A data retention and disposal policy sets out how long each category of personal data is kept, on what grounds and where, and how it is deleted, destroyed or anonymised once that period ends. Under Türkiye's KVKK it is mandatory for data controllers registered with VERBIS, but it only delivers value once your systems actually apply it.
The problem: "Let's keep everything, just in case"
In many companies personal data is never deleted; it simply accumulates. CVs from applicants five years ago sit in a mailbox, copies of former employees' ID cards fill an archive cabinet and years of access control logs remain on a server. The justification is almost always the same: "We might need it one day." Which periods apply to personnel files is covered separately in employee personal data under KVKK.
Türkiye's Personal Data Protection Law (KVKK, Law No. 6698) does not accept that. Article 4 requires personal data to be kept only for the period set by the relevant legislation or needed for the purpose of processing, and Article 7 requires it to be erased, destroyed or anonymised, on the controller's own initiative or at the data subject's request, once the grounds for processing no longer apply.
The detail sits in the 2017 Regulation on the Erasure, Destruction or Anonymisation of Personal Data. Under that regulation, data controllers obliged to register with the Data Controllers' Registry (VERBIS) must prepare a retention and disposal policy consistent with their personal data inventory. It is the local counterpart of the GDPR's storage limitation principle, with more prescriptive paperwork.
The cost of keeping data and never disposing of it
Every record kept longer than necessary carries two risks: complaints and breaches.
Complaint volumes are rising. According to the KVKK 2025 Annual Activity Report, the Authority received 12,512 complaints and reports in 2025, and the Board fined 876 data controllers. "I asked for my data to be deleted and it wasn't" is one of the easiest complaints to substantiate.
On the breach side the logic is simple: data you no longer hold cannot be stolen. According to the Microsoft Digital Defense Report 2025, attackers sought to steal data in 80% of the incidents Microsoft's teams investigated. The IBM Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million.
The ID and bank details of 300 people who left five years ago directly increase the number of people affected, the 72-hour breach notification workload and the reputational damage. Only 37% of breached organisations say they encrypt sensitive data both at rest and in transit (IBM 2026 press release), and old archives are often left outside that protection.
What a data retention and disposal policy must contain
The regulation lists the minimum content. In practice the policy is organised under these headings:
- Purpose and scope. Which legal entities, sites and groups of data subjects it covers.
- Recording media. Every place the data lives: ERP, payroll, email, file servers, cloud storage, time and attendance, IP camera recorders and paper archives. If cloud storage sits abroad, the rules on cross-border data transfer apply as well.
- Responsibilities. Job titles, departments and duties of everyone involved in retention and disposal.
- Technical and organisational measures. How data is stored securely and protected against unlawful access.
- Grounds for retention. Legal (periods set by statute), technical or other reasons for keeping data. For internet access logs, for example, the period is set by Law 5651 log retention rules.
- Disposal techniques. Deletion, destruction or anonymisation for each medium.
- Retention and disposal schedule. Retention period and disposal timing per process and data category. For an example of tracking records with statutory periods in a system, see digital tracking of OHS training records.
- Periodic disposal interval. Under the regulation, periodic disposal takes place at intervals of no more than six months.
- Revisions. The date and content of changes to the policy.
Deletion, destruction and anonymisation: what is the difference?
| Method | What it means | Typical example |
|---|---|---|
| Deletion | Making data inaccessible and unusable in any way for the relevant users | Removing a database record, permanently revoking access |
| Destruction | Making data inaccessible, irretrievable and unusable by anyone | Shredding paper, physically destroying a disk |
| Anonymisation | Making data impossible to link to an identified or identifiable person, even when combined with other data | Stripping identities from access logs and keeping only aggregate counts |
A sample retention schedule
Periods depend on your business; the rows below only illustrate the method and should be confirmed with your legal adviser.
| Data / document | Ground for retention | Period |
|---|---|---|
| Commercial books and records | Turkish Commercial Code, Art. 82 | 10 years |
| Tax records and documents | Tax Procedure Law, Art. 253 | 5 years (from the following calendar year) |
| Employee personnel file | Potential claims arising from employment, general limitation period | A period set by the company after employment ends |
| CVs of unsuccessful applicants | Assessing the application | A short, clearly stated period |
| Access control and attendance logs | Security and timekeeping | Limited to payroll and potential dispute periods |
| CCTV footage | Physical security | Short, limited to the purpose |
Making the policy work in your systems
Writing the policy is the easy part; the hard part is making the periods in the document actually run in your software.
- Give every system an owner. "Who deletes the data in this table?" should have a named answer.
- Build retention periods into software. In document management, email and access control systems, expired records should move to a disposal list or be anonymised automatically. We cover email in email archiving and data protection and documents in our paperless office guide.
- Remember version history. Old versions and recycle-bin copies of a deleted document are still data; our article on document version control touches on this.
- Include backups in the policy. Write down how long data deleted from live systems survives in backups; our guide to ransomware and 3-2-1 backups helps structure backup retention.
- Record every disposal. Under the regulation, deletion, destruction and anonymisation operations are recorded, and those records are kept for at least three years, other legal obligations aside.
- Set a deadline for data subject requests. When someone asks for their data to be deleted, the request must be concluded within 30 days at the latest; the workflow is explained in handling data subject requests.
One point is often missed: disposal is not only an IT job. Paper personnel files, old laptops and decommissioned disks are recording media too. Methods such as shredding, physical disk destruction or secure erasure software should be written into the policy for each medium, and a disposal certificate should be obtained whenever an outside firm does the work. Backup retention cycles and the secure disposal of old devices are also part of basic security hygiene; we list them in our SME cyber security checklist.
The periods in your policy should match the maximum retention periods declared in VERBIS; see our VERBIS registration guide and, for the full picture, our KVKK compliance roadmap.
How we implement retention and disposal at Digital Bridge
In our data protection compliance consultancy we derive the policy from the inventory and then build it into software. Because the same team develops our software and hardware, we can define a retention rule both in the document and in the code.
- We build retention periods and disposal lists per document type directly into document management system projects.
- We design retention and access rules for staff data in HR, payroll and personnel management software.
- We set up structures that turn person-level data into anonymous statistics for reporting as part of data warehouse projects.
- We clarify duplicate personal records and data ownership across systems through data governance and quality work.
We do not sell off-the-shelf packages; after a needs analysis we provide a written proposal setting out scope, phases and cost.
SmartPass: retention and disposal for access records
Access control and attendance logs show where every employee was, every day, which makes them one of the most sensitive rows in any retention schedule. Our own SmartPass brings card access control, time and attendance and canteen meal counting into one system. These are its main data protection features for access records:
- Expired records are anonymised. When the defined retention period ends, records can no longer be linked to a person.
- Card numbers are never stored in plain text. They are kept as an irreversible hash.
- Audit trail. Changes are logged with old and new values, and the auditor role is read-only.
- Scoped permissions. Role and zone scope are enforced at the core; each organisation runs on its own subdomain and database, and sites cannot see each other's records.
For the attendance side of SmartPass, see our time and attendance guide; for biometric readers, see biometric attendance and data protection.
Next step
Start today with a single system: pick the application that holds the most personal data and find the date of its oldest record. If you have no written reason for keeping it, your policy has not yet reached your systems. Share what you find through our contact page and we will draw up your retention schedule together and build the disposal rules into your software. For the other compliance steps, see our Cyber Security & Compliance guide.