Let your security policies be valid in law as well.
The legal framework of the ISMS (ISO 27001) and information security policies: access regime, employee obligations, supplier requirements and legislation mapping.
A technical document — and a legal one
In most companies, information security policies remain technical documents written by IT; yet the same documents are read as legal evidence in disciplinary proceedings, supplier disputes and regulatory audits. A rule that is not written cannot be enforced; a rule written wrongly turns against you.
The scope of the legal review
The employment-law validity of the policy set (access, acceptable use, remote work, incident management) — notice, employee consent and proportionality; the KVKK limits on monitoring and logging; binding supplier security requirements into contracts; whether the sanction tiers can be documented if a breach occurs.
Legislation mapping
ISO 27001 controls are mapped to customer requirements arising from NIS2, KVKK technical and administrative measures, and sector-specific regulations. One control set, many audits: instead of duplicate documents, a mapping matrix is built.
From audit to a living framework
We run a five-step programme. Document inventory: a complete list of policies, procedures and commitments. Legal gap report: each document is scored for employment-law validity, mapping against the data-security measures of Article 12 of the KVKK (Law No. 6698), and its contractual connections. Revision and notification: policies are turned into annexes to the employment contract, and their communication is made provable through wet-ink or e-signature records. Training: the rules are made understood in the field. Annual maintenance: legislative and technology changes are written into the set — a rhythm we operate as part of an ongoing legal counsel arrangement. Deliverables: the mapping matrix, the revised policy set and notification-record templates.
Who sits at this table?
Three profiles stand out. Suppliers serving EU customers along the supply chain: customers caught by NIS2 push security requirements downstream through contract annexes; before those annexes are signed, we test whether the internal framework actually meets them. Companies preparing for ISO 27001 certification: we build the legal side of the policy set the auditor will ask for, on the certification timeline. Türkiye subsidiaries of German parent companies: group ISMS policies are localised through the filter of Turkish employment law and the KVKK — the group standard is preserved, and mandatory local rules are added. The full picture of attack and breach scenarios comes together in one programme under our Cybersecurity focus.
We are by your side for Information Security Policies & ISMS Law
We pass your existing ISMS documents through a legal filter, close the gaps and set up the employee information-and-consent framework. Our response line for the moment of an incident and our cyber insurance practice for the insurance layer work within the same programme.

Other Applications of This Service
Compliance — our other specialised solutions in this area.
Matter Connections
The focus areas, practice areas, desks and legislation connected with this sub-service.
Our Matters in This Service
The anonymised examples of our work that relate to this service.
Uninterrupted legal counsel for a multinational supplier
Retainer-based support across day-to-day commercial operations, contract management and compliance processes.
Review the matter →ESG & ComplianceSupply chain due diligence (LkSG) compliance programme
Risk assessment and compliance architecture for a Turkish supplier network under the German LkSG.
Review the matter →Market AccessEstablishing a distribution network in Türkiye
Designing a market entry strategy, distributorship agreements and competition compliance.
Review the matter →The Team Delivering This Service
With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

Mehmet Köksal
Founder and Managing PartnerIstanbul · Berlin · KyreniaProfile →
Kübra Köksal-Yılmaz
PartnerBerlin · İstanbulProfile →
Gül Efem
Of CounselİstanbulProfile →
Sven Köksal
Legal EngineerBerlin · İstanbulProfile →
Gökçe Yıldırım
Of CounselİstanbulProfile →Related Publications
Fresh perspectives and guides from the Knowledge Centre.
Proportionate, disclosed, and purpose-limited monitoring is possible; covert and unlimited monitoring is risky under both KVKK and employment law. The trio of policy + privacy notice + technical limits is essential.
The certificate shows that processes exist, not that they are legally valid. On the day of a disciplinary action or lawsuit, the documents must pass the employment law and KVKK test — that is a separate audit.
Management approval + a record of employee notification (preferably electronic signature/log) is the standard. In the NIS2 world, the management body’s approval record has gained additional importance.
Information Security Policies & ISMS Law — get the right legal support.
Let us identify the right solution together, drawing on our experience in Türkiye and the DACH region.
