Smart City Data Sovereignty; Tehran’s Lesson, Istanbul’s Risk

Smart City Data Sovereignty; Tehran’s Lesson, Istanbul’s Risk


Have you ever watched a city from a screen? The morning fog over a river, the crowd at a transit hub, the traffic streaming from one district to another — all of it, through a single dashboard, a single algorithm? Someone is watching. Perhaps someone always has been. But the question has changed: where are those images flowing, under whose law are they being processed — and who is responsible for the data sovereignty of a city?

I. Tehran’s Lesson: The Strategic Risk of Urban Surveillance Infrastructure

According to a Financial Times report citing anonymous sources, Israeli intelligence had penetrated Tehran’s traffic camera network years before Operation Roaring Lion. Those cameras were part of an infrastructure the Iranian regime had built for urban surveillance purposes. The irony is sharp: the system constructed to consolidate the regime’s own control was quietly turned, over the years, into the instrument of its undoing.

Footage was reported to have been encrypted and relayed to servers in Tel Aviv; AI algorithms processed the raw data, mapping the life patterns of Iranian officials — where they went, when, with whom, by which route. When the map was complete, the operation that followed reached its targets swiftly. General Dan Caine’s statements confirm that cyber and space capabilities were integral to the campaign. Not weapons, data. Not fire, pattern.

The war has not ended. Iran survives, and the outcome remains uncertain. Tehran is not a closed file — it is an open one, sitting in front of us.

And on 10 March 2026, one of its pages opened from an unexpected direction.

Michael Rubin, a senior fellow at the American Enterprise Institute (AEI) and former Pentagon adviser, posted in Turkish on his social media account. Rubin has closely followed regional politics since the 1990s and personally managed Iraq and Iran files at the Pentagon; his critical stance toward Türkiye is no secret.

His message, in summary: it is highly likely that traffic cameras in Istanbul and Ankara are similarly accessible. Turkish politicians, drone factory workers, intelligence and military personnel involved in supporting Hamas or Hezbollah or in operations targeting Kurds could have their movements tracked through these cameras — and that information could be shared with relevant actors. He estimated how long such individuals would survive in a potential conflict: a few minutes.

This text, coming from policy circles that are not particularly friendly toward Türkiye, can be read as political provocation, or as a risk notification. From a legal standpoint, that distinction is secondary: a scenario directly concerning the physical safety of Turkish officials was put into the public domain. Rubin offers no technical proof; but he points to an architectural risk grounded in verifiable facts. What are those facts?

II. Istanbul and Ankara’s Traffic Infrastructure: What Do Public Records Show?

On 22 September 2020, while a pandemic held both cities still, Istanbul Metropolitan Municipality (İBB — İstanbul Büyükşehir Belediyesi) signed a 5.1 million dollar grant agreement with the U.S. Trade and Development Agency (USTDA) and American software company SAS Turkey, for the “Istanbul Transportation and Traffic Excellence Center” project. One month earlier, on 20 July 2020, the Ankara Metropolitan Municipality had signed its own 2.5 million dollar agreement with the same USTDA and SAS Turkey, for a “Route and Operations Optimization Project.” The scope: public transit routes, journey times, emergency scenarios — the operational backbone of the Turkish capital.

In 2020, cybersecurity awareness in Türkiye had not reached its current level; Law No. 7545 did not yet exist, and secondary regulations were not yet being discussed. This context matters when evaluating the agreements. The question this analysis raises is not a retrospective criticism of those who signed them — it is about an architecture that is still operating today, under a legal framework that remains incomplete.

The sums may seem modest relative to the scale of urban infrastructure. That impression is not wrong, but the structure behind it matters: the money did not flow to the municipalities. It was paid by the U.S. government to SAS — the American contractor — effectively financing an American technology company’s entry into a foreign market. Small amount, large door.

The project’s stated goals included reducing average journey times and traffic congestion. Six years on, no public outcome report or performance evaluation exists. When İBB responded to allegations in March 2025, it stated that data is stored in its own data center — but offered no assessment of whether the project’s transportation objectives had been met.

USTDA describes itself as the U.S. government’s “first mover” in critical infrastructure development in emerging markets. It operates under the foreign policy guidance of the State Department; its budget justifications state the priorities plainly: “U.S. leadership in critical and emerging technologies” and “service to national security and foreign policy objectives.” SAS, meanwhile, is a longstanding supplier to the U.S. Department of Defense. Its own public sector page states: “SAS’ first customer was the U.S. Federal Government.

Today, every cabinet-level department and all branches of the Department of Defense are SAS customers.” These are not allegations — they are the company’s own public disclosures. Being a supplier does not mean sharing data; but from a legal risk assessment perspective, this relationship cannot be ignored.

III. FISA 702, the CLOUD Act and the Legal Status of Foreign Software

So where is the data from Istanbul and Ankara actually processed?

SAS Viya runs on Microsoft Azure. There is no Microsoft Azure data center region in Türkiye — this is confirmed in Microsoft’s own community forum. The nearest regions are in Western Europe (Netherlands, Ireland) or the Middle East (UAE, Qatar). Whether either contract includes a data localization clause has not been made public.

This is where the legal question begins.

The United States FISA Section 702 establishes a potential access regime under which American technology companies can be compelled to facilitate access to communications and data belonging to foreign nationals — without individualized court orders; the general authorization of the FISA Court suffices. The fact that the target is a Turkish citizen or a Turkish institution changes nothing in this legal calculus. The CLOUD Act goes further: as the U.S. Department of Justice itself defines it, where a company is subject to U.S. jurisdiction, it may be required to produce data it controls — regardless of where that data is stored. The process runs silently; the result is data changing hands without notice.

No bad faith is required. The architecture produces this outcome by design. This is the data sovereignty problem in its most concrete form: not a question of intent, but of jurisdiction.

İBB stated in March 2025 that data is stored in its own data center. If that is accurate, the FISA/CLOUD Act access risk for this specific project should be assessed differently. But the core legal problem goes beyond data location: there is no independent technical audit mechanism to verify this claim, the contract specifications are not public, and Law No. 7545 has not, to date, made such audits mandatory. The assurance rests on the institution’s own declaration.

IV. Why Have Municipalities Failed to Solve What the Banking Sector Already Has?

Türkiye’s banking sector recognized this risk years ago. BDDK’s Banking Information Systems and Electronic Banking Services Regulation (Article 25, effective 1 July 2020) requires banks to maintain their primary and secondary systems within Turkish territory — including the systems of any cloud service providers used by those banks. A Turkish bank’s customer data cannot be processed on Dutch servers. But the daily movement data of millions of Istanbul and Ankara residents — where they go every morning, which route they take, where they are at each hour — can be processed abroad without any legal obstacle.

The two municipal agreements, signed in the same year the banking regulation came into force, fell entirely outside its scope. Data localization — mandatory for banks, nonexistent for cities. 

There is now a public debate: were the data stolen, who has them, who is responsible? Political framing, investigative language. But behind that debate, a quieter and more durable question remains.

The architecture already contained this risk.

From the regulatory and oversight authorities — from BTK, from the Cybersecurity Presidency, from the Ministry of Interior as the owner of KGYS — no statement. From the municipalities that signed the agreements, no statement either. Whether this silence represents a choice or a deficiency — both answers are serious in their own right. Public institutions have a responsibility to explain to citizens the technical and legal framework under which public services operate; this transparency is among the most fundamental requirements of democratic accountability.

Lawrence Lessig wrote decades ago: code is law. Which cloud platform was selected, whether a data localization clause appears in the contract, which encryption protocols were applied — these are all legal decisions. And they were typically made during procurement, in technical specifications, far from legal oversight.

V. Two Systems, One City: KGYS, UYM and the Question of Isolation

Tehran taught us something: urban data infrastructure is a security matter. Traffic cameras, sensors, movement patterns — these are strategic assets as much as technical systems. The legal regime under which they operate may seem like a detail in peacetime.

But at this point, a technical distinction needs to be stated clearly. Istanbul has two separate urban camera layers. The first is the security-focused Kent Güvenlik Yönetim Sistemi (KGYS) — formerly known as MOBESE. This system operates within the General Directorate of Security, under the Ministry of Interior. It is technically the closest equivalent to the system penetrated in Tehran. The second is İBB’s Ulaşım Yönetim Merkezi (UYM) — focused on traffic flow, journey times, sensors, and mobile application integration. This is the system the USTDA-SAS agreement targeted.

İBB stated that data in this system is held in its own data center; if accurate, the FISA/CLOUD Act access risk for this project should be assessed differently. But the boundary between the two systems is less clear in practice than it appears. İBB’s own UYM page documents that the Governor’s Office has real-time access to this system; in emergencies, all systems converge under the AKOM umbrella. A 2022 official document from the Istanbul Governor’s Office also acknowledges that municipal camera systems can constitute alternative data sources outside KGYS.

The legal framework governing this integration is not publicly defined. The conditions under which access to municipal systems is granted, to whom and when, are not established in any public document. Nor is the audit mechanism to which KGYS’s cybersecurity architecture is subject. Rubin’s risk does not reside in a single system — it resides in this entire infrastructure: fragmented, distributed, and interlocking.

VI. Law No. 7545, Data Sovereignty and the Absent Cybersecurity Presidency

Law No. 7545 on Cybersecurity entered into force on 19 March 2025. Nearly a year has passed. The critical infrastructure list the law mandates has not been published. Whether municipal and urban transportation systems fall within scope remains unclear. No secondary regulation on data localization obligations has been issued. No work on introducing foreign software audit requirements into procurement processes has been shared with the public. As Forseti’s January 2026 analysis noted, the first half of 2026 is discussed in the market as a likely window — but the Cybersecurity Presidency is not visible in this process. If a law cannot be implemented this quietly — or is not being implemented — that too is a choice.

The window is still open. Bringing municipal infrastructure explicitly within the critical infrastructure definition, establishing mandatory independent audits for foreign software in public systems, inserting data localization conditions into procurement specifications — these are legal choices, not technical ones — and together they define what data sovereignty means in practice. The cost of delay rises with each passing day.

A note to policymakers and practitioners in emerging markets: the questions raised here are not specific to Türkiye. Any city that has signed a smart infrastructure agreement with a U.S.-based provider — regardless of the project’s stated purpose — operates within the same legal architecture. FISA 702 and the CLOUD Act do not distinguish between countries. The time to ask these questions is before the agreement is signed, not after the cameras are installed.

Rubin wrote a scenario. The scenario is technically plausible. Law’s task is to make that scenario impossible — or at minimum, to make the architecture that prevents it mandatory.

The war has taught us something else as well: sovereign software, independent infrastructure, domestic data centers — these are no longer questions of technology policy but of security policy. Emerging markets that continue to outsource their urban data architecture to foreign jurisdictions are not just making a technical choice. They are deciding, often without realizing it, whose law governs their cities. That question deserves a separate piece — and an urgent one.

 

Cover:  J. M. W. TurnerRain, Steam and Speed – The Great Western Railway; the painting depicts an early locomotive of the Great Western Railway crossing the River Thames on Brunel’s recently completed Maidenhead Railway Bridge.The painting is also credited for allowing a glimpse of the Romantic strife within Turner and his contemporaries over the issue of the technological advancement during the Industrial Revolution. Rain, Steam and Speed – The Great Western Railway (1844). Oil on canvas, 91 × 121.8 (aproximation) cm (36 × 48.0 in). National Gallery, London.