Glossary

What is Data Breach Notification?

A data breach notification is the mandatory notice a data controller gives to the competent authority and affected individuals when personal data is unlawfully obtained by others. Article 12(5) of the KVKK requires notification 'as soon as possible', and the Turkish Data Protection Board has set this period at 72 hours. Article 33 of the GDPR likewise provides for notification to the supervisory authority within 72 hours.

Article 12(5) of the KVKK imposes a two-way duty on the data controller when processed personal data is obtained by others through unlawful means: the situation must be notified as soon as possible both to the affected individuals and to the Turkish Data Protection Board. The Board has concretized 'as soon as possible' through its decision practice, adopting a 72-hour period for notification to the Board from the moment the breach is learned, handled through the authority's online breach notification process. Article 33 of the GDPR requires notification to the supervisory authority, where feasible within 72 hours of becoming aware of the breach; notification is not needed if the breach is unlikely to result in a risk to individuals' rights and freedoms, and any delay must be justified. Where the breach carries a high risk, the affected individuals must also be informed.

The 72-hour window is very short for an unprepared team, so the real work happens before a breach. Prepare a written incident response plan defining who detects, who assesses, who decides on notification and who writes the notice. A good notification describes the nature of the breach, the categories of individuals and data affected, the likely consequences and the measures taken or planned. Add a clause to your data processing agreements obliging processors to inform the controller without delay when they discover a breach, and even when your assessment concludes that no notification is required, document the process and the reasoning.

Frequently asked questions

Within how many hours must a data breach be reported?

The text of the KVKK says 'as soon as possible'; the Turkish Data Protection Board has concretized this as 72 hours for notifying the Board from the moment the breach is learned. Article 33 of the GDPR likewise requires notification to the supervisory authority within 72 hours where feasible and expects any delay to be justified. Notifying affected individuals arises separately in both regimes; the way to meet the deadline is an incident response plan prepared in advance.

Does every data breach have to be reported?

The two regimes work differently. The trigger under the KVKK is personal data being obtained by others through unlawful means; once that occurs, the notification duty arises. The GDPR uses a risk-based threshold: if the breach is unlikely to result in a risk to individuals' rights and freedoms, notification to the authority is not required. Under both regimes, the assessment made and the conclusion reached must be documented with reasoning.

This content is for information only and is not legal advice.