KVKK Fines: Current Amounts and Technical Causes

TL;DR: The 2026 amounts for all five KVKK fine categories, how they are recalculated every year, the technical gap behind each fine, and the prison sentences under the Turkish Penal Code.
Most business owners assume a KVKK fine is a legal department problem. In practice, a large share of the penalties issued by Türkiye's Personal Data Protection Board trace back not to a contract clause but to an unresolved technical gap: an unencrypted backup, a shared folder left open to everyone, an unpatched server, or access logs that were never kept.
This observation comes from the field. In the KVKK technical readiness projects we carry out, compliance at most companies starts as a legal document and stays there, yet the questions asked in an audit are technical: where does the data sit, who can access it, is that access logged, and is the data encrypted? We describe the scope of these projects in our case studies.
KVKK is Türkiye's Personal Data Protection Law, Law No. 6698. It is a Turkish statute in its own right, not a local version of the GDPR, and its penalty regime works differently.
This article sets out the fine amounts that apply in 2026, using official figures, and then pairs each type of violation with the technical situation that most often causes it and the IT control that prevents it.
The amounts below apply to the 2026 calendar year and were verified as of 13 September 2026. This is an IT team's perspective, not legal advice; if you face an actual penalty, consult a lawyer.
KVKK administrative fines for 2026
Article 18 of Law No. 6698 sets administrative fines for five categories of violation. These are the lower and upper limits in force for 2026:
| Article | Violation | Minimum | Maximum |
|---|---|---|---|
| 18(1)(a) | Failing to meet the obligation to inform data subjects | 85,437 TL | 1,709,200 TL |
| 18(1)(b) | Failing to meet data security obligations | 256,357 TL | 17,092,242 TL |
| 18(1)(c) | Failing to comply with Board decisions | 427,263 TL | 17,092,242 TL |
| 18(1)(ç) | Breaching the Data Controllers' Registry (VERBİS) registration and notification obligation | 341,809 TL | 17,092,242 TL |
| 18(1)(d) | Failing to notify the Authority of a standard contract used for cross-border transfer | 90,308 TL | 1,806,177 TL |
One figure stands out: the 17 million lira ceiling on data security, ten times the ceiling for the transparency obligation. The law treats failing to protect data as far more serious than failing to explain how it is used.
Why the amounts change every year
The original figures written into the law date from 2016 and are far below today's numbers. The statute still lists 5,000 to 100,000 TL for the transparency obligation. The gap comes from annual revaluation.
Under Article 17(7) of the Misdemeanours Law No. 5326, administrative fines are increased at the start of each calendar year by the revaluation rate announced under the Tax Procedure Law. Fractions of a lira are dropped in the calculation.
The revaluation rate for 2026 was set at 25.49% and published in the Official Gazette of 27 November 2025, issue 33090.
Because each year builds on the previous one, always check which year a fine table refers to before relying on it. A risk assessment built on the 2024 table would understate today's ceiling by almost half: the data security ceiling in 2024 was 9,463,213 TL.
The cross-border notification fine (18(1)(d)) is a newer addition. It was introduced by Law No. 7499, known as the 8th Judicial Package and published in the Official Gazette of 12 March 2024. It started from a base of 50,000 to 1,000,000 TL and has been revalued only twice since.
Most fines start with a technical gap
Below, each type of fine is paired with the technical situation that most often leads to it in the field.
Data security obligations (18(1)(b))
The row with the highest ceiling is also the one that concerns IT most directly. Article 12 requires data controllers to take all technical and administrative measures needed to ensure an appropriate level of security against unlawful processing and access.
The situations that breach this obligation are usually mundane:
- A customer list copied to an unencrypted USB drive or a personal cloud account
- The accounting folder shared on the network with "everyone" permissions
- A departed employee's account left active for days or even months
- Ransomware getting in through an unpatched server
- Backups kept unencrypted and in a single location
- No record at all of who accessed which data
A key part of this obligation is breach notification. Article 12(5) requires that data subjects and the Board be notified as soon as possible when processed data is obtained unlawfully by others. In its decision of 24 January 2019, no. 2019/10, the Board set that period at 72 hours at the latest, counted from the moment the controller becomes aware of the breach.
The Board added a further detail in its decision of 25 December 2025, no. 2025/2451: breach announcements published on the Authority's website now stay online for no more than 60 days, and are removed earlier if the affected individuals have already been notified. The 72-hour deadline itself is unchanged. The practical effect is to reward controllers who inform affected people quickly.
In practice, the clock starts the moment you discover a ransomware attack. To establish what was affected within three days, the logs must already exist before the incident. A system that keeps no records can never answer the question "what was exposed?"
The IT side: role-based access rights that are reviewed regularly, encrypted portable devices and backups, same-day account closure when someone leaves, patch management and central access logging. We turned these into concrete items in our IT checklist for KVKK compliance.
The obligation to inform (18(1)(a))
When personal data is collected, the individual must be told who is processing it, for what purpose and on what legal basis. This looks like a matter of legal wording, yet the failure often happens in a technical layer:
- A website contact form with no link to the privacy notice
- A cookie banner that appears on screen but blocks nothing
- A security camera at the office entrance with no information sign
- A guest Wi-Fi login page with no data processing notice
The IT side: linking forms, cookie management and guest network login pages to the privacy notice, and making sure the cookie banner genuinely prevents the relevant cookies from running until the user consents.
VERBİS registration and notification (18(1)(ç))
Data controllers that are subject to registration must enrol in the Data Controllers' Registry, known as VERBİS, and keep their entry up to date. Whether a company must register depends on thresholds such as headcount and annual balance sheet total, and those thresholds have changed over time through Board decisions.
We cover who has to register, and the current thresholds, in what VERBİS is and who must register.
From an IT point of view, the most overlooked aspect of VERBİS is that the registered information must match the real systems. An entry stating that data is held on servers in Türkiye, while company e-mail actually runs on a cloud service abroad, makes the inconsistency visible.
Cross-border transfer notification (18(1)(d))
This fine arrived with the 2024 amendment, and it is the area where companies are most often caught unprepared. Where personal data is transferred abroad on the basis of a standard contract, the contract must be notified to the Authority within five business days of signature. Notification can be made in hard copy, through KEP (Türkiye's registered electronic mail) or via the Authority's Standard Contract Notification Module.
The crucial point is that this obligation applies not only to the data controller but also to the data processor. The other fine categories target the controller alone; here, both parties are responsible.
Many SMEs do not realise they transfer data abroad at all. Yet using e-mail, file sharing, CRM or accounting software hosted outside Türkiye is, in most cases, a transfer. We explain how this plays out across common services in KVKK cross-border data transfer: a reality check for cloud users.
The IT side: an inventory of the cloud services in use and the country where each one actually stores data. A company that does not know which of its services run abroad cannot know which contracts it has to notify.
Failing to comply with Board decisions (18(1)(c))
After a complaint or an investigation, the Board may order a data controller to take specific measures or to remedy a violation. Failing to carry out that decision is a separate violation, and it carries the highest minimum fine in the table.
For IT, this means that a Board order such as "correct the access rights on this system" or "delete this data" must be technically achievable within the deadline. An organisation that cannot show who has access to what, or does not know which backups hold the data, will struggle to comply in time.
What determines the size of the fine?
The ranges are wide. For a data security violation, the minimum is 256,357 TL and the maximum is 17,092,242 TL. Not every violation attracts the ceiling.
Under Article 17(2) of the Misdemeanours Law, the amount is set by taking into account the wrongfulness of the act, the fault of the offender and the offender's economic situation together.
In practical terms, the number of people affected, the nature of the data exposed, how quickly the violation was detected and reported, and the measures already in place all influence where within the range a fine lands. Security measures documented before an incident are the most concrete evidence a company can put forward in that assessment.
Prison sentences: the Penal Code, not KVKK
Article 18 of KVKK provides only for administrative fines. Criminal offences involving personal data are set out in the Turkish Penal Code, Law No. 5237:
| Penal Code article | Offence | Penalty |
|---|---|---|
| 135(1) | Unlawfully recording personal data | 1 to 3 years' imprisonment |
| 135(2) | The same offence involving special categories of data (health, religion, political opinion, trade union membership, etc.) | Sentence increased by half |
| 136(1) | Unlawfully giving, disseminating or obtaining personal data | 2 to 4 years' imprisonment |
| 137 | Committing these offences as a public official abusing authority, or by exploiting the advantages of a profession or trade | Sentence increased by half |
| 138(1) | Failing to destroy data in the system after the legal retention periods have expired | 1 to 2 years' imprisonment |
The key difference between an administrative fine and a prison sentence is who bears it. Under Article 20(2) of the Penal Code, criminal penalties cannot be imposed on legal entities. So while the company receives the administrative fine, the risk of imprisonment falls on the individual who committed the offence.
The clearest IT example is an employee who takes the customer database with them when they leave. The company may face an administrative fine for breaching its data security obligations, while the person who took the data is personally liable under Article 136. The two sanctions are not alternatives; a single incident can produce both.
Article 138 deserves attention too. Deleting data once its retention period has expired is an obligation, not a choice. Old backups and archives that are never purged are a direct risk in this respect.
If a fine arrives, the window to object is short
Administrative fines under KVKK are handled within the framework of the Misdemeanours Law. Under its Article 27, an objection can be filed with the criminal judgeship of peace within 15 days of notification of the decision.
Fifteen days is little time to assemble the technical facts of an incident. Records showing which measures were in place beforehand, access lists and backup documentation need to be ready within that window; documents produced after the event carry limited weight.
FAQ
Frequently Asked Questions
Can a sole trader be fined under KVKK?
Yes. The law's definition of a data controller includes natural persons. A sole trader who processes personal data is subject to the transparency, data security and other obligations. The VERBİS registration obligation, however, depends separately on the applicable thresholds.
Is every violation fined at the maximum?
No. The fine is set between the minimum and maximum shown in the table. Under the Misdemeanours Law, the wrongfulness of the act, the degree of fault and the company's economic situation are assessed together. The scale of the violation, the speed of notification and the measures already in place all feed directly into that assessment.
What happens if I don't report a data breach to the Board?
Breach notification is part of the data security obligation in Article 12 of the law. The Board expects notification within 72 hours of the controller becoming aware of the breach. Failing to notify can be assessed under the data security obligation, which carries a 2026 fine of between 256,357 TL and 17,092,242 TL.
We use Microsoft 365 or Google Workspace. Does the cross-border transfer fine apply to us?
Quite possibly. If your data is stored on servers outside Türkiye, that is in most cases a cross-border transfer. Where the transfer relies on a standard contract, the contract must be notified to the Authority within five business days of signature; failing to do so carries a 2026 fine of between 90,308 TL and 1,806,177 TL.
If an employee leaks data, who gets fined?
Two separate sanctions can arise. If the company failed to take the necessary technical and administrative measures, it may face an administrative fine for breaching its data security obligations. The employee who unlawfully obtained or disseminated the data faces personal liability under Article 136 of the Turkish Penal Code, with a sentence of 2 to 4 years' imprisonment.
Will the amounts change again in 2027?
Yes. The amounts are updated at the start of each calendar year using the revaluation rate announced for that year. The 2026 rate was published in the Official Gazette on 27 November 2025; the 2027 rate will be announced towards the end of the year and will apply from 1 January 2027.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Turkey's KVKK and Cross-Border Data Transfers: a Cloud Reality Check
If your company email or files are hosted in a data centre outside Turkey, the KVKK's cross-border transfer rules apply to you. The standard-contract regime introduced in 2024, the cloud service inventory, and the concrete IT-side steps — in plain language.

NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?
Europe's NIS2 directive obliges in-scope companies to secure their supply chains too. Turkish SMBs selling into the EU are now receiving security questionnaires and contract clauses — here is what will be asked, and how to be ready before it arrives.

Disposing of Old Computers Securely: the Data Destruction and e-Waste Guide
Old computers gathering dust in the store room are not assets — they are open filing cabinets with customer data on their disks. Why formatting is not enough, the right destruction method per disk type, the record-keeping, and the e-waste handover, step by step.