When a news website's subscriber list, comment database or admin panel is compromised, the first question asked is always the same: “Within how many hours do I have to notify?” The most important finding of this article is this: there is no numerical deadline in the text of Personal Data Protection Law No. 6698 (“KVKK”). Article 12(5) says only “as soon as possible”; no figure appears, in hours or in days. Below we give the whole of Article 12 word for word, clarify who the notification goes to, and list the operational steps to follow at the moment of a breach.

Data security obligations — Article 12 of KVKK, word for word

Obligations relating to data securityARTICLE 12- (1) The data controller is obliged to take all necessary technical and administrative measures to provide an appropriate level of security, for the purpose of; a) preventing the unlawful processing of personal data, b) preventing unlawful access to personal data, c) ensuring the retention of personal data.”

“(2) Where personal data are processed on behalf of the data controller by another natural or legal person, the data controller is jointly responsible with those persons for taking the measures set out in the first paragraph.”

“(3) The data controller is obliged to carry out, or have carried out, the necessary audits within its own institution or organisation in order to ensure the implementation of the provisions of this Law.”

“(4) Data controllers and persons who process data may not disclose the personal data they learn to others contrary to the provisions of this Law, nor use them outside the purpose of processing. This obligation continues after they leave their post.

The last sentence of the fourth paragraph matters particularly for news organisations: the duty of confidentiality of a departing editor, reporter or system administrator continues after they leave. That calls not only for revoking access in your exit procedure, but also for a written reminder.

Breach notification — Article 12(5), word for word

(5) Where the processed personal data are obtained by others by unlawful means, the data controller shall notify this situation to the person concerned and to the Board as soon as possible. The Board may, if necessary, announce this situation on its own website or by another method it deems appropriate.

This single-sentence paragraph constitutes the whole of the notification regime. Four elements can be drawn out of it.

  • The triggering event: “the processed personal data are obtained by others by unlawful means”. Not only an attack from outside; an unauthorised employee copying data, a bulk email sent to the wrong recipient, or the download of a backup left exposed may also fall within that definition.
  • Who is obliged: the data controller. Even if the leak happens at your supplier, you are the one obliged to notify; under Article 12(2) the responsibility is joint.
  • There are two addressees: both “the person concerned”, that is the data subject, and the Board. Doing one of the two is not enough.
  • Deadline: “as soon as possible”. There is no other measure of time in the paragraph.

There are two addressees: the data subject and the Board

The most frequent mistake in practice is to notify only the Board and skip the data subjects. Article 12(5) says “to the person concerned and to the Board”; the conjunction is not “or”. Both notifications must be made.

AddresseeLegal basisWhat it covers
The data subject (the person whose data leaked)Art. 12(5) — “to the person concerned”Notification of the breach affecting them
The Personal Data Protection BoardArt. 12(5) — “and to the Board”Notification of the breach to the official authority
The publicArt. 12(5), last sentenceIf the Board deems it necessary, it may announce it on its own website or by another method it deems appropriate

The last row is important: the decision to announce to the public is at the discretion of the Board, not yours. Delaying notification out of the fear that “our reputation will suffer if it is announced” both breaches Article 12(5) and increases the risk under Article 18(1)(b).

Other obligations arising after a breach

Notification alone is not enough. A breach triggers a chain of further obligations.

  • Art. 12(1) — Closing the vulnerability that led to the breach and restoring an appropriate level of security.
  • Art. 12(3) — Carrying out, or having carried out, the necessary audits within the organisation.
  • Art. 13(2) — Concluding applications from data subjects free of charge within thirty days at the latest.
  • Art. 15(3) — Sending the information and documents requested by the Board within the scope of its examination within fifteen days, and where necessary allowing an on-site examination.
  • Art. 15(5) — Implementing the Board's decision on remedying the breach without delay and within thirty days at the latest.
  • Art. 11(1)(ğ) — The right of a person who suffers damage because of unlawful processing to claim compensation; this right does not disappear in any case of exemption.

Do not overlook Article 15(7) either: “Where losses that are difficult or impossible to compensate arise and there is manifest unlawfulness, the Board may decide to suspend the processing of data or the transfer of data abroad.” In a serious breach, the possibility of the activity being halted is on the table.

Operational checklist

The list below is not a procedure enumerated word for word in the Law; it is an operational flow suggested as a way of reaching the outcomes Article 12 requires. Adapt it to your own organisation and have it ready now, not at the moment of a breach.

text
DATA BREACH RESPONSE CHECKLIST
(operational suggestion — not a procedure enumerated in the Law)

INCIDENT NO: ..........  DETECTED AT (DATE-TIME): ...........
INCIDENT OWNER: ......................................

--- 1. DETECTION AND CONTAINMENT ---
[ ] The moment the incident was first noticed recorded (date-time)
[ ] Noticed by (person / system): ....................
[ ] Ongoing access cut off
    (sessions terminated, keys revoked, passwords reset,
     open endpoints closed)
[ ] Evidence preserved (logs, images, backups — NO deletion)

--- 2. DETERMINING THE SCOPE ---
[ ] Which systems were affected: ......................
[ ] Which data categories leaked:
    [ ] identity  [ ] contact    [ ] membership/subscription
    [ ] password hashes          [ ] payment data
    [ ] IP / session logs        [ ] comment content
    [ ] SPECIAL CATEGORY DATA (KVKK Art. 6(1)) — tick if any
[ ] How many data subjects affected (approximate): ....
[ ] Did the data go abroad: yes / no
[ ] Can the affected persons be listed: yes / no

--- 3. RECORD ---
[ ] Incident record form completed
[ ] Timeline created
    (breach start - detection - containment - notification)
[ ] Every action taken recorded with date and time
[ ] Decision-makers and their reasoning written down

--- 4. NOTIFICATION  [basis: KVKK Art. 12(5)] ---
[ ] Notification made to THE BOARD
    Date-time: ..........  Reference: ..............
[ ] Notification made to THE DATA SUBJECTS
    Method: e-mail / site announcement / ...........
    Date-time: ....................................
    NOTE: Art. 12(5) names both addressees — one is not enough.
[ ] The notification text contains:
    - when and how the breach occurred
    - which data categories were affected
    - the measures taken and to be taken
    - a contact channel for applications
[ ] The Board's power to announce to the public noted
    (Art. 12(5), last sentence — the decision is the Board's)

--- 5. MANAGING APPLICATIONS ---
[ ] A channel opened for incoming applications
[ ] The 30-day response period put under tracking [Art. 13(2)]
[ ] The 15-day information-and-document period tracked [Art. 15(3)]

--- 6. REMEDIATION  [basis: Art. 12(1), Art. 12(3)] ---
[ ] Root cause analysis completed
[ ] Vulnerability closed and verified
[ ] Supplier contracts reviewed             [Art. 12(2)]
[ ] Access rights reorganised
[ ] Added to the audit plan                 [Art. 12(3)]
[ ] Inventory and destruction policy updated
[ ] Staff briefed                           [Art. 12(4)]

DEADLINE WARNING: KVKK Art. 12(5) says only "as soon as
possible". There is NO deadline in hours or days in the Law.
The period to be applied has been determined by Board decision
— verify the current period and the notification form with the
Authority.

Preparation before a breach: the most effective measure

Article 12(1) says “to take all necessary technical and administrative measures”. When a breach occurs, what will be assessed is not only the breach itself but the adequacy of the measures taken beforehand. For news websites the preparation items that make the greatest difference in practice are these:

  • Protecting access to the admin panel with multi-factor authentication and limiting privileges on a role basis.
  • Keeping database backups encrypted and managing access to backups with a separate set of privileges.
  • Keeping audit logs that answer the question of who accessed which data and when, and setting the log retention period down in writing.
  • Putting the data processor relationship with suppliers (hosting, email delivery, measurement) in writing — responsibility under Article 12(2) is joint.
  • Keeping the inventory up to date: the scope-determination step can be completed within minutes only if you know which data is where.

The fifth item is the one most often skipped. We gave a template for drawing up the inventory in the article on the VERBİS registration obligation. Once you have set the retention periods down in writing, you can read the affected data set in a breach from the very same document.

Sanctions

Article 18(1)(b) of KVKK: an administrative fine “from 15,000 Turkish lira to 1,000,000 Turkish lira” is imposed on “those who fail to comply with the obligations relating to data security provided for in Article 12”. Because the notification obligation is regulated in the fifth paragraph of Article 12, it falls within this subparagraph.

Article 18(1)(c): an administrative fine “from 25,000 Turkish lira to 1,000,000 Turkish lira” is imposed on “those who fail to implement the decisions taken by the Board pursuant to Article 15”. Under Article 18(2) as amended by Law No. 7499 these fines are applied to the data controller; Article 18(3) determines the avenue of appeal as the administrative court.

Furthermore, under Article 17(1), “as regards offences relating to personal data, the provisions of Articles 135 to 140 of the Turkish Penal Code No. 5237 of 26/9/2004 shall apply.” In other words criminal liability is established not within Law No. 6698 itself but by reference to the Penal Code. And under Article 14(3) the right of those whose personal rights are violated to claim compensation under the general provisions is reserved in any event.

Finally: a data breach rarely comes alone. If the leaked data spreads across the internet, content removal request processes and right to be forgotten applications also come onto the agenda. Review your site's overall compliance position regularly through the legal compliance checklist for internet news sites; and build the privacy notice and application infrastructure you will need at the moment of a breach in advance, using the template in the article on the privacy notice.