forumNew topic

How many years can I keep customer data? Can I just trash it? What does KVKK say?

İİlker A***MemberCommunity member
Joined
Feb 2023
Message
292
#1

I store my e-commerce customers' addresses, phone numbers, emails, and payment info in the database. If someone bought something 5 years ago and hasn't been in touch since, do I still need to keep their data? Or can I delete it?

KVKK says 'unnecessary data should be deleted'. But what does 'necessary' actually mean? I know tax auditors can ask for documents for 5 years. Do I have to keep customer data for 5 years?

Is there any info on how long data stays in the electronic trash before it's gone? I didn't delete it from the database but it remains in backups, does that count?

FFiliz U***Member
Job title
Social media manager
Sector
Consulting
Organization type
two-branch business
Joined
Sep 2025
Message
1
Most Helpful#2

Data retention period is determined by KVKK and tax laws. General principles: 1) Purpose Limitation: data kept for its purpose, deleted once purpose is over, 2) Storage Limitation: necessary duration + a little extra, then delete (Single Delete), 3) Tax records: mandatory to keep for 5 years (Tax Procedure Code), 4) Customer data: transaction completed + 5 years, then delete (recommended), 5) Data in backups: delete-after retention should be implemented (incremental backups overwrite old versions, full backups have 3-month retention). Deletion: data must be truly deleted (recovery not possible unless overwritten on backup). Documentation: data processing policy (policy document), retention schedule (list of deletion periods), deletion record. Risk: compliance audit, mandatory data breach notification. KVKK: it is recommended to ask a consultant, there's a rule to hire a lawyer consultant.

EEbru O***MemberCommunity member
Joined
Mar 2022
Message
370
#3

max 5 years for keeping customer data then delete then tax law says 5 years, but thats not for customer data. ask kvkk or a legal consultant, theyll tell you the right thing. if it stys in backups you need to get a destruction certificate...

SSelim E***Member
Job title
Director of Finance
Sector
Tourism
Organization type
cooperative
Joined
Oct 2025
Message
209
#4

Data retention policy: 1) Define retention period (purpose-based, compliance-based), 2) Automated deletion (database triggers, scheduled jobs), 3) Backup lifecycle (incremental overwrite after retention), 4) Archival (offline storage, if long-term retention needed), 5) Purge verification (before/after counts). GDPR: right to erasure (GDPR Article 17), backup retention (technical limitation documented). Turkish law: tax 5 years, consumer 2 years (non-food). Consultant: writing a data processing policy, creating a retention matrix.

GGökhan D***Member
Job title
System administrator
Sector
Retail
Organization type
300-person organization
Joined
Dec 2024
Message
5
#5

delete customer data after 5 years, that's what KVKK says. even if it stays in backups it's a problem set up a rotation schedule and overwrite it. if the tax inspector asked for 5 years, keep the tax records, but if the customer says 'delete me', delete it immediately. get legal advice first, then you'll be chill...

HHilal Z***MemberCommunity member
Joined
Dec 2024
Message
136
#6

Data lifecycle management: 1) Collection (purpose), 2) Processing (necessary duration), 3) Retention (legal requirement + practicality), 4) Deletion (secure, verifiable), 5) Audit. Retention matrix: customer data (2-5 years), transaction logs (5 years for tax), personally identifiable information (delete after purpose is served). Destruction: database deletion (logical), secure overwrite (physical hard drive), destruction certificate (third party). KVKK Article 3: 'personal data subject to processing principles' — cessation of processing = cessation of retention.

İİlknur E***Member
Job title
Social media manager
Sector
Leather
Organization type
workshop
Joined
Jul 2023
Message
228
#7

I can't fully agree with this. Having backups accessible on the same network and with the same identity makes them part of the target.

Hope this helps.

EEmre G***MemberCommunity member
Joined
Dec 2022
Message
198
#8

I've been dealing with this for a long time. Trying to do this alone is the most expensive way.

If I were you, I'd go this route.

BBurcu B***Expert
Job title
Software developer
Sector
Accounting & advisory
Organization type
300-person organization
Joined
Aug 2025
Message
210

Doki · Log management setup · 2025

#9

I'll try it.

VVeli S***ExpertCommunity member
Joined
Apr 2026
Message
62
#10

Three different views emerged, they all complement each other. Most incidents start with a leaked password, not a vulnerability.

If I were you, I'd go this route.

OOrhan T***Member
Job title
Purchasing manager
Sector
Printing
Organization type
medium-sized business
Joined
Mar 2023
Message
348

Doki · E-commerce infrastructure · 2023

#11

I've been down this road, let me tell you. Just because everyone does it doesn't mean it's right.

Just leaving this note, it might be useful.

HHandeMember
Job title
Communications consultant
Joined
Aug 2024
Message
92
#12

You're right, I've been down that road too. When we decide without measuring, we always end up in the same place.

BBeyza A***Member
Job title
Field sales representative
Sector
Electrical-electronics
Organization type
sole proprietorship
Joined
Feb 2026
Message
61
#13

I have a question. Processes without records never improve, because you don't know what to fix.

If I were you I'd go this route.

KKemal Y***Member
Job title
QA Tester
Sector
Sports and fitness
Organization type
a company within a holding
Joined
Jan 2022
Message
269
#14

let me summarize what's been said so far.. then any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

correct me if I'm wrong.

HHakan G***Member
Job title
Purchasing manager
Sector
Seafood
Organization type
300-person organization
Joined
Oct 2024
Message
185
#15

exactly and not many people know this. like if 2FA is on a stolen password alone is useless.

when we decde without measuring, we always end up in the same place. of course it varies if your situation is different.

HHatice T***ExpertCommunity member
Joined
Mar 2025
Message
222
#16

i'm a small business let me explain from my side.. and btw taking notes for two weeks yields better results than a six-month estimate.

correct me if Im wrong.

NNeslihan A***New member
Job title
Company Owner
Sector
Plastic
Organization type
chain store
Joined
Aug 2026
Message
4
#17

Timely topic.

TTuğçe C***Expert
Job title
Human Resources Specialist
Sector
Law
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
185
#18

You're right. Mistakes made on the customer data retention period side are usually reversible but expensive.

This is my opinion, I'm not claiming it's absolute truth.

OOkan U***ExpertCommunity member
Joined
Apr 2023
Message
286
#19

Could you elaborate on that? Solutions that work at a small scale collapse when you grow; I learned this late.

This is my opinion, I'm not claiming it's absolute truth.

ZZeynep T***MemberCommunity member
Joined
Sep 2024
Message
17
#20

Let me summarize what's been said so far. Your time to detect an issue directly determines its cost.

Payment information changes are never verified through the channel they came from. Of course it varies if your situation is different.

Reply