Türkiye Overhauls Telecom Fraud Prevention: Biometric Verification, Subscriber Limits, and a New Enforcement Regime

Türkiye Overhauls Telecom Fraud Prevention: Biometric Verification, Subscriber Limits, and a New Enforcement Regime


Introduction

On 25 December 2025, Türkiye enacted Law No. 7571, introducing sweeping amendments to the Electronic Communications Law (Law No. 5809). These changes represent one of the most comprehensive telecom fraud prevention frameworks in recent regulatory history. The new legislation mandates biometric identity verification for telecommunications subscriptions, imposes strict limits on the number of lines per person, and establishes rapid intervention mechanisms for fraud-related offences.

It is important to note that Law No. 5809 governs all electronic communications services in Türkiye, not merely mobile telephony. The new requirements therefore apply across the sector, encompassing fixed-line telephony, broadband internet access, corporate data services, satellite communications, and all other authorised electronic communications services.

While certain provisions—such as device-based line limits targeting SIM box operations and dedicated numbering for foreign nationals—have particular relevance to mobile services, the core identity verification and subscriber management obligations extend to the full range of telecommunications offerings.

The timing of these amendments is particularly notable. Just weeks earlier, the UK telecommunications industry signed its second Telecommunications Fraud Sector Charter with the Home Office, committing to similar objectives through voluntary industry cooperation. Türkiye’s approach, by contrast, relies on binding legislative requirements backed by substantial administrative penalties. This divergence offers valuable insights into different regulatory philosophies for addressing what the UK Charter describes as the most common crime in modern economies.

The Scale of the Türkiye’s Telecom Fraud Problem

The explanatory memorandum accompanying Law No. 7571 is remarkably candid about the scale of the problem facing Turkish authorities. According to judicial and administrative assessments cited in the memorandum, telecommunications lines registered without the knowledge or consent of the actual identity holder have become instrumental in crimes ranging from financial fraud to terrorism.

These lines, known in the industry as “fake” or “open” lines, create three distinct categories of harm. While mobile lines have been the primary vector for such abuse, the amendments address vulnerabilities across all electronic communications services.

The first harm is investigative. Fraudulent registrations prevent law enforcement from tracing calls and messages to actual perpetrators, undermining criminal investigations at their most critical stage. The second harm falls on innocent citizens whose identities are misused. These individuals face the burden of proving their non-involvement when called before judicial authorities regarding crimes they knew nothing about. The third harm concerns evidentiary integrity. The reliability of telecommunications data as evidence is fundamentally compromised when subscriber records do not reflect actual users.

Turkish authorities have specifically identified foreign nationals’ subscriptions as a vulnerability. The memorandum notes that the lack of electronic identity verification capability in foreign identity documents, combined with the absence of biometric verification requirements, has created systematic opportunities for abuse.

Mandatory Biometric Identity Verification

The cornerstone of Türkiye’s new framework is the requirement for biometric identity verification at the point of subscription. Under the amended Article 50 of the Electronic Communications Law, operators may no longer accept identity documents that lack electronic verification capability for any telecommunications subscription—whether mobile, fixed-line, or broadband. This provision effectively ends the use of older-style identity cards for new service registrations across the sector.

For Turkish citizens, identity verification must now be performed through specific enumerated methods. These include facial or fingerprint biometric data matched against the identity document, e-Government (e-Devlet) password verification, or identity card PIN verification. Critically, the law expressly states that these methods are exhaustive, using the Turkish legal term “tahdidi.” This means the Information and Communication Technologies Authority (BTK) cannot expand the list through secondary regulation—any additions would require parliamentary action.

Foreign nationals face additional requirements under the new framework. Where electronic identity verification is unavailable, biometric data must be verified through the Directorate General of Migration Management via BTK systems. For remote registrations, the mobile operator must also transmit the applicant’s location data to the Migration Management authorities. This location data requirement raises potential privacy concerns that will require careful consideration during implementation.

A narrow exception exists for diplomatic personnel and their families, as well as staff of international organisations with status agreements. These individuals may register upon confirmation by the Ministry of Foreign Affairs without meeting the standard biometric requirements.

From a data protection perspective, biometric data constitutes “special category” personal data under both Türkiye’s Personal Data Protection Law (KVKK Article 6) and the EU’s General Data Protection Regulation (GDPR Article 9). The new framework’s reliance on statutory obligation rather than explicit consent as the legal basis for processing raises compliance questions that operators must address in their privacy documentation and data protection impact assessments.

Ongoing Subscriber Verification and Line Limits

Beyond initial registration, the new law imposes continuing obligations on operators regarding their existing subscriber base. Operators must now verify the continued validity of all subscriptions on a quarterly basis. This verification encompasses death records checked via the Central Population Administration System (MERNIS), dissolution of legal entities verified through the Trade Registry, and expiration of foreign nationals’ legal residence status confirmed through Migration Management databases. Lines belonging to subscribers whose status cannot be verified must be disconnected from the network.

The operational implications of this requirement are substantial. For operators with millions of subscribers, conducting quarterly verification against multiple government databases represents a significant technical and administrative undertaking. Smaller operators may find these requirements particularly burdensome relative to their resources.

The legislation also empowers BTK to set maximum limits on the number of lines that may be registered to any natural or legal person across all telecommunications services. Additionally, BTK may limit the number of subscriber lines that may be used on a single device within a specified period—a provision with particular relevance to mobile services, directly targeting “SIM box” operations. These devices accommodate multiple SIM cards simultaneously and are commonly used for bulk fraud calls and messages. The explanatory memorandum explicitly identifies SIM boxes as a key enabler of telecommunications fraud that the legislation seeks to address.

Dedicated Mobile Number Ranges for Foreign Nationals

Perhaps the most distinctive provision in Türkiye’s new framework authorises BTK to establish separate numbering allocation and usage rules specifically for mobile lines belonging to foreign nationals. Unlike the biometric verification requirements which apply across all telecommunications services, this provision is expressly limited to mobile communications. The explanatory memorandum suggests this measure is intended to create “awareness” among Turkish citizens receiving calls from such numbers, enabling them to exercise greater caution.

This approach is unusual in international practice and raises potential concerns under human rights frameworks, particularly regarding non-discrimination principles enshrined in instruments such as Protocol 12 to the European Convention on Human Rights. The implementation details will be critical in determining whether the measure serves legitimate fraud prevention objectives in a proportionate manner. BTK’s forthcoming secondary regulations on this matter warrant close attention from both operators and civil society organisations.

New Powers Over OTT Platforms

The amendments introduce significant new enforcement powers over what the law terms “network-independent service providers,” commonly known as over-the-top or OTT platforms. Providers that fail to comply with regulatory obligations under Article 9 of the Electronic Communications Law, or that operate without proper authorisation, now face a graduated enforcement regime.

Initial violations may result in administrative fines ranging from one million to thirty million Turkish Lira. For providers that fail to pay these fines and do not achieve compliance within six months of BTK notification, more severe measures become available. BTK may order bandwidth throttling of up to ninety-five percent, effectively rendering the service unusable, or may order complete access blocking of the relevant application or website.

These provisions bring messaging-focused OTT platforms such as WhatsApp and Telegram within BTK’s direct enforcement reach, though the framework also extends to content streaming services. This represents a more interventionist approach than frameworks such as the European Union’s Digital Markets Act, which focuses primarily on competition concerns rather than direct service blocking powers.

Rapid Intervention for Fraud Offences

The new legislation creates mechanisms for rapid response when mobile lines are identified as instrumentalities in specified crimes. Under the new Article 60/18, mobile lines may be disconnected upon a court order or, in urgent cases, upon a written order from a public prosecutor. Prosecutorial orders are subject to judicial review within twenty-four hours, with the measure automatically lapsing if not confirmed by a judge within forty-eight hours.

The covered offences include aggravated theft under Article 142/2-e of the Turkish Criminal Code, fraud under Articles 157 and 158, and misuse of bank or credit cards under Article 245. These categories encompass the most common forms of telephone-enabled financial crime.

Operators that fail to comply with disconnection orders face administrative fines ranging from fifty thousand to three hundred thousand Turkish Lira. Notably, these fines are imposed directly by the public prosecutor rather than by BTK—an unusual enforcement mechanism that blurs traditional distinctions between administrative and criminal procedure. This arrangement may face legal challenges regarding the appropriate separation of powers between prosecutorial and administrative functions.

The legislation also imposes strict timelines for operator responses to information requests from judicial authorities. Operators must provide requested information or documents within ten days, whether in physical or electronic form. Failure to comply, or providing incomplete information, results in administrative fines in the same fifty thousand to three hundred thousand Lira range, again imposed by the prosecutor.

Implementation Timeline

The legislation establishes a phased implementation schedule designed to allow operators and the regulator time to develop necessary technical infrastructure. The law was published in the Official Gazette on 25 December 2025, establishing the baseline for all subsequent deadlines.

The first major milestone arrives on 1 April 2026, when three BTK decisions adopted in December 2025 enter into force. These decisions address unwanted communications, calling line identification (CLI) rules, and SMS service regulations. Operators must have their technical systems and commercial practices aligned with these requirements by this date.

The biometric verification and line limit provisions become effective on 25 June 2026, six months after the law’s publication. This date also serves as the deadline for BTK to publish its secondary regulations specifying implementation details. The same date marks the beginning of the registration update period for foreign national subscribers.

Foreign nationals must update their subscription records by 25 December 2026, though BTK may extend this deadline by an additional six months if circumstances warrant. Those who fail to update their records will have their lines disconnected within one month of the deadline. Subscribers who exceed the forthcoming line limits must transfer or close excess lines by 25 June 2027, with this deadline also potentially extendable by six months.

To facilitate compliance, the law waives all taxes, fees, penalties, and early termination charges for line transfers or closures required by the new limits. This provision recognises that penalising subscribers for regulatory compliance would be counterproductive.

The UK Approach: A Comparative Perspective

The UK’s second Telecommunications Fraud Sector Charter, signed on 5 November 2025, offers an instructive comparison with Türkiye’s legislative approach. Where Türkiye relies on binding primary legislation with substantial penalties, the UK framework is built on voluntary industry commitments coordinated through the Communications Crime Strategy Group (CCSG). The Charter signatories include major mobile operators BT EE, Virgin Media O2, VodafoneThree, Sky, TalkTalk, and Tesco Mobile.

https://newsroom.ee.co.uk/working-in-partnership-with-industry-in-the-fight-against-scams-and-fraud/

The structural differences between the two approaches are significant. Türkiye mandates biometric verification by law for all telecommunications subscriptions, while the UK relies on enhanced know-your-customer practices developed through industry best practice primarily in the mobile sector.

Türkiye will impose statutory limits on lines per person applicable across service types, while the UK has no formal limits but has established a working group to study SIM farm operations in mobile networks. Türkiye’s enforcement toolkit includes bandwidth throttling and access blocking for non-compliant OTT platforms, while the UK relies on Ofcom guidance and industry self-regulation.

Despite these structural differences, both frameworks share core objectives and certain implementation approaches. Both seek to develop traceback capability—Türkiye through rapid disconnection powers enabling source identification, and the UK through a commitment to operational traceback across participating networks within twelve months. Both frameworks specifically address bulk SIM operations, though through different mechanisms.

Both contemplate cross-sector coordination, with the UK Charter emphasising workshops with banking and technology sectors while Türkiye’s existing Article 51/11 provides legal authority for similar data sharing that has yet to be fully activated.

The UK Charter includes elements absent from Türkiye’s framework, most notably specific victim support commitments. UK operators have committed to resolving the majority of fraud cases within twenty-one days by November 2026, reducing to fourteen days by November 2027. The Charter also establishes an AI Fraud Prevention Working Group to coordinate artificial intelligence deployment across the sector, an area not specifically addressed in the Turkish legislation.

CCSG

Conversely, Türkiye’s legislative approach offers certainty and enforceability that voluntary frameworks cannot match. Operators know precisely what is required, and the penalties for non-compliance are clearly specified. The UK model, while more flexible, depends on sustained industry commitment and may struggle to address non-compliant fringe players who decline to sign the Charter.

A hybrid approach combining elements of both models might prove most effective. Türkiye’s clear legal framework for identity verification and line limits could be complemented by UK-style cross-sector data sharing platforms and measurable victim support commitments. Similarly, the UK might consider whether certain baseline requirements warrant legislative backing rather than voluntary commitment alone.

Practical Implications for Operators

Telecommunications operators serving the Turkish market—whether providing mobile, fixed-line, broadband, or other electronic communications services—face substantial compliance obligations under the new framework.

In the immediate term, before 1 April 2026, operators should review their marketing practices in light of BTK’s restrictions on outbound calling to non-subscribers. Technical infrastructure for secure electronic signatures on messaging platforms must be implemented, and registered electronic mail integration established for business messaging customer onboarding. Existing sender ID inventories require review against new alphanumeric requirements.

In the medium term, between April and December 2026, operators must deploy biometric verification systems meeting BTK specifications. Interfaces with government databases for quarterly verification must be established and tested. Foreign national subscribers requiring record updates should be identified and notified. Subscriber bases should be analysed against anticipated line limits to identify potential excess registrations.

Looking further ahead to 2027, operators must implement ongoing quarterly verification processes as a permanent operational function. Anomaly detection systems for potential SIM box activity should be developed or enhanced. Operators may also wish to consider participation in industry-wide fraud intelligence sharing initiatives, building on the legal authority provided by Article 51/11 of the Electronic Communications Law.

While the new requirements impose significant compliance costs, operators should also consider potential revenue benefits from a cleaner market. Reduced bypass traffic as fraudulent messaging channels close should improve legitimate A2P revenues. Lower interconnect revenue leakage from SIM box arbitrage will benefit network operators. Enhanced customer trust as fraud rates decline may reduce churn and support premium service adoption. Reduced liability exposure in fraud-related civil litigation provides additional financial benefit.

Conclusion

Türkiye’s Law No. 7571 represents a decisive legislative response to telecommunications fraud, prioritising enforcement certainty over industry flexibility. The biometric verification mandate applicable across all electronic communications services, quarterly subscriber validation, and rapid disconnection powers create a comprehensive framework that will fundamentally change how telecommunications services are provided and monitored in the Turkish market.

The contrast with the UK’s contemporaneous Fraud Sector Charter highlights genuinely different regulatory philosophies. Türkiye has chosen binding rules with clear penalties. The UK has chosen voluntary cooperation with industry ownership. Neither approach is inherently superior. Türkiye’s framework may prove more effective against determined bad actors but risks burdening legitimate operators disproportionately, particularly smaller players lacking the resources of major network operators. The UK model preserves operational flexibility and encourages innovation but depends on sustained industry commitment that future market pressures might erode.

What both frameworks recognise is that telecom fraud cannot be addressed through isolated measures. Effective prevention requires layered defences encompassing identity verification, traffic monitoring, data sharing, rapid response mechanisms, and cross-sector cooperation extending beyond telecoms to banking, technology platforms, and law enforcement.

For international operators, investors, and legal practitioners, Türkiye’s new framework demands careful attention. The compliance timeline is aggressive, the penalties substantial, and the operational changes significant. But for an industry grappling globally with telecommunications-enabled fraud, such comprehensive measures may increasingly become the international norm rather than the exception.

*Gökhan Candoğan is a telecommunications and cybersecurity lawyer at Forseti Law Office, Ankara. He advises telecom operators on regulatory compliance and represents the Turkish Association of Independent Telecommunications Operators (TELKODER) on policy matters.*