Personal data breaches are notified to the Board as soon as possible and within 72 hours of becoming aware (Board decision No. 2019/10). Under the KVKK this is not gated on a high risk threshold the way GDPR Article 33 is — the risk assessment mainly governs whether the affected individuals must also be informed, which is required where the breach is likely to harm them. The threshold analysis is a legal decision and must be documented.
Because the clock is short, the documented assessment and a ready notification template should sit in the response plan before any incident, not be drafted under pressure.
Shall we apply this matter to your situation?
Tell us your specific situation in a few sentences; we'll assess it with the right team.