Single Blog Title

This is a single blog caption

What should be done if a warning notice is received due to unlicensed software?

What should be done if a warning notice is received due to unlicensed software?

What should you do if you receive a warning notice due to unlicensed software? This comprehensive guide covers triple penalties, damages, penalty risks, evidence gathering, internal company review, and the right defense steps under the Turkish Copyright Law (FSEK).

A cease and desist letter received due to unlicensed software is initially perceived by many companies as merely a "commercial warning." However, such letters are often the beginning of a much larger legal process. In Turkish law, computer programs are protected works under the Law No. 5846 on Intellectual and Artistic Works; the Ministry of Culture and Tourism explicitly states that both civil and criminal proceedings can be initiated in cases of copyright infringement. The current official text of the Law on Intellectual and Artistic Works also defines computer programs separately, and computer programs and, under certain conditions, their preparatory designs are protected.

Therefore, a notice of unlicensed software use should not be seen as a mere sales or marketing tactic. The party sending the notice, often acting as the rights holder, authorized licensor, distributor, or representative of the software, informs the sender that unlicensed or off-license use exists and demands that this use cease, that any missing licenses be completed, that compensation be paid for past usage, or that further legal action will be taken. If the matter is not managed correctly, the process can escalate to demands for cessation of infringement, prevention of infringement, triple compensation, monetary damages, transfer of profits, preliminary injunctions, and even criminal charges. Articles 66, 68, 69, 70, 71, 75, 76, and 77 of the Turkish Copyright Law (FSEK) clearly illustrate this legal framework when read together.

The first important point is this: the receipt of a cease and desist letter does not automatically mean that every claim made by the other party is true. However, ignoring a cease and desist letter is also not safe. Because these documents are often the first official step taken by the rights holder, offering an opportunity for settlement and license completion, and indicating that they will proceed with legal action or prosecution if no resolution is reached. In the Turkish copyright regime, protection is not dependent on mandatory registration; according to the Ministry, a work is protected from the moment it is created, and optional registration only facilitates proof. Therefore, the approach of "if there is no registration, there is no problem" or "let them file a lawsuit first, then we'll see" is often flawed.

Why should a warning letter be taken seriously?

A notice of unlicensed software typically points to three main possibilities. First, the rights holder may genuinely believe the use is unlicensed. Second, a license may exist but be exceeded; for example, a single-user license might be used by a team, an OEM license might be transferred to the wrong device, an educational or trial version might be used for commercial purposes, or usage might continue despite the subscription expiring. Third, the rights holder or their representative may be relying on incorrect or incomplete technical data. The correct strategy is not to accept or reject these three possibilities outright without considering them.

Another reason to take the cease and desist letter seriously is the wide range of claims in copyright law. According to the Ministry's official statement, in cases of copyright infringement, in addition to civil lawsuits, criminal proceedings may also arise for actions such as unauthorized processing, reproduction, distribution, public dissemination, publication, and the purchase, import, export, possession (other than personal use), or storage of illegally reproduced works for commercial purposes. In the case of software, this means that the company may not be able to settle the matter simply by paying the license fee.

The risk is particularly greater if cracks, patches, keygens, fake activations, or other technical tools that bypass license verification have been used. The current official text of the Copyright Law and its 2021 amendments also include actions aimed at rendering technological measures ineffective within the scope of sanctions. Therefore, a warning letter can sometimes indicate that the other party is not only conducting license verification but also laying the groundwork for a potential penalty application.

What should be done in the first 24 hours after receiving the warning notice?

The biggest mistake after receiving a warning notice is to panic and try to clean computers, silently uninstall software, delete log records, ask employees to "repeat the same thing," or attempt to fabricate documents. While such reflexes may seem relieving in the short term, they weaken the defense in the long term. This is because, in both civil and criminal proceedings, the decisive factor is the presentation of the current situation with concrete evidence. Article 134 of the Code of Criminal Procedure allows for searching, copying, and, if necessary, seizing computers, computer programs, and files in cases of strong suspicion based on concrete evidence and the inability to obtain evidence otherwise. Article 400 of the Code of Civil Procedure, on the other hand, opens the way for the identification of evidence if there is a possibility that the evidence may be lost or that it will be difficult to present it in the future.

Therefore, the key to success in the first 24 hours is not to destroy evidence, but to preserve it and understand the situation. Within the company, it's crucial to first identify which software received the warning, on which devices or user accounts this software was installed, under what license model it was used, where the invoices and contracts are located, who accessed the subscription management panel (if any), and who provided IT support in the past. This work is the backbone of the defense. Because without seeing the technical picture of the case, you cannot accurately assess either your legal risk or your potential for settlement.

Secondly, new installations must be stopped immediately, and expansion should be prevented if there is license key or user account sharing, but existing evidence must be preserved. This is the fine line between “not continuing the infringement” and “not destroying the evidence.” Especially with cloud software, user assignments, device logs, and access logs can be critical for your defense later. Hasty removal without seeing the current picture can also destroy records that would refute the opposing side's claim.

Should the warning notice be answered immediately?

Yes, but not without consideration. Ignoring a cease and desist letter is often not a good idea; it can create the perception on the other side that "the allegations went unanswered, therefore the process might be tougher." Conversely, a hasty written admission such as "we were wrong, we will complete the licenses" can unnecessarily burden the company. The correct approach is to first conduct an internal review, then formulate a measured and controlled response. This response might include requesting an extension of time if necessary, informing that a technical review is underway, requesting clarification of the requested documents and alleged use, or noting that the allegations are partially disputed.

The primary goal here is neither to remain silent nor to surrender defenselessly. If the claims are technically vague, the opposing party may be asked to clarify which product, version, number of users, date range, and license infringement pattern they are basing their claims on. Abstract statements such as "unlicensed use has been detected in your company" are insufficient for a sound legal assessment. Any acceptance made without concretizing the dispute often creates an unnecessary burden. This approach is consistent with the Turkish Copyright Law's systematic approach, which evaluates the scope of licenses and the use of financial rights within the framework of written permission.

What kind of internal review should be conducted within the company?

Following a warning notice, an internal company review should be conducted in four layers. The first layer is the technical inventory. It should be clarified which devices or user accounts have the relevant software, which version is installed, how long it has been active, which license key was used, and how many users are visible in the network or cloud management panel. The second layer is the contract and document set. Invoices, license agreements, reseller offers, subscription renewal emails, admin panel screens, and product terms (if any) should be gathered together. The third layer is the purpose of use. Was the software actually used for commercial activity, or was it retained for training/trial/testing purposes? The fourth layer is the chain of responsibility. Was the installation done by a company employee, an external IT firm, or did a former employee leave the account? This should be determined.

This final layer is particularly important because companies often resort to the defense of "the IT firm did it" or "the employee set it up on their own." However, Article 116 of the Turkish Code of Obligations stipulates that the debtor may also be held responsible for the actions of their assistants. Article 66 of the Copyright Law also states that lawsuits can be filed against the business owner for breaches committed by representatives or employees during the course of service, and that fault is not a requirement. In other words, finding the responsible party in an internal relationship is one matter; the company's responsibility to the rights holder is another.

What kinds of lawsuits can be filed?

The first lawsuit that can be filed after a notice of unlicensed software is a lawsuit for the removal of the infringement. Article 66 of the Turkish Copyright Law stipulates that a person whose moral and financial rights have been infringed may request the removal of the infringement. This lawsuit aims to have the software removed, unauthorized installations terminated, and the existing infringement eliminated. The rights holder may resort to this course of action, especially if the unlicensed software is still in active use.

The second type of lawsuit is an action to prevent infringement. Article 69 of the Turkish Copyright Law states that a person whose financial or moral rights are threatened with infringement may sue to prevent the potential infringement. If the use continues or is likely to recur, the opposing party may not only seek retroactive compensation but also demand that future use be stopped. For a company, this can have serious operational consequences, especially if the workflow is dependent on the software.

The third, and often the most significant, financial demand is the triple fee stipulated in Article 68 of the Copyright Law. According to the official text, the rights holder can demand up to three times the price they would have requested if a contract had been made, or the current market value. Therefore, the notice should not be interpreted simply as "let's get the missing license and shut down." Especially in CAD, ERP, accounting, database, and enterprise production software, this demand can reach very substantial figures.

In addition, under Article 70 of the Copyright Law, claims for monetary damages and the transfer of profits obtained through infringement may also arise. If the software was used in commercial activity, the other party may dispute not only the license fee but also the economic benefit obtained from that use. In such cases, a notice of default is often a harbinger of a more comprehensive compensation lawsuit to come.

When does the risk of punishment become real?

The risk of punishment increases particularly in the following cases: if a crack or license-breaking tool is used, if a fake activation is employed, if there is commercial reproduction or systematic use, if the software has been integrated into the business operation for a long time, and if the rights holder frames this situation as intentional infringement. The Ministry's official statement clearly indicates that processing, reproduction, distribution, public transmission, publication without written permission, and acquiring, possessing, or storing illegally reproduced works for commercial purposes are among the circumstances under which criminal proceedings can be initiated. Article 75 of the Law on Intellectual and Artistic Works also states that the investigation and prosecution of these crimes are, as a rule, dependent on a complaint.

Therefore, simply interpreting the warning letter as "they demand money first, then they file a lawsuit" would be incomplete. In some cases, the warning letter may also serve as a final warning to the opposing party before filing a criminal complaint. Especially if there are concerns about the loss of evidence, or if there are technical indications that the opposing party is using cracks or similar tools, the prosecution process can be initiated more quickly. Article 134 of the Code of Criminal Procedure also strengthens this possibility.

Why is evidence gathering and document submission critical?

One of the most important issues after receiving a notice of unlicensed software use is determining the burden of proof. Article 76 of the Copyright Law gives the rights holder a strong advantage. If the plaintiff presents sufficient evidence, the court can request the necessary permission and authorization documents or a list of the protected works used from the user; failure to provide these constitutes a presumption of unauthorized use. In other words, if you do not have proper license documents, the defense of "we were actually licensed" can be seriously weakened.

The rights holder may also request the determination of evidence in accordance with Article 400 and subsequent articles of the Code of Civil Procedure. If there is a possibility that the evidence may be lost or that it will be difficult to present it in the future, an on-site inspection or expert examination may be requested before the lawsuit is filed; in urgent cases, evidence determination may be carried out without prior notification to the opposing party. This shows that the process after the notice may not remain only at the correspondence stage, but may quickly turn into a technical examination.

Is compromise always the right option?

Not in every case. In some instances, an internal review may reveal a genuine licensing breach or overreach, and a controlled settlement may be more economical than the risk of litigation. However, three questions must be answered before a settlement is reached: Is the alleged use actually legitimate? Is the requested fee reasonable according to the actual licensing model? Has the amount requested for past use been excessively inflated under the threat of a triple-cost settlement? Paying without considering these questions, simply to avoid escalating the issue, can create unnecessary financial losses.

Conversely, in some cases, the opposing party's technical assessment may be exaggerated or inaccurate. For example, a trial version may remain in a test environment, an old employee account may appear active but not actually be in use, or a valid license may exist through a reseller chain. In such cases, hastily writing an acceptance statement unnecessarily narrows the scope of defense. The most appropriate approach is to verify the technical assessment and then take a position.

What language should be used in the response to the warning letter?

The response should use language that doesn't undermine the defense, but also doesn't appear irrelevant. It could state that the opposing party's claims are being examined, that a technical and legal assessment has been initiated within the company, that substantiation of the claims is awaited, that the sharing of certain documents may be requested if deemed necessary, and that the company remains open to discussion at this stage, without implying preconceived notions. Such a response demonstrates both a serious approach to the process and the protection of your defense. Legally, the weakest responses are either complete silence or panicked admissions. This assessment becomes even more crucial when considering the severe consequences under the Turkish Copyright Law and the logic of contractual liability under the Turkish Code of Obligations.

Conclusion

If you receive a cease and desist notice due to unlicensed software, the first step shouldn't be to instinctively delete or deny the content out of fear, but to establish a controlled legal defense. In Turkish law, computer programs are protected works; in cases of copyright infringement, both civil and criminal avenues are open; claims for triple damages, compensation, revocation and prohibition, preliminary injunctions, and digital evidence processes can all occur simultaneously in the same case. Therefore, a cease and desist notice is often the first serious warning sign testing a company's software compliance.

The correct approach is this: first, review the technical and contractual details, preserve the evidence, avoid escalating the new breach, refrain from comprehensive admission, substantiate the other party's claim, and only then decide whether compromise or defense is the more appropriate course of action. A company with a well-organized inventory of licenses, contract sets, user records, and a controlled response strategy is in a much stronger position against a formal notice. A company that lacks any documentation and acts in panic usually chooses the path that leads to the most costly outcome.

Leave a Reply

Call Now Button