İBYS: a record not sent to the Ministry counts as not made
In Türkiye, the training, examination and hazard-source records produced by the occupational safety specialist and the workplace physician are sent electronically to the Ministry's database. This is not an optional step towards digitalisation; it rests on Article 27(3) of Law No. 6331 and on External Circular 2018-1 of the Directorate General.
This page is written for two readers at once: so that an employer can ask about their own position, and so that a service provider following an incomplete path can turn back from it.
How a record reaches the Ministry
Data can only be sent through the software of an authorised integrator company. The conditions are listed in the Circular: a confidentiality and data-sharing agreement with the Directorate General, an information security management system certificate as at the date of application, and an approved penetration test report.
Companies whose application is accepted are published on the Ministry's page as authorised firms; the listing shows the firm's name and the product and platform the registration was granted for. A firm that cannot maintain the conditions, or acts contrary to the agreement, has its authorisation deactivated — and that too is published on the same page.
So not every product calling itself "OHS software" can send data to the Ministry. Those that can have been published, and the list is open to everyone.
The employer's duty: to check
An employer receiving service from an authorised body does not have to buy software. But the verb the Circular places on the employer is "to check": the employer is obliged to check that the relevant personnel of the body providing the service use a software application produced by an integrator company.
Where the employer runs the service with their own staff, the direction is the other way round. Article 6(1)(b) of Law No. 6331 requires the employer to meet "all necessary needs, such as tools, equipment, space and time" so that the assigned person can carry out their duties. OHS software sits among those needs — alongside a computer, internet access, an electronic signature and a place to work. It is the employer who establishes and provides the system.
So what the employer checks is not software the assigned professional acquired on their own; it is whether the system the employer established is actually being used. Where the service is bought from outside, the check is instead that the provider uses registered software.
An employer who cannot carry out this check has not discharged the duty.
What this means for the service provider
If the body providing the service does not use registered software, every employer it serves is unable to discharge their own duty to check. The duty stays with the employer, but the employer alone cannot put the situation right.
Under the legislation the provider's job is to guide the employer on the surveillance of the working environment. Falling short on the very subject being guided goes to the substance of the service.
Which duty carries what consequence
Every row below was read from downloaded legislation text; none was written from memory. The amounts apply to 2026.
Legal basis
The table shows the obligations of the legislation region you pick in the top bar; it refreshes without reloading the page when the region changes.
Türkiye — the duty and what follows
| Obligation | Legal basis | How the page covers it |
|---|---|---|
| Employer: to check that the personnel of the body serving them use integrator software | External Circular 2018-1, §6(a) | The Circular attaches no separate sanction to this duty; the consequence arises from the underlying duty of the record that was not sent |
| Employer: to meet all needs — tools, equipment, space and time — so the assigned person can carry out their duties; OHS software sits among those needs | Law No. 6331 art. 6/1-b → penalty art. 26/1-b | Administrative fine — 2026: TRY 33,326 |
| Employer: occupational health and safety training of employees | Law No. 6331 art. 17 → penalty art. 26/1-ğ | Administrative fine, separately per employee for each breach — 2026: TRY 8,980 per employee |
| Employer: health surveillance and health report | Law No. 6331 art. 15 → penalty art. 26/1-f | Administrative fine, for each employee not placed under health surveillance or without a report — 2026: TRY 22,194 per employee |
| Employer: risk assessment | Law No. 6331 art. 10/1 → penalty art. 26/1-ç | Administrative fine — 2026: TRY 66,725; TRY 100,119 for each month the breach continues |
| Employer: penalty multiplier — workplace size and hazard class | Law No. 6331 art. 26/3 | Fewer than 10 employees: hazardous +25%, very hazardous +50% · 10-49: +50% / +100% · 50 and above: low hazard +50%, hazardous +100%, very hazardous +200%. The increase does not apply to fines multiplied by the number of employees (art. 26/5) |
| Service provider: training records not kept, or no copy held | OHS Services Regulation art. 21/1 → Annex 7 | Minor breach, 20 warning points per inspection |
| Service provider: information and documents requested in inspections not provided | OHS Services Regulation art. 21/1 → Annex 7 | Serious breach, 100 warning points |
| Service provider: suspension of the authorisation certificate | OHS Services Regulation art. 22/1-2 | When warning points total 300, the certificate is suspended for six months; the authorisation cannot be used while suspended |
| Service provider: revocation of the certificate and its publication | OHS Services Regulation art. 22/4-6 | Three suspensions within one visa period is a direct ground for revocation; suspension and revocation are published on the website |
| Occupational safety specialist: failure to carry out duties and obligations | Occupational Safety Specialists Regulation art. 33/1 → Annex 8 | Moderate breach, 20 warning points per inspection |
| Workplace physician: failure to carry out duties and obligations | Workplace Physician and Other Health Personnel Regulation art. 40/1 → Annex 11 | Moderate breach, 20 warning points per inspection |
| Specialist and physician: suspension of the certificate | Occupational Safety Specialists Regulation art. 34/1 · Workplace Physician Regulation art. 41/1 | When warning points reach 100 for individuals and 200 for institutions, the certificate is suspended for six months |
| OHS professional: to report the data-set records to the Ministry through integrator software | External Circular 2018-1, §4(a) | The Circular attaches no separate sanction to this duty; the consequence arises from the underlying duty of the record that was not reported |
Every row was read from downloaded legislation text. Amounts are for 2026. The warning-point regime is specific to the scheme of Law No. 6331.
This table is specific to Turkish legislation. The warning-point regime is part of the scheme of Law No. 6331; the inspection and enforcement arrangements of other countries are not its counterpart and are not mapped onto this table.
The penalties do not arise one by one, but as a chain
The rows above are not independent of one another. When the software is not provided, it is not only the duty to supply tools and equipment that is breached: because records cannot be produced and reports cannot be made, the duties on training, health surveillance and risk assessment become impossible to meet at the same time.
Each of these is a separate administrative fine under its own sub-paragraph of Article 26 of Law No. 6331; one does not replace another, and paying one does not cancel the rest. A single gap therefore gives rise to several linked penalties at once.
The way the amounts work compounds this: some apply separately for each breach, some per employee, and some again for every month the breach continues — with the workplace size and hazard class multiplier applied on top.
The chain starts with the employer as well. The Law requires those needs to be met "so that" the assigned person "can carry out their duties"; an employer who does not provide the software is in effect preventing the assigned professional from doing their job. Even though the obstacle originates with the employer, the consequence falls on both sides: the professional who cannot send the record faces warning points, and the employer faces the administrative fines arising from the same gap.
Check it in ten seconds
Look at the Ministry's authorised firms page. Is the maker of the software you use — or the software used by the body serving you — on the list? The list shows the firm's name, the registered product and the platform.
If the answer is no, no record has been sent with that software. One question settles it: which registered software are the records sent with?
What is sustainable: whose system should the software sit in
Everything up to here is duty. What follows is operational sense, and the legislation does not write it down — which is why most businesses arrive at the conclusion at their own cost.
You worked with one service provider for a year. All the training records, examination results, risk assessments and equipment inspections accumulated in their software. Then you parted ways.
That is where the chain begins. The next provider has no software, so records start again from nothing. You part with them too; the third has software of their own, but the records of the second period stayed in the previous system and everything is set up afresh. When the third leaves, the past is left behind somewhere once more.
The same three things happen at every change: past records stay in the old system; in the new one the previous result of a periodic inspection and the repeat date of a training are not visible; and in an audit the answer to "where is last year's record" has to be requested from a company you no longer work with. That is not a sustainable arrangement.
The sustainable arrangement is the opposite: the software sits within the business itself. Whichever joint health and safety unit is engaged, and whichever occupational safety specialist or workplace physician is assigned, they carry out their work through the system the employer uses and make their submissions to the Ministry from it. The provider changes, the professional changes; the record stays where it is and whoever arrives next picks the work up where it was left.
The second dimension is who holds the data. Employees' health records are personal data of a special category. If those records sit only in the system of the company you buy service from, then when the relationship ends you must answer three questions: do you hold a copy, was the copy in the old system deleted, and how do you confirm it was deleted?
This is also a founding principle of information security: data stays in the hands of its owner and remains accessible; its continuity is not tied to a third party's system, nor to the lifespan of the relationship with that party.
The legislation says an employer buying the service is not obliged to buy software. That is a minimum boundary; it does not describe good practice.
Where Optifora stands
EGEROBOT Otomasyon Mühendislik Proje Danışmanlık San. ve Tic. Ltd. Şti., which develops Optifora, is on the Ministry's list of authorised integrator companies.
There are 44 integrator companies on the list today, and each registration is published with the firm's name together with the product and platform it was granted for. The list is open to everyone; you can apply the step above to us as well.
The duties described on this page apply to the product itself too: whether a record reaches the Ministry depends on the sending software being registered.
What to do
- If you are an employerAsk the body serving you one question: which registered software do you send the records to the Ministry with? If the answer is not clear, your duty to check has not been met.
- If you are the service providerAsk yourselves the same question. If there is no answer, this is a correctable gap, and the cost of correcting it is lower than the consequence of not doing so.
- If you are an OHS professionalThe records set out in the data set are reported to the Ministry through an application obtained from an integrator company. Confirm that the software you use opens this route.