Digital Evidence Retention: Turkish Penal Code Article 162 (6-year retention period). Evidence types: 1) Disk image (hard drive copy), 2) Memory dump (RAM capture), 3) Log files (access.log, syslog), 4) Screenshots (attack evidence), 5) Malware samples (restricted access, sandbox environment), 6) Incident reports (internal written report), 7) Forensic report (by an expert). Storage methods: 1) Encrypted storage (AES-256 minimum), 2) Access restriction (legal/IR team only), 3) Offsite backup (secondary location, physical security), 4) Chain of custody documentation (who held it and when), 5) Audit logs (access trail). Retention period: 6 years if a criminal complaint is filed (Turkish judicial system), 5 years for insurance claims (compensation demands), 5 years if a KVKK violation is reported (audit requirement). Deletion: Even if you receive a 'complaint dropped' letter from the prosecutor, you must wait 6 years (risk of reopening). Secure deletion (Eraser tool, secure overwrite) — formatting is not enough, requires bit-by-bit overwrite. Legal risk: Destroying evidence constitutes 'obstruction of justice' (TCK Article 278). Business note: Acceptance of 'human error' or 'control weakness' must be in writing by the responsible individual, serving as proof that responsible oversight was exercised.