forumNew topic

There was a leak in our customer database, we have to report to the privacy board — how many days do we have?

HHasan K***Member
Job title
Sales Manager
Sector
Healthcare services
Organization type
chain store
Joined
Sep 2024
Message
404
#1

The other day our IT manager said 'there was a leak in the customer database'. Panic started immediately. Legal said 'you have to report to the Privacy Board'. How many days do we have? Who is going to do this?

our db has email, phone, and home address for 5000 customers. idk if the leak exposed all their full names. how long do i have to notify the board? will a fine be enough?

there's no map on the customer side, what happens if someone starts posting 'data leak' on twitter? what if it leaks to the press? how do we manage this?

AAli Y***Member
Job title
Site Manager
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Jan 2024
Message
129
Most Helpful#2

the legal framework for data breach notification is defined in KVKK. briefly: you must notify the Privacy Board within 72 hours of becoming aware of the leak.

as for customers, you are only obligated to notify them without delay if the data leak poses a 'high risk'.

the person making the notification: ideally it should be the Data Protection Officer (DPO); if not, legal counsel can do it. make the notification in writing (email + document).

NNecati A***MemberCommunity member
Joined
Jan 2025
Message
5
#3

72 hours? seems too short, how are we gonna manage to investigate in time?

TTaner Y***Expert
Job title
Regional Manager
Sector
Electrical-electronics
Organization type
cooperative
Joined
Sep 2025
Message
3

Doki · Vulnerability scanning · 2025

#4

do we have to write to each of the 5000 customeers separately or is a site announcement enough? edit: site announcement is enough but notify your insurance too

ZZehra D***Expert
Job title
Administrative manager
Sector
Electrical-electronics
Organization type
two-branch business
Joined
Jul 2024
Message
343
#5

first things to do right now: 1) tell IT to 'find the extent of the leak within 24 hours', 2) notify the lawyer, 3) tell the company's Data Protection Officer. 72 hours is 3 days, move fast!

KKaan Y***Member
Job title
Social media manager
Sector
Furniture manufacturing
Organization type
two-branch business
Joined
Jun 2025
Message
84
#6

besides the 72-hour window who else should know about the leak? if there's no buzz on twitter, are we just not gonna investigate?

VVolkan A***Expert
Job title
Operations director
Sector
Jewelry
Organization type
cooperative
Joined
Nov 2022
Message
314
#7

go to the Privacy Board's website and find the 'data breach notification' section. there's a form there, fill it out. it clearly states which fields are mandatory and which are optional.

KKadir G***MemberCommunity member
Joined
Sep 2022
Message
44
#8

Noted, thanks.

RRecep S***MemberCommunity member
Joined
May 2025
Message
342
#9

Saved.

MMelis A***Member
Job title
Operations manager
Sector
Plastic
Organization type
120-person company
Joined
Feb 2023
Message
94
#10

correct.

SSinan B***Member
Job title
Customer Relations Manager
Sector
Law
Organization type
regional distributor
Joined
Oct 2023
Message
50

Doki · Corporate website · 2024

#11

Do you think this works at any scale? Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

ZZerrinMember
Job title
Wedding planning
Joined
Apr 2024
Message
84
#12

Do you think this works at any scale? Taking measures without an inventory leaves doors you haven't seen open.

KKemal Ö***Member
Job title
Co-founder
Sector
Cleaning services
Organization type
300-person organization
Joined
Oct 2023
Message
28
#13

This thread is archived.

İİlknur E***Member
Job title
Social media manager
Sector
Leather
Organization type
workshop
Joined
Jul 2023
Message
228
#14

My perspective changed after experiencing that. The harder it is to reverse a decision, the slower you should make it.

If I were you, I'd go this route.

EEmine A***MemberCommunity member
Joined
May 2022
Message
254
#15

Let me speak from the other side; I'm on the supplier side. Everyone rushing into data breach notification gets stuck at the same point.

I'm also curious if anyone does it differently.

SSedaNew member
Job title
Teacher · side hustle
Organization type
cooperative
Joined
Oct 2024
Message
42
#16

i have a question, don't want to go off-topic though. btw an untested backup is not a backup.

correct me if Im wrong.

HHasan G***Member
Job title
QA Tester
Sector
Printing
Organization type
cooperative
Joined
Mar 2022
Message
8
#17

I can't fully agree with this. Don't rely on a single measure; go layer by layer.

Hope this helps.

MMetin A***MemberCommunity member
Joined
Jan 2025
Message
160
#18

Saved.

OOnur S***Member
Job title
System support specialist
Sector
Packaging
Organization type
300-person organization
Joined
Jul 2025
Message
14
#19

Here's how it went for us. Taking measures without an inventory leaves doors you haven't seen open.

Of course, it varies if your situation is different.

LLale G***Member
Job title
Call center representative
Sector
Glass
Organization type
chain store
Joined
Feb 2024
Message
172

Doki · E-commerce infrastructure · 2025

#20

The discussion got scattered, let me summarize. Most time waste accumulates in tasks waiting for approval.

Hasty decisions become decisions you have to fix six months later. Hope this helps.

Reply