On the night of a breach, let protocol, not panic take over.
Legal command centre at the moment of breach: the 72-hour notification regime, management of KVKK/GDPR and contractual notifications, evidence preservation, communications, and defence before the Board.
The anatomy of the first 72 hours
A data breach or cyber incident starts four clocks at once: the KVKK and GDPR notification deadlines, the 24-72 hour commitments in customer contracts (increasingly driven by NIS2), the notice conditions of the cyber-insurance policy, and the clock on evidence degradation. Managing these four clocks under a single command structure often determines the damage of the incident more than the incident itself.

Response chain
Detection and triage
rapid assessment of the affected data categories, number of individuals, and risk level — legal analysis of the notification threshold.
Containment and evidence
simultaneously with the technical team; preservation of system logs to a digital-forensics standard, with our e-discovery infrastructure.
Notifications
making Board/authority notifications on time and with the correct scope; where required, notice texts for the affected individuals.
Communications
structuring customer, press, and employee communications so as not to amplify litigation risk.
Aftermath
root-cause analysis, recourse (a faulty vendor, insurance), and feedback into the compliance programme.
Preparation is half the response
Making decisions in the moment of an incident is the most expensive method. A pre-prepared response plan answers, before the incident, the questions of who will be called, which logs will be frozen, where the notification drafts are, and who the spokesperson is. An annual tabletop exercise keeps the plan from remaining on paper. For the board-of-directors dimension, see our NIS2 analysis.
The map of notification regimes
Two of the four clocks come straight from statute. Under Article 12 KVKK the Board must be notified “at the earliest opportunity” — its settled practice takes 72 hours as the benchmark — and the affected individuals must be told by the quickest route available. Articles 33–34 GDPR set the 72-hour notification and, where the risk is high, direct communication to the individuals themselves. In the sectors caught by NIS2 the staged regime — early warning within 24 hours, notification within 72, a final report within a month — is now being pushed down to suppliers through contract. The notification threshold is a legal judgment: not every incident is notifiable, and notifying late is a ground for a penalty in its own right. Making that judgment inside a few minutes is only possible against a classification matrix worked out in advance.
The liability layer after the incident
Once the incident closes, the liability map opens: compensation claims from the data subjects, an assessment against the data-crime provisions of the Turkish Criminal Code (Articles 135–136), the question of supervisory liability for directors, and recourse against the suppliers at fault.
Recovery under the policy and recourse against others is a discipline of its own; running as it does on the language of the policy and the contract, that stage is handled by our cyber insurance and recourse service. The technical, organisational and sector-specific obligations are gathered together in our cyber security focus area.
We are by your side for Data Breach & Cyber Incident Response
Our Data & Cybersecurity Desk joins the incident as fast as the technical team: with a 24/7 access setup, ready-made notification templates and experience defending in Board proceedings. In ransom scenarios, we manage the payment decision by documenting its sanctions/AML dimension; once the incident closes, we carry the file into the compensation and recourse stage.

Other Applications of This Service
Compliance — our other specialised solutions in this area.
Matter Connections
The focus areas, practice areas, desks and legislation connected with this sub-service.
Our Matters in This Service
The anonymised examples of our work that relate to this service.
Uninterrupted legal counsel for a multinational supplier
Retainer-based support across day-to-day commercial operations, contract management and compliance processes.
Review the matter →ESG & ComplianceSupply chain due diligence (LkSG) compliance programme
Risk assessment and compliance architecture for a Turkish supplier network under the German LkSG.
Review the matter →Market AccessEstablishing a distribution network in Türkiye
Designing a market entry strategy, distributorship agreements and competition compliance.
Review the matter →The Team Delivering This Service
With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

Mehmet Köksal
Founder and Managing PartnerIstanbul · Berlin · KyreniaProfile →
Kübra Köksal-Yılmaz
PartnerBerlin · İstanbulProfile →
Gül Efem
Of CounselİstanbulProfile →
Sven Köksal
Legal EngineerBerlin · İstanbulProfile →
Gökçe Yıldırım
Of CounselİstanbulProfile →Related Publications
Fresh perspectives and guides from the Knowledge Centre.
Your obligations as data controller continue; recourse against the provider depends on the security and indemnity clauses in your contract. We strengthen supplier contracts based on incident scenarios.
A decision to pay carries serious risks in terms of sanctions lists, anti-money-laundering legislation, and insurance policy terms. The decision should not be taken alone; it should be documented with a legal assessment.
In effect yes: where personal data is unlawfully obtained, the breach must be notified to the Board within 72 hours of becoming aware of it (Article 12(5) of the Law; Board decision 2019/10 of 24.01.2019). Unlike the GDPR, notification to the Board does not turn on a risk threshold; the risk assessment determines whether the affected individuals must also be notified. The threshold analysis is a legal decision and must be documented.
The period runs from the moment of becoming aware and, in practice, should be managed in calendar days. That is why the response plan is built to cover weekend and holiday scenarios as well.
Data Breach & Cyber Incident Response — get the right legal support.
Let us identify the right solution together, drawing on our experience in Türkiye and the DACH region.
