Jump to

Service Provider Related Breaches: Why Does Liability Stay With the Data Controller?

Service Provider Related Data Breaches — Vircon Legal

When a breach originates with a software vendor, a hosting service or a group company’s shared infrastructure, the question of who is liable is the common thread of these five decisions. The Board’s answer is consistent: the data controller is required to supervise its service provider not only contractually but in practice.

This article is part 3 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.

Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.

Decisions covered in this article

Service Provider Related Breaches: Why Does Liability Stay With the Data Controller? — the decisions reviewed in this instalment.
Decision Date Subject Outcome
2022/711 21 July 2022 Left Responsibility With the Data Controller in an Attack Originating From a Service Provider TRY 500,000
2023/1796 19 October 2023 Stated That a Contractual Security Undertaking Is Not Sufficient on Its Own and That an Audit Obligation Exists TRY 200,000
2024/413 6 March 2024 Assessed a Breach That Spread Through Shared Group Infrastructure TRY 150,000
2024/415 6 March 2024 Found That the Absence of Network Segmentation Led to an Attack That Spread to Eight Servers TRY 430,000
2025/881 22 May 2025 Treated an Inadvertently Activated Third-Party Integration as a Low-Risk Breach No administrative fine

The Board Left Responsibility With the Data Controller in an Attack Originating From a Service Provider

Decision no: 2022/711  ·  Date: 21 July 2022  ·  Outcome: TRY 500,000

The facts

In the incident under examination, an automotive electronics manufacturer uses an external software service to manage its human resources processes. The account through which the company providing that service (the data processor) accessed the system was seized by attackers; through that access, the data controller‘s systems were infiltrated and a ransomware attack was carried out.

660 people were affected by the attack, and the affected data set was not limited to employees alone; it extended to a broad scope including customer and supplier information. Among the affected data, special categories of health data such as blood group, Covid-19 status and the content of doctors’ reports appear within the same data set as identity and contact information of a general nature.

What the Board held

The Board expressly stated that the fact that the attack began not directly through the data controller but through the account of a service provider (the data processor) does not relieve the data controller of responsibility. In its assessment, the principle of joint responsibility of the data controller and the data processor under Article 12(2) was applied forcefully.

The fact that special categories of data were affected within a data set intermixed with general data categories was also assessed in the reasoning of the decision.

Why this decision matters

This decision is one of the clearest applications of the principle of joint responsibility for companies that use external service providers (particularly those with access to sensitive systems such as HR and accounting). It shows that the defence that “the breach originated not from our system but from our supplier” is not sufficient on its own.

What organisations should watch for

  • It is recommended that the access rights of service providers that have access to sensitive data, such as in human resources and accounting, be reviewed regularly.
  • It is required that security obligations be clearly defined in contracts concluded with service providers and that those obligations be actually audited.
  • It is recommended that data sets containing special categories of data be kept, as far as possible, in environments separate from general data.

Vircon Legal assessment

An administrative fine of TRY 500,000 was imposed. It is considered that the decision gives concrete form to the importance of supplier risk management for every company that processes sensitive data as part of a supply chain.

The Board Stated That a Contractual Security Undertaking Is Not Sufficient on Its Own and That an Audit Obligation Exists

Decision no: 2023/1796  ·  Date: 19 October 2023  ·  Outcome: TRY 200,000

The facts

In the incident subject to the Board’s assessment, a content delivery network service provider is used in the website infrastructure of a clothing store for the purpose of delivering customer content to the end user. Owing to a caching error that occurred in that service provider’s system, customer account and order information that should normally be displayed only to the user concerned became viewable on the screens of other users as well.

The complainant, having noticed that their own account information had been viewed by another user, reported the situation to the company and to the Board. In its defence, the company argued that the error originated not from its own systems but from the infrastructure of the external service provider.

What the Board held

The Board expressly stated that the conclusion of a contract containing a security undertaking with the service provider is not sufficient on its own, and that pursuant to Article 12(3) the data controller has an obligation to audit, or have audited, whether that undertaking is actually being fulfilled.

Why this decision matters

In expressing directly and clearly a theme that is repeated in decisions 2022/711 and 2024/1361 as well — the data controller’s audit obligation in breaches originating from a data processor/supplier (CDN, cloud, SaaS) — this decision sets out a principle applicable to almost every company that procures services externally.

What organisations should watch for

  • Adding a security undertaking to contracts concluded with service providers is the first step; actually verifying that undertaking by requesting a periodic audit, a security assessment report or certification is a second and equally important step.
  • It is recommended that the caching and access control configurations of CDN, cloud hosting and similar infrastructure providers be reviewed periodically.

Vircon Legal assessment

An administrative fine of TRY 200,000 was imposed. It is considered that the decision renders supplier auditing not merely a contractual but an operational obligation, and that the Board’s case law on this matter is repeated consistently.

The Board Assessed a Breach That Spread Through Shared Group Infrastructure

Decision no: 2024/413  ·  Date: 6 March 2024  ·  Outcome: TRY 150,000

The facts

In the incident under examination, a ransomware attack was carried out against the central server system located abroad of the international group to which an agricultural machinery manufacturer belongs. The server system in question is used jointly not only by that company but also by subsidiaries in different countries within the group.

The attack also spread through the central system to the company in Türkiye; in this way, the personal data of 56 employees (including health data) were affected.

What the Board held

The Board found that multi-factor authentication and patch management had been put into operation only after the breach. The distinguishing element of the decision is that the fact that different data controllers used the same server system jointly, which led to the breach spreading to more than one company, was assessed as both a technical and an administrative shortcoming.

Why this decision matters

The decision is important for group companies or undertakings that share a common IT infrastructure in that it shows that a security vulnerability in the shared infrastructure may not remain limited to a single company but may lead to it spreading in a chain.

What organisations should watch for

  • It is recommended that the IT infrastructure shared between group companies be divided into segments in such a way as to prevent a breach originating from a single point from spreading to the entire group.
  • It is required that multi-factor authentication and patch management be applied consistently and preventively across the group.

Vircon Legal assessment

An administrative fine of TRY 150,000 was imposed. This decision, together with decision no. 2024/415 discussed below, shows that the risk of shared infrastructure in international group structures should be addressed as a separate audit heading.

The Board Found That the Absence of Network Segmentation Led to an Attack That Spread to Eight Servers

Decision no: 2024/415  ·  Date: 6 March 2024  ·  Outcome: TRY 430,000

The facts

In the case at hand, an attack was carried out with a ransomware named Lockbit against the servers of the France-based group to which an automotive supply industry company belongs. After the attackers infiltrated the central servers, since there was no adequate separation between the network of the company in Türkiye and the central network, the attack also spread to 8 separate servers in Türkiye.

Although the company stated the number of affected persons as 43 in its official notification, as a result of the technical examination carried out it was assessed that the number of affected records could in fact be over 100,000; this indicates that the breach may be broader in scope than in the initial notification.

What the Board held

The Board identified the failure to carry out a penetration test, the absence of an endpoint detection and response (EDR) system and the inadequacy of network segmentation as the fundamental shortcomings.

Why this decision matters

When read together with decision no. 2024/413, this decision confirms, through two separate concrete examples, the critical role of network segmentation in preventing a central attack within an international group structure from spilling over into local systems.

What organisations should watch for

  • It is recommended that network segmentation be applied between central/international group servers and local systems, so as to prevent a breach at one point from spreading across the entire network.
  • It is required that endpoint detection and response (EDR) solutions be put into operation before a breach, as a preventive measure.

Vircon Legal assessment

An administrative fine of TRY 430,000 was imposed. Together with 2024/413, this decision points to the importance of Turkish companies that form part of an international group carrying out a security assessment independent of the central infrastructure.

The Board Treated an Inadvertently Activated Third-Party Integration as a Low-Risk Breach

Decision no: 2025/881  ·  Date: 22 May 2025  ·  Outcome: No administrative fine

The facts

In the incident under examination, an employee at a telecommunications technology company inadvertently activated a third-party application integration offered within a business software program that they used. When that integration came into operation, the name, work e-mail and work telephone information of certain employees defined in the system were automatically shared with an external company.

The error was noticed within a short time and the integration was deactivated. 488 people were affected by the incident; however, since the category of data shared was limited to contact information alone, the level of impact was assessed as low.

What the Board held

The Board, taking into account the rapid detection and response, the limited nature of the affected data category and the low level of overall risk, found no grounds for action.

Why this decision matters

The decision is valuable in that it shows that SaaS/third-party integration risk — such as an employee activating an integration by mistake — is a rarely encountered but increasingly widespread type of breach. The outcome reveals that the rapid response and the limited scope of the data were decisive in the favourable assessment.

What organisations should watch for

  • It is recommended that the activation of third-party application integrations be restricted by an authorisation and approval process.
  • It is recommended that access and sharing logs be monitored so that integration errors can be detected quickly.

Vircon Legal assessment

No administrative fine was imposed. In showing that the Board adopts a proportionate approach where the breach is small-scale and has been responded to quickly, this decision indicates that the speed of breach management processes is an important factor in terms of the absence of a fine.

Other parts of this series

The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Hizmet Sağlayıcı Kaynaklı İhlaller: Sorumluluk Neden Veri Sorumlusunda Kalıyor?.

For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

  • İrem Alp

    Vircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory

    View all posts
Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 16 August 2026 · last updated: 13 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.