Skip to content
Symmetric Metro Internet: equal download and upload up to 10 Gbps
Erbe Bilişim
KVKK & Compliance

Data Breach Notification in Turkey: The 72-Hour Rule and Crisis Plan

Apply Turkey's 72-hour data breach notification rule: report to the KVKK authority and affected individuals on time, and prepare your crisis plan early.

  • Erbe Bilişim Uzman Ekibi
  • 7 min read
KVKK & Compliance category cover — a sealed document icon on a dark navy background

It is Monday morning and an employee calls: a copy of your customer database is for sale on a forum you have never heard of, and server logs show unauthorized access around midnight. That moment is when the clock starts. If your company processes personal data in Turkey, the local data protection framework ties your breach notification duty to a 72-hour window. This guide covers what a breach is, how to notify the authority and affected individuals, how to run crisis communication, and which technical measures stop breaches before they happen, so you can prepare in advance rather than improvise under pressure.

What Counts as a Data Breach

A personal data breach is any event where security controls are bypassed and data is exposed, altered, or made inaccessible without authorization. Classifying the type correctly shapes your notification decision. Three categories cover most cases:

  • Confidentiality breach: data seen or leaked to unauthorized parties.
  • Integrity breach: data changed or corrupted without permission.
  • Availability breach: data lost or made inaccessible.

A ransomware attack encrypts files and can trigger both an availability and a confidentiality breach at once; a stolen laptop, a misdirected email, or a misconfigured database are equally typical. Not every event forces a notification, though. The deciding test is whether personal data was affected: losing encrypted, backed-up data briefly may pose little risk, while a leak of identity, contact, or financial data has serious consequences. Record this assessment in writing so you can account for your decision later.

The 72-Hour Rule: Notifying the Authority

When a breach is detected, the most time-critical duty is notifying the Personal Data Protection Authority. Turkish regulatory context: under KVKK, the data controller must report a breach as soon as possible and no later than 72 hours after becoming aware of it. The clock starts the moment the incident is noticed, not when the investigation ends, and foreign companies operating in Turkey face the same window as local ones.

If you cannot report in time, you must explain the reason for the delay. Missing the deadline is not an automatic fixed penalty, but an unjustified delay makes your liability heavier. Notification is filed on the authority's breach notification form, whose core fields are:

FieldContent
Nature of the breachHow and when it occurred
Affected data categoriesGroups such as identity, contact, financial
Affected people and recordsApproximate scale estimate
Likely consequencesPossible risks to individuals
Measures takenContainment and remediation steps

Full information is rarely available at the start. Phased notification is allowed: you open the file within the window and complete the missing details afterward. You can reach the current form and guidance from the Personal Data Protection Authority and the full text of the law on the Legislation Information System. To place this duty inside a wider program, see our KVKK compliance process guide.

Informing Affected Individuals

Notifying the authority is only one leg. If the breach poses a risk to people, the data subjects must be told too, so they can protect themselves by changing a password or watching card activity. The message must be clear and plain, describing the event and the person's options without technical overload. An effective notice carries four elements:

  1. Summary of the event: what happened and which data was affected.
  2. Likely consequences: concrete risks to the individual.
  3. Recommended steps: measures such as changing passwords or monitoring activity.
  4. Contact channel: a point of contact for questions.

This is where most mistakes happen: companies delay the notice or write it in language that hides the event, yet a transparent, timely message limits reputational damage far more than any fine. Phishing often rises after a breach, so remind people to stay alert; our guide to spotting phishing emails is worth sharing.

Building a Crisis Communication Plan

The most expensive delay during a breach is uncertainty over who does what. A crisis plan, written before the incident and rehearsed regularly, removes it. It names responsibilities person by person: an incident response team with technical, legal, communications, and management members, each with a role and a backup, plus multiple contact channels so they can assemble within minutes. Separate internal and external communication in advance, name a single spokesperson to prevent contradictory statements, and avoid sharing unverified information that creates a lasting trust gap.

The backbone of the plan is three stages:

  • Detection and containment: confirm the incident, isolate affected systems.
  • Assessment and notification: measure the risk, decide on notifying the authority and individuals.
  • Recovery and learning: restore systems safely, take lessons from the event.

A plan that stays on paper is worthless, so run at least one scenario exercise per year. A disaster recovery approach complements it for business continuity; see our disaster recovery plan guide.

Technical Measures That Prevent Breaches

The best notification is the one you never have to send. Preventing the breach is the real objective, and Turkish data protection rules also require adequate technical measures. A layered defense rests on complementary controls, not a single product:

Technical measureRisk it prevents
Firewall and network segmentationUnauthorized network access
Data loss prevention (DLP) toolsData exfiltration
Encryption and regular backupsData loss and ransomware impact
Multi-factor authenticationLogin with a stolen password
Log collection and SIEM monitoringDelayed breach detection

Among controls aimed at data exfiltration, data loss prevention leads; our platform of choice is Teramind DLP. Early detection, in turn, needs continuous log collection. A SIEM (security information and event management) system gathers logs from many sources and correlates them, so an abnormal access turns into an alert and the response clock begins. In our own 24/7 monitoring, a single deployment recorded 262 attack attempts and 104 IPs in 24 hours, with 16 attempts per second at peak, and all logs stayed fully on-premise with 0 cloud transfer. Built entirely in Turkey, ERBE SIEM adds a TÜBİTAK RFC 3161 timestamp to the log stream, strengthening the evidentiary value of your records.

Conclusion

Breach notification is only the visible face of a 72-hour race; what matters is meeting those three days with a plan prepared in advance. Organizations that define the breach correctly, notify the authority and individuals on time, manage crisis communication, and lower the odds with technical measures protect themselves from both penalties and reputational loss. To plan physical and digital security under one roof, explore our cyber security services.

Frequently Asked Questions

What should we do in the first 24 hours after spotting a breach?

Confirm the incident without panic, then isolate affected systems, preserve evidence, and assemble the incident response team. Next, assess which personal data was affected and the likely risk, since that drives your decision to notify the authority and the individuals. Log every step by the hour so you can account for your actions later.

What happens if we cannot notify within 72 hours?

Missing the window is not, on its own, a fixed penalty, but you must explain a reasonable justification for the delay to the authority. An unjustified delay makes your liability heavier. If some details are still unclear, phased notification is allowed: open the first notification on time rather than stay silent, then complete the missing information afterward.

Is notifying affected individuals mandatory for every breach?

No. The test is whether the breach creates a risk for the individuals concerned. A short outage of encrypted, backed-up data may not carry high risk. But when identity, contact, or financial data leaks, people must be informed so they can take protective steps such as changing a password. Keep a written record of your reasoning.

Tags

  • data breach
  • breach notification
  • crisis management