KVKK Compensation Lawsuits: Individual Rights in Personal Data Breaches and Digital Forensic Evidence
The right to compensation under KVKK Article 14. The difference between an administrative fine (the Board) and compensation (the court). Competent courts (Civil Court of First Instance + Labor + Consumer). Pecuniary vs. non-pecuniary damages. A comparison with GDPR Art. 82. The four elements of the burden of proof under HMK 190. Types of evidence (Board decision, Court of Cassation precedent, forensic report, email header, HIBP, device image). Three scenarios (phishing, identity theft, health data). Coordinated litigation.
KVKK Compensation Lawsuits: Individual Rights in Personal Data Breaches and Digital Forensic Evidence
An e-commerce site is breached, and your phone number and address end up on dark-web forums. Soon after, a "shipping company" that knows your name calls you, sends a fake link, and your card details are stolen. At the head of this chain is the negligence of a data controller. So, in Turkey, does an individual harmed by that negligence simply have to file a complaint with the KVKK Board and wait for an administrative fine, or can they recover compensation that goes into their own pocket? The answer: they can, but only if they build the right legal route and the right technical evidence. In this guide we cover the legal basis of a KVKK compensation lawsuit, the competent court, the burden of proof, and the role of the digital forensic report in this process.
Legal Basis: KVKK Article 14 and TBK Article 49
Article 14 of the Law on the Protection of Personal Data explicitly governs the right to compensation. After stating that a person must first direct any requests regarding the application of the Law's provisions to the data controller, the article continues: "The right of those whose personality rights have been violated to claim compensation under the general provisions is reserved." In other words, KVKK Art. 14 does not reinvent the right to compensation; it activates the existing "general provisions." The official text of the law is published as the Law No. 6698 PDF on the Legislation Information System.
The "general provisions" that KVKK points to are, in practice, Article 49 of the Turkish Code of Obligations (TBK), which governs liability in tort. TBK Art. 49, first paragraph, states: "A person who causes harm to another through a faulty and unlawful act is obliged to remedy that harm." The full text can be found in the TBK Law No. 6098 PDF. A KVKK violation supplies the unlawful-act element ready-made. What remains are fault, damage, and the causal link. We will examine a detailed analysis of TBK 49 in digital-evidence practice in our forthcoming article, Turkish Code of Obligations Article 49 and Digital Evidence.
The Difference Between an Administrative Fine and a Compensation Lawsuit
This is the point victims confuse most often. The administrative fine that the Board imposes following a complaint goes into the state treasury. Not a single kurus reaches the victim's pocket. Compensation is an entirely separate route: the amount the court awards is paid directly to the party that was harmed.
We keep regular summaries of Board decisions; to see which type of violation has drawn what penalty in which sector, take a look at our Data Breach Trends From KVKK Board Decision Summaries article. In practice these two routes do not replace each other; they complement each other. A Board decision serves as a preliminary document that strengthens the finding of an "unlawful act" in a compensation lawsuit. While the court is not bound to reach the same conclusion itself, it weighs the decision as evidence.
Competent and Authorized Court
KVKK compensation lawsuits are, as a rule, heard in the Civil Courts of First Instance. Under the framework of the Code of Civil Procedure (HMK), subject-matter jurisdiction is a matter of public order, and the court considers it ex officio. As for venue, the victim, in their capacity as plaintiff, also has the option of filing suit in the Civil Court of First Instance at their own place of residence, because HMK grants optional venue in tort cases. For the full text of the HMK, refer to the HMK Law No. 6100 PDF.
In certain special circumstances a different court may have jurisdiction. If the data controller is an employer and the violation arises from the employment relationship, the Labor Court may be competent. If the data controller is a company offering goods or services to consumers and the victim is acting as a consumer, the Consumer Court may come into play. To draw this distinction clearly, it is essential to consult a lawyer specialized in the field before filing suit.
Pecuniary and Non-Pecuniary Damages
Two heads of damages can be claimed together in a compensation lawsuit. Pecuniary damages cover the person's direct financial loss: money withdrawn from a bank account through phishing, the cost of fraudulent card transactions, the legal fees and court costs paid to close an account opened in your name after identity theft, the data-recovery invoice paid to restore emails, and similar items. Every item that can be invoiced should be documented.
Non-pecuniary (moral) damages, on the other hand, cover the non-financial harm such as distress, fear, and reputational loss caused by the violation of personality rights. In scenarios such as fraud committed under your identity after a data breach, the leaking of intimate photographs, or the disclosure of health data, non-pecuniary damages take on greater weight. Determining non-pecuniary damages falls within the judge's discretion; there is no fixed tariff.
Comparison With GDPR Article 82
Article 82 of the EU's General Data Protection Regulation formulates the right to compensation far more directly. According to the official text at gdpr.eu, GDPR Art. 82(1) states: "Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor." What Turkish KVKK routes by reference to TBK 49, the GDPR governs on its own in a single article.
This difference has a practical consequence: in EU member states, thousands of individual data-compensation lawsuits are filed every year, and in some countries dedicated platforms that aggregate such claims have even emerged. In Turkey, by contrast, compensation lawsuits remain relatively rare alongside KVKK Board complaints. Among the reasons are that the burden of proof rests on the plaintiff, that quantifying the damage is difficult, and that legal and expert-witness costs appear high relative to the compensation amount. The quality of the digital forensic report directly affects this equation.
The Burden of Proof and HMK 190
Article 190 of the HMK provides that "Unless there is a special provision in the law, the burden of proof rests on the party that derives a right in its own favor from the legal consequence attached to the alleged fact." In a KVKK compensation lawsuit, this provision means that the victim seeking compensation must prove four elements.
First, the unlawful act: that the data controller acted contrary to its KVKK obligations. Second, fault: the existence of negligence or intent, and in practice the inadequacy of data-security measures is generally treated as negligence. Third, damage: the concrete demonstration of pecuniary or non-pecuniary harm. Fourth, the causal link: the direct connection between the violation and the harm, that is, that the number used in the phishing call genuinely came from the leaked database.
None of these four elements proves itself "automatically." Each one requires documents and technical evidence. This is precisely where the digital forensic report comes in.
Which Evidence Is Considered Valid
We can group the evidence that can be presented to the court in a KVKK compensation lawsuit into the following practical categories.
The KVKK Board decision. If the Board has issued a decision against the data controller responsible for the breach, that decision is an official finding. It can be obtained through the Board decision search portal or through summaries of Board decisions. A Board decision significantly reinforces the unlawful-act element.
Court of Cassation precedents. You can see how similar cases were resolved at the appeal stage on the Court of Cassation Decision Search portal. Precedents are not binding, but they influence the judge's assessment.
The digital forensic report. This comes from a court-appointed expert or from an expert report commissioned privately by the parties. We examined the structure of this report in detail in our Digital Forensic Expert Report Structure, Format, and Sections article. The report confirms in technical language that the email-header analysis reveals the forged sender information, that the phishing SMS on the phone is authentic, and that the call records intensified after the breach.
Email headers and SMTP logs. The sending IP of the fake email, the SPF, DKIM, and DMARC record results, the time received, and the machine. When this data is extracted correctly, it exposes the fraudster's infrastructure.
SMS and call records. Detailed call logs requested from the operator show when the fraudster's number that reached the victim initiated the call. When this timeline overlaps with the date of the leak, it strengthens the causal link.
Have I Been Pwned findings. haveibeenpwned.com is a free service that shows which breaches an individual's email appeared in. It is not sufficient evidence on its own, but it is useful as supporting proof to attach to the expert's report.
A forensic device image. The victim's phone is examined for spyware or malicious applications. We described the details of this process in our Signs of Spyware on a Phone and Digital Forensic Detection article. If malware is found on the device, and a connection is established to the data controller's violation, fault and causation become clearer.
For all of this evidence to be accepted by the court, the chain of custody must remain unbroken. We detailed the logic of this chain in our Digital Forensics Process 2026: KVKK Chain of Custody and the Court article.
Typical Compensation Scenarios
In practice, the bulk of the cases that come before the court fit the following patterns.
Phishing following a data leak. An e-commerce platform is breached. The victim's name, phone, and order information end up on the black market. The fraudster calls, citing the order number, sends a fake link "for a shipping return," and redirects the victim to a page designed to capture the card's CVV. The victim's money is gone. The compensation lawsuit includes both pecuniary (the money withdrawn) and non-pecuniary (the stress experienced, the reputational impact) heads.
Identity theft. A national ID number, name, and date of birth are leaked. A third party opens a phone line, a credit application, or a subscription in the victim's name. The victim spends time and money closing these. Pecuniary damages cover the legal and administrative costs, and non-pecuniary damages cover the reputational loss.
Disclosure of health data. The leaking of health information, which falls into the category of sensitive data, is an area KVKK protects specifically. Non-pecuniary damages can reach serious amounts here. It is advisable to pursue this in parallel with a complaint before the KVKK Board.
Is a Collective (Class) Action Possible?
Turkey's civil procedure law does not have a true class-action structure like that in the United States. Group lawsuits under the HMK are limited and are generally reserved for associations and foundations. Even when individual victims number in the thousands, each must file a separate suit. There is, however, a practical solution: people harmed by the same data leak can form litigation teams with the same law partnership, and the cases can be run as related files. A single expert report can be prepared jointly, and the cost is shared per person. These coordinated lawsuits are the most practical model approaching the organized compensation platforms in GDPR countries.
Practical Steps for the Victim
If you suspect you have experienced a data breach, take the following steps in order.
- Write down the moment of the incident. The date, time, the text of the fake message, the number that called you. Add every update to a single notebook throughout the process.
- Do not power off or freeze your device, but avoid installing new applications or doing a factory reset. Doing so destroys evidence in a later forensic examination.
- Send a written request to the data controller under KVKK Art. 13. Keep the response you receive. If no response is given or it is inadequate, the right to complain to the Board arises without waiting the 30 days.
- File a complaint with the KVKK Board. Run the process with logic similar to the framework we described in our KVKK Data Breach Notification 72-Hour Form article, only this time you are the victim, not the violator.
- Apply to a digital forensics lab. Have a logical image of the phone taken, request an email-header analysis, and ask for the operator records of the fake calling number.
- Prepare the compensation lawsuit together with your lawyer. If there is a KVKK Board decision, it is attached to the case; if not, the Board process is run in parallel.
If you are on the data-controller side, we covered the steps you need to take at the moment of a breach at the planning level in our KVKK Compliance Consulting: VERBIS, Policies, Audit article, and at the incident level in our KVKK Data Breach Notification 72-Hour Form article.
Frequently Asked Questions (FAQ)
1. What is the statute of limitations in a KVKK compensation lawsuit? The TBK tort statute of limitations applies: two years from the date the damage and the perpetrator are learned, and in any case ten years from the date the act was committed. In most data-leak cases, the date of learning is the date of the phishing attempt that reached the victim.
2. Can I file a compensation lawsuit without complaining to the KVKK Board? You can; an application to the Board is not mandatory for filing the lawsuit. However, a Board decision is strong evidence in court, so running them in parallel works in your favor.
3. Can I obtain compensation without a digital forensic report? Theoretically possible, in practice very difficult. The court is reluctant to award compensation without technical evidence that concretizes the causal link and the damage.
4. Can I sue a data controller located abroad? KVKK protects the data subjects in Turkey. For EU-based companies, GDPR and KVKK come into play in parallel. In practice, collection abroad is difficult, but for companies with an EU representative a lawsuit can be filed in Turkey.
5. Can the compensation amount be calculated in advance? It depends on the court's discretion; there is no fixed tariff. If pecuniary damage is documented, its equivalent is claimed; non-pecuniary damage is determined according to the severity of the incident.
6. An employee of the data controller leaked my personal data, against whom is the compensation directed? As a rule, it is directed at the data-controller organization. Under TBK Art. 66, the employer bears liability. The organization may pass the compensation it pays on to the employee by way of recourse.
7. Who is responsible for the credit debt opened after identity theft? The primary responsibility lies with the fraudster and, due to poor controls, with the financial institution that opened the credit. If the data controller's KVKK violation played a role in this chain, joint and several liability may come into play.
8. My child's data was leaked, can I file a lawsuit? Under your right of custody, you can file suit on the child's behalf. Children's data is considered to be of special importance, and this is taken into account in the assessment of non-pecuniary damages.
Conclusion: When Law and Digital Forensics Work Together
The KVKK compensation lawsuit is still an underused right in Turkey. The technical reason is usually insufficient evidence; the legal reason is a lack of clarity about which court to approach and with what claim. A properly prepared digital forensic report, combined with a Board decision, goes a long way toward meeting the burden of proof under TBK 49. To set this route up correctly, the legal and technical sides must plan together.
DSET Bilisim Legal Support At our headquarters at Hacettepe Teknokent in Ankara, we provide services for KVKK compensation lawsuit processes: preparing digital forensic reports, email-header analysis, phone imaging, recording the chain of custody, and giving oral explanations in court. We work in direct coordination with your law office. DSET, since 2003, Ankara Hacettepe Teknokent Beytepe; +90 536 662 38 09. For a free preliminary consultation, you can reach us on +90 536 662 38 09.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.