Under KVKK, data breach notification in Turkey means a controller that learns personal data was unlawfully obtained must notify the Personal Data Protection Board without delay and within 72 hours, then tell affected people as soon as reasonably possible. The clock starts when you become aware of the breach, so your response plan must exist beforehand.
The problem: 72 hours is very short if you are unprepared
Breaches rarely announce themselves. An employee spots an unfamiliar sign-in alert, a customer forwards an email "from you" they did not expect, or files on the server will not open one morning. In the first hours nobody knows whether personal data is involved; IT is busy restoring systems, management is worried about reputation and legal is reading contracts. Meanwhile the clock is running.
Article 12 of KVKK (Law No. 6698) requires breaches to be reported "as soon as possible". Board Decision 2019/10 of 24 January 2019 interprets that as 72 hours: the data controller must notify the Board without delay and within 72 hours at the latest after becoming aware of the breach (KVKK 2025 Annual Activity Report). Weekends and public holidays do not pause it.
The deadline mirrors the GDPR, but there is an important difference: KVKK has no provision exempting low-risk breaches from notification. If personal data has been unlawfully obtained by others, notification must be considered.
The cost of late or incomplete notification
In Türkiye, breach notifications are now routine business for the regulator:
According to the KVKK 2025 Annual Activity Report, the Authority received 328 data breach notifications in 2025, and 51 breaches were publicly announced on its website that year.
Notifications can lead to sanctions. The same annual report shows that of the 876 data controllers fined in 2025, 142 were fined in connection with breach notifications. A breach published on the Board's website carries a reputational cost that can outweigh the fine itself.
The breach is expensive in its own right. The IBM Cost of a Data Breach Report 2026 puts the global average cost of a data breach at a record $4.99 million. Data is usually the target: according to the Microsoft Digital Defense Report 2025, attackers sought to steal data in 80% of the incidents Microsoft's teams investigated. The Verizon 2026 Data Breach Investigations Report found ransomware present in 48% of all breaches, which means a ransomware incident is very often a personal data breach as well.
Data breach notification in Turkey: an hour-by-hour plan for the first 72 hours
The timeline below counts from the moment the breach is discovered. The windows are upper limits; every step you finish earlier improves the quality of the notification.
| Time | What happens | Owner |
|---|---|---|
| Hours 0–4 | Log the incident, record the moment of awareness, assemble the team, contain the spread | IT + incident lead |
| Hours 4–24 | Preserve evidence, identify affected systems and data categories, estimate how many people are affected | IT + security support |
| Hours 24–48 | Legal assessment, draft the notification form and the message to data subjects | Data protection lead + legal |
| Hours 48–72 | Submit the notification to the Board, plan how missing details will follow | Data protection lead, signed off by management |
| After 72 hours | Notify data subjects, root cause analysis, lasting fixes, incident file | Whole team |
These are the steps that make the table work in practice:
- Record the moment of awareness. The 72 hours start when you learn of the breach. From the first minute, write down who noticed, when and on what evidence.
- Contain without destroying evidence. Reset compromised passwords, end sessions and isolate affected devices. Before rebuilding anything, copy the logs and take a disk image; the root cause analysis depends on them.
- Establish the scope. Which systems, which data categories and roughly how many people are affected? An up-to-date personal data inventory turns hours of searching into minutes.
- Notify the Board. Notification is made through the Personal Data Breach Notification Form on the Authority's website. If not all information is available at once, it can be provided in stages without undue delay. If you miss 72 hours, include the reasons for the delay.
- Inform the people affected. Once they are identified, notify them as soon as reasonably possible: directly where you can reach them, otherwise by suitable means such as your website. Explain when the breach happened, which data was involved, likely consequences, the measures taken and a contact point.
- Bring processors into the loop. If the incident happened at a software, payroll or cloud provider, that processor must inform you without delay. Make sure your contract spells out that duty and the contact channel. The clauses a software supplier contract should contain are covered in software contracts and source code ownership.
- Document everything. The Board decision requires controllers to record the facts of the breach, its effects and the measures taken, and to keep that record available for the Board.
What must be ready before an incident
- A response team list with names, phone numbers and deputies
- A current personal data inventory and system map
- Centrally collected access and session logs (SIEM and log management; if you offer internet access to guests or staff, the Law 5651 log records)
- An offline copy of backups and regular restore testing
- A pre-filled draft notification and data subject message
- A tabletop exercise at least once a year and regular security awareness training for staff
Each part of that preparation has its own guide:
- Baseline controls: our SME cyber security checklist, and for the whole topic our Cyber Security & Compliance guide.
- Recovery: tested backups kept out of an attacker's reach, covered in ransomware and 3-2-1 backups.
- Entry points: a significant share of breaches start with stolen credentials and phishing, so business password security and how to spot phishing emails are part of prevention.
- Limiting data exfiltration: restrict sensitive files leaving uncontrolled by email, cloud or USB stick with data loss prevention (DLP) rules.
- Finding weak points first: what penetration testing involves, from scope to report.
- AI tools: to list, before any incident, which personal data goes to which AI service, see our guide to AI and personal data protection.
How we prepare for and respond to breaches at Digital Bridge
Breach management is both a legal and a technical job, and we handle both within the same plan.
- We write the response plan. Through our data protection compliance consultancy we prepare the personal data inventory, roles, notification templates and decision tree around your organisation.
- We build technical readiness. Our cyber security consultancy team handles central logging, access control, backups and penetration testing, and supports scoping and evidence preservation during an incident.
- We make logs usable. We bring access and event logs from different systems together through system integrations and set up anomaly detection to flag unusual behaviour. How unusual patterns in security logs are caught is explained in our anomaly detection guide.
- We harden the infrastructure. Backup and disaster recovery architecture is designed as part of our cloud migration and infrastructure consultancy.
We do not sell off-the-shelf packages; after a needs analysis we provide a written proposal setting out scope, phases and cost. Our technical support team is available 24/7.
Next step
Ask yourself one question this week: "If a breach were discovered at 6 pm on a Friday, who gets the first call, and what would that person send to the Board by Sunday night?" If the answer is unclear, get in touch through our contact page. We will build your response plan and notification templates with you, then test them in a tabletop exercise. For the rest of the compliance picture, see our KVKK compliance roadmap.