Quick answer: When a data breach is detected in Turkey, according to the principle set by KVKK the data controller must notify the Personal Data Protection Board as soon as possible from the moment the breach is learned and without unreasonable delay, within 72 hours at the latest. The correct order in the first 72 hours is: first contain the incident and preserve the evidence, then determine the scope (which data, how many people), then notify the Board and the affected data subjects. The most common mistake is deleting and rebuilding systems in a panic, thereby both destroying the evidence and leaving the scope uncertain. The correct response follows a fast but evidence preserving order, which requires running the forensic and legal processes at the same time.

A data breach is not a possibility but a matter of time. What is critical is to have planned in advance what you will do in the first 72 hours when a breach happens. This article presents the KVKK notification obligation, the correct order of the first 72 hours and a decision matrix.

KVKK notification obligation

The Personal Data Protection Board has placed a notification obligation on the data controller for data breaches. The core principles:

  • Time. Notification to the Board is made as soon as possible from the moment the breach is learned, within 72 hours at the latest.
  • Notice to the data subject. Affected people are also informed as soon as reasonably possible by a suitable method.
  • Content. The notification must include the nature of the breach, the affected data and number of people, the likely consequences and the measures taken.
  • Documentation. The breach and response process must be documented.

This obligation is part of the VERBIS registration and general KVKK compliance framework.

First 72 hours decision matrix

Time Step Purpose
0 to 4 hours Contain the incident, isolate the system Stop the spread, preserve evidence
4 to 24 hours Determine the scope, start forensic examination Which data, how many people affected
24 to 48 hours Legal and management assessment Notification need and content
48 to 72 hours Notify the Board, communicate with data subjects Meet the legal obligation
After 72 hours Remediation, root cause, lesson Prevent recurrence, document the process

The essence of this matrix is running speed and evidence preservation at the same time. An acceleration that destroys the evidence harms both legally and technically.

The most common mistake

When a breach is detected, the most common reflex is to immediately delete and rebuild the affected system. Although this seems to stop the incident, it causes two big harms: the digital evidence that shows how the breach happened is destroyed, and which data was affected becomes uncertain. Notification cannot be done correctly without knowing the scope. The correct approach is to isolate the system rather than delete it and to preserve the evidence first.

Forensics and law at the same time

The first 72 hours require running the technical and legal processes in parallel. Forensics reveals the scope and how the breach happened with evidentiary value; without this information the legal notification remains incomplete. In situations such as ransomware, a recovery dimension is also added. So breach response requires the technical team, legal and management to be at the same table.

Data breach response with DSET

DSET manages the first 72 hours of a data breach together with its technical and legal dimensions. It contains the incident while preserving evidence, quickly determines the scope with the local AI engine KAOS and supports the KVKK notification process with content. Because KAOS runs fully offline, sensitive breach data is not sent to external services, which does not create an additional leakage risk during the examination. The result is a response that both meets the legal obligation and prevents recurrence.

Frequently asked questions

What happens if I do not notify KVKK within 72 hours? Failing to fulfill the notification obligation on time creates the risk of an administrative sanction. Also, late and incomplete notification leads to the harm of the data subjects growing and to reputation loss. So time and scope are critical.

Must every data breach be notified to the Board? Breaches that involve personal data and pose a risk to the data subjects are notified. Determining the scope correctly requires a forensic examination. If in doubt, an expert assessment should be obtained to clarify the scope.

Is it wrong to immediately delete and clean the system? Yes, as a first reflex it is wrong. Deleting the system destroys the evidence and leaves the scope uncertain. The correct path is to isolate the system, preserve the evidence and move to remediation after determining the scope.

Sources

To manage the first 72 hours of a data breach while preserving evidence and meeting the KVKK obligation, contact DSET. We provide 24/7 emergency incident response from our Ankara Hacettepe Teknokent laboratory.