Data retention and destruction policy
The internal policy setting how long each type of personal data is kept and how it is deleted, destroyed or anonymised when that period ends.
- 01
Why it matters
Personal data must not be kept longer than needed for the purpose it was processed for; every record kept unnecessarily means extra harm in a breach. In Turkey, data controllers registered in VERBİS must prepare a retention and destruction policy, and periodic destruction is carried out at intervals not exceeding six months.
- 02
Example
A company decides to keep unsuccessful job applications for one year and contact form records for two years. Every six months, expired records are deleted automatically and the operation is logged.
- 03
Common mistake
Writing the policy and forgetting the backups. Data deleted from the main system can stay in backups for years; backup retention periods must match the policy too.
- 04
Let's talk about your project.
Tell us what you need; we will define the scope together.