Compliance · Alt Service

On the night of a breach, let protocol, not panic take over.

Legal command centre at the moment of breach: the 72-hour notification regime, management of KVKK/GDPR and contractual notifications, evidence preservation, communications, and defence before the Board.

Parent ServiceCompliance
Focus AreasCybersecurity·Data
Sub-service Dossier
Overview

The anatomy of the first 72 hours

A data breach or cyber incident starts four clocks at once: the KVKK and GDPR notification deadlines, the 24-72 hour commitments in customer contracts (increasingly driven by NIS2), the notice conditions of the cyber-insurance policy, and the clock on evidence degradation. Managing these four clocks under a single command structure often determines the damage of the incident more than the incident itself.

Data Breach & Cyber Incident Response
01

Response chain

a)

Detection and triage

rapid assessment of the affected data categories, number of individuals, and risk level — legal analysis of the notification threshold.

b)

Containment and evidence

simultaneously with the technical team; preservation of system logs to a digital-forensics standard, with our e-discovery infrastructure.

c)

Notifications

making Board/authority notifications on time and with the correct scope; where required, notice texts for the affected individuals.

d)

Communications

structuring customer, press, and employee communications so as not to amplify litigation risk.

e)

Aftermath

root-cause analysis, recourse (a faulty vendor, insurance), and feedback into the compliance programme.

02

Preparation is half the response

Making decisions in the moment of an incident is the most expensive method. A pre-prepared response plan answers, before the incident, the questions of who will be called, which logs will be frozen, where the notification drafts are, and who the spokesperson is. An annual tabletop exercise keeps the plan from remaining on paper. For the board-of-directors dimension, see our NIS2 analysis.

03

The map of notification regimes

Two of the four clocks come straight from statute. Under Article 12 KVKK the Board must be notified “at the earliest opportunity” — its settled practice takes 72 hours as the benchmark — and the affected individuals must be told by the quickest route available. Articles 33–34 GDPR set the 72-hour notification and, where the risk is high, direct communication to the individuals themselves. In the sectors caught by NIS2 the staged regime — early warning within 24 hours, notification within 72, a final report within a month — is now being pushed down to suppliers through contract. The notification threshold is a legal judgment: not every incident is notifiable, and notifying late is a ground for a penalty in its own right. Making that judgment inside a few minutes is only possible against a classification matrix worked out in advance.

04

The liability layer after the incident

Once the incident closes, the liability map opens: compensation claims from the data subjects, an assessment against the data-crime provisions of the Turkish Criminal Code (Articles 135–136), the question of supervisory liability for directors, and recourse against the suppliers at fault.

Recovery under the policy and recourse against others is a discipline of its own; running as it does on the language of the policy and the contract, that stage is handled by our cyber insurance and recourse service. The technical, organisational and sector-specific obligations are gathered together in our cyber security focus area.

Why Köksal?

We are by your side for Data Breach & Cyber Incident Response

Our Data & Cybersecurity Desk joins the incident as fast as the technical team: with a 24/7 access setup, ready-made notification templates and experience defending in Board proceedings. In ransom scenarios, we manage the payment decision by documenting its sanctions/AML dimension; once the incident closes, we carry the file into the compensation and recourse stage.

Köksal team multidisciplinary work
05

Other Applications of This Service

Compliance — our other specialised solutions in this area.

Compliance — back to the parent service
06

Matter Connections

The focus areas, practice areas, desks and legislation connected with this sub-service.

08

The Team Delivering This Service

With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

09

Related Publications

Fresh perspectives and guides from the Knowledge Centre.

Your obligations as data controller continue; recourse against the provider depends on the security and indemnity clauses in your contract. We strengthen supplier contracts based on incident scenarios.

A decision to pay carries serious risks in terms of sanctions lists, anti-money-laundering legislation, and insurance policy terms. The decision should not be taken alone; it should be documented with a legal assessment.

In effect yes: where personal data is unlawfully obtained, the breach must be notified to the Board within 72 hours of becoming aware of it (Article 12(5) of the Law; Board decision 2019/10 of 24.01.2019). Unlike the GDPR, notification to the Board does not turn on a risk threshold; the risk assessment determines whether the affected individuals must also be notified. The threshold analysis is a legal decision and must be documented.

The period runs from the moment of becoming aware and, in practice, should be managed in calendar days. That is why the response plan is built to cover weekend and holiday scenarios as well.

Service

Data Breach & Cyber Incident Response — get the right legal support.

Let us identify the right solution together, drawing on our experience in Türkiye and the DACH region.