After the 2026 revaluation, administrative fines issued by the KVKK Board range from roughly 50,000 TL to 9.5 million TL. The lower and upper limits of a fine are determined by factors such as the nature of the breach, the number of affected individuals, the level of technical safeguards in place, and the data controller's turnover. Notifying the Board within 72 hours is mandatory.

TL;DR

  • Administrative fine band under Article 18 of the KVKK after the 2026 revaluation rate has been applied: roughly 50,000 TL to 9,500,000 TL.
  • Violation of the data security obligation is the most frequently penalized heading.
  • Data breach notification deadline: 72 hours (KVKK decision 2019/271).
  • International precedent decisions: Facebook 2019/144 (1.6 million TL), Marriott 2020/173 (1.45 million TL).
  • The 5 main factors that determine the fine: number of affected individuals, data category, safeguards taken, degree of fault, turnover.

Detailed answer

2026 penalty band (after the revaluation rate)

The penalty amounts under Article 18 of the KVKK are increased every year by the revaluation rate pursuant to repeated Article 298 of the Tax Procedure Law (Vergi Usul Kanunu). For the 2026 application, the bands are as follows.

Type of violation KVKK article 2026 penalty band (approx. TL)
Breach of the disclosure obligation 10 50,000 - 1,000,000
Breach of the data security obligation 12 150,000 - 9,500,000
Failure to comply with Board decisions 15 250,000 - 9,500,000
Breach of the obligation to register with VERBIS 16 200,000 - 9,500,000

The exact amounts are set by the annual revaluation rate published in the Resmi Gazete (Official Gazette), and the current table is available on the KVKK Board page.

The 5 main factors that determine the fine

  1. Number of affected data subjects. There is a large difference in penalty scale between a breach affecting a few hundred people and one affecting millions.
  2. Data category. A breach of special categories of personal data (health, biometric, criminal conviction) is penalized 3 to 5 times more heavily than ordinary personal data.
  3. Technical and administrative safeguards taken. An ISO 27001 certificate, penetration test reports, a KVKK compliance project, and training records provide a reduction in the penalty.
  4. Degree of fault and intent. Active bad faith (selling data) is assessed separately from negligence (an unpatched server).
  5. The data controller's economic situation. For companies with large turnover, a penalty close to the upper band is imposed for deterrence.

Important Board decision examples

Decision 2019/144 (Facebook). After unauthorized access to the photos of 300,000 users through a Photo API vulnerability, the Board imposed on Facebook Ireland Ltd a fine of 1,150,000 TL for the data security breach plus 450,000 TL for the breach of the notification obligation, a total administrative fine of 1,600,000 TL.

Decision 2020/173 (Marriott International). For a reservation database leak that included passport information of 5.25 million guests, 1,100,000 TL for data security plus 350,000 TL for the notification obligation, a total of 1,450,000 TL.

Decision 2021/241 (Aktif Bank). 300,000 TL following a call center employee's unauthorized access to customer information and external sharing of it.

Decision 2021/1187 (Vodafone Net Iletisim). 750,000 TL in a case where subscriber information was obtained through a SIM swap attack.

Decision 2020/650 (Clubhouse). A warning and an administrative process were initiated against a foreign application serving in Turkey for the lack of VERBIS registration and a local representative.

(All decision texts are published in the Board Decision Summaries section of kvkk.gov.tr; every data controller should confirm the current texts directly from the official source for its own situation.)

Data breach notification deadline: 72 hours

By decision No. 2019/271 dated 24.01.2019, the KVKK Board ruled that a data breach notification must be made to the Board within 72 hours at the latest. For notifications exceeding 72 hours, it is mandatory to provide justification and to document the delaying cause.

Mandatory fields of the notification form:

  • Breach date, detection date, application date (UTC+03).
  • Estimate of the number of affected individuals and the data categories.
  • Source of the breach (cyber attack, insider threat, lost/stolen device, erroneous sharing).
  • Urgent measures taken.
  • Notification made or planned to the relevant individuals.

For a ready template: /en/rehber/kvkk-72-saat-veri-ihlali-bildirim-sablonu.

Post-breach process

  1. Hours 0-2. The incident is detected, the IR (incident response) team is activated, and the affected system is isolated. Details: /en/rehber/siber-olay-mudahale-playbook-nist-800-61-checklist.
  2. Hours 2-24. The digital forensics team takes an image and starts the hash chain. The scope and the number of affected individuals become clear.
  3. Hours 24-72. The Board notification form is completed and submitted. Notification to the relevant individuals is planned.
  4. Weeks 1-4. The Board may request additional information, and a written defense is submitted.
  5. Decision. The Board issues an administrative fine decision based on the investigation report, the defense, and the technical evidence. The decision is published in the Decision Summaries on kvkk.gov.tr, not in the Resmi Gazete.

Factors that reduce the penalty

  • Compliance with the 72-hour deadline.
  • The existence of an ISO 27001, ISO 27701, or KVKK compliance certificate.
  • Regular penetration test reports (annual or every 6 months).
  • Employee KVKK training records and undertakings.
  • A remedial action plan after the breach and proof of its implementation.

For a first-24-hours action list in urgent scenarios such as ransomware: /en/rehber/fidye-yazilim-ilk-24-saat-aksiyon-cizelgesi.

Frequently Asked Questions (FAQ)

Can a KVKK fine be paid in installments?

Administrative fines are collected pursuant to the Law on the Collection Procedure of Public Receivables No. 6183, and an installment request is made to the tax office. The Board itself does not have the authority to grant installments.

What is the way to appeal a fine?

An action can be brought against an administrative fine before the Ankara Administrative Court within 15 days of notification, pursuant to Article 27 of the Law on Misdemeanors (Kabahatler Kanunu). A request for a stay of execution may also be raised in this action.

How does company turnover affect the fine?

The KVKK has not introduced a clear ratio tied to turnover like the EU GDPR; however, through the criterion of the "data controller's economic situation" the Board imposes penalties close to the upper band on large companies. Penalties close to the lower band are common for small businesses.

Can a KVKK fine and a GDPR fine be imposed together?

Yes, for Turkish companies operating in the EU. The GDPR and the KVKK are two independent regimes, and the same breach can be penalized separately by both authorities.

What happens if a data breach is not reported?

A breach of the notification obligation is in itself considered a violation of Article 12 of the KVKK, and an additional administrative fine is imposed. In the Facebook and Marriott decisions, a separate penalty was imposed for the notification delay.


DSET KVKK Compliance and Digital Forensics Services Hacettepe Teknokent, Beytepe, Ankara 20+ years of experience, ISO 27001, KVKK compliance projects Phone: +90 536 662 38 09, Email: [email protected] 72-hour breach notification support, emergency incident response team.