Simultaneously, internal reporting should be carried out; management, legal, IT, and, if necessary, external forensic experts should work in coordination. A "let's continue for now, we'll see later" approach is the riskiest path in this process; because continued known unlicensed use increases both the fault and the extent of the damage.
Secondly, documents related to the former employee should be collected. Job descriptions, software installation authorizations, delivery records, email correspondence, chain of command, statements made during the departure process, and accounts used should all be examined together. The aim here is not to immediately shift responsibility to the former employee, but to determine who knew what at which stage. Because this information chain is the crucial factor in any lawsuit or investigation. If the company directly targets the former employee without questioning its own lack of oversight, it may be at a disadvantage in external disputes.
Thirdly, forward-looking corporate measures must be taken. Software inventory, licensing matrix, installation authorization, technical handover process upon employee departure, password transfer, corporate account policy, and software compliance audits must be standardized in companies. In particular, the installation of critical systems using personal email addresses, personal credit cards, personal subscriptions, or administrator access linked to a single employee should be prohibited. The problem of unlicensed systems installed by former employees often arises not just from the fault of one person, but from a lack of corporate control. The duty of care in the Turkish Commercial Code and the organizational responsibility in the Turkish Code of Obligations are already based on this principle.
Conclusion
Unlicensed software systems installed by an employee upon leaving their job are not a one-dimensional problem under Turkish law. Since computer programs are protected as works of art, copyright infringement under the Law on Intellectual and Artistic Works (FSEK) can lead to claims for up to three times the amount, damages, and penalties. For the employee, the duty of care and loyalty under Article 396 of the Turkish Code of Obligations (TBK) may bring about contractual and tort liability towards the employer. Under the Labor Law, if the incident was learned while the employment relationship was ongoing, it may constitute grounds for justified termination. For the company, however, the defense of "the former employee did this" is not sufficient on its own; because if the company continued to use the system, failed to conduct inspections, or did not address the risk even after learning about it, it also increases its own external liability.
Therefore, the correct legal approach is to first determine the source of liability, then the chain of knowledge and fault, and finally, whether the use continued. If the employee is grossly negligent, recourse is possible; however, the company's own lack of oversight and organization must also be taken into account. The safest approach is not to create a defense after a dispute arises, but to establish employee termination procedures, license inventories, and technical delivery mechanisms from the outset. This is because unlicensed systems often become a real legal crisis not on the day the employee leaves, but when the company continues to use them as a natural part of its corporate process.