A data breach affecting a Turkish subsidiary triggers obligations under Law No. 6698 (KVKK) that do not map neatly onto GDPR playbooks. The 72-hour notification clock starts when the data controller — not the local team, not the parent company — could reasonably have known. Administrative fines for breaches under Article 12 reached TRY 17,092,242 in 2026, and a turnover-based reform proposal remains before Parliament as of mid-2026, not yet enacted. This note sets out the practical framework for multinationals: what triggers notification, what the timeline looks like in practice, and where multinational response plans most commonly fail.

1. The 72-Hour Clock Starts Earlier Than You Think

KVKK requires the data controller to notify the Turkish Personal Data Protection Board within 72 hours of becoming aware of a breach affecting personal data. "Awareness" is not defined as the moment the incident is formally confirmed. In practice, it is treated as the moment when a reasonable data controller, exercising ordinary diligence, could have known.

For multinational groups, this creates a specific vulnerability. If the parent company's global SOC detects an incident affecting Turkish subsidiary systems on a Friday evening, and the Turkish compliance team learns about it on Monday morning, the clock has already been running for 60 hours.

Notification delays are treated by the Board as separate violations, not mitigating factors. A late report can compound the original breach rather than moderate it.

2. Notification: To Whom, and With What

Two parallel obligations exist under Article 12. First, notification to the Board within 72 hours. Second, notification to affected data subjects "as soon as possible."

The Board notification must include the nature of the breach, the categories and approximate number of data subjects affected, the categories and approximate number of records affected, likely consequences, and measures taken or proposed.

Notification to data subjects must be clear, plain, and in Turkish. Sending a group-wide English-language notice via a global template is not sufficient. A linguistically inaccessible notification is, in effect, no notification.

3. Cross-Border Group Structures

Where the Turkish entity is a data controller processing data on behalf of a global parent, or where personal data is transferred to a group parent for centralised processing, the KVKK cross-border transfer regime applies in parallel to breach obligations.

Standard contractual clauses drafted for GDPR do not automatically satisfy Article 9 of the KVKK. The Turkish framework has its own approved SCCs, its own notification requirements, and a more cautious posture on data flowing to jurisdictions without an adequacy decision. "We use the EU SCCs" is not a defence.

Where a breach occurs at the group level and affects Turkish data subjects, the Turkish entity remains responsible for its own notification obligations — even if the incident originated outside its control.

4. Where Multinational Response Plans Most Commonly Fail

Three failure patterns appear repeatedly.

The first is the escalation delay. Global incident response protocols route notifications through regional legal teams, then to local counsel, then to compliance officers. Each handoff consumes hours. The 72-hour clock does not pause for internal review.

The second is the translated-notice problem. The global privacy team drafts a data subject notification in English, and the Turkish team translates it. If the translation is completed after the notification window has closed — or if the underlying notice omits KVKK-specific disclosures — the notification is treated as incomplete.

The third is the forensic report gap. Boards frequently ask for the forensic report or an equivalent technical assessment as part of the investigation. If this report is prepared for global counsel only and marked privileged in a way that does not translate to Turkish procedural law, the controller may find itself unable to produce documentation on request.

5. Financial Exposure in 2026

Under Article 18 of the KVKK, administrative fines for 2026 range as follows (Official Gazette, 27 November 2025):

— Article 12 (data security): TRY 256,357 to TRY 17,092,242
— Article 15 (non-compliance with Board decisions): TRY 427,263 to TRY 17,092,242
— Article 16 (VERBİS registration): TRY 341,809 to TRY 17,092,242

Where a single incident constitutes multiple violations — for example, inadequate security measures under Article 12 combined with a failure to notify — the Board has authority to impose penalties cumulatively. The theoretical cumulative ceiling exceeds TRY 51 million.

A turnover-based reform proposal (annual revenue at 2–4%) remains before the Turkish parliament as of mid-2026, not yet enacted. If passed, the calculus for large multinationals would shift materially.

6. A Pre-Breach Framework Worth Building

The most effective breach response is the one designed before an incident occurs. Four elements make the difference between a controlled response and an escalating one.

A local escalation protocol that does not require sign-off from a jurisdiction where the 72-hour clock does not apply. The Turkish entity must be able to notify the Board without waiting for global approval.

Pre-approved notification templates in Turkish, reviewed by local counsel, ready to be populated with incident-specific facts.

A forensic engagement framework that produces a report usable in Turkish administrative proceedings — not one that is privileged only under the parent company's home jurisdiction.

A tabletop exercise every twelve months, run in Turkish, with the local team leading the response. Global playbooks work in theory. Local exercises show where they break.

Conclusion

Data breach exposure in Turkey is no longer a theoretical compliance concern; it is an operational risk with a defined financial ceiling and a compressed timeline. For multinationals, the gap between GDPR readiness and KVKK readiness is smaller than starting from zero — but it is not zero. The most common assumption we see, that global playbooks cover local obligations, is the assumption that becomes visible only after the notification window has closed.

The question worth asking today is narrower than "are we compliant?" It is: "if a breach occurred tomorrow, does our Turkish entity have the authority, the templates, and the local counsel to notify the Board within 72 hours — without waiting for anyone else?"

Sources

Law No. 6698 on the Protection of Personal Data (KVKK), Articles 9, 12, 15, 16, 18
Official Gazette, 27 November 2025 — 2026 revaluation rate (25.49%)
Personal Data Protection Board, publicly disclosed decisions (kvkk.gov.tr)
This note is provided for general information; it does not constitute legal advice on any specific matter.