Glossary
e-Transformation Terms Glossary
Short, factual definitions of the terms you often encounter in e-Signature, KEP, e-Notification and e-Correspondence, and in related Turkish legislation.
- Audit Trail
- A time-stamped, tamper-evident chain of records showing who created or modified a document, when, and from which IP address. In e-Signature flows it is kept in a certified manner.
- e-Notification
- A notification method with legal validity under Turkish Law No. 7201, delivered to the parties' electronic addresses through UETS (National Electronic Notification System).
- e-Signature (Electronic Signature)
- Electronic data created under Turkish Law No. 5070 based on a qualified electronic certificate, with the same legal validity as a wet signature; bound to a single person, non-repudiation.
- eIDAS
- The EU regulation on Electronic Identification, Authentication and Trust Services; it governs cross-border recognition of trust services such as electronic signatures, seals and time stamps across the EU.
- EYP (e-Correspondence Package)
- The electronic document package used for official correspondence between Turkish public institutions. The e-Correspondence Technical Guide (e-Yazışma Teknik Rehberi), which defines document structure, format, signing and encryption mechanisms, is published by the Digital Transformation Office; an institution may reject a document that was not prepared in line with the guide.
- Hash (Digest Value)
- A fixed-length digest value produced algorithmically from a document's content; it changes completely when the content changes and serves as the mathematical proof of the document's integrity.
- KEP (Registered Electronic Mail)
- A legal electronic mail service that uniquely identifies the sender and the recipient, and records the moment of sending and delivery as evidence.
- KVKK (Turkish Personal Data Protection Law)
- Turkish Law No. 6698 on the Protection of Personal Data, which regulates the processing, storage and protection of personal data in Turkey; it sets compliance requirements for e-signature and e-government processes.
- Law No. 5070 (Electronic Signature Law)
- Turkish Law No. 5070 defines the legal framework for electronic signatures in Turkey; an electronic signature created with a qualified electronic certificate (QEC) has the same legal validity as a wet (handwritten) signature.
- Law No. 7201 (Notification Law)
- Turkish Law No. 7201 regulates notification procedures in Turkey and provides the legal framework for electronic notification (e-Notification) delivered through UETS.
- Mobile Signature
- An electronic signature created over the mobile operator infrastructure using a qualified electronic certificate held on a SIM card or mobile device; legally valid under Turkish Law No. 5070.
- QEC (Qualified Electronic Certificate)
- A certificate issued by ESHS providers authorized by BTK (Information and Communication Technologies Authority), used to create authenticated, secure electronic signatures.
- Time Stamp
- An electronic signature issued by a trusted third-party authority that proves an electronic datum existed at a specific date and time and has not been changed since.
- UETS (National Electronic Notification System)
- The national system operated by PTT (Turkish postal service) where electronic notification addresses of legal and real persons are defined and e-Notification deliveries are carried out.
- WORM (Write Once Read Many)
- A storage model where data is written once and cannot be modified afterwards, used for long-term archiving; it keeps e-Transformation documents intact throughout their legal retention periods.
An audit trail records every action throughout a document's lifecycle, including creation, viewing, signing, modification, and deletion, in sequence and in a non-reversible form. A typical record includes the time of the action, the user who performed it, the user's role, the IP address, device information, and the type of action. This structure makes it possible to reconstruct the chronology of an event when a dispute arises.
Record integrity is strengthened with hash chains or time stamps. Each new record also carries a summary of the previous record, so a gap can be detected even if an intermediate record is removed. This design makes later attempts to interfere mathematically visible and makes manual alteration practically impossible.
In institutional use, an audit trail should be treated as evidence, not merely as a log. Access permissions, retention periods, and the backup strategy must be defined separately, and the activity of users who access the audit trail must also be recorded in the same trail.
e-Notification is delivered through UETS to persons included in the eleven mandatory categories listed in Article 7/a of Law No. 7201. The delivery is recorded in the system operated by PTT (Turkish postal service). The Regulation on Electronic Notification (Official Gazette No. 30617) establishes the procedures and principles for preparing, sending, registering, and informing the recipient about the notification.
The determining rule for the notification date is that electronic notification is deemed to have been made at the end of the fifth day following the date on which it reached the recipient's electronic address (Law No. 7201, Article 7/a). UETS associates the notification message with a time stamp and delivers it to the recipient's address. The evidence records generated by the system are conclusive evidence, and the authority issuing the notification is notified within twenty-four hours at the latest.
The Regulation sets out the retention periods: transaction records are kept for ten years and evidence records for thirty years. Institutions should regularly check that UETS addresses belong to the correct person and start an update process for addresses used by employees whose authority has ended or whose duties have changed.
Regulation on Electronic Notification — resmigazete.gov.trThe Law defines a secure electronic signature as an electronic signature that meets the technical conditions in Article 4, including the signer's identity, control of the tool used for signing, and data integrity, and that produces the same legal consequence as a wet signature under Article 5. This definition ties non-repudiation not only to the existence of a QEC, but also to the certificate being valid at the relevant time.
Article 3 defines an electronic signature as electronic data added to, or logically linked with, other electronic data and used for authentication. A secure electronic signature is the special form of this definition that meets the Article 4 conditions. The device that creates the signature, such as a smart card, USB token, or mobile device, must protect the certificate's private key.
In an institutional process, an e-signature is created through the person's individual certificate. The signer's authority to act on behalf of the institution must be determined separately. Procedures for certificate renewal, PIN blocking, device loss, and changes of duty should be defined in advance; otherwise, the signature may remain invalid.
Turkish Law No. 5070 on Electronic Signature — mevzuat.gov.treIDAS is a set of common rules for the mutual recognition of electronic identities, authentication, and trust services within the EU. The regulation addresses trust services such as electronic signatures, electronic seals, time stamps, registered electronic delivery, and website authentication in layers, and separately defines the qualified level.
The regulation subjects trust service providers established in the EU to accreditation and supervision mechanisms. Harmonized ETSI standards provide the measure of technical competence. Under this framework, a signature created as qualified in one EU member state also produces the same legal effect in the other member states.
In Turkey, electronic signature, electronic seal, and time-stamp services are carried out under Law No. 5070 and the related secondary regulations. The legal position in Turkey of a trust service established in the EU therefore requires a separate assessment under the relevant Turkish legislation; automatic equivalence is not asserted.
The Regulation on Official Correspondence, based on Articles 6 and 7 of Presidential Decree No. 1, establishes electronic correspondence between public institutions as the principal method. Documents prepared in this scope are sent as an e-Correspondence Package. The Regulation identifies the e-Correspondence Technical Guide (e-Yazışma Teknik Rehberi) published by the Digital Transformation Office as the binding reference and leaves the technical details to that guide.
Article 17 requires documents signed with a secure electronic signature to be prepared in a way that allows them to be converted into an archive signature. Under Article 23, documents can also be verified through e-Devlet. Article 30 gives the receiving administration the right to reject a package that does not comply with the guide, so schema and metadata checks should be completed before every submission.
Under Article 25, the Turkish confidentiality level ‘Restricted’ (Hizmete Özel) may be processed electronically, while Article 28 requires metadata for documents. Institutions should follow the Guide versions in their EYP-producing systems and complete preparation and testing before moving to production during a version change.
Regulation on Official Correspondence (Presidential Decree No. 2646) — mevzuat.gov.trA hash function produces a fixed-length digest, such as 256 bits for SHA-256, from a data set of any length, and always returns the same output for the same input. The output cannot be calculated backwards from the input, and a one-bit change in the input produces a completely different output. These two properties provide the basic basis for an integrity proof.
When a document is signed, the signature algorithm often signs the hash value rather than the document itself, allowing large files to be signed quickly and securely. During verification, the hash recalculated from the signed document is compared with the hash inside the signature. A match shows that the document was not changed after signing.
In institutional processes, hash values are also used when archiving and transferring documents. Producing the same hash in two separate systems demonstrates that their contents are equivalent. Older algorithms such as MD5 should not be used because of collision risk; existing systems should move to SHA-256 or a stronger algorithm.
KEP is defined in Article 4 of the Regulation on Registered Electronic Mail (Official Gazette No. 28036). It requires identification of the sender and recipient, recording of the sending and delivery times, and retention of those records. The system provides the ‘store-and-forward’ and ‘store-and-notify’ services together, and KEP evidence is produced for both services.
Under Article 12, except in cases of force majeure, an incoming message to an account that the account holder does not access is deemed to have arrived and been read on the following business day. Under Article 13, the recipient's KEP account may be closed for use, but closure cannot be applied retroactively. Article 15 describes KEP evidence as conclusive evidence with the effect of a private instrument, showing the special evidentiary value of KEP records in legal disputes.
Article 16 requires KEP service providers to keep their systems available 24/7, to maintain primary and backup systems in Turkey, and to retain records for at least twenty years. Article 20 regulates the payment of an administrative fee of 0.4 percent to BTK (Information and Communication Technologies Authority); this obligation is reflected in the cost structure of KEP providers.
Regulation on the Procedures and Principles of KEP (Official Gazette No. 28036) — resmigazete.gov.trThe Law ties the processing of personal data to the conditions in Article 5. These include an express provision in the relevant legislation, a direct connection with the establishment or performance of a contract, and the data controller's need to fulfill its legal obligation. During e-signature processes, data processed for a certificate application and identity verification must rely on one of these conditions.
Article 7 regulates the deletion, destruction, or anonymization of personal data. This obligation determines how e-signature logs and document contents are handled when their retention period ends. Article 12 regulates the technical and administrative measures for data security; in practice, this requires encryption, access control, and logging infrastructure.
Under Article 16, data controllers are assessed within the scope of the registration obligation in the Data Controllers' Registry Information System (VERBİS). For institutions providing e-signature services, this registration includes the categories of data processed and their retention periods. The misdemeanors in Article 18 and the duties and powers of the Board in Article 22 determine the enforcement risk of a compliance gap.
Turkish Law No. 6698 on the Protection of Personal Data — mevzuat.gov.trThe Law defines a secure electronic signature as an electronic signature created with a QEC and carrying the technical elements set out in Article 4. This definition provides the legal basis for non-repudiation: the signed data can be verified with the qualified certificate of the relevant electronic certificate service provider when the private key is protected on a smart card, USB token, or mobile SIM.
Article 5 gives a secure electronic signature the same legal consequence as a wet signature, while preserving exceptions such as acts whose subject constitutes a crime and obligations concerning taxes and social-security premiums. Each transaction therefore still requires a separate exception check; the existence of a secure electronic signature is not by itself sufficient for every document.
In an institutional process, the electronic certificate service provider, certificate renewal schedule, and suspension or revocation procedures must be selected according to the document type. If a certificate is revoked, the notification obligations determined under Article 11 must be fulfilled, and the signer's status as an individual or authorized representative of a legal entity must also be verified.
Turkish Law No. 5070 on Electronic Signature — mevzuat.gov.trArticle 7/a makes electronic notification mandatory for legal entities that are public institutions and for the eleven categories expressly listed in the Law. The address is defined through UETS, which is operated by PTT (Turkish postal service), and the notification is made through that system. The Law provides that an electronic notification is deemed to have been made at the end of the fifth day following the date on which it reached the recipient's electronic address.
Article 60 authorizes the Ministry of Justice to establish the procedures and principles. The Regulation on Electronic Notification issued under this authority sets out the detailed rules. Institutions should define opening, updating, and closing UETS addresses as a separate procedure within their internal operations.
Additional Article 2 defines a single UETS address for each natural and legal person. The address is matched through an identity number or a system number. If electronic notification cannot be made, the other procedures in the Law apply; in an electronic workflow, the evidence chain relies on the records generated by UETS.
Turkish Law No. 7201 on Notification — mevzuat.gov.trA mobile signature is an application of the electronic signature defined in Article 3 of Law No. 5070 and is subject to the Law's secure electronic signature provisions. The certificate is loaded onto the mobile operator's SIM card or a secure element in the device. Signature creation is triggered through the operator's infrastructure by an SMS OTP or a similar approval flow.
In terms of legal validity, a mobile signature produces the same consequence as a card- or token-based secure electronic signature. The same Article 4 conditions—identity, control, and integrity—also apply. When the signature is created, the electronic certificate service provider verifies that the certificate holder is a natural person, that the certificate is within its validity period, and that it has not been revoked.
In institutional use, if the mobile-signature device is lost or stolen, the electronic certificate service provider must be notified and the certificate suspended. Institutions should separately define the required compliance level for mobile signatures, including the use of a secure electronic signature, and determine through a policy document which transactions may accept a mobile signature.
Turkish Law No. 5070 on Electronic Signature — mevzuat.gov.trA QEC contains the mandatory fields listed in Article 9 of Law No. 5070: the certificate holder's identity information, certificate serial number, validity start and end dates, the electronic certificate service provider's information, and information about access to the provider's electronic-signature and certificate-revocation or information keys. A certificate is not considered a QEC unless these fields are complete.
Under Article 8 of Law No. 5070, the electronic certificate service provider notifies BTK and begins operating two months after the notification. The notification includes commitments such as the use of secure products and systems. The provider must follow the prescribed procedures throughout the certificate lifecycle, including issuance, distribution, renewal, and revocation.
During an institutional QEC application, the identity-verification obligation in Article 10 must be fulfilled. Identity and contact data obtained during verification must also be assessed under the KVKK. If a certificate is revoked, the provider must keep the current certificate status list (CRL/OCSP) accessible in accordance with the notification obligations in Article 11.
Turkish Law No. 5070 on Electronic Signature — mevzuat.gov.trArticle 3 of Law No. 5070 defines a time stamp as electronic data showing the date and time at which an electronic datum was produced and used for verification together with a secure electronic signature. The time stamp is based on the electronic certificate service provider's trusted time source, which must comply with international standards such as UTC traceability.
In practice, a time stamp is created from the hash of the document to be signed. The time-stamp server signs the hash with its own time information and certificate. During verification, the hash recalculated from the document is compared with the hash in the time stamp; a match shows that the document was not changed after the time shown in the stamp.
In institutional processes, time stamps are used particularly to prove the start and end of legal periods, such as a tax return, tender application, or contract. For the time stamp to be valid, the time-stamp server's certificate must not have been revoked and the electronic certificate service provider's authorization must remain valid; otherwise, the time stamp loses its evidentiary value.
Turkish Law No. 5070 on Electronic Signature — mevzuat.gov.trUETS is the central system through which e-Notification is delivered under Article 7/a of Law No. 7201. It is operated by PTT, and its records are kept securely under the relevant Regulation. Under Additional Article 2 of Law No. 7201, a single electronic notification address is defined for each natural and legal person. The address is matched through an identity number or a system number.
PTT creates a unique electronic notification address within one month from the application date. Legal entities designate at least one and at most ten principal transaction authorities in the system. An address closed for use remains accessible to its owner for six months.
Institutions should keep UETS addresses in a separate internal inventory. When an authority changes, they must promptly start the process of opening a new address and closing the old one. If the recipient's address is closed or inactive, notification cannot be made, so the address must be confirmed as active at the beginning of the process.
Regulation on Electronic Notification — resmigazete.gov.trWORM storage guarantees that data written once cannot be changed, deleted, or overwritten during the defined retention period. This can be provided through physical media such as WORM disks or through software-based immutable containers. In both cases, the purpose is to prevent later alteration of the content.
For e-Transformation documents, WORM preserves document integrity throughout the legally required retention period, reducing the risk that a document can be removed from the archive and changed. When the retention period ends, the data is deleted or anonymized in accordance with the legislation, and this step must also be recorded.
In institutional use, WORM storage should be considered one of the technical measures under Article 12 of the KVKK. Access permissions, backup strategy, and disaster-recovery planning must be compatible with the retention period. For high-volume, long-term archives, the balance between cost and performance must also be planned.
Can't find the term you're looking for?
Let us know which terms you'd like us to add; let's expand the e-Transformation definitions together.
