Dodo Pizza and three pizza companies report unauthorized access to customer data
Turkey's data protection authority published four breach notices involving Dodo Brands and three pizza businesses, citing exposure of identity, contact, location and financial data.
At a glance
- Dodo Brands International FZCO detected unauthorized access to systems holding personal data on September 28, 2026.
- Deniz Pizza, DDP Temizlik Pizza and Smart Delivery Pizza reported unauthorized access to data processor systems holding their data.
- All four notices list identity, contact, location, customer transaction and financial data of customers and employees.
- The number of affected people has not yet been determined; Dodo says it will notify people via the Dodo Pizza mobile app.
Dodo Brands International FZCO, the company behind the Dodo Pizza brand, and three pizza businesses operating in Turkey have reported unauthorized access to systems holding customer and employee data, according to four notices published on October 7 by KVKK, Turkey's Personal Data Protection Authority. The notices list the same categories of personal data, though KVKK does not explicitly state how the four cases are related.
What happened
According to KVKK, Dodo Brands International FZCO detected on September 28, 2026, that unauthorized access had been gained to systems containing personal data belonging to the company. The notice does not say when the breach began or how the access was obtained.
The other three notices, filed by Deniz Pizza Restoranları ve Ticaret, DDP Temizlik Pizza Gıda Sanayi ve Ticaret and Smart Delivery Pizza Yemekçilik Gıda E-Ticaret Reklamcılık ve Ticaret, state that unauthorized access was gained to data processor systems holding the companies' data. Deniz Pizza and Smart Delivery Pizza say the processor informed them on September 30, while DDP says it was notified on October 1. The notices do not name the data processor.
The Personal Data Protection Board ordered the notices published under Article 12(5) of Law No. 6698 with decisions 2026/2199, 2026/2198, 2026/2197 and 2026/2200 respectively.
Who is affected
All four notices list customers and employees as affected groups. The data involved includes identity, contact, location, customer transaction and financial information. The notices do not specify what the financial data consists of, for example whether card details are involved. Work to determine the number of affected people is still under way in each case, and KVKK says its examination continues.
Dodo Brands said affected individuals will be informed through the Dodo Pizza mobile app. The notices do not describe other remediation steps.
What to do
Customers who have ordered from Dodo Pizza or these businesses should be cautious of messages that reference recent orders or delivery addresses and ask for payment or card details, review bank statements for unfamiliar transactions and change the password of their food ordering accounts, especially if it is reused elsewhere. Notifications from the Dodo Pizza app and the companies' official channels should be followed for details about the scope of the incident.
Sources
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Dodo Brands International FZCO — Kişisel Verileri Koruma Kurumu (KVKK)
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Deniz Pizza Restoranları ve Ticaret Limited Şirketi — Kişisel Verileri Koruma Kurumu (KVKK)
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – DDP Temizlik Pizza Gıda Sanayi ve Ticaret Limited Şirketi — Kişisel Verileri Koruma Kurumu (KVKK)
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Smart Delivery Pizza Yemekçilik Gıda E-Ticaret Reklamcılık ve Ticaret Limited Şirketi — Kişisel Verileri Koruma Kurumu (KVKK)
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



