The administrative fines imposed by the Personal Data Protection Authority for KVKK violations are increased every year in line with the official revaluation rate. The up-to-date penalty amounts for 2026 are set out below.
KVKK Article 18 — Administrative Fines
1. Breach of the Duty to Inform (Art. 18/1-a)
For those who fail to fulfil the duty to inform under KVKK Art. 10:
- An administrative fine between 13,000 TL and 270,000 TL
This is the most common type of violation. Typical cases include the absence of a privacy notice on a website, failure to post a notice where hidden cameras are used, and the lack of a consent statement beneath a form.
2. Breach of the Data Security Obligation (Art. 18/1-b)
For those who fail to take the measures required for data security under KVKK Art. 12:
- An administrative fine between 40,000 TL and 6,000,000 TL
This is the most severe category of penalty. It applies to organizations that suffer a data breach, store passwords in plain text, lack 2FA, or fail to run vulnerability scans.
3. Failure to Comply with a Board Decision (Art. 18/1-c)
For those who fail to carry out decisions issued by the Board:
- An administrative fine between 67,500 TL and 6,000,000 TL
4. Breach of the VERBİS Registration Obligation (Art. 18/1-ç)
For those who fail to register with VERBİS or who make an incorrect or incomplete notification:
- An administrative fine between 54,000 TL and 2,700,000 TL
Other Types of Penalty
Acts That Constitute Criminal Offenses (Turkish Penal Code)
In addition to KVKK, certain acts involving personal data are defined as criminal offenses under the Turkish Penal Code (TCK):
- TCK Art. 135 — Recording of personal data: 1 to 3 years' imprisonment
- TCK Art. 136 — Unlawfully providing or obtaining data: 2 to 4 years' imprisonment
- TCK Art. 138 — Failure to destroy data: 1 to 2 years' imprisonment
Alongside the individuals who commit these offenses (typically natural persons — IT managers and employees), security measures may also be applied to legal entities.
Annual Revaluation
Penalty amounts are increased each year in line with the revaluation rate under Article 298 of the Tax Procedure Law. From 2025 to 2026 there was an increase of roughly 59%, and a similar rise is expected for 2027.
Examples of Recent Rulings
Here are a few examples from the Personal Data Protection Authority's recent decisions:
- A major e-commerce platform — data breach: 1,350,000 TL
- A hotel chain — missing privacy notice: 120,000 TL
- A hospital — inadequate data security: 900,000 TL
- A bank — communication without explicit consent: 1,800,000 TL
How to Protect Yourself Against Penalties
- Prepare a privacy notice and display it at every point where you collect data.
- Complete your VERBİS registration within 30 days once you exceed the threshold.
- Document your data security measures (encryption, 2FA, audit logs).
- Respond to data subject requests within 30 days.
- Notify the Board within 72 hours in the event of a breach.
- Provide employee training on a regular basis.
Reducing Your Risk with SignLogger
The data security obligation carries the most expensive penalties. SignLogger provides concrete measures for data security:
- TLS 1.2+, bcrypt password hashing, and AES-256 backup encryption;
- RBAC plus mandatory 2FA on management panels;
- Access traceability through audit logs;
- Automated data deletion and anonymization;
- brute-force protection via fail2ban.
For details, review our security policy.
A Priority Order for Avoiding Penalties
When you look at the Board's decisions, the vast majority of fines come down to three root causes. If you are working toward compliance on a limited budget, close these gaps in order:
- Lack of data security measures (the highest fines): Systems without access control, unencrypted file sharing, and unmonitored logs. You also need to be able to prove your technical measures — you must be able to answer, with logs, the question of who accessed which data and when.
- Missing privacy notices (the most common fine): A notice must be present on every channel where data is collected (web forms, call centers, Wi-Fi portals); see the Privacy Notice Guide.
- Delay in breach notification: Being caught unprepared by the 72-hour rule aggravates the penalty; see the 72-Hour Action Plan.
How Log Management Reduces Your Penalty Risk
The proof of your data security measures rests largely on logs: server access records, authorization changes, and failed login attempts. These records themselves must also be tamper-proof — otherwise they carry no evidential weight. SignLogger's electronically signed and timestamped archive answers the "can these records be trusted?" question in both Law No. 5651 and KVKK audits; for details, see the Law No. 5651 Logging Obligation guide and the Signed Logs article.
Frequently Asked Questions
How are the penalty amounts determined?
They are set within the lower and upper limits at the Board's discretion, based on the severity of the violation, the number of people affected, the degree of fault, and the level of cooperation. More than one article may be applied to the same incident.
Can a penalty be appealed?
Yes — Board decisions can be challenged before the administrative courts. Because the time limits are short, you should act quickly once the decision is served.