

A foreign employee is accused of unauthorized access to company systems in Turkey. Learn about criminal liability, digital evidence, access permissions, employee accounts, forensic examination and defense options.
A foreign employee working in Turkey may suddenly face a criminal investigation after an employer alleges that they entered a company server, e-mail account, database, cloud platform, customer-management system or another digital environment without authorization. These allegations can arise after dismissal, resignation, an internal investigation, a shareholder dispute or suspected disclosure of confidential information. However, the fact that an employee technically accessed a system does not by itself resolve whether the access was criminal. A proper investigation should examine the employee’s actual authorization, job responsibilities, access credentials, timing of the alleged access, technical logs, intent and what the employee allegedly did after entering the system.
Turkish criminal law contains specific provisions concerning unlawful access to information systems and other computer-related conduct. Depending on the facts, allegations may involve unauthorized entry into or remaining within an information system, interference with data or systems, obtaining information, misuse of credentials or additional offenses connected with the alleged conduct.
The precise criminal characterization depends on what actually happened.
An employee may legitimately have access to certain company systems but not others. Authorization can depend on department, position, project, security level and specific duties.
The investigation should therefore determine the actual limits of the employee’s authority at the relevant time.
A common dispute arises where the employee had routinely accessed the same system for months or years before the employer later characterizes the access as unauthorized.
Employment contracts, job descriptions, internal policies, e-mails and historical access records can become important defense evidence.
Some workplaces use shared accounts or credentials. If several employees knew the same password, a login associated with that account may not establish which individual actually performed the disputed action.
The technical evidence must therefore be analyzed carefully.
A log showing that a particular account was used does not necessarily prove that the account holder personally performed the activity.
Investigators may need to consider the device used, IP information, authentication records, physical access, timestamps and other corroborating evidence.
An IP address can be important digital evidence, but its meaning depends on the network architecture and circumstances.
Corporate networks, VPN systems, shared internet connections, remote-access systems and dynamic addresses can complicate attribution.
Many foreign employees work remotely or travel internationally. Company VPN systems may create records that appear different from the employee’s physical location.
VPN logs, authentication records and remote-access policies should therefore be preserved.
Access after termination can create greater risk, particularly if the employee’s authority had clearly ended.
However, investigators should still establish who accessed the system, whether credentials remained active, what information was accessed and what actions were performed.
If an employer leaves an employee’s account active after termination, that fact may become relevant to the technical and factual analysis.
It does not automatically make every later access lawful, but it can affect the surrounding circumstances and evidence concerning authorization.
Entering a system and copying confidential files are not necessarily the same act.
The prosecution should identify what conduct is alleged: login, viewing information, downloading files, deleting records, forwarding documents or transferring information to another person.
If investigators allege that the employee downloaded customer lists, financial data, source code, trade secrets or internal documents, additional legal issues may arise.
The defense should determine exactly which files were allegedly copied and whether the employee ordinarily needed them for work.
Employees sometimes send documents to personal e-mail accounts for remote work. After an employment dispute, the employer may characterize those transfers as data theft.
The context, workplace practice, document contents and subsequent use of the files can therefore become important.
Company documents may be transferred through cloud platforms or collaboration systems. Access history, synchronization records and sharing permissions can help reconstruct what happened.
Preservation of provider and company logs should be considered immediately.
An allegation that an employee intentionally deleted, altered, corrupted or made data inaccessible can involve substantially different criminal issues from a simple access allegation.
Forensic analysis should determine whether deletion actually occurred and which account or device performed it.
Modern laptops and cloud applications may automatically synchronize files without the employee manually downloading each document.
Technical evidence should distinguish deliberate user actions from automated system processes.
Server logs, computers, mobile phones, external drives, e-mail records and cloud data can change or disappear.
Both the investigation and defense may therefore depend heavily on timely preservation of digital evidence.
A foreign employee accused of unauthorized access should consider whether relevant logs may eventually be overwritten under the company’s retention policy.
Appropriate legal steps may be necessary to preserve evidence capable of supporting the defense.
Internal company reports can be useful evidence, but the defense should determine how the records were generated, preserved and interpreted.
A spreadsheet prepared by the employer after the dispute is not necessarily equivalent to original forensic data.
A digital forensic expert may need to examine devices, server records, authentication logs, metadata and other technical evidence.
The objective is to reconstruct the actual sequence of events rather than rely on assumptions.
If a company laptop or phone is seized or examined, records concerning collection, imaging and preservation can become important.
The defense may question whether the evidence remained technically reliable throughout the process.
If investigators believe a personal device contains relevant evidence, search or examination measures may become an issue under Turkish criminal procedure.
The scope and legal basis of the examination should be reviewed carefully.
The fact that a laptop belongs to the employer does not by itself answer every criminal-procedure question concerning the collection and examination of digital evidence.
The manner in which evidence was obtained can remain legally relevant.
Employers may submit screenshots alleging that an employee discussed unauthorized access or shared company information.
Screenshots should be evaluated for authenticity, completeness, context and connection with the accused person.
Deletion does not necessarily mean that a communication cannot be recovered or reconstructed from another device, backup or digital record.
Conversely, an allegation that messages were deleted does not itself prove criminal conduct.
The circumstances surrounding the access may matter significantly.
An employee performing assigned work presents a different factual situation from someone deliberately bypassing restrictions to obtain information for an unrelated purpose.
An employee may violate an internal IT policy without necessarily satisfying all elements of a criminal offense.
Employment disciplinary liability, civil liability and criminal liability should therefore be analyzed separately.
A criminal complaint starts or contributes to an investigative process; it does not establish guilt.
The prosecutor must evaluate the evidence and circumstances.
A foreign suspect has procedural rights in Turkish criminal proceedings, including the right to understand the accusation and exercise applicable defense rights.
Where the suspect cannot adequately understand Turkish, interpreter rights become particularly important.
A foreign employee should carefully review the content of any police or prosecutor statement before signing it.
Translation errors concerning technical terminology can materially change the meaning of an explanation.
Words such as server, administrator account, VPN, remote desktop, authentication, database and cloud synchronization may have precise technical meanings.
An inaccurate translation can create the false impression that the suspect admitted conduct they were actually trying to explain.
Relevant evidence may include employment contracts, job descriptions, authorization e-mails, IT tickets, project instructions, remote-working policies, historical access records and communications with supervisors.
These materials may demonstrate that disputed access was part of ordinary work.
Once an investigation is anticipated, deleting messages, wiping devices or destroying records can create additional evidentiary problems.
Preserve potentially relevant information.
If police search the employee’s residence or seize digital devices, the legal basis, scope and execution of the measure should be examined.
Any challenge to the evidence should be based on the specific circumstances of the search and seizure.
Depending on the seriousness and circumstances of the investigation, judicial-control measures may potentially affect a foreign suspect’s ability to travel.
Foreign nationals who regularly travel for work should therefore address criminal-procedure issues promptly.
A criminal investigation and immigration status are legally distinct matters, but developments in a criminal case can potentially create additional immigration concerns for a foreign national.
The criminal defense strategy should therefore consider the person’s wider legal position in Turkey.
If forensic evidence demonstrates that another employee used the account, the access was authorized or the alleged event never occurred, that evidence should be placed before the investigating authority as early as strategically appropriate.
Investigate credential sharing, device access, authentication methods and physical presence.
Witness statements alone may not resolve a technical attribution dispute where multiple persons had access to the same credentials.
Office-entry records and security-camera footage may show whether the accused employee was physically present when an alleged local-system access occurred.
These records may be retained only for limited periods, making early preservation important.
Create a minute-by-minute or event-by-event timeline connecting logins, e-mails, VPN sessions, device activity, physical location and communications.
A well-constructed timeline can expose contradictions in the allegation.
Where the Turkish company is part of an international group, servers may physically be located abroad and access permissions may be controlled by a foreign parent company.
The defense may therefore require evidence from multiple jurisdictions.
Unauthorized-access allegations sometimes arise alongside dismissal, severance, confidentiality or trade-secret disputes.
Statements made in one proceeding should be coordinated carefully with the criminal defense.
The employer may seek compensation if it alleges that unauthorized access caused financial loss, data leakage or business interruption.
Causation and the amount of alleged damage should be independently examined.
A foreign employee accused of unauthorized access should identify the exact system and alleged access, preserve employment and authorization evidence, request preservation of server and authentication logs, reconstruct the timeline, determine whether credentials were shared, review VPN and device evidence, preserve relevant communications, avoid deleting digital information and obtain legal assistance before providing detailed statements on complex technical allegations.
No. The employee’s authorization, purpose, system involved and specific conduct must be examined.
Yes, depending on the circumstances. Possession of valid credentials does not necessarily answer whether a particular access was authorized.
Not necessarily. Network configuration, VPN use, shared connections and other technical evidence may need to be examined.
They can be relevant because shared credentials may complicate attribution of particular actions to one individual.
Potentially. Their source, integrity, interpretation and relationship with other digital evidence can be examined.
The employee should preserve evidence showing job responsibilities, instructions and ordinary workplace practices supporting that explanation.
Digital devices can become subject to criminal-procedure measures where the applicable legal requirements are satisfied. The legal basis and execution of the measure should be reviewed.
Interpreter rights are particularly important so that the suspect can understand proceedings and provide an accurate defense.
A complaint is not itself proof of guilt. The criminal allegation must be evaluated together with the evidence.
Preserve digital and employment evidence immediately. Unauthorized-access cases frequently turn on technical logs, permissions and timelines that can disappear quickly, so the defense should establish what the employee was actually authorized to access and who performed the disputed digital activity.
Criminal allegations involving company systems can require simultaneous analysis of cybercrime law, digital forensic evidence, search and seizure, employment permissions, confidentiality obligations and the procedural rights of foreign suspects. Fırat Fesih Kaya Law Office assists foreign employees, executives and international companies involved in criminal investigations concerning alleged unauthorized system access, company data and digital evidence in Turkey. Lawyer Fırat Fesih Kaya provides legal assistance during police and prosecutor proceedings, digital-evidence disputes, search and seizure challenges and related criminal proceedings.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower, Office No:148, 06520 Balgat, Çankaya, Ankara, Turkey