Briefing Note · ESG & Supply Chains

What Turkish Companies Must Do

How the German Supply Chain Due Diligence Act and the draft EU Directive affect Turkish companies, with a practical list of compliance steps: strategies, independent risk analysis, complaint centres, supplier contracts, recourse clauses and training.

28 March 20224 dk okumaBy Sven Köksal · ESG & Supply Chains

Türkiye has signed the international treaties and conventions referred to in the annex to, or within the body of, both the Act and the Directive. 

Significant steps have also been taken within the legislative framework with respect to occupational safety and worker health. Employees’ social rights have been placed under adequate legal protection. 

Nor is there any legal gap in environmental terms. 

The real problem: enforcement

The problem lies in supervising whether these regulations are being breached. Because there are not enough experts to carry out inspections, inspections take place very rarely. Although Türkiye has signed almost all of the ILO conventions, there are unfortunately still problems regarding child labour and equal pay for equal work.

Sanctions and the real risk for Turkish suppliers

Very severe penalties also apply where violations are identified. The Due Diligence Act has applied since 1 January 2023, while the EU Directive will apply only from 26 July 2029. The Act does place responsibility on companies, but BAFA stopped reviewing reports on 7 November 2025, so the expectation that the supervision gap would be closed has not been borne out as matters stand.

For this reason, it will be useful to comply with the steps that we have listed below.  Where the Act is not complied with, the German company in scope faces administrative fines of up to EUR 800,000 — and, for legal persons with an average annual turnover above EUR 400 million, up to 2% of average annual worldwide turnover for certain breaches (Section 24) — together with exclusion from German public contracts for up to three years (Section 22). For Turkish suppliers the risk is not a legal sanction but the contractual and commercial consequences.

What companies should do

And although the major responsibility in this regard falls on the companies concerned …

  1. Every company must internally prepare its strategies regarding the due diligence obligation set out in the Directive and the Act.
  2. It must have the due diligence risk analysis carried out by an independent organisation.
  3. It must remedy the deficiencies identified in the risk analysis as soon as possible.
  4. It must establish a complaint centre that is open to employees (including its own employees and the employees of its intermediary suppliers)  and that is easily accessible to and understandable by them.
  5. It must make this complaint centre as independent as possible and seek ways to reach a settlement with those who may be harmed.
  6. It must carry out frequent internal checks.
  7. It must establish relationships at management level with those carrying out inspections or with independent complaint centres. 
  8. If it also has a supplier or suppliers, it must ensure that they too comply with the due diligence obligations under the Act or the Directive.
  9. It must establish the conditions enabling recourse against its own suppliers.
  10. It must review its purchasing and other contracts and introduce rules compliant with the Act and the Directive.
  11. Since the protection of personal data is also important within the meaning of the Act and the Directive, it must likewise implement the relevant arrangements in this regard.
  12. It must inform its employees and attach importance to the necessary in-house training at management level.
  13. It must provide for penalty clauses regarding breaches in the contracts it concludes with its own suppliers.
  14. It must always work with advisors who are knowledgeable about supply chain due diligence.
  15. It must make the necessary preparations regarding the Directive’s requirement to appoint a representative. 

Sector-specific points to define and keep updated

Taking into account the specific characteristics of the sector in which the company operates, it will be necessary to determine — and to keep continuously updated — the measures required in the event of a breach of obligations, the methods and measures needed to prevent a breach, the establishment of an independent complaint body accessible to the persons concerned in the event of a breach, the person responsible for due diligence, how training will be conducted and how often, how inspections (both internal and at suppliers) will be carried out, and the general code of conduct.

This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all
Knowledge Centre

Get a legal assessment on this matter.

Get in touch with our team for an assessment of your specific situation.