SSS · Data Breach & Cyber Incident Response

Do we have to notify the Board of every data breach?

Personal data breaches are notified to the Board as soon as possible and within 72 hours of becoming aware (Board decision No. 2019/10). Under the KVKK this is not gated on a high risk thre…

Updated · July 20261 min readCategory · Data Breach & Cyber Incident Response
Short answer

In effect yes: where personal data is unlawfully obtained, the breach must be notified to the Board within 72 hours of becoming aware of it (Article 12(5) of the Law; Board decision 2019/10 of 24.01.2019). Unlike the GDPR, notification to the Board does not turn on a risk threshold; the risk assessment determines whether the affected individuals must also be notified. The threshold analysis is a legal decision and must be documented.

Personal data breaches are notified to the Board as soon as possible and within 72 hours of becoming aware (Board decision No. 2019/10). Under the KVKK this is not gated on a high risk threshold the way GDPR Article 33 is — the risk assessment mainly governs whether the affected individuals must also be informed, which is required where the breach is likely to harm them. The threshold analysis is a legal decision and must be documented.

Because the clock is short, the documented assessment and a ready notification template should sit in the response plan before any incident, not be drafted under pressure.

Shall we apply this matter to your situation?

Tell us your specific situation in a few sentences; we'll assess it with the right team.

Get in touch
This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Categories
Data Breach & Cyber Incident Response

The right start means a predictable process.

From the first meeting to completion of the work; let's plan every step transparently.