A personal data breach is the unlawful obtaining, recording, use, transfer or disclosure of information belonging to a person. Your name, telephone number, address, identity number, location data, and audio and video recordings are all personal data. Information about health, biometric data, religion, sexual life and criminal convictions counts as special-category data and is subject to much stricter protection.
Which situations are breaches? #
- Processing data without consent or without a legal basis
- Using a telephone number given for a purchase to send advertising messages
- A company’s database leaking and customer information being spread
- A CV taken in a job application being transferred to other companies not applied to
- Footage from a site camera being shared on social media
- Data whose erasure has been requested not being erased
- The duty to inform not being performed at all
The order to follow: first, an application to the data controller #
A complaint cannot be made directly to the Personal Data Protection Board. It is compulsory first to apply in writing to the data controller, that is the body processing the data. The application can be made by written petition, registered electronic mail, secure electronic signature, or an e-mail address previously notified to the body.
The application must clearly set out identity details, the request and the information on which it is based. What can be requested is: to learn whether the data has been processed, to learn the purpose, to learn the third parties to whom it has been transferred, to have it corrected if processed incompletely or wrongly, to have it erased or destroyed, and to have those steps notified to the parties to whom it was transferred.
The data controller must conclude the application within thirty days at the latest. Where the process involves a further cost, the fee in the tariff can be charged; as a rule the application is free.
Complaint to the Board #
If the application is refused, if the answer given is found insufficient, or if no answer is given at all within thirty days, a complaint can be made to the Board. There are two periods and both must be met: the complaint must be made within thirty days of learning of the answer and, in any event, within sixty days of the date of the application.
The complaint is made through the Board’s online system or in writing. If the Board finds a breach, it requires the data controller to remedy the non-compliance and may impose an administrative fine. Where losses difficult to make good would arise and there is a clear non-compliance, it can also order the processing of data to be stopped.
Notification of a data leak #
When a personal data breach occurs — where a system leak happens, for instance — the data controller must notify the Board as soon as possible and within seventy-two hours at the latest. Notification must also be given to the affected individuals within the shortest reasonable time. Failure to notify is a non-compliance in itself and a ground for an administrative sanction.
Claim for compensation #
The administrative process does not make good the loss suffered. Independently of the route of complaint to the Board, a claim for pecuniary and non-pecuniary damages can be brought under the general provisions. The nature of the data, how widely it spread, the reputational loss suffered by the victim and the duration of the breach are all taken into account in setting the award.
In files where special-category data — health information or criminal convictions, for instance — has been disclosed, awards of non-pecuniary damages rise markedly. Having complained to the Board is not a condition for bringing a compensation claim; but a Board decision constitutes strong evidence in the civil case.
Situations that constitute an offence #
A personal data breach can also be an offence. The Turkish Criminal Code separately makes it an offence to record personal data unlawfully, to give it to another or to obtain it, and to fail to destroy it once the statutory period has passed. These offences do not depend on a complaint; the prosecutor opens an investigation of their own motion.
A criminal complaint can be made independently of the compensation claim and of the complaint to the Board. All three routes can be run at the same time. For the steps to follow at the investigation stage, see our guide to statements and the right of defence.
Unsolicited advertising messages #
A commercial electronic message sent without consent breaches both the data protection and the commercial communication rules. For messages of that kind, consent can be withdrawn through the message management system and a complaint can be made to the Ministry of Trade. Asking where your number was obtained from, by contrast, is the subject of a personal data application; the data controller is obliged to disclose the source of the data.
How should evidence be kept? #
The problem encountered most often in these files is proof. A screenshot on its own is weak evidence; if there is a chance the content will disappear, the securing of evidence should be sought from the court. Recording the messages received together with the date and time, keeping e-mails with their header information, and having web content certified by a notary all prove decisive at the later stage.
For the subject as a whole see our information law and data protection page, and for checking time limits our time limit and limitation checker.
What can be done against a Board decision? #
The Personal Data Protection Board examines the complaint and, if it finds a breach, directs the data controller to the way of putting it right; it may also impose an administrative fine. If the Board does not answer the complaint within sixty days, the request is treated as refused. Both that implied refusal and an express refusal are administrative acts: an action for annulment can be brought in the administrative court within sixty days of service. On the data controller’s side, an administrative fine is challenged not before the criminal judgeship of peace but, again, in the administrative court.
If you are a company: the first 72 hours after a breach #
When a data leak occurs, the data controller’s obligation runs independently of the leak itself: the position must be notified to the Board within seventy-two hours, reasonably, and to the affected individuals as soon as possible. Failure to notify gives rise to a penalty as a non-compliance separate from the breach.
What must be done within that window is, in order: isolating the affected system, preserving the log records unaltered, establishing which category of data affected how many people, completing the Board’s breach notification form and preparing the text of the notification to be sent to the individuals concerned. That these steps rest on a written response plan prepared in advance, rather than being improvised at the moment of the incident, directly affects both meeting the notification deadline and the scope of any penalty.
Is express consent always required? #
A widespread misconception is that every processing of data requires express consent. In fact the law lists conditions for processing other than express consent: that it is expressly provided for by law, that it relates directly to the conclusion or performance of a contract, that the data controller is meeting a legal obligation, that the data has been made public by the person concerned, that it is necessary for the establishment or protection of a right, and legitimate interest.
That has two practical consequences. First, for data that is necessary for the performance of a contract, separate consent need not be sought — and if it is sought, the consent may not meet the condition of “free will”, since withdrawing it would interrupt the service. Second, consent cannot be made a condition of the service: a consent obtained by saying “if you do not accept, we cannot provide the service” is not valid.
The distinction between commercial electronic messages and data protection #
Two separate sets of rules operate where advertising messages are sent without consent. Under the commercial communication rules, the complaint is made to the message management system and the Ministry of Trade, and an administrative fine comes into play. Under data protection, by contrast, the question is where the data was obtained from; the person concerned can apply to the data controller and ask for their data to be erased. The two routes are not alternatives to one another and can be run together.

