Turkish Penal Code Article 243: Unlawful Access to an Information System: Supreme Court Decisions and Penalties
ARTICLE 243 OF THE TURKISH PENAL CODE: UNLAWFUL ACCESS TO AN INFORMATION SYSTEM
ENTRANCE
With the rapid development of information and communication technologies, the security of information systems has gained paramount importance. Unlawful access to information systems can cause serious harm at both individual and corporate levels. This situation has highlighted the need for the law to regulate crimes against information systems. Article 243 of the Turkish Penal Code addresses the crime of unlawfully accessing an information system. This article will examine in detail the crime of unlawfully accessing an information system as defined in Article 243 of the Turkish Penal Code.
The provision of Article 243 of the Turkish Penal Code
Article 243 of the Turkish Penal Code is structured as follows:
- Anyone who unlawfully enters or remains in all or part of an information system shall be sentenced to imprisonment for up to one year or a fine.
- If the acts described in the paragraph above are committed against systems that can be used for a fee, the penalty shall be reduced by up to half.
- If this act results in the loss or alteration of data contained within the system, the offender shall be sentenced to imprisonment for a period of six months to two years.
- (Added: 24/3/2016-6698/30 art.) A person who unlawfully monitors data transfers within an information system or between information systems using technical means without accessing the system shall be punished with imprisonment from one to three years.
ELEMENTS OF THE CRIME
PERPETRATOR AND VICTIM
The perpetrator of this crime can be any person. It is sufficient for the perpetrator to illegally enter or remain in the information system. The victim can be the natural or legal person who owns or uses the information system. For example, a person who gains unauthorized access to a company's computer system could be the perpetrator of this crime, while the company is the victim.
VERB
The act constituting this crime is to unlawfully enter or remain in a computer system. For the act to occur, the perpetrator must gain unauthorized access to or remain in the computer system. For example, a person illegally entering another person's computer to examine or copy data constitutes this crime.
ILLEGALITY
The crime must be unlawful. The act of accessing or remaining in an information system must occur without the owner's consent and in an unlawful manner. For example, actions taken by a system administrator within the scope of their job description would not be considered unlawful.
CASTE
The crime defined in Article 243 of the Turkish Penal Code is a crime that can only be committed intentionally. The perpetrator must knowingly and willingly carry out the act of illegally entering or remaining in an information system.
AGGRAVATED FORM OF THE CRIME
Article 243 of the Turkish Penal Code also regulates certain aggravated forms of the crime. These aggravated forms are situations that require a more severe punishment for the crime:
- SYSTEMS AVAILABLE FOR A FEE: If these offenses are committed using systems available for a fee, the penalty may be reduced by up to half.
- LOSS OR ALTERATION OF DATA: The penalty is increased if the data contained in the system is lost or altered as a result of the commission of the crime.
- MONITORING DATA TRANSMISSIONS: Anyone who unlawfully monitors data transmissions within an information system or between information systems using technical means without accessing the system shall be punished with imprisonment for one to three years.
IMPORTANCE AND PLACE IN PRACTICE
Article 243 of the Turkish Penal Code aims to ensure information security by regulating unlawful access to information systems. The regulation of this crime is of great importance in terms of protecting information systems and data. Companies, public institutions, and individuals, in particular, should act with awareness of this legal regulation in order to counter threats to the security of information systems.
CASE STUDIES AND JUDICIAL DECISIONS
SUPREME COURT OF APPEALS, 11TH CRIMINAL DIVISION Date: 19.03.2012
Case No: 22385
Decision No: 3683
“Given the allegation that the defendant, while working at the plaintiff company, used the internet password given to him due to his job, and after leaving the workplace, used it without authorization to access the plaintiff company's IT system and remained there, and the defendant's defense confirming this allegation by accessing the plaintiff company's IT system with his invalid password and remaining there for a sufficient period to redirect the emails of the company's employees to a site he created; instead of convicting the defendant on the grounds that the elements of the crime under Article 243/1 of the Turkish Penal Code, namely unlawfully accessing or remaining in an IT system, have been fulfilled, a verdict of acquittal has been issued as written…”
CONCLUSION
Article 243 of the Turkish Penal Code aims to protect information security and data integrity by regulating unlawful access to information systems. This provision acts as a deterrent against cybercrimes and protects the rights of individuals and institutions regarding information systems. Therefore, it is of great importance for lawyers and all individuals working in the field of information technology to have a good understanding of the content and application areas of Article 243 of the Turkish Penal Code and to act accordingly.
Law Student Intern
Osman Recep Gülşen
