Data Leakage and GDPR Violations: Who is Responsible for Cyberattacks?
I. INTRODUCTION
In the digitalized world, companies, institutions, and even public authorities of all sizes process personal data extensively. However, due to cyberattacks, ransomware, system vulnerabilities, or employee negligence, this data is sometimes accessed by unauthorized individuals.
So in this situation:
Is the data breach victim solely the data owner, or is the company or institution also held responsible?
In Turkey, the Law No. 6698 on the Protection of Personal Data (KVKK), the Turkish Code of Obligations, the Turkish Penal Code , and related secondary regulations provide answers to these questions.
II. WHAT IS A DATA BREACH?
Definition:
Data breach according to KVKK (Turkish Personal Data Protection Law):
“This refers to the situation where personal data is unlawfully obtained, shared, or made accessible to others.”
For example:
- Bank customer information stolen by a hacker
- Disclosure of appointment, diagnosis, and identity information from hospital systems
- Credit card information of users leaked from an e-commerce site
They all count as "data breaches".
III. DATA LEAKAGE AND RESPONSIBILITY: THE ATTACKER OR THE ONE WHO FAILED TO PREVENT IT?
According to Article 12 of the KVKK (Turkish Personal Data Protection Law), the data controller is:
"It is responsible for ensuring data security. It must take the necessary technical and administrative measures and prevent unauthorized access."
Therefore, even if the attack comes from an external source,
the data controller's obligation to protect remains.
The excuse of "we were hacked" often does not absolve the data controller of responsibility.
IV. WHO IS CONSIDERED A DATA CONTROLLER?
- Private companies (e-commerce, finance, healthcare, education, software companies)
- Public institutions (universities, municipalities, population registration offices)
- Associations, foundations
- Natural persons (doctors, lawyers, consultants, etc., if they have their own office)
These individuals data controllers .
V. CONSEQUENCES OF DATA BREACH
1. Administrative Fines (Imposed by the Personal Data Protection Board)
The Personal Data Protection Board, based on Article 18 of the Personal Data Protection Law:
- Institutions that fail to take adequate security measures can be fined up to 500,000 TL as of 2024. This fine amount may increase depending on the scope of the violation and the number of people affected.
2. Liability for Compensation to Data Owners
According to Articles 49 and 58 of the Turkish Code of Obligations:
- Moral damages (violation of privacy)
- Monetary compensation (damages resulting from data misuse)
In this respect, the data controller may be the defendant.
3. Obligation to Disclose Information to the Public
When the data breach is discovered:
- Notification to the Personal Data Protection Authority is mandatory within 72 hours at the latest .
- In addition, individuals whose data has been breached should be notified individually.
Failure to do so will also result in an administrative fine.
VI. DECISIONS OF THE PERSONAL DATA PROTECTION BOARD
Example Decision 1: (Decision No: 2023/132)
A cyberattack on a hotel chain's system resulted in the leakage of the names, surnames, and email addresses of 12,000 customers. The system was outdated and lacked backups. An administrative fine of 400,000 TL was imposed. Additionally, a further 100,000 TL fine was applied for failing to notify individuals .
Example Decision 2: (Decision No: 2024/015)
A data breach occurred at a private hospital when a former employee accessed the system using passwords. The hospital was found negligent for failing to delete the former employee's passwords and was fined 300,000 TL .
VII. CRIMINAL LAW ASPECT
Turkish Penal Code Article 136:
"Anyone who unlawfully discloses, disseminates, or obtains personal data belonging to another person shall be punished with imprisonment from 2 to 4 years."
Well:
- Criminal case against hacker
- If the data controller has committed gross negligence, criminal liability may arise.
VIII. THE ROLE OF BTK (INFORMATION TECHNOLOGY AUTHORITY)
- Internet service providers, hosting companies, and data center providers are under the supervision of the BTK (Information and Communication Technologies Authority).
- Institutions with critical infrastructure (banks, telecommunications companies, energy firms) are also obligated to report data breaches to the BTK (Information and Communication Technologies Authority).
IX. WHAT TO DO? – PREVENTIVE MEASURES
Administrative and technical measures that data controllers must take :
Technical Measures:
- Antivirus, firewall, SSL certificates
- Encryption systems
- Penetration testing and security audits
- Advanced user access control
Administrative Measures:
- Staff training
- Preparation of GDPR policies and procedures
- Archiving of explicit consent documents
- Registration in the contact person and data controller registry
X. CONCLUSION:
Cyberattacks may not be preventable; however, the legal system "if preventive measures have not been taken" .
Board (KVK Kurulu)often does not forgive a data controller who has failed to take necessary precautions despite being attacked. Similarly, aggrieved consumers file a compensation lawsuit to claim damages.
In conclusion: "Responsibility lies as much with who committed the attack as with who failed to prevent it."
Trainee Instructor Esmanur AKTAŞ
