Let's talk about your project

Data retention and destruction policy

The internal policy setting how long each type of personal data is kept and how it is deleted, destroyed or anonymised when that period ends.

  1. 01

    Why it matters

    Personal data must not be kept longer than needed for the purpose it was processed for; every record kept unnecessarily means extra harm in a breach. In Turkey, data controllers registered in VERBİS must prepare a retention and destruction policy, and periodic destruction is carried out at intervals not exceeding six months.

  2. 02

    Example

    A company decides to keep unsuccessful job applications for one year and contact form records for two years. Every six months, expired records are deleted automatically and the operation is logged.

  3. 03

    Common mistake

    Writing the policy and forgetting the backups. Data deleted from the main system can stay in backups for years; backup retention periods must match the policy too.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.