Data Protection

Data Breaches Under Türkiye's KVKK: Notification Duties and Penalties

If your company suffers a data breach affecting personal data connected to Türkiye, you must report it to the Turkish Personal Data Protection Board within the shortest possible time and tell the affected individuals. These duties come from the Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu No. 6698, "KVKKKVKKPersonal Data Protection Law No. 6698Türkiye's data protection statute — the rules on collecting, storing and transferring personal data, and the authority that enforces them.Glossary →"), and ignoring them can lead to significant administrative fines that are increased every year. This guide explains, in plain terms, what counts as a breach, who you must notify and how fast, and how the penalty system works under the current regime after the 2024 amendment.

What counts as a data breach under the KVKK?

A data breach happens when personal data is accessed, disclosed, changed, or lost in a way that is not lawful or not intended. The KVKK frames this through its data security rule rather than through a stand-alone "breach" definition.

The governing provision is Article 12 of the Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu — the Turkish equivalent of the GDPR). Article 12 requires the data controller (veri sorumlusu — the party that decides the purposes and means of processing) to take all necessary technical and organisational measures to keep personal data safe. A breach is, in essence, the failure of those safeguards.

Common examples that can qualify include:

  • A hacker or ransomware attack that exposes a customer or employee database.
  • An employee emailing a spreadsheet of personal data to the wrong recipient.
  • A lost or stolen laptop, phone, or backup drive containing unencrypted personal data.
  • A misconfigured server or cloud bucket that leaves data open to the internet.
  • An insider copying or selling personal data without authorisation.

The legal hook: Article 12 KVKK puts the security burden on the data controller. When that security fails and personal data is captured by others unlawfully, the notification duties described below are triggered.

Importantly, the obligations can reach foreign companies. If your business processes personal data of people in Türkiye — for example through a Turkish branch, local customers, or a Turkish-facing service — you may fall within the scope of the KVKK even without a Turkish registered office. Whether you do is a fact-specific question worth checking early.

The duty to notify the Board — how fast is "the shortest time"?

If a breach occurs, the data controller must report it to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) — the regulator that enforces the KVKK — within the shortest time. The law itself uses this qualitative phrasing under Article 12 rather than fixing a precise deadline in the statute.

To give that phrase a concrete meaning, the Board issued guidance. That guidance is commonly cited as requiring notification within 72 hours of the controller becoming aware of the breach. Because this figure comes from Board guidance and practice rather than the bare wording of the statute, and because timing rules can be updated, you should confirm the current applicable window for your specific situation before relying on it.

Treat the clock as already running. The safest assumption is that you have a very short, fixed number of hours from the moment you detect a breach. Do not wait until your internal investigation is finished to start the notification process — late notification is itself a compliance failure that the Board can act on.

A Board notification is generally expected to describe what happened, which data and how many people are affected, the likely consequences, and the steps you are taking to contain and remedy the breach. Where you cannot yet provide all the detail, it is usual to notify on the basis of what is known and supplement afterwards. The exact required content and any official notification form should be checked against current Board materials.

Notifying the affected individuals

Reporting to the Board is not the end of your duty. When a breach affects identifiable people, you must also inform the affected individuals — the data subjects whose personal data was compromised. This lets them take their own protective steps, such as changing passwords or watching for fraud.

The notice to individuals should be made in a clear, accessible way. Where you can reach affected people directly — for instance by email or letter — that direct route is generally expected. Where direct contact is not possible, the Board's practice contemplates other reasonable methods, which may include a notice published on your website. The appropriate method and wording should be confirmed for your facts.

What a good individual notice usually covers

  • That a breach occurred, and in plain terms what happened.
  • Which categories of their personal data were affected.
  • The possible consequences for them.
  • What you have done in response, and what they can do to protect themselves.
  • A contact point where they can ask questions.

Prepare templates in advance. The fastest way to meet a tight notification window calmly is to have draft Board and data-subject notices, an internal escalation chart, and a decision log ready before any incident. In a real breach you will be editing a template under pressure, not writing from scratch.

Administrative fines and other penalties under Article 18

The penalty framework sits in Article 18 of the KVKK, which sets out the administrative fines (idari para cezaları) the Board can impose. Rather than quoting figures — which change — it is more useful to understand the structure, because the structure is stable even as the numbers move.

Article 18 ties penalties to specific categories of failure. Broadly, distinct fineable failures include not fulfilling the obligation to inform data subjects, not meeting data security obligations (the Article 12 duties, which is where breach handling lives), not complying with Board decisions, and VERBİS registration failures, where applicable. Each category carries its own monetary band of minimum and maximum amounts.

The figures move every year. The fine bands in Article 18 are revalued annually in line with the statutory revaluation rate. Any specific number you read in an older article is likely already out of date — always check the amount in force for the year of the violation.

How exposure can add up

  • Per-violation logic: fines attach to violations, so a single incident that breaches several obligations can attract more than one penalty.
  • Scale matters: the Board weighs factors such as the seriousness of the violation and the controller's conduct when setting the amount within the band.
  • Beyond the fine: a breach can also bring reputational harm, individual compensation claims by affected people, and, in some fact patterns, separate criminal exposure under the Turkish Penal Code for unlawful data conduct — which is distinct from the administrative fines under the KVKK.

2024 reform: the KVKK was amended by Law No. 7499 (2024), which reshaped parts of the regime — notably around cross-border data transfers and aspects of enforcement and the route for appealing administrative fines. Because of this, advice and figures published before the amendment may no longer reflect the current rules. The current position should be verified rather than assumed.

Cross-border transfers and special-category data after the 2024 amendment

Breaches rarely happen in isolation from how data moves. Two areas changed meaningfully with the 2024 reform and deserve a check before any incident, because they affect both your day-to-day compliance and your exposure if something goes wrong.

Cross-border data transfers

The way personal data may lawfully be transferred outside Türkiye was restructured by Law No. 7499. The amended framework recognises mechanisms — broadly, adequacy-style routes and appropriate safeguards such as standard contractual clauses, alongside certain exceptional bases — but the precise conditions, documentation, and any notification expectations are technical and were newly introduced. If your group sends Türkiye-linked data abroad (for example to a parent company or a cloud provider), the lawful basis for that transfer should be confirmed under the current rules.

Special categories of personal data

The KVKK treats special categories of personal data (özel nitelikli kişisel veri) — such as health, biometric, religious belief, or criminal-record data — with heightened protection. A breach involving these categories is generally more serious and is treated as higher-risk. The conditions for processing and protecting special-category data were also touched by the 2024 amendment, so the safeguards you rely on should be reviewed against the current text.

Mapping where your Türkiye-linked data lives, where it flows, and which categories it includes is the single most useful preparation you can do. It tells you, in advance, both how to transfer lawfully and how bad a given breach would be.

A practical response checklist for foreign companies

If you operate from outside Türkiye but handle personal data connected to it, the following sequence helps you meet KVKK expectations under pressure. None of this is a substitute for advice on your specific incident.

  • Detect and contain first. Stop the ongoing exposure — isolate systems, revoke access, secure backups.
  • Start the clock consciously. Record the date and time you became aware; the notification window is short and is measured from awareness.
  • Assess scope. Identify what data, whose data, how many people, and which categories — paying special attention to special-category data and any cross-border element.
  • Notify the Board promptly. File within the applicable window (commonly cited as 72 hours — confirm), supplementing detail as your investigation continues.
  • Notify affected individuals. Tell the people whose data was compromised, in clear language, with practical guidance.
  • Document everything. Keep a contemporaneous log of decisions, timings, and measures; this record matters if the Board reviews your conduct.
  • Remediate and review. Fix the root cause and update your technical and organisational measures under Article 12.

This article explains the general framework and is not legal advice. Breach handling is fact-sensitive and time-critical, and the figures and deadlines change. If you are facing an incident involving Türkiye-linked data, get tailored advice quickly — the difference is often measured in hours.

If you would like help building a breach-response plan, or you are dealing with a live incident, our team can review your situation under the current KVKK regime and help you respond in a structured, defensible way.

Frequently asked questions

How quickly must I report a data breach to the Turkish Board?

The KVKK requires notification within the "shortest time." The Board's guidance is commonly cited as a 72-hour window from when you become aware of the breach, but because this comes from Board guidance and practice and can be updated, you should confirm the current applicable deadline for your situation. The safest approach is to treat the clock as running from the moment of detection.

Does the KVKK apply to my company if we are based outside Türkiye?

It can. If you process personal data of people in Türkiye — through a branch, local customers, or a Türkiye-facing service — you may fall within the scope of Law No. 6698 even without a registered office there. Whether you do is fact-specific, so it is worth confirming your status before an incident rather than during one.

What are the penalties for failing to notify a breach?

Administrative fines are set out in Article 18 of the KVKK and apply to categories of failure, including breach-related data security obligations. The amounts are arranged in monetary bands that are revalued every year, and fines attach per violation, so one incident can trigger more than one penalty. Because the figures change annually, you should check the amount in force for the relevant year rather than relying on older numbers.

Do I have to tell the affected individuals, or just the Board?

Both. When a breach affects identifiable people, the KVKK requires you to inform those individuals as well as the Board, so they can take protective steps. The notice should be clear and accessible, made directly where possible, with other reasonable methods where direct contact is not feasible — the appropriate method should be confirmed for your facts.

What changed with the 2024 amendment to the KVKK?

Law No. 7499 (2024) reshaped parts of the regime, notably the rules for transferring personal data outside Türkiye, the treatment of special-category data, and aspects of enforcement and the route for appealing administrative fines. Because of these changes, guidance published before the amendment may be out of date, so the current position should be verified rather than assumed.

Could a breach lead to anything beyond an administrative fine?

Yes. Beyond the Article 18 administrative fines, a breach can lead to compensation claims by affected individuals, reputational harm, and — in certain fact patterns — separate criminal exposure under the Turkish Penal Code for unlawful data conduct. These are distinct from the KVKK fines and should be assessed together for your specific incident.

Need a lawyer for this?We handle data protection (kvkk) for foreigners, end to end, in English, on a fixed fee.
Data Protection (KVKK)

Related articles

GDPR and Turkish Companies: Navigating ComplianceTurkey's Cybersecurity Law No. 7545: Scope & Principles
Let's begin

Speak to a Turkish lawyer who speaks your language.

Tell us your commercial, corporate or personal matter and get a clear, fixed-fee answer from a real Turkish lawyer — usually within one business day.

★★★★★ 4.9 from 60 Google reviews · Recognised on Mondaq, Clutch & Trustpilot
WhatsApp us
A real lawyer replies — usually within a day
WhatsAppEmailBook a consultation