forumNew topic

Found a data leak — how many hours do I have to report to KVKK? Do I notify my customers at the same time?

EErcan A***Member
Job title
QA Tester
Sector
Catering
Organization type
medium-sized business
Joined
Dec 2023
Message
5
#1

You did your research and found out customer data is leaking. What does KVKK say? Is there really a 72-hour window? Or is it immediate notification? What kind of document do I need to send?

Once I notify KVKK, do I have to notify my customers at the same time? Or should I investigate first and then tell them? Is there a fine if I report late?

Is a data leak considered minor if it's just 'name + email' or major if it's 'credit card'? Do all leaks have to be reported?

FFeyza I***Member
Job title
Regional Manager
Sector
Glass
Organization type
20-person company
Joined
Aug 2024
Message
94
Most Helpful#2

KVKK data breach reporting rules: 1) Reporting deadline: within 72 hours to the Data Protection Board (72-hour notification), 2) Customer notification: If risk of harm per person is high (financial, health, etc.), notify customers simultaneously; if risk is minimal, notify KVKK but customer notification is optional, 3) Reporting content: cause of leak, date of leak, number of affected records, risk assessment, measures taken and to be taken, 4) Minimal risk exception: if encryption or pseudonymization is present (data technically protected), it might not count as a data breach. Example: credit card leak → HIGH RISK (notify individuals); name+email → MEDIUM RISK (assessment needed). Penalty: reporting after 72 hours → Data Protection Board decision (fines between 500-5,000,000 TL possible). Template: KVKK Article 49, Example notification template (from Ministry of Interior presentation). Document publication: official letter, SMS, email (must be kept on record).

MMehmet Ç***MemberCommunity member
Joined
Apr 2023
Message
277
#3

72 hours mandatory to report to KVKK. how to notify customers depends: if credit cards leaked immediately; if name+email leaked, ask for caution. fines are huge man if you report late its millions...

CCeren E***MemberCommunity member
Joined
Apr 2025
Message
95
#4

KVKK Article 49: mandatory personal data breach notification, 72-hour deadline. Risk assessment: data type (sensitivity), encryption status, attack vector. If encrypted/tokenized: low risk, individual notification may not be required. If plain PII + payment data: high risk, mandatory notification. Documentation: notification date, method, recipients, KVKK reference. KVKK forms: breach notification form (VKK website), content template. Penalties: Article 18 (administrative fines), non-compliance 3 million - 50 million TL.

HHaticeMember
Job title
Family business
Organization type
boutique agency
Joined
Jun 2024
Message
86
#5

notify KVKK within 72 hours, don't be late. if customer data like credit card info leaked definitely report it; if just name/email, assess the risk right now. the text must be formal send it via registered mail, specify the date. fines are brutal, millions...

TTuğçe B***MemberCommunity member
Joined
Oct 2025
Message
100
#6

KVKK Data Breach Notification: 1) Confirm the breach (verify it actually happened), 2) Assess the risk (PII type, encryption status attacker access), 3) Inform the data controller (within 72 hours), 4) Inform the data subjects (if high risk), 5) Document (timestamps recipients, response). Risk assessment: PII only (medium), PII + payment (high), encrypted PII (low). Notification template (Ministry of Interior template): nature of the breach, date, scope, corrective measures. Keep records of all communications (proof of notification).

HHakan Ş***New memberCommunity member
Joined
Aug 2026
Message
2
#7

We've heard this a lot, but it never happened like that for us. Processes without records never improve, because you don't know what to fix.

If I were you, I'd go this route.

OOkanMember
Job title
Bookseller
Joined
Jan 2024
Message
71

Doki · Server maintenance contract · 2026

#8

Exactly, and not many people know this... tbh everything goes well for the first three months; problems arise in the fourth.

Of course it varies if your situation is different.

BBurcu B***MemberCommunity member
Joined
Jan 2025
Message
264
#9

I'd appreciate it if you shared the outcome.

NNazlı T***Member
Job title
Social media manager
Sector
Packaging
Organization type
medium-sized business
Joined
Nov 2023
Message
58
#10

Same here.

HHilal D***MemberCommunity member
Joined
Dec 2024
Message
166
#11

Just a heads-up. Everyone rushing into kvkk data breach notification deadline gets stuck at the same point.

Proven by experience.

FFerhat C***MemberCommunity member
Joined
Aug 2024
Message
225
#12

Let me summarize the topic, since several different answers were given. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Of course, it varies if your situation is different.

EElif C***MemberCommunity member
Joined
Feb 2023
Message
374
#13

I'm a small business, let me explain from my side. Trying to do this alone is the most expensive way.

The biggest time-waster for us was not knowing who had the final say. Hope this helps.

LLale K***MemberCommunity member
Joined
Oct 2024
Message
253
#14

Yes, that's exactly how it is with kvkk data breach notification deadline. Just because everyone does it doesn't mean it's right.

When we decide without measuring we always end up in the same place. Good luck with that.

EErcan D***Member
Job title
Administrative manager
Sector
Software
Organization type
two-branch business
Joined
Jul 2022
Message
419
#15

I'll try it.

EEmre A***Member
Job title
Accounting Manager
Sector
E-commerce
Organization type
regional distributor
Joined
Jun 2023
Message
146
#16

I agree. like your time to detect an issue directly determines its cost.

Hope this helps.

RRabia B***ExpertCommunity member
Joined
Mar 2025
Message
232
#17

Exactly like that. When we decide without measuring, we always end up in the same place.

If I were you, I'd go this route.

KKemal G***Expert
Job title
System support specialist
Sector
Cleaning services
Organization type
a company within a holding
Joined
Feb 2024
Message
377

Doki · Log management setup · 2024

#18

Correct. Your time to detect an issue directly determines its cost.

That's all, sorry if I went on too long.

GGökhan K***Member
Job title
Software team lead
Sector
Packaging
Organization type
20-person company
Joined
Feb 2022
Message
207
#19

This thread is archived.

PPerihan T***New memberCommunity member
Joined
Jun 2026
Message
203
#20

There's also a measurement aspect to this. People defend habits, not processes. Resistance comes from there.

Reply