Follow us :
KVKK & Compliance

Data Retention and Destruction Policy: Mandatory in Türkiye?

A hand stamping an official document — Xen Bilişim KVKK & Compliance

A personal data retention and destruction policy is the written document where a company sets out, category by category, how long it keeps personal data and what happens to that data once the retention period ends. Under Türkiye’s data protection law (KVKK, Law No. 6698), any company registered in VERBİS — the national Data Controllers Registry — is legally required to have one. Companies below the registration threshold still have to delete data eventually under the law’s general obligation; they just aren’t required to document it formally. In practice, this policy is one of the first things an inspector asks for, and most small and mid-sized companies simply don’t have it.

Who actually has to write one?

The legal basis is specific: a regulation published in the Official Gazette on 28 October 2017 (No. 30224), on the deletion, destruction, or anonymization of personal data, requires every VERBİS-registered data controller to prepare a written retention and destruction policy.

Board Decision 2025/1572 exempts companies with fewer than 50 employees and an annual balance sheet under 100 million TL, provided their main line of business isn’t processing special categories of personal data. That exemption removes the registry obligation, not the underlying duty. Even an exempt company doesn’t get to keep customer, employee, or applicant data indefinitely — the general deletion rule still applies.

What the policy needs to cover

The document has to answer three questions for every data category: what data, on what legal basis, for how long. And then: which of the three destruction methods applies once that period ends. The specifics vary by sector, but this table is a reasonable starting point for most SMEs:

Data categoryLegal basisTypical retention period
Invoices, ledgers, accounting recordsTax Procedure Law art. 2535 years
Contracts, commercial correspondenceTurkish Commercial Code art. 8210 years
Employee personnel filesLabor law + statute of limitations10 years
CVs of rejected job applicantsProportionality principle (KVKK art. 4)A reasonable period after the hiring process ends

There’s no fixed number in the law for rejected applicants’ CVs — “reasonable period” comes from the proportionality principle, and in practice companies usually land somewhere between a few months and a year. What matters is that the period is justified, not arbitrary: write down why you chose it.

Deletion, destruction, anonymization: three different things

The regulation defines three separate methods, and they aren’t interchangeable.

  • Deletion: access and usage rights to the data are removed. The data can physically remain in the system, but no one can reach it anymore.
  • Destruction: the data is eliminated in a way that makes it permanently unrecoverable — physical destruction, degaussing, overwriting.
  • Anonymization: the data is altered so it can no longer be linked to an identified or identifiable person, even when cross-referenced with other data.

Which method applies depends on the data type and where it lives. Paper records call for physical destruction (shredding, incineration); a database record on a server needs secure overwriting or dedicated erasure software.

The destruction cycle, and what an inspection actually checks

The policy isn’t meant to cover one-off manual deletions. It’s supposed to run on a cycle: the periodic destruction interval can be no longer than six months. Once a data category’s retention period lapses, it should be destroyed in the next scheduled cycle — a hand-tracked spreadsheet rarely holds up to that standard.

An inspection typically checks three things: does a policy exist, does the periodic destruction cycle actually run, and is there data past its retention period still sitting in the system. That third point is the most common finding — a policy that exists on paper but nobody follows.

As of 2026, the administrative fine bracket for failing to take adequate data security measures runs from 256,357 TL to 17,092,242 TL, and a missing or unenforced destruction policy is usually assessed under that category. Separately, Article 138 of the Turkish Penal Code sets a prison term of one to two years for anyone responsible for destroying data once the legally mandated period has passed and fails to do so — that penalty falls on the responsible individual, not the company.

Frequently asked questions

We’re not registered in VERBİS. Do we still need a written policy? Not a formal one, but you still can’t keep data indefinitely. Even at small scale, a short internal rule on what you keep and for how long is worth having.

Who needs to approve the policy? The regulation doesn’t specify a signing authority. Approval from whoever represents the data controller internally — usually a partner or general manager at a small company — is enough.

How often should we update it? Whenever you start processing a new data category, move a system to the cloud, or the law changes. There’s no fixed annual review requirement, but a policy that no longer matches your VERBİS inventory is the first mismatch an inspector will spot.

Writing the policy is only half the work — you also need a record showing the destruction cycle actually runs. If you’d like help setting this up alongside your data inventory, get in touch.

Share this post
Türkçe oku

Related Posts