Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Cyber Security & Compliance

Data Retention and Disposal Policy: How to Write One Under KVKK and Make It Work in Your Systems

How to write a data retention and disposal policy under Turkey's KVKK: required content, a sample schedule, deletion vs anonymisation and 6-month disposal.

9 min read  · Digital Bridge Engineering Team
Data Retention and Disposal Policy: How to Write One Under KVKK and Make It Work in Your Systems

A data retention and disposal policy sets out how long each category of personal data is kept, on what grounds and where, and how it is deleted, destroyed or anonymised once that period ends. Under Türkiye's KVKK it is mandatory for data controllers registered with VERBIS, but it only delivers value once your systems actually apply it.

The problem: "Let's keep everything, just in case"

In many companies personal data is never deleted; it simply accumulates. CVs from applicants five years ago sit in a mailbox, copies of former employees' ID cards fill an archive cabinet and years of access control logs remain on a server. The justification is almost always the same: "We might need it one day." Which periods apply to personnel files is covered separately in employee personal data under KVKK.

Türkiye's Personal Data Protection Law (KVKK, Law No. 6698) does not accept that. Article 4 requires personal data to be kept only for the period set by the relevant legislation or needed for the purpose of processing, and Article 7 requires it to be erased, destroyed or anonymised, on the controller's own initiative or at the data subject's request, once the grounds for processing no longer apply.

The detail sits in the 2017 Regulation on the Erasure, Destruction or Anonymisation of Personal Data. Under that regulation, data controllers obliged to register with the Data Controllers' Registry (VERBIS) must prepare a retention and disposal policy consistent with their personal data inventory. It is the local counterpart of the GDPR's storage limitation principle, with more prescriptive paperwork.

The cost of keeping data and never disposing of it

Every record kept longer than necessary carries two risks: complaints and breaches.

Complaint volumes are rising. According to the KVKK 2025 Annual Activity Report, the Authority received 12,512 complaints and reports in 2025, and the Board fined 876 data controllers. "I asked for my data to be deleted and it wasn't" is one of the easiest complaints to substantiate.

On the breach side the logic is simple: data you no longer hold cannot be stolen. According to the Microsoft Digital Defense Report 2025, attackers sought to steal data in 80% of the incidents Microsoft's teams investigated. The IBM Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million.

The ID and bank details of 300 people who left five years ago directly increase the number of people affected, the 72-hour breach notification workload and the reputational damage. Only 37% of breached organisations say they encrypt sensitive data both at rest and in transit (IBM 2026 press release), and old archives are often left outside that protection.

What a data retention and disposal policy must contain

The regulation lists the minimum content. In practice the policy is organised under these headings:

  1. Purpose and scope. Which legal entities, sites and groups of data subjects it covers.
  2. Recording media. Every place the data lives: ERP, payroll, email, file servers, cloud storage, time and attendance, IP camera recorders and paper archives. If cloud storage sits abroad, the rules on cross-border data transfer apply as well.
  3. Responsibilities. Job titles, departments and duties of everyone involved in retention and disposal.
  4. Technical and organisational measures. How data is stored securely and protected against unlawful access.
  5. Grounds for retention. Legal (periods set by statute), technical or other reasons for keeping data. For internet access logs, for example, the period is set by Law 5651 log retention rules.
  6. Disposal techniques. Deletion, destruction or anonymisation for each medium.
  7. Retention and disposal schedule. Retention period and disposal timing per process and data category. For an example of tracking records with statutory periods in a system, see digital tracking of OHS training records.
  8. Periodic disposal interval. Under the regulation, periodic disposal takes place at intervals of no more than six months.
  9. Revisions. The date and content of changes to the policy.

Deletion, destruction and anonymisation: what is the difference?

MethodWhat it meansTypical example
DeletionMaking data inaccessible and unusable in any way for the relevant usersRemoving a database record, permanently revoking access
DestructionMaking data inaccessible, irretrievable and unusable by anyoneShredding paper, physically destroying a disk
AnonymisationMaking data impossible to link to an identified or identifiable person, even when combined with other dataStripping identities from access logs and keeping only aggregate counts

A sample retention schedule

Periods depend on your business; the rows below only illustrate the method and should be confirmed with your legal adviser.

Data / documentGround for retentionPeriod
Commercial books and recordsTurkish Commercial Code, Art. 8210 years
Tax records and documentsTax Procedure Law, Art. 2535 years (from the following calendar year)
Employee personnel filePotential claims arising from employment, general limitation periodA period set by the company after employment ends
CVs of unsuccessful applicantsAssessing the applicationA short, clearly stated period
Access control and attendance logsSecurity and timekeepingLimited to payroll and potential dispute periods
CCTV footagePhysical securityShort, limited to the purpose

Making the policy work in your systems

Writing the policy is the easy part; the hard part is making the periods in the document actually run in your software.

  • Give every system an owner. "Who deletes the data in this table?" should have a named answer.
  • Build retention periods into software. In document management, email and access control systems, expired records should move to a disposal list or be anonymised automatically. We cover email in email archiving and data protection and documents in our paperless office guide.
  • Remember version history. Old versions and recycle-bin copies of a deleted document are still data; our article on document version control touches on this.
  • Include backups in the policy. Write down how long data deleted from live systems survives in backups; our guide to ransomware and 3-2-1 backups helps structure backup retention.
  • Record every disposal. Under the regulation, deletion, destruction and anonymisation operations are recorded, and those records are kept for at least three years, other legal obligations aside.
  • Set a deadline for data subject requests. When someone asks for their data to be deleted, the request must be concluded within 30 days at the latest; the workflow is explained in handling data subject requests.

One point is often missed: disposal is not only an IT job. Paper personnel files, old laptops and decommissioned disks are recording media too. Methods such as shredding, physical disk destruction or secure erasure software should be written into the policy for each medium, and a disposal certificate should be obtained whenever an outside firm does the work. Backup retention cycles and the secure disposal of old devices are also part of basic security hygiene; we list them in our SME cyber security checklist.

The periods in your policy should match the maximum retention periods declared in VERBIS; see our VERBIS registration guide and, for the full picture, our KVKK compliance roadmap.

How we implement retention and disposal at Digital Bridge

In our data protection compliance consultancy we derive the policy from the inventory and then build it into software. Because the same team develops our software and hardware, we can define a retention rule both in the document and in the code.

We do not sell off-the-shelf packages; after a needs analysis we provide a written proposal setting out scope, phases and cost.

SmartPass: retention and disposal for access records

Access control and attendance logs show where every employee was, every day, which makes them one of the most sensitive rows in any retention schedule. Our own SmartPass brings card access control, time and attendance and canteen meal counting into one system. These are its main data protection features for access records:

  • Expired records are anonymised. When the defined retention period ends, records can no longer be linked to a person.
  • Card numbers are never stored in plain text. They are kept as an irreversible hash.
  • Audit trail. Changes are logged with old and new values, and the auditor role is read-only.
  • Scoped permissions. Role and zone scope are enforced at the core; each organisation runs on its own subdomain and database, and sites cannot see each other's records.

For the attendance side of SmartPass, see our time and attendance guide; for biometric readers, see biometric attendance and data protection.

Next step

Start today with a single system: pick the application that holds the most personal data and find the date of its oldest record. If you have no written reason for keeping it, your policy has not yet reached your systems. Share what you find through our contact page and we will draw up your retention schedule together and build the disposal rules into your software. For the other compliance steps, see our Cyber Security & Compliance guide.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

Who must prepare a retention and disposal policy?

Under the regulation, data controllers obliged to register with the Data Controllers' Registry must prepare a retention and disposal policy consistent with their personal data inventory. For companies exempt from VERBIS a written policy is not mandatory, but the duty not to keep data longer than necessary and to dispose of it when the period ends applies to everyone, so a written rule set is useful at any size.

How often should periodic disposal take place?

The regulation requires periodic disposal at intervals of no more than six months, and the interval must be stated in the policy. In practice that means identifying expired records at least twice a year and deleting, destroying or anonymising them. Every disposal operation should be recorded, and those records kept for at least three years.

What is the difference between deletion and anonymisation?

Deletion makes data inaccessible and unusable for the relevant users. Anonymisation makes it impossible to link the data to a specific person, even when combined with other data. Anonymised data is no longer personal data, so it can still be used for statistics and reporting, for example daily entry counts with all personal identifiers removed.

What if someone asks for deletion before a legal retention period ends?

If a statutory retention duty still applies, such as for commercial records or tax documents, the data may be kept for that period. The request is answered with the reasons within 30 days at the latest, and the data is held only for the legal purpose with restricted access. Once the period expires, it is disposed of in the next periodic disposal run.

Do personal data in backups need to be disposed of too?

Yes. Backups are a recording medium and belong in the policy. Define in writing how long data deleted from live systems remains in backups, alongside your backup rotation. When you restore from backup, plan a post-restore check so that data already disposed of does not quietly return to the live system.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.