

A former employee downloads company data before leaving Turkey. Learn when unauthorized copying of customer lists, trade secrets, files or databases may lead to criminal proceedings, evidence preservation and compensation claims.
An employee who downloads large amounts of company data shortly before resigning, being dismissed or leaving Turkey can create serious legal and commercial risks for the employer. The copied material may include customer lists, pricing information, contracts, source files, financial records, technical documents, business plans, passwords, databases or trade secrets. Under Turkish law, however, the mere fact that an employee downloaded company files does not automatically establish a criminal offence. The legal assessment depends on what information was taken, whether the employee was authorized to access it, how it was copied, whether access continued after authorization ended, whether the information constitutes a trade secret or personal data, and what the employee subsequently did with it.
No. Employees routinely access and download information as part of their jobs. Criminal liability therefore cannot normally be established merely by showing that files were transferred to a computer or storage device.
The employer should determine whether the employee exceeded authorized access, copied information for an unauthorized purpose, transferred it to a personal account, disclosed confidential information or accessed company systems after employment or access rights ended.
The nature of the information is critical. A few ordinary working documents may present a very different case from the mass extraction of a customer database, confidential pricing models, source code, technical designs or strategic documents.
The company should create an inventory of the files allegedly taken.
A detailed customer database may contain names, contact information, purchasing history, prices, commercial preferences and contractual information.
Depending on its content and circumstances, unauthorized extraction can raise issues involving confidentiality, trade secrets, personal data and unfair competitive conduct.
Manufacturing methods, formulas, algorithms, internal pricing, supplier terms, technical drawings, business strategies and other confidential commercial information may constitute valuable trade secrets.
The company should be able to explain why the information was confidential and what measures were used to protect it.
If the allegedly secret information was freely accessible to all employees, publicly available or routinely distributed outside the company without restrictions, establishing its confidential character may become more difficult.
Access controls, confidentiality policies and employment agreements can therefore become important evidence.
Access and misuse are separate questions.
An employee may have legitimately been authorized to open a customer database during employment but not authorized to copy the entire database to a private device for personal use after resignation.
The scope and purpose of authorization should therefore be examined carefully.
If the former employee logs into the company’s system after access rights have ended, different criminal-law issues may arise concerning unauthorized access to information systems.
Companies should therefore disable credentials promptly when employment ends.
Once departure is confirmed, review access to email, cloud services, remote connections, internal servers, customer-management platforms and other systems.
This is both a security measure and an important step in preventing additional loss.
System logs may show that a USB storage device was connected shortly before the employee’s departure.
However, the existence of a USB connection alone does not establish which files were copied or what happened to them afterward.
Technical evidence should be interpreted carefully.
Forwarding confidential files to a private email account shortly before resignation can be significant evidence, particularly where the files have no legitimate remaining employment purpose.
The company should preserve relevant email and security records lawfully.
Files may be transferred through personal cloud storage, file-sharing services or synchronization applications.
IT teams should preserve available logs before retention periods expire.
Messages concerning the transfer, sale or intended use of company information can become relevant.
Employers should nevertheless observe applicable privacy and evidence rules when collecting employee communications.
If a company laptop is returned, avoid immediately reformatting or reallocating it.
Preserving the device in its existing condition may be important if forensic examination becomes necessary.
A qualified digital examination may help determine which files were accessed, copied, deleted, compressed or transferred and when those actions occurred.
The examination should be conducted in a manner that preserves evidentiary integrity.
Record who collected the laptop or phone, when it was collected and where it was stored.
A clear evidence-handling record can reduce later disputes concerning manipulation.
Many systems automatically delete older logs. The company should preserve relevant authentication, download, access and file-transfer records promptly.
Waiting several months can result in important evidence disappearing automatically.
Potentially. If the available evidence indicates conduct that may constitute a criminal offence under Turkish law, the company can evaluate filing a criminal complaint with the competent authorities.
The complaint should describe the concrete conduct and supporting evidence rather than simply characterize the former employee as having “stolen data.”
If the employee accessed an information system without authorization or continued accessing it after authorization ended, provisions concerning information-system offences may become relevant depending on the facts.
The exact technical access history should therefore be reconstructed.
An employee who had lawful system access may still create legal exposure by unlawfully obtaining, using or disclosing particular information.
The investigation should identify the specific conduct rather than attempting to fit every case into a single cybercrime theory.
If confidential commercial information is unlawfully disclosed or transferred to another person or competitor, provisions protecting commercial, banking or customer secrets may potentially become relevant depending on the circumstances.
Evidence showing actual disclosure can materially strengthen the case.
Customer and employee databases may contain personal data.
Unauthorized copying or transfer can therefore potentially raise issues under both criminal-law provisions concerning personal data and Turkey’s data-protection framework.
Where personal data have been exfiltrated, the employer should not focus exclusively on pursuing the former employee.
The company should also evaluate whether the incident triggers internal security, data-breach assessment or other obligations applicable to the data controller.
Evidence that the former employee contacted customers using the downloaded list, joined a competitor, reproduced company documents or used confidential pricing can become highly relevant.
Nevertheless, actual subsequent use is not necessarily the only legally relevant conduct. The precise offence alleged must be analyzed separately.
Employees are generally free to change jobs subject to valid contractual and legal restrictions.
The criminal issue is not simply that the person began working for a competitor, but whether protected information was unlawfully obtained, retained, disclosed or used.
Breach of a contractual non-compete obligation does not automatically constitute a criminal offence.
Contractual remedies, unfair-competition claims and criminal allegations should be separated carefully.
Employment contracts, confidentiality undertakings, IT policies and data-security rules can help establish what information the employee knew was restricted.
They are particularly useful in showing the boundaries of authorized use.
Some information may still receive legal protection even without a standalone non-disclosure agreement.
However, the company’s treatment of the information remains relevant when determining whether it was genuinely confidential.
This is a common defense and should be evaluated against timing and circumstances.
Ask when the download occurred, whether the employee was still working on relevant tasks, how much information was copied, where it was transferred and whether there was a legitimate business reason.
A mass download hours or days before resignation may raise legitimate questions, especially if the employee had never previously downloaded comparable amounts.
Timing alone, however, should not be treated as conclusive proof of criminal intent.
Deletion after discovery does not necessarily resolve the dispute.
The company may still need to determine whether copies exist elsewhere, whether information was disclosed and whether damage already occurred.
Search, seizure and digital examination are criminal-procedure measures requiring the applicable legal conditions and competent decisions.
The employer cannot simply demand that police seize every device belonging to the former employee. The complaint should provide concrete facts capable of supporting the requested investigative steps.
Potentially, if legally authorized within the criminal investigation.
The scope of examination should relate to the investigation, and procedural safeguards concerning digital evidence remain important.
Potentially, where the applicable criminal-procedure conditions are satisfied.
Whether seizure or forensic examination is justified depends on the facts and investigative needs.
Employers should not attempt to hack the former employee’s private email, cloud account or personal devices to recover information.
Unauthorized access can create separate legal problems and jeopardize otherwise legitimate claims.
Document lost customers, cancelled contracts, pricing disadvantage, competitive use of confidential information and investigation expenses where applicable.
This evidence may become relevant to compensation claims.
Depending on the facts, the employer may consider claims seeking cessation of unlawful conduct, protection of confidential information, return or destruction of copied materials and compensation.
Urgent interim protection may also need to be evaluated where disclosure is continuing.
Use or disclosure of confidential business information can potentially raise unfair-competition issues independently of criminal proceedings.
This can be particularly important where information has been transferred to a competitor.
If a competitor knowingly receives or uses confidential company information, the dispute may extend beyond the former employee.
The evidence should establish what the competitor knew and what information it actually received or used.
Before accusing a former employee publicly or contacting a new employer with allegations of theft, the company should verify its evidence carefully.
Unsubstantiated accusations can create additional disputes.
Where appropriate, a formal notice can demand cessation of use, preservation and return of company information, deletion of unauthorized copies and confirmation that data have not been disclosed.
The wording should preserve rather than prejudice potential criminal and civil proceedings.
Leaving Turkey does not automatically eliminate potential criminal liability for conduct allegedly committed in Turkey.
However, the procedural consequences depend on the alleged offence, evidence and location of the individual.
If the former employee transferred information to servers or companies abroad, obtaining evidence can become more complex.
The company should preserve all evidence available in Turkey before pursuing information located abroad.
The employer may have criminal, contractual, employment, unfair-competition and compensation issues arising from the same conduct.
Each legal route has different requirements and should be coordinated strategically.
The company should preserve the employment contract, confidentiality agreement, IT policies, access permissions, resignation or termination documents, server logs, email records, device records, file-access history, customer databases, forensic reports and evidence of subsequent use.
Evidence should be collected lawfully.
When a former employee downloads company data before leaving Turkey, the employer should immediately preserve logs, disable remaining access, secure returned company devices, identify the downloaded information, determine whether access was authorized, preserve confidentiality policies and contracts, consider forensic examination, investigate transfers to private email or cloud systems, assess personal-data exposure, document commercial damage and coordinate potential criminal, civil and interim remedies.
No. The circumstances, authorization, nature of the information and subsequent use must be examined.
Potentially. Authorized access for employment purposes does not necessarily authorize copying confidential information for personal use or disclosure after employment.
Potentially. Their legal protection depends on their content, confidentiality, commercial value and circumstances of acquisition or use.
Company-owned equipment may be examined subject to applicable employment, privacy and evidence rules. Forensic preservation is advisable where litigation is anticipated.
Potentially, where the legal requirements for search, seizure or digital examination are satisfied within a criminal investigation.
No. Employment with a competitor is not itself proof that company information was unlawfully taken or used.
Depending on the circumstances, contractual, civil and other legal remedies may potentially support demands concerning return, deletion or cessation of use.
The company should also evaluate data-protection and potential data-breach consequences, independently of claims against the employee.
Potentially. Criminal proceedings and civil or commercial remedies involve different legal requirements but can arise from the same facts.
Preserve the digital evidence before it disappears. Access logs, company devices, email records and file-transfer information can be lost or overwritten quickly, and the distinction between ordinary employee access and unlawful data extraction often depends on precise technical evidence.
Cases involving former employees can combine cybercrime allegations, trade secrets, confidential company information, personal data, digital evidence, unfair competition and compensation claims. Fırat Fesih Kaya Law Office assists foreign companies, international investors, employers and individuals in Turkey with criminal investigations involving unauthorized access, alleged data extraction and misuse of confidential business information. Lawyer Fırat Fesih Kaya provides legal assistance in preserving digital evidence, preparing criminal complaints and defenses, coordinating forensic evidence, seeking urgent protection for confidential information and managing related commercial disputes.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower, Office No:148, 06520 Balgat, Çankaya, Ankara, Turkey