KVKK for AI Agents · concept · an Avalanche AI example wiki verified 2026-07-23 · live

Breach Notification — the 72-Hour Rule for AI Incidents

Article 12/5 requires a veri sorumlusu to notify the Authority within 72 hours of becoming aware of a breach — not 72 hours from when the breach occurred. The clock starts on discovery, which is exactly why detection speed is itself a compliance control, not just an ops concern.

What counts as a breach for an agent

Nothing about Art. 12 is AI-specific, but agent deployments create breach modes that don't fit the mental model of "database got hacked":

Each of these is a personal-data breach in the ordinary Art. 12 sense the first time it's discovered — "the AI did it" changes nothing about the notification obligation.

The notification itself

Why this belongs next to the deployment patterns

Pattern 2 (decide where transcripts live before go-live) and Pattern 5 (keep a decision trail) both exist partly for this moment: when something goes wrong, "what data did the agent have access to, and who did it talk to" is the first question, and a system with no compiled record of its own processing activity answers it slowly. The 72-hour clock does not pause while you reconstruct what happened.

---

Educational reference maintained by Avalanche AI — not legal advice, and not incident-response guidance for a live breach. If you are inside the 72-hour window right now, go to kvkk.gov.tr and your own counsel, not this page.