Legal Roadmap for Companies Facing a Data Breach

Cybersecurity is no longer confined to the technical agenda of the information technology function alone. Data breaches have become a matter of corporate governance that simultaneously triggers board-level liability, regulatory notifications, criminal investigations, compensation claims, contractual recourse, and reputation management. With the entry into force of Cybersecurity Law No. 7545, companies must design their incident-response plans from a multi-authority and multi-layered compliance perspective.
This legal roadmap addresses, in general and staged terms — while acknowledging that each specific incident and attack must be assessed individually — the legal and technical steps that companies should follow in the aftermath of a cyberattack or data leak.
1. Determining the Type of Breach
Just as not every cyber incident constitutes a personal data breach, not every personal data breach necessarily arises from a cyberattack. For example, a denial-of-service attack may constitute a cyber incident without leading to the acquisition of personal data; conversely, the loss of a printed personnel file may amount to a breach under the Personal Data Protection Law (“KVKK”) while not qualifying as a cyber incident within the meaning of Law No. 7545. This distinction determines which authority must be notified and which time limit will run.
The initial legal classification should be carried out under at least four headings:
  • Have the personal data been obtained by others through unlawful means? In this case, the notification regime under Article 12/5 of the KVKK comes into play.
  • Does the incident qualify as a “cyber incident” involving a breach of the confidentiality, integrity, or availability of information systems or data, or as an identified “vulnerability”? In this case, the notification obligation under Law No. 7545 must be assessed separately.
  • Is the company subject to sector-specific regulation, such as banking, payment services, electronic communications, insurance, healthcare, energy, or critical infrastructure? Additional notifications to the relevant regulatory authorities may be required.
  • Does the incident affect data subjects, group companies, or foreign customers located abroad? Applicable foreign data protection and cybersecurity regulations must also be examined.
2. Mapping the Areas of Liability
In data breach management, a single incident may simultaneously trigger the following areas of liability:
  • Administrative and regulatory liability: Notification, cooperation, and audit obligations may arise before the Personal Data Protection Board, the Cybersecurity Presidency, and, depending on the nature of the incident, sector-specific regulatory authorities.
  • Criminal law dimension: Risks may arise both in connection with the company’s application as an injured party against the attackers and with respect to the responsible natural persons who acted with fault or intent in the incident. Under Turkish criminal law, criminal liability rests with natural persons; for legal entities, the security measures provided for by law, together with administrative and private law consequences, may come into play.
  • Private law liability: Claims for pecuniary and non-pecuniary damages, as well as contractual liabilities, may be asserted by data subjects, customers, employees, and business partners.
  • Corporate governance liability: The oversight and duty of care of the management bodies, deficiencies in internal controls, and post-incident accountability may come to the fore.
  • Commercial and contractual consequences: Service-level breaches, confidentiality undertakings, customer notifications, supplier recourse claims, cyber insurance policy conditions, and notification obligations under financing agreements may need to be assessed.
3. Pre-Breach Preparation
In terms of Board decisions and practice, what proves decisive is not only the measures taken after an incident, but also the security and governance architecture established before the breach. The defense that “the necessary technical and administrative measures were taken” must be supported not by policy documents drawn up after the incident, but by employee records, drill results, authorization matrices, log policies, risk analyses, supplier audits, and management decisions.
In practice, companies are advised to put in place at least the following structure before an incident occurs:
  • An incident-response team composed of representatives from legal, information security, information technology, human resources, internal audit, corporate communications, and senior management, with a clear allocation of duties.
  • A written escalation and notification protocol specifying who reports which incident, within how many hours, and through which channel.
  • Procedures governing the integrity of evidence, log retention periods, backups, access rights, and chain of custody.
  • In data processor and supplier agreements, internal notification periods shorter than the statutory time limit, together with audit, log-sharing, digital forensics support, subcontractor, and recourse provisions.
  • At least one tabletop exercise per year and technical scenario studies for critical systems; a SOME (Cyber Incident Response Team) structure where the field of activity or sector-specific legislation so requires, and, in other companies, a functionally equivalent incident-response organization.
  • Where a cyber insurance policy is in place, prior determination of which incidents are to be notified to the insurer, within which period and by which procedure, and which service providers are subject to prior approval.
4. Phase 1: Halting the Spread Without Destroying the Evidence
When a breach is detected, the first objective is to limit the spread of the harm. However, the response undertaken for this purpose must not eliminate the digital evidence required for the investigation and the defense. Formatting devices in panic, resetting systems, overwriting logs, or deleting malware without a trace makes it difficult to determine the source and duration of the attack and the affected data set. For this reason, the response should, where possible, be carried out in coordination with the legal team and with the support of an independent digital forensics expert.
During the initial response, records such as the following should be secured with time stamps: security alerts; access and transaction logs; cloud service records; IP and user information; e-mail headers; session and authorization changes; malicious file samples; screenshots; backup statuses; and an incident log showing by whom and at what time each response was carried out.
In addition, the time at which the technical alarm was received and the moment at which the data controller became aware of the breach must be recorded separately. The examination process must not be used to postpone the notification period artificially; once sufficient certainty has been established, the legal assessment and the preparation of the notification must be commenced immediately.
Practical Timing for the First 72 Hours
  • First stage: establishing the crisis desk, limiting the spread, freezing the evidence, ensuring the secure continuity of critical services, and starting the incident log.
  • Second stage: preliminary assessment of the affected system, data category, group of persons, and geographic scope; determination of the data controller/data processor roles; and review of contractual, insurance, and sectoral notification obligations.
  • Third stage: preparation of the KVKK notification form and, where necessary, submission of the initial/staged notification; fulfillment of the “without delay” notification standard vis-à-vis the Cybersecurity Presidency and other authorities; approval of the data subject communication plan; and documented briefing of the management body.
5. Phase 2: The Notification Regime
5.1. Notification to the Personal Data Protection Board
Pursuant to Article 12/5 of the KVKK, where processed personal data are obtained by others through unlawful means, the data controller is obliged to notify the data subject and the Board as soon as possible. Pursuant to the Personal Data Protection Board’s Decision No. 2019/10 dated 24 January 2019, notification to the Board must be made without delay and within 72 hours at the latest from the moment the breach is learned of.
The 72-hour period is not a waiting period; it is a maximum period. Where the full details of the incident have not yet become clear, an initial notification may be made on the basis of the verified information available, and new findings may be supplemented without delay through staged notifications. Where the 72-hour period is exceeded for a justified reason, the reason for the delay must be explained together with the notification.
5.2. Notification to Data Subjects
Pursuant to the Personal Data Protection Board’s Decision No. 2019/10 dated 24 January 2019, once the persons affected by the breach have been identified, notification must be made within the shortest reasonable time and in clear, plain, and guiding language. Where contact information is available, direct notification is the rule; where direct access is not possible, appropriate methods such as the company’s website may be used.
This notification should address matters such as when the breach occurred; which personal data were affected by the breach, on the basis of personal data categories (drawing a distinction between personal data and special categories of personal data); the likely consequences of the personal data breach; the measures taken or recommended to be taken in order to mitigate the adverse effects of the breach; and the names and contact details of the contact persons who will enable data subjects to obtain information about the breach, or the full address of the data controller’s web page, its call center, and similar means of contact. Moreover, the notification should not be a mere legal formality but should also contain practical recommendations enabling the data subject to mitigate their harm; for example, incident-related measures such as renewing passwords, cancelling cards, remaining vigilant against phishing messages, or monitoring account activity should be explained.
5.3. Notification to the Cybersecurity Presidency
Cybersecurity Law No. 7545 requires those who provide services, collect data, or process data using information systems to notify the Cybersecurity Presidency, without delay, of any vulnerabilities or cyber incidents detected in their field of service. The criterion laid down for this obligation under the Law is that action be taken “without delay.”
The important nuance is this: not every KVKK breach automatically gives rise to a notification to the Cybersecurity Presidency. The notification obligation depends on the incident also qualifying as a vulnerability or cyber incident within the scope of Law No. 7545. Conversely, a cyber incident may be subject to notification under Law No. 7545 even where it does not result in the acquisition of personal data. The channel and content of the notification should be determined by separately verifying the applicable current secondary legislation, the Presidency’s announcements, and sectoral procedures.
5.4. Sectoral, Contractual, and Cross-Border Notifications
For companies operating in the fields of banking, payment services, electronic communications, insurance, healthcare, and critical infrastructure, additional notification obligations to regulatory authorities, sectoral incident-response structures, or public authorities may arise. Likewise, agreements with customers and business partners, financing documents, data processing agreements, and cyber insurance policies may provide for periods shorter than the statutory notifications.
For companies operating internationally, where the incident affects data subjects in the European Union or in other countries, foreign authority notifications and intra-group crisis protocols must be assessed simultaneously. Accordingly, the document to be prepared in the first hours is not merely a KVKK form, but an incident-specific notification matrix.
6. Phase 3: The Criminal Law Process with the Company as the Injured Party
A cyberattack may also give rise to a situation in which the company is the injured party for the purposes of criminal law. Depending on the nature of the specific incident, the following provisions may come into play: unlawful access to an information system (Article 243 of the Turkish Criminal Code (“TCK”)); hindering or disrupting the system, or destroying or altering data (TCK Art. 244); unlawfully giving, disseminating, or seizing personal data (TCK Art. 136); misuse of bank or credit cards (TCK Art. 245); qualified fraud in which information systems are used as an instrument (TCK Art. 158/1-f); and the provisions on threat and blackmail.
In this context, an effective criminal investigation is important for identifying the perpetrator, limiting the spread of the data, securing the evidence through the official authorities, and the subsequent compensation and recourse processes. An application to the Chief Public Prosecutor’s Office or to law enforcement units should be supported by verified IP/URL information, forensic copies of the logs, hash values, time-stamped screenshots, ransom correspondence, an incident chronology, and a preliminary technical report.
Prior to, or simultaneously with, the criminal complaint, measures to prevent the dissemination and alteration of the evidence should also be considered. In this regard, where leaked content has been published on the internet, in-platform removal processes, the identification of evidence, interim injunctions, the protection of the privacy of private life, and access-restriction remedies specific to criminal content should be assessed separately according to the specific content and the legislation in force.
7. Phase 4: Documentation and Third-Party Management
The most important output of a well-managed breach is a consistent and auditable set of records covering the incident from beginning to end. The incident log should include the time of detection, the decisions taken, the basis for each decision, the persons carrying out the response, the systems shut down, the evidence preserved, the notifications made, the communication texts, and the corrective actions.
Public statements, customer e-mails, employee announcements, and official notifications should rest on the same factual core. Matters that have not yet been verified should not be presented as established fact; conversely, matters that are known and must be disclosed should not be withheld. Communication texts should be jointly approved by the legal and technical teams.
Where the breach originates from a cloud provider, software firm, call center, payroll service, e-mail service, or another data processor/supplier, it is important to address the following matters without delay: the contractual notification obligation, access to logs and evidence, digital forensics cooperation, the subcontractor chain, the limits of liability, compensation and recourse rights, service continuity, and insurance notification.
8. Phase 5: Defense and Administrative Litigation
Once an administrative review begins, the defense should center on the following: that the pre-incident measures were proportionate to the risk; that the incident was detected in a timely manner; that the response was conducted in a controlled manner; that the notifications were made within the applicable time limits; and that measures to prevent recurrence have been implemented.
An action may be brought before the administrative courts against administrative fines imposed by the Personal Data Protection Board. Unless a specific period is provided, the general period for bringing an action is 60 days from the date of notification. The administrative judicial remedy is likewise available against administrative fines imposed by the Cybersecurity Presidency; in addition, pursuant to Law No. 7545, a 30-day period from the date of notification is provided for the submission of a defense prior to the imposition of a sanction.
9. Sanction Outlook as of 2026
Under the KVKK, where the obligations relating to data security are not fulfilled, the range of administrative fines for 2026 is between TRY 256,357 and TRY 17,092,242. The failure to make, or the late making of, a breach notification is likewise assessed within the framework of the data security obligations under Article 12 of the KVKK. Where different obligations are breached in the course of the same incident, it is possible for the acts to be assessed separately and for the sanction risk to increase accordingly.
The fixed administrative fines under Cybersecurity Law No. 7545 are also updated within the framework of the revaluation provisions. Taking into account the 2026 revaluation rate, the fine range for failing to take cybersecurity measures, or for failing to notify a detected vulnerability/cyber incident without delay, stands between TRY 1,254,900 and TRY 12,549,000. For breaches of audit obligations, a fine of between TRY 125,490 and TRY 1,254,900 applies; for commercial companies, a sanction of up to 5% of the audited annual gross sales revenue — but not less than the lower limit — may come into play.
Where a benefit is obtained, or damage is caused, as a result of an act contrary to the Law, the administrative fine may be set at no less than three times and no more than five times the benefit or the damage. In addition, Law No. 7545 also provides for terms of imprisonment in respect of acts such as the failure to provide information and documents, unauthorized activity, breach of the confidentiality obligation, unlawfully making leaked data accessible or selling it, and serious acts targeting critical infrastructure.
In addition to the foregoing, data subject compensation, mass customer loss, service interruption, contractual penalties, digital forensics expenses, notification and call center costs, loss of business continuity, and reputational damage may also arise as financial risks.
In conclusion, the effective management of data breaches consists not merely of fulfilling the statutory notifications within the applicable time limits, but also of being prepared before the breach, conducting the technical and legal response in a coordinated manner at the time of the incident, preserving the evidence, establishing consistent communication with the relevant parties, and implementing lasting corrective measures after the incident. It is of critical importance that companies establish an incident-response and notification mechanism tailored to their own circumstances — in line with their fields of activity, the nature of the data they process, the sector-specific regulations to which they are subject, and their contractual obligations — both in order to limit administrative, criminal, and private law risks and in order to protect corporate reputation and business continuity.