ARTICLE 244 OF THE TURKISH PENAL CODE: WHAT YOU NEED TO KNOW ABOUT THE CRIME OF OBSTRUCTION AND DISRUPTION OF THE SYSTEM
ARTICLE 244 OF THE TURKISH PENAL CODE: CRIME OF OBSTRUCTION, DISRUPTION, DESTRUCTION OR ALTERATION OF DATA
ENTRANCE
In what could be called the information age, the importance of information technologies and digital systems is steadily increasing. These technologies have become an integral part of our lives, both at the individual and corporate levels. Therefore, any interference with these systems can have serious consequences. Article 244 of the Turkish Penal Code regulates and prescribes sanctions for unlawful actions against information systems in this context. This article will examine in detail the crime of "obstructing, disrupting, destroying, or altering data in a system" as evaluated under Article 244 of the Turkish Penal Code.
The provision of Article 244 of the Turkish Penal Code
Article 244 of the Turkish Penal Code is structured as follows:
- Anyone who obstructs or disrupts the functioning of an information system shall be punished with imprisonment for one to five years.
- Anyone who corrupts, destroys, alters, or renders inaccessible data in an information system, inserts data into the system, or transmits existing data to another location shall be punished with imprisonment for a period of six months to three years.
- If these offenses are committed on an information system belonging to a bank or credit institution, or a public institution or organization, the penalty shall be increased by half.
- If the acts defined in the paragraphs above result in an unjust gain for oneself or another person, and this does not constitute another crime, the perpetrator shall be sentenced to imprisonment for two to six years and a judicial fine of up to five thousand days.
ELEMENTS OF THE CRIME
PERPETRATOR AND VICTIM
The crime defined in Article 244 of the Turkish Penal Code concerns information systems, therefore the perpetrator must be someone with access to and the ability to interfere with these systems. The victim, on the other hand, can be a natural or legal person who has legal protection over the information system. For example, an employee who unauthorizedly enters a company's information processing system and modifies data could be the perpetrator of this crime, while the company is in the position of the victim.
VERB
This crime can be committed in four different ways:
- SYSTEM DISRUPTION: Partially or completely halting the operation of an information system.
- SYSTEM DISRUPTION: Interrupting the normal operation of the system or rendering it completely inoperable.
- DATA DESTRUCTION: The unlawful deletion of information from the system.
- DATA ALTERATION: Unlawfully altering data within the system.
ILLEGALITY
For a crime to occur, the act must be unlawful. For example, while it may be lawful for a system administrator to make changes to the system, it is unlawful for an unauthorized person to do so.
CASTE
The crime defined in Article 244 of the Turkish Penal Code is a crime that can only be committed intentionally. The perpetrator must knowingly and willingly interfere with the information system in order to obstruct or disrupt its operation, destroy or alter data.
AGGRAVATED FORM OF THE CRIME
Article 244 of the Turkish Penal Code also regulates certain aggravated forms of the crime. These aggravated forms are situations that require a more severe punishment for the crime:
- OFFENSES AGAINST PUBLIC INSTITUTIONS: If the crime is committed against the information systems of public institutions or professional organizations with the characteristics of public institutions, the penalty is increased by half.
- TRANSFER OR DESTRUCTION OF DATA: If, as a result of a crime, data belonging to another person is transferred to another location without permission or destroyed, the penalty shall be increased by one-third.
- COMMITTED WITHIN THE FRAMEWORK OF ORGANIZED CRIME: If the crime is committed within the framework of an organized crime activity, the penalty is increased by half.
IMPORTANCE AND PLACE IN PRACTICE
The crimes regulated in Article 244 of the Turkish Penal Code are of great importance in terms of information security and data protection. These crimes aim to protect the functioning of information systems and the integrity of data. Therefore, it is extremely important for companies, public institutions, and organizations operating in the field of information security to be aware of and apply these provisions.
JUDICIAL DECISIONS
13TH CRIMINAL DIVISION OF THE SUPREME COURT OF APPEALS
Case No: 2013/19796
Decision No: 2014/18903
Date: 27.05.2014
Turkish Penal Code Article 244:
Crime of Obstructing, Disrupting, Destroying or Altering Data.
Based on the contents of the file and trial transcripts, the legally valid and relevant evidence gathered and examined and discussed at the decision-making stage, the reasoning, and the judge's discretion, it has been determined that there is no procedural or legal irregularity in accepting that the crime was committed by the defendant, and the other appeals have also been deemed unfounded.
However;
1-) Article 244/4 of the Turkish Penal Code states, "...If the act defined in the paragraphs above results in an unjust gain for oneself or another person, and this does not constitute another crime..." This indicates that the provision in this paragraph is a secondary norm. Accordingly, after first assessing whether other crimes that can be committed through the use of information systems as defined in the law have occurred, and if the act does not fit the definition of any of these crimes, it is considered that the act constitutes a crime under Article 244/4 of the Turkish Penal Code; The defendant's actions, in which he accessed the complainant's bank account online and transferred 1000 TL belonging to the complainant to his own account via EFT and withdrew it on the same day, were deemed to constitute the crime of "theft by means of information technology" as defined in Article 142/2-e of the Turkish Penal Code, as explained in the decision of the Supreme Court Criminal General Assembly dated November 17, 2009, numbered 193/268. The intent of the defendant was to transfer the movable property in the complainant's bank account to his own account using an information system, to cause a decrease in the complainant's assets against their will, and to acquire property by taking the money represented by this data, rather than sending the data elsewhere
According to the acceptance;
2) Acting contrary to the third paragraph of Article 53/1 of the Turkish Penal Code by failing to consider that the deprivation of parental, guardianship, and trusteeship powers under clause (c) of the same article would continue until the conditional release date with respect to "their own descendants,"
3) The non-application of Article 58 of the Turkish Penal Code to the defendant who has a prior criminal record constituting recidivism
CONCLUSION: The judgment is hereby REVERSED in accordance with the notification, as the appeal of the defendant AK is deemed justified, and the acquired right is protected pursuant to Article 326/last paragraph of Law No. 1412, via Article 8/1 of Law No. 5320. The decision was made unanimously on May 27, 2014.
CONCLUSION
Article 244 of the Turkish Penal Code aims to ensure the safe use of information technologies by regulating unlawful acts against information systems. This provision acts as a deterrent against cybercrimes and protects the rights of individuals and institutions regarding information systems. Therefore, it is of great importance for lawyers and all individuals working in the field of information technology to have a good understanding of the content and application areas of Article 244 of the Turkish Penal Code and to act accordingly.
Law Student Intern
Osman Recep Gülşen
