Single Blog Title

This is a single blog caption

Unauthorized Use of Cloud Software and Legal Liability

Unauthorized Use of Cloud Software and Legal Liability

In what situations does unauthorized use of cloud software occur? This comprehensive guide examines account sharing, user overload, data processing, data transfer abroad, triple charges, compensation, and penalty risks within the framework of Turkish law (FSEK, TBK, and KVKK).

Cloud-based software, unlike classic desktop programs, relies not only on an installation file but also on user accounts, subscription duration, session authentication, centralized management, and often remote data processing infrastructure. Therefore, the issue of unauthorized use in cloud software is no longer just a matter of "pirate copying." Today, many disputes arise from sharing user accounts, exceeding seat limits, usage outside the scope of the subscription, converting trial or training access into commercial activity, opening accounts to group companies or third parties, and circumventing protection mechanisms. In Turkish law, computer programs are protected as works under the Law No. 5846 on Intellectual and Artistic Works; this protection also applies to cloud architecture.

The issue is not limited solely to copyright law. Companies using cloud software often process employee, customer, supplier, or business partner data on the same systems. Therefore, unauthorized use, while creating license and copyright infringement, can also give rise to separate responsibilities in terms of personal data security, the data processor-data controller relationship, data transfer abroad, and technical and administrative security measures. The Personal Data Protection Authority clearly states that a company providing cloud services may act as a data processor in some cases; and that the data controller cannot evade the responsibility of ensuring the necessary level of security.

Why is cloud software different from a traditional licensing relationship?

In the classic licensing model, users often assumed they were receiving local installation and device-based authorization for a specific version. In the cloud model, however, usage rights are often account-based and time-bound. Adobe's current enterprise licensing documents explicitly state that the named user licensing model ties application and service usage to a specific individual user, licenses are centrally managed, and compliance tracking is done through the user, not the machine. Autodesk's current support materials state that in subscriptions requiring login, each seat will be assigned to a single "Authorized User" and seats cannot be shared. The Microsoft Service Agreement also stipulates that account information cannot be transferred to another user or entity. This structure forms the basis of cloud software license breaches: even if technical access exists, legal authority is limited according to the person, organization, duration, and scope.

This difference is also important from the perspective of Turkish law. According to Article 52 of the Copyright Law, contracts and transactions relating to financial rights must be in writing, and the rights in question must be specified separately. In other words, the right to use software is not an abstract and unlimited freedom; it must be based on a written and specific legal relationship. The same law also stipulates that a license can be a simple or a full license, that licenses are considered simple unless otherwise agreed, and that the transfer of ownership over a copy of the work does not constitute a transfer of intellectual property rights. Therefore, accessing a user account in a cloud software subscription does not, in itself, grant broad usage rights.

Under what circumstances does unauthorized use of cloud software occur?

The most common form of unauthorized use in cloud software is the sharing of named user or single-user subscriptions within a team. While the use of the same username and password by multiple employees within a company is very common in practice, it can clearly violate the licensing structure. Autodesk's official support explicitly states that in single-user subscriptions, each seat must be assigned to a single authorized user and cannot be shared. The Microsoft Service Agreement also states that account information cannot be transferred to another user or organization. On the Adobe side, the named user model already demonstrates that the license is tied to the user and that this structure is based on centralized compliance tracking. Therefore, the argument that "the same team uses it" often does not provide legal protection in cloud licensing.

The second common type of infringement is actually exceeding the number of purchased seats or users. In growing companies, starting with a few subscriptions and then employing new workers on the same product is a typical behavior that exceeds the scope of the license. Autodesk, in its current audit page, lists "overuse of subscription seats" and "overuse of perpetual seats" as separate categories of non-compliance. This indicates that, from the manufacturer's perspective, excessive seat usage is an independent type of infringement. In Turkish law, the broader use of recognized economic rights over software than permitted cannot be considered insignificant simply because of technical convenience; because Article 68 of the Turkish Copyright Law (FSEK) prescribes aggravated financial consequences in cases of unauthorized processing, reproduction, distribution, representation, or public transmission.

A third typical violation is the continued commercial use of software after the subscription period has expired. In the cloud software ecosystem, users sometimes assume that usage is still permitted because the software can still be opened on the device or access to old files is still possible. However, from a legal perspective, what matters is not just technical access, but the continued right to use the software. The subscription model, by its nature, establishes a usage right tied to a specific period. When the period ends, the company's contractual basis also ends. Continued commercial use after this point can give rise to a copyright infringement dispute in addition to breach of contract.

The fourth important point is the conversion of trial, educational, personal, or consumer subscriptions into commercial activity. Autodesk's educational access documentation clearly states that this access can only be used for learning, teaching, and research purposes, and is closed to commercial and professional use. Within the same ecosystem, it is understood that trial versions are intended for limited-time evaluation and are not designed for production-oriented commercial use. Therefore, for the company to use educational access to prepare a customer project or integrate a trial version into its production chain is not only an "inappropriate option" choice, but also a usage model that exceeds the permitted purpose limits.

The fifth common type of breach is the use of the same subscription by different companies, group companies, subcontractors, or external consultants. In practice, it is common for a cloud software account registered in the name of the central company to be used by branches, subsidiaries, or freelance teams. However, the licensing relationship is often tied to a specific user or organization that is a party to the contract. Especially considering Microsoft's account transfer ban and Autodesk's authorized user structure, it is very easy for de facto sharing between companies to exceed the scope of the license. Intra-group affiliation does not create contractual authority.

One of the most serious forms of infringement is circumventing protective measures. Continuing to use software that is inaccessible due to the expiration of the subscription period through cracks, patches, fake activations, or other technical means constitutes more than just a breach of contract. Law No. 7346, specifically Article 72 of the Copyright Law, has established a broader protection regime for products and tools designed to render technological measures ineffective. WIPO's current legislative record confirms that the Turkish copyright regime has been updated with the 2021 amendments; these changes make acts aimed at circumventing protective measures more visible.

The contractual aspect of unauthorized use of cloud software

Unauthorized use of cloud software often appears as a breach of contract in the initial stages. According to Article 112 of the Turkish Code of Obligations, if a debt is not performed at all or properly, the debtor is obligated to compensate the creditor for the damages unless they prove their innocence. Article 113, on the other hand, allows for the remedy of the consequences of breaches in obligations to perform or not to perform, and, where appropriate, the elimination of the breach. If the number of users, purpose of use, account transfer, session sharing, organizational limits, and contract duration are clearly defined in cloud subscription agreements, their violation directly creates liability for breach of contract.

This contractual liability narrows the company's defense. Because factual explanations such as "the program was working" or "we used it within the team" do not provide legal legitimacy if the limits set in the contract have been exceeded. Furthermore, according to Article 116 of the Turkish Code of Obligations, even if the debtor has entrusted the performance of the obligation or the exercise of the contractual right to auxiliary personnel, the debtor is liable for the damage caused to the other party by these auxiliary personnel while carrying out the work. Therefore, even if the account was shared by an employee, former personnel entered the data, or an external IT firm managed the installation, the company that is a party to the license agreement remains liable in most cases.

Copyright infringement aspect

Unauthorized use of cloud software is not only a breach of contract; it often extends to copyright protection. Since the Turkish Copyright Law protects computer programs as works, the broader commercial use of protected software beyond what is permitted raises the issue of unauthorized use without written permission. The Ministry of Culture and Tourism states that in cases of copyright infringement, civil or criminal proceedings can be initiated; and that processing, reproduction, distribution, public dissemination, publication, and the purchase, import, export, possession (except for personal use), or storage of illegally reproduced works for commercial purposes fall under the scope of sanctions. This statement reveals that cloud software is not subject to a "different legal framework simply because it is in the cloud"; rather, it falls within the copyright regime.

Article 68 of the Turkish Copyright Law is the most severe financial instrument in this context. In cases of processing, reproduction, distribution, representation, or public transmission without written permission, the rights holder may demand up to three times the amount they would have demanded if a contract had been made, or the current market value. In cloud software, named user sharing, exceeding the number of seats, using the wrong license type, or commercial use after the expiration date can form the basis of this demand. For companies, this means that simply purchasing a license later may not eliminate the economic risk of the past period.

Articles 66 and 69 of the Turkish Copyright Law are also important in terms of removing and preventing infringement. The rights holder can request the cessation and prohibition of the infringement. Especially if cloud software is central to the company's daily operations, closing the account or suspending access can have very serious consequences. Since "account access" is as valuable as "installed files" in the cloud model, requests for cessation and removal can be even more effective in creating operational pressure.

Why are data protection and GDPR aspects particularly important?

Cloud software often represents not only the right to use the software but also the data processing infrastructure. Therefore, unlicensed or unauthorized use carries the risk of unlawful access to personal data, viewing by the wrong user, or inappropriate transfer. The "Data Controller and Data Processor" document of the Turkish Personal Data Protection Law (KVKK) explicitly states that a company providing cloud computing services acts as a "data processor" in some cases with respect to data processed on behalf of its customers. This means that the company receiving the cloud software service does not lose its status as data controller; rather, it must establish the data processor relationship correctly.

The Personal Data Security Guide of the Turkish Data Protection Law (KVKK) also states that, in accordance with Article 12 of the Law, the data controller is obliged to take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data and to ensure the preservation of data. The same guide states that the data controller must first identify risks and threats, raise employee awareness, manage relationships with data processors, and evaluate adequate security measures for personal data stored in the cloud. The guide particularly emphasizes measures such as two-factor authentication, access logs, user account management, network security, log records, and backups for data stored in the cloud. These recommendations demonstrate why account sharing or unauthorized access in cloud software is not only a licensing issue but also a data security issue.

If the cloud software infrastructure operates with servers located abroad, the transfer of personal data abroad also becomes an issue. The "Transfer Abroad" page of the KVKK (Personal Data Protection Law) states that, following the 2024 amendments, standard contracts and binding company rules are foreseen as appropriate safeguard methods; and that signing standard contracts announced by the Board may allow data transfer without requiring additional permission. The guide also explains that standard contracts can be used with limited modifications based on the texts announced by the Board. Therefore, regardless of how smooth the licensing relationship of a company using cloud software, a separate KVKK risk may arise if an appropriate transfer mechanism is not established in cloud environments containing personal data.

Why are cloud software programs more sensitive in terms of evidence and proof?

In cloud software disputes, evidence can be more centralized and traceable compared to traditional desktop software. This is because usage is often managed through user accounts, session times, license assignments, product profiles, access history, and an organizational panel. Adobe Admin Console officially states that it offers a centralized panel for license, user, and payment management, and that named user licensing facilitates centralized compliance tracking. Autodesk also explicitly states that in single-user subscriptions, each seat will be assigned to a single authorized user. This structure can make it technically more difficult for the company to conceal unauthorized usage.

In Turkish law, this technical visibility, combined with Article 76 of the Copyright Law, creates a strong burden of proof. When the rights holder provides sufficient initial evidence, the user company can be asked to provide the necessary permissions and authorization documents or a list of the works used; failure to provide these constitutes a presumption of unauthorized use. For companies using cloud software, this makes the retention of license panel records, user assignments, subscription invoices, and access history even more crucial. Simply stating "we were actually licensed" is not enough; it must be demonstrated with account, user, and contract data.

What are the practical implications of cloud software for companies?

In practice, the biggest risk is the assumption that cloud software means "no physical copy, therefore no classic infringement." However, the cloud model often makes infringement more visible, not less so. Unauthorized users, shared accounts, extra seats, transferring an educational version to a commercial project, keeping expired subscriptions in active use, or group company sharing can leave easier traces in centralized systems. This allows the rights holder to more easily establish both contractual and copyright-based claims.

Companies' primary responsibility in this area is not just to purchase software, but to continuously monitor the matching of users, seats, accounts, time, and organizations. Furthermore, data processing agreements, technical and administrative measures, two-factor authentication, access logs, and, if necessary, data transfer mechanisms abroad must be established for cloud systems containing personal data. Otherwise, license breaches and GDPR violations could be combined in the same case. In the cloud age, legal responsibility revolves less around "who installed it?" and more around "who accessed what data, with what authority, and to what extent?".

Conclusion

Unauthorized use of cloud software is a broader and more complex legal area than the classic understanding of software piracy. Account sharing, exceeding seat limits, continuing expired subscriptions, converting trial or educational access to commercial use, opening accounts with different companies or third parties, and circumventing protection measures are the main forms of infringement. In Turkish law, computer programs are protected as works; therefore, unauthorized use of cloud software can result in both breach of contract and copyright infringement. Furthermore, the data controller-data processor relationship, technical and administrative measures, and international data transfer regulations in cloud environments where personal data is processed create separate areas of responsibility.

The safest approach is to manage cloud software not just on the basis of "we purchased a subscription," but with a focus on user and data governance. If a company doesn't manage its licensing roadmap, user assignments, contract scope, and data security measures together, legal risk often begins. In the cloud ecosystem, the measure of legitimacy is not just access; it's about ensuring that access is established by the right person, for the right purpose, for the right duration, and under the right contractual framework.

Frequently Asked Questions

Does sharing a cloud software account within the same team truly constitute a violation?
Many providers' official terms and conditions state that single-user or named-user licenses are personal and that sharing is prohibited. Therefore, sharing passwords within a team often violates the license.

My subscription has expired, but if the program is still accessible, can I continue using it?
Continued technical access does not automatically mean that the contractual right to use the service continues. In a subscription-based model, the essential element is the valid rights relationship.

If the cloud provider is the data processor, does the company's responsibility under the GDPR (General Data Protection Regulation) end?
No. According to the GDPR guidelines and explanations, the data controller is obligated to ensure that the data processor takes the necessary technical and administrative measures.

What is required for data transfer to a cloud server abroad?
Under the current GDPR regulations, standard contracts and binding company rules are stipulated as appropriate safeguards. Using standard contracts announced by the Board may enable data transfer without requiring additional permission.

Can a company still be held liable if an employee or external IT firm has misused the system?
Yes. Article 116 of the Turkish Code of Obligations regulates liability for the actions of auxiliary personnel; furthermore, under Article 66 of the Turkish Copyright Law, a lawsuit can be filed against the business owner for violations committed by employees during the course of service.

Leave a Reply

Call Now Button