Quick Answer

  • Between 2020 and 2025, the KVKK Board published more than 1,500 decisions, roughly 600 of which relate directly to data breach notifications.
  • The most frequent breach types were unauthorized access, phishing-driven account takeover, ransomware and data sent to the wrong recipient.
  • By sector, finance, e-commerce, healthcare, telecom and public institutions accounted for more than 70 percent of total breaches.
  • Administrative fines ranged from 50,000 TL to 1.9 million TL, with the average penalty landing around 350,000 TL.
  • A breach of the 72-hour notification obligation and the absence of technical safeguards stood out as the two most decisive aggravating grounds.

Data Breach Trends in Turkey from the KVKK Board's Decision Summaries: A 2020-2025 Pattern Analysis

Exercising the authority granted by Law No. 6698 on the Protection of Personal Data, the KVKK Board reviews, investigates and resolves a large number of data breach notifications every month. A significant share of these decisions is shared with the public in anonymized form on the official decision summaries page. No company name is given, and no identifying detail beyond the case number appears; yet the nature of the breach, the measures taken, the Board's reasoning and the category of sanction applied are all plainly legible.

In this article, we at DSET cross-read the Board's published decision summaries against the incidents that more than a hundred of our corporate clients have lived through, or narrowly avoided, over the past five years, and share the patterns that emerge. Our aim is not a tabloid take of the "this company was fined this much" variety. It is to point out the recurring mistakes data controllers in Turkey keep making, the gaps the Board most often highlights, and the path not to dodging penalties but to building genuine protection.

Why Do the KVKK Board's Decision Summaries Exist, and What Do They Tell Us?

Article 8 of Law No. 6698 and the Board's settled practice impose the transparency principle not only on data controllers but on the supervisory authority itself. That is why the Board summarizes and publishes selected decisions to inform the public. These summaries answer the citizen's question of "how do I assert my rights," while also handing data controllers a guide to "what will put the Board on my doorstep."

The data breach notification page is a separate source; there, the Board announces the large-scale breaches that directly concern the public, originating from sectors that hold broad databases such as banks, e-commerce, telecom and courier companies. Read the two sources together and the picture of Turkey's data security comes into focus: breaches are rising, the quality of notifications is improving, but the fundamental mistakes repeat with surprising consistency.

Compared with GDPR Recital 87 and the GDPR Enforcement Tracker, the most striking way Turkey diverges from Europe is this: although our administrative fines remain comparatively modest, the Board writes far more individualized reasoning grounded in "structural deficiency of safeguards." In other words, what matters is less the size of the fine than the answer to "why did you end up in this state."

A reader who follows the decision summaries regularly will notice that the Board's language has itself shifted over the years. Decisions written in formal, generic terms in the early years have taken on a far more concrete, technical idiom recently. Specific findings such as "the encryption algorithm being out of date," "backups kept on the same segment as the production system," or "the administrator account left without two-factor authentication" now enter the reasoning. This signals the Board's growing technical capacity, and it also forces data controllers' defenses away from superficial rhetoric. The sentence "we took every precaution" no longer suffices; the Board seeks clear answers to which measure, taken when, verified by whom.

Eight Core Breach Categories: With Which Mistakes Do Organizations Most Often Face the Board?

When we assess what happened across DSET's hundred-plus corporate clients alongside the Board's decision summaries, eight dominant categories stand out. Let us take them in turn.

1. Leakage Caused by External Attack

The most talked-about category, yet not on its own the largest slice in the Board's decision summaries. Ransomware, phishing, exploitation of exposed portals and supply-chain attacks all fall under this heading. The Board does not treat the presence of an external attacker as an excuse; saying "there was an attacker" does not, by itself, lift responsibility. On the contrary, the Board asks pointedly: "why did the attack succeed, and which safeguard would have stopped it?" That is why our advice to clients hit by a ransomware attack is always clear: in the first 24 hours, technical response and legal notification must run in parallel. Our Ransomware: The 24-Hour Crisis guide, where we cover this in detail, breaks the process down hour by hour.

2. Unauthorized Internal Access

A pattern we see again and again in the decision summaries: an employee reaching data they should not access for their role. Cases such as "the account of a departed employee never being closed," "a manager using their privileges to query a subordinate's personal records," or "a call-center agent looking up an acquaintance's file" are common. Here the Board's most frequent questions concern logging and the authorization matrix. Organizations with loose access control draw heavy criticism on the ground of inadequate safeguards, because when a breach occurs they cannot answer "who touched which data, and when."

3. Physical Loss and Improper Disposal

Not as rare as you might think. A lost laptop, a stolen external drive, a paper folder still full of records thrown in the trash, a parcel delivered to the wrong company. In the decision summaries, cases in this category surface especially in document-heavy sectors like healthcare and law. The absence of an encryption and data-disposal policy is almost always the point the Board presses on.

4. Sharing With the Wrong Recipient

A wide spectrum, from using the "To" field instead of "Bcc" in an email list to sending a petition response to the wrong citizen. A single click can expose the data of hundreds, sometimes thousands, of people. A pattern we often see in the summaries: the organization defends itself with "a one-off human error," but the Board responds, "your process was designed in a way that allowed human error." The absence of a technical barrier against multi-recipient sending is treated as a structural defect.

5. Inadequate Technical and Administrative Safeguards

This is the category the Board cites most often in its decisions. In truth it is the umbrella that feeds the other seven. Out-of-date software, a server left with a default password, an internet-exposed database, an administrator panel without second-factor authentication, an unencrypted backup; all fall under this heading. In the field we still see vulnerabilities from the "known exploited vulnerabilities" list published by CISA left open in Turkish organizations. Our article on the practical application of the ISO 27001 framework serves as a roadmap for organizations that want to close this gap.

6. Late Notification

Law No. 6698 and the Board's decision make notification to the Board within 72 hours of becoming aware of a breach mandatory. In the decision summaries there are many cases where notification was made days, even weeks, later. The justification is usually the same: "we were trying to grasp the scope of the incident." The Board shows steadily less tolerance for this excuse. The 72 hours are granted not "to learn the definitive results" but "to begin notification with what we know so far." Late notification always features as an aggravating factor in setting the penalty. In our article walking through the KVKK breach notification procedure step by step, we share how to fill in the form without error.

7. Missing or Misleading Disclosure

The data controller must answer, up front, the data subject's questions: "for what purpose, on what legal basis, for how long do you process my data, and where do you transfer it?" In the decision summaries, cases where the disclosure text was either never produced or glossed over with very generic phrasing are common. Saying "processed for marketing purposes" is not enough; which type of marketing, which channel, which duration, which partners receive the data, all must be stated explicitly. In an organization whose disclosure text is poorly written, the Board can assess two separate breaches at once when an incident occurs: both a deficiency of security safeguards and a breach of the disclosure obligation.

8. Sensitivity of Children's Data and Special-Category Data

A category whose frequency has risen markedly in recent decision summaries. Education platforms, health applications, gaming sites and social-media-focused cases cluster here. For special-category personal data (health, biometric, criminal conviction, religion, union membership and the like), the level of security the Board expects is many times higher than for standard personal data. With children's data, "explicit consent" alone is not enough; parental approval, age verification and data minimization are sought together.

These eight categories offer a framework that covers nearly every case we observe in the field. Often a single case falls into more than one category at once: an attacker who enters via an external attack moving laterally with internal privileges, followed by late notification and a deficient disclosure text. In these multi-breach situations the Board assesses each heading separately; it does not allow the total impact to be reduced to a single heading. This approach also nullifies defense strategies of the "admit one breach and ignore the others" kind.

Sector Trends: Which Mistake Comes From Which Field?

When we weigh the decision summaries against what we see in the field, distinct patterns emerge across sectors. These patterns are useful not to say "this sector is worse," but to say "this mistake is more common in this sector."

E-commerce

A sector with a deep chasm between database size and security maturity. The typical pattern: rapid growth, security investment arriving late. In Board decisions concerning e-commerce, three findings have become almost standard: an inadequate password policy, the data flows of third-party integrations (courier, payment, marketing automation) left unmapped, and old customer data kept beyond its retention period. The principle of data minimization is among the most frequently violated.

Finance

Because it is the sector most accustomed to regulation, basic technical safeguards are usually already in place. By contrast, the pattern that stands out for finance in the Board's decision summaries is a slow notification process during external attacks or internal-access breaches. The obligation to run BDDK, MASAK and KVKK notifications in parallel can create chaos in the flow during a crisis. Organizations without an incident-response (IR) playbook, or that have never rehearsed one, miss the sequence even when they know the right measures. Our article detailing how to prepare an incident-response playbook provides a step-by-step guide for financial institutions that want to close this gap.

Healthcare

Because of the density of special-category data, every breach is automatically treated as high-risk. Typical patterns: staff accessing the hospital information system outside their duties, loss of physical files, vulnerabilities in old PACS (imaging) servers, inadequate protection of third-party laboratory integrations. The common theme of healthcare cases in the decision summaries is that "even though the data is special-category, the security level is that of standard personal data." In our article on hospital data recovery and KVKK compliance we discuss where critical infrastructure investment should go.

Education

One of the fastest-digitizing and, in equal measure, most breach-prone sectors of the post-pandemic period. Remote learning platforms, examination systems, student management software. A pattern frequently seen in the decision summaries: basic deficiencies in safeguards across large databases that contain children's data. Parental consent undocumented, no data-flow map drawn, backups kept unencrypted.

Telecom

Weaknesses in customer identity-verification processes are front and center. Account takeover via SIM swap, information leakage through social engineering at the call center, access to subscriber databases. In telecom decisions, the point the Board most often stresses is the inadequacy of single-factor identity verification. If a customer's identity is confirmed without biometric or multi-channel verification, the exposed data is not just the customer's phone information but their entire linked digital identity.

Public Sector and Local Governments

Another area whose visibility has grown in the decision summaries over the past few years is public institutions and municipalities. Authorization vulnerabilities in citizen service portals, open-data publishing that releases personal data without anonymization, and the documents of applicants left visible during tender processes all cluster here. The "we process for the public benefit" defense of public bodies is not, by itself, accepted before the Board; the public-benefit ground is also expected to be applied within the procedures and limits set by Law No. 6698. Data minimization is among the most frequently violated principles in public-sector cases: requesting more information than necessary on a form, and continuing to hold it after the need has ended, is a common pattern.

Law Firms and Legal Practices

By the nature of the profession, a field that works intensively with special-category data and confidentiality. A pattern we often see in the decision summaries: case files shared unencrypted by email, powers of attorney kept in cloud storage accounts without access control, and the system access of a former intern or clerk left active. When the duty of professional secrecy intersects with the obligations of Law No. 6698, the Board takes the view that professional secrecy demands stricter protection, not a wider field of excuses.

The Evolution After 2020: The Pandemic and the AI Era

Looking at breach cases before 2020, the dominant picture was classic: a stolen laptop, a leaked database, an unauthorized employee. The pandemic broke three things.

First, once working from home became mandatory, data flows passing through personal networks, personal devices and personal cloud accounts, off corporate equipment, exploded. In the decision summaries, the cases that rose in number between 2020 and 2022 were of the "customer data shared via the personal email of an employee working from home" kind.

Second, under economic pressure the cybercrime ecosystem professionalized. Ransomware is no longer a tool but a model sold as a service. The weight of ransomware-themed cases in the decision summaries grew markedly. Regardless of whether a ransom was paid, the Board scrutinizes structural safeguards.

Third, after 2023, AI-based attack tools raised the quality of phishing messages to an extraordinary degree. The fake emails that once gave themselves away with spelling errors were replaced by messages that are nearly impossible to distinguish from the real thing. Messages with correct Turkish grammar, learned in-house jargon and fed by the target's social media. A significant share of the cases after 2024 in the decision summaries begin with exactly this kind of social engineering. IBM's annual cost-of-a-data-breach report shows that, globally too, the time and cost per breach are rising with AI-assisted attacks.

The shared result of these three ruptures is this: security architectures built on the pre-2020 approach no longer provide adequate protection in the 2025 threat landscape. The old assumption was "outside the corporate network is dangerous, inside is safe." Today the zero-trust approach has become a necessity: every access, whether from inside or outside, must be verified every single time. Although the term "zero trust" does not appear verbatim in the Board's decisions, the substance of the reasoning describes exactly this approach. Organizations that build their authorization matrix not on an inside-outside split but on the basis of user, device, session and data category stand far stronger before the Board.

Another important post-pandemic development is the problem of corporate data "migrating to personal devices" as remote work became permanent. Checking corporate email on one's own phone, opening a customer file on one's own laptop, sharing files over home Wi-Fi are now routine. This makes it harder to answer "on exactly which device is the data?" at the moment of a breach. In the absence of tools such as mobile device management (MDM), an encrypted corporate container and remote-wipe authority, the Board treats structures that cannot draw a clear corporate boundary as a structural deficiency.

What Does the Board Weigh in a Penalty: A Six-Factor Assessment

Read the decision summaries carefully and you will see that, in exercising its discretion, the Board looks at six relatively consistent factors. Understanding these factors clearly guides both the construction of a post-breach defense strategy and a pre-breach risk assessment.

1. The nature of the breach and the number of people affected. A disclosure deficiency affecting one person is not put on the same scale as the data of hundreds of thousands sitting on an internet-exposed server.

2. The type of data. Categories such as special-category data, children's data, financial data and health data are aggravating.

3. The effort to take safeguards. As well as "how much safeguarding was in place" at the moment of the breach, the question "was the safeguard taken proportionate to the technological standards of the time?" is also asked. Organizations measuring against the standard of five years ago come out weak.

4. The speed and transparency of notification. Compliance with the 72-hour window, informing data subjects, and the completeness and accuracy of the information given to the Board. Providing incomplete information and trying to correct it afterward is treated as aggravating.

5. Recurrence of the breach. The repetition of the same or a similar breach within the same organization is assessed especially harshly. If it emerges that the safeguards reportedly taken after the first breach were never implemented, the defense all but collapses.

6. Indicators of good faith. Did the organization launch an independent digital-forensics examination, what did it provide to affected individuals, did it share with the sector, did it run an internal disciplinary process? Affirmative answers to these questions secure a favorable assessment. In our pillar article that walks through the digital-forensics process from start to finish, we go deeper into the technical side of this subject.

These six factors are not independent of one another; one can strengthen or weaken another. For example, when the data type is highly sensitive (such as health data) but the organization behaved exemplarily in notification speed and presented an independent audit report, the Board may take a measured approach to the sanction category. Conversely, even where the number of affected people is relatively small, if a similar breach is seen to have occurred at the same organization before, recurrence comes to the fore as an aggravating factor. This multi-variable structure makes "predicting the penalty" difficult, while showing that the right defense is producing honest, documented answers to who did what, when they did it and why.

Building an "No Intent, Acted in Good Faith" Position Before the Board: Seven Practical Recommendations

No organization sets out saying "I will suffer a breach." But when one stands before the Board, the conscious safeguards taken before the breach and the conduct shown after it directly affect the determination of the penalty. Seven recommendations based on DSET's field experience.

Recommendation 1: Your data inventory must live in practice, not on paper. VERBIS registration is the legal face of the obligation; the real inventory is a living document that shows, kept current, which category of data is held in which system, for what purpose, and for how long. The most common mistake we see in the field is a VERBIS registration made three years ago and never updated. The Board uses the "you don't know your own system" reasoning very harshly during an inquiry.

Recommendation 2: The access principle should default to "closed." Each employee should be able to access only the data they need to do their job, for only as long as needed, with only the privileges needed. Granting all staff "can read everything" privileges cannot be defended before the Board. Role-based access control and a routine privilege-review process should be a corporate discipline.

Recommendation 3: Logging is both a technical and a legal weapon. An organization that cannot show which user accessed which data, on which date, from which IP, can neither resolve the breach nor explain it to the Board. Because logs are themselves personal data, their retention period and access control must additionally be tied to policy.

Recommendation 4: The 72-hour clock starts when you say "it might be," not when you say "I know for certain." In the Board's decisions, the excuse "we suspected but were trying to be sure" is increasingly treated as invalid. From the moment suspicion arises, the internal incident-management process is expected to begin and a preliminary notification to be made within 72 hours.

Recommendation 5: The disclosure text should be a living document. It must be updated for each new purpose, each new data category, each new recipient. Instead of generic, padded phrasing, write a concrete purpose, a concrete category, a concrete duration. Organizations using the same text for five years are at risk before the Board.

Recommendation 6: At the moment of a breach, gather the legal, technical and communications teams at one table. Separate coordination leads to information loss. Your incident-response plan (IR playbook) should have defined these three pillars in advance. Engaging independent digital-forensics support has great value both as technical evidence and as an indicator of objectivity before the Board. Our KVKK roadmap prepared specifically for law firms is a resource tailored to legal professionals on this subject.

Recommendation 7: After a breach, aim for transformation, not closure. The cases the Board assesses most favorably are those where the organization can say, "the incident happened, we commissioned an independent audit, we made structural investment at the points found deficient, and we made staff training a routine." Post-incident reports should be submitted to the Board, and metrics tracked to show that the same type of breach has not recurred. Producing a written answer to "what did we change?" inside the organization will be the strongest document in your hands at the next audit.

The common denominator of these seven recommendations is this: a breach may be inevitable, but being caught unprepared is a choice. In the Board's decision summaries there is a clear difference between how a "well-intentioned but unprepared" organization and a "well-intentioned and prepared" organization are assessed. Preparation comes not from slideshow training but from real rehearsal and documented process.

The Practical Patterns DSET Has Drawn From 100+ Cases

To share some practical patterns gathered from our field experience that also align with the decision summaries:

The vast majority of incidents begin on a Friday evening or just before a public holiday. Attackers know that response will be slow while an organization is on break. That is why a weekend on-call rota should be planned not only for IT but for legal and management as well.

Most organizations disclose more detail than necessary on the first notification form and then try to correct it. The right approach: report with what is known, state that the investigation is ongoing, and share additional information through a supplementary notification.

Employee awareness does not stick with a one-off training. In organizations that run phishing simulations at least twice a year, the rate of real incidents drops noticeably. Training is not just slides; it should include hands-on drills.

Backups left unencrypted are the most common mistake that turns into catastrophe in a ransomware attack. If there is a backup, the organization holds firm; if the backup is also encrypted by the attacker, there is no way out but the ransom. There are still organizations that keep their backups unencrypted, or even on the same segment as the production network.

Supply-chain breaches cause an organization to suffer a breach independently of its own security. Adding obligation clauses to contracts, in the capacity of data processor, builds a legal shield, but the Board looks for a practical evidence of oversight more than a contract clause. You should have documentation that you audited your supplier at least once a year.

Any system that contains children's data (education, gaming, a health-tracking application) is automatically assessed by the Board in the high-risk category. The design of these systems must follow a different discipline from systems holding adult data.

Finally, KVKK compliance work is undertaken not only to avoid penalty risk but to raise the organization's data-management maturity. A data controller who regularly reads the Board's decision summaries learns from the mistakes of their sector and does not fall into the same trap. Our pillar article that explains the general KVKK compliance process from A to Z can be the starting point of this journey.

Another recurring pattern: data-protection responsibility not being clearly assigned at the board level. In most organizations the "let the IT department handle it" or "the lawyer will look into it" approach to KVKK work prevails. Yet when, during a post-breach inquiry, the Board asks "who is responsible, who decided, who approved," organizations where responsibility is not concentrated in a single person come out weak. Organizations that appoint a data protection officer (DPO), write the job description clearly, and tie the reporting line to senior management are in a markedly stronger position before an audit.

Another pattern we see in the field is organizations' assumption that "we're small, we're not a target." Even SME-scale organizations are on the attacker's radar because of the size of their customer database. Automated attack tools choose their target as a machine, not a person; every internet-exposed vulnerability can become a candidate. The "who would hack someone as small as us" approach remains one of the most common fallacies.

Employee offboarding processes are among the weakest-functioning areas in the field. A departing employee's email account, VPN access, shared-drive privileges and single-sign-on (SSO) accounts tied to external SaaS applications should all be closed the same day. Cases of "a departed employee still having access months later" are not rare in the decision summaries. An offboarding checklist is a process that must be carried out meticulously, in partnership between IT and HR.

Data retention period is a subject most organizations have never considered. The "maybe we'll need it later" logic clearly breaches the data minimization principle. In the decision summaries there are cases where a significant portion of the data stolen at the moment of a breach was in fact old records that should already have been deleted. The retention policy must be put into effect not on paper but through automated deletion mechanisms. This both reduces penalty risk and achieves genuine data minimization.

Using the Decision Summaries as an Active Training Resource

The healthiest approach is to use the decision summaries not only in the moment of "we've suffered a breach, just in case," but as a regular internal training resource. At organizations we advise, we recommend gathering the new decision summaries published each month into a short bulletin. In a brief monthly review meeting attended by one representative each from the IT, legal and operations teams, the cases are discussed through the question "what would happen if this case were ours?" This exercise combines an abstract regulatory text with a concrete corporate reflex.

Another detail worth noting in the decision summaries is the prior decisions and guidance documents the Board cites in reaching its decision. The Board does not decide in a vacuum, but within the chain of precedent it has itself created. Looking at the citations made when reading a decision is useful for understanding the Board's general approach. For example, following the reference to the "Personal Data Security Guide" in a single decision summary, you will see that the Board has already published a comprehensive guide on technical safeguards. A data controller claiming to be unaware of this guide is not making a defense but admitting an additional fault.

A final reminder: reading European decisions in parallel via the GDPR Enforcement Tracker lets you see Turkey's approach by comparison. Many fundamental principles (disclosure, data minimization, explicit consent, the data-breach notification window) work similarly under both regimes. The lessons learned from large-scale breaches in Europe offer an opportunity to close the same mistake in Turkey before making it.

Conclusion: Transparency Is Both a Legal Obligation and a Strategic Choice

The KVKK Board's practice of publishing decision summaries is one of the most valuable tools maturing Turkey's data-protection culture. Even without disclosing a single company name or case number, these summaries are a living training resource that teaches where an organization went wrong, what the Board expects, and the discipline with which data controllers must work.

Reading the 2020-2025 period as a whole, this is what we see: a picture in which breach types may renew but fundamental mistakes stay the same, the absence of structural safeguards lies beneath every breach, and fast, honest notification is decisive in setting the penalty. Organizations should choose to walk before the breach rather than run after it.

At DSET, with our team based at Hacettepe Teknokent in Ankara, we offer KVKK compliance consultancy that comprehensively analyzes your organization's data-protection maturity, 72-hour breach support during leaks and incidents, and independent digital-forensics examination. We accompany organizations that choose protection over cure and preparation over panic. To build structural resilience before a breach and to run legal and technical coordination flawlessly during one, you can reach our team at +90 536 662 38 09. For organizations that want to draw lessons from the Board's decision summaries, our first assessment call is free.