KVKK 72-Hour Data Breach Notification Template: Step-by-Step Form and Timeline
The 72-hour notification obligation under the KVKK Decision No. 2019/10 dated 18/01/2019 and the Data Breach Notification Communiqué. T0 to T+72 timeline, every field of the form, 3 example scenarios, and references to real administrative fines imposed by the Board.
The Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) concretized the phrase "as soon as possible" found in the fifth paragraph of Article 12 of Law No. 6698 as 72 hours, through the text of Decision No. 2019/10 dated 18/01/2019. The text of the decision has been published on the Authority's official website at kvkk.gov.tr/Icerik/5469. This time window begins to run from the moment the data controller becomes aware of the breach. The starting point of the period is a contentious matter. In the Board's decisions, the "moment of awareness" is interpreted not as the moment the IT team completes technical verification, but as the moment the first suspicion becomes meaningful on reasonable grounds.
With the amendments published in the Resmi Gazete (Official Gazette) No. 31405 dated 24/02/2021, the notification format is received digitally through the "Data Breach Notification Form" portal on kvkk.gov.tr. The form does not require wet-signed documents; however, confirmation by the person authorized to represent the data controller is expected via e-signature or KEP (registered electronic mail). The 25 MB size limit for scan-based attachments retained in the front section of the form is specified in KVKK's official announcement.
This guide breaks the period from the moment T0 when the breach is detected to T+72 hours into hour-by-hour actions. The goal is not "to make it in time" but to complete a technical and legal file of a quality that can be made in time.
Section 1. Legal Framework and Definitions
1.1. What is a data breach
Article 12/5 of Law No. 6698 (KVKK) ties the notification obligation to the case of "processed personal data being obtained by others through unlawful means." In parallel with the definition in Article 4(12) of the European General Data Protection Regulation (GDPR), the Board addresses the breach in three fundamental dimensions.
| Dimension | What is compromised | Typical example |
|---|---|---|
| Confidentiality breach | Secrecy of the data | Database leak, unauthorized access, lost laptop |
| Integrity breach | Accuracy of the data | Unauthorized modification, record manipulation, ransomware encryption |
| Availability breach | Access to the data | DDoS, record deletion, being left without backup, ransomware lockout |
A single incident may cover more than one dimension at the same time. In ransomware incidents, confidentiality, integrity, and availability are classically endangered all at once.
1.2. Who is obligated to notify
The notification obligation rests on the "data controller." The data processor's responsibility is limited to notifying the data controller of the breach without delay. Actors such as cloud service providers, external IT support firms, and call centers act in the capacity of data processor. Even if the contract states otherwise, the legal notification obligation cannot be transferred. This point was explicitly emphasized in the Board's Decision No. 2019/271.
1.3. Which incidents are notified, and which are not
The Board does not interpret "low-risk" exceptions broadly. Even a loss that is encrypted and whose key has not been compromised must be notified if there is reasonable suspicion regarding the security of the key. The general rule is whether or not the breach has the potential to pose a risk to the rights and freedoms of natural persons.
Section 2. T0 to T+72 Hour Timeline
The table below lists the hour-by-hour actions a typical data controller should follow from the moment a breach is detected to the delivery of the notification. The durations are maximum recommended values; faster closure is expected.
| Hour | Task | Responsible role | Output |
|---|---|---|---|
| T0 | Detection, verification of the first suspicion | SOC, IT, user | Opening of the incident ticket |
| T+1 | Activation of the incident command chain | CISO, IT Manager | Written call record |
| T+2 | Draft of affected systems and data categories | IT, Legal | Preliminary scope note |
| T+4 | Temporary isolation decisions | IT, business units | Network segmentation record |
| T+6 | Forensic copy acquisition, RAM dump | Internal team or external expert | Image hash records |
| T+8 | Definitive determination of data categories | Data inventory owner | Estimate of the number of affected persons |
| T+12 | Legal department draft of the notification text | Legal Counsel | First completed version of the form fields |
| T+18 | Senior management briefing | CEO, Board of Directors | Signature authority approval |
| T+24 | Completion of the breach classification matrix | CISO | Dimension x risk score |
| T+36 | Finalization of person count, data category, impact | IT, data inventory owner | Form attachments |
| T+48 | Completion of the internal technical report | Digital forensics team | Findings file |
| T+60 | Final revision of the form | Legal + CISO | Approved draft |
| T+66 | Delivery of the e-signed notification via KEP | Authorized signatory | Receipt confirmation document |
| T+72 | Archiving of the notification confirmation | Data controller | Archive file |
This timeline is a defense tool as much as it is a target. During a Board examination, the answer given to the question "what was done each hour" directly affects the severity of the administrative fine.
Section 3. Notification Form Fields
The form on the Board's veriihlalbildirim.kvkk.gov.tr portal consists of the following main sections. The form can be saved while being filled in field by field, and the session can be left half-finished and completed later.
3.1. Data controller information
VERBIS registry number, trade name, KEP address, contact person's name and phone number. If there is no KEP address, problems arise at the notification stage even if the form is submitted.
3.2. Breach category
A multiple-choice field. Combinations of confidentiality, integrity, and availability are checked. More than one dimension can be selected.
3.3. Source of the breach
Sub-headings such as externally sourced attack, malicious insider access, negligence, third-party provider, physical loss, and hardware failure.
3.4. Affected data categories
Headings such as identity, contact, location, finance, health, biometric, criminal conviction, customer transaction, and employee personnel records. When the special category data heading is selected, the Board examination is automatically placed in a higher importance tier.
3.5. Number of affected persons
If the exact number is unknown, a band range is accepted. However, if a band range is provided, a definitive number update is expected within 7 days.
3.6. Incident summary
Free text of 500 to 1,500 characters. An understandable account of the nature of the breach is preferred, not technical detail.
3.7. Measures taken
Technical and administrative measures relating to the moment of the incident and afterward. Leaving it blank may be evaluated by the Board as an incomplete notification.
3.8. Notification to the data subjects
Whether the data controller has made a separate notification to the data subjects, and if it intends to, the method and the estimated date.
3.9. Attachments
Technical reports, screenshots, log summaries, legal opinions, and excerpts of third-party contracts. A single attachment is expected not to exceed 25 MB.
Section 4. Three Example Scenarios
Scenario A. Encryption of a file server by ransomware
At a mid-sized manufacturing firm, it is noticed at 22:40 on Thursday evening that the file server has become inaccessible. At 08:15 in the morning, the IT team detects the encrypted file extensions and the ransom note. T0 here can be accepted not as 22:40, but as 08:15, when reasonable suspicion was confirmed. However, during the Board examination, the argument that the night shift could also have noticed may come up, so preserving the night log records is important.
In this scenario, the breach covers all three dimensions. If the encrypted files include employee personnel files and customer contracts, the categories include identity, contact, and employee personnel records. If the number of affected persons is not exact, a band range such as "between 1,000 and 5,000" is accepted. In the "measures taken" section of the form, items such as isolation from the network, restoration from backup, resetting of credentials, deployment of EDR, and making multi-factor authentication mandatory are listed.
Scenario B. Stolen laptop
A car belonging to an employee from the field sales team was broken into in İstanbul on Sunday night, and the laptop was stolen from the bag. The device held approximately 800 customer record tables. The device was full-disk encrypted with BitLocker, and the startup PIN was 6 digits.
In this incident, the confidentiality dimension is the priority, but due to the encryption, a "low risk" argument can be presented to the Board. In the form field, honest answers must be given to questions about the weakness of the PIN policy and whether or not brute-force protection exists. In its Decision No. 2020/13, the Board explicitly stated that the loss of a device, even if encrypted, is an incident that must be notified.
Among the practical actions are a theft report to the police, a remote wipe command (via MDM), revocation of the VPN certificate, and invalidation of stored session tokens for access to the customer portal.
Scenario C. Email sending error
In a campaign email sent by the marketing team to 6,300 customers, the "CC" option was used instead of "BCC," and the email addresses of all recipients were exposed to one another. The first customer complaint came 22 minutes later.
This incident, which seems minor, is in fact a classic confidentiality breach. The number of affected persons is exact: 6,300. The data category is contact data; it is not special category. However, if the customer profile can be inferred from the announcement content (for example, a health service subscription), then the special category data breach dimension also comes into play.
The measures taken should include a rule in the email system that "the CC field cannot exceed 50 recipients" for bulk sending, a double approval requirement, and awareness training for the marketing team. In such breaches, the Board considers the absence of systemic control an aggravating factor.
Section 5. Examples of KVKK Board Administrative Fines
The decisions below can be verified from the Board's official decision summaries page. These summaries are not interpretation; they are based on disclosed decision summaries.
| Decision date · number | Incident | Sanction |
|---|---|---|
| 16/05/2019 · 2019/144 | Facebook's overseas data breach, affecting Turkish data subjects | 1,150,000 TL administrative fine |
| 27/02/2020 · 2020/173 | Marriott Hotel international data breach, Turkish guest information | 1,450,000 TL administrative fine |
| 17/09/2020 · 2020/717 | A bank's failure to protect the personal data of a former employee | 250,000 TL administrative fine |
| 22/12/2020 · 2020/966 | An e-commerce platform's late notification of a data breach | 1,100,000 TL administrative fine |
| 11/08/2022 · 2022/793 | A courier company's customer data being accessible over the web | 950,000 TL administrative fine |
These decisions show that the Board evaluates both the breach itself and the management of the notification process separately. Late notification, incomplete notification, and a baseless "low risk" claim are processed as aggravating factors.
Section 6. Post-Notification Board Examination Process
After the notification is received, the Board typically completes the preliminary examination within 30 to 90 days. The process consists of the following steps.
- Evaluation of whether the notification form is technically incomplete
- Request for additional information from the data controller (in writing, usually with a 15-day response period)
- Decision on whether the breach will be made the subject of a public announcement by the Board
- On-site examination or remote technical examination
- Taking of the data controller's defense
- Placement on the administrative sanction agenda
- Notification of the decision and, if necessary, a public statement
In some cases, the Board looks at the data controller's post-notification communication discipline rather than at the incident itself. Compliance with deadlines, complete delivery of the requested documents, and the consistency of the defense are decisive in keeping the administrative fine at the lower limit.
Section 7. 10-Hour Action Checklist
The table below summarizes the steps a typical data controller should take in the first 10 hours after a breach. This is a working list that condenses the first segment of the 72-hour timeline in Section 2.
| Hour | Action | Owner | Output |
|---|---|---|---|
| 0-1 | Opening the incident ticket, initial documentation | Detector | Incident number |
| 1-2 | Command chain meeting, role assignment | CISO | Meeting minutes |
| 2-3 | Involvement of the legal department in the process | Legal Counsel | Legal note |
| 3-4 | Temporary isolation decisions, network segmentation | IT Operations | Change record |
| 4-5 | Forensic copy preparation, RAM dump | Internal team or DSET | Image hash |
| 5-6 | Draft determination of the affected data category | Data inventory owner | Preliminary inventory |
| 6-7 | Senior management briefing | CEO office | Briefing note |
| 7-8 | Starting the form draft, KEP confirmation | Legal + CISO | Form ID |
| 8-9 | Informing the third-party provider | Procurement | Correspondence record |
| 9-10 | Communication plan draft, customer message template | Marketing + Legal | Template awaiting approval |
This list is a time-saving reference for organizations that say "we have no time to think about what to do."
Section 7.5. Obligation to Notify the Data Subjects
In addition to notifying the Authority of the breach, the data controller is obligated to notify the data subjects affected by the breach via an "appropriate method." In its Decision dated 24/01/2019, the Board did not impose a concrete format for this method, but required that the communication be reasonable, understandable, and direct.
7.5.1. Direct communication channels
The preferred communication is a channel established one-to-one with the data subject. Email, SMS, in-portal membership messages, physical mail, or a phone call fall within this scope. A social media announcement, a website banner notice, or a newspaper advertisement on its own is not considered sufficient. These channels can only be used as a complementary method in situations where reaching the data subjects directly would create a disproportionate cost.
7.5.2. What the message content must include
The message to be sent to the data subject must include the following information.
- The date and duration of the breach
- The nature of the breach (confidentiality, integrity, availability)
- The affected personal data categories
- Possible consequences and risks (in particular identity theft, fraud)
- The technical and administrative measures taken and planned
- The point of contact the data subject can apply to
- The date and summary of the notification made to the Authority
The message must be written in plain language, free of indirect expressions caught up in legal reservations. When the Board determines in some cases that the communication message is "dismissive of the incident," it evaluates this as an aggravating factor.
7.5.3. Timeline
Notification to the data subjects is measured by the phrase "reasonable period." In the Board's decisions, this period has been concretized as between 7 and 15 days. Having notified the Authority within 72 hours does not require that the data subjects be notified within the same period. However, as the delay grows, the data controller's burden of justification becomes heavier.
Section 7.6. Cross-Border Data Transfer and Foreign Authorities
If the data breach affects data subjects residing in more than one country, or if the data controller also operates abroad, a notification obligation to foreign authorities may arise in addition to the KVKK notification. The most frequently encountered parallel obligations are as follows.
- The supervisory authorities of EU member states under the GDPR (for example, Germany's BfDI, France's CNIL)
- The United Kingdom ICO (Information Commissioner's Office)
- US state authorities, in particular the California CPPA and the New York Attorney General's Office
Managing cross-border coordination requires appointing a single legal lead. Conveying messages of different content to different jurisdictions may later become the subject of an inconsistency claim during a Board examination.
Section 8. Typical Mistakes
When the decisions published by the Board are examined, the same mistakes appear before us again and again.
- Exceeding the 72 hours by saying "let us handle it internally, let us not be hasty"
- Filling the "measures taken" field of the form with empty sentences such as "the investigation is ongoing"
- Showing the number of affected persons below the truth and then being forced to revise it
- Not making a notification by treating the existence of encryption as a "we took measures" justification
- Trying to delegate responsibility to the data processor by saying "you notify"
- Not notifying the data subjects or turning the notification into a social media statement
- Responding late to the Board's request for additional information after the notification
- Presenting measures as verbal commitments and failing to document them
- The absence of the KVKK supplementary protocol in third-party service provider contracts
- Deliberately presenting the incident as an "IT failure" and thereby delaying the legal process
Section 9. DSET Incident Response Retainer
DSET, with over 20 years of cyber incident response and digital forensics experience, supports data controllers in managing the KVKK 72-hour process with zero loss. Our team, located on the Hacettepe University Teknokent Beytepe campus, works with a chain of custody compliant with the ISO 27037 standard.
Our retainer service covers four fundamental pillars.
- Pre-incident preparation. Policy review, command chain drills, KEP infrastructure preparation, and pre-prepared versions of the KVKK form draft.
- 24/7 access during an incident. Field team guidance via the +90 536 662 38 09 line, remote evidence securing, isolation strategy consulting.
- Notification file preparation. Filling the form fields with technical and legal compliance, preparing attachments, and coordinating delivery via KEP.
- Post-incident defense. Responding to the Board's requests for additional information, accompaniment during the on-site examination process, and preparation of the defense text.
For meeting requests, you can write to [email protected] or call the +90 536 662 38 09 line directly. The initial scope consultation is free and is conducted under a confidentiality agreement.
Closing Note
The KVKK 72-hour notification process is not a matter of speed but a matter of preparation. If you do not want to race against the minutes at the moment of an incident, you must have your timelines, your forms, your command chains, and your external support contracts in place before the incident. This guide is a starting point; we recommend getting in touch with the DSET team for adaptation specific to your organization.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.