Follow us :
KVKK & Compliance

KVKK Data Breach Notification: What to Do in the First 72 Hours

Desk with dual monitors showing security monitoring dashboards — Xen Bilişim KVKK & Compliance

An old backup drive goes missing, or an employee’s account gets compromised. How much time do you actually have — two days, a week? Under KVKK, Türkiye’s personal data protection law, the answer is 72 hours. But the clock doesn’t start when the incident happened — it starts the moment you find out about it, and that distinction trips up most companies the first time they face a breach.

When does the 72-hour clock actually start?

Article 12(5) of Law No. 6698 (KVKK) requires data controllers to notify the Board “as soon as possible” when personal data has been unlawfully obtained by a third party. The Board turned that vague phrase into a hard number with Decision No. 2019/10, dated 24 January 2019: as soon as possible means no later than 72 hours.

The starting point is where most companies get it wrong. The countdown begins when the controller learns of the breach — not when the breach technically occurred. An intrusion that happened three weeks ago but only surfaced in yesterday’s logs still gives you a clock that started yesterday. Which means the slower your detection setup — log monitoring, alerting, EDR — the less real maneuvering room you have once something goes wrong.

What the first hours should look like

Seventy-two hours is short, and panic makes it shorter. The order matters:

  • Contain it first. Isolate the compromised account, server, or network segment. Don’t destroy evidence while you’re at it — wiping a system before imaging the disk makes it impossible to later establish what was actually lost.
  • Scope it. Which data categories are affected (identity, contact, financial, health), how many people, which systems? If you don’t have exact numbers yet, work with an estimate and update it as the picture clears.
  • Loop in your compliance lead immediately. Whether that’s an internal KVKK officer or an outside advisor, the 72-hour window is their preparation time too.
  • Start a log. When it was discovered, by whom, what steps were taken and when — this record becomes the backbone of both the notification form and any later audit.

Notifying the Board: the form and the channel

Notification goes through the official Personal Data Breach Notification Form, submitted electronically via ihlalbildirim.kvkk.gov.tr. The form asks for the nature of the breach, the categories and approximate number of affected individuals, the likely consequences, and the measures taken or planned.

You don’t need every field finalized within 72 hours. The Board accepts phased notification: file with what you know, then follow up as details firm up. If you do miss the deadline, the form still gets submitted — you just need to explain the delay in it.

When and how to notify the affected individuals

The Board notification deadline is a fixed 72 hours. Notifying the people whose data was affected works differently — the law only says “as soon as reasonably possible,” with no fixed number of hours. The standard is the size of the potential harm: if passwords, national ID data, or financial details leaked, notification shouldn’t wait; for a lower-risk exposure, a short assessment period is generally accepted.

Direct contact — email, phone, SMS — is the preferred route. When that’s not possible (say, contact details weren’t even part of what you held), a public notice on the company website or another suitable channel is acceptable. In published Board decisions involving hundreds or thousands of affected individuals, this second route shows up often.

What happens if you miss the window

Missing 72 hours doesn’t trigger an automatic fine — the Board weighs the justification. But when the underlying cause is “the controller hadn’t implemented adequate technical measures,” a different and much heavier article applies:

Violation2026 minimum2026 maximum
Breach notification failure85,437 TL1,709,200 TL
Data security measures (Art. 12)256,357 TL17,092,242 TL

The real exposure usually isn’t the late notification itself — it’s the security gap that let the breach happen. Even when the notification process runs perfectly, weak underlying infrastructure pushes the Board’s decision into a far more expensive bracket.

Frequently asked questions

Does the 72-hour clock pause over a weekend? No. It runs in calendar hours; public holidays and weekends don’t extend it.

Should we contain the breach first, or notify first? Contain first. If a system is still actively exposed while you’re filling out the form, closing that gap comes before paperwork — the notification can be prepared in parallel.

Does a small business really have to file this notification? Yes. The obligation isn’t tied to headcount or the VERBİS registration threshold; any data controller facing unlawful access to personal data falls under this process.

Having an incident response plan and a notification template ready before you need them is the most practical way to get through 72 hours without scrambling. If you’d like a second set of eyes on your current process, get in touch.

Share this post
Türkçe oku

Related Posts