What should companies do if they detect unlicensed software?
What should companies do if they detect unlicensed software?
What legal and practical steps should companies take if unlicensed software is detected? This guide covers copyright infringement under the Turkish Copyright Law (FSEK), triple compensation, damages, penalty risks, evidence management, and corporate compliance.
In the digital business world, software is no longer a tool, but the business itself. Since a significant portion of processes such as accounting, engineering, architecture, design, data management, human resources, and production are carried out through software, the detection of unlicensed software represents not just a technical vulnerability for companies, but a multifaceted legal risk. In Turkish law, computer programs are protected under the Law on Intellectual and Artistic Works; this law regulates the financial and moral rights of authors and outlines legal and criminal remedies in case of unauthorized use. Computer programs are specifically defined in the law and are also protected as scientific and literary works. The current consolidated text, including the amendments made by Law No. 7346, is in effect as of December 25, 2021.
Therefore, when unlicensed software is detected in a company, the first question to ask is not "Does this program work?" but "Under what license, by how many users and devices, since when, and for what commercial purpose is this program being used?" This is because Article 22 of the Turkish Copyright Law regulates the direct or indirect, temporary or permanent reproduction of copies of a work as the exclusive right of the author. In the case of computer programs, this protection is not limited to the classic act of copying; it also encompasses a broad scope including installation, operation, storage, and saving processes. Therefore, unauthorized installations within a company often constitute not only a breach of contract but also a copyright infringement.
The first reflex should not be panic, but controlled self-assessment
When unlicensed software is discovered, the most common mistake companies make is to hastily clean up their systems, silently uninstall programs, or delete log records. This reflex often does more harm than good legally. Because, according to Article 76 of the Copyright Law, in legal cases arising from copyright disputes, the court can request the necessary permissions and authorization documents or a list of the works used from the software user if the plaintiff presents sufficient evidence; the failure to provide these documents creates a presumption of unlawful use. In criminal investigations, Article 134 of the Code of Criminal Procedure allows for searching, copying, and, if necessary, seizing computers, programs, and files if there is strong suspicion based on concrete evidence and the inability to obtain evidence otherwise. Therefore, the first step is not to destroy evidence, but to determine the current situation in a controlled manner.
The next step is to initiate a swift but disciplined "license inventory emergency review" within the company. It must be determined which software is installed on which devices, which version is being used, when the subscription or license period began and ended, whether the number of users exceeds the license limit, whether the program is used locally or over a network, and whether the license documents are present in the company archives. Any decision made without this assessment will be incomplete. For example, the same program might be openly pirated on one device while having a valid license on another; the license for one software program might have expired while another simply exceeds the user limit. Legal exposure can only be accurately assessed after this concrete picture is established. This assessment is essential because the law protects computer programs as intellectual property and links the use of financial rights to written permission.
The company must first understand the source of the problem
Unlicensed software doesn't always originate from the same source. Sometimes there's a clearly cracked installation. Sometimes a single-user license is run on numerous computers. Sometimes a trial version effectively becomes a permanent user tool. Sometimes an external IT company installs an unlicensed version under the pretext of "ease of installation." And sometimes the company misinterprets the scope of a legally obtained license in the past, for example, extending authorization granted for only one office to different branches and subsidiaries. Article 38 of the Turkish Copyright Law grants the freedom to reproduce and process a computer program for its intended purpose, provided it has been legally acquired; installation, execution, and error correction of the program are, as a rule, not prohibited. However, this exception applies only to legally acquired software. If there was unauthorized installation, a forged license key, or exceeding the scope from the outset, Article 38 does not provide a protective shield.
The company's accurate identification of the source of the problem determines the subsequent strategy. If the problem is solely a shortage of licenses, the solution may be some form of license replenishment and settlement. If the problem is the use of cracks, keygens, or activation cracking tools, the case carries a higher risk of heavier penalties. If the problem originates from an employee or external supplier, the employer's internal distribution of responsibility also comes into play. Article 66 of the Turkish Copyright Law stipulates that if the violation is committed by the representatives or employees of the business while performing their duties, the business owner can also be sued, and fault is not a requirement for such a lawsuit. Therefore, the defense of "the IT company installed it, we had no knowledge" or "the employee installed it on their own" does not automatically move the company to a safe zone.
Evidence must be preserved, but its unlawful use must not continue
For companies, the most delicate balance lies between preserving evidence and preventing the continuation of the infringement. On the one hand, it is necessary to document the current situation; on the other hand, the conscious continuation of unlawful use can create new risks. Therefore, the most practical approach is to first create a technical overview; then, restrict external access, immediately stop new installations, cease license key sharing, and freeze the use of the program in a controlled manner according to legal assessment. If necessary, a plan should be prepared to switch to alternative licensed software, but records of what is on which device should also be secured during this transition. Because later, the scope of past use will be discussed based on this data in both civil and potential criminal cases. Considering that Article 71 of the Turkish Copyright Law also criminalizes acts such as purchasing, importing, exporting for commercial purposes, possessing or storing software other than for personal use, the continuation of use after detection becomes even more important.
For the same reason, internal company emails, messaging correspondence, license invoices, supplier offers, IT service records, and contracts should also be subjected to separate scrutiny. Because in a license dispute, it's not just whether the program is installed on the computer that matters, but also how that installation was done, who directed it, whether the company has previously purchased licenses, and how it interprets the scope of the license. Especially due to the requirement to present documents and the presumption of unlawful use under Article 76 of the Turkish Copyright Law, the more organized your set of contracts and invoices, the wider your legal maneuvering space will be. Lack of documentation, in most cases, is the company's weakest point.
No step can be considered complete without creating a legal risk map
The third major step a company must take in detecting unlicensed software is to categorize the legal risks. The first risk is lawsuits for the removal and prevention of infringement. According to Article 66 of the Turkish Copyright Law, a person whose financial and moral rights have been violated can demand the removal of the infringement. Article 69 states that a preventive lawsuit can be filed if there is a risk of infringement or if the infringement is likely to continue or recur. These two types of lawsuits can mean that the company is forced to remove the unlicensed software from its systems, its use is stopped, and the unlawful situation is terminated through the courts. Therefore, the issue is not just the risk of paying money; the company's operational flow also becomes vulnerable to interference.
The second risk is the financial aspect. Article 68 of the Copyright Law allows copyright holders to demand from the person who processes, reproduces, distributes, represents, or communicates the work to the public without written permission in accordance with this Law, up to three times the price they could have demanded if a contract had been made, or the current market price. This is one of the most important provisions showing why unlicensed software files are not a simple matter of "completing a missing license." If the company uses particularly expensive CAD, ERP, accounting, design, database, or sectoral enterprise software, the calculation of three times the price can have extremely serious consequences. Demands such as the destruction of the unauthorized copies or their delivery to the copyright holder at an appropriate price may also come into play depending on the specific case.
The third risk is compensation and profit transfer. According to Article 70 of the Turkish Copyright Law, a person whose financial rights have been violated can claim compensation under the provisions of tort law if the infringer is at fault. The same article stipulates that the injured party can also demand that the profits obtained be given to them in addition to compensation. This means that the commercial advantage, project production capacity, or cost reduction that the company gained from using unlicensed software may become a matter of dispute. Therefore, not only the license fee but also the economic benefit the company gained from its use can be brought to court. It is vital for the company to calculate this exposure in its internal assessment beforehand in order to determine its defense strategy.
The fourth risk is the criminal aspect. Article 71 of the Copyright Law stipulates imprisonment for one to five years or a judicial fine for actions such as processing, reproducing, distributing, publicly transmitting, publishing, and commercially purchasing, importing, exporting, possessing or storing illegally reproduced works without the written consent of the rights holder. Article 75 states that investigation and prosecution for these offenses are dependent on a complaint, and for the complaint to be valid, the rights holders or professional associations must submit documents and evidence demonstrating their rights to the Chief Public Prosecutor's Office. For the company, the consequence is this: if the rights holder takes active action, the matter may not remain solely in a civil court; it may also turn into a case before the prosecutor's office.
The fifth risk is precautionary measures. Article 77 of the Copyright Law stipulates that if there is a possibility of substantial harm, imminent danger, or a fait accompli, the court may order the performance or non-performance of a specific action, decide on the closure or reopening of the place where the work is performed, and seize the reproduced copies or means of reproduction. This provision creates significant pressure, especially if the unlicensed software is at the very heart of the company's operations. Because the measure can lead to operational contraction even before the case is finalized. If the company does not recognize this risk early, it will have to base its legal defense not only on the merits of the case but also on the possibility of an emergency measure.
How should a company react if it receives a warning notice from the rights holder?
If a notice of infringement is received from the rights holder or their representative, the company should first avoid a reflex of "denial" and "delaying." This is because, in copyright law, rights holders can pursue both civil and criminal remedies; the Ministry of Culture and Tourism explicitly states that civil or criminal proceedings can be initiated in cases of copyright infringement. The most sound approach is to examine the scope of the notice, the number of licenses requested, the alleged usage period, and any technical findings; compare this with the company's internal inventory; and determine the legal position accordingly. Blind acceptance or reflexively rejecting all claims can be wrong. In some cases, the rights holder may have exaggerated the number of uses; in others, the infringement may be more extensive than the company anticipates.
At this stage, the company should not view correspondence with the other party as merely a commercial negotiation. Software license disputes are copyright disputes carrying the risk of evidence and penalties. Therefore, the response to the warning should be supported by a technical report, license inventory, and contract review. If the company has indeed identified a clear infringement, options for settlement and license completion should often be considered. However, when establishing a settlement, the scope of the past infringement, the potential risk of triple damages, compensation, and the possibility of a penalty complaint should be evaluated together. Otherwise, a hasty acceptance could unnecessarily weaken the company's bargaining power. This conclusion is drawn from reading Articles 68, 70, 71, and 75 of the Turkish Copyright Law together.
External IT firm and employee responsibility should also be investigated
When unlicensed software is detected within a company, viewing the incident solely as a relationship between the rights holder and the company is insufficient. An internal chain of responsibility must also be investigated. Who installed the program, who gave the instructions, what contract was the supply based on, was the IT service outsourced, was a budget allocated for licensing, was the program known to be pirated, were previous managers or employees warned about this? All these questions are important. Because, although Article 66 of the Copyright Law does not eliminate the company's responsibility towards the rights holder, the company needs to correctly identify the source of the incident in order to establish internal recourse and distribution of responsibility. Furthermore, if the external supplier used a counterfeit license, pirated installation, or cracking tool, contractual liability and claims for damages may arise within the internal relationship.
This review is particularly important from a corporate governance perspective. Because a software breach sometimes stems not from a single employee error, but from the company's complete lack of a licensing policy. In such a case, the problem is structural, not technical. If a licensing tracking flow hasn't been established between the purchasing, accounting, IT, and legal departments, the same problem will recur in the future. Indeed, the document submission and presumption regime in Article 76 of the Turkish Copyright Law demonstrates how dangerous it is for companies to leave software usage to chance. If the same weakness recurs in the next audit, the defense position becomes even weaker.
Permanent solution: create a software compliance policy
After detecting unlicensed software, the company's primary task is not just to extinguish the existing problem, but to establish a corporate system that will prevent it from reigniting. This requires documenting a software inventory policy, license purchase and renewal procedures, user-based authorization tracking, prohibitions on trial and training versions, contractual licensing commitments for external IT companies, and processes for restricting access for departing employees. The Ministry of Culture and Tourism's statement that copyright arises from the creation of the work, not registration, also demonstrates that acting on the assumption that "the other party hasn't registered it, so it won't be noticed" is not legally defensible. Protection often already exists; the issue is whether or not you are acting in accordance with that protection.
Within the same framework, companies need to conduct periodic internal audits. Software-license matching should be performed at least once a year to check which programs are actually being used, which are underutilized, which require renewal, and which have exceeded their user limits. This work not only provides legal protection but also reduces unnecessary software costs for the company. License compliance and financial efficiency are often complementary rather than contradictory goals. Therefore, a good compliance system both reduces the risk of litigation and improves budget management. Considering Articles 68 and 76 of the Copyright Law, the cost of such preventative measures is much lower than the price that would be paid if a dispute arises.
Conclusion
When unlicensed software is detected, companies should not panic and secretly delete the programs or leave the matter solely to the IT department. The correct approach is to quickly but systematically identify existing usage, preserve evidence, stop new unlawful use, collect the license and contract set, assess legal exposure within the framework of Articles 66, 68, 69, 70, 71, 75, 76, and 77 of the Turkish Copyright Law, respond consciously to any copyright holder's warning, and ultimately establish a permanent software compliance system. This is because computer programs are protected under Turkish law; the copyright holder can pursue triple compensation, damages, and penalties; the court may request the submission of documents, and the failure to provide documents may create a presumption of unlawful use; in some cases, precautionary measures and digital evidence processes may also be initiated. In short, the detection of unlicensed software is a crisis that needs to be managed quickly but with legal control.
Frequently Asked Questions
Should a company immediately delete software when unlicensed software is detected?
While continued unlawful use should be prevented, panicking and deleting software without gathering evidence and inventory is often the wrong strategy. This is because courts may request documents and lists, and digital examination may be required in criminal investigations.
If a company employee establishes the business, would the employer still be held liable?
Yes, they could. According to Article 66 of the Turkish Copyright Law, if the violation is committed by an employee or representative during the performance of their duties, a lawsuit can be filed against the business owner; fault is not a requirement for this lawsuit.
What monetary claims can the rights holder make?
Depending on the specific case, claims may include up to three times the amount that could have been demanded if a contract had been made, or the market value, as well as tort-based damages and the transfer of profits.
Could this situation lead to a criminal investigation?
Yes. Criminal liability may arise for the acts listed in Article 71 of the Copyright Law; according to Article 75, the investigation is dependent on a complaint, and the rights holder must submit documents and evidence.
What is the strongest company defense?
The strongest defense is a well-organized license inventory, stored contracts and invoices, user-based authorization records, and internal processes established in writing. This is because Article 76 of the Turkish Copyright Law stipulates a presumption of unlawful use if documentation cannot be presented.