A Judgment Analysis from the Perspective of IT Law and Criminal Proceedings: Criminal Liability of Hosting Providers and the Principle of Benefit of the Doubt

18 Ağustos 2026 Autore: Ertugrul Salih Ozhan

Abstract Based on file no. 2022/… of the İzmir 48th Criminal Court of First Instance, this article examines the legal distinction between a “hosting provider” and a “content provider” in crimes committed through information systems. The study analyzes the reflection of the principle “in dubio pro reo” (benefit of the doubt) on digital evidence, asserting that the act of merely providing technical infrastructure is insufficient to establish principal liability or complicity in the primary offense.

1. Introduction: The Problem of Identifying the Perpetrator in IT Layers The case examined by the İzmir 48th Criminal Court of First Instance originates from an operation conducted by law enforcement against online prostitution activities. Technical evaluations revealed that photos of foreign nationals were shared via the website to facilitate prostitution. The Public Prosecutor’s Office demanded the punishment of the defendant, S… B…, who managed the technical infrastructure and provided hosting services, alleging that these actions constituted the crime of “facilitating prostitution.”

The greatest misconception regarding cybercrimes is assuming that holding the “key” (hosting/domain privileges) to a digital platform automatically makes one the perpetrator of the crime. However, IT law draws a clear line between infrastructure providers and those who generate illegal content using that infrastructure.

2. Technical and Legal Nature of Hosting Providers Pursuant to Law No. 5651, a “hosting provider” is not obligated to monitor the data hosted on its systems. The domain and hosting services provided by defendant S… B… constitute a “hosting provision” activity. A hosting provider is akin to a digital landlord; unless concrete evidence proves knowledge of or participation in illegal activities conducted by the tenant, the provider cannot be held liable. The court and expert reports established no direct causal link between the provided service and the execution of the crime.

3. Analysis of Digital Footprints and Chain of Perpetration

  • “Admin” Privileges and Access Logs: It was established that all illicit posts were made under the “admin” username. However, the core question in criminal law is: “Who is the admin?” The expert report revealed no uninterrupted log connection between this account and the defendant’s personal devices or IP addresses.
  • Technical Impossibility and Presumptions: Selling hosting services does not prove that the seller is the “admin” user. In IT systems, the billed party and the actual user can be different individuals. The defense statement remained a reasonable doubt supported by technical data.

4. Material Reality and “In Dubio Pro Reo” Criminal proceedings aim to establish material facts, not assumptions. Without login logs proving entry into the “digital room” or cache data on personal devices, holding the “deed to the door” is insufficient for conviction. The court acquitted the defendant pursuant to Article 223/2-e of the Code of Criminal Procedure (CMK) due to the absence of a digital footprint proving intentional complicity.

5. Conclusion The ruling of the İzmir 48th Criminal Court of First Instance serves as an exemplar of integrating IT law principles into criminal adjudication, reinforcing legal safeguards for digital service providers against unwarranted criminal liability.

← Torna alla Home