In short
How many hours do I have to report a data breach?
A data controller must notify the authority within 72 hours at the latest from the date it learns of a personal data breach; the period was set by the data protection board's decision 2019/10 of 24 January 2019. Notification is made using the breach notification form the authority publishes. Neuros writes the detection mechanism that starts that clock into the delivery scope.
Steps
0 / 6 steps
Start the clock and write it down
Whoever first becomes aware records the date and time. That single line becomes the basis of every later discussion: there is no other evidence of where the 72 hours began.
Watch out: "We suspected but were not sure" is also a date; record the uncertainty too.
Stop the spread
Close the leaking access, revoke compromised credentials, isolate the affected system. This step comes before notification and does not delay it — the two run in parallel.
Establish the scope
Which data categories, how many people, over what period, is special category data involved, did data leave the country. Even without exact answers, give estimated ranges; the form can be completed in stages.
Notify the authority
The breach notification form the authority publishes is completed and sent before the 72 hours expire. If information is missing the form is still sent; a supplementary notification follows.
Watch out: With the deadline approaching, sending an incomplete form beats sending a complete one late.
Notify the affected individuals
Affected individuals are notified within a reasonably short time by an appropriate method. Directly where a contact address is known; otherwise by an appropriate method such as an announcement published on the company's own website.
Keep the record and update the plan
Record the breach, its effects and the measures taken. That record is requested in an audit. At the same time update your breach response plan with what this incident taught — every breach handled without a plan is handled at the same speed the second time.
When do the 72 hours start?
This is where the most common misreading happens. The period starts when the controller **learns** of the breach, not when the breach occurred. For a leak that happened months ago but was noticed today, the 72 hours run from today.
The practical consequence: an organisation without detection capability cannot notify on time — because the moment of learning either never arrives or arrives far too late. And that is precisely one of the questions asked in an audit: how and when did you notice the breach?
Searches this page answers
- how many hours to report a data breach
- 72 hour breach notification rule
- where to file a data breach notification form
- customer data leaked what do i do
- does ransomware require a breach notification
- email sent to wrong person is it a breach
- how to notify affected individuals
- data breach penalty amount
Which incidents count as a data breach?
Personal data being obtained unlawfully by others is a breach. That definition is wider than assumed: not only an external attack but an email sent to the wrong recipient, a lost unencrypted laptop, an unauthorised employee downloading a customer list, and backups left in open storage all fall within it.
In some cases — the loss of an encrypted device, for instance — it can be argued the risk did not materialise; but that assessment has to be made and recorded at the time of the incident. Saying afterwards "it was not risky anyway" is not a defence without the record.
What if our supplier discovers the breach?
When your cloud provider, software supplier or call centre notices a breach, they are obliged to notify you without delay. The clock still starts with your awareness, but a delay in that chain does not save you: what an audit asks is whether such a notification duty was in writing between you and the supplier.
That is why processor contracts carry a one-sentence clause: the party becoming aware of a breach notifies the other in writing without delay and in any case within twenty-four hours of becoming aware. Without that clause your 72 hours are effectively at your supplier's mercy.
Can you notify while information is still missing?
Notification can be made in stages. Where all the information cannot be provided at once, notification is made with what is available and the rest is submitted as it is completed. This is not an exception but the intended route — read the 72 hours as time allowed to make the first notification rather than to finish the investigation.
Where the deadline could not be met at all for a justified reason, the reasons for the delay are explained together with the notification. An unexplained delay is treated more severely than the delay itself.
How do you tell customers about a data breach?
Notifying the authority and notifying affected individuals are two distinct obligations, and the second is skipped in most companies. The purpose of both is the same: letting people protect themselves. So the text should read like a warning rather than a legal document — which data was affected, what risk it creates, and what the person should do, stated plainly.
Where no contact address is known, notification can be made by an appropriate method such as an announcement published on the company's own website. The measure of appropriateness is whether the notice has a real chance of arriving; a link in the site's footer does not meet it.
How do you prepare a breach response plan?
- A breach response plan: who decides, who notifies, who handles communication — named in writing.
- Detection: access logs, unusual-download alerts, and regular scanning of backup and storage permissions.
- A notification clause and deadline in processor contracts.
- An inventory: which data sits in which system — the only way to establish scope within 72 hours.
- Draft notifications: an internal template for the authority's form and a draft of the text going to individuals.
What is the penalty for a data breach?
Amounts are revalued each year, so no figure is printed here — confirm the amount in force on the authority's page. What matters more is what the penalty is calculated against: not the breach itself but the adequacy of the measures taken and whether notification was timely. Timely notification and documented measures read in your favour; concealment reads against you.
If an employee leaked the data, is notification still needed?
Yes. Whether the source is internal or external does not change the obligation; the test is personal data being obtained unlawfully by others. In that scenario employment law runs in parallel, but that is a separate process and not a reason to delay the 72-hour notification.
Is notification needed if the leaked data was encrypted?
If you can show the encryption genuinely protected it, the assessment differs: with the key not leaked and a current method in use, it can be argued the risk did not materialise. But that assessment has to be made and recorded at the time. An after-the-fact "it was encrypted anyway" is not accepted in an audit without the contemporaneous record.
How many people have to be affected before notifying?
The number of people is not a threshold. The obligation arises even where one person's data was affected; the count only affects the severity and how individuals are notified. "Few people were affected, let us not report it" is the most common mistake read as concealment in an audit.
“The 72 hours are time allowed to make the first notification, not to finish the investigation.”
Sources
- 01Kişisel Veri İhlali Bildirim Usul ve Esasları — Kurul Kararı 2019/10Kişisel Verileri Koruma Kurumu · 2019
- 026698 sayılı Kişisel Verilerin Korunması KanunuT.C. Mevzuat Bilgi Sistemi · 2016
- 03Kişisel Veri Güvenliği Rehberi (Teknik ve İdari Tedbirler)Kişisel Verileri Koruma Kurumu · 2018