Follow us :
KVKK & Compliance

If Your Vendor Gets Hacked, Who Pays the KVKK Fine? A 33-Breach Lesson

Two colleagues reviewing data security next to a server rack — Xen Bilişim KVKK & Compliance

On Wednesday, September 2, 2026, Türkiye’s Personal Data Protection Authority (KVKK) published 33 separate data breach notices on its website, all on the same day. Twenty-two of them came from companies with nothing in common on paper: apparel, footwear, cosmetics, sporting goods, food retail. Yet the wording was nearly identical: unauthorized access to a server operated by a data processor acting on the controller’s behalf. Not one notice named the vendor. The outcome was the same for all 22 brands: each paid the price, under its own name, for a single shared weak point.

Same sentence, 22 different companies

Nine of the notices disclosed numbers, adding up to 74,600 affected individuals. The exposed data included full names, phone numbers, emails, and in some cases hashed login credentials. The breach was reportedly detected in late August and early September, with a short gap before disclosure. A week later, on September 9, the authority disclosed six more breaches, this time flagging ransomware and unauthorized server access as the common pattern again. Two waves in two weeks is not a coincidence. Most SMEs today don’t store customer data on their own servers at all; it sits with their e-commerce platform, shipping tracker, or CRM provider.

Controller or processor: who’s actually on the hook?

Turkish data protection law, Law No. 6698, draws a sharp line between the two roles. A data controller decides why and how personal data is processed (in the example above, the apparel brand collecting customer data). A data processor handles that data on the controller’s instructions, on the controller’s behalf: an e-commerce platform, a payment provider, a shipping tracking tool. Article 12(1) of the law puts the burden of supervising the processor’s security measures on the controller, not just its own systems. So when your vendor gets hacked, liability doesn’t automatically shift to them. In most decisions, the fine still lands on the controller: the brand itself.

ObligationController (the brand)Processor (the vendor)
Notify KVKKLegally required (Art. 12/5)Must notify the controller promptly
Technical/organizational measuresResponsible for vetting and monitoring the vendorResponsible for implementing agreed measures
Regulatory fineUsually the one held liableRarely fined directly
Contractual indemnityCan seek recovery from the vendorLiable to indemnify, if the contract says so

That last row matters. Even when KVKK fines the brand, a solid data processing agreement lets it recover some or all of that cost from the vendor. Without one, or with only a vague clause, the fine simply stays where it landed.

Four clauses your contract should have

If you work with a data processor (and virtually every SME today uses at least one cloud service that qualifies), check your agreement for these:

  • Instruction limits: the processor commits in writing to processing data only on your instructions, never for its own purposes.
  • Subprocessor approval: if the vendor outsources part of the work to another party, it needs your prior sign-off.
  • Notification window: for you to meet KVKK’s 72-hour reporting deadline, the vendor needs to notify you much faster, ideally within 24 hours. Without a written deadline, a vendor can stay quiet for days.
  • Audit rights: the right to send an annual security questionnaire or request an ISO 27001 / SOC 2 certificate. Without this clause, a vendor can simply decline an audit.

If these four are missing, they can be added through an amendment; you don’t need to renegotiate the whole contract. With a small vendor, say a one-person dev shop or a regional courier, adding these clauses is usually straightforward. The real resistance tends to come from large SaaS providers with standard, take-it-or-leave-it terms. Even there, a side letter covering audit rights and the notification window is often negotiable.

Reputation doesn’t care whose fault it was

A “your data was exposed” notice reaching 74,600 people doesn’t distinguish between controller and processor for the person reading it. Customers hold accountable whoever they handed their information to; they don’t care where the supply chain broke. That’s the real story behind the September 2 wave: companies of different sizes, in unrelated sectors, all had to deliver the same bad news to their own customers on the same day. A regulatory fine gets paid and closed out. Customer trust doesn’t come back nearly as fast.

Frequently asked questions

What happens if I have no data processing agreement with my vendor at all? In a KVKK review, this is treated as a failure to meet the controller’s supervisory duty under Article 12(1), and it tends to make any resulting fine heavier.

How do I find out which vendor was behind a breach notice? KVKK’s public notices almost never name the processor. The only reliable way is to ask your own vendor directly; if your contract has a notification clause, they should have already told you.

Does a small business really need to audit its vendors? Yes. Neither headcount nor Türkiye’s VERBİS registration threshold removes this obligation. It doesn’t require a large budget: an annual questionnaire and a handful of added contract clauses are a reasonable starting point for most SMEs.

If you’d like to go through your vendor list and flag which ones are missing a proper data processing agreement, get in touch with us.

Share this post
Türkçe oku

Related Posts