Data Breach and Compensation Rights under the Turkish Personal Data Protection Law (KVKK)
Data Breach and Compensation Rights under the Turkish Personal Data Protection Law (KVKK)
1. Introduction
With digitalization dominating almost every aspect of life, the lawful processing and security of personal data has become a fundamental legal issue. Banks, hospitals, e-commerce companies, employers, insurance companies, educational institutions, public institutions, and internet platforms process a large amount of personal data in their daily operations. Therefore, the unauthorized acquisition of personal data, its unauthorized sharing with third parties, its transmission to the wrong individuals, or its disclosure as a result of cyberattacks, has serious legal consequences for the data controller and also provides data subjects with various rights to appeal and compensation.
In Türkiye, one of the fundamental legal bases for the protection of personal data is Article 20 of the Constitution. In addition, the Law No. 6698 on the Protection of Personal Data ("KVKK") regulates in detail the principles regarding the processing of personal data, the obligations of data controllers, and the legal remedies available to individuals whose personal data has been breached.
Under the Personal Data Protection Law (KVKK), ensuring data security is not merely a technical matter concerning the internal organization of companies. The protection of personal data is a fundamental right directly linked to the right to privacy and personal rights. Therefore, when a data breach occurs, depending on the circumstances, administrative proceedings before the Personal Data Protection Authority, compensation lawsuits in civil courts, and in some cases, criminal investigations may all arise as a result of the same incident.
2. What is Personal Data?
Under the Turkish Personal Data Protection Law (KVKK), personal data is any information relating to an identified or identifiable natural person.
This definition is quite broad. It includes not just a person's first and last name;
Data that directly or indirectly identifies an individual, such as Turkish national identity number, passport information, telephone number, email address, home or work address, bank account information, credit card information, vehicle license plate number, IP address, location information, customer transaction records, photographs and videos, audio recordings, and personal and payroll information, may be considered personal data.
Certain types of data, such as health information, biometric data, and genetic data, are subject to higher protection under the law. The Personal Data Protection Authority also specifically emphasizes that obtaining special categories of personal data may create discrimination or other serious harm to the data subjects.
Therefore, when assessing the legal weight of a data breach, it is important not only to ask "was data leaked?" but also what type of data was exposed.
3. What is a Data Breach under the Personal Data Protection Law (KVKK)?
When we talk about data breaches, we often think of large-scale hacker attacks. However, according to the Turkish Personal Data Protection Law (KVKK), data security breaches have a much broader scope.
Events such as personal data being obtained by unauthorized third parties, unlawful access to databases, customer information being sent to the wrong person, employees accessing data without authorization, loss or theft of documents containing data, and databases becoming accessible over the internet can be considered data security breaches.
According to Article 12 of the KVKK (Law on Protection of Personal Data), the primary obligation of the data controller is:
to prevent the unlawful processing of personal data,
to prevent unlawful access to personal data,
to ensure the protection of personal data
The aim is to take the necessary technical and administrative measures. The institution's procedures regarding data breaches are also based on these obligations.
Therefore, a company simply stating "we were subjected to a cyberattack, and the attack was carried out by a third party" is not enough to absolve it of responsibility. It must also be assessed whether reasonable technical and administrative security measures were taken prior to the incident.
4. Data Controller's Obligation to Ensure Data Security
In the KVKK (Personal Data Protection Law) system, the primary responsibility for ensuring the security of personal data rests with the data controller.
The data controller is the natural or legal person responsible for establishing and managing the data recording system, and who determines the purpose and method of processing personal data.
For example, a bank that processes customer information may be the data controller, an employer may be the data controller regarding employee personal information, and a hospital or healthcare institution may be the data controller regarding patient information.
Data controllers' security responsibilities are not limited to simply installing antivirus software or setting passwords for the system.
Depending on the nature of the specific case;
Measures such as restricting access rights, using strong authentication methods, maintaining log records, keeping systems up-to-date, protecting databases, detecting unauthorized access, training employees, limiting access to personal data to job-related issues, including security clauses in contracts with data processors, and developing data breach response plans may be considered.
Indeed, recent data breach announcements by the organization reveal a wide variety of attack methods. Breach reports for 2026 include different incident types such as employee account hijacking via voice phishing, ransomware attacks, software vulnerabilities, and unauthorized access to the database through a compromised user account.
This situation demonstrates that data security obligations are not static, but require continuous updating.
5. Obligation to Report in Case of a Data Breach
According to Article 12/5 of the Personal Data Protection Law, if personal data processed is obtained by others through unlawful means, the data controller is obliged to notify the data subject and the Personal Data Protection Board of this situation as soon as possible.
Although the law uses the phrase "as soon as possible," the Personal Data Protection Board, in its decision dated January 24, 2019, and numbered 2019/10, has clarified this timeframe.
Accordingly, the data controller is obliged to notify the Board without delay and at the latest within 72 hours from the date they become aware of the breach.
If notification cannot be given within 72 hours, the justifiable reasons for the delay must be explained to the Board.
Once the individuals affected by the breach have been identified, they should be notified as soon as reasonably possible.
If the relevant person's contact information is known, notification can be made directly. If they cannot be reached, appropriate methods such as an announcement on the company's website can be used.
6. What should be included in the notification to the relevant person?
A data breach notification should not be limited to a simple, abstract statement such as "your data may have been leaked.".
According to the Personal Data Protection Board's decision numbered 2019/271, the notification to the data subject must be prepared in clear and simple language and must include at a minimum:
when the violation occurred
which categories of personal data were affected by the breach
potential consequences of the violation
Measures taken or recommended to be taken to reduce negative impacts,
Communication channels through which the relevant person can obtain information about the violation
It should contain information on the subject.
The aim is to enable the individual to ensure their own safety.
For example, a person whose credit card information has been leaked can cancel their card, a person whose password has been compromised can change their password, or a person whose identity information has been compromised can take necessary precautions against potential fraud only if they are informed of the breach in a timely manner.
7. Consequences of Late Reporting of Data Breach
Failure to fulfill the notification obligation in a timely manner may also give rise to legal liability.
In the practice of the Personal Data Protection Board, notification of a breach by the data controller to the relevant parties or the Board after a very long delay is considered a breach of the obligation under Article 12/5 of the Personal Data Protection Law.
Indeed, a summary of the decision published by the Authority states that administrative sanctions were imposed on the data controller because the data breach was reported to the relevant individuals with a delay of 17 months and to the Board with a delay of 10 months.
Therefore, for companies, the first few hours after a data breach is detected are legally extremely important.
8. Rights of the Data Subject Whose Personal Data Has Been Breached Under the Personal Data Protection Law (KVKK)
Article 11 of the Personal Data Protection Law grants extensive rights to the data subject.
The data subject may contact the data controller to inquire whether their personal data is being processed, request information about this processing if so, and find out the purpose for which the data is being processed and whether it is being used appropriately for that purpose.
They also have the right to know to which third parties, domestically or internationally, the data has been transferred.
You may request the correction of incomplete or inaccurate data, the deletion or destruction of data under the conditions stipulated by law, and notification of these actions to third parties to whom the data has been transferred.
Most importantly, within the scope of Article 11 of the Personal Data Protection Law;
If you suffer damages due to the unlawful processing of your personal data, you may claim compensation for those damages.
This regulation is one of the key foundations for data breach victims to claim compensation.
9. First, Apply to the Data Controller
There is a tiered application mechanism for exercising the rights under the Personal Data Protection Law (KVKK).
The data subject should first contact the data controller.
For example, in the application;
Explanation of which personal data was affected by the breach,
informing who the data is transferred to,
deletion or destruction of data held unlawfully,
Correction of erroneous data,
Explanation of the source of the violation and the measures taken,
compensation for damages
It can be requested.
The Personal Data Protection Authority also explicitly states that, regarding requests within the scope of the Personal Data Protection Law, it is mandatory to first apply to the data controller.
The data controller must finalize the application within a maximum of 30 days.
10. Complaint to the Personal Data Protection Board
If the application to the data controller is rejected, if the response is deemed insufficient, or if no response is given within the specified time, the data subject may file a complaint with the Personal Data Protection Board.
Complaint period;
30 days from the date of receipt of the data controller's response ,
In any case, it is 60 days from the date of application to the data controller .
The institution also explicitly states that the data controller must be contacted before filing a complaint directly with the Board.
However, there is an important distinction:
Filing a complaint with the board is not the same as filing a compensation lawsuit.
The Board can monitor whether the data controller has acted in violation of the KVKK (Personal Data Protection Law) and impose administrative sanctions where necessary. However, the amount of material or moral compensation to be paid to the individual is generally decided by the courts of law.
11. Can Financial Compensation Be Claimed Due to a Data Breach?
Yes.
If a personal data breach has resulted in a tangible decrease in a person's assets, monetary compensation may be considered.
For example, a claim for financial damages may arise in cases where an unlawful money transfer is made from a bank account as a result of a data breach, fraud is committed using personal information, economic losses occur due to the disclosure of trade secrets, or necessary expenses are incurred to remedy the breach.
However, according to the general principles of compensation law, it is important to establish a proper causal link between the damage and the unlawful act.
Therefore, data breach victims;
bank records,
fraudulent transactions,
SMS and email notifications,
Breach notifications sent by the company,
screenshots,
account transactions,
Board decisions,
prosecutor's or police reports
It is important to preserve evidence such as these.
12. Can I Claim Damages for Non-Pecuniary Damages Due to a Data Breach?
One of the most important legal claims in data breaches is compensation for non-pecuniary damages.
Article 14/3 of the Personal Data Protection Law clearly states:
"Those whose personal rights have been violated retain the right to compensation according to general provisions."
It accepts this principle.
The Personal Data Protection Board has also stated in many of its decisions that it does not award compensation for moral damages itself, and that these claims should be made in general courts.
Therefore, if a person's private life information, health information, economic information, or other personal data is unlawfully shared with third parties, compensation for non-pecuniary damages may arise due to the violation of personal rights.
13. How is the amount of moral damages determined?
Under the Turkish Personal Data Protection Law (KVKK), there is no fixed compensation tariff determined for each data breach.
The court considers all the specifics of the case.
Especially;
scope of the violation
which data categories were revealed,
whether or not there is any special category personal data,
how many people the data reached
whether the data was published on the internet or not,
the duration of the violation
fault of the data controller,
whether the necessary measures were taken despite the violation being discovered,
impact on the victim's social and personal life,
whether the data was misused
Factors such as these can be important.
For example, the accidental sharing of a phone number with a third party cannot be judged with the same weight as the online publication of a person's psychiatric health history.
With regard to sensitive personal data, the impact of the breach on the victim may be more severe.
14. The Approach of the Constitutional Court
The protection of personal data is not only a legal right regulated under the Personal Data Protection Law (KVKK).
It is constitutionally guaranteed under Article 20 of the Constitution.
The Constitutional Court also considers the right to protection of personal data as an important element of the right to respect for private life.
For example, in a decision on an individual application dated July 17, 2024, the Constitutional Court ruled that the right to protection of personal data had been violated and awarded the applicant 30,000 TL in moral damages.
Similarly, in its Cem Özberk decision dated March 20, 2025, the Constitutional Court assessed the ineffective conduct of the criminal investigation regarding allegations of unlawful acquisition of health information in terms of the right to protection of personal data and ruled that there was a violation.
These decisions demonstrate that the protection of personal data is not merely a matter of administrative compliance, but an area with a fundamental rights dimension.
15. Is a prior decision from the Personal Data Protection Board required for compensation to be awarded?
This is one of the important questions in practice.
A person does not necessarily have to obtain a violation decision from the Personal Data Protection Board before filing a compensation lawsuit.
According to the institution's statement, while filing an application with the data controller is mandatory, filing a complaint with the Board is optional. A person whose application is explicitly or implicitly rejected may, on the one hand, file a complaint with the Board, and on the other hand, pursue legal action.
Therefore, the Board process and the compensation process should be separated.
However, a decision by the Personal Data Protection Board regarding a specific case can constitute important evidence in a legal case.
16. Can the Personal Data Protection Board Award Compensation?
No.
The Personal Data Protection Board has administrative oversight and enforcement powers under the Law. However, it is not the authority that directly awards material or moral damages in favor of the victim.
The institution's decision regarding the bank's unauthorized sharing of the individual's data with his father also clearly states that the claim for moral damages should be brought in general courts under Article 14/3 of the Personal Data Protection Law.
Therefore, the person who has been affected by the data breach;
"I applied to the Personal Data Protection Authority (KVKK), the Board will pay me compensation."
His idea that this is correct is not true.
If the board imposes an administrative fine, the money is paid to the public, not to the victim.
The victim must also file a legal claim for compensation for the damages they have suffered.
17. Legal Grounds for Compensation Claims
The legal basis for compensation claims arising from data breaches under the KVKK (Turkish Personal Data Protection Law) is determined according to the specific characteristics of the case.
The main pillars are:
Article 20 of the Constitution,
KVKK Article 11,
KVKK Article 12,
KVKK Article 14/3,
Turkish Civil Code, Articles 24 and 25,
Provisions of the Turkish Code of Obligations regarding torts and violations of personal rights
it could be.
According to Article 24 of the Turkish Civil Code, a person whose personal rights have been unlawfully violated may request protection against the violation.
According to Article 58 of the Turkish Code of Obligations, a person who has suffered damages due to the violation of their personal rights may claim compensation for moral damages.
Since the right to protection of personal data is an important part of the right to privacy and personality, unlawful data processing activities are also evaluated within the scope of these provisions.
18. Can a Data Breach Also Constitute a Crime?
Yes.
Personal data breaches do not only give rise to administrative or legal liability under the Personal Data Protection Law (KVKK).
Depending on the specifics of the incident, a crime may also be committed under the Turkish Penal Code.
Especially;
Unlawful recording of personal data within the scope of Article 135 of the Turkish Penal Code,
Under Article 136 of the Turkish Penal Code, unlawfully disclosing, disseminating, or obtaining personal data,
Not destroying data under Article 138 of the Turkish Penal Code
Their crimes may come to light.
In addition, if there has been unauthorized access to the system, the provisions relating to cybercrimes should also be considered.
Therefore, regarding the same event;
Complaint to the Personal Data Protection Board,
criminal complaint to the prosecutor's office,
lawsuit for material and moral damages
They can come up together.
However, the purpose and conditions of each legal avenue are different.
19. Breach of Special Categories of Personal Data
The disclosure of sensitive personal data, such as health information, biometric data, and genetic data, can have particularly serious consequences.
For example, the disclosure of a person's medical history, psychological treatment information, or biometric data to third parties can constitute a more serious intrusion into privacy than the leakage of ordinary contact information.
The Personal Data Protection Board, in its decisions regarding the publication of health information in the press, acknowledges that a proportionality assessment must be made between the public interest and the right to protection of personal data, and that publishing excessive details of private life may violate personality rights.
Therefore, data sensitivity is a crucial factor in compensation assessment.
20. Does a cyberattack automatically absolve a company of liability?
No.
One defense frequently encountered in practice by data controllers is that the breach occurred due to a cyberattack carried out by a third party.
However, the fact that a data breach occurs as a result of a cyber attack does not relieve the data controller of their security obligations under the Turkish Personal Data Protection Law (KVKK).
What really needs to be examined is;
whether reasonable security measures were taken that could have prevented the attack from happening,
whether security vulnerabilities are addressed in a timely manner,
whether access permissions are configured correctly,
whether the systems are regularly audited,
whether the violation was detected in time
These are some of the issues.
Indeed, data breach announcements published by the Agency in 2026 demonstrate that methods such as social engineering, user account hijacking, software vulnerabilities, and ransomware continue to be current risks to data security.
21. What Should a Data Breach Victim Do?
It is crucial for anyone who suspects their personal data has been leaked or accessed by unauthorized individuals to first preserve the evidence.
All breach notifications, SMS messages, or emails sent by the company, screenshots, banking transactions, and other documents should be saved.
Then, a written application is made to the data controller within the scope of the KVKK (Personal Data Protection Law);
which data was breached,
Date of the violation,
who obtained the data,
whether or not transfers were made to third parties,
security measures taken
It can be asked.
You may also request the deletion or correction of your data, or compensation for any damage that has occurred.
Depending on the response to the application, a complaint may be filed with the Personal Data Protection Board, and if necessary, a compensation lawsuit may be filed in civil courts.
If there is suspicion of a crime, filing a criminal complaint with the Public Prosecutor's Office should also be considered.
22. The Importance of Proof in Data Breach Cases
One of the most important aspects of compensation claims is the issue of proof.
The plaintiff's claim that "my data was stolen" may not be sufficient in every case.
Because;
where the data breach occurred
The plaintiff's data was found to be breached
unlawful conduct of the data controller
the damage that occurred
the causal link between damage and data breach
This should be presented on a case-by-case basis.
Documenting the amount of damage is particularly important in terms of monetary compensation.
In terms of compensation for non-pecuniary damages, the nature of the data, the extent of the breach, and its impact on the individual's private life are key factors.
23. Legal Consequences of Data Breach for Companies
Data breaches do not result in a one-dimensional penalty for companies.
The same event;
Administrative fines under the Personal Data Protection Law (KVKK),
Instructions from the Board to change data processing procedures
compensation lawsuits
criminal investigations,
loss of commercial reputation
customers terminating their contracts,
sanctions of sectoral regulatory bodies
This can lead to various consequences.
Therefore, compliance with the Personal Data Protection Law should not be seen as merely preparing an information text or posting a privacy policy on a website.
Data security is an active and continuous process.
24. Conclusion
Ensuring the security of personal data is one of the most important elements in protecting fundamental rights today. Law No. 6698 on the Protection of Personal Data imposes significant obligations on data controllers to prevent the unlawful processing of personal data and unauthorized access to personal data.
If personal data is obtained by third parties through unlawful means, the data controller must assess the breach without delay and notify the Personal Data Protection Board within 72 hours at the latest, in accordance with the Board's practice.
Those affected by the violation should also be informed as soon as reasonably possible.
Individuals whose personal data has been processed unlawfully or has fallen into the hands of third parties may, under Article 11 of the Personal Data Protection Law, apply to the data controller, file a complaint with the Personal Data Protection Board if the necessary conditions are met, and claim material and moral damages within the framework of general provisions if their personal rights have been violated.
Especially when health data, financial information, identity information, biometric data, or information relating to the privacy of personal life are breached, the incident should be evaluated not only from the perspective of the Personal Data Protection Law (KVKK) but also from the perspectives of personal rights, tort liability, and criminal law, as the breach can have serious consequences.
In conclusion, the rights of data breach victims are not limited to simply requesting the deletion of their data. If unlawful data processing has resulted in tangible harm or a violation of personal rights, the injured party may also claim material and moral damages, provided the conditions are met.