Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
The Board’s decision published on 18 September 2019 concerns the minimum elements that must be contained in the notification to be made to the data subject and to the Board where personal data being processed are obtained by others through unlawful means. The decision dwells on the importance of data breach notification and, setting out the existing provisions of Law No. 6698 on the Protection of Personal Data (KVKK), specifies the minimum elements to be included in the notification. In order to examine the importance of personal data breach notification and the minimum elements that, as explained in the decision, such a notification must satisfy, I will try to explain the subject by considering first the KVKK and then the GDPR provisions. I will assess the Board’s decisions in question, nos. 2019/271 and 2019/10, in the light of this information.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
Elements Required in a Data Breach Notification and the Principles and Procedures of Notification: The Personal Data Protection Board’s Decisions No. 2019/271 of 18 September 2019 and No. 2019/10 of 24 January 2019
An Assessment
Assoc. Prof. Dr. Murat Volkan Dülger*
Introduction
Data breach notifications have recently become as important as data breaches themselves. Indeed, it is not only a controller’s committing a data breach but also its failure to notify such breaches that amounts to a violation of the obligations relating to data security laid down in Article 12 of the Law on the Protection of Personal Data (KVKK). Since it is, moreover, quite plain whether this obligation has been breached (the decisions rendered by the Personal Data Protection Board ex officio or upon complaint, without any notification by the controller), we come across a great many decisions in which, alongside the data breach, administrative fines were imposed because the breach notification had not been made.
Frankly, the fines imposed for breach of the notification obligation are by no means negligible either. The fact that amounts of TRY 450,000 (decision of 18.09.2019, No. 2019/269) and TRY 550,000 (decision of 11.04.2019, No. 2019/104) against Facebook, TRY 350,000 (decision of 16.05.2019, No. 2019/143) against Marriott, and TRY 100,000 against Cathay Pacific Airways and Clickbus Seyahat (decision of 16.05.2019, No. 2019/144 and decision of 16.05.2019, No. 2019/141) were imposed solely because no breach notification had been made demonstrates, I believe, the point I made in my previous sentence and the determination of the Personal Data Protection Board (the Board) in this matter. This effect has also led to a large number of data breach notifications being submitted to the Board recently, some of which were announced to the public through the Authority’s website. Microsoft, İş Bankası, Denizbank, TEB, ING Bank and Zynga Games are the controllers that come to my mind offhand as having made data breach notifications. The Board’s determination to apply Article 18 and to impose administrative fines where no data breach notification is made will increase the number of data breach notifications to be made.
On the other hand, although data breach notification is an obligation on which the Board has dwelt, it is unfortunately not a concept on which the statute dwells much. In Art. 12(5) the Law provides: “Where the personal data processed are obtained by others by unlawful means, the controller shall notify the data subject and the Board thereof as soon as possible. Where necessary, the Board may announce this on its own website or by any other method it deems appropriate.” Beyond this, however, it contains no explanatory provision whatsoever. As I shall discuss in detail below, this is a significant shortcoming. The Board, for its part, is endeavouring through its decisions to explain the data breach notification obligation and to remove the uncertainties. In this short article I shall deal with the decision which the Board rendered on this subject and published on 15 October 2019. In addition, I shall also try to touch on the decision of 24 January 2019, which may be regarded as its complement.
The decision which the Board published on 18 September 2019 deals with the minimum elements that must be contained in the notification to be made to the data subject and to the Board where the personal data processed are obtained by others by unlawful means. The decision dwells on the importance of data breach notification and, after setting out the existing provision of the KVKK, specifies the minimum elements to be contained in the notification.
In order to examine the importance of the notification of personal data breaches and the minimum elements which, as explained in the decision, such a notification must satisfy, I shall try to explain the subject by dwelling first on the provisions of the KVKK and then on those of the GDPR. I shall assess the Board’s decisions No. 2019/271 and No. 2019/10 in the light of this information.
I. Data Breach Notification under the KVKK and Its Conditions
Pursuant to Art. 12(1) of the KVKK, the controller is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, to prevent unlawful access to personal data and to ensure the safekeeping of personal data. The technical measures are ensuring cybersecurity, monitoring personal data security, ensuring the security of environments containing personal data, the storage of personal data in the cloud, the procurement, development and maintenance of information technology systems, and the backing-up of personal data. The administrative measures, for their part, are measures comprising the identification of existing risks and threats, the training of employees and awareness-raising activities, the determination of personal data security policies and procedures, the reduction of personal data as far as possible, and the management of relations with processors.
In addition to taking measures with regard to breaches, a further obligation of the controller is to notify the Board and the data subject of the breach where a data breach occurs. Law No. 6698 provides that, where the personal data processed are obtained by others by unlawful means, the controller must notify the data subject and the Board thereof as soon as possible. Indeed, in one of its decisions the Board held that the controller’s notifying the data breach that had occurred to the data subjects with a delay of 17 months and to the Board with a delay of 10 months went beyond what the Law means by “as soon as possible”.
However, on a matter as important as how a data breach notification is to be made and what its content is to be – a matter for which administrative fines in high amounts are provided – not only was there no provision in the statute, but there was also no clarity on the part of the Board until its decisions of 24.01.2019, No. 2019/10 and of 18.09.2019, No. 2019/271.
The Law merely regulates the existence of the obligation (Art. 12(5)) and the sanction for breach of the obligation (Art. 18(1)(b)), but contains no separate provision on data breach notification. In its decision No. 2019/10 the Board decided that the expression “as soon as possible” is to be interpreted as 72 hours, and addressed the form of the data breach notification, the form on which that notification is to be made and the concept of a data breach response plan. In its decision No. 2019/271, which forms the subject of this article, it clarified the minimum elements that must be contained in a data breach notification.
II. Data Breach Notification under the GDPR and Its Conditions
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller is obliged to communicate the personal data breach to the data subject without undue delay (GDPR, Art. 34(1)). In the case of a personal data breach, the controller is obliged to notify the personal data breach to the supervisory authority not later than 72 hours after having become aware of the breach (GDPR, Art. 33(1)). The data breach notification must contain the elements listed below (GDPR, Art. 33(3)):
• The nature of the data breach must be described, including explanations concerning the data subjects, the categories of data and their number.
• The name and the necessary details of the Data Protection Officer or of another contact point from which more information can be obtained must be provided.
• The likely consequences of the personal data breach must be described.
• The measures taken/proposed to mitigate the possible adverse effects of the data breach must be described.
Where it is not possible to provide this information at the same time, the information may also be provided in phases without undue further delay (GDPR, Art. 33(4)).
As can be seen, unlike the KVKK, the GDPR enumerates the minimum elements to be contained in the notification to be made to the data subject in the event of a data breach and regulates the exceptions to the making of a breach notification. According to the cross-reference in Art. 34 GDPR, in the notification to be made to the data subject where a data breach occurs, the name and contact details of the data protection officer or of another contact point from which more information can be obtained are communicated; and the likely consequences of the personal data breach, together with the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects, are described in clear and plain language.
In some cases, however, the controller may refrain from notifying the data subject of the matter. For this, it is necessary that the controller has implemented appropriate technical and organisational protection measures and that those measures – in particular measures such as encryption, which render the personal data unintelligible to anyone who is not authorised to access them – were applied to the personal data affected by the personal data breach; or that it has taken additional measures which ensure that the high risk to the rights and freedoms of the data subject is no longer likely to materialise; or that the notification would be of such a nature as to involve disproportionate effort. Even where the notification has not yet been made by the controller, the authority may impose a requirement that the notification be made, or may require that one of the exceptions to notification be fulfilled.
III. The Board’s Decision No. 2019/271 of 18 September 2019 and Decision No. 2019/10 of 24 January 2019
The fact that the KVKK did not regulate what form a data breach notification is to take and which elements are to be included in it used to raise question marks in the mind of a controller wishing to make a breach notification in practice. At the same time, this situation also caused problems for the persons affected by the breach, because controllers adopted a reticent attitude when giving information to data subjects. Yet data subjects, where their personal data have been obtained by others by unlawful means, should have the right to demand that measures be taken which make it possible to forestall as quickly as possible, and to minimise, the adverse consequences that such a breach may entail.
According to the Board’s decision in question, when a data breach occurs the controller, in notifying it in clear and plain language to the persons affected by the breach and to the Board, must address the following elements:
• when the breach occurred,
• which personal data were affected by the breach, on the basis of categories of personal data (distinguishing between personal data and special categories of personal data),
• the likely consequences of the personal data breach,
• the measures taken or proposed to be taken to mitigate the adverse effects of the data breach,
• the names and contact details of the contact persons who will enable the data subjects to obtain information about the data breach, or means of communication such as the full address of the controller’s web page, its call centre, etc.; it was decided that these elements must be included.
Pursuant to the Board’s decision of 24.01.2019, No. 2019/10, in turn, the following applies to the data breach notification, which must contain the elements enumerated above: the controller must notify the Board without delay and at the latest within 72 hours from the date on which it becomes aware of the breach; and, once the persons affected by the breach in question have been identified, the data subjects must also be notified within the shortest reasonable time – directly, if the data subject’s contact address can be reached, and, if it cannot, by appropriate methods such as publication on the controller’s own website.
In data breach notifications, the form contained in that decision must be used; the information concerning data breaches, their effects and the measures taken must be recorded by the controller and kept ready for examination by the Board. A data breach response plan must be prepared, covering matters such as to whom within the controller’s own organisation reports are to be made where a data breach occurs and, lastly, who within the controller’s own organisation bears responsibility for the notifications to be made under the Law and for assessing the likely consequences of the data breach; and this plan must be reviewed at regular intervals.
4. Legal Assessment of the Decisions
As I explained above, while the KVKK provides that the data breach notification to the data subject is to be made as soon as possible, it does not address the content of the notification or how it is to be made. An attempt was made to fill the first of the gaps relating to these two matters – which are highly important but not regulated in the statute – by the decision of 24.01.2019, No. 2019/10. It was decided “that, once the persons affected by the data breach in question have been identified by the controller, the data subjects shall also be notified within the shortest reasonable time, directly if the data subject’s contact address can be reached and, if it cannot, by appropriate methods such as publication on the controller’s own website”.
However, deciding only on how the notification is to be made was not sufficient for the KVKK’s aim of protecting the fundamental rights and freedoms of persons, first and foremost the right to respect for private life, in the processing of personal data. Moreover, these questions were frequently put to me in practice, and I used to answer them by filling this gap in the statute in the light of the provisions of the GDPR. Indeed, by rendering – belatedly, but correctly – a decision that runs parallel to the GDPR, the Board has both issued a decision that supports this view of mine and eliminated possible differences of opinion.
In the first decision, the uncertainty as to which elements this notification must contain, that is, as to its content, had not been removed. The first decision, which addressed only the procedure, has been completed by the second decision, in which the content too has been filled in. The basic problems concerning data breach notification are thus resolved by reading these two decisions together.
As the only difference from the GDPR, the Board stated that it must also be indicated when the breach occurred. Apart from that, the same solution as in the GDPR has been adopted. The adoption of such an approach is in fact a not very surprising and indeed expected state of affairs. It is nevertheless gratifying that the Board is aware of this gap in the statute and is trying to fill it through the new decisions it has rendered. The step to be taken now should be to provide for the data breach notification obligation in a separate and independent provision, just as in the GDPR, and to enact this case law of the Board into statute.
The fact that we are moving closer with each passing day from Directive 95/46/EC, the source text, towards the GDPR shows that our transition process in the field of personal data protection law is gathering pace and that an effort is being made to catch up with the European countries in this field within a short time.
Footnotes
- Academic / Attorney-at-Law. ↑
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
