Restaurant Chain Fined 1 Million Liras for Failing to Protect Personal Data

Serdar HocamAuthor & Editor

KVKK imposed a fine on the restaurant after the data of more than half a million customers was leaked.

◉ 2 views
Kişisel bilgileri koruyamayan şirkete 1 milyon lira ceza

The Personal Data Protection Authority completed its investigation into the leakage of data belonging to 505,000 customers and issued a total administrative fine of 1 million liras to the restaurant chain on the grounds that security measures were not taken.

Malware and Unauthorized Access

Cyber attackers gained unauthorized access to the computer of an employee working in the IT department via malware and seized passwords saved in the browser.

Using the employee's account information, the attackers infiltrated the company's system and managed to access the personal information of 505,337 customers.

Blackmail Message and Investigation Process

After the attackers sent a message to the company manager's phone stating that the data had been seized, the authorities reported the situation to the KVKK.

Upon the notification, the authority launched a comprehensive investigation into the incident and examined the company's security vulnerabilities.

Fines Imposed by KVKK

The authority imposed an administrative fine of 800,000 liras on the company due to the failure to take necessary technical and administrative measures.

Additionally, it was determined that notifications were not made to the individuals affected by the data breach, and another 200,000 liras in fines were added, bringing the total amount to 1 million liras.

Security and Training Deficiencies

It turned out that alarm mechanisms to report system logins were not established and there were deficiencies in the data controller's monitoring mechanism.

The decision also emphasized that the company did not provide sufficient training and awareness activities to its employees regarding the protection of personal data.