The rapid expansion of the digital landscape, coupled with the ubiquity of social media networks, forums, and instant messaging applications, has profoundly reshaped communication. While these technological iterations facilitate unprecedented connectivity, they simultaneously engender sophisticated vectors for rights violations. Among these emerging digital threats, doxxing (ifşa) has evolved from an obscure internet subculture practice into a widespread weapon for online harassment, vigilantism, extortion, and reputational destruction.
In the jurisdiction of the Republic of Turkey, doxxing is not merely a violation of digital etiquette or platform terms of service. It constitutes a severe infringement of fundamental constitutional rights—specifically the right to privacy and the protection of personal data under Article 20 of the Turkish Constitution.
This comprehensive legal analysis explores the dual regulatory and punitive framework governing doxxing and personal data breaches in Turkey. It examines administrative, civil, and criminal liabilities under the Law on the Protection of Personal Data No. 6698 (KVKK) and the Turkish Penal Code No. 5237 (TCK), supplemented by landmark precedents from the Court of Cassation (Yargıtay) and the Constitutional Court (AYM).
1. Deconstructing Doxxing: Technical Concept and Legal Definition
The Mechanics of Online “Ifşa”
The term “doxxing”—derived from altering the abbreviation “docs” (documents)—refers to the malicious act of gathering, aggregating, and publicly releasing identifying information regarding an individual or corporate affiliate without authorization, typically via the internet. In Turkish socio-legal discourse, this phenomenon is widely categorized under the broader term ifşa (unauthorized exposure or disclosure).
Doxxing typically targets data points that can bridge a victim’s digital pseudonymity with their physical, real-world existence. The targeted data routinely includes:
- National Identification Numbers (T.C. Kimlik Numarası)
- Residential, corporate, or school addresses
- Personal telephone numbers and private email addresses
- Employment history and workplace details
- Financial records, banking details, or asset ownership data
- Private photographs, correspondence log captures, and biometric indices
- Sensitive family lineages, medical histories, or ideological orientations
The Legal Nature of Data Subject to Doxxing
Under Turkish jurisprudence, the legality of the disclosed information does not hinge on whether the data was previously obscure or public. Even if an individual’s phone number or workplace is discoverable through professional registries, aggregating and broadcasting that information with malicious intent, or without a legal processing basis, converts the act into a statutory breach.
The core legal asset protected here is informational self-determination—the autonomous right of a natural person to decide when, how, and to what extent their personal attributes are communicated to others.
2. Regulatory Compliance and Administrative Liability Under KVKK No. 6698
The Law on the Protection of Personal Data No. 6698 (KVKK), enacted in 2016 and heavily modeled after the European Union’s Directive 95/46/EC (the predecessor to the GDPR), forms the statutory bedrock for data processing compliance in Turkey. Doxxing activities structurally violate the fundamental principles of data protection codified within this regulatory framework.
┌────────────────────────────────────────┐
│ UNAUTHORIZED EXPOSURE (DOXXING) │
└───────────────────┬────────────────────┘
│
┌────────────────────────┴────────────────────────┐
▼ ▼
┌───────────────────────────────┐ ┌───────────────────────────────┐
│ ADMINISTRATIVE TRACK │ │ CRIMINAL TRACK │
│ (KVKK No. 6698) │ │ (TCK No. 5237) │
├───────────────────────────────┤ ├───────────────────────────────┤
│ • Data Controller Liability │ │ • Illicit Recording (Art. 135)│
│ • Unlawful Processing Fines │ │ • Unlawful Dissemination │
│ • Security Breach Penalties │ │ or Acquisition (Art. 136) │
│ • Board Enforcement Orders │ │ • Destruction Failure(Art.138)│
└───────────────────────────────┘ └───────────────────────────────┘
Violation of Fundamental Core Processing Principles (Article 4)
Article 4 of the KVKK mandates that all processing of personal data must strictly conform to specific baseline principles. Doxxing fundamentally breaches these commands:
- Lawfulness and Conformity with Fair Play: Acquiring data surreptitiously or utilizing it to target an individual is inherently contrary to the principle of good faith (dürüstlük kuralı).
- Accuracy and Being Up-to-Date Where Necessary: Doxxing often relies on outdated, out-of-context, or purposefully manipulated datasets to generate maximum reputational damage.
- Processing for Specific, Explicit, and Legitimate Purposes: The purpose of doxxing is invariably extrajudicial punishment, harassment, or character assassination, which lacks any legitimate legal purpose.
- Relevance, Appropriateness, and Restraint (Proportionality): Broadcasting a target’s entire identity profile to millions of internet users to highlight a minor private dispute totally invalidates the rule of proportionality.
The Problem of the “Natural Person” Exemption (Article 28/2-a)
A common defense raised by individual doxxers is Article 28(1)(a) of the KVKK, which states that the law does not apply if personal data is processed by a natural person solely within the scope of completely personal or family-related activities, provided that data security obligations are respected and the data is not disclosed to third parties.
The Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) and appellate bodies have consistently rejected this defense in doxxing cases. Once an individual uploads another person’s identification, contact details, or private correspondence to a public social media platform or a non-restricted group chat, the processing transcends “solely personal or family-related activities.” By disseminating the data to an indeterminate number of third parties, the exemption is voided, subjecting the perpetrator to the full force of administrative enforcement.
Administrative Fines and Data Security Violations (Article 12 & Article 18)
Data controllers—including corporate entities, law firms, e-commerce platforms, or public repositories whose systems are breached or leaked to fuel a doxxing campaign—face severe systemic liabilities.
Under Article 12 of the KVKK, data controllers must implement all necessary technical and organizational measures to ensure an appropriate level of security to prevent the unlawful processing of, and access to, personal data. When employee records, client registries, or user databases are compromised and weaponized online, the Board conducts exhaustive compliance audits.
| Violation Type (KVKK Article 18) | Enforcement Mechanism | Statutory Scope / Impact |
| Failure to Fulfill Data Security Obligations (Art. 12) | Administrative Fines (Adjusted annually via revaluation rates) | Applied to Data Controllers failing to prevent data leaks or unauthorized secondary access. |
| Failure to Notify Breaches (Art. 12/5) | Board Sanctions and Public Disclosure | Mandatory 72-hour notification to the Board and affected data subjects upon detecting a breach. |
| Non-Compliance with Board Decisions | Severe Financial & Administrative Penalties | Failure to implement deletion, correction, or blocking mandates issued by the Board. |
3. Criminal Liability Under the Turkish Penal Code (TCK) No. 5237
While the KVKK manages administrative compliance and institutional oversights, the Turkish Penal Code (TCK) actively punishes the individual or coordinated actors who perpetrate doxxing. The TCK dedicates a specialized section—Ninth Chapter: Crimes Against Privacy and the Secret Sphere of Life—to penalizing these infractions.
Article 135: Unlawful Recording of Personal Data (Kişisel Verilerin Kaydedilmesi)
The preliminary stage of most doxxing operations involves gathering, cataloging, and storing the target’s information into localized spreadsheets, text documents, or specialized folders.
TCK Article 135/1: Any person who unlawfully records personal data shall be sentenced to imprisonment for a term of one to three years.
If the doxxer compiles data concerning an individual’s political opinions, philosophical beliefs, religious affiliations, racial origins, moral tendencies, health conditions, or sexual orientations, the offense elevates to a qualified state:
$$ \text{Base Sentence (1 to 3 Years)} \times 1.5 = \text{Qualified Sentence (1.5 to 4.5 Years)} $$
Under Article 135/2, if sensitive data is recorded unlawfully, the penalty is automatically increased by one-half.
Article 136: Unlawfully Acquiring, Disseminating, or Exhibiting Personal Data (Verileri Hukuka Aykırı Olarak Verme veya Ele Geçirme)
Article 136 represents the primary statutory mechanism utilized by public prosecutors to charge individuals who engage in doxxing or online “ifşa”.
┌────────────────────────┐
│ TCK ARTICLE 136/1 │
└───────────┬────────────┘
│
┌────────────────────────────┼────────────────────────────┐
▼ ▼ ▼
┌──────────────────┐ ┌──────────────────┐ ┌──────────────────┐
│ DELIVERY │ │ DISSEMINATION │ │ ACQUISITION │
│ (Verme) │ │ (Yayma) │ │ (Ele Geçirme) │
├──────────────────┤ ├──────────────────┤ ├──────────────────┤
│Transferring data │ │Broadcasting data │ │Seizing control of│
│to a single third │ │to an indefinite │ │protected personal│
│party explicitly. │ │public audience. │ │data fields. │
└──────────────────┘ └──────────────────┘ └──────────────────┘
The text of the statute establishes a severe penal baseline:
TCK Article 136/1: Any person who unlawfully gives, disseminates, or acquires the personal data of another person by any means shall be sentenced to imprisonment for a term of two to four years.
For an act of doxxing to trigger Article 136, the material element requires one of three alternative actions (seçimlik hareket):
- Giving (Verme): Passing the personal data to a specific third party (e.g., transmitting a target’s private phone number to an aggressive online group via a direct message).
- Disseminating (Yayma): Making the data accessible to an indeterminate number of people. This is the classic doxxing scenario—posting residential addresses on Twitter/X, publishing ID cards on Telegram channels, or indexing personal emails on forums.
- Acquiring (Ele Geçirme): Gaining dominion or control over data that was previously outside the perpetrator’s lawful access (e.g., phishing a database or hacking a device to obtain a target’s contact sheet).
Aggravating Circumstances and Heightened Penalties (Article 137)
The criminal exposure deepens significantly if the doxxing is executed by utilizing structural social privileges or technological access points. Under TCK Article 137, the sentences prescribed in Articles 135 and 136 are increased by one-half if the crime is committed:
- By a public official abusing their official authority or public office duties (e.g., a police officer, tax clerk, or municipal employee pulling a target’s address from a state database like MERNİS for personal disputes).
- By capitalizing on the systemic convenience or professional accessibility provided by a specific profession, art, or trade (e.g., a bank employee exporting financial details, a telecommunications engineer extracting call logs, or a legal professional leveraging judicial records outside the scope of an active, lawful defense).
Under these aggravated conditions, the minimum statutory prison term for a basic data dissemination offense under Article 136 escalates sharply from 2 years to 3 years, with a maximum potential ceiling of 6 years of imprisonment.
4. Distinguishing Personal Data Breaches (TCK 135/136) from the Violation of Private Life (TCK 134)
A persistent point of confusion in digital litigation centers on the boundary between personal data violations and crimes against the confidentiality of private life. The General Assembly of Criminal Chambers of the Court of Cassation (Yargıtay Ceza Genel Kurulu) has issued crucial framework decisions designed to demarcate these statutory applications.
The Scope of Article 134 (Özel Hayatın Gizliliğini İhlal)
Article 134 specifically penalizes the act of violating the secrecy of an individual’s private sphere, particularly through the secret recording or unauthorized public exposure of images or audio recordings that capture intimate personal moments.
The Analytical Framework: Data vs. Intimacy
To determine whether an online exposure falls under Article 134 or Article 136, courts analyze the content and context of the exposed media:
- Application of TCK 136: If a doxxer posts an individual’s driver’s license, professional portrait, work phone number, or an ordinary photograph taken in a public park, the act is charged under Article 136. These items constitute “personal data” because they identify a natural person, but they do not intrinsically expose an intimate secret or a hidden aspect of their private life.
- Application of TCK 134: If the exposure includes video footage captured secretly inside a victim’s home, recordings of highly confidential personal conversations, or images revealing physical or sexual privacy, the act breaches the inner core of private life. This elevates the charge to Article 134, which carries a sentence of two to five years of imprisonment.
As emphasized by the 12th Civil Chamber of the Court of Cassation, where an image or audio file contains distinct attributes of both crimes, prosecutors must evaluate the exact nature of the privacy breach to prevent incorrect sentencing classifications.
5. Procedural Enforcement, Evidence Collection, and Remedy Strategies
Successfully prosecuting doxxing offenses and mitigating ongoing damage requires rapid, highly specialized legal intervention. Digital evidence is volatile and can be permanently altered, deleted, or anonymized within minutes.
Overcoming Anonymity and Jurisdictional Walls
A major hurdle in doxxing litigation is that perpetrators often operate via anonymous social media accounts or encrypted messaging platforms (e.g., Telegram, Signal, or ProtonMail) that do not maintain local offices within Turkey. This prevents local authorities from directly serving standard judicial data localization requests.
To overcome this roadblock, legal practitioners must utilize a multi-layered evidentiary and defensive strategy:
┌────────────────────────────────────────┐
│ DOXXING DETECTED / LEAK ACTIVE │
└───────────────────┬────────────────────┘
│
┌────────────────────────────┼────────────────────────────┐
▼ ▼ ▼
┌──────────────────┐ ┌──────────────────┐ ┌──────────────────┐
│STEP 1: LITIGATION│ │STEP 2: INJUNCTIVE│ │STEP 3: RECOURSE │
│ EVIDENCE │ │ REMOVAL │ │ & SAVINGS │
├──────────────────┤ ├──────────────────┤ ├──────────────────┤
│• Blockchain time-│ │• Law No. 5651 │ │• Criminal charges│
│ stamping. │ │ Article 9. │ │ filed via TCK. │
│• Notarized e- │ │• Urgent access │ │• Civil litigation│
│ tastik captures.│ │ blocking orders.│ │ for damages. │
└──────────────────┘ └──────────────────┘ └──────────────────┘
1. Immutable Evidentiary Preservation
Standard screenshots are routinely challenged in Turkish courts due to the ease of digital manipulation and forging. It is critical to secure metadata-validated digital captures immediately.
- Legal teams should utilize specialized platforms that verify and timestamp web pages directly onto a blockchain ledger, or obtain an official electronic confirmation via the Turkish Notaries Association’s electronic determination portal (e-tespit).
- Practitioners must preserve full URL structures, account identification numbers (which remain static even if the username is changed), and underlying network routing information where available.
2. Urgent Content Removal and Access Blocking (Law No. 5651, Article 9)
To limit ongoing harm, victims must immediately seek to restrict public access to the leaked information. Under Article 9 of Law No. 5651 (Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications), individuals whose personal rights (kişilik hakları) are violated due to online publications can apply directly to a Criminal Judge of Peace (Sulh Ceza Hakimliği).
The judge is legally required to evaluate the petition and issue an ex parte decision within 24 hours. If the petition is approved, an urgent order is dispatched directly to the Access Providers Union (ESB) to block access to the specific URLs or remove the offensive content within 4 hours.
3. Initiation of Ex Officio Criminal Investigations
Violations under TCK Article 136 (Unlawful Dissemination of Personal Data) are classified as public order offenses and are not subject to a complaint statute of limitations (şikayete tabi değildir). Once a public prosecutor is notified via a formal criminal complaint, they must initiate a rolling investigation ex officio.
The case cannot be abandoned or dropped even if the victim later forgives the perpetrator or reaches a private settlement. The matter proceeds directly to a full public trial (kamu davası) before a Criminal Court of First Instance (Asliye Ceza Mahkemesi).
6. Civil Law Remedies: Tort Liability and Claims for Damages
Beyond administrative fines and criminal imprisonment, doxxing inflicts quantifiable financial devastation and intense emotional distress on its victims. To address this, the Turkish legal system provides robust civil remedies rooted in the Turkish Code of Obligations (TBK) and the Turkish Civil Code (TMK).
Protection of Personality Rights (TMK Article 24 & 25)
Article 24 of the TMK establishes that any person whose personality rights are unlawfully violated may sue for protection against the attackers. Through this civil pathway, a victim can request the court to:
- Determine the presence and unlawfulness of the ongoing attack.
- Enjoin, halt, or prevent imminent threats or repetitions of the doxxing campaign.
- Order the defendant to publish the final court verdict in prominent media outlets to restore the victim’s professional and social standing.
Material and Moral Damages (TBK Article 49 & 56)
Doxxing constitutes a clear-cut digital tort (haksız fiil) under Article 49 of the TBK, which dictates that any person who causes damage to another unlawfully—whether intentionally or through negligence—is bound to indemnify that damage.
┌────────────────────────────────────────┐
│ CIVIL COMPENSATORY REMEDIES │
└───────────────────┬────────────────────┘
│
┌────────────────────────────┴────────────────────────────┐
▼ ▼
┌──────────────────────────────────────┐ ┌──────────────────────────────────────┐
│ MATERIAL DAMAGES (Art. 49 TBK) │ │ MORAL DAMAGES (Art. 56 TBK) │
├──────────────────────────────────────┤ ├──────────────────────────────────────┤
│• Direct financial loss mitigation │ │• Mitigation of psychological trauma │
│• Security infrastructure costs │ │• Compensation for anxiety and shock │
│• Proven income or commercial loss │ │• Non-punitive emotional restitution │
└──────────────────────────────────────┘ └──────────────────────────────────────┘
Material Damages (Maddi Tazminat)
The plaintiff can claim direct financial losses caused by the leak. For example, if a corporate executive or prominent attorney is doxxed, they can seek compensation for documented loss of business, costs incurred from changing residential locations for physical safety, expenditures for private security infrastructure, and fees paid to digital risk mitigation firms to scrub the leaked data from the internet.
Moral Damages (Manevi Tazminat)
Under Article 56 of the TBK, a judge can award a non-trivial sum of moral damages to compensate for the psychological trauma, acute anxiety, social isolation, and reputational injury suffered by the victim. In evaluating the amount of moral damages, the court reviews the social and economic status of both parties, the viral reach of the doxxing content, and the severity of the malice demonstrated by the defendant.
7. Strategic Synthesis: The Intersections of Digital Liability
Navigating a doxxing crisis requires understanding how administrative, criminal, and civil enforcement mechanisms interact in practice. The following comparative matrix outlines the distinct roles, proof standards, and primary outcomes of each legal pathway:
| Legal Arena | Governing Legislation | Primary Regulatory Body / Forum | Proof Standard Required | Primary Remedial Outcome |
| Administrative | KVKK Law No. 6698 | Personal Data Protection Board (Kurul) | Balance of probabilities, institutional compliance audits, and systemic system logs. | Heavy administrative fines levied on organizations and corrective deletion mandates. |
| Criminal | Turkish Penal Code (TCK) | Criminal Courts of First Instance (Asliye Ceza) | Beyond a reasonable doubt; requires clear proof of intent (kast) and verified metadata. | Imprisonment terms (2 to 6 years) and permanent criminal records for individuals. |
| Civil | TMK No. 4721 / TBK No. 6098 | Civil Courts of First Instance (Asliye Hukuk) | Preponderance of evidence proving an unlawful act, actual injury, and proximate causation. | Financial restitution through material and moral damage awards; permanent injunctions. |
8. Conclusion: The Critical Need for Proactive Digital Defense
Doxxing is a dangerous form of digital violence that threatens individual safety and foundational privacy rights. As online communities grow, the potential for malicious data exposures increases exponentially. The legal framework of the Republic of Turkey treats these acts with appropriate severity. By combining the compliance mandates of the KVKK with the strict punitive measures of the TCK, the law provides a robust mechanism to hold bad actors accountable.
For legal practitioners, corporate compliance officers, and high-exposure individuals alike, defending against doxxing requires a proactive strategy. Organizations must maintain strict, audited access logs to protect their databases from being used as sources for leaks.
When a breach occurs, victims must act quickly—using secure electronic time-stamping, moving fast to block access under Law No. 5651, and filing parallel criminal and civil actions. Only by consistently enforcing these statutory tools can we deter digital bad actors and preserve the fundamental right to personal data security in the digital age.
Yanıt yok