01/10
Document security board by risk tier
Work in three tiers: finish the mandatory baseline first, then strong protection, then advanced measures. Verify each item for your own firm before moving on; the list is a self-audit ledger, not a score.
Mandatory baseline
Without these a document store cannot be called secure.
- 01/18
Type and size checks on every upload
Files outside the permitted document types and files over the size limit are never accepted.
- 02/18
Mandatory malware scanning
No document is stored before the scan returns clean; if the scan cannot finish, the upload is rejected.
- 03/18
Personal accounts only
No shared logins or shared passwords; every staff member has an individual account.
- 04/18
Least privilege
People can perform only the document actions their job requires.
- 05/18
Per-company data separation
Another firm's or account's documents never appear in any query.
- 06/18
Written retention and destruction policy
It states how long each document type is kept and when it is destroyed.
- 07/18
Breach owner named
If a leak happens, who does what is assigned in advance.
Strong protection
The second tier that hardens day-to-day practice.
- 08/18
MFA enforced
A second verification step on top of the password, at least on partner and administrator accounts.
- 09/18
Document activity logs are reviewed
Views, downloads, deletions and signatures are recorded and checked at regular intervals.
- 10/18
Version history on
Every change is kept so you can return to an earlier version.
- 11/18
Deletion is reversible
A document deleted by mistake can be restored before it is lost.
- 12/18
Written sharing rule
It is clear through which channel and in what form a document goes to a client.
- 13/18
Leaver procedure
Access is closed as soon as employment ends and a handover list is kept.
Advanced
Extra assurance for mature firms.
- 14/18
Periodic permission reviews
At set intervals you check who holds which permission.
- 15/18
Separate access by document type
Identity documents and health data are open to a narrower group.
- 16/18
Restore from backup tested
You have verified not only that backups run but that they can be restored.
- 17/18
Qualified e-signature rule
It is recorded which documents get a qualified electronic signature and which are signed differently.
- 18/18
Breach drill
A leak scenario is walked through at the table once a year.
02/10
Legal status of a document: lawyer confidentiality and KVKK
Every document a client leaves with you is subject to two separate duties. The first is professional: under Article 36 of the Turkish Attorneyship Law (No. 1136), a lawyer may not disclose matters entrusted to them or learned through their work, and testifying requires the client's consent. A draft petition and a client's bank statement are equally covered by that duty of confidentiality.
Article 34 of the same law requires lawyers to perform their duties with care, honesty and dignity and to follow the professional rules set by the Union of Turkish Bar Associations. In practice that means not losing documents, not showing them to unauthorised people and applying the same care digitally. Confidentiality binds everyone in the office, from trainee to secretary, and you are responsible for knowing who sees which document.
KVKK Articles 4 and 12: technical and administrative measures
The second duty is data protection. Documents often carry identity, contact and financial details, sometimes health or criminal history. Article 4 of Law No. 6698 (KVKK) sets the general principles: lawfulness and fairness, accuracy, specified and legitimate purposes, relevance and proportionality, and retention only as long as necessary. Article 12 obliges the data controller to take all technical and administrative measures needed for an appropriate level of security against unlawful processing and access and to ensure safekeeping; where a processor is involved, you remain jointly responsible.
- Technical measures
- Upload checks, malware scanning, role and permission based access, multi-factor authentication, activity logs, backups and deletion mechanisms. The board below splits these into three tiers.
- Administrative measures
- A written retention and destruction policy, staff undertakings and training, joiner and leaver procedures, sharing rules and a breach procedure. Tools alone never replace administrative discipline.
For the broader controller duties, see the KVKK compliance guide for law firms. This page covers the document side only.
03/10
Upload gate and malware scanning
Document security is mostly won or lost at the door. An email attachment from a client, a renamed executable or a macro-laden file can open the whole office's archive. So the upload order must be fixed: type and size first, then content, then scanning, and only then storage.
In the document security module the sequence works like this: the file name is sanitised, extension and real content go through type checking, a 25 MB limit applies and malware scanning is mandatory. The rule is simple: if the system cannot be sure, it does not accept. If the scan finds malware, or cannot complete at all, the file is not stored. The five sample files below pass the gate in turn.
A document's path: from upload to e-signature
One document, one scenario: the lawyer uploads a fee agreement to the file, it passes the gate, is opened to authorised users and is sent for signature. The steps advance on their own; pause, or step through them one by one.
Upload
Sample document; the file name, date and time are fictional.
Upload gate simulation
Five attachments a client sent by e-mail are uploaded to the same case in one go. For each one, three checks run in order; the first check that rejects stops the file and the later checks do not run.
- 01/05
expert-report.pdf
PDF · 3.2 MB
Type and extension
PassedSize limit (25 MB)
PassedMalware scan
PassedReason
Accepted
Extension and real content both match PDF, the size is under the limit and the scan came back clean. The document is stored and its scan status recorded.
- 02/05
setup-tool.exe
Executable · 1.4 MB
Type and extension
RejectedSize limit (25 MB)
Not runMalware scan
Not runReason
Rejected
Executables are not among the permitted document types; the file stops at the first check and is never even scanned.
- 03/05
scanned-archive.pdf
PDF · 31 MB
Type and extension
PassedSize limit (25 MB)
RejectedMalware scan
Not runReason
Rejected
The type is fine but the file exceeds the 25 MB limit. Split or compress it, then upload again.
- 04/05
contract-annex.docx
Word document · 0.8 MB
Type and extension
PassedSize limit (25 MB)
PassedMalware scan
RejectedReason
Rejected
Type and size are fine but the malware scan found harmful content. The file is not stored.
- 05/05
power-of-attorney-copy.pdf
PDF · 2.1 MB
Type and extension
PassedSize limit (25 MB)
PassedMalware scan
Did not finishReason
Rejected
The scan timed out without a result. Because the outcome is unknown, the upload is rejected; try the file again later.
This behaviour is called failing safe: when something breaks, the door closes rather than stays open. Explaining a rejection to a client is mildly annoying; letting a malicious file into the archive costs far more. Sanitising file names also blocks path tricks and unexpected characters. Test your own process with one question: if scanning goes offline, does uploading stop, or does it quietly continue?
Tip: do not open a rejected file on your own machine. If a flagged document arrived by the client's email, confirm with the sender through a separate channel; their account may have been compromised.
04/10
Which document, who should see it, how it is signed, how long it stays
Documents are not all managed by the same rule. The matrix below is an illustrative classification; build your own from your firm's data inventory. The rows follow the document categories in HukukBis and the client documents lawyers meet most often.
| Document type | Sensitivity | Who should see it | E-signature suitable? | Retention note |
|---|---|---|---|---|
| Power of attorney | High | The assigned lawyer and authorised office staff. | A power of attorney issued before a notary follows notarial form; an e-signature does not replace it. Keep the original and a copy as documents. | While the file is open; at closure per your retention policy. |
| Petition | High | The lawyer team on the file; the client sees their own petition. | Yes. Cases can be filed electronically with a qualified e-signature (Code of Civil Procedure, HMK, Art. 445/2). | With the file; drafts live in version history. |
| Court decision | Medium | The team on the file and the client. | Not a document your office signs; keep the signed copy obtained from UYAP, the national court system, unchanged. | Until finality and enforcement steps are complete. |
| Expert report | High | The lawyer team on the file and the client. | No. The report belongs to the expert; your office signs only its own opinion letter. | Until the file closes; keep reachable because objections cite it. |
| Contract | High | The drafting team and the client. | If no statutory form is required, it can be signed with a qualified e-signature (Law 5070, Art. 5). | For the contract term and the period of dispute risk. |
| Evidence | Very high | Only the lawyer running the case and the necessary team. | Not signed; keep the original untouched and add any edit as a new version. | Until the case concludes; never delete the original file version. |
| Client identity document | Very high | The narrowest group: staff who verify identity and the responsible lawyer. | Not signed. | Only as long as needed; destroy when the purpose ends (KVKK Art. 4). |
Sensitivity levels are illustrative and are not classes defined by law. The e-signature column states the general rule; check the formal requirements of a specific transaction in the relevant legislation.
05/10
Access, activity logs and MFA
Who can see a stored document is your second decision. The roles and permissions module defines access at the permission level, not only by role: viewing, downloading, deleting and sending for signature are separate permissions. A trainee can be allowed to view while deletion stays off. The permission management guide walks through how to design roles.
Least privilege and per-company isolation
The principle is to give staff no more than their job needs. There is no reason for accounting staff to read case documents or for a trainee to open client identity documents. In HukukBis each firm's data is separated per company: one account's documents never appear in another account's queries. That separation also protects groups that run several firms.
Activity logs
Security is measured by questions you can ask after the fact: who downloaded this document, at what time, who deleted that file? Activity logs answer them. Do not read the logs only after an incident; a short monthly look often catches early warnings such as bulk downloads at odd hours or someone opening a file they have no reason to touch.
MFA
A password alone is a weak barrier. Multi-factor authentication makes it much harder for a leaked password to open the document store. Turn it on for partner and administrator accounts first, then for everyone. See the security page for infrastructure details.
- Separate permissions
- Viewing, downloading, deleting and signing are authorised individually.
- Company isolation
- Data is separated per company; another account's documents stay invisible.
- Activity record
- Actions on a document are recorded.
- MFA
- A second verification step is added on top of the password.
06/10
E-signature for lawyers: legal effect and correct use
The Electronic Signature Law (No. 5070) defines electronic signature and related terms in Article 3, and Article 4 lists the four attributes of a secure (qualified) electronic signature. It is exclusively linked to the signatory, created with a secure signature creation device under the signatory's sole control, based on a qualified electronic certificate that identifies the signatory, and able to show whether the signed data was changed afterwards.
- 01It is exclusively linked to the signatory.
- 02It is created with a secure signature creation device under the signatory's sole control.
- 03It rests on a qualified electronic certificate that establishes identity.
- 04It shows whether the signed data was altered afterwards.
Article 5 states the effect: a secure electronic signature has the same legal consequence as a handwritten signature. Two exceptions apply: transactions that the law subjects to an official form or a special ceremony, and security contracts other than bank letters of guarantee and surety bonds issued by insurers resident in Turkey, cannot be concluded with a secure electronic signature. The equivalence is broad, not unlimited.
For court work, Article 445/2 of the Code of Civil Procedure (HMK) provides that a case can be filed electronically with a secure electronic signature, fees and advances can be paid and case files inspected; under Article 445/1, UYAP (the National Judiciary Informatics System) is the information system built to run judicial services electronically. You use your own signature device for UYAP actions; for documents inside the firm you need a separate decision table.
Which document gets which signature
- 01/03
Secure electronic signature
Based on a qualified certificate and equal to a handwritten signature. First choice for contracts, letters under a power of attorney and UYAP actions.
- 02/03
Simple electronic approval
Email confirmation or a click on screen does not carry the equivalence of a secure electronic signature. Use it for acknowledgements and routine approvals, not for a transaction that must bind.
- 03/03
Wet ink or notarial form
Required for transactions subject to an official form; under Law 5070 Art. 5 these cannot be completed with a secure electronic signature.
The signature record in HukukBis
At an authorised user's request, HukukBis sends the document to an external e-signature service. When signing completes, the document is marked as signed and the signing time is recorded, so the firm can see from the document list which file was signed and when. How the service connection works is covered on the integrations page. Check the final version before you send a file for signature; if signed data changes later, the signature fails, which is exactly the safeguard you want.
07/10
Version history and safe sharing with clients
Version history answers two needs: undoing a bad change and proving when a document became what it is. In document management every change is kept as a new version and you can return to an earlier one. For petition drafts this ends the question of which sentence changed when; for evidence it guarantees you can always reach the original.
Templates speed up recurring documents, and a client sharing link reduces the need to pass files around as email attachments. A document that leaves as an attachment is out of your control the moment it is sent and gets copied freely; with a sharing link the document stays in your own store. Even so, no tool is safe without rules.
Safe sharing rules
- Right channel
- Send documents only to an email address or phone number the client has confirmed to you; avoid group chats.
- Minimum content
- Strip identity, bank or health details the client's matter does not need before sharing (KVKK Art. 4: proportionality).
- Record the transfer
- Note in the file or document record who was sent which document and when.
- Review links at closure
- When sharing is no longer needed, review the link at file closure and end the share if necessary.
- No onward forwarding
- What the client does with the document next is outside your control; remind them with a note inside the document.
08/10
Retention period, backup and offboarding
KVKK Article 4 sets two principles plainly: data must be relevant, limited and proportionate to its purpose, and kept for the period required by applicable legislation or necessary for the purpose. The document store is where most firms are least careful: a file closes, but documents stay for years just in case. The single firm recommendation is this: write down a period and a basis for each document type and destroy when it expires.
In HukukBis deletion is reversible, so a document deleted by mistake is not lost. That is a good safeguard but it does not replace your decision on permanent destruction. When a retention period ends, remove the document for good and record who approved it. To handle a data subject's deletion request, data transfer and KVKK tools provide export and deletion request handling.
Backup
Automatic backup limits your loss from hardware failure or ransomware. Two cautions: backups contain personal data too, so your retention and access rules apply to them as well, and having a backup does not prove it can be restored. Rehearse a restore at least once a year and state the backup cycle in your destruction policy.
Offboarding a departing employee
Confidentiality does not end when an employee leaves, but cutting access is the firm's job and reminding them of the duty is yours. On the departure day, follow this order:
- 01Disable the account and end any open sessions.
- 02Hand over the files and document responsibilities to another lawyer.
- 03Review the last thirty days of document activity logs for unusual downloads.
- 04Change shared passwords, shared mailboxes and access in external accounts.
- 05Remind them of their written confidentiality undertaking and record it in the exit note.
09/10
Five steps after a document leak
KVKK Article 12/5 requires that when processed personal data is obtained by others through unlawful means, the data subject and the Personal Data Protection Board are notified as soon as possible. For documents covered by lawyer confidentiality you also owe the client. Instead of deciding in a panic, use an order written in advance.
- 01/05
Stop it
Disable the affected account, close sharing links and end open sessions.
- 02/05
Scope it
From the activity logs, work out which documents were accessed, by whom and when.
- 03/05
Notify
Notify affected clients and the Board as soon as possible; decide beforehand who sends the notice.
- 04/05
Record it
Write down the incident, your decisions and their timing.
- 05/05
Fix the cause
Find why it happened, strengthen the relevant checklist item and brief your staff.
Official notification forms and deadlines can change; confirm the current Board announcements and decisions on the KVKK Authority website.
10/10
Questions about document security
- 01
How does a lawyer use a secure electronic signature in Turkey?
A secure electronic signature rests on a qualified electronic certificate and a signature device that only you control. Under Law No. 5070 Article 5 it has the same legal effect as a handwritten signature. Lawyers use it for UYAP actions, including filing a case (HMK Art. 445/2), and for contracts that do not require an official form. In HukukBis an authorised user sends the document to an external e-signature service, and when signing completes the document is marked as signed with the signing time recorded.
- 02
Is sending client documents by email or WhatsApp safe?
No channel is safe or unsafe by itself. What matters is verifying the recipient, keeping the data in the document to a minimum and recording the transfer. Do not send very sensitive documents such as identity papers to group chats or unknown addresses. Where possible, share the document by a link from your document store and note when and to whom it went.
- 03
How long should I keep client documents?
There is no single period. Under KVKK Article 4 a document is kept for the period set by the relevant legislation or as long as the purpose requires. Establish the basis for each document type, write the period into your retention and destruction policy and destroy the document when it expires. For case documents the period usually runs from file closure; check the relevant legislation and your bar's practice for exact periods.
- 04
Is a document uploaded if the malware scan cannot finish?
No. In HukukBis malware scanning is mandatory: the upload is rejected if the scan finds malicious content and also if it returns no result because of a timeout or service error. The system does not accept a file it cannot be sure about. Trying again a little later is enough.
- 05
When should a departing employee's access be closed?
On the day employment ends, ideally at the end of the last working hours. Disable the account, end open sessions, hand over file and document responsibilities and review the recent activity logs. Lawyer confidentiality (Attorneyship Law Art. 36) continues after the person leaves, so remind them in writing.
- 06
What should I do if a document leaks?
First stop access, then use the activity logs to establish which documents were affected. KVKK Article 12/5 requires notifying the data subject and the Board as soon as possible when personal data is obtained by others unlawfully. Also inform your clients, record the incident in writing and fix the root cause.
Official sources and provisions relied on
The legal references in this guide rely on the official texts below. Check the source for the current wording.
- 01Electronic Signature Law No. 5070 (opens in a new tab) · Art. 3, 4, 5
- 02Personal Data Protection Law No. 6698 (KVKK) (opens in a new tab) · Art. 4, 12
- 03Attorneyship Law No. 1136 (opens in a new tab) · Art. 34, 36
- 04Code of Civil Procedure No. 6100 (HMK) (opens in a new tab) · Art. 445
- 05Personal Data Protection Authority (KVKK) (opens in a new tab) · Board announcements and decisions
Related guides
- KVKK Compliance Guide for Law Firms in TurkeyWhat Turkey's data protection law requires of a law firm as data controller, from inventory and privacy notices to retention, access control and breach reporting.Read the guide (11 min)
- Roles and Permissions in a Law Firm: A GuideLeast privilege, typical firm roles, an access matrix, offboarding, two-step verification and audit records, with examples for small and mid-sized Turkish firms.Read the guide (8 min)

