Legal Roadmap for Companies Facing a Data Breach

Cybersecurity is no longer confined to the technical agenda of the information technology function alone. Data breaches have become a matter of corporate governance that simultaneously triggers board-level liability, regulatory notifications, criminal investigations, compensation claims, contractual recourse, and reputation management. With the entry into force of Cybersecurity Law No. 7545, companies must design their incident-response plans from a multi-authority and multi-layered compliance perspective.
This legal roadmap addresses, in general and staged terms — while acknowledging that each specific incident and attack must be assessed individually — the legal and technical steps that companies should follow in the aftermath of a cyberattack or data leak.
1. Determining the Type of Breach
Just as not every cyber incident constitutes a personal data breach, not every personal data breach necessarily arises from a cyberattack. For example, a denial-of-service attack may constitute a cyber incident without leading to the acquisition of personal data; conversely, the loss of a printed personnel file may amount to a breach under the Personal Data Protection Law (“KVKK”) while not qualifying as a cyber incident within the meaning of Law No. 7545. This distinction determines which authority must be notified and which time limit will run.
The initial legal classification should be carried out under at least four headings:
- Have the personal data been obtained by others through unlawful means? In this case, the notification regime under Article 12/5 of the KVKK comes into play.
- Does the incident qualify as a “cyber incident” involving a breach of the confidentiality, integrity, or availability of information systems or data, or as an identified “vulnerability”? In this case, the notification obligation under Law No. 7545 must be assessed separately.
- Is the company subject to sector-specific regulation, such as banking, payment services, electronic communications, insurance, healthcare, energy, or critical infrastructure? Additional notifications to the relevant regulatory authorities may be required.
- Does the incident affect data subjects, group companies, or foreign customers located abroad? Applicable foreign data protection and cybersecurity regulations must also be examined.
2. Mapping the Areas of Liability
In data breach management, a single incident may simultaneously trigger the following areas of liability:
- Administrative and regulatory liability: Notification, cooperation, and audit obligations may arise before the Personal Data Protection Board, the Cybersecurity Presidency, and, depending on the nature of the incident, sector-specific regulatory authorities.
- Criminal law dimension: Risks may arise both in connection with the company’s application as an injured party against the attackers and with respect to the responsible natural persons who acted with fault or intent in the incident. Under Turkish criminal law, criminal liability rests with natural persons; for legal entities, the security measures provided for by law, together with administrative and private law consequences, may come into play.
- Private law liability: Claims for pecuniary and non-pecuniary damages, as well as contractual liabilities, may be asserted by data subjects, customers, employees, and business partners.
- Corporate governance liability: The oversight and duty of care of the management bodies, deficiencies in internal controls, and post-incident accountability may come to the fore.
- Commercial and contractual consequences: Service-level breaches, confidentiality undertakings, customer notifications, supplier recourse claims, cyber insurance policy conditions, and notification obligations under financing agreements may need to be assessed.
3. Pre-Breach Preparation
In terms of Board decisions and practice, what proves decisive is not only the measures taken after an incident, but also the security and governance architecture established before the breach. The defense that “the necessary technical and administrative measures were taken” must be supported not by policy documents drawn up after the incident, but by employee records, drill results, authorization matrices, log policies, risk analyses, supplier audits, and management decisions.
In practice, companies are advised to put in place at least the following structure before an incident occurs:
- An incident-response team composed of representatives from legal, information security, information technology, human resources, internal audit, corporate communications, and senior management, with a clear allocation of duties.
- A written escalation and notification protocol specifying who reports which incident, within how many hours, and through which channel.
- Procedures governing the integrity of evidence, log retention periods, backups, access rights, and chain of custody.
- In data processor and supplier agreements, internal notification periods shorter than the statutory time limit, together with audit, log-sharing, digital forensics support, subcontractor, and recourse provisions.
- At least one tabletop exercise per year and technical scenario studies for critical systems; a SOME (Cyber Incident Response Team) structure where the field of activity or sector-specific legislation so requires, and, in other companies, a functionally equivalent incident-response organization.
- Where a cyber insurance policy is in place, prior determination of which incidents are to be notified to the insurer, within which period and by which procedure, and which service providers are subject to prior approval.
4. Phase 1: Halting the Spread Without Destroying the Evidence
When a breach is detected, the first objective is to limit the spread of the harm. However, the response undertaken for this purpose must not eliminate the digital evidence required for the investigation and the defense. Formatting devices in panic, resetting systems, overwriting logs, or deleting malware without a trace makes it difficult to determine the source and duration of the attack and the affected data set. For this reason, the response should, where possible, be carried out in coordination with the legal team and with the support of an independent digital forensics expert.
During the initial response, records such as the following should be secured with time stamps: security alerts; access and transaction logs; cloud service records; IP and user information; e-mail headers; session and authorization changes; malicious file samples; screenshots; backup statuses; and an incident log showing by whom and at what time each response was carried out.
In addition, the time at which the technical alarm was received and the moment at which the data controller became aware of the breach must be recorded separately. The examination process must not be used to postpone the notification period artificially; once sufficient certainty has been established, the legal assessment and the preparation of the notification must be commenced immediately.
Practical Timing for the First 72 Hours
- First stage: establishing the crisis desk, limiting the spread, freezing the evidence, ensuring the secure continuity of critical services, and starting the incident log.
- Second stage: preliminary assessment of the affected system, data category, group of persons, and geographic scope; determination of the data controller/data processor roles; and review of contractual, insurance, and sectoral notification obligations.
- Third stage: preparation of the KVKK notification form and, where necessary, submission of the initial/staged notification; fulfillment of the “without delay” notification standard vis-à-vis the Cybersecurity Presidency and other authorities; approval of the data subject communication plan; and documented briefing of the management body.

