Open menu
26February2019

Data Breach Notification Procedure for the Data Controllers Has Been Published

An announcement (the “Announcement”) regarding the personal data breach notification procedures, has published with the 2019/10 numbered decision of Personal Data Protection Institution on 24.01.2019. The “Personal Data Breach Notification Form” is also shared within this Announcement, you may reach the sample form here.

The Announcement mentions about the obligations of the Data Controller stated in the Art. 12 of the Personal Data Protection Law ("KVKK") and Data Controllers should inform the institution as soon as possible in case of any data breach. The institution has expressed that this notification process aims to prevent negative conclusions or to minimize risks that arise from these breaches on data subjects and others.

Under this scope, the Institution has taken below mentioned decisions to create a ground parallel with European General Data Protection Regulation (GDPR) which constitutes basis for the KVKK:

  1. The “as soon as” statement in the clause 5 of the Art. 12 of KVKK that follows “in case a processing data will be obtained by third parties in unlawful ways, the data controller should inform the one that concerns and the institution as soon as possible…” should be interpreted as 72 hours as of learning the breach and also the data subject should be informed via contact information or (unless a contact info is not provided) an announcement should be made on the data controller’s own web-page;
  2. If no notification with a valid reason will be made to the institution within 72 hours, the data controller should provide delay reasons to the institution along with the notification;
  3. The Personal Data Breach Notification Form should be submitted with the notification made to the Institution and information should be provided one by one if it is not possible to provide all information at the same time;
  4. The Data Controller should save information, affects and preventions regarding the data breach and should keep them for the investigation of the Institution;
  5. If the data breached has actualized with data possession of third party from the data processor, the data processor should inform data controller as soon as possible,
  6. If data breach takes place in a data controller resident abroad and this situation affects the ones in Türkiye or the service/good to be provided is benefitted in Türkiye, then same procedure applies for the notification to the Institution;
  7. Data controller should prepare “data breach intervention plan” and should review this plan regularly; this plan should include:
    • The ones to be reported,
    • The notification to be made under the Law and the evaluation of probable affects,
    • The authority to be responsible in the data controller.

You may reach the full text of the decision here.

Author CottGroup Hukuk ve Mevzuat Ekibi, Category Personal Data Protection Law

  • Notification!

    Contents provided in this article serve to informative purpose only. The article is confidential and property of CottGroup® and all of its affiliated legal entities. Quoting any of the contents without credit being given to the source is strictly prohibited. Regardless of having all the precautions and importance put in the preparation of this article, CottGroup® and its member companies cannot be held liable of the application or interpretation of the information provided. It is strictly advised to consult a professional for the application of the above-mentioned subject.

    For each concrete situation, it is strongly advised to seek guidance from a professional advisor. If you are a customer of ours, please consult with your customer representative before taking any action related to the announcement. If you are not a customer, seek advice from an expert.

About The Author

/tr/mevzuat/item/veri-sorumlulari-icin-kisisel-veri-ihlali-bildirim-proseduru

Other Legislation

Bu web sitesi çerez kullanıyor.

Bu internet sitesinde, kullanıcı deneyimini geliştirmek, verimli çalışmasını sağlamak ve istatistiki verileri takip etmek için çerezler kullanılmaktadır. Sitemizi kullanarak çerezleri kabul etmiş olursunuz. Çerezleri nasıl kullandığımız ile ilgili detaylı bilgi için lütfen Çerezler (Cookies) sayfasını okuyunuz. Bu seçim 30 gün süreyle ya da tarayıcınızdaki çerezleri siz silene kadar geçerlidir.

Çerez Tercihleri Cookie Preferences

Çerezleri Ayarla

Çerezler, web sitelerinin kullanıcı deneyimini daha verimli hale getirmek için kullanabileceği küçük metinlerdir. Kanun, bu sitenin işleyişi için kesinlikle gerekli olan çerezlerin cihazınıza saklanabileceğini belirtir. Diğer tüm çerez türleri için izninize ihtiyacımız var. Bu site, çeşitli türde çerezler kullanmaktadır. Bazı çerezler, sayfalarımızda görünen üçüncü taraf hizmetler tarafından yerleştirilir.

Verdiğiniz izinler aşağıda yer alan web siteleri için geçerlidir:

  • www.cottgroup.com