Legal Preventive Measures Against the Use of Unlicensed Software
Legal Preventive Measures Against the Use of Unlicensed Software
What legal preventive measures should be taken against the use of unlicensed software? This comprehensive guide explains company compliance policies, contractual safeguards, evidence gathering, precautionary measures, triple compensation, and penalty risks within the framework of Turkish law (FSEK, TBK, HMK, and KVKK).
Software is no longer just a technical tool; it is the fundamental infrastructure at the heart of companies' accounting, production, design, engineering, data management, sales, customer relations, and internal communication processes. Therefore, the use of unlicensed software cannot be seen as a simple IT deficiency or administrative negligence. In Turkish law, computer programs are among the works protected under Law No. 5846 on Intellectual and Artistic Works, and in cases of copyright infringement, both civil and criminal avenues may be pursued. Therefore, measures against the use of unlicensed software should be designed not only as technical but also as direct legal precautions.
From a "preventive legal measure" perspective, there are two distinct aspects to consider. Firstly, there's the internal compliance system and contractual security layer that companies or professionals using the software must establish from the outset to prevent license infringement. Secondly, there are the legal tools available to rights holders to stop unlicensed use before it escalates. A robust protection system requires considering both approaches together. This is because the problem of unlicensed software is often only discovered after an infringement occurs; however, the most cost-effective solution is to establish preventative measures before a dispute arises.
Why are preventive measures essential?
The primary reason why preventive measures are necessary is that copyright protection arises automatically. According to the official statement of the Ministry of Culture and Tourism, copyright arises the moment the work is created; there is no mandatory registration or recording requirement. Voluntary registration does not create rights; it primarily facilitates proof. Therefore, companies' "let's wait for a warning, then we'll see" approach is not legally secure. Protection already exists; the only issue is when and how the rights holder will assert it.
The second reason is that software license infringement often has more serious consequences than it appears. The General Directorate of Copyright states that in cases of copyright infringement, legal and criminal avenues are open not only for unauthorized processing, reproduction, modification, distribution, public dissemination, and publication, but also for purchasing, importing, exporting, possessing, or storing illegally reproduced works for commercial purposes, except for personal use. In this context, unlicensed software not only creates the risk of incomplete license fees; it can also trigger pressure for precautionary measures, compensation, and penalties.
The third reason is scattered usage habits within the company. In practice, breaches often don't begin directly with "pirated CDs." Sharing a single-user license among a team, transferring OEM software to another device, using a trial or training version for commercial purposes, continued use after the subscription period has expired, or uncontrolled installation by an external IT company are the most common scenarios. This is where preventive legal measures should come into play: the goal is not to establish a defense after a breach occurs, but to systematically prevent the breach from happening in the first place.
Basic legal framework
The first important point regarding the Turkish Copyright Law (FSEK) is that computer programs are considered protected works. The official text defines computer programs and states that all forms of computer programs, along with their preparatory designs, are protected under certain conditions. This protection also covers the economic use of the program. Therefore, any use that goes beyond the licensing relationship can be considered not only a commercial incompatibility but also an interference with copyright.
The second important point is the requirement for contracts relating to financial rights to be in writing. Article 52 of the Turkish Copyright Law stipulates that contracts and transactions concerning financial rights must be in writing and that the rights in question must be clearly indicated. This provision mandates that licensing relationships be managed not through verbal agreements within the company, but through a clear and verifiable documentation system. A software licensing compliance policy is necessary precisely for this reason: which software is used under what authorization cannot be left to arbitrary interpretation.
From the perspective of debt law, preventive measures are also mandatory. According to Article 112 of the Turkish Code of Obligations, if a debt is not properly fulfilled, the debtor is obliged to compensate the creditor for the damage unless they prove their innocence. Article 113 makes it possible to remedy the consequences of breaches in obligations to do and not to do. Article 116 regulates that the debtor may also be held responsible for the actions of assisting persons. When these provisions are read together, it is seen that the fact that unlicensed software was installed by an employee, an external IT company, or a subcontractor does not automatically absolve the company of responsibility. Therefore, preventive measures should govern not only the software but also human behavior.
First preventive measure: written software licensing compliance policy
The first and most fundamental legal measure against the use of unlicensed software is to establish a written software licensing compliance policy within the company. This document should specify which software can be used under which license model, who can request software, who can approve purchase and installation, under what circumstances user transfer is permitted, and which actions are explicitly prohibited. Without a written policy, internal usage habits create de facto legal consequences; whereas in copyright and contract law, boundaries must be defined by contract and written documentation.
This policy should specifically define OEM, single-user, multi-user, trial, educational, personal subscription, and enterprise cloud accounts separately. Each license type carries different legal risks. If license types are not clearly differentiated, employees often normalize misuse with the mentality of "same program, same job." However, using the wrong license type can sometimes constitute a direct breach of contract, or even copyright infringement.
Second preventive measure: central purchasing and installation authorization
The second pillar of preventive legal measures is centralizing the software acquisition and installation process. A system where everyone within the company can download and install software on their own initiative is an open invitation to license infringement. This is because it becomes very easy to use trial versions in a production environment, transfer educational licenses to customer business, use individual subscriptions in corporate projects, or purchase products from unauthorized sources. Without a central approval mechanism, "compliance" is effectively impossible.
The legal significance of this centralized system lies in the fact that the licensing relationship concretizes which rights are used by whom. If purchasing, installation, and user assignment are carried out by different individuals in a scattered manner, it becomes difficult to later prove which right was obtained with which document. Therefore, the licensing compliance policy must clearly separate the purchasing authority, the installation authority, and the account management authority; it must leave auditable records.
Third preventive measure: inventory and documentation discipline
One of the most important defense mechanisms under the Copyright Law is proving the existence and scope of the license. The importance of necessary permits and authorization documents is clear in the Ministry's statement on copyright infringement and in the legal framework; these documents may be requested from the user under Article 76, and failure to provide them may constitute a presumption of unauthorized use. Therefore, a robust inventory and documentation discipline should be central to preventive measures against the use of unlicensed software.
The company must regularly keep records of which software is installed, which versions are used, which devices are matched by which license, which users are assigned to which seats, when each subscription expires, and which reseller the purchase was made through. These records are necessary not only for internal control but also for legal defense in the event of a potential warning or lawsuit. An undocumented license is, in practice, often a vulnerable license.
Fourth preventive measure: employee and subcontractor contracts
A significant portion of the risk associated with unlicensed software arises from the conduct of employees or external IT service providers. Therefore, obligations regarding the use of software under the license must be clearly stated in employment contracts, confidentiality agreements, information security policies, and external service contracts. Furthermore, since Article 116 of the Turkish Code of Obligations regulates liability for the actions of auxiliary personnel, it is also crucial for the company to contractually discipline the conduct of external contractors or personnel.
These agreements should explicitly state the following points: prohibition of unauthorized software installation, prohibition of sharing user accounts, prohibition of sharing company licenses with third parties, prohibition of making trial and training versions available for commercial use, immediate termination of access for departing employees, and the company's right to request employee cooperation during license audits. These clauses do not protect the company from every risk; however, they both create a preventative effect and strengthen the internal chain of responsibility.
Fifth preventive measure: access control and log records
Unlicensed usage often grows through user behavior. Therefore, access control and logging systems are important preventive legal measures not only from the perspective of the Personal Data Protection Law (KVKK) but also in terms of licensing compliance. The KVKK's Personal Data Security Guide recommends identifying existing risks and threats to data security, regularly monitoring access control logs and other reporting tools, taking action upon warnings, and testing system security. This approach also provides a strong framework for determining who is using the software and whether there has been unauthorized access.
If a company doesn't log named user licenses, cloud dashboards, admin consoles, and device access, it becomes blind to both data security and license compliance. Seeing which user logged in and when, which accounts are shared, whether old employee accounts remain active, and the actual number of users in the license panel is one of the most practical ways to prevent breaches. Therefore, a good license compliance policy should be considered in conjunction with information security and access logs.
Sixth preventive measure: regular internal audit
Software license compliance isn't a one-time job to be forgotten. Employee numbers change, equipment is upgraded, subscriptions expire, projects increase, companies merge, or acquire other businesses. Therefore, license compliance requires regular internal audits. Otherwise, the company will only feel secure because "it was once compliant," while copyright and contract risks silently grow.
Internal auditing is not just about counting installed software. The use of trial or training versions, user sharing, unauthorized reseller purchases, OEM migration, the use of cloud accounts between group companies, and the actual use of expired subscriptions should also be examined. Without regular internal audits, problems are often only discovered after a warning notice is received from the rights holder. However, the logic behind preventative legal action is to conduct internal investigations before an external warning is issued.
Seventh preventive measure: integrating data protection and cloud usage with licensing compliance
In companies using cloud services, licensing compliance and data protection cannot be considered separately. The "Data Controller and Data Processor" document of the Turkish Personal Data Protection Law (KVKK) clearly states that a company providing cloud computing services may, in some cases, act as a data processor; while the data controller retains responsibility as the party determining the purposes and means of processing personal data. Therefore, sharing cloud software licenses or using them with unauthorized users can create not only copyright risks but also the risk of personal data being processed by the wrong person.
As a preventive legal measure, the company must ensure that the data controller-data processor relationship in cloud software is clearly defined in the contract, user accounts are correctly identified, access is logged, and two-factor authentication, role-based authorization, and secure session management are used in systems containing personal data. This closes vulnerabilities that could simultaneously lead to both license breaches and data security breaches.
Preventive legal tools for rights holders
Legal preventative measures against the use of unlicensed software are not limited to user companies. Rights holders can also pursue certain legal avenues before the infringement escalates. These include warnings, contractual audit clauses, evidence gathering, and preliminary injunctions. When a rights holder discovers an infringement, they are not obligated to file a large compensation lawsuit immediately; the primary goal can be to substantiate the usage, secure evidence, and prevent the infringement from continuing.
Article 400 and subsequent articles of the Code of Civil Procedure, concerning the institution of evidence preservation, constitute a crucial preventive tool here. Before a lawsuit is even filed, an on-site inspection or expert examination may be requested to ascertain a fact that could be presented in a future lawsuit; a legal interest is deemed to exist if there is a possibility of the evidence being lost or its future presentation becoming difficult. Since log records, installation traces, user assignments, and activation data in software files can be deleted or altered, evidence preservation is a particularly effective preventive legal tool.
The prohibition of infringement in Article 69 and the provisional measures in Article 77 of the Copyright Law are also preventive tools for rights holders. The aim is not merely to demand retroactive compensation, but to stop potential or ongoing infringement. Therefore, a well-designed preventive strategy often requires the copyright holder to establish their licensing policy, control mechanism, and warning procedure in advance.
Conclusion
Taking preventative legal measures against the use of unlicensed software is not a luxury but a necessity for today's companies. This is because computer programs are protected works under Turkish law; legal and criminal avenues are open in case of copyright infringement; the actions of accomplices can bind the company; lack of documentation weakens the defense; and in cloud and data processing environments, license infringement can be combined with data security problems. Therefore, it is not enough for a company to simply "purchase a license"; it must use the license with the right person, on the right device, for the right purpose, and under the right contractual terms.
The essence of preventive legal action is this: instead of trying to correct the infringement after a lawsuit has been filed, it is to systematically make it impossible for the infringement to occur. When written policy, centralized organizational discipline, inventory and documentation procedures, employee and subcontractor agreements, log and access control, regular internal audits, and data security integration are established together, the risk of unlicensed software is significantly reduced. Without them, a seemingly minor software choice can turn into a major copyright and reputation crisis.
Frequently Asked Questions
Is a licensing compliance policy necessary for small companies as well?
Yes. Copyright protection does not change depending on company size. However, the risk is often greater in smaller companies because scattered use and lack of documentation are more common.
If an employee installs unlicensed software, is the company still liable?
In most cases, yes. Article 116 of the Turkish Code of Obligations regulates liability for the actions of auxiliary personnel; Article 66 of the Turkish Copyright Law also stipulates that lawsuits can be filed against the business owner for violations committed by employees during the course of their service.
Can using a trial or training version in a commercial setting also be considered a license breach?
Yes. If the use exceeds the limits of the purposes granted by the license, breach of contract and copyright claims may arise.
Are preventive measures only necessary for the company?
No. For rights holders as well, notices, evidence gathering, and injunction/precautionary mechanisms are preventive legal tools that help stop the violation before it escalates.
If there's no documentation but the software was actually purchased, would that be a problem?
It could be. Failure to prove the existence and scope of the license would significantly weaken a company's defense in litigation and audit proceedings.