Blog01 August 20264 min read932 words

Data Breach Notification: The KVKK 72-Hour Rule and Action Plan

Under Türkiye's data protection law (KVKK), a personal data breach must be reported to the Board within 72 hours. This guide covers what counts as a breach, an hour-by-hour action plan, the notification contents, and how log infrastructure underpins breach management.

#kvkk#data-breach#incident-response#compliance

Bad scenarios do happen: an employee's laptop is stolen, a server is hacked, a database is accidentally exposed to the public, an email goes to the wrong recipient. All of these count as a personal data breach. Under Article 12/5 of the KVKK (Türkiye's data protection law), notifying the Personal Data Protection Board within 72 hours is mandatory in such cases.

What Is a Data Breach?

According to the KVKK Board's decision, a data breach is the unauthorized disclosure, loss, alteration, or deletion of personal data, or unlawful access to it. Examples:

  • Data leakage following a cyberattack on a server
  • An employee exposing data, whether deliberately or by accident
  • A leak through a third-party service provider
  • A ransomware attack
  • A bulk email sent to the wrong recipient
  • A lost or stolen laptop, USB drive, or smartphone
  • Data exposure due to a cloud misconfiguration

When Does the 72-Hour Clock Start?

It starts the moment the breach is discovered. "I didn't know" is not a valid excuse — under your duty of reasonable care, you are responsible for investigating a suspicious incident.

Breach Action Plan (First 24 Hours)

1. Verify and Isolate the Incident

  • The security team runs the incident response procedure;
  • The affected system is isolated from the network;
  • Evidence is preserved (logs, disk images, network traffic);
  • If the attack is ongoing, the channel is cut off.

2. Assemble the Team

  • Incident Response Team (IRT): IT, legal, KVKK specialist, management, communications;
  • An open communication channel (a Slack / WhatsApp group) is set up;
  • Owners and a timeline are defined.

3. Begin the Impact Analysis

  • Which data was affected? (category, number of records, sensitivity)
  • How many people were affected?
  • What are the possible consequences? (identity theft, financial loss, reputation)
  • Is the breach ongoing?

24–72 Hours: Preparing the Formal Notification

Contents of the Notification to the Board

The Authority's "Data Breach Notification Form" is completed. It contains:

  1. Data controller information
  2. Date and duration of the breach
  3. Date of discovery
  4. Nature of the breach (loss / leak / unauthorized access)
  5. Categories of personal data affected
  6. Number of data subjects affected
  7. Possible consequences
  8. Measures taken and to be taken
  9. Contact person

Notification Method

Through VERBİS or the Board's e-Government integration. In urgent cases, via kvkk.gov.tr/veri-ihlali-bildirimi.

Notifying the Affected Data Subjects

Under Article 12/5 of the KVKK, the data controller must also notify the affected individuals "within the shortest reasonable time," provided this does not aggravate the consequences of the breach. The notification should:

  • Be delivered by email, SMS, or post;
  • Cover the nature of the breach, the measures taken, and the protective steps the person can take;
  • Include a point of contact (the KVKK contact person);
  • Use plain, clear language.

When the 72 Hours Are Exceeded

If notification could not be made within 72 hours, the reason must be explained to the Board. Even with valid reasons, the risk of a penalty increases. The 2026 penalty range: 40,000 – 6,000,000 TL.

Breach Detection and Preparedness with SignLogger

Detecting a data breach quickly requires concrete infrastructure:

Anomaly Detection

  • Sign-in attempts at unusual times or from unusual locations;
  • Unusual query volume;
  • Failed 2FA / brute-force patterns.

Audit Trail

  • Every access is recorded — who, when, and which data;
  • Made tamper-proof with a hash chain;
  • Speeds up root-cause analysis after a breach.

Notification Templates

An integrated breach notification form template with SignLogger; the first draft submitted to the Board is prepared automatically. Notifications to affected individuals can be sent by bulk email.

For details, review our security policy and the SignLogger features.

The 72-Hour Action Plan: Hour by Hour

  1. 0–4 hours — Detection and response: isolate the affected system, rotate access keys, and preserve evidence (logs, images). Deleting or altering logs at this stage is the biggest mistake.
  2. 4–24 hours — Scope analysis: which data, how many people, over what time window? The answers come from the log records: who accessed which system, and when.
  3. 24–48 hours — Assessment and decision: determine whether the incident meets the definition of a "personal data breach," its risk level, and whether notification is required; obtain legal support.
  4. 48–72 hours — Notification: file with the KVKK Board using the breach notification form and inform the affected individuals within a reasonable time. If information is incomplete, "phased notification" is possible — don't miss the deadline.

Logs Are the Backbone of Breach Management

The most critical question during a breach is "what happened, and how far did it spread?" — and only logs can answer it. Access logs reveal the systems the attacker entered; network logs reveal the scale of data exfiltration. It is also essential that these records be tamper-proof: an attacker tries to erase their tracks, but a digitally signed, timestamped archive cannot be altered. For the infrastructure, see the Signed Logs and Law 5651 Logging Obligation guides.

Breach Preparedness Checklist

  • ☐ A breach response team and communication chain are defined (IT + legal + management)
  • ☐ The current version of the Board's notification form and the required information are known
  • ☐ System and network logs are centralized, signed, and retained for at least the legal period
  • ☐ The restore-from-backup procedure has been tested
  • ☐ A tabletop exercise is conducted once a year

Frequently Asked Questions

Does every security incident require notification?

No — if there was no unauthorized access, disclosure, or loss of personal data (e.g. a failed attack attempt), notification is not required; still, keep an incident record.

When does the 72 hours start?

From the moment the breach is discovered. To avoid delaying "discovery," monitoring and alerting infrastructure (including log monitoring) is critically important.

Last updated: 01 August 2026

Questions about SignLogger?

Contact us