Data Loss at a Law Office: Client Files, Attorney-Client Privilege, and the KVKK

Data lost at a law office is not an ordinary office loss. Client files, case notes, audio and video recordings, UYAP screenshots, the KEP archive, e-signed petition drafts, transcripts of consultation meetings, and expert reports are, all at once, both a commercial asset and a "secret" under Article 36 of the Attorneys Act. The same data is also, in most cases, special categories of personal data under the Personal Data Protection Law (KVKK), because it contains health reports, criminal records, family secrets, financial account records, or information about a child. That is why the death of a hard disk or a RAID array simultaneously triggers, for a lawyer, the risk of professional liability, disciplinary liability, and an administrative fine, all at the same time.

This article was prepared to summarize, by tying it to the legal framework, the picture seen in the field by the DSET Data Recovery team, which operates on the Hacettepe Teknokent campus in Ankara and works largely with offices around the Ankara Courthouse. For the technical foundation of the general data recovery process, see our main data recovery guide, and for evidence integrity in forensic processes, see our digital forensics pillar article.

Attorney-Client Privilege: Why a Lost File Is Not an Ordinary File

Article 36 of the Attorneys Act prohibits a lawyer from disclosing information learned in the course of the profession; the same article leaves to the lawyer's discretion whether to share that secret even when permission is given. The Union of Turkish Bar Associations' Professional Rules also list the protection of client secrets among a lawyer's fundamental obligations. The legislative text can be verified via the Official Gazette in the Attorneys Act PDF, and the TBB Professional Rules via barobirlik.org.tr.

In practice, this means: a lawyer is obliged not only to keep the secret, but also to keep secure the medium in which the secret is stored. A failed disk, a stolen laptop, a NAS locked by ransomware, or a RAID enclosure melted in a fire: if it contains client correspondence, it is the loss of the physical carrier of what we call the "secret." Handing this over to an unauthorized repair shop or a random computer technician directly harms the interest protected by Article 36. Even during the data recovery process, file contents must not be viewed, logs must be kept, and the chain must be documented.

What Data Is Kept at a Typical Law Firm

The inventory of a classic law firm that we encounter in the field is roughly as follows:

  • Petition, decision, and writ PDFs downloaded via UYAP
  • E-signed petition drafts and signature timestamps
  • The KEP (registered electronic mail) correspondence archive
  • Audio and video recordings of meetings held with clients
  • WhatsApp, Telegram, and SMS message backups (including those carrying evidentiary value)
  • Expert reports, appraisal files, title deeds, registry records, and bank statements
  • Scanned ID cards, powers of attorney, and contract images
  • The accounting and self-employment receipt software database
  • Password manager, certificates, and e-signature backup keys

A significant part of this inventory is considered special category data under KVKK Article 6. For example, a health report submitted in a labor lawsuit, the criminal record in a criminal case file, and a child's statement in a divorce case are all "special categories of personal data." For typical evidentiary disputes encountered in family law, see our digital evidence in divorce cases article, and for the legal debate over messaging records, see our WhatsApp messages as evidence article.

The Lawyer's Responsibility Under the KVKK

Under the KVKK, the lawyer is the "data controller" for the client's personal data; all legislation and guidance should be referenced from kvkk.gov.tr. This means not only keeping the secret, but being able to prove that the data is kept in a secure environment. When a data breach occurs, there is an obligation to notify the Board within 72 hours. A disk burning, being stolen, being held for ransom, or being subject to unauthorized access all fall within this scope.

At this point, the documents a lawyer should have on hand are: a data inventory, a retention and destruction policy, a backup procedure, access logs, training records, and the KVKK disclosure text in contracts. All of these are the written basis for being able to say, in the event of a disk failure, "I had done everything in my power." For a general corporate compliance perspective, our KVKK compliance article offers a detailed starting point.

The Most Common Data Loss Scenarios

1. Collapse of the RAID 5 Array on the Server

Law firms with multiple partners mostly keep their files on 4- or 5-disk RAID 5 arrays. When one disk fails, the warning is often ignored and the system "appears to be working." After weeks pass, the second disk also fails and the array goes down completely. In this case, because file-system pieces are distributed across different disks, reassembling them in the wrong order or miscalculating parity permanently corrupts the entire archive. For a technical comparison of RAID levels and why RAID alone is not considered a backup, see our RAID 5 data recovery article.

2. Sudden Death of an SSD

The SSDs in lawyers' personal laptops, unlike mechanical disks, often die all at once without warning. They boot one day, and the next day the BIOS does not even see the disk. If they hold the past week's petition drafts, meeting notes, and audio recordings, and regular backups have not been taken, what is lost is not just "a computer," but the only record of a meeting held with a client.

3. Ransomware

Ransomware spread through an e-mail attachment opened from outside or an unpatched remote desktop service has been among the threats frequently hitting law firms over the past three years. Opening encrypted files is impossible in most cases; a significant portion of firms that pay the ransom either receive the wrong key or get no response at all. That is why the only real protection against ransomware is taking an immutable backup.

4. Theft or Fire

Offices around the Ankara Courthouse are places where theft cases occur frequently, due to the heavy flow of people in and out. Fire is rarer but more destructive. In either case, trusting the security of the physical space is not enough; the data must also exist at a different geographic location.

5. Infection via Cafe or Hotel Wi-Fi

File transfers made over connections obtained through hotel Wi-Fi or cafe networks during hearing trips are a common source of data leakage, due to both encryption vulnerabilities and misconfigured shared folders. This is not "data loss" in the classic sense, but it falls into the "unauthorized acquisition" of data category and requires a KVKK breach notification.

Backup Strategy: 3-2-1 and Beyond

The reasonable minimum backup strategy for a law firm is the 3-2-1 rule:

  • 3 copies of data (1 primary, 2 backups)
  • 2 different media (for example, server disk plus external disk or cloud)
  • 1 copy at a different physical location

Given the ransomware threat, an immutable layer is also needed on top of this. That is, once a backup is taken, it cannot be deleted or modified for a certain period. A practical setup is this: a NAS in the office, a rotating external disk set off-site, and an encrypted cloud account. Daily backups for critical petitions and hearing recordings, and weekly backups for the client archive, are a reasonable frequency.

Backups must be encrypted. The encryption key, in turn, must be kept somewhere independent of the backups, ideally in a physical safe. Putting the key next to the backup is no different from leaving the apartment key under the doormat.

The Particularities of the E-Signature, KEP, and UYAP Archive

An e-signed document loses its function not only when the file is lost, but also when the e-signature certificate expires. When renewing certificates of e-signature services accessible via e-Government (turkiye.gov.tr) whose validity has expired, the timestamps that were recorded must be kept verifiable with the old keys. That is why an e-signature archive must hold not only the signed document, but also a backup of the relevant certificate and timestamp.

As for the KEP archive, the archiving periods offered by service providers are limited. When the period expires, correspondence may be permanently deleted. Keeping a local archive of warnings, notifications, and replies sent via KEP becomes the single point of reference in a future dispute.

A local backup of files downloaded via UYAP is critical for both speed and an independent evidentiary basis. When the system goes into maintenance, when an account is temporarily locked, or when connection problems occur, not having a local archive turns into lost work.

Evidence Integrity: ISO/IEC 27037 and the Connection to the HMK

If the content of a recovered disk is to be submitted to a court as evidence later, it must have been acquired through a chain compliant with the ISO/IEC 27037 standard. This international standard sets the rules for the identification, collection, preservation, and transfer of digital evidence and can be referenced via iso.org/standard/44381.html. Under Turkish law, within the framework of the Code of Civil Procedure (HMK PDF) and the Code of Criminal Procedure (CMK PDF), proving the integrity and the method of acquisition is essential for evidence to be admitted into proceedings.

In the recovery work carried out at DSET's office, an image is taken for each case, a hash (SHA-256) is calculated, the recovery work is done not on the original image but on its copy, and the process is reported along with date, time, operator, and stage information. Preparing this report in a format that can be submitted to a court or an expert witness is a concrete defense against the later question of "could this data have passed into someone else's hands."

What to Do in the First 24 Hours After Data Loss

When a disk at a law office starts to "click," a folder "will not open," or the system gives a RAID error message, our first recommendations are these:

  1. Shut down the device immediately. Repeatedly restarting the disk increases physical damage.
  2. Do not attempt any repairs. Stay away from internet suggestions such as opening, drying, or freezing the disk.
  3. Do not run "amateur recovery software" on a disk that contains client files. A write operation can overwrite the recoverable area.
  4. If the disk loss is the result of theft or ransomware, do not intervene at the scene; the traces must be preserved.
  5. If there is a suspected KVKK breach, keep the 72-hour window in mind and start the legal consultation process.
  6. If there is a backup of the data, check the state of the backup as well. It has often been seen that the backup disk had failed on the same date.

The Opinion Obtained at the End of the Process

The DSET team, when needed, prepares a technical opinion regarding the digital evidence and data recovery process. This opinion explains which device was examined with which method, the hash values, the tools and versions used, the categories of data recovered and not recovered, and the process's compliance with ISO/IEC 27037. The opinion can be used as an addendum to the case file or as the technical basis for an expert witness report.

The opinion process is especially useful in labor, family, and criminal law files for preemptively closing off the opposing party's objections that "this data may have been altered afterward." The lawyer can submit to the court an audio recording of a meeting with a client, or a digital title deed image of a property, with the integrity chain documented.

Field Example: Typical Workflow After a RAID Collapse

It is helpful to describe, in general terms for the sake of confidentiality, a typical scenario that occurred at a medium-sized law firm we worked with in Ankara. On a file server kept in a four-disk RAID 5 array, the warning that the first disk had failed was ignored on the system for weeks, and when the second disk failed, the array went down completely. The firm had a backup; however, because the backup was also made to a different partition of the same server, the backup became inaccessible along with the collapse.

When the device reached the DSET laboratory, the first task was to take a sector-by-sector image of each disk separately and to record the hash values. One of the disks was mechanically damaged and required a head swap in the cleanroom environment in our facility. After the images were taken, the original array was logically reconstructed using a parity calculation, and the consistency of the file system was ensured. At the end of the process, the vast majority of the client files were recovered without breaking the case folder structure; the list of the missing portion was also reported. So that the lawyer could also make a KVKK breach assessment, it was documented, with log and hash records, that the file contents were not viewed during the recovery process, and that work was done only at the file-system level.

These types of cases teach two things: first, if the backup sits on another partition in the same enclosure, it is not a backup; second, RAID warning messages must not be postponed, and a response plan must be put into action the very day the first warning arrives.

Preventive Steps: A Checklist for a Disciplined Law Firm

The checklist below can be used before an audit or during an annual internal review:

  • Has a data inventory been drawn up, and what type of data is on which server?
  • Has a retention and destruction policy been put in writing?
  • Is the 3-2-1 backup rule being applied, and is there an immutable layer?
  • Are backups periodically put through a restore test?
  • Is the e-signature certificate renewal schedule on record?
  • Is the KEP archive also backed up locally?
  • Is a password manager used, and is the master password also kept physically?
  • Are the KVKK disclosure texts up to date?
  • Has annual data security training been provided for staff?
  • Is the list of data recovery and legal support to call in an incident ready?

Reviewing this checklist twice a year is enough both to maintain professional discipline and to be able to answer clearly, in a data incident, the question of "was due diligence exercised."

Contact Us

On the Hacettepe Teknokent campus in Ankara, a short distance from the Ankara Courthouse, we provide data recovery and digital forensics services tailored to law firms. The work is carried out under a confidentiality agreement, every stage of the process is reported, and if needed, a technical opinion is prepared for the expert witness process.

WhatsApp and phone: +90 536 662 38 09

Delivering your disk or server without opening it yourself, without formatting it, and without straining the data, significantly increases the chances of recovery. For our colleagues obliged to protect client secrets, it is best to fulfill that obligation through a procedure they have determined themselves, not standing over a collapsed disk.