Is the company responsible for the software used by freelance and outsourced teams?
Is the company responsible for the software used by freelance and outsourced teams?
Is a company liable for unlicensed or unauthorized software used by freelance developers, agencies, and outsourcing teams? A comprehensive assessment from the perspective of Turkish law, including the Copyright Law, Turkish Code of Obligations, Turkish Commercial Code, Personal Data Protection Law, and criminal law.
Companies are increasingly outsourcing many tasks, such as software development, design, modeling, data processing, accounting automation, ERP implementation, CAD drawing, testing, cybersecurity, and cloud management, to freelancers or external teams due to cost and speed advantages. However, outsourcing doesn't automatically mean transferring legal risk. Especially when external teams use unlicensed, cracked, or compromised software, or software exceeding the usage limits specified in the contract, the defense of "this isn't our personnel" might seem appealing at first glance, but the situation is often more complex under Turkish law. Computer programs are protected as works under the Law No. 5846 on Intellectual and Artistic Works; the installation, viewing, execution, transmission, and storage of the program are also covered by the right of reproduction. Therefore, inappropriate use by an external team can transform from a purely technical purchasing problem into a multi-layered issue involving copyright, contract, compensation, managerial diligence, data security, and in some cases, criminal risks.
The most critical question in this section is: If the external individual or team is not a salaried employee of the company, can the company still be held liable? The answer is "yes, to a certain extent" in most cases; however, the type and severity of liability are not the same in every scenario. This is because there are different legal avenues of liability: external liability under the Law on Intellectual and Artistic Works (FSEK) towards the rights holder, liability for breach of contract under the Turkish Code of Obligations (TBK) towards the parties to the contract, internal recourse relationships within the company, the duty of care and responsibility of managers under the Turkish Commercial Code (TTK), the aspect under the Personal Data Protection Law (KVKK) if data processing is involved, and criminal liability towards individuals if the act has been taken to the criminal realm. Therefore, both extreme approaches, such as "only the freelancer is liable if they used a freelancer" or "the company is fully liable in all cases," are legally incomplete.
Why should the software used by outsourced teams be of interest to the company?
The first reason for this is that outsourcing often works on behalf of the company. If a freelance developer writes a client portal for the company, if an outsourced accounting team manages the company's current and financial processes through software, if an agency does design and assembly work for the company's business, or if an integrator installs an ERP system on the company's live data, the work is no longer an abstract external service; it is an execution activity linked to the company's business. This link brings up the relationship of "actual use" under the Law on Intellectual and Artistic Works, "assistant party" under the Turkish Code of Obligations, and in most cases, "data processor" under the Turkish Personal Data Protection Law. In other words, even if the outsourced team works in their own office, the work they do touches upon the company's legal sphere.
The second reason is that software license infringement often targets not only the installer but also the party benefiting from and continuing to use the system. According to Article 66 of the Turkish Copyright Law, a person whose moral and financial rights have been violated can sue for the cessation of the infringement; if the infringement was committed by a representative or employee of a business while performing their services, a lawsuit can also be filed against the business owner, and fault is not a prerequisite. This provision explicitly states "representative or employee"; outsourced teams may not be employees in the classic sense. However, when the outsourced team is actually integrated into the company organization, installs systems on behalf of the company, and the company uses these systems in its commercial activities, it becomes difficult to say that the company is completely excluded. At the very least, the company is obliged to disclose its own use and approval. Therefore, the existence of an outsourcing model does not automatically provide immunity against the rights holder.
From an FSEK (Turkish Copyright Law) perspective, when does the company become the primary party to address?
Since computer programs are considered works, unauthorized processing, reproduction, distribution, performance, or public transmission are evaluated within the financial rights regime of the Copyright Law (FSEK). Article 68 of the FSEK allows the copyright holder to demand up to three times the amount they could have demanded if a contract had been made, or the market value, from those who process, reproduce, distribute, perform, or publicly transmit the work without obtaining written permission from the copyright holder in accordance with the law. In practice, the copyright holder often turns to the company using the software in its commercial process before the technical creator. The reason for this is simple: the commercial benefit is often reflected in the company's balance sheet and business process.
Here, it is crucial to know whose account the outsourcing team is using the software under, with what license, and in whose name. If the company provides the freelance developer with its own corporate licenses, remote access accounts, or servers, and the outsourcing team exceeds the license limit using these tools, the company's direct connection to the user and organization is much stronger. Similarly, if the company knowingly runs the delivered software on unlicensed software, keeps it on a live system, or makes it available to its own users, the defense of "this was done by the agency, not us" against the rights holder is significantly weakened. This conclusion stems from the fact that Article 22 of the Turkish Copyright Law (FSEK) includes the installation, execution, and storage of computer programs within the scope of reproduction rights, and from the structure of Articles 66-68, which directly affect company usage.
Conversely, if the external team works entirely with its own tools, on its own independent infrastructure, delivering only the final output, and the company does not use or incorporate that inappropriate software into its own system, the company's liability as a direct user of the software under the Law on Intellectual and Artistic Works (FSEK) may not be equally weighted in every case. However, the risk is still not eliminated; because whether the company was aware of this method, whether it gave instructions for it, how it integrated the result into its commercial activities, and whether there are additional copyright issues with the output are all decisive factors. This point is not written in a single sentence in the law; it is an assessment resulting from the combined interpretation of the FSEK's logic of actual use and the breach of contract and auxiliary liability in the Turkish Code of Obligations (TBK).
Why is the liability of an "assistant" so important under the Turkish Code of Obligations?
Regarding outsourced teams, one of the most critical provisions is Article 116 of the Turkish Code of Obligations. According to this article, even if the debtor has entrusted the performance of the debt or the exercise of a right arising from a debt relationship to auxiliary personnel, they are still obligated to compensate the other party for any damage caused by these auxiliary personnel during the execution of the work. When you outsource software development, integration, ERP implementation, design, data processing, or technical support work as part of a company's contractual obligation, that team often becomes your "auxiliary personnel." In this case, if the outsourced team has produced the product offered to the customer using unlicensed software, used inappropriate components, or performed support services using illegal means, the company may be held liable to the customer or the other party to the contract.
Article 66 of the Turkish Code of Obligations is similarly important. An employer is obligated to compensate for any damage caused to third parties by the employee during the performance of their work; however, they may be absolved if they prove they exercised due diligence in selection, instruction, supervision, and control. While outsourced teams are not always considered classic employees, this article is considered in conjunction with Article 116 when they are integrated into the company's organization and perform work on behalf of the company. Especially if the outsourced team connects to your server, processes company data, opens modules for your users, or produces a product delivered to your client, your defense will not be "they are not my personnel," but rather "I established reasonable selection, a clear licensing policy, and supervision and control.".
In other words, outsourcing work is not a transfer of legal risk; at most, it is risk sharing. The company may later try to seek recourse from the agency, freelancer, or external software developer; however, the first line of defense against the rights holder or client is often the company itself. Therefore, simply stating "all responsibility lies with the contractor" in the outsourcing contract does not provide sufficient protection. The contract is important, but the court will also consider the company's own failures in supervision and organization in the specific case. This conclusion arises from reading Articles 112, 116, and 66 of the Turkish Code of Obligations together.
Can company executives completely get away with it by saying "the agency did it"?
No. Article 367 of the Turkish Commercial Code (TTK) states that management can be delegated partially or completely through internal regulations; these internal regulations must specify the duties, relationships of allegiance, and information disclosure obligations. Article 369 of the TTK obligates board members and third parties entrusted with management to perform their duties with the diligence of a prudent manager and to protect the company's interests in accordance with the rules of honesty. Article 553 of the TTK also stipulates that managers who violate obligations arising from the law and the articles of association will be liable to the company, shareholders, and creditors unless they prove their innocence. Therefore, if license management in outsourced software use is entirely left to the agency, but senior management has not established any control, internal regulations, approval process, or reporting chain, the problem can eventually become a lack of managerial diligence.
This is particularly important for technology companies, SaaS firms, e-commerce companies working with agency chains, ERP outsourcing groups, and customer data processing platforms. This is because the software used by external teams is often directly part of the company's product or service. If management considers the mere existence of an outsourcing contract sufficient and does not check the licensing status of the software used, the integration chain, third-party components, and access accounts, the standard of due diligence under the Turkish Commercial Code (TTK) may be called into question. This outcome is a direct reflection of the current management and liability provisions of the TTK.
Why does the GDPR aspect pose a separate risk?
Outsourced teams often don't just write code; they also access the company's customer, employee, supplier, or user data. According to the Turkish Personal Data Protection Law (KVKK), the data controller is obliged to take technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing and access of personal data and to ensure the preservation of data. If personal data is processed by another natural or legal person on behalf of the data controller, the data controller and that person are jointly responsible for taking these measures. Furthermore, a data processor is defined as a person who processes data on behalf of the data controller within the scope of the authority and instructions given by the data controller. Therefore, even if the outsourced team is "merely a subcontractor," the company's KVKK risk continues if there is a data processing relationship.
This area converges with license infringement at this point: if an external team uses cracked, insecure, outdated, or unlicensed software, it's not just a copyright issue; data security is also weakened. For example, if an external agency processes a client's live data with an unlicensed ETL tool, a freelance accountant stores payroll data in an unauthorized desktop program, or an integrator exports internal data using an unlicensed ERP consulting tool, the company cannot completely absolve itself in the event of a data breach by simply saying "the supplier did it." The official statements of the Turkish Personal Data Protection Law (KVKK) clearly state that the data controller's responsibility continues in cases of breaches committed by the data processor.
Who is at risk from a criminal law perspective?
Criminal liability is, as a rule, personal. According to Article 20 of the Turkish Penal Code, no one can be held responsible for the actions of another; legal entities are not subject to criminal sanctions, but security measures stipulated by law are reserved. Therefore, if an external team installs a crack or uses a tool that disables the protective program, the primary assessment in the criminal case is made based on the individuals involved. However, this does not mean that the company is completely safe. Because Article 71 of the Law on Intellectual and Artistic Works (FSEK) sanctions unauthorized processing, reproduction, distribution, public transmission, and possession or storage for commercial purposes; and Article 72 sanctions programs or hardware designed to disable protective programs created to prevent the unlawful reproduction of computer programs. If the company manager, IT manager, or project owner has personally directed, knowingly carried out, or organized these actions, the risk of criminal liability may extend to them personally.
The risk is particularly heightened in the following scenario: the company explicitly tells the outsourcing company, "Don't get a license, manage as you are"; it provides unauthorized access without opening a corporate license; it allows the use of fake accounts or shared keys; and then continues to use the resulting system live. In this case, it is possible to speak not of the independent action of the outsourcing team, but of a jointly committed illegality. Although the company's legal entity is generally not penalized, company servers, logs, access records, and outsourcing contracts can be used as evidence in the investigation. This conclusion stems from reading Articles 71-72 of the Law on Intellectual and Artistic Works and Article 20 of the Turkish Penal Code together.
How does the company protect itself?
The most effective method of protection in this area is not simply writing "the contractor is responsible for all licenses" in the contract. The company needs to establish at least the following structure: the outsourcing team will only use software approved by the company; all third-party tools and components used will be reported; license documents will be submitted upon request; the team working as a data processor will be subject to GDPR obligations; the company reserves the right to audit and review logs; access will be closed at the end of the project, and a list of the tools used will be submitted. All of this is the practical equivalent of the auxiliary person's liability under the Turkish Code of Obligations and the data controller's liability under the GDPR.
Article 64 of the Turkish Commercial Code (TTK) is also important here. A merchant is obliged to keep their commercial books and documents in a way that provides insight into their activities and financial situation; they must also store copies of their business documents in written, visual, or electronic form. When working with outsourced teams, keeping records of license documents, subcontractor agreements, user lists, access permissions, delivery receipts, and audit logs is not only good practice but also the backbone of the company's defense in future disputes. If the company does not keep records, proving which software the outsourced team used and to what extent becomes very difficult later on.
Conclusion
The liability of a company for software used by freelance and outsourced teams is broader than commonly believed under Turkish law. The existence of an outsourcing model does not automatically absolve the company. Since computer programs are considered works, the rights holder under the Law on Intellectual and Artistic Works (FSEK) can often be held liable by the company, which is the actual user and commercial beneficiary. Under the Turkish Code of Obligations (TBK), the liability of auxiliary personnel and employers makes it difficult for the company to completely absolve itself of the actions of the external team. The duty of care and supervision of managers under the Turkish Commercial Code (TTK), and the data controller-data processor relationship under the Personal Data Protection Law (KVKK), further reinforce this conclusion. While liability in criminal terms is personal, in cases of use organized on behalf of a company, individual managers and those responsible may also be included in the case file.
Therefore, the correct question is not "If they used a freelancer, will the company be spared?" The correct question is: what did the outsourcing team do on behalf of the company, which software did they use and under what license, did the company know about this, did it control it, and how did it integrate the results into its own business operations? If the answers are strong in favor of the company, the risk is manageable. If the answers are weak, the outsourcing model creates an additional chain of responsibility for the company, not a shield. The company's safest position is not to release the outsourcing; it is to make the licensing, access, data, and delivery processes contractually and practically auditable.
Frequently Asked Questions
If a freelance software developer uses pirated software on their own computer, is the company still liable?
Not to the same extent in every case; however, the company's risk is not eliminated. The company's liability increases if they gave instructions, integrated the result into their own system, knew about the unlicensed use, or could have known about it through reasonable supervision. For the company to be completely exempt, the actual use, knowledge, and organizational connection would need to be weak.
Does contracting with an outsourcing agency protect a company?
It provides partial protection, but it is not sufficient on its own. The contract provides for recourse and risk sharing; however, it does not mean that the company is completely relieved of liability under Article 116 of the Turkish Code of Obligations and other related provisions in relation to the rights holder or client.
If an external team processes the data, does the company's liability under the GDPR continue?
Yes. According to the official GDPR regulations, the data controller is jointly responsible for taking necessary precautions even if the data is processed by another natural or legal person on their behalf. The company's liability may continue even if the data breach originates from an external team.
Do managers bear personal risk in this regard?
Yes, they may. Especially if license management, outsourcing approval, and internal audit mechanisms have not been established, or if known violations have been overlooked, the burden of care and responsibility of managers can be debated within the framework of Articles 369 and 553 of the Turkish Commercial Code.
In a criminal case, is the company a defendant?
As a rule, no; criminal liability is personal. However, the individuals who organized, instructed, or knowingly carried out the act may be subject to investigation; furthermore, the company's infrastructure may be opened for examination of evidence.