

A foreign company’s customer database is stolen in Turkey. Learn about criminal complaints, digital evidence, employee liability, unauthorized copying, data disclosure, evidence preservation and emergency legal remedies.
A customer database can be one of a company’s most valuable commercial assets. It may contain customer identities, contact information, purchasing histories, pricing information, contractual details, sales opportunities, internal notes and other commercially sensitive information. When an employee, former employee, competitor, contractor or unauthorized third party copies or removes this information in Turkey, the incident may create several different legal issues simultaneously. Depending on how the database was accessed, copied, transferred or disclosed, the conduct may potentially involve offenses concerning information systems, unlawful acquisition or disclosure of personal data, commercial secrets or other criminal-law provisions. Foreign companies should therefore avoid treating database theft merely as an employment or contractual dispute. The immediate priorities are usually preserving digital evidence, stopping continuing access, identifying what information was taken, determining how it was obtained and preparing an evidence-based criminal complaint where appropriate.
Database theft does not necessarily require the original database to disappear.
A person may copy information from a company server while leaving the original records untouched. Customer lists may also be downloaded to a personal computer, transferred to cloud storage, sent by email, copied to an external drive, photographed or exported from CRM software.
The central question is therefore often unauthorized acquisition or copying rather than physical removal.
Potential perpetrators can include current employees, former employees, sales representatives, managers, IT personnel, contractors, consultants, business partners or external attackers.
The person’s existing access rights can significantly affect the legal analysis.
An employee may legitimately need access to customer information to perform their job.
That does not necessarily mean the employee is entitled to download the entire database, transfer it to a private device or retain it after leaving the company.
The scope and purpose of authorization should therefore be investigated.
A common scenario occurs shortly before or after resignation.
A salesperson or manager may export customer records before joining a competitor or establishing a competing business. The company should preserve evidence showing when the information was downloaded and what happened immediately afterward.
Once unauthorized access is suspected, the company should consider terminating unnecessary credentials, changing passwords, protecting administrator accounts, reviewing remote access and preventing further extraction.
However, security measures should be implemented in a way that does not unnecessarily destroy evidence.
Removing access may be necessary, but the company should first consider preserving relevant logs and account records.
Deleting an account without preserving associated information can make reconstruction of events more difficult.
Server and application logs can show login times, IP addresses, downloads, exports, unusual queries and other activity.
Relevant logs should be preserved promptly because retention periods may be limited.
If the company uses customer relationship management software, determine whether the system records exports, mass downloads, logins, user activity or changes.
CRM audit trails can become particularly important in employee-related cases.
Review legally accessible corporate email records for suspicious attachments, forwarding, downloads or messages to personal accounts.
Evidence should be collected in a manner consistent with applicable privacy and employment rules.
Customer information may be transferred to personal or unauthorized cloud accounts.
The company should determine whether corporate systems record uploads or synchronization events.
USB devices and external drives may be used to copy substantial amounts of data quickly.
Computer forensic analysis may help establish whether external storage devices were connected and what activity occurred.
If the suspected person used a company laptop or desktop, the device should be secured carefully.
Continuing ordinary use can overwrite valuable forensic information.
Opening files repeatedly, modifying folders or attempting to reconstruct deleted material without appropriate technical procedures can alter metadata.
For significant cases, forensic preservation should be considered.
A forensic copy of relevant digital media can help preserve the condition of the evidence while technical examination proceeds.
The method of acquisition and chain of custody should be documented.
Screenshots can be useful, but they may not establish the complete technical history.
Preserve original files, logs, metadata and system records whenever available.
The company should determine whether the incident involves the complete customer database or only particular records.
Identify the number of customers, categories of information, commercial sensitivity and whether personal data were included.
The commercial value of a database can arise from its organization and additional information.
Purchase histories, negotiated prices, decision-makers, customer preferences, sales forecasts and internal evaluations may be significantly more sensitive than publicly available company names.
The defense may argue that customer identities were publicly available.
The company should therefore distinguish publicly obtainable information from proprietary information generated through its own business activity.
Customer databases frequently contain information relating to identifiable individuals.
Unauthorized acquisition or disclosure may therefore create separate questions under Turkish criminal and personal-data legislation.
Pricing structures, customer-specific conditions, purchasing behavior and confidential business strategies may have commercial-secret characteristics depending on the facts.
The company should explain why the information was confidential and commercially valuable.
Evidence showing that the company treated the database as confidential can strengthen the factual case.
Relevant measures may include password protection, restricted access, confidentiality agreements, internal policies and role-based permissions.
Determine whether employees signed confidentiality, data-security, intellectual-property or post-employment provisions.
Contractual restrictions do not themselves determine criminal liability, but they may help establish the authorized scope of access and the employee’s knowledge of confidentiality.
Internal policies may expressly prohibit downloading customer databases, using personal cloud services, forwarding corporate information or copying files to external storage.
Preserve evidence showing that the relevant person received or accepted those policies.
The answer depends on how the information was obtained and used.
Potential criminal-law issues can arise from unauthorized access to information systems, interference with or copying of digital information, unlawful acquisition or disclosure of personal data, disclosure of protected commercial information or other conduct covered by Turkish criminal legislation.
The precise offense should be determined from the facts rather than labeling every customer-list dispute as “theft.”
If the suspect used another employee’s password, bypassed technical restrictions or accessed a system after authorization ended, the manner of access can become independently important.
Preserve authentication records and access logs.
An employee may have been entitled to see customer information while employed but not entitled to copy and retain it for another purpose.
In these cases, the investigation should distinguish authorized access from the subsequent acquisition, transfer, disclosure or use of the information.
Where the available facts indicate potential criminal conduct, the affected company may submit a criminal complaint to the competent Turkish authorities.
The complaint should explain what happened and attach available supporting evidence rather than relying on broad accusations.
A strong file may include a chronology, identification of the suspect where known, employment or contractual relationship, access permissions, technical logs, forensic findings, emails, database-export records, confidentiality documents and evidence concerning subsequent use.
Prosecutors may need to understand complex IT evidence.
The complaint should explain in straightforward terms what each log or forensic record demonstrates.
An IP address or USB connection may support an investigation but does not necessarily prove every alleged act by itself.
Different pieces of evidence should be analyzed together.
Where the legal requirements are satisfied, digital devices and information relevant to a criminal investigation may become subject to search, examination, copying or seizure procedures under Turkish criminal procedure.
The exact measure depends on the investigation and judicial or prosecutorial decisions involved.
If the company believes the suspect may delete information, destroy devices or erase cloud records, the urgency should be explained clearly when approaching the authorities.
Timing can determine whether digital evidence remains recoverable.
Relevant information may be held by email providers, hosting services, telecommunications companies or other third parties.
Applicable retention periods and lawful evidence-gathering mechanisms should therefore be considered quickly.
Preserve evidence linking the suspect with the recipient.
Emails, messages, employment records, business approaches to customers and unusual customer migration may become relevant.
Do not assume that the competitor necessarily participated knowingly without supporting evidence.
If customers report receiving approaches using confidential details known only to the company, preserve those communications.
Customer testimony may help demonstrate how the database was used.
A group of customers moving immediately after an employee leaves may justify investigation but does not by itself prove criminal conduct.
The company should seek direct digital and documentary evidence.
Depending on the circumstances and available legal remedies, the company may pursue measures intended to stop continued possession, disclosure or use of unlawfully obtained information.
Criminal proceedings may also interact with civil, commercial or employment-law remedies.
A company does not necessarily have to choose only one route.
The same incident may create potential criminal complaints, contractual claims, unfair-competition issues, employment claims and requests for injunctive relief.
The procedural strategy should be coordinated.
Preserve evidence of lost customers, investigation expenses, system-restoration costs and other measurable losses.
Avoid speculative calculations that cannot be connected to the incident.
A foreign-owned or foreign-headquartered company is not excluded from Turkish criminal-law protection merely because its shareholders or management are abroad.
Jurisdiction and procedural representation should be assessed according to the facts.
A foreign company pursuing proceedings in Turkey should prepare the corporate and representation documents necessary for its lawyers to act effectively.
This should be addressed early rather than after an urgent procedural issue arises.
Employees who witnessed unusual downloads, customer-list exports or statements by the suspect should be identified.
Record the underlying facts while memories are fresh.
Internal investigations should preserve reliability.
Employees should be asked what they actually observed rather than encouraged to confirm a predetermined narrative.
Record who collected each device or file, when it was obtained, where it was stored and whether copies were created.
This can help protect the evidentiary value of digital material.
If personal data were compromised, the company should separately assess obligations arising under the applicable personal-data framework.
The criminal investigation does not automatically replace regulatory compliance obligations.
Cybersecurity containment and legal evidence preservation should proceed in parallel.
A company should not allow continuing unauthorized access merely because a criminal complaint has been filed.
If one account was compromised, determine whether the incident extends to other credentials or systems.
The scope of the breach should be established rather than assumed.
Do not prematurely conclude that a departing employee is responsible merely because the timing appears suspicious.
Investigate malware, credential theft, unauthorized remote access and other possibilities where technically plausible.
When a foreign company discovers that its customer database may have been stolen in Turkey, it should immediately secure ongoing access, preserve logs and devices, identify the affected data, establish a forensic timeline, determine the suspect’s authorized access, preserve confidentiality agreements and IT policies, investigate transfers to personal accounts or third parties, assess personal-data implications, document commercial losses and prepare an evidence-based criminal complaint where the facts support one.
Yes. Digital information can be unlawfully acquired, transferred or disclosed even where the original database remains intact. The legal characterization depends on the circumstances.
Potentially. Authorization to use information for employment duties does not necessarily authorize copying, retaining or transferring it for another purpose.
Usually the evidentiary consequences should be considered first. Important forensic information can be lost through unnecessary alteration.
They can help, but original logs, files, metadata and forensic records can provide much stronger technical evidence.
Potentially, yes, where the alleged conduct falls within Turkish criminal jurisdiction and procedural requirements are satisfied.
Digital search, examination or seizure measures may be available where the statutory conditions of Turkish criminal procedure are satisfied and the competent authority orders the relevant measure.
The company should assess criminal-law issues together with its separate obligations under the applicable personal-data framework.
Potentially. Criminal, employment, contractual, commercial and unfair-competition remedies may arise from the same conduct.
Evidence concerning the transfer, recipient’s knowledge and subsequent use should be preserved. Liability should be assessed separately for each person or company involved.
Preserve the digital evidence before confronting the suspected person. Server logs, CRM records, email activity, device metadata and other technical evidence can disappear or be overwritten quickly, while an accusation made before evidence is secured may alert the suspect and make the investigation substantially more difficult.
Customer database incidents can involve cybercrime, unauthorized system access, personal data, commercial secrets, former employees, digital evidence, device examination, criminal complaints and parallel civil proceedings. Fırat Fesih Kaya Law Office assists foreign companies, international investors and corporate executives facing criminal and digital-evidence disputes in Turkey. Lawyer Fırat Fesih Kaya provides legal assistance in preserving evidence, preparing criminal complaints, coordinating forensic findings, representing foreign companies before investigative authorities and evaluating parallel remedies against employees, former employees, competitors and other responsible parties.
Phone:
+90 312 434 22 22
Mobile:
+90 532 769 22 22
Email:
info@firatfesihkaya.av.tr
Address:
Mevlana Boulevard No:221, Yıldırım Tower, Office No:148
06520 Balgat, Çankaya, Ankara, Turkey