Skip to content
Noroxi
Compliance5 min read

KVKK data breach notification: the 72-hour rule and technical readiness

Under KVKK (Turkey’s personal data protection law), breach notification looks like a legal matter, but without logging and detection in place you won’t make the deadline.

At first glance, a data breach notification looks like a job for the legal team. In reality, meeting the notification deadline is entirely a matter of technical preparation. Without logs, you can’t tell what was exposed; without detection, you won’t even notice when the clock started.

When does the 72-hour clock start?

Under a decision of Turkey’s Personal Data Protection Board, a data controller must notify the Board as soon as reasonably possible, and no later than seventy-two hours after becoming aware of a breach. The key phrase is “becoming aware.” The clock starts when you notice the breach, not when the attack took place.

That is why detection sits at the heart of preparation. The longer it takes you to notice, the more of those seventy-two hours are already gone.

What should the notification include?

The Board’s form expects concrete information about the nature of the incident:

  • When and how the breach occurred
  • The approximate number of affected individuals and records
  • The categories of data affected
  • The likely consequences and the technical measures taken

If you only start gathering this information once the incident is underway, you will not make the deadline. Every item on that list is the output of logging and detection that were put in place beforehand.

Technical preparation: four fundamentals

1. Centralized, tamper-proof logging. At a minimum, authentication, data access and outbound data flows should be logged. Logs should be stored in a separate location that an attacker cannot wipe.

2. Detection rules. Rules that raise alerts for unusual access, bulk exports and after-hours administrative activity. If no alert fires, you find out about the incident days later.

3. A written response plan. Who gets informed, who makes the call, which system gets isolated, who prepares the notification. That sequence needs to be settled in advance, not in the middle of an incident.

4. Exercises. Run the plan through a tabletop scenario at least once a year. A plan that is tested for the first time during a real incident is not a plan.

A common mistake

The gap we see most often is that logs exist but are retained for far too short a period. Attacks frequently begin weeks before anyone notices. If your logs only cover the last few days, you will never see where the incident began, and you won’t be able to answer the “when” question on the notification form.

Conclusion

The 72-hour rule reads like a legal clause, but in practice it is an engineering requirement. The way to meet the deadline is logging, detection and response that are in place before the incident. We can build that setup with you and put it to the test in an exercise.

Up next

Security headers: ten vulnerabilities closed with five lines