Introduction
Compensation for data breach and privacy violations in Turkey is an increasingly important area of Turkish compensation law, technology law, consumer law, employment law, healthcare law, e-commerce law, and corporate compliance. In the digital economy, personal data is collected, stored, transferred, analyzed, and shared by companies, hospitals, banks, schools, employers, hotels, online platforms, mobile applications, insurance companies, public institutions, and service providers. When this data is processed unlawfully, disclosed without authorization, accessed by third parties, transferred abroad unlawfully, used for purposes beyond consent, or leaked due to weak security measures, the affected person may have the right to claim compensation.
Data breach and privacy violation cases may involve identity information, phone numbers, e-mail addresses, home addresses, passport details, Turkish identity numbers, bank information, medical records, biometric data, genetic data, location data, photographs, private messages, employment records, customer data, children’s data, online account information, IP logs, shopping history, or sensitive personal information.
The constitutional foundation is strong. Article 20 of the Constitution of the Republic of Turkey protects private and family life and expressly recognizes the right to request protection of personal data. This constitutional right includes being informed about personal data, accessing it, requesting correction or deletion, and learning whether it is used consistently with its intended purposes. Personal data may be processed only in cases provided by law or with explicit consent, and the principles and procedures must be regulated by law.
The main statutory framework is the Personal Data Protection Law No. 6698, commonly known as KVKK. The official English text of the law states that its purpose is to protect fundamental rights and freedoms, particularly the right to privacy, with respect to processing personal data and to set obligations, principles, and procedures for persons who process personal data.
What Is a Data Breach Under Turkish Law?
A data breach generally occurs when personal data is unlawfully accessed, disclosed, obtained, lost, altered, transferred, destroyed, published, or made available to unauthorized persons. It may happen because of hacking, phishing, ransomware, weak passwords, employee misconduct, wrong e-mail delivery, misconfigured cloud storage, database exposure, stolen laptops, unauthorized access by personnel, insufficient encryption, poor vendor management, unlawful data sharing, or failure to delete old data.
Under KVKK, personal data means any information relating to an identified or identifiable natural person. Processing is defined broadly and includes collection, recording, storage, protection, alteration, disclosure, transfer, retrieval, making available, categorization, and prevention of use. The law also defines the data controller as the person or legal entity determining the purposes and means of processing and responsible for establishing and managing the data filing system.
This broad definition means that a privacy violation in Turkey does not require a large-scale cyberattack. A single unlawful disclosure of medical records, an employer sharing an employee’s private information, a company sending customer data to the wrong recipient, or a website publishing personal information without legal basis may create a legal issue.
Legal Basis of Compensation for Data Breach
The most direct basis for compensation is Article 11 of KVKK. The law gives each person several rights against the data controller, including the right to learn whether personal data is processed, request information, learn the purpose of processing, know third parties to whom data is transferred, request correction, request erasure or destruction under legal conditions, object to certain automated results, and claim compensation for damage arising from unlawful processing of personal data.
This right to compensation is crucial. It means that data protection law is not only an administrative compliance system. It also creates a civil remedy for individuals harmed by unlawful data processing. Affected persons may claim material damages, moral compensation, or both, depending on the nature and consequences of the violation.
Compensation claims may also be supported by general provisions of Turkish private law. If a privacy violation damages personality rights, moral compensation may be requested under the Turkish Code of Obligations and Turkish Civil Code principles. If the violation causes financial loss, such as identity theft, account compromise, fraud, loss of business, medical expenses, or costs of restoring digital security, material damages may also be claimed.
Data Controller’s Security Obligations
Data controller liability is central in data breach compensation cases. Article 12 of KVKK requires the data controller to take all necessary technical and organizational measures to provide an appropriate level of security for preventing unlawful processing, preventing unlawful access, and ensuring protection of personal data. If processing is carried out by another person on behalf of the data controller, the data controller is jointly responsible with that person for these measures. The data controller must also carry out or have necessary audits carried out within its organization.
This is particularly important in outsourcing relationships. A company cannot automatically escape liability by saying that the breach occurred through a software provider, call center, cloud service, payroll company, marketing agency, hospital information system, or external IT vendor. If a processor handles data on behalf of the controller, the controller’s responsibility must still be examined under Article 12.
Technical and organizational measures may include access control, encryption, logging, employee training, role-based authorization, secure software development, penetration testing, vendor due diligence, incident response plans, data minimization, retention policies, secure destruction, multi-factor authentication, backup security, and regular audits. The exact standard depends on the nature of data, risk level, sector, processing volume, and sensitivity of information.
Notification Obligations After a Data Breach
Article 12 of KVKK also regulates breach notification. If processed data is obtained by others through unlawful means, the data controller must communicate the breach to the data subject and notify the Personal Data Protection Board within the shortest time. The Board may announce the breach on its official website or by another method it considers appropriate.
Failure to notify can increase legal risk. It may also strengthen a compensation claim if the delay caused additional damage. For example, if a company fails to inform affected customers that identity numbers, passwords, medical data, or bank-related data were leaked, the affected individuals may lose the opportunity to protect themselves early by changing passwords, notifying banks, monitoring accounts, or preventing fraud.
In data breach litigation, the notification timeline is very important. The claimant should ask when the breach occurred, when the controller discovered it, what data categories were affected, how many people were affected, what measures were taken, whether the Board was notified, whether affected persons were notified, and whether the controller minimized further harm.
What Counts as Privacy Violation?
Privacy violations may arise even without a technical data breach. A person’s privacy may be violated by unlawful surveillance, unauthorized publication of photographs, disclosure of private messages, publication of health data, sharing of personal address, doxxing, unlawful use of CCTV footage, disclosure of employee disciplinary records, unauthorized marketing communications, unlawful transfer of customer data, or use of personal data for purposes beyond the original legal basis.
Some privacy violations may also have criminal consequences. The Turkish Criminal Code includes offenses concerning violation of privacy, recording of personal data, and unlawfully obtaining, disseminating, or giving personal data to others. English translations of Turkish criminal law materials identify Article 134 on violation of private life, Article 135 on unlawful recording of personal data, and Article 136 on unlawfully obtaining, disseminating, or giving personal data.
Criminal proceedings and civil compensation proceedings are different. A criminal complaint may seek investigation and punishment. A civil lawsuit seeks compensation. In many cases, both routes may be considered, but a criminal complaint does not automatically result in payment of compensation.
Material Damages After a Data Breach
Material damages are financial losses caused by the data breach or privacy violation. These may include money stolen through identity theft, unauthorized banking transactions, costs of replacing documents, digital security expenses, credit monitoring costs, professional consultancy expenses, loss of business, loss of employment opportunity, medical treatment expenses caused by psychological trauma, costs of changing phone numbers or addresses, and financial losses resulting from fraud enabled by leaked data.
For example, if a leaked identity number, phone number, address, and banking information are used for fraud, the victim may claim the resulting financial loss if causation can be proven. If a businessperson’s private commercial information is leaked and competitors misuse it, commercial damages may be evaluated. If a patient’s medical data is unlawfully disclosed and the patient loses employment or suffers measurable financial consequences, material compensation may be claimed.
Material damages require proof. The claimant should collect bank records, fraud reports, police complaints, invoices, expert reports, correspondence, account access logs, screenshots, credit records, identity replacement expenses, and any document showing the link between the breach and the financial loss.
Moral Compensation for Privacy Violations
Moral compensation is often the most important remedy in privacy and data breach cases. Not every data breach causes direct financial loss, but unlawful disclosure of personal data may cause fear, humiliation, anxiety, loss of dignity, reputational harm, social embarrassment, loss of trust, psychological distress, or serious disruption of private life.
Moral compensation may be especially relevant where the breach involves health data, sexual life, biometric data, genetic data, children’s data, criminal record information, financial vulnerability, private photographs, correspondence, family matters, or location data. Special categories of personal data receive stronger protection under KVKK. The official text lists race, ethnic origin, political opinion, philosophical belief, religion, association or union membership, health data, sexual life, criminal convictions, biometric data, and genetic data among special categories of personal data. The 2024 amendments also revised the legal conditions for processing special categories of personal data.
A moral compensation petition should not merely state that the claimant was “disturbed.” It should explain the concrete emotional and social consequences: fear of fraud, public embarrassment, family pressure, professional harm, anxiety about medical privacy, distress caused by exposure of private photographs, or loss of control over personal identity.
Unlawful Processing of Health Data
Health data is one of the most sensitive forms of personal data. Hospitals, clinics, laboratories, pharmacies, insurance companies, employers, medical tourism agencies, and digital health platforms may process health data. A breach involving diagnosis, test results, prescriptions, surgeries, mental health records, reproductive health data, genetic information, or disability status may cause serious harm.
Under KVKK, health data falls within special categories of personal data. Processing of special categories is generally prohibited unless one of the legal conditions exists, such as explicit consent, express legal provision, protection of life or physical integrity, establishment or protection of a right, public health and medical diagnosis or treatment purposes by persons under confidentiality obligations or authorized public institutions, and other listed conditions. Adequate measures determined by the Board must also be implemented.
If a hospital employee shares a patient file with unauthorized persons, if a medical tourism agency discloses patient photographs, if a laboratory sends test results to the wrong person, or if an employer demands unnecessary health information, compensation may be considered depending on the facts.
Employee Data Breaches
Employers process large amounts of employee data: identity information, payroll, bank accounts, disciplinary records, performance reports, health documents, camera recordings, biometric access data, e-mails, phone logs, and leave records. Employee data breaches may arise from excessive monitoring, unauthorized sharing, weak HR systems, unlawful biometric systems, disclosure of salary information, or publication of disciplinary records.
Employee data claims may involve KVKK, labor law, personality rights, employment contracts, and sometimes criminal law. Employers must process employee data lawfully, fairly, proportionately, and for legitimate purposes. They must also provide proper information notices, define retention periods, limit access, and protect data from unauthorized disclosure.
A dismissed employee may also raise KVKK issues if the employer shares negative information with future employers, publishes private workplace records, refuses access to personal data, keeps data longer than necessary, or uses employee data for retaliation. Evidence may include e-mails, HR documents, internal messages, screenshots, access records, employment contracts, privacy notices, and witness statements.
Consumer, E-Commerce and Platform Data Breaches
E-commerce platforms, mobile applications, online marketplaces, delivery platforms, fintech services, subscription platforms, hotels, airlines, and telecom-related service providers may process large volumes of consumer data. A breach may expose names, addresses, phone numbers, order history, card-related information, location data, user profiles, and private preferences.
For consumers, a data breach may cause spam, phishing, identity theft, reputational harm, stalking risk, or financial fraud. If an online platform fails to maintain adequate security or uses personal data beyond the disclosed purpose, the consumer may seek remedies before the data controller, the Personal Data Protection Board, and civil courts.
Where the data breach is linked to a consumer service, consumer law may also be relevant. However, KVKK compensation is not limited to consumers. It protects natural persons whose personal data is processed, including customers, employees, patients, students, users, guests, and business contacts.
Data Breach by Public Authorities
Public institutions also process personal data. Schools, municipalities, hospitals, universities, law enforcement units, immigration authorities, social services, and other public bodies may hold sensitive information. A privacy violation by a public authority may involve administrative law, constitutional rights, KVKK, and compensation principles.
Article 40 of the Constitution states that everyone whose constitutional rights and freedoms have been violated has the right to request prompt access to competent authorities, and damages incurred through unlawful treatment by public officials shall be compensated by the State according to law, with the State reserving recourse to the responsible official.
If the breach is caused by a public hospital, public school, municipality, or administrative body, the legal route may differ from a private company claim. Administrative application and administrative court procedure may need to be evaluated. The correct defendant, time limits, and procedural path should be determined before filing.
Cross-Border Data Transfers and Privacy Risk
Cross-border transfers are increasingly important in data breach and privacy claims. Companies often use foreign cloud providers, international CRM systems, global HR platforms, overseas call centers, foreign parent companies, and analytics tools. The 2024 amendments to Article 9 of KVKK introduced a revised cross-border transfer system based on adequacy decisions, appropriate safeguards, standard contracts, binding corporate rules, written commitments, and limited incidental transfer situations.
If personal data is transferred abroad unlawfully and later misused, lost, or disclosed, the cross-border transfer structure may become a key issue in compensation litigation. A claimant may ask whether there was an adequacy decision, whether appropriate safeguards were used, whether a standard contract was notified to the Authority within the required period, whether the transfer was truly incidental, and whether the data subject was properly informed.
Cross-border transfer violations may be especially important in international companies, health tourism, hotels, travel agencies, online platforms, SaaS services, fintech, outsourcing, and multinational employment relationships.
Application to the Data Controller
Before complaining to the Personal Data Protection Board, the data subject generally must apply to the data controller. Article 13 provides that data subjects must make requests relating to implementation of the law to the data controller in writing or by other means determined by the Board. The controller must respond as soon as possible and at the latest within thirty days. The response may accept the request or reject it with justified grounds.
This step is not merely procedural. It can help identify the facts needed for compensation: what data was processed, why it was processed, with whom it was shared, whether it was transferred abroad, whether it was deleted, whether there was a breach, and what security measures existed.
A strong application should be clear, specific, and evidence-based. It may request information about processed data, purposes, legal basis, recipients, foreign transfers, breach details, security measures, deletion or correction, and compensation position. The application should be documented carefully because it may later support a Board complaint or civil lawsuit.
Complaint to the Personal Data Protection Board
If the data controller refuses the request, gives an insufficient response, or does not respond within the legal period, the data subject may lodge a complaint with the Board. Article 14 provides that the complaint must be filed within thirty days from learning the controller’s response, and in any case within sixty days from the request date. A complaint cannot be lodged before exhausting the application remedy to the data controller. Article 14 also expressly reserves the right to compensation under general provisions for those whose personal rights are violated.
The Board may examine the complaint or act ex officio. Article 15 allows the Board to demand information and documents, conduct examinations, order remediation of violations, publish resolutions in widespread infringement cases, and stop processing or cross-border transfers where explicit illegality and damage difficult or impossible to compensate exist.
A Board decision may support a civil compensation lawsuit, but administrative sanctions and civil compensation are different. The Board may impose administrative measures or fines, while a civil court determines compensation payable to the harmed person.
Civil Lawsuit for Compensation
A person harmed by a data breach or privacy violation may file a civil compensation lawsuit where legal conditions are met. The lawsuit should identify the data controller or responsible party, describe the unlawful processing or breach, explain the violated rights, prove damage, establish causation, and request material and/or moral compensation.
The claim may be based on KVKK Article 11, general tort principles, personality rights, contractual liability, consumer law, employment law, administrative liability, or a combination of these depending on the facts.
The petition should explain the data categories involved, sensitivity of the information, number of unauthorized recipients, duration of exposure, whether data was published online, whether data was transferred abroad, whether the controller notified the affected person, whether security measures were adequate, and how the claimant was harmed.
In moral compensation claims, the strongest argument is usually loss of control over private information, fear of misuse, humiliation, damage to reputation, psychological distress, and exposure of sensitive personal life. In material compensation claims, the strongest argument is measurable financial loss supported by documents.
Evidence in Data Breach and Privacy Claims
Evidence is decisive. Data breach cases are often technical, and much of the evidence may be controlled by the data controller. The claimant should collect screenshots, notification e-mails, SMS messages, privacy notices, consent forms, data subject application records, Board complaint records, company responses, breach announcements, fraud reports, bank records, police complaints, expert reports, metadata, access logs where available, and witness statements.
If private information was published online, screenshots should show the URL, date, time, account name, platform, content, and visibility. Notarial determination or technical expert preservation may be useful where content can be deleted quickly.
If the claim involves hacking or unauthorized access, technical expert reports may be necessary. Experts may evaluate whether reasonable security measures existed, whether access controls were weak, whether logs show unauthorized access, whether passwords were stored insecurely, whether data was encrypted, and whether the breach was foreseeable.
Burden of Proof and Causation
The claimant must generally prove the violation, damage, and causal link. In some cases, the controller’s statutory obligations may help frame the claim. For example, if the controller cannot explain what security measures were taken, cannot produce access logs, failed to notify the breach, or ignored a data subject request, this may support the claimant’s position.
Causation can be difficult. The claimant must show that the financial loss or moral harm resulted from the specific breach or unlawful processing. If a person receives phishing messages after a data leak, causation may be disputed unless the leaked data and subsequent fraud are connected. If sensitive health data is disclosed to an employer, causation may be easier to show if adverse consequences follow directly.
A strong case should build a timeline: collection of data, unlawful processing or breach, discovery, notification or lack of notification, misuse or exposure, emotional or financial consequences, applications made, responses received, and continuing harm.
Administrative Fines and Their Relationship to Compensation
Administrative fines are imposed by the Board and are paid to the State, not directly to the injured person. They may still be relevant because a fine or Board finding may support the argument that the controller violated KVKK duties.
Article 18 of KVKK regulates administrative fines for failures such as breach of disclosure obligations, data security obligations, Board decisions, registry obligations, and the cross-border transfer notification obligation added in 2024. The official English law text reflects the 2024 amendment adding a fine for failure to fulfill the notification obligation under Article 9(5).
However, a person seeking personal recovery should not rely only on an administrative complaint. To obtain compensation, a civil lawsuit or settlement strategy may be necessary.
Criminal Complaint and Civil Compensation
Some data breaches may involve criminal offenses. Unlawful recording of personal data, unlawful acquisition or dissemination, violation of private life, unlawful publication of private images, or failure to destroy data may lead to criminal complaints depending on the facts. Criminal materials identify Article 136 of the Turkish Criminal Code as punishing unlawful giving, publishing, or acquisition of personal data.
Criminal proceedings may help obtain evidence, identify perpetrators, preserve digital records, and establish unlawful conduct. However, criminal punishment and civil compensation are separate. A criminal complaint may be useful but may not fully compensate the victim’s material and moral losses. Therefore, a civil compensation path should be evaluated independently.
Claims by Foreigners in Turkey
Foreign nationals may claim compensation for data breach and privacy violations in Turkey if their personal data is processed in Turkey or by a Turkish data controller, or if the violation has sufficient connection with Turkey. This may include foreign patients in medical tourism, tourists in hotels, foreign employees, international students, expatriates, foreign customers of Turkish platforms, or foreign investors whose personal data is processed by Turkish companies.
Foreign claimants should preserve passports, contracts, treatment records, booking documents, e-mails, privacy notices, consent forms, invoices, platform messages, breach notifications, screenshots, and evidence of damage. If documents are issued abroad, sworn translation and apostille or legalization may be required depending on procedure.
A Turkish lawyer can usually pursue data subject applications, Board complaints, criminal complaints, and civil compensation lawsuits through a properly issued power of attorney.
Common Mistakes in Data Breach Claims
One common mistake is confusing a KVKK complaint with compensation. A Board complaint may lead to administrative action, but personal compensation usually requires a separate civil claim or settlement.
Another mistake is failing to apply to the data controller first. Article 14 requires exhaustion of the Article 13 application route before lodging a Board complaint.
A third mistake is failing to preserve digital evidence. Online content, breach announcements, messages, and account logs may disappear quickly.
A fourth mistake is claiming material damages without financial proof. Identity theft, fraud, or income loss must be supported by documents.
A fifth mistake is underestimating moral compensation in sensitive data cases. Disclosure of health, biometric, sexual life, children’s, or location data may have serious non-financial consequences.
A sixth mistake is signing a settlement or waiver before understanding the scope of the breach, future risks, and continuing misuse of data.
Why Work With a Turkish Data Protection Lawyer?
Compensation for data breach and privacy violations in Turkey requires knowledge of KVKK, constitutional privacy rights, civil compensation law, criminal law, technology evidence, cybersecurity, consumer law, employment law, healthcare confidentiality, and administrative procedure.
A Turkish data protection lawyer can identify the data controller, prepare data subject applications, file Board complaints, preserve digital evidence, evaluate technical security failures, coordinate expert reports, calculate material damages, prepare moral compensation claims, file criminal complaints where appropriate, negotiate settlements, and pursue civil litigation.
For companies, legal advice is equally important. A company facing a breach must manage notification duties, evidence preservation, internal investigation, communications with affected persons, vendor liability, Board correspondence, and litigation risk. Poorly handled breach response may increase both administrative fines and civil compensation exposure.
Conclusion
Compensation for data breach and privacy violations in Turkey protects individuals whose personal data, private life, dignity, reputation, financial security, or sensitive information has been harmed by unlawful processing, unauthorized disclosure, weak security, unlawful transfer, or misuse. The Constitution protects private life and personal data as fundamental rights, while KVKK provides data subject rights, data controller obligations, security duties, breach notification rules, complaint procedures, and the right to claim compensation.
A successful data breach compensation claim requires more than proving that data was processed. The claimant must show unlawful processing or breach, damage, causal link, and responsible party. Material damages should be supported by financial documents. Moral compensation should be justified through the seriousness of the privacy violation, sensitivity of data, extent of disclosure, emotional impact, and continuing risk.
Anyone affected by a data breach or privacy violation in Turkey should act quickly, preserve evidence, apply to the data controller, consider a Board complaint within the statutory deadlines, evaluate criminal complaint options where relevant, and obtain legal advice before signing any settlement. A carefully prepared data breach compensation claim can make a decisive difference in protecting privacy, reputation, financial security, and personal dignity.
Yanıt yok