Jump to

Authentication, Email and Physical Access: The Security Standard in Five Decisions

Authentication and Access Security Decisions — Vircon Legal

The five decisions here focus on the door through which the attack reached the organisation: email accounts without multi-factor authentication, passwords saved in browsers, spoofed executive emails and an unlocked server room. The Board’s approach across these decisions is to treat the absence of low-cost measures as an aggravating factor.

This article is part 2 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.

Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.

Decisions covered in this article

Authentication, Email and Physical Access: The Security Standard in Five Decisions — the decisions reviewed in this instalment.
Decision Date Subject Outcome
2025/88 9 January 2025 Assessed a Breach in Which a Single Employee’s Browser Record Affected More Than 500,000 People TRY 1,000,000
2024/728 9 May 2024 Separately Penalised Late Notification in a Data Leak Effected Through a Fake Executive E-mail TRY 1,000,000
2022/714 21 July 2022 Treated the Absence of Multi-Factor Authentication as the Cause of a BEC Attack TRY 200,000
2024/1523 10 September 2024 Emphasised That Physical Server Access Must Be Audited as Much as Digital Security TRY 500,000
2023/412 21 March 2023 Assessed the Fact That the Breach Was Noticed Six Months Later as a Separate Shortcoming TRY 350,000

The Board Assessed a Breach in Which a Single Employee’s Browser Record Affected More Than 500,000 People

Decision no: 2025/88  ·  Date: 9 January 2025  ·  Outcome: TRY 1,000,000

The facts

In the specific incident, the computer of an employee working in the information technology team of a restaurant chain was infected with malicious software; this software captured the username and password information that the employee kept saved in their internet browser for ease of logging in. Since the login credentials of a third-party platform supported by the employee were also saved in the same browser, the attackers gained access, from a single device, both to the company’s own systems and to that third-party platform.

This access, which began from a single point, grew within a short time through a snowball effect, and as a result the name and surname, gender, e-mail, telephone and city information of 505,337 customers were affected. The company did not make any direct notification to the affected customers regarding this breach.

What the Board held

The Board found the absence of two-step authentication (2FA), the fact that security systems such as SIEM and a firewall were procured only after the breach, and the failure to submit any evidence of employee security training to be the fundamental shortcomings.

In addition, the failure to notify the affected data subjects was assessed as a separate breach with reference to Board decision no. 2019/271.

Why this decision matters

The decision is a powerful example drawing attention to the scale effect, in that it concretely shows how a single password stored in one employee’s browser can turn into a breach affecting hundreds of thousands of people on an institutional scale.

The reference to decision no. 2019/271 as the basis for the obligation to notify data subjects should also be noted, in that it offers a reference point separate from decision no. 2019/10 (the 72-hour notification to the Board).

What organisations should watch for

  • It is recommended that browser-level password saving be disabled on corporate devices and that the use of a corporate password manager be encouraged.
  • It is recommended that two-step authentication be made mandatory, particularly for accounts that provide access to third-party systems.
  • Providing security training on a regular basis and documenting attendance may constitute an important element of defence in a possible examination.

Vircon Legal assessment

An administrative fine of TRY 800,000 for the security shortcomings and a further TRY 200,000 for the failure to notify the data subjects, amounting to a total of TRY 1,000,000 (the statutory upper limit), was imposed. Given the scale of the decision and the prevalence of the browser password risk, it is considered that this decision will become a precedent that is frequently cited.

The Board Separately Penalised Late Notification in a Data Leak Effected Through a Fake Executive E-mail

Decision no: 2024/728  ·  Date: 9 May 2024  ·  Outcome: TRY 1,000,000

The facts

In the incident under examination, a CEO fraud attack was carried out against the system of an international accounting/finance professional body. The attackers sent a fake e-mail, which they had prepared by impersonating the body’s president, to an authorised member of staff within the body; owing to its genuine appearance, this e-mail persuaded the member of staff to share a list containing the name and surname, membership number and e-mail information of 217 Turkish members. The list thereby fell into the hands of the attackers.

The body notified the Board after detecting the incident; however, the examination established that this notification had been made after the 72-hour period stipulated in the Law had elapsed.

What the Board held

The Board assessed the fact that e-mail verification controls (technical measures that block fake sender addresses) had not been strengthened before the breach, and the inadequacy of the risk analysis process, as a breach of the security obligation.

As a separate heading, it was established that the breach had not been notified within the 72-hour period stipulated in the Law; this matter was additionally assessed with reference to Board decision no. 2019/10.

Why this decision matters

The decision contains two separate instructive elements, in that it shows both that e-mail verification controls have become a concrete expectation against CEO fraud type attacks and that the 72-hour notification period (established by decision no. 2019/10) is applied strictly.

The penalising of the security shortcoming and the late notification as separate items confirms that these two obligations are assessed independently of one another.

What organisations should watch for

  • It is recommended that it be ensured that sender address verification mechanisms are active in corporate e-mail systems.
  • It is recommended that finance and accounting teams be informed on a regular basis about fake requests that impersonate senior management.
  • The breach notification process is required to have been defined in advance and rehearsed in such a way as to ensure compliance with the 72-hour statutory period.

Vircon Legal assessment

An administrative fine of TRY 750,000 for the security shortcoming and a further TRY 250,000 for the late notification, amounting to a total of TRY 1,000,000 (the statutory upper limit), was imposed. This decision, in which the 72-hour notification period was applied in concrete terms, shows that breach response plans must be designed in a way that places the statutory period at their centre.

The Board Treated the Absence of Multi-Factor Authentication as the Cause of a BEC Attack

Decision no: 2022/714  ·  Date: 21 July 2022  ·  Outcome: TRY 200,000

The facts

In the incident subject to examination, the e-mail account of a senior executive at an agricultural commodities trading company was compromised through a click on an e-mail with phishing content and the subsequent infection of the computer with keylogger software. Using the account they had compromised, the attackers sent e-mails containing fake debt notifications, giving the impression that a genuine debt relationship existed, to approximately 1,000 people. This type of attack is referred to in practice as “business e-mail compromise” or “CEO fraud” and generally aims to induce recipients to make a payment or to share sensitive information.

After noticing the attack, the company notified the Board of the situation; the examination revealed that the attack had begun with the compromise of a single executive account and that a wide body of recipients had been reached through that account.

What the Board held

The Board found shortcomings such as the absence of multi-factor authentication (MFA), the absence in the password policy of a warning against using the same password on other platforms, and the failure to monitor access/log records on a regular basis, to be the fundamental causes of the security breach.

Why this decision matters

The decision shows that, in CEO fraud type attacks, the Board has made MFA and password hygiene a minimum expectation. Since this type of attack can reach a wide body of people through the account of a single employee, the importance of preventive measures is particularly emphasised.

What organisations should watch for

  • It is recommended that multi-factor authentication be made mandatory, particularly for finance and senior management e-mail accounts.
  • Password policies are required to contain an explicit warning against re-using the same password on different platforms.
  • Regular monitoring of access and login records is recommended in terms of the early detection of anomalous logins.

Vircon Legal assessment

An administrative fine of TRY 200,000 was imposed. It is considered that the decision is valuable for all companies whose finance and accounting processes are conducted by e-mail, in that it gives concrete form to the minimum technical measures expected to be taken against BEC attacks.

The Board Emphasised That Physical Server Access Must Be Audited as Much as Digital Security

Decision no: 2024/1523  ·  Date: 10 September 2024  ·  Outcome: TRY 500,000

The facts

In the incident subject to examination, a computer belonging to a member of staff at a hotel management/tourism company was opened to access by attackers as a result of the opening of an e-mail with phishing content. Shift schedule data belonging to 450 employees were affected through this computer.

As a result of the examination, it was established that the breach had remained limited to the computer of the member of staff concerned; that no vulnerability had arisen in the company’s server or other hotel systems; and that, upon examination of the internet traffic, the data had not been taken outside. Nevertheless, in the general security audit carried out at the company, further technical and physical shortcomings, independent of this incident, were also identified.

What the Board held

Although the breach itself had remained limited to a single computer, the Board, in the general assessment carried out at the company, identified shortcomings such as out-of-date virtual server and database systems, the use of weak passwords and spam protection being significantly vulnerable. The decision also includes a rarely encountered finding: that physical access to the server room was possible without identity verification or access control.

Why this decision matters

The instructive aspect of the decision is that it shows that, alongside digital security measures, physical access security is also within the scope of the Board’s assessment. For companies that physically host their own server infrastructure, this finding indicates that security audits must cover not only the software layer but also the physical layer.

What organisations should watch for

  • Server and database systems are required to be kept at current versions and regular patch management is required to be applied.
  • It is recommended that access to physical server rooms be restricted by a control mechanism such as identity verification or an access card.
  • It is recommended that the effectiveness of spam and phishing protection systems be tested on a regular basis.

Vircon Legal assessment

An administrative fine of TRY 500,000 was imposed. It is considered that the decision offers companies that host physical infrastructure (that have their own data centre or server room) a checklist going beyond digital measures.

The Board Assessed the Fact That the Breach Was Noticed Six Months Later as a Separate Shortcoming

Decision no: 2023/412  ·  Date: 21 March 2023  ·  Outcome: TRY 350,000

The facts

In the incident subject to examination, a data leak occurred through a security vulnerability in a third-party management panel that a hosting company provided to its customers. Using this vulnerability, the attackers gained access to the system; they obtained the identity, contact, customer transaction, financial and credit card information of 31,179 people, together with company documents, and published them on the dark web.

The breach could be detected not by the company’s own security monitoring systems, but upon an affected customer noticing that their data were being offered for sale on the dark web and informing the company, and approximately six months after the incident.

What the Board held

In the Board’s examination it was established that the breach had been noticed not by the company’s own security systems but upon a customer notification and six months after the incident. The absence of an intrusion detection system, the failure to apply data masking, the failure to adopt the principle of data minimisation, the failure to use two-step authentication (2FA) and the absence of a control that would prevent bulk data downloading were listed separately in the reasoning of the decision.

Why this decision matters

The prominent aspect of the decision is that the principle of data minimisation (the general principles within the scope of Article 4) is assessed together with the security obligation (Article 12); the Board implicitly accepted that retaining more data than necessary magnified the impact of the security breach.

It is also instructive in that it shows that the assumption that a breach “will be noticed by itself” needs to be tested; where there is no intrusion detection system, breaches can go unnoticed for months.

What organisations should watch for

  • It is recommended that it be ensured that intrusion detection and monitoring systems are installed and active.
  • Masking practices are required to be implemented for sensitive financial data such as credit card information.
  • It is recommended that technical controls that restrict or give warning of bulk data downloading operations be brought into operation.
  • It is recommended that the data categories retained be reviewed periodically as to whether they are proportionate to the purpose of processing (data minimisation).

Vircon Legal assessment

An administrative fine of TRY 350,000 was imposed. The fact that a large number of data categories, including credit card data, were affected and that detection came about through an external notification makes the decision a multi-dimensional example in terms of both data security and data minimisation.

Other parts of this series

The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Kimlik Doğrulama, E-posta ve Fiziksel Erişim: Beş Kararda Güvenlik Standardı.

For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 15 August 2026 · last updated: 13 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.