Single Blog Title

This is a single blog caption

Legal Liability of Companies in Case of Data Breach

Entrance

With digitalization, a company's most important assets are no longer just capital, brand value, or trade secrets. Customer data, employee data, supplier information, payment records, camera footage, IP addresses, membership information, health data, financial information, and user behavior data have become central to company operations. Therefore, a data breach for a company is not just a technical cybersecurity problem; it also means serious legal liability, reputational damage, administrative sanctions, and compensation risks.

A data breachcan be defined as the unauthorized access, disclosure, loss, alteration, rendering inaccessible, unlawful sharing of personal data, or the compromise of the security of data environments that should be protected. Examples of data breaches include a company's customer database being hacked, employee salary information being sent to the wrong person via email, user information being viewed by third parties due to a security vulnerability on a website, a former employee continuing to access the system, a cloud folder being left publicly accessible, or data being encrypted as a result of a ransomware attack.

In Turkey, the primary legal basis for companies' liability in the event of a data breach the Law No. 6698 on the Protection of Personal Data. According to Article 12 of the KVKK (Law on the Protection of Personal Data), the data controller is obligated to take all necessary technical and administrative measures to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the preservation of personal data. Furthermore, the data controller may be jointly liable with the data processor for taking necessary measures if personal data is processed on their behalf by another natural or legal person.

What is a data breach?

A data breach is any unlawful act that affects the security, confidentiality, integrity, or accessibility of personal data. While in practice data breaches are often equated with cyberattacks, they don't only refer to hacker attacks. Human error, lack of authorization, sending incorrect emails, using weak passwords, failing to close old employee accounts, misconfigured cloud systems, keeping backups without passwords, supplier errors, or internal misconduct can also lead to data breaches.

For example, the publication of a customer's name, phone number, email address, address, and order information online by an e-commerce company is a clear data breach. Unauthorized employees viewing a hospital's patient records constitutes a data breach. The manipulation of URLs to make a claim file accessible to third parties by an insurance company is a data breach. A human resources company sending candidate resumes to the wrong people is also a data breach. Therefore, data breaches can occur due to both external cyberattacks and internal organizational deficiencies within a company.

For companies, the crucial point is to quickly answer questions such as "Which data was affected, how many people were affected, is the breach still ongoing, is there a possibility of harm to relevant individuals, should the Board be notified, and how will the evidence be protected?" before asking "Who did this?" at the moment a data breach occurs. Data breach management requires the simultaneous implementation of both technical and legal interventions.

The Company's Core Responsibilities as Data Controller

In the KVKK (Turkish Personal Data Protection Law) system, companies are in most cases data controllers . A data controller is a natural or legal person who determines the purposes and means by which personal data will be processed. A company acts as a data controller if it collects membership information from its customers, maintains employee personnel files, uses cookies on its website, stores payment and order data, or operates a CRM system.

The primary obligation of the data controller company is to process personal data lawfully and ensure its security. According to Article 12 of the KVKK (Law on Protection of Personal Data), the company must prevent the unlawful processing of personal data, prevent unlawful access to data, and ensure the preservation of data. To this end, it must take technical and administrative measures to ensure an appropriate level of security.

This obligation cannot be fulfilled simply by publishing a "privacy policy" or "KVKK (Personal Data Protection Law) information text". The company's technical infrastructure, employee authorizations, data retention periods, supplier contracts, access logs, encryption practices, backup system, incident response plan, employee training, and data breach procedures are all evaluated together.

Responsibility for Taking Technical and Administrative Measures

When a data breach occurs, one of the first questions the Board and the courts will look at is: Did the company take the necessary technical and administrative measures to prevent this breach? If the company did not take the necessary precautions, it may be held legally liable even if the breach occurred directly through the actions of an attacker or a malicious employee.

Technical measures include strong password policies, multi-factor authentication, firewalls, antivirus and malware protection, database encryption, backups, log recording, access restrictions, penetration testing, vulnerability scanning, server security, network segmentation, data masking, unauthorized access alerts, and regular software updates.

Administrative measures, on the other hand, relate to internal company policies and organizational processes. Examples of administrative measures include employee confidentiality commitments, data processor contracts, supplier audits, access authorization matrices, retention and destruction policies, data inventory, personnel training, closing accounts of departing employees, data breach response plans, and internal audit mechanisms.

The size of the company, the nature of the data it processes, and its field of activity affect the level of security measures to be taken. For example, a small business with only a general contact form cannot be expected to have the same level of technical infrastructure as a payment institution processing the financial data of millions of customers. However, every data controller must ensure a reasonable level of security appropriate to the risks of its own operations.

Liability for Breach of Action by Data Processors and Suppliers

Many companies process personal data not within their own systems, but through third-party service providers. Hosting companies, cloud service providers, CRM systems, call center services, email marketing platforms, payroll companies, software companies, and payment infrastructures can all be considered data processors in this context.

According to the Turkish Personal Data Protection Law (KVKK), when personal data is processed by another natural or legal person on behalf of the data controller, the data controller is jointly responsible with these persons for taking the necessary precautions. Therefore, the company cannot escape responsibility in every case by saying, "the data leaked from the supplier's system, not my system.".

It is important for the company to consider its supplier selection, whether it has obtained contractual guarantees, whether it monitors the technical and administrative measures of the data processor, whether it has defined the data processing instructions in writing, and whether it has stipulated notification obligations in case of a breach in the contract. The Board's data breach notification procedures and principles clearly state that the data processor must notify the data controller without delay when a breach occurs.

Therefore, companies must include provisions on data security, confidentiality, subcontractor usage, international data transfer, breach reporting, audit rights, log retention, evidence protection, and liability for damages in their supplier agreements.

What to do in the first 24 hours after discovering a data breach?

The company's initial reaction upon learning of a data breach is critical. Mistakes made at this stage can lead to the loss of evidence and late or incomplete notification to the Board. Initially, the company should establish a crisis team consisting of IT, legal, senior management, data protection officer/compliance team, communications unit, and, if necessary, external cybersecurity experts.

First, the source of the breach must be identified. Is the attack still ongoing? Which systems were affected? Which databases were accessed? Does it contain personal data? Is there any sensitive or private data? How many people may have been affected? Was data copied? Was it just access, or was data deleted or encrypted? These questions must be answered through a technical investigation.

However, the technical team must not destroy evidence while fixing the system. Log records, server images, firewall logs, access traces, malware samples, email headers, user activity, and backups must be preserved. Because these records can be important in notifications to the Board, in prosecutor investigations, and in compensation lawsuits.

The company should also evaluate its notification obligations together with its legal team. Under Article 12/5 of the KVKK (Personal Data Protection Law), if personal data is obtained by others through unlawful means, the data controller is obliged to notify the data subject and the Board as soon as possible. The Board interprets the phrase "as soon as possible" as 72 hours.

Obligation to notify the Board within 72 hours

In the event of a data breach, one of the most important obligations of companies is to notify the Personal Data Protection Board without delay, and no later than 72 hours from the date they become aware of the breach. According to the Board's decision dated January 24, 2019, and numbered 2019/10, if notification cannot be made within 72 hours, the reasons for the delay must also be explained to the Board. Furthermore, if it is not possible to provide all information at the time of the initial notification, the information can be provided in stages.

The biggest mistake companies make at this point is waiting for the technical review to be completely finished. However, in the Board's practice, it is not a requirement for all details to be finalized before notification. When a company learns of a breach, it should make reasonable initial assessments, identify the affected data categories, groups of people, the potential impact of the breach, and the measures taken, and then submit the notification. Missing information can be completed later.

Data breach notifications can also be made to the Board electronically. The Personal Data Protection Law (KVKK) has made it possible to submit the Personal Data Breach Notification Form to the Board via the internet; however, it has been stated that this form must be filled out by the data controller, and that complaints and notifications must be made through different channels.

Late notification carries a serious risk of sanctions. A summary of a decision published by the Personal Data Protection Authority (KVKK) states that a data controller's failure to notify individuals of a breach within 17 months and the Board within 10 months exceeds the "shortest possible time" and is considered a data security breach, resulting in administrative sanctions.

Notification Obligation to Relevant Persons

In the event of a data breach, simply notifying the Board is insufficient. The relevant individuals affected by the breach must also be notified as soon as reasonably possible. If the individual's contact information is available, direct notification should be made; if not, appropriate methods should be used, such as posting an announcement on the company's website.

The notification to the relevant individuals must be prepared in clear and simple language. According to the Board's decision dated 18.09.2019 and numbered 2019/271, the notification to the relevant individual must include, at a minimum, when the breach occurred, which personal data categories were affected, the possible consequences of the breach, the measures taken or recommended to mitigate the negative effects, and the communication channels through which the relevant individuals can obtain information.

This notification is also crucial for the company's legal defense. Incomplete, misleading, or alarming notifications can damage the company's reputation. Conversely, failing to notify or concealing the breach can have more serious legal consequences. Instead of using vague statements such as "we experienced a minor technical glitch at our company," the notification to relevant parties should honestly and clearly explain the scope of the breach.

Risk of Administrative Fines

In the event of a data breach, companies may face administrative fines under Article 18 of the Personal Data Protection Law (KVKK). Specifically, failure to fulfill data security obligations, non-compliance with Board decisions, breach of the duty to inform, failure to fulfill VERBİS obligations, and late notification of data breaches can all result in administrative sanctions.

The Personal Data Protection Authority (KVKK) has announced that the administrative fines stipulated in Article 18 of Law No. 6698 are increased annually in accordance with the revaluation rate, effective from the beginning of each calendar year, pursuant to Law No. 5326 on Misdemeanors, and that the updated amounts for the years 2017-2026 have been published separately. Therefore, companies should check the updated fine amounts annually.

In its assessment of sanctions, the Board considers the nature of the violation, the number of affected individuals, the categories of data affected, whether or not there is sensitive personal data, the technical and administrative measures taken by the company, the timeframe for detecting the violation, the notification period to the Board and relevant individuals, the actions taken after the violation, and the degree of fault of the company.

For example, companies that have experienced similar security vulnerabilities in the past but fail to take precautions, do not restrict access for former employees, do not use encryption, do not keep logs, do not conduct penetration testing, or conceal the breach for months will face a higher risk of administrative sanctions.

Liability for Damages

A data breach doesn't only create a risk of administrative fines. Those affected can also claim compensation for their material and moral damages. Under Article 11 of the Personal Data Protection Law (KVKK), individuals who suffer damages due to the unlawful processing of their personal data have the right to claim compensation. Furthermore, provisions of the Turkish Code of Obligations concerning torts, breach of contract, or violation of personal rights may also come into play.

Financial damage is the economic loss a person suffers as a result of a breach. For example, a person whose bank information has been leaked and money withdrawn from their account can claim financial damages. A person whose identity information has been leaked and fraudulent transactions have been made in their name can claim compensation for their losses. If a company's business relationships have been disrupted due to a leak of customer data, claims for contractual liability or commercial damages may arise.

Non-pecuniary damage relates to the impairment of a person's privacy, sense of security, reputation, or personal rights. Claims for non-pecuniary damages may be more strongly raised in cases involving the leakage of sensitive data such as health data, sexual information, biometric data, children's data, financial information, or private correspondence.

In determining a company's liability for damages, fault, appropriate causal link, the existence of damage, and the scope of the breach are evaluated. However, it is crucial for a company under data security obligations to prove that it took the necessary precautions. Therefore, documenting measures taken before the breach, maintaining training records, storing audit reports, and having regular supplier contracts strengthens the company's defense.

Criminal Law Aspect

In the event of a data breach, the company or its employees may also face criminal liability. The Turkish Penal Code defines the unlawful recording, disclosure, dissemination, or acquisition of personal data as separate types of crimes. If an employee sells a customer list to a competitor, provides health data to a third party, a former employee downloads data by accessing the system, or company managers knowingly allow unlawful data sharing, a criminal investigation may be initiated.

A company as a legal entity is not directly subject to imprisonment; however, criminal liability may arise for the individuals who committed the crime. Furthermore, if the conditions are met, security measures and administrative sanctions may be considered against the legal entity. If the data breach occurred as a result of a cyber attack, crimes such as unauthorized access to an information system, obstruction or disruption of the system, destruction or alteration of data, misuse of bank/credit card information, and aggravated fraud may also be evaluated.

Therefore, when a data breach occurs, the company should not only notify the Board but also consider filing a criminal complaint with the Public Prosecutor's Office if the perpetrator is identified and there is a possibility of internal personnel negligence, data theft, breach of trade secrets, or fraud.

Contractual Liability and Commercial Relations

Data breaches can also create liability for companies in terms of their contracts with business partners and customers. Technology companies, software providers, payment institutions, healthcare organizations, call centers, e-commerce platforms, financial institutions, and cloud service providers, in particular, include data security, privacy, and breach notification clauses in their contracts.

When a company fails to protect its customer's data, it may be held liable not only under the Turkish Personal Data Protection Law (KVKK) but also to the contracting party. Failure to meet the security standards stipulated in the contract, breach of SLA obligations, violation of data processing instructions, unauthorized use by subcontractors, or delayed notification of a breach may result in compensation claims and contract termination.

Therefore, companies should draft data processing agreements that are relevant to their actual business processes, not just using generic and standardized statements. The agreements should clearly specify which data is being processed, which systems it is stored in, who has access to it, whether data is being transferred abroad, whether subcontractors will be used, the timeframe for notification in case of a breach, how evidence will be protected, and how liability for damages will be shared.

Data Breach Response Plan

The Board's data breach notification procedures and principles state that data controllers must prepare a data breach response plan that includes determining who should be notified in the event of a data breach, who is responsible for notifications under the Law, and who is responsible for evaluating the potential consequences of the breach, and that this plan must be reviewed at regular intervals.

A data breach response plan is a roadmap outlining what a company will do in the event of a crisis. This plan should answer questions such as: who will detect the breach, who will report it, when will the legal team get involved, which IT logs will be protected, how will the report be submitted to senior management, who will be responsible for notifying the Board, who will prepare the notification text for relevant individuals, and who will decide whether a press release is necessary.

The plan shouldn't just exist on paper. Regular drills should be conducted, employees should receive awareness training, communication channels with suppliers should be tested, and incident scenarios should be created for critical systems. Companies that act quickly and accurately in the event of a data breach will both minimize losses and have a stronger position before the Board.

Things Companies Should Not Do After a Data Breach

Some mistakes companies make after a data breach can increase their legal liability. The first of these is concealing the breach. If a company does not notify the Board or relevant parties out of fear of reputational damage, the subsequent discovery of the breach can lead to more severe administrative and legal consequences.

The second mistake is deleting or altering all system logs before the technical investigation is complete. Destroying evidence makes it harder to identify the attacker and prevents the company from proving that it took the necessary precautions.

The third mistake is providing vague and incomplete notifications to the relevant parties. Instead of general statements such as "We experienced a minor issue with our system," the nature of the breach and the measures to be taken should be clearly stated. According to the Board's decision, the notification to the relevant party must include at least the following elements: the time of the breach, the categories of data affected, the possible consequences, and the proposed measures.

The fourth mistake is shifting all responsibility to the supplier. Even in cases of breaches originating from the supplier, the data controller company's oversight, contractual, and auditing obligations remain.

Conclusion

Companies face multifaceted legal responsibilities in the event of a data breach. They are not only the parties harmed by the cyber attacker's actions but also data controllers obligated to protect personal data. Therefore, a data breach can result in numerous consequences, including administrative fines, compensation, contractual liability, criminal investigations, reputational damage, and loss of customer trust.

Under Article 12 of the KVKK (Law on Protection of Personal Data), companies are obliged to take technical and administrative measures to prevent the unlawful processing and access of personal data, to ensure the preservation of data, and to provide an appropriate level of security. In the event of a breach, the company must notify the Board without delay, and no later than 72 hours from the date it becomes aware of the breach; inform the affected individuals as soon as reasonably possible; take measures to mitigate the effects of the breach; and document the entire process.

The best approach for companies is not to panic after a data breach occurs, but to establish a robust compliance and security system before a breach happens. Data inventory, access authorization, encryption, log management, backup, employee training, data processor agreements, penetration testing, a data breach response plan, and regular internal audit mechanisms are fundamental elements of this system.

In conclusion, a data breach should not be viewed as a simple technical malfunction or a temporary system problem. A data breach is a serious event that simultaneously tests a company's GDPR compliance, cybersecurity capabilities, crisis management, customer relations, and legal risk management. Therefore, it is crucial for companies to manage data breach processes professionally, considering the dimensions of information technology law, personal data protection law, and commercial liability.

Leave a Reply

Call Now Button