

Cloud Accounts in Turkish Criminal Investigations: Can Police Access Foreign Servers? 2026 Guide
Can Turkish police access Google, Apple, Microsoft, social-media or other cloud data stored abroad? Learn how foreign-server evidence, international judicial assistance, seized phones and cloud accounts are handled in Turkish criminal investigations in 2026.
A foreign national whose phone, computer or online account becomes part of a criminal investigation in Turkey may face a question extending far beyond the physical device:
Can Turkish authorities access data stored in a foreign cloud account or on servers located outside Turkey?
Potentially, yes—but the answer is not as simple as physically seizing a phone and opening the files stored on it.
Modern digital evidence can be distributed across several locations. A photograph visible on a phone may actually be synchronized with a cloud service. An email may be stored on servers abroad. Messages may be accessible through a linked computer. Documents may be stored in a corporate cloud account controlled from another country.
When relevant data is held by a foreign service provider or located abroad, Turkish authorities may need international judicial-cooperation mechanisms, provider cooperation or other legally available procedures to obtain it.
The Turkish Ministry of Justice explains that international mutual legal assistance may be used to obtain information and evidence, documents and records, conduct searches and seizures, and perform other evidentiary measures in another state. Under Law No. 6706, the Ministry of Justice serves as Turkey’s Central Authority for international judicial cooperation in criminal matters.
For foreign suspects, however, several separate questions must always be distinguished:
Can investigators access the physical device?
Can they access an account already authenticated on that device?
Can they obtain information directly from the service provider?
Can they compel production of data physically held in another country?
These are not necessarily the same legal procedure.
Cloud data broadly refers to digital information stored or processed through remote infrastructure rather than exclusively on the user’s physical device.
Potential examples include:
A foreign suspect may therefore have relevant information distributed across a phone, laptop, cloud account and foreign service provider simultaneously.
Possibly both.
Cloud systems frequently synchronize information across several locations.
For example, a photograph may exist:
Similarly, an email visible through a smartphone application may primarily be stored on a provider’s server.
The defense should therefore identify the actual source of every piece of digital evidence.
Potentially, but the legal basis depends on how access occurs.
There is an important distinction between:
data already stored locally on a seized device
and
data that must be retrieved remotely from a cloud provider.
The Ministry of Justice’s Digital Evidence Guide recognizes that investigators may encounter situations where physical or remote access to relevant information is not possible and that obtaining records may require cooperation from third parties such as hosting or internet-service providers.
Accordingly, the fact that investigators possess the suspect’s phone does not necessarily mean they automatically have unrestricted legal authority to obtain every piece of information stored in every foreign cloud account connected to it.
This should not be assumed.
A smartphone may provide technical access to accounts containing information far beyond the locally stored data.
For example, a seized phone could potentially be connected to:
The scope and legal basis of the digital examination should therefore be assessed carefully.
Physical possession of the device and remote acquisition of additional information can raise different legal and privacy questions.
This can create a particularly sensitive issue.
A seized device may already contain an authenticated session.
Technically, opening an application could potentially expose remotely stored information without requiring investigators to enter a new password.
But technical accessibility and legal authority are separate questions.
Defense counsel should determine:
These questions can become important when determining whether evidence was obtained within the lawful scope of the digital examination.
Yes, potentially.
Where information is held abroad, international mutual legal assistance can provide a formal mechanism for obtaining evidence.
The Ministry of Justice describes international criminal mutual legal assistance as cooperation through which one state’s judicial authorities perform investigative or evidentiary measures for another state. Available measures can include obtaining information and evidence, acquiring original or certified records, tracing relevant property or information, and conducting searches and seizures.
The precise procedure depends on factors including:
The Ministry of Justice plays a central role.
Under Law No. 6706 on International Judicial Cooperation in Criminal Matters, the Ministry of Justice acts as Turkey’s Central Authority for international mutual legal assistance. The Ministry’s Directorate General for Foreign Relations and European Union Affairs carries out these functions.
This means a Turkish prosecutor investigating data held abroad may, where necessary, use formal international judicial-cooperation procedures rather than simply exercising Turkish investigative powers directly in another state’s territory.
Potentially.
Emails can become relevant evidence in investigations involving:
If the relevant records are held by a foreign provider, the prosecutor may need to identify the provider and determine the appropriate mechanism for obtaining the data.
The Ministry of Justice expressly lists the procurement of information, evidence, records and documents among the matters capable of being pursued through international criminal mutual legal assistance.
Potentially.
Foreign-hosted social-media evidence can include:
However, not all categories of information are treated identically.
Provider policies and foreign law can affect what information is available and the legal process required.
The Ministry of Justice maintains specific guidance concerning international mutual legal assistance for internet-related offences and explains that traffic and IP information associated with foreign internet providers may need to be requested through international judicial channels.
A service may be widely used in Turkey without the relevant evidentiary records actually being controlled in Turkey.
The Ministry of Justice’s internet-crime guidance explains that for certain foreign service providers, relevant traffic or IP records may need to be sought from the judicial authorities of the country where the provider is based.
Accordingly, having a local office or commercial presence does not necessarily mean that the local entity possesses or controls the relevant criminal-evidence data.
Generally, territorial jurisdiction makes this more complicated than searching a device physically located in Turkey.
A Turkish authority ordinarily cannot simply execute domestic coercive investigative powers inside another sovereign state’s territory as though the foreign server were physically located in Turkey.
International cooperation exists precisely because evidence frequently needs to be obtained across borders.
The Ministry of Justice explains that international mutual legal assistance operates through bilateral treaties, multilateral conventions and, where no treaty applies, international custom and reciprocity.
No.
The fact that information is stored abroad does not make it automatically inaccessible to Turkish criminal proceedings.
It may instead affect:
Cross-border evidence is therefore often procedurally more complicated rather than legally impossible.
International mutual legal assistance is the formal process through which one country’s judicial authorities request another country’s authorities to perform an investigative or evidentiary act.
The Turkish Ministry of Justice lists measures including:
as matters that may be addressed through international criminal judicial assistance.
For cloud evidence, the process may therefore be used when relevant records are under foreign jurisdiction.
A request cannot simply say:
“Send us everything belonging to this foreigner.”
Ministry of Justice guidance states that international mutual legal assistance requests should contain information including the requesting judicial authority, factual allegations, relevant legal provisions, the assistance sought and the purpose for which the evidence or information is requested.
The requested state then generally executes the request according to its own law.
This can be important where the defense argues that a request was excessively broad or unrelated to the alleged offence.
Not necessarily.
A core principle of international mutual legal assistance is that the requested state generally executes the evidentiary measure according to its own domestic law.
The Turkish Ministry of Justice expressly states this principle in its international judicial-assistance guidance.
Therefore, whether a foreign provider must produce particular cloud data may depend partly on the law of the country receiving the Turkish request.
Some forms of international judicial cooperation may involve examining whether the alleged conduct is criminal in both countries.
The Ministry of Justice notes that applicable conventions and bilateral agreements can permit refusal of assistance where conduct is not criminalized in the requested state.
The precise rule depends on the applicable treaty, requested measure and foreign law.
Cross-border investigations frequently involve urgency because electronic evidence can disappear quickly.
The Ministry of Justice’s materials on international criminal cooperation discuss mechanisms designed to facilitate rapid information sharing in cybercrime investigations.
For defense purposes, the same practical concern is important: potentially exculpatory cloud information should be identified early before retention periods expire.
Yes, relevant exculpatory evidence should not be ignored simply because it is located abroad.
For example, cloud evidence might establish that:
Defense counsel can identify the evidence and request appropriate investigative steps.
Suppose a foreign national is accused of sending a fraudulent email from an account.
Account-security records may reveal:
These records can help test whether the accused person actually controlled the account.
Account compromise is a significant digital-attribution issue.
Evidence may include:
A suspect claiming account compromise should preserve these records immediately.
Simply asserting “my account was hacked” may be less persuasive than producing objective account-security evidence.
Shared credentials can create attribution problems.
This is common in businesses.
A company cloud account may be accessed by:
Therefore:
account ownership does not necessarily equal authorship of every action performed through the account.
Foreign-owned companies may use cloud platforms for:
If investigators obtain data from a corporate cloud account, the defense should determine:
Corporate cloud attribution can be considerably more complex than identifying the nominal account owner.
They can be highly useful.
Depending on the platform, logs may show:
But logs should be interpreted carefully.
An IP address does not automatically identify a human user, and shared accounts can complicate attribution.
Cloud logs should therefore be compared with other evidence.
Potentially, depending on the legal authority and technical circumstances.
A cloud backup can contain information that is no longer visible on the physical phone.
This could include:
However, accessing remotely stored backup information raises questions distinct from merely examining local device storage.
Defense counsel should determine whether the forensic examination retrieved information locally or initiated remote access to cloud-hosted material.
Potentially.
Deleting information from the current device does not necessarily mean every historical backup has been identically modified.
Whether an older backup contains the information depends on:
This can become important in investigations involving allegedly deleted communications.
Potentially, yes.
Evidence does not become unusable merely because the server was located abroad.
The important questions include:
The geographic location of the server is therefore one factor rather than an automatic exclusion rule.
The defense should determine whether the prosecution can establish where the data came from.
Relevant questions include:
A PDF printout of an email and provider-generated technical records may raise very different evidentiary questions.
Once foreign digital evidence is obtained, its handling becomes important.
The defense may examine:
Digital evidence should be capable of meaningful verification.
Cloud providers may record timestamps in:
A Turkish criminal file may use local time.
A failure to convert timestamps correctly can distort the timeline.
For example:
21:00 UTC and 21:00 local time are not necessarily the same event time.
This is especially important where prosecutors compare foreign cloud logs with:
Yes.
A cloud production may cover only:
The defense should determine the exact scope of the production.
Missing data does not necessarily mean it never existed.
Yes.
Screenshots can potentially provide evidence, but they may not reveal:
Where authenticity or completeness is disputed, underlying provider records or forensic evidence may become important.
Potentially relevant third-party data may become part of an investigation, but the scope of collection matters.
The Ministry of Justice’s Digital Evidence Guide recognizes that evidence may be held by third parties and that investigators may need cooperation from hosting providers and other service providers to obtain logs and service records.
However, a corporate account can contain extensive unrelated confidential information.
Defense counsel should examine whether the collection was appropriately connected to the investigation.
A cloud account may contain communications with lawyers alongside ordinary business records.
Where privileged or legally protected communications are implicated, separate legal safeguards may become relevant.
A foreign executive whose corporate email account is collected should therefore immediately inform counsel if legally protected communications may be included.
That is highly risky.
A person who becomes aware that an account may contain relevant evidence should not attempt to destroy, alter or remotely erase potentially relevant information.
Deleting an account may also eliminate exculpatory material.
The safer approach is to preserve the account and obtain legal advice.
A foreign suspect should not attempt to erase a seized device through a cloud account.
The Ministry of Justice Digital Evidence Guide recognizes that connected devices can potentially be remotely modified, locked or erased, which is one reason investigators use preservation procedures when handling mobile devices.
Attempting remote deletion after seizure can seriously complicate the defense.
Yes.
Cloud evidence can be exculpatory.
For example:
The defense should therefore investigate cloud evidence proactively rather than treating it solely as prosecution evidence.
A significant constitutional development occurred in 2026.
On 12 February 2026, the Turkish Constitutional Court annulled specified portions of Article 134 of the Criminal Procedure Code governing searches, copying and seizure involving computer systems and records. The Court concluded that the statutory framework lacked sufficient safeguards in several respects concerning digital data and privacy.
However, the Court ordered the annulment to take effect nine months after publication of the decision in the Official Gazette, rather than immediately.
This distinction is essential for criminal investigations conducted during 2026.
Counsel must examine:
It would be incorrect to assume that the Constitutional Court’s February 2026 ruling immediately eliminated the existing Article 134 framework.
The Constitutional Court emphasized the extraordinary quantity of personal information capable of being contained in digital systems.
Its 2026 decision identified deficiencies including the absence of sufficient rules concerning matters such as examination of digital data, integrity safeguards and the storage and destruction of forensic copies and personal information.
Cloud accounts can contain even broader datasets than an individual computer.
Accordingly, scope, necessity, integrity and privacy safeguards are particularly important when criminal investigations expand from a physical device into remote accounts.
No.
The decision should not be interpreted as a universal exclusion of digital or cloud evidence.
The legality of particular evidence depends on:
Each case therefore requires individual analysis.
Cross-border electronic evidence remains an active area of legal development.
In April 2025, the Ministry of Justice and the Council of Europe held a workshop specifically concerning development of Turkey’s legal framework for cybercrime and electronic evidence, including issues arising in the collection and assessment of electronic evidence.
This continuing work reflects a practical reality: modern criminal evidence frequently crosses national borders even when the suspect and alleged offence are physically located in Turkey.
The suspect should not immediately assume that the authorities possess every record in the account.
Counsel should determine:
Where cloud-account evidence is used against a foreigner in Turkey:
Potentially, yes. Where evidence is located abroad, Turkish authorities may use international mutual legal assistance or other legally available cooperation mechanisms. The Ministry of Justice acts as Turkey’s Central Authority under Law No. 6706.
Cross-border coercive evidence collection ordinarily raises territorial-jurisdiction issues. Formal international judicial cooperation may therefore be required when evidence is under another state’s jurisdiction.
It should not be assumed that physical seizure automatically authorizes unrestricted remote access to every connected account. The legal basis, scope and manner of the digital examination should be reviewed.
Potentially. International mutual legal assistance can be used to obtain relevant information, evidence and records from abroad.
Potentially. Ministry of Justice guidance specifically addresses international judicial-assistance procedures for obtaining IP and traffic information connected with foreign internet providers.
Potentially. Whether deleted material remains available depends on the application, backup configuration, synchronization, encryption and retention arrangements.
Yes. Potential challenges may concern legality, scope, authenticity, completeness, attribution, timestamps, account access and technical integrity.
No. Shared credentials, corporate accounts, compromised accounts and multiple devices can create attribution issues. Audit logs and other evidence may be needed to identify the actual user.
Yes. Login records, security alerts, document history and other cloud information may establish unauthorized access, another user’s activity or facts supporting the foreigner’s defense.
The foreigner should preserve relevant accounts and devices, avoid deleting or remotely altering data, and have counsel determine exactly what information was obtained, from whom, through which legal procedure and what the technical records actually establish.
Cloud evidence can make a criminal investigation significantly more complicated because the physical location of the suspect, the device, the account and the server may all be different.
A foreigner’s phone may be seized in Turkey while the relevant email account, backup, business documents or security logs are controlled by a provider abroad.
The central defense questions are therefore not simply whether investigators obtained data, but how the data was obtained, which jurisdiction was involved, what was actually produced, whether the records are complete and authentic, and whether they genuinely identify the foreigner as the person responsible for the alleged act.
Fırat Fesih Kaya Law Office provides criminal-law assistance to foreign nationals, employees, executives, investors, tourists and foreign-owned companies involved in digital-evidence and cybercrime investigations in Turkey.
Lawyer Fırat Fesih Kaya assists foreign clients with cloud-account evidence, foreign-server records, international evidence requests, seized phones and computers, email and social-media evidence, IP and login records, deleted data, digital forensic examinations, account-attribution disputes and challenges to unlawfully or unreliably obtained electronic evidence.
Early intervention can be particularly important because cloud providers may apply retention periods and because potentially exculpatory login records, security alerts and other digital information can disappear over time.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower No:148, 06520 Balgat, Çankaya, Ankara, Turkey
This publication is provided for general informational purposes and does not constitute legal advice. The collection and use of cloud evidence in Turkey must be assessed according to the location and controller of the data, the investigative measure used, applicable international cooperation rules, authorization, technical integrity and circumstances of the individual criminal investigation.