In short: Under the KVKK Board’s Decision No. 2019/10, a controller should notify the Board without delay and no later than 72 hours after becoming aware of a personal-data breach. Affected individuals follow a separate “shortest reasonable period” standard after identification. The Board decision also calls for staged information where needed and documentation of all breaches.
Who should read this: This guide is for controllers, processors, privacy teams and groups handling data about people in Türkiye.
At a Glance
| Board notification | Without delay and no later than 72 hours after controller awareness, under Board Decision No. 2019/10. |
| Notice to individuals | Shortest reasonable period after affected people are identified; a separate standard. |
| Processor escalation | Processor should notify the controller without delay. |
| Foreign controller | Same principles may apply where the affected people reside in Türkiye and use services offered there. |
| Evidence | Document the facts, impact and mitigation for every personal-data breach. |
Türkiye’s Personal-Data Breach Notification Rule
Article 12(5) of Personal Data Protection Law No. 6698 (KVKK) requires a data controller to notify the affected person and the Personal Data Protection Board when processed personal data has been obtained by others through unlawful means. The Board’s Decision No. 2019/10 interprets notification to the Board as being made without delay and no later than 72 hours after the controller becomes aware of the breach.
The deadline is for the controller’s Board notification. It should not be confused with the notice to affected people: the Board says data subjects should be informed within the shortest reasonable period after they are identified. If all information cannot be provided at once, the controller may submit information in stages without undue delay and should explain any delay in the Board notice.
What Counts as a Breach Requiring Triage?
Start with the facts, not the incident label. Investigate whether personal data was accessed, acquired, disclosed, altered, lost or made unavailable through an event involving unlawful access or processing. A ransomware incident, misdirected email, exposed database, lost device, compromised supplier account or unauthorised export may require immediate assessment. The legal reporting decision depends on what happened to personal data and the roles of the organisations involved.
Identify the data controller and any data processor. Under the Board decision, a processor that becomes aware that data it holds has been obtained unlawfully should notify the controller without delay. The contract can set a shorter operational escalation window; a controller should not wait for a processor’s final forensic report before beginning its own clock assessment.
First 72 Hours: Incident Response Sequence
- Activate the response plan. Name an incident lead, privacy/legal contact, security lead and business owner. Record when each person first learned facts that may establish awareness.
- Contain and preserve. Limit further access, protect affected systems and preserve logs, messages, access records and forensic evidence. Do not destroy evidence while restoring service.
- Map the data and people. Identify data categories, approximate records and people, affected systems, locations, recipients and any sensitive or financial data. Distinguish verified facts from estimates.
- Assess the controller/processor roles. Determine which entity decides the purposes and means of processing, which entities act on instructions, and who submits the notification.
- Decide and submit to the Board. Use the Board’s prescribed personal-data breach notification form and channel. Submit without delay and no later than 72 hours after awareness; provide available information and explain any delay.
- Notify affected people. Once people are identified, communicate in the shortest reasonable period using a direct channel where contact details are available. Explain practical protective steps in clear language.
- Supplement and document. Update the Board and affected individuals as material information is confirmed, and maintain a record of facts, effects, decisions, notifications and mitigation.
What the Board Notification Should Establish
The initial report should make clear what is known, what remains under investigation, the categories and approximate number of affected people and records, the likely consequences, the containment steps and the contact point. The Board’s decision expressly allows information to be provided gradually if it is not possible to complete the form at the same time. Do not wait for perfect certainty; label preliminary estimates and update them as the investigation develops.
Notifying Individuals: Clear, Useful and Timely
The notification to people affected serves a different purpose from the regulator filing. Use plain language to say what happened, what data may be involved, what the organisation has done and what practical steps people can take. Avoid unsupported assurances that there is no risk. If contact details cannot be reached, the Board decision refers to appropriate alternative methods, including publication on the controller’s website in suitable cases.
Foreign Controllers and International Incidents
The Board’s Decision No. 2019/10 specifically addresses controllers established abroad. It states that the same notification principles apply where a breach affects data subjects residing in Türkiye who benefit from products or services provided in Türkiye. An international group should not assume that reporting to another country’s regulator replaces the Turkish assessment. Coordinate notices across jurisdictions while preserving the Turkish deadline and role analysis.
After the Immediate Response
The controller should document all personal-data breaches, including their facts, effects and measures taken, and make those records available to the Board if requested. Review whether access controls, processor contracts, retention, monitoring, training and escalation paths contributed to the event. Update the periodically reviewed breach response plan, including who decides notification, who contacts affected people and how the organisation evaluates likely consequences.
KVKK Breach Readiness Checklist
- Maintain an incident plan with a named decision-maker and a reliable record of awareness time.
- Require processors to escalate suspected personal-data breaches immediately under written procedures.
- Keep a current data map covering systems, data categories, vendors and affected-person contact routes.
- Prepare the KVKK Board notification form and internal fact-gathering template in advance.
- Separate Board reporting from affected-person communication and track each timing decision.
- Preserve incident evidence and document all breaches, including those for which no notification is made.
Frequently Asked Questions
How quickly must a Turkish personal-data breach be reported to the KVKK Board?
The Board’s Decision No. 2019/10 interprets “the shortest time” in Article 12(5) as without delay and no later than 72 hours after the data controller becomes aware of the breach. If a complete submission is not possible within that period, information may be provided in stages and the reasons for delay should be stated.
Do affected individuals also have to be notified within 72 hours?
The Board decision uses a separate standard for people affected: communication should be made within the shortest reasonable period after those individuals are identified. The 72-hour period is the Board-notification standard.
Must a foreign controller notify the Turkish Board?
The Board decision states that an overseas-established controller must notify under the same principles where a breach affects data subjects residing in Türkiye who benefit from products or services offered in Türkiye. Scope should be assessed on the facts.
What if the controller is still investigating when the 72-hour period expires?
The Board’s decision permits information to be supplied gradually where it cannot all be provided at once. The controller should notify without delay, explain any delay and supplement the report as facts are confirmed.
Should every breach be documented even if no notification is made?
The Board decision says controllers should document all personal-data breaches, including facts, effects and measures taken, and keep that documentation available for the Board to examine.
