
Breach Notification: Five Decisions on the 72-Hour Deadline, Procedure and Transparency
Five KVKK decisions on the 72-hour notification deadline, the official notification form, informing data subjects and contradictory statements.
Insights and updates
From emerging regulation to deal mechanics, we write about the questions founders and investors actually ask: practical analysis you can put to work.

Five KVKK decisions on the 72-hour notification deadline, the official notification form, informing data subjects and contradictory statements.

Five KVKK decisions on breaches originating with software vendors, hosting services and shared group infrastructure: why supplier oversight is an operational duty.

Five KVKK decisions on multi-factor authentication, passwords saved in browsers, BEC attacks and physical server access.

Five KVKK decisions on ransomware and unauthorised access: how missing penetration tests, password hygiene and authorisation gaps become the basis of the fine.

The Turkish Personal Data Protection Board published 47 decision summaries on 10 August 2026. TRY 11.5 million in fines, four penalties at the statutory maximum and recurring patterns under eight headings, with a twelve-point action plan.

A year of Board decisions is the cheapest compliance consulting: biometrics with alternatives, hollow privacy notices, undeclared transfers via SaaS tooling, notification timing, retention by inertia — each with its to-do.