KVKK Data Breach Notification: What to Do Within 72 Hours, How to Fill Out the Form

TL;DR: Article 12/5 of Law No. 6698, the Personal Data Protection Law, requires the data controller to notify the Board, in the event of a breach, as soon as possible and within 72 hours at the latest, through the KVKK Data Breach Notification System. The counter starts the moment the breach is "learned of," and there is no weekend exception. Even if the form is incomplete, it must be submitted on time and can be updated later. Late notification significantly increases the risk of an administrative fine.

What is a breach, and which situations must be reported?

KVKK Article 12 obliges the data controller to prevent the "unlawful processing" of personal data and "unauthorized access." Paragraph 5 of the same article regulates the notification obligation in the event that the processed data is obtained by others.

In practice, there are four types of incident that are subject to notification:

  1. Leak (data leak) · The database was published on a forum, the backup file was downloaded from an open S3 bucket, an employee deliberately took it outside.
  2. Loss · An unencrypted laptop was stolen, a USB stick was forgotten, a backup tape went missing.
  3. Unauthorized access · A DB table was pulled via SQL injection, a panel was opened with stolen credentials, a former employee's VPN is still active.
  4. Ransomware encryption · Ransomware encrypted the data · in this incident, even if no evidence of a leak is found, notification is recommended on the assumption of double extortion.

The KVKK Board's established approach is this: "reasonable suspicion" is sufficient, certainty is not expected. That is, an anomaly alarm came from your SIEM, log analysis is ongoing, there is no evidence yet but the indication is strong · the counter has already started.

How does the 72-hour counter start?

The counter starts at the moment the breach is "learned of." This is not the moment the breach occurred. The attacker may have been inside for weeks; the counter runs from the moment you reasonably notice it.

Example scenario: At 09:15 on Monday morning, your SOC team received an unusual outbound data transfer alarm, and the first confirmation came at 11:00. The counter starts at 11:00, and notification must be submitted by 11:00 on Thursday morning.

Critical points:

  • There is no weekend or public holiday exception. If you noticed it at 17:00 on Friday evening, the deadline is 17:00 on Monday evening.
  • Waiting for the digital forensics report is not a valid excuse. The form is opened with incomplete information and then updated.
  • The matter of hours counts. In its sample decisions, the KVKK Board treats notifications exceeding 72 hours as "late" and raises the penalty baseline.

The operation of this counter is directly linked to the chain of custody and the response workflow we examined in detail in our article The Digital Forensics Process 2026 · poor management of the first few hours negatively affects both the notification and the penalty case file.

Step-by-step notification process

  1. Incident detection and confirmation · The SOC or IT team confirms the suspicion, and a timestamped record is opened.
  2. The digital forensics team is called in · The internal team or an external expert, in parallel, begins imaging and collecting volatile evidence.
  3. Scoping runs in parallel · Which system, which table, which date range, which data category was affected · the first draft should be ready within 24 hours.
  4. The KVKK form is filled out · Incomplete fields are passed with the note "not yet known, to be updated," and the Board accepts this approach.
  5. Preparation of the announcement to affected individuals · Pursuant to Article 12/5, in high-risk situations the data subjects are also informed separately.

For a stricter action plan for the first 24 hours specific to ransomware, we detailed isolation, ransom negotiation, and USOM notification in our article Ransomware first 24 hours.

The notification form step by step

The form opened through the KVKK Data Breach Notification System consists of eight main sections. You will find a practical explanation of each section below.

Section 1: Data controller identity details

The trade name, tax number, VERBİS registry number, full address, and contact point are entered. The contact point is either an appointed data protection officer (DPO) or legal counsel. Provide a corporate channel rather than the company owner's direct number · the person the Board will reach back to must be available throughout the 72 hours.

Section 2: The nature of the breach

Leak, loss, unauthorized access, or a combination is checked. The attack vector is summarized in the free-text field: "Access to the customer table via SQL injection in a public-facing web application," "Theft of an employee's laptop, no disk encryption," and the like.

Section 3: Affected data categories

Identity (full name, Turkish ID number, date of birth), contact (email, phone, address), finance (IBAN, card details · if card details are not tokenized, this must be specifically noted), special category data such as health and genetics, biometric data, children's data · each category is a separate checkbox. If there is special category data, the Board's approach is much stricter.

Section 4: Number of affected individuals

If the exact number is not known, enter a range: "An estimated 50,000 to 80,000 records." It can later be updated once the digital forensics report is finalized. Rather than writing "unknown," it is advisable to provide at least an upper-bound estimate.

Section 5: Possible consequences

The pecuniary and non-pecuniary harm risks the data subject may face are listed: being targeted by phishing campaigns, identity theft, fraudulent credit applications, social engineering, reputational damage. This section is decisive in the Board's assessment of your obligation to also announce to the affected individuals.

Section 6: Measures taken and to be taken

Immediate actions: shutting down the affected system, rotating all administrator passwords, making multi-factor authentication mandatory, invalidating leaked sessions, network segmentation. Medium-term actions: a WAF rule, code review, extending the log retention period, employee awareness training.

Section 7: Digital forensics report

If there is an ISO 27037-compliant report, it is uploaded as an attachment to the form. If it is not ready, the note "the report is being prepared, it will be submitted to the Board on X date" is added. Notifications that include a digital forensics report are found more credible; we covered this subject in detail in our The Digital Forensics Process 2026 pillar article.

Section 8: Approval and submission

The authorized signature and approval via KEP (registered electronic mail). The system issues an automatic reference number · this number is critical for subsequent updates.

How is the announcement to affected individuals made?

KVKK Article 12/5 requires direct notification of the data subject in situations carrying "high risk." Method: email, SMS, a letter to the registered address, an in-panel notification in the user portal, and, if necessary, a press statement.

The content of the announcement must cover four basic headings:

  • What happened? The attack type and date range.
  • Which data was affected? Which categories, what number of records.
  • What should the data subject do? Reset the password, monitor account activity, do not click on suspicious emails.
  • Where can they apply? The internal support channel, the KVKK Board application line, and supports such as a free credit monitoring service.

Failure to make this announcement can be evaluated, in high-risk breaches, as a separate violation that aggravates the administrative fine.

Common notification mistakes

In the decision summaries published by the KVKK Board, the frequently recurring mistakes are summarized as follows:

  1. Missing the deadline · The excuse "we were waiting for the digital forensics report" is not accepted.
  2. Defining the scope inadequately · In cases where the number of affected individuals was reported tenfold short, the Board opens a supplementary investigation.
  3. Notification without a digital forensics report and never adding one later · The notification is open but the file is always incomplete.
  4. Neglecting the announcement to the affected individual · Notifying only the Board and not informing the data subjects.
  5. Inconsistent information in subsequent updates · 5,000 people in the first notification, then 50,000 with no explanation · the Board loses trust.

The consequences of negligence

KVKK Article 18 provides for an administrative fine on the order of millions of TL for non-compliance with the data security obligation. The amount is updated each year by the revaluation rate; for the current figure, the penalty notices page at kvkk.gov.tr should be taken as the basis.

Beyond the monetary penalty, there are three additional risks:

  • A compensation lawsuit by the data subject · Pecuniary and non-pecuniary compensation according to general provisions, within the scope of Article 14.
  • Reputational harm · The notification reaching the media, customer loss.
  • Supplier contractual obligations · The "inform within 24 hours in the event of a breach" clause in your B2B customers' contracts · a separate legal process apart from KVKK.

Sample KVKK Board decisions

When the breach notification decisions published in the "Decision Summaries" section of the KVKK website are examined without naming companies, recurring patterns are visible: SQL injection on e-commerce platforms, unauthorized access in the finance sector, special category data leaks in the healthcare sector, and third-party supplier breaches in the telecom sector.

The common message of the decisions is this: data controllers with timely notification, complete scope, and documentation of technical measures stay at the lower band of the penalty · if one of these is missing, the climb toward the upper band begins.

The difference between VERBİS registration and breach notification

The two obligations are frequently confused:

  • VERBİS is an inventory of a preventive nature · the data controller records in advance which data it processes for which purpose, for how long it retains it, and with whom it shares it.
  • Breach notification, on the other hand, is a reactive obligation · it is made within 72 hours after the incident occurs.

The two are different processes but they support each other. An organization with proper VERBİS registration answers the question "what kind of data was on which system" within minutes at the moment of a breach. An organization that neglects VERBİS, on the other hand, loses even while filling out the notification form.

Aspects shared with and differing from GDPR

GDPR Recital 87 and Articles 33-34 adopt the same 72-hour principle as KVKK. The fundamental commonalities: the timeline, the content, and the obligation to announce to the data subject.

Differences:

  • Under GDPR, the supervisory authority is each member state's own DPA · if a Türkiye-based organization processes EU citizen data, it notifies both the KVKK Board and the relevant EU DPA.
  • The maximum GDPR penalty goes up to 4 percent of global annual turnover.
  • KVKK keeps the penalty band in a fixed TL range, but climbs rapidly to the upper band in a special category data breach.

For Turkish companies that process EU citizen data, the dual obligation is real · an English version of the notification text must also be prepared.

Why is the digital forensics report critical?

The digital forensics report is the backbone of the notification. It answers three questions on the basis of evidence:

  • Scope · Which table, what number of records, which field was affected.
  • Time · When did the attack start, when was it detected, when did the exfiltration occur.
  • Vector · Which vulnerability was used to get in, which tool was used, is there lateral movement.

The KVKK Board considers notifications that present a forensic report more credible, and the penalty amount drops markedly. Moreover, in potential compensation lawsuits and in criminal investigation, this report is the fundamental document the court will request · for this reason it must have ISO 27037-compliant chain integrity. You can find the details in our article The Digital Forensics Process 2026.

Frequently Asked Questions (FAQ)

There is suspicion but it is not certain, should I still report?

Reasonable suspicion is sufficient. Waiting for certainty causes you to lose the 72 hours. The form is opened with incomplete information and updated later.

I missed the 72 hours, what happens?

The delay raises the administrative fine baseline. The reason for the delay (for example, the attack going undetected for a long time) must be explained with a supplementary justification letter, and a defense must be prepared within the framework of the principles of misdemeanor law.

Data leaked from a server abroad, does it fall under KVKK?

If the data controller is established in Türkiye or processes the data of persons established in Türkiye, the KVKK obligation continues even if the server is abroad. If there is EU citizen data, GDPR also comes into play.

An employee leaked it deliberately, does it count as a breach?

Yes. It falls under the category of unauthorized access or misuse. The employee's action may constitute a crime, but the data controller's notification and announcement obligation to the data subject continues.

Ransomware only encrypted, there is no leak, should I report?

The KVKK Board assumes that modern ransomware groups also steal the data in almost every case (double extortion). Even if you have no evidence of a leak, notification is the safe approach.

In which situation is announcing to affected individuals mandatory?

In a "high risk" situation. Special category data, financial data, children's data, and a wide-scope leak of identity information are deemed directly high risk.

How much does KVKK compliance consultancy cost?

It varies according to company size, data category, sector, and scope. DSET offers a tailored quote after a preliminary assessment meeting.

Working with DSET

At DSET we deliver three services from a single source: KVKK compliance consultancy (VERBİS registration, policy, training), digital forensics (ISO 27037-compliant imaging, reporting, court process), and 72-hour breach-moment support (filling out the form, announcing to data subjects, correspondence with the Board).

You can find the preventive side in our article The Digital Forensics Process 2026, and the real-time response side in our article Ransomware first 24 hours.

Hacettepe Teknokent Ankara · +90 536 662 38 09 · contact us for KVKK compliance and breach notification consultancy. If your 72-hour counter has started, even the first call recovers lost time.


Sources: KVKK · KVKK Data Breach Notification System · Law No. 6698 (KVKK) · GDPR Recital 87 · VERBİS · USOM.