Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Cyber Security & Compliance

Data Breach Notification in Turkey: What to Do in the First 72 Hours Under KVKK

How to notify a data breach within 72 hours under Turkey's KVKK: notifying the Board and affected people, preserving evidence and an hour-by-hour plan.

7 min read  · Digital Bridge Engineering Team
Data Breach Notification in Turkey: What to Do in the First 72 Hours Under KVKK

Under KVKK, data breach notification in Turkey means a controller that learns personal data was unlawfully obtained must notify the Personal Data Protection Board without delay and within 72 hours, then tell affected people as soon as reasonably possible. The clock starts when you become aware of the breach, so your response plan must exist beforehand.

The problem: 72 hours is very short if you are unprepared

Breaches rarely announce themselves. An employee spots an unfamiliar sign-in alert, a customer forwards an email "from you" they did not expect, or files on the server will not open one morning. In the first hours nobody knows whether personal data is involved; IT is busy restoring systems, management is worried about reputation and legal is reading contracts. Meanwhile the clock is running.

Article 12 of KVKK (Law No. 6698) requires breaches to be reported "as soon as possible". Board Decision 2019/10 of 24 January 2019 interprets that as 72 hours: the data controller must notify the Board without delay and within 72 hours at the latest after becoming aware of the breach (KVKK 2025 Annual Activity Report). Weekends and public holidays do not pause it.

The deadline mirrors the GDPR, but there is an important difference: KVKK has no provision exempting low-risk breaches from notification. If personal data has been unlawfully obtained by others, notification must be considered.

The cost of late or incomplete notification

In Türkiye, breach notifications are now routine business for the regulator:

According to the KVKK 2025 Annual Activity Report, the Authority received 328 data breach notifications in 2025, and 51 breaches were publicly announced on its website that year.

Notifications can lead to sanctions. The same annual report shows that of the 876 data controllers fined in 2025, 142 were fined in connection with breach notifications. A breach published on the Board's website carries a reputational cost that can outweigh the fine itself.

The breach is expensive in its own right. The IBM Cost of a Data Breach Report 2026 puts the global average cost of a data breach at a record $4.99 million. Data is usually the target: according to the Microsoft Digital Defense Report 2025, attackers sought to steal data in 80% of the incidents Microsoft's teams investigated. The Verizon 2026 Data Breach Investigations Report found ransomware present in 48% of all breaches, which means a ransomware incident is very often a personal data breach as well.

Data breach notification in Turkey: an hour-by-hour plan for the first 72 hours

The timeline below counts from the moment the breach is discovered. The windows are upper limits; every step you finish earlier improves the quality of the notification.

TimeWhat happensOwner
Hours 0–4Log the incident, record the moment of awareness, assemble the team, contain the spreadIT + incident lead
Hours 4–24Preserve evidence, identify affected systems and data categories, estimate how many people are affectedIT + security support
Hours 24–48Legal assessment, draft the notification form and the message to data subjectsData protection lead + legal
Hours 48–72Submit the notification to the Board, plan how missing details will followData protection lead, signed off by management
After 72 hoursNotify data subjects, root cause analysis, lasting fixes, incident fileWhole team

These are the steps that make the table work in practice:

  1. Record the moment of awareness. The 72 hours start when you learn of the breach. From the first minute, write down who noticed, when and on what evidence.
  2. Contain without destroying evidence. Reset compromised passwords, end sessions and isolate affected devices. Before rebuilding anything, copy the logs and take a disk image; the root cause analysis depends on them.
  3. Establish the scope. Which systems, which data categories and roughly how many people are affected? An up-to-date personal data inventory turns hours of searching into minutes.
  4. Notify the Board. Notification is made through the Personal Data Breach Notification Form on the Authority's website. If not all information is available at once, it can be provided in stages without undue delay. If you miss 72 hours, include the reasons for the delay.
  5. Inform the people affected. Once they are identified, notify them as soon as reasonably possible: directly where you can reach them, otherwise by suitable means such as your website. Explain when the breach happened, which data was involved, likely consequences, the measures taken and a contact point.
  6. Bring processors into the loop. If the incident happened at a software, payroll or cloud provider, that processor must inform you without delay. Make sure your contract spells out that duty and the contact channel. The clauses a software supplier contract should contain are covered in software contracts and source code ownership.
  7. Document everything. The Board decision requires controllers to record the facts of the breach, its effects and the measures taken, and to keep that record available for the Board.

What must be ready before an incident

  • A response team list with names, phone numbers and deputies
  • A current personal data inventory and system map
  • Centrally collected access and session logs (SIEM and log management; if you offer internet access to guests or staff, the Law 5651 log records)
  • An offline copy of backups and regular restore testing
  • A pre-filled draft notification and data subject message
  • A tabletop exercise at least once a year and regular security awareness training for staff

Each part of that preparation has its own guide:

  • Baseline controls: our SME cyber security checklist, and for the whole topic our Cyber Security & Compliance guide.
  • Recovery: tested backups kept out of an attacker's reach, covered in ransomware and 3-2-1 backups.
  • Entry points: a significant share of breaches start with stolen credentials and phishing, so business password security and how to spot phishing emails are part of prevention.
  • Limiting data exfiltration: restrict sensitive files leaving uncontrolled by email, cloud or USB stick with data loss prevention (DLP) rules.
  • Finding weak points first: what penetration testing involves, from scope to report.
  • AI tools: to list, before any incident, which personal data goes to which AI service, see our guide to AI and personal data protection.

How we prepare for and respond to breaches at Digital Bridge

Breach management is both a legal and a technical job, and we handle both within the same plan.

  • We write the response plan. Through our data protection compliance consultancy we prepare the personal data inventory, roles, notification templates and decision tree around your organisation.
  • We build technical readiness. Our cyber security consultancy team handles central logging, access control, backups and penetration testing, and supports scoping and evidence preservation during an incident.
  • We make logs usable. We bring access and event logs from different systems together through system integrations and set up anomaly detection to flag unusual behaviour. How unusual patterns in security logs are caught is explained in our anomaly detection guide.
  • We harden the infrastructure. Backup and disaster recovery architecture is designed as part of our cloud migration and infrastructure consultancy.

We do not sell off-the-shelf packages; after a needs analysis we provide a written proposal setting out scope, phases and cost. Our technical support team is available 24/7.

Next step

Ask yourself one question this week: "If a breach were discovered at 6 pm on a Friday, who gets the first call, and what would that person send to the Board by Sunday night?" If the answer is unclear, get in touch through our contact page. We will build your response plan and notification templates with you, then test them in a tabletop exercise. For the rest of the compliance picture, see our KVKK compliance roadmap.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

When does the 72-hour clock start under KVKK?

It starts when the data controller becomes aware of the breach, not when the breach actually occurred. That is why the time of discovery, who discovered it and the evidence behind it should be recorded from the first minute. Weekends and public holidays do not stop the clock, so your response plan needs named owners and deputies for holiday periods as well.

Can we notify the Board before we have all the facts?

Yes. The Board decision allows information to be provided in stages, without undue delay, where it cannot all be provided at once. Rather than missing the 72-hour deadline while waiting for complete facts, notify what you know and state which details will follow. If the deadline is missed, the notification must explain the reasons for the delay.

Do we also have to notify the people affected?

Yes. Once affected individuals are identified, the data controller must inform them as soon as reasonably possible: directly where they can be reached, otherwise by suitable means such as a website notice. The message should cover when the breach occurred, which data categories were involved, likely consequences, the measures taken and a contact point for questions.

Is a ransomware attack a data breach?

In most cases, yes. Many ransomware groups copy data out before encrypting files, which can amount to personal data being unlawfully obtained by others. If you cannot quickly prove that no data left your network, the safer course is to treat the incident as a breach, start the notification process and complete the findings in stages as the investigation progresses.

Who notifies if the breach happens at a supplier?

If you are the data controller, the duty to notify the Board and affected people stays with you. A software, payroll or cloud provider acting as your processor must inform you without delay when it learns of a breach. That is why processing agreements should set out the notification deadline, contact person and the information to be shared in advance.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.