Administrative Fines and Company Liability in Case of Violation of the Personal Data Protection Law (KVKK)
Entrance
The protection of personal data is not merely a compliance procedure for companies, but a significant risk area with direct financial and legal consequences. Today, almost every company processes a large amount of personal data, including customer information, employee files, camera recordings, website cookies, email lists, billing records, call center records, shipping information, health reports, IP addresses, and payment information. Failure to process, store, transfer, or destroy this data lawfully may result in administrative fines, board decisions, compensation lawsuits, and even criminal investigations under the Law No. 6698 on the Protection of Personal Data.
In practice, when violations of the Personal Data Protection Law (KVKK) are mentioned, only "data leakage" is often understood. However, administrative fines are not only applied in cases of data leakage. Failure to fulfill the obligation to inform, failure to take technical and administrative measures regarding data security, failure to implement Board decisions within the specified time, violation of VERBİS registration and notification obligations, or violation of notification obligations in data transfers abroad can also lead to administrative fines. In its announcement dated December 31, 2025, the Personal Data Protection Authority stated that the administrative fines in Article 18 of Law No. 6698 are increased annually according to the revaluation rate, and the increased amounts for the years 2017-2026 have been published.
Therefore, for companies, compliance with the Personal Data Protection Law (KVKK) is not simply a matter of adding a few texts to their website. The company's actual data processing activities, data inventory, information notices, explicit consent processes, retention and destruction policies, VERBİS (Data Protection and Information System) obligations, data security measures, employee training, contracts with third-party service providers, and data breach response plans must all be considered together.
What is a GDPR administrative fine?
The KVKK (Personal Data Protection Law) administrative fine is an administrative sanction imposed by the Personal Data Protection Board on data controllers who violate the obligations stipulated in Law No. 6698. These fines are not judicial fines imposed by criminal courts. Administrative fines are imposed as a result of the Board's investigation and come into play when a company violates its data protection obligations.
In most cases, the primary responsible party under the KVKK (Turkish the data controller. The data controller is the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system. An e-commerce company, hospital, clinic, hotel, software company, human resources company, educational institution, insurance company, bank, law firm, or employer can be the data controller, depending on the specific circumstances.
The crucial point for companies is this: excuses such as "the data is with the accountant," "the website is managed by an agency," "server services are outsourced," "the employee sent it by mistake," or "the shipping company made a mistake" do not always absolve them of responsibility. The Personal Data Protection Authority states that, within the scope of data security obligations, the data controller must take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data and to ensure the preservation of the data; and that even if the data is processed by other individuals or companies on their behalf, the data controller may be jointly liable with the data processor for these measures.
Therefore, companies' responsibility under the Personal Data Protection Law (KVKK) is not limited solely to internal personnel. Call centers, software companies, accounting firms, shipping companies, cloud service providers, advertising agencies, human resources consultants, or security companies that process data on behalf of the company are also part of the data processing ecosystem. The data controller company must oversee how these third parties process and protect personal data.
2026 GDPR Administrative Fine Amounts
Administrative fines under the Personal Data Protection Law (KVKK) are increased annually according to the revaluation rate. The table published by the Authority for 2026 shows the revaluation rate as 25.49%. The prominent administrative fine ranges as of 2026 are as follows:
| Type of Deviance | Administrative Fine Range 2026 |
|---|---|
| Failure to fulfill the obligation to provide information | 85,437 TL – 1,709,200 TL |
| Failure to fulfill data security obligations | 256,357 TL – 17,092,242 TL |
| Failure to comply with board decisions | 427,263 TL – 17,092,242 TL |
| Violation of VERBİS registration and notification obligations | 341,809 TL – 17,092,242 TL |
| Failure to fulfill the notification obligation stipulated in Article 9, paragraph 5 of the Law | 90,308 TL – 1,806,177 TL |
These amounts can have very serious financial consequences for companies. Especially considering that the upper limit exceeds 17 million TL for data security violations, non-compliance with the Board's decision, and breaches of VERBİS obligations, it shows that the KVKK compliance process is no longer a formality that can be postponed. Furthermore, administrative fines alone do not represent the ultimate risk. Individuals may file compensation lawsuits for the same incident, the data breach may become public knowledge, the company's reputation may be damaged, and depending on the nature of the incident, a criminal investigation under the Turkish Penal Code may be initiated.
Violation of the Obligation to Inform
One of the most common risks companies face under the Personal Data Protection Law (KVKK) is the incomplete or incorrect fulfillment of the obligation to inform. The obligation to inform requires providing the data subject, whose personal data is being processed, with information about who is processing their data, for what purpose, on what legal grounds, to whom it may be transferred, the method of collection, and their rights. The Authority explicitly states that the data controller is obligated to inform the data subject at the time of data collection; this obligation continues regardless of whether data processing is based on explicit consent or another processing condition stipulated in the Law.
A breach of the obligation to inform is not only caused by the complete absence of text. The risk also arises if the text is general, unclear, copied from another company, outdated, does not reflect the data processing activity, or does not indicate the legal basis. For example, a single-sentence statement from an e-commerce site such as "Your personal data is processed under the KVKK (Personal Data Protection Law)" is insufficient. It must clearly indicate which data is processed for order, payment, invoicing, delivery, customer service, or marketing purposes.
Confusing the information provided with the explicit consent form is a significant mistake. Information provided is informing the data subject; explicit consent is giving approval for a specific data processing activity. Companies should avoid general and collective statements such as, "I have read the KVKK (Personal Data Protection Law) text and I consent to the processing of all my personal data." If the obligation to provide information is not fulfilled correctly, the explicit consent process also becomes questionable. For the year 2026, the administrative fine that can be applied for a violation of the obligation to provide information ranges from 85,437 TL to 1,709,200 TL.
Violation of Data Security Obligations
One of the highest administrative fine risks under the Personal Data Protection Law (KVKK) is the breach of data security obligations. The data controller is obligated to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the preservation of personal data. The Authority states that necessary technical and administrative measures must be taken to ensure an appropriate level of security for the fulfillment of these obligations.
A data security breach doesn't only mean a cyber attack. Other examples include granting unauthorized personnel access to customer lists, failing to revoke system access for former employees, storing health records in shared folders, allowing public viewing of camera recordings, storing customer data on personal phones, sending sensitive data via unsecured email, lack of backups, failure to maintain log records, and not establishing an explicit consent mechanism or contracting with data processing companies when using cookies.
Companies must take both technical and administrative measures regarding data security. Technical measures include access authorization, password policies, two-factor authentication, antivirus software, firewalls, log management, encryption, backups, network security, penetration testing, and data loss prevention systems. Administrative measures include GDPR policies, employee training, confidentiality agreements, data processor contracts, authorization matrices, data inventory, breach response plans, retention and destruction policies, and regular internal audits.
The organization also emphasizes that data security measures should be determined in accordance with the structure, activities, and risks of each data controller. In other words, the scope of measures that a small consulting firm and a large hospital processing health data should take may not be the same; however, both should establish a reasonable and effective level of security appropriate to their own risks.
As of 2026, the administrative fines that can be applied for failure to fulfill data security obligations range from 256,357 TL to 17,092,242 TL. Therefore, data security is the most critical aspect of the GDPR compliance process.
Data Breach Reporting and Companies' Liability to Report
If personal data is obtained by others through unlawful means, the data controller is obliged to notify the data subject and the Personal Data Protection Board as soon as possible. The Board states that, within the scope of data security obligations, data breaches must be reported, and the Board may announce this on its website or by another method it deems appropriate.
Data breach reporting is one of the areas where companies are most often delayed. Unauthorized access to a company's system, sending customer information to the wrong person, email recipients seeing each other's information, an employee exporting the customer list, customer information being found on a stolen laptop, or incorrect authorization in a cloud system can all lead to a data breach. In such a case, the first thing a company should do is not hide the incident, but determine the scope of the breach, the number of affected individuals, the data categories, the consequences of the breach, and the measures taken.
Companies are more likely to make wrong decisions during a crisis if they lack a data breach response plan. It should be predetermined which department will be notified, how the legal and IT teams will work together, what information will be collected for notification to the Board, how relevant individuals will be notified, and how evidence will be preserved. Otherwise, poor management after a breach can create additional liability, in addition to the breach itself.
Failure to Implement Board Decisions
The Personal Data Protection Board may conduct an investigation upon receiving a complaint or upon learning of an alleged breach. If a breach is found as a result of the investigation, it will decide on the remedy of the illegality and notify the data controller of this decision. The Board states that the data controller is obliged to comply with the Board's decision without delay and within a maximum of thirty days from the date of notification.
Failure to comply with the Board's decisions is, in itself, grounds for a separate administrative fine. For example, the Board may have decided to cease unlawful data processing activities, correct inaccurate data, respond to the data subject, implement data security measures, or correct the information texts. If the data controller fails to implement this decision within the specified time, they face the risk of sanctions not only for the initial violation but also for non-compliance with the Board's decision.
For the year 2026, the administrative fine that can be applied for non-compliance with the Board's decisions ranges from 427,263 TL to 17,092,242 TL. The high range of these fines indicates that the Board's decisions must be implemented seriously and on time by companies.
Violation of VERBİS Registration and Notification Obligation
VERBİS is the Data Controllers Registry Information System. Data controllers meeting certain criteria are required to register with VERBİS and submit notifications regarding their personal data processing activities. The Authority's announcement regarding the Data Controllers Registry states that, in accordance with Article 16 of Law No. 6698, natural and legal persons who process personal data as data controllers are obliged to register with the Data Controllers Registry before commencing data processing.
The VERBİS (Personal Data Protection Law) obligation is particularly important for medium and large-sized companies, as well as businesses that process special categories of personal data. However, the most common mistake companies make is thinking, "If we don't have a VERBİS registration, we are not subject to the KVKK (Personal Data Protection Law)." Being exempt from VERBİS registration does not mean being completely exempt from the KVKK. Obligations such as informing, data security, lawful data processing, storage and destruction, responding to applications, and reporting data breaches may continue.
The institution announced that it can conduct investigations ex officio against data controllers who fail to fulfill their VERBİS registration and notification obligations; and that as of August 1, 2024, a total of 503,935,000 TL in administrative fines have been imposed on domestic and foreign data controllers who failed to fulfill their registration and notification obligations.
For the year 2026, administrative fines for non-compliance with VERBİS registration and notification obligations range from 341,809 TL to 17,092,242 TL. Therefore, companies' number of employees, total financial balance, main business activity, and whether they process special categories of data should be regularly evaluated.
Notification Obligation for Data Transfer Abroad
With the amendments made to the KVKK (Personal Data Protection Law) in 2024, new mechanisms regarding the transfer of personal data abroad have been introduced. The 2026 penalty schedule also includes a separate range of administrative fines for failure to fulfill the notification obligation stipulated in Article 9, paragraph 5 of the Law. For 2026, the administrative fine for this violation ranges from 90,308 TL to 1,806,177 TL.
This topic is particularly important for cloud services, CRM software, email marketing tools, advertising panels, analytics cookies, global human resources software, servers located abroad, and multinational corporate groups. Even if a company collects data in Türkiye, if its service provider is located abroad or the data is processed on servers abroad, a data transfer analysis should be performed.
Companies' approach of saying, "We use Google, Meta, Microsoft, Amazon, HubSpot, Mailchimp, or similar systems, but we don't transfer data," is often an incomplete assessment. It is necessary to further examine which personal data is transferred to which provider, to which country, through which legal mechanism, and whether the conditions stipulated in the law for this transfer are met.
Data Subject Applications and Complaint Process
Violations of the Personal Data Protection Law (KVKK) are not only discovered through the Board's own investigations. Most investigations begin with an application by the data subject to the data controller, followed by a complaint to the Board. Data subjects have the right to learn whether their personal data is being processed, to request information if it is being processed, to request the correction of incomplete or inaccurate data, to request the deletion or destruction of unlawful data, and to request compensation for damages. The Board states that, as a rule, data subjects must first apply to the data controller before they can file a complaint with the Board.
The data controller must finalize the data subject's applications as soon as possible, and no later than thirty days. If the application is rejected, the response is deemed insufficient, or no response is given within the specified time, the data subject may file a complaint with the Board within thirty days of learning of the data controller's response, and in any case within sixty days of the application date.
Therefore, companies need to establish an application management system. The address to which GDPR applications should be submitted, the unit that will evaluate them, how responses should be prepared, how identity verification should be carried out, the timeframe for processing requests, and how responses should be archived should be determined in advance. Failure to respond on time, writing unnecessary rejection letters, or rejecting the applicant's request without legal evaluation increases the risk of complaints to the Board.
Does an administrative fine prevent a compensation lawsuit?
Imposing an administrative fine under the Personal Data Protection Law (KVKK) does not prevent the individual from claiming compensation. If the individual's personal rights have been violated, their right to compensation under general provisions remains. The institution also clarifies that the application and complaint process does not eliminate the individual's possibility of pursuing legal or administrative remedies.
Therefore, a data breach can simultaneously have three different consequences. Firstly, the Board may impose an administrative fine. Secondly, the affected party may file a lawsuit for material or moral damages. Thirdly, if the incident involves the unlawful recording, disclosure, dissemination, or acquisition of personal data, a prosecutor's investigation may be initiated.
For example, the dissemination of an employee's medical report at the workplace, the sharing of a customer's debt information with third parties, the sending of a patient's test results to the wrong person, or the leakage of customer data by an e-commerce site can lead to not only administrative sanctions but also liability under civil and criminal law.
The Most Common GDPR Mistakes Companies Make
The first major mistake companies make is viewing the Personal Data Protection Law (KVKK) solely as a matter of preparing documents. However, the information text, the explicit consent text, and the privacy policy alone are insufficient. If the company's actual practices are not consistent with the texts, compliance on paper does not provide serious protection.
The second mistake is using text copied from other companies. Each company has different data processing purposes, recipient groups, retention periods, software infrastructure, and field of activity. Another company's privacy policy may not reflect your company's actual data processing activities.
The third mistake is confusing explicit consent with informed consent. Companies try to obtain explicit consent for every data processing activity or use general checkboxes in areas where explicit consent is required. However, explicit consent must be given freely, based on informed knowledge, and related to a specific matter.
The fourth mistake is viewing data security as solely the responsibility of the IT department. GDPR compliance requires collaboration among legal, human resources, accounting, marketing, sales, IT, and management departments.
The fifth mistake is failing to define data retention periods. Companies often store customer, employee, and supplier data indefinitely. However, data should only be retained for the period necessary for its processing purpose; after that period, it should be deleted, destroyed, or anonymized.
The sixth mistake is not contracting with data processors. Contracts containing data security provisions should be made with third parties such as accountants, software companies, call centers, advertising agencies, cloud providers, and shipping companies.
The seventh error is not having registered with VERBİS or not keeping it up-to-date. Even if you have registered with VERBİS, outdated notifications can also create risks.
What should companies do to avoid administrative fines under the Personal Data Protection Law (KVKK)?
The first step companies should take is to create a personal data inventory. This inventory should identify which personal data is processed, who owns this data, the purpose of processing, the legal basis for processing, to whom it is transferred, where it is stored, and how long it is retained.
Secondly, information texts should be prepared according to the relevant person groups. Separate processes should be evaluated for customers, employees, job applicants, suppliers, visitors, website users, and business partners.
Thirdly, data processing activities requiring explicit consent should be identified. Marketing, commercial electronic communications, certain cookies, some processing of sensitive data, and certain international data transfer processes require special consideration.
Fourthly, technical and administrative measures must be taken. An authorization matrix, access restrictions, encryption, backup, log records, employee training, confidentiality commitments, cybersecurity measures, and a data breach response plan should be established.
Fifthly, a process for responding to individual applications must be established. The thirty-day period must not be missed, and responses must be reasoned and based on legal considerations.
Sixth, VERBİS obligations should be checked and records kept up-to-date. The obligation should be reassessed as the company's number of employees, balance sheet, main business activity, and special categories of data processing change.
Seventh, regular GDPR audits should be conducted. A company should not completely abandon the process after completing compliance work once. GDPR compliance should be re-checked when new software is used, a new marketing tool is introduced, a new camera system is implemented, a new personnel tracking application is used, or a new service provider is brought in.
Conclusion
Administrative fines that companies may face for violations of the Personal Data Protection Law (KVKK) have reached significant levels, particularly as of 2026. Violations of the obligation to inform, failure to take data security measures, non-compliance with Board decisions, failure to fulfill VERBİS registration and notification obligations, and violation of the obligation to notify about data transfers abroad are all grounds for separate administrative fines. Some of these fines can exceed 17 million TL.
However, the risks associated with the Personal Data Protection Law (KVKK) are not limited to administrative fines. The same violation can also lead to compensation claims, a corrective action decision by the Board, public disclosure of the data breach, damage to the company's reputation, and criminal investigations. Therefore, companies should view the KVKK not merely as a formal textual obligation, but as a crucial part of their corporate risk management.
In conclusion, to establish a company structure compliant with the Personal Data Protection Law (KVKK), a data inventory should be prepared, information texts should be concretized, explicit consent processes should be separated, VERBİS (Turkish Data Protection Authority) obligations should be checked, data security measures should be implemented, employees should be trained, contracts should be made with data processors, and a rapid response plan should be created in case of a data breach. A properly conducted KVKK compliance process not only protects the company from administrative fines; it also increases customer trust, protects employee data, strengthens commercial reputation, and significantly strengthens the company's hand in potential disputes.