Legal information
This publication gives general information on Turkish law as of its stated review date. It does not create an attorney–client relationship; documents, deadlines, jurisdiction, venue and current legislation require file-specific review.
Contact usMaterial and Moral Damages for a Personal-Data Breach in Türkiye: short answer
A personal-data breach supports compensation when unlawful processing or inadequate security causes a proven material or non-material injury. The controller's KVKK duties, regulatory fine and civil liability are distinct; notification of a breach does not release the controller, and an administrative Board decision is not a prerequisite to every damages action.
Scope of review: the legal classification, decisive evidence, filing deadlines, court route, urgent protection and enforceable remedies for Material and Moral Damages for a Personal-Data Breach in Türkiye.
Law checked through: 7 September 2026. Responsible lawyer: Attorney Emirhan Keskin.
Material and Moral Damages for a Personal-Data Breach in Türkiye
A personal-data breach supports compensation when unlawful processing or inadequate security causes a proven material or non-material injury. The controller's KVKK duties, regulatory fine and civil liability are distinct; notification of a breach does not release the controller, and an administrative Board decision is not a prerequisite to every damages action.
The decisive task is to classify the legal relationship before selecting a remedy. In Material and Moral Damages for a Personal-Data Breach in Türkiye, the evidentiary record must link the protected status, the controlling instrument, the legally operative date, the opposing act and the expressly stated requested order. The deciding institution does not infer a remedy from unfairness alone; it applies the statutory test to pleaded facts and admissible records.
An insurer, employer, public body and direct actor answer under different preconditions and limits. For Material and Moral Damages for a Personal-Data Breach in Türkiye, this boundary determines who must be named, which precondition must be completed, which evidence should be requested from third parties and whether an urgent order preserves the final result. Mixing legally distinct routes produces a jurisdiction objection, a missed period or an order that cannot be enforced.
The practical starting point is direct: Identify the unlawful act, liable persons, fault or strict-liability basis, causal chain, loss date and every special limitation rule. Secure incident, investigation and contemporaneous records proving the wrongful event and record the first legally operative date before contacting the opposing party. The claimant should protect originals before sending a broad accusation, because later correspondence often changes account access, asset position, document wording or the answering party's explanation.

Legal basis and governing rules
The legal analysis of Material and Moral Damages for a Personal-Data Breach in Türkiye starts with the official sources listed below. The applicable text is the version governing the operative event, read with its regulations, transition rules and procedural provisions. Neither a later amendment nor an outdated online form changes the rule that applied on that date.
Personal Data Protection Act No. 6698 — official consolidated text
Act No. 6698 regulates lawful processing, special-category data, information duties, data security, data-subject applications and complaints. In the Material and Moral Damages for a Personal-Data Breach in Türkiye file, a data dispute requires identification of the controller, each processing purpose and legal basis, recipients, retention, security failure, prior controller application and provable loss. The source should be cited by article and version after the factual chronology fixes the legally relevant date.
Read the official source used for this legal guide.
Turkish Code of Obligations No. 6098 — official consolidated text
The Code of Obligations governs formation, interpretation, performance, default, termination, restitution, damages and the special contract rules used throughout private-law disputes. In the Material and Moral Damages for a Personal-Data Breach in Türkiye file, the claim must identify the exact obligation, its due date, the required notice or automatic-default event, the elected remedy and the causal loss; mutually inconsistent remedies cannot be pursued as if they were cumulative. The source should be cited by article and version after the factual chronology fixes the legally relevant date.
Read the official source used for this legal guide.
Turkish Penal Code No. 5237 — official consolidated text
The Penal Code defines offences, fault forms, participation and criminal limitation periods relevant to conduct that also produces a civil loss. In the Material and Moral Damages for a Personal-Data Breach in Türkiye file, civil liability and criminal responsibility remain separate, while the longer criminal limitation period applies to qualifying tort claims under the conditions fixed by private law. The source should be cited by article and version after the factual chronology fixes the legally relevant date.
Read the official source used for this legal guide.
Code of Civil Procedure No. 6100 — official consolidated text
The Code of Civil Procedure regulates jurisdiction, venue, pleading burdens, evidence, experts, interim injunctions, judgments and appellate procedure in Turkish civil courts. In the Material and Moral Damages for a Personal-Data Breach in Türkiye file, a successful file connects each requested order to a pleaded material fact and admissible evidence, preserves objections on time and separates interim protection from the final merits remedy. The source should be cited by article and version after the factual chronology fixes the legally relevant date.
Read the official source used for this legal guide.
Enforcement and Bankruptcy Act No. 2004 — official consolidated text
The Enforcement and Bankruptcy Act regulates payment orders, objections, complaints, attachments, sales, precautionary attachment, insolvency and enforcement of judgments. In the Material and Moral Damages for a Personal-Data Breach in Türkiye file, the selected remedy must match the instrument and claim. Service, objection, complaint, sale-request and follow-on action periods run independently and require a dated procedural chronology. The source should be cited by article and version after the factual chronology fixes the legally relevant date.
Read the official source used for this legal guide.
Mediation in Civil Disputes Act No. 6325 — official consolidated text
Act No. 6325 and the relevant special statutes govern mandatory pre-action mediation and the legal effect of the final mediation record. In the Material and Moral Damages for a Personal-Data Breach in Türkiye file, where mediation is a condition of action, the claimant must name the correct parties and claims, obtain the final record and file it with the petition; urgent interim protection remains separately available. The source should be cited by article and version after the factual chronology fixes the legally relevant date.
Read the official source used for this legal guide.
Private International Law and International Civil Procedure Act No. 5718
Act No. 5718 determines applicable law, international jurisdiction, recognition and enforcement of foreign judgments and foreign-claimant security in Turkish proceedings. In the Material and Moral Damages for a Personal-Data Breach in Türkiye file, a foreign nationality, foreign document or foreign-law clause does not answer the governing-law question by itself; each claim, form requirement and Turkish mandatory rule is classified separately. The source should be cited by article and version after the factual chronology fixes the legally relevant date.
Read the official source used for this legal guide.
Available remedies and claim design
A remedy for Material and Moral Damages for a Personal-Data Breach in Türkiye should restore the legal position created by the proven breach and remain executable. Plead alternative routes in a coherent order while election remains open, and request cumulative recovery only for distinct losses. State the principal sum, interest start, currency, non-monetary performance, costs and responsible person for every component.
- Moral damages: request this relief only for the element and defendant it legally addresses in Material and Moral Damages for a Personal-Data Breach in Türkiye. Tie the proposed operative wording to a precise exhibit, amount or registry act and clarify how it avoids duplicate recovery.
- Interest, costs and enforceable security: request this relief only for the element and defendant it legally addresses in Material and Moral Damages for a Personal-Data Breach in Türkiye. Tie the proposed operative wording to a precise exhibit, amount or registry act and explain how it avoids duplicate recovery.
- Reinstatement or cessation of the harmful state: request this relief only for the element and defendant it legally addresses in Material and Moral Damages for a Personal-Data Breach in Türkiye. Tie the proposed operative wording to a precise exhibit, amount or registry act and clarify how it avoids duplicate recovery.
- Documented past economic loss: request this relief only for the element and defendant it legally addresses in Material and Moral Damages for a Personal-Data Breach in Türkiye. Tie the proposed operative wording to a precise exhibit, amount or registry act and set out how it avoids duplicate recovery.
- Future support, earnings or care loss: request this relief only for the element and defendant it legally addresses in Material and Moral Damages for a Personal-Data Breach in Türkiye. Tie the proposed operative wording to a precise exhibit, amount or registry act and clarify how it avoids duplicate recovery.
For every monetary request in Material and Moral Damages for a Personal-Data Breach in Türkiye, record the original currency, valuation date for court fees, principal, default event and applicable interest source. An accountant computes the figures from those instructions; the legal basis and election between incompatible remedies remain matters for the pleading and court.
Evidence and proof plan
Evidence for Material and Moral Damages for a Personal-Data Breach in Türkiye should be collected in native form, preserved with metadata and listed by the legal proposition it shows. Screenshots must include the full screen, URL, account, date and surrounding context; exported data should retain headers and audit information. Keep originals available for inspection when a translated or redacted working copy is filed.
- Expert inputs and a calculation schedule excluding overlap and betterment.
- Insurance, payment, mitigation and third-party recovery records.
- A dated chronology created specifically for Material and Moral Damages for a Personal-Data Breach in Türkiye.
- Original records proving the exact status, breach and requested relief in Material and Moral Damages for a Personal-Data Breach in Türkiye.
- Incident, investigation and contemporaneous records proving the wrongful event.
- Medical, repair, income, market and accounting evidence for each loss item.
Institution-held evidence in Material and Moral Damages for a Personal-Data Breach in Türkiye should be identified before retention periods expire. Specify the custodian, account or file reference, date range and expressly stated record sought. A court production request must connect that record to a disputed fact and detail the unsuccessful direct request.
Personal data and confidentiality do not eliminate proof. They require proportionate collection, restricted use, redaction of unrelated information and a protective order where appropriate. Secretly obtaining excessive data creates a separate admissibility and liability problem that distracts from lawful evidence.
Deadlines, competent court and venue
Operative deadline
The controller must answer a data-subject application within thirty days; a Board complaint follows within thirty days of the response and no later than sixty days after the application. Civil tort claims generally use two years from knowledge and ten years from the act, subject to contract and longer criminal-period rules.
For Material and Moral Damages for a Personal-Data Breach in Türkiye, build a date table before filing: operative event, notification method, legally effective service, any mediation or administrative pause, remaining time and filing cut-off. Electronic delivery, silence and finality follow their own statutory rules. Preserve the source record for every date used in the calculation.
Competent authority
The competent forum follows the source of liability—civil, commercial, consumer, labour, administrative or criminal-procedure compensation—not the label 'damages'.
Territorial venue
Tort venue includes the act, damage and claimant-residence alternatives fixed by procedure, while employment, consumer, administrative, insurance and criminal-procedure compensation retain their special venue rules.
Mandatory preliminary step
The source of liability fixes the precondition: commercial, consumer, employment and rental monetary claims use their assigned mediation; public loss, insurance and criminal-procedure compensation use separate applications.
Before the Material and Moral Damages for a Personal-Data Breach in Türkiye petition is signed, verify the competent branch, territorial connection, monetary threshold and mediation or administrative precondition. Correcting a forum error later does not restore a forfeiture period that expired while the first case was pending.
Interim protection and urgent action
The claimant seeks cessation, evidence preservation, an injunction or asset security tied to the threatened loss. A monetary claim uses precautionary attachment only when its due receivable and statutory risk conditions are established.
The Material and Moral Damages for a Personal-Data Breach in Türkiye emergency application needs a precise target. Identify the asset, status, record or conduct at risk; define the temporary measure and explain urgency with dates. Broad requests against unrelated property or activity weaken proportionality and enforceability.
Attach the strongest existing record instead of promising later proof. If the defending party is heard after an ex parte order, prepare implementation and objection stages together. Start the linked merits action or enforcement step within its legally defined period so interim protection does not lapse.
Evidence protection is itself urgent when logs rotate, footage is overwritten, goods are repaired, buildings change, funds move or a foreign document remains with another party. A narrowly framed determination or production request often creates more value for Material and Moral Damages for a Personal-Data Breach in Türkiye than an unsupported asset freeze.
Cross-border documents and remote representation
For a client abroad, the Material and Moral Damages for a Personal-Data Breach in Türkiye file begins with capacity and authority. Match passport and registry details, confirm the signatory’s corporate power and prepare a Turkish-compliant mandate. Consular execution avoids a separate apostille step; a foreign notarial document follows the authentication route applicable to its issuing state.
Private International Law Act No. 5718 separates governing law, Turkish international jurisdiction, foreign security for costs and recognition or enforcement. A foreign-law clause does not erase Turkish mandatory rules, and a foreign judgment does not execute against Turkish assets until the required recognition or enforcement decision exists.
Remote instruction should use verified identity and a controlled document channel. Normalise time zones, foreign currency and transliterated names in the chronology. For Material and Moral Damages for a Personal-Data Breach in Türkiye, use the expressly stated passport, registry and transaction spelling and describe every variation before it is treated as another person or entity.
Translate the complete document, including stamps, attachments and visible alterations. A summary is unsuitable when form, notice, authority or limitation turns on omitted wording. Keep the original available for court or notarial comparison.
Step-by-step legal action plan
- Start Material and Moral Damages for a Personal-Data Breach in Türkiye with preservation. Copy native data, secure originals, photograph changing conditions and document who holds each fragile record.
- Confirm the legal identity and capacity of each claimant, adverse party, representative, company and public authority before naming parties.
- Build one chronology covering transaction, performance, breach, discovery, notice, service, application and proposed filing dates.
- Classify each claim, keep the distinctions in this guide separate and select the law attached to the requested legal effect.
- Prepare a deadline sheet showing trigger, valid service, suspension, resumed time and final day, supported by the source documents.
- Secure institution-held proof through precise requests and prepare a reasoned court production request for records that remain unavailable.
- Build a relief table stating liable party, principal or performance, currency, interest date, mitigation credit and supporting exhibit.
- Audit every condition of action before suit; retain the final record and confirm that it covers each defendant and requested result.
- Coordinate urgent and final requests so the interim order preserves the same right that the merits petition asks the court to recognise.
- Read the requested judgment from the implementing authority’s perspective and specify every action, amount, record and responsible person.
The Material and Moral Damages for a Personal-Data Breach in Türkiye plan should change through documented facts, not through repeated informal assurances. Confirm every extension or concession in writing and continue any filing needed to protect rights. Keep the chronology and exhibit index aligned with each revision.
Enforcement after the decision
Read a favourable decision by its operative paragraph. Declaration, payment, title correction, release, reinstatement, permit reconsideration and content cessation require distinct implementation. Before appeal or enforcement in Material and Moral Damages for a Personal-Data Breach in Türkiye, verify service, finality, interest, costs and the expressly stated person or authority ordered to act.
Serve the judgment on every implementing body and retain proof. Reproduce principal, currency, interest and costs exactly in monetary enforcement, and attach finality evidence when the registry or authority calls for it. Escalate non-compliance through the precise statutory route.
An appeal does not create one universal suspension rule. Enforceability and security for a stay depend on the governing procedure and decision type. Calendar appeal and implementation together so success in Material and Moral Damages for a Personal-Data Breach in Türkiye is not lost through an avoidable post-judgment omission.
Frequently asked questions
What is the legal result for Material and Moral Damages for a Personal-Data Breach in Türkiye?
A personal-data breach supports compensation when unlawful processing or inadequate security causes a proven material or non-material injury. The controller's KVKK duties, regulatory fine and civil liability are distinct; notification of a breach does not release the controller, and an administrative Board decision is not a prerequisite to every damages action.
What deadline applies to Material and Moral Damages for a Personal-Data Breach in Türkiye?
The controller must answer a data-subject application within thirty days; a Board complaint follows within thirty days of the response and no later than sixty days after the application. Civil tort claims generally use two years from knowledge and ten years from the act, subject to contract and longer criminal-period rules.
Which authority hears disputes concerning Material and Moral Damages for a Personal-Data Breach in Türkiye?
The competent forum follows the source of liability—civil, commercial, consumer, labour, administrative or criminal-procedure compensation—not the label 'damages'.
Which evidence is most important for Material and Moral Damages for a Personal-Data Breach in Türkiye?
Start with Incident, investigation and contemporaneous records proving the wrongful event, Medical, repair, income, market and accounting evidence for each loss item and Expert inputs and a calculation schedule excluding overlap and betterment. Each document should be tied to a date, legal element and requested order.
What is the first step in Material and Moral Damages for a Personal-Data Breach in Türkiye?
Identify the unlawful act, liable persons, fault or strict-liability basis, causal chain, loss date and every special limitation rule. Secure incident, investigation and contemporaneous records proving the wrongful event and record the first legally operative date before contacting the opposing party.
Does foreign nationality change the rule for Material and Moral Damages for a Personal-Data Breach in Türkiye?
Foreign nationality does not remove Turkish mandatory rules or equal access to the competent authority. It adds identity, apostille or legalisation, sworn translation, governing-law, international jurisdiction and remote-representation checks where the file contains a foreign element.
Which urgent protection applies to Material and Moral Damages for a Personal-Data Breach in Türkiye?
The claimant seeks cessation, evidence preservation, an injunction or asset security tied to the threatened loss. A monetary claim uses precautionary attachment only when its due receivable and statutory risk conditions are established.
How does a Turkish lawyer handle Material and Moral Damages for a Personal-Data Breach in Türkiye?
Counsel verifies status and service, calculates every live period, secures third-party records, selects the correct remedy and forum, completes any precondition and drafts an enforceable request. For Material and Moral Damages for a Personal-Data Breach in Türkiye, that work starts with the documents listed in this guide.
Which deadline must be recorded first for Material and Moral Damages for a Personal-Data Breach in Türkiye?
The controller must answer a data-subject application within thirty days; a Board complaint follows within thirty days of the response and no later than sixty days after the application. Civil tort claims generally use two years from knowledge and ten years from the act, subject to contract and longer criminal-period rules.
Which court or authority handles Material and Moral Damages for a Personal-Data Breach in Türkiye?
The competent forum follows the source of liability—civil, commercial, consumer, labour, administrative or criminal-procedure compensation—not the label 'damages'.
Related legal publications
- Damages and Compensation Law in Turkey services and case assessment
- Remarriage Probability and Shares in Turkish Loss-of-Support Compensation
- Damages for Wrongful Precautionary Attachment in Türkiye
- Deepfake and AI Personality-Rights Compensation in Türkiye
- Contact Attorney Emirhan Keskin in English
Official sources
- Personal Data Protection Act No. 6698 — official consolidated text
- Turkish Code of Obligations No. 6098 — official consolidated text
- Turkish Penal Code No. 5237 — official consolidated text
- Code of Civil Procedure No. 6100 — official consolidated text
- Enforcement and Bankruptcy Act No. 2004 — official consolidated text
- Mediation in Civil Disputes Act No. 6325 — official consolidated text
- Private International Law and International Civil Procedure Act No. 5718
Discuss Material and Moral Damages for a Personal-Data Breach in Türkiye with a Turkish lawyer
For a deadline and document review, send the contract or decision, proof of service, payment records and a short chronology. Our office provides English-language representation in Turkish negotiations, applications, courts and enforcement proceedings.
Legal information notice: The guide supplies general information on Turkish law and does not show an attorney-client relationship. File-specific advice follows only after conflict review, formal engagement, examination of original records and confirmation of current rules and periods.
