These decisions address what happens after the breach: whether notification was made in time, through which form it was submitted, whether data subjects were informed, and whether the organisation’s statements remained consistent throughout. They show that late or contradictory notification is assessed as a separate head of penalty, independent of the underlying security failure.
This article is part 4 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.
Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.
Decisions covered in this article
| Decision | Date | Subject | Outcome |
|---|---|---|---|
| 2024/790 | 16 May 2024 | Held That the “The Data Was Not Corrupted” Defence Does Not Remove the Notification Obligation | TRY 350,000 |
| 2024/2196 | 26 December 2024 | Assessed Contradictory Statements Made During the Breach Process Against the Data Controller | TRY 250,000 |
| 2024/1718 | 9 October 2024 | Assessed a Multinational Breach Requiring Notification to 19 Separate Authorities | TRY 500,000 |
| 2025/833 | 2 May 2025 | Recalled the Use of the Official Notification Form in a Low-Risk Unauthorised Access Case | No administrative fine |
| 2022/1087 | 7 October 2022 | Did Not Characterise an Unproven “Data Has Been Leaked” Allegation as a Breach | No administrative fine |
The Board Held That the “The Data Was Not Corrupted” Defence Does Not Remove the Notification Obligation
Decision no: 2024/790 · Date: 16 May 2024 · Outcome: TRY 350,000
The facts
In the incident under examination, it was established that unauthorised access had been gained to the database of a software/technology start-up developing a mobile application for the management of co-working spaces. Since the company had not set up a separate and comprehensive logging infrastructure beyond the default logs offered by its cloud provider during the software development stage, it could not subsequently be determined exactly how and by which method the attacker infiltrated the system.
The name, e-mail and telephone information of 7,823 members of the application were affected by the breach. In its internal assessment the company established that the content of the data had not been altered and that it may only have been viewed, and on this ground made no notification to the affected members.
What the Board held
The Board rejected the company’s defence that “there is no integrity breach, the data was not altered”. According to the assessment, even if the integrity of personal data is not compromised, the fact that any one of the confidentiality and accessibility dimensions has been breached is a sufficient reason for notification to be made to data subjects; since unauthorised access is itself already a breach of confidentiality.
In addition, the failure to establish an adequate logging infrastructure during the software development stage was separately assessed as a breach of the security obligation.
Why this decision matters
This decision is an important clarification in that it clearly sets out that each element of the “confidentiality, integrity, accessibility” triad must be assessed separately in data security breaches; looking only at whether the data has been altered is not sufficient.
The assessment, as an obligation, that the security and logging infrastructure is to be established from the outset during the software development stage is a directly applicable principle, particularly for start-ups and software companies.
What organisations should watch for
- It must not be forgotten that the “the data was not altered” defence will not remove the notification obligation; unauthorised access itself requires notification.
- It is recommended that an adequate logging and monitoring infrastructure (not merely the cloud provider’s default logs) be established from the very beginning of the software development process.
- Even if the access method of a breach cannot be determined, the necessity of notification is required to be assessed on the basis of the number of affected persons and the data category.
Vircon Legal assessment
An administrative fine of TRY 250,000 for the security and logging deficiency and a further TRY 100,000 for the failure to notify the data subjects, amounting to a total of TRY 350,000, was imposed. It is considered that the decision is a precedent that will directly affect the early-stage security architecture decisions of start-ups and software companies.
The Board Assessed Contradictory Statements Made During the Breach Process Against the Data Controller
Decision no: 2024/2196 · Date: 26 December 2024 · Outcome: TRY 250,000
The facts
In the case at hand, a manufacturer of plastic household goods was subjected to a ransomware attack and notified the Board of the situation. As the examination process progressed, it emerged that the company had made mutually contradictory statements regarding the affected persons and data categories: at the initial stage the company made a statement to the effect that “employee and customer data were affected”, whereas in its responses to the Board’s subsequent requests for information it this time made a declaration contradicting its earlier statement, to the effect that “no personal data were affected, only commercial data were affected”.
Throughout the process the Board requested the company to submit its data processing inventory and samples of the documents subject to the breach; however, the company was unable to transmit these documents to the Board either.
What the Board held
The Board expressly assessed the company’s failure to act transparently and consistently throughout the process as a negative factor in the reasoning of its decision.
Why this decision matters
This decision is a rare and instructive example showing that the internal consistency of the statements given during the breach notification and examination process is as important as the process itself. It reveals that the Board also includes the data controller‘s attitude of cooperation in its assessment, beyond deficiencies in technical measures.
What organisations should watch for
- Taking care to ensure that the statements made during the breach notification process are consistent from the initial notification onwards, and, if there is uncertainty, expressing this explicitly as “under investigation”, is a safer approach than contradictory definitive statements.
- Keeping basic compliance documents such as the data processing inventory up to date is important in terms of being able to give a rapid and consistent response in a possible Board examination.
Vircon Legal assessment
An administrative fine of TRY 250,000 was imposed. In showing that post-breach crisis communication is an inseparable part of the management of the legal process, the decision points to an area in which both legal and communications teams need to work together.
The Board Assessed a Multinational Breach Requiring Notification to 19 Separate Authorities
Decision no: 2024/1718 · Date: 9 October 2024 · Outcome: TRY 500,000
The facts
In the incident subject to examination, unauthorised access was gained to the network server of a cosmetics and personal care company by means of infection with a trojan horse (trojan) virus; using this access, the attackers demanded a ransom from the company.
432 customers and business partners were affected by the incident, of whom the identity document information of 325, and the identity and contact information of 107 persons holding “brand ambassador” status, were placed at risk. Because the company is part of an international group and some of the affected persons are resident in Europe, the incident was notified simultaneously not only to the Board in Türkiye but also to 19 separate data protection authorities in Europe.
What the Board held
The Board established that the endpoint detection and response (EDR) solution had been procured only after the breach, that no penetration test had ever been carried out and that the risk analysis process was inadequate.
Why this decision matters
The decision concretely shows, for data controllers with an international group company structure, that a single breach may require simultaneous notification to supervisory authorities in more than one country. It is also assessed that EDR has become a concrete expectation as a preventive measure.
What organisations should watch for
- It is recommended that companies operating in more than one country or falling within the jurisdiction of more than one authority plan the multi-authority notification process in advance for a possible breach.
- Endpoint security solutions such as EDR are required to be put in place in advance as a preventive measure, rather than after a breach.
- It is recommended that penetration tests be commissioned at regular intervals and that their results be monitored.
Vircon Legal assessment
An administrative fine of TRY 500,000 was imposed. It is considered that the decision is valuable in that it shows the complexity of the notification process in multinational group structures and that EDR has become a concrete security expectation.
The Board Recalled the Use of the Official Notification Form in a Low-Risk Unauthorised Access Case
Decision no: 2025/833 · Date: 2 May 2025 · Outcome: No administrative fine
The facts
In the incident under examination, a non-profit scientific organisation uses a newsletter platform provided by an external data processor in order to send a regular newsletter to its subscribers. Unauthorised access was gained through this platform; as a result of the access, the name-surname and e-mail information of 15 persons were affected.
The organisation notified the Board of this small-scale incident; during the examination it was seen that the content of the notification form did not fully comply with the Board’s standard format.
What the Board held
Taking the low level of risk into account, the Board found no grounds for action; it also recalled that the official “Personal Data Breach Notification Form” established by decision no. 2019/10 must be used in breach notifications.
Why this decision matters
In confirming that the notification process must be conducted in accordance with the procedure (through the official form) even in small-scale breaches, the decision points to a procedural rule that is independent of the size of the breach.
What organisations should watch for
- It is recommended that care be taken to make breach notifications through the Board’s official “Personal Data Breach Notification Form”.
- It is recommended that unauthorised access risks also be monitored regularly in services provided through data processors.
Vircon Legal assessment
No administrative fine was imposed. It is considered that the decision, although small in scale, contains a practical procedural note for data controllers of every size on account of its reminder concerning the notification procedure.
The Board Did Not Characterise an Unproven “Data Has Been Leaked” Allegation as a Breach
Decision no: 2022/1087 · Date: 7 October 2022 · Outcome: No administrative fine
The facts
In the incident under examination, a threatening e-mail alleging that the personal data being processed by the company had been accessed reached a technology company from an unidentified person or persons.
Following the receipt of the e-mail, the company notified the Board of the situation and, at the same time, engaged two separate security firms specialised in the field and initiated a comprehensive penetration test and analysis process on its systems.
What the Board held
The Board established that, as a result of the examination and the penetration tests commissioned by the company, no actual leak or match with the alleged data had been found; it found no grounds for action under art. 12/1.
Why this decision matters
The decision is an instructive but limited example showing that an “allegation” and a “breach” are not the same thing and that, for a threat or an allegation to give rise to an administrative sanction, it must be proven in concrete terms.
What organisations should watch for
- When e-mails containing threats or blackmail are encountered, it is recommended that, rather than acting in panic, the accuracy of the allegation be verified through technical examination (penetration test, log analysis).
- Even in notifications made as a precaution, the fact that the results of the examination carried out have been documented is assessed positively by the Board.
Vircon Legal assessment
No administrative fine was imposed. Although the precedent value of the decision is limited, it is useful in that it constitutes an example of the correct process to be followed against unfounded breach allegations (investigate, verify, document).
Other parts of this series
- Part 1 — Ransomware and Unauthorised Access: Which Technical Measures Does the Board Expect?
- Part 2 — Authentication, Email and Physical Access: The Security Standard in Five Decisions
- Part 3 — Service Provider Related Breaches: Why Does Liability Stay With the Data Controller?
- Part 4 — Breach Notification: Five Decisions on the 72-Hour Deadline, Procedure and Transparency (this article)
- Part 5 — Explicit Consent: Marketing Permissions, Tick Boxes and Service Conditions
- Part 6 — Where Explicit Consent Is Not Required, and the Limits of the Law: Five Decisions
- Part 7 — Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions
- Part 8 — The Proportionality Test: CCTV, Audio, Biometrics, Cookies and Masking
- Part 9 — When Does the Board Take No Action? Five Low-Risk Breach Decisions
- Part 10 — Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries
The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: İhlal Bildirimi: 72 Saatlik Süre, Usul ve Şeffaflık Üzerine Beş Karar.
For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsVircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory
More from Vircon Insights
When Does the Board Take No Action? Five Low-Risk Breach Decisions
August 22, 2026Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions
August 20, 2026Where Explicit Consent Is Not Required, and the Limits of the Law: Five Decisions
August 19, 2026Authentication, Email and Physical Access: The Security Standard in Five Decisions
August 15, 2026Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries
August 23, 2026Can You Answer a KVKK Data Subject Request by Phone? The Authority's 1 October 2026 Announcement
October 1, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →