Note: This page is an English translation provided for the convenience of international applicants. The Turkish text is the binding version. As the policy itself states: in the event of any discrepancy between the Turkish text and any translation, the Turkish text prevails.
Caferilik İnancını Tanıtma, Araştırma ve Eğitim Derneği — Personal Data Retention and Destruction Policy
Document Name: Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Personal Data Retention and Destruction Policy
Target Audience: All natural persons whose personal data is processed by Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği
Prepared / Approved by: Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Personal Data Protection Committee
Version: v. 0.1
Effective Date: 6 June 2025
Where the Policy has been prepared in Turkish, and a discrepancy arises between that Turkish version and any translated version, the Turkish text shall be taken into account.
© Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği, 2026. This document may not be reproduced or distributed without the written permission of Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği.
1. Introduction
The protection of personal data is of great importance to Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği (the "Association"), which shows the utmost sensitivity on this matter. Accordingly, processing personal data in a manner consistent with individuals' expectations and in compliance with the law is one of our Association's fundamental cornerstones.
In this respect, our Association retains and destroys the personal data it obtains during its activities in accordance with the general principles and arrangements set out in this Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Personal Data Retention and Destruction Policy (the "Policy"), which has been prepared in compliance with the Constitution above all, Law No. 6698 on the Protection of Personal Data (the "Law"), the Regulation on the Deletion, Destruction, or Anonymisation of Personal Data (the "Regulation"), and other applicable legislation.
2. Purpose and Scope of the Policy
Through this Policy, our Association aims to set out the Association's general principles concerning the retention and destruction of the personal data of natural persons subject to its data processing activities under the Law, and to fulfil the obligations set out in the relevant legislation on these matters.
This Policy covers all personal data subject to our Association's data processing activities under the Law. In addition, unless otherwise stated in this Policy, the documents referenced by this Policy cover both their printed and electronic copies.
3. Definitions
Unless the context requires otherwise, in this Policy:
- Explicit Consent: Consent relating to a specific matter, based on being informed, and expressed with free will.
- Recipient Group: The category of natural or legal persons to whom the Data Controller transfers personal data.
- Constitution: The Constitution of the Republic of Turkey.
- Anonymisation: Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even when matched with other data.
- Relevant User: Persons who process personal data within the Data Controller's organisation, or under the authorisation and instruction received from the Data Controller, excluding the person or unit responsible for the technical storage, protection, and backup of the data.
- Destruction: The deletion, destruction, or anonymisation of personal data.
- Recording Medium: Any medium containing personal data processed wholly or partly by automated means, or by non-automated means provided that they form part of a data recording system.
- Personal Data: Any information relating to an identified or identifiable natural person (e.g. full name, national ID number, e-mail, address, date of birth, credit card number, bank account number — accordingly, the processing of information relating to legal entities is not within the scope of the Law).
- Data Subject: The natural person whose personal data is processed.
- Processing of Personal Data: Any operation performed on personal data such as its collection, recording, storage, retention, alteration, reorganisation, disclosure, transfer, taking over, making it retrievable, classification, or prevention of its use, whether wholly or partly by automated means, or by non-automated means provided that they form part of a data recording system.
- Board: The Personal Data Protection Board.
- Special Categories of Personal Data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance, membership of associations, foundations, or trade unions, health, sexual life, criminal conviction, and security measures, as well as biometric and genetic data.
- Periodic Destruction: The process of Deletion, Destruction, or anonymisation to be carried out ex officio, at recurring intervals specified in this Policy, where all of the conditions for processing personal data set out in the Law have ceased to exist.
- Deletion: The process of rendering personal data inaccessible and unusable in any way whatsoever for relevant users.
- Data Controller: The person who determines the purposes and means of processing personal data and who is responsible for the establishment and management of the place (the data recording system) where the data is systematically kept.
- Destruction (of data, "Yok Etme"): Rendering personal data inaccessible, irretrievable, and unusable by anyone, in any way whatsoever.
4. Recording Media Governed by the Policy
Our Association retains all personal data subject to its data processing activities under the Law, in media containing personal data processed wholly or partly by automated means, or by non-automated means provided that they form part of a data recording system.
5. Reasons Requiring the Retention and Destruction of Personal Data
Our Association bases its personal data processing activities on the following principles:
- Compliance with the law and the principle of good faith,
- Ensuring that personal data is accurate and, where necessary, up to date,
- Processing for specified, explicit, and legitimate purposes,
- Being relevant, limited, and proportionate to the purposes for which they are processed, and
- Retention for the period stipulated by the applicable legislation or required for the purpose for which they are processed.
In line with the principles mentioned above, our Association retains and uses personal data based on the personal data processing purposes set out in the relevant articles of the Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Personal Data Protection and Processing Policy and the Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Employees' Personal Data Protection and Processing Policy, and on the conditions for processing personal data set out in Articles 5 and 6 of the Law below, and destroys personal data ex officio or upon the request of the Data Subject once all of these conditions cease to exist.
(a) Explicit Consent of the Data Subject
One of the conditions for processing personal data is the explicit consent of the data subject. The Data Subject's explicit consent must be declared in relation to a specific matter, based on being informed, and with free will.
(b) Being Expressly Provided for by Law
The data subject's personal data may be lawfully processed without obtaining explicit consent where this is expressly provided for by law.
(c) Impossibility of Obtaining the Data Subject's Explicit Consent Due to Actual Impossibility
Where it is mandatory to process the personal data of a person who is unable to declare consent due to actual impossibility, or whose consent is not legally valid, in order to protect the life or bodily integrity of that person or of another person, the data subject's personal data may be processed.
(d) Direct Connection to the Establishment or Performance of a Contract
Provided that it is directly related to the establishment or performance of a contract, the processing of personal data belonging to the parties to the contract may be permitted where it is necessary.
(e) Legal Obligation
Where data processing is mandatory for our Association to fulfil its legal obligations, the Data Subject's data may be processed.
(f) The Data Subject Having Made Their Own Personal Data Public
Where the data subject has made their own personal data public, the relevant personal data may be processed to the extent limited to the purpose of that disclosure.
(g) Data Processing Being Mandatory for Our Association's Legitimate Interest
Provided that it does not harm the data subject's fundamental rights and freedoms, where data processing is mandatory for our Association's legitimate interests, the data subject's personal data may be processed.
Accordingly, the basis of a personal data processing activity may be only one of the conditions listed above, or more than one of these conditions may together form the basis of the same personal data processing activity.
6. Methods Applied for the Destruction of Personal Data, and the Technical and Administrative Measures Taken for the Lawful Destruction of Personal Data
Where all of the conditions for processing personal data set out in Articles 5 and 6 of the Law cease to exist, our Association deletes, destroys, or anonymises personal data using the methods below. Our Association exercises utmost care and diligence in the destruction of personal data. In this context, our Association takes the necessary technical and administrative measures, according to technological possibilities and the cost of implementation, in accordance with Article 12 of the Law, the provisions of the Regulation, the general principles stated above, this Policy, and Board decisions. All operations carried out within the scope of destruction are recorded by our Association, and such records are kept for at least three years, except for other legal obligations. Unless otherwise decided by the Board, our Association selects, ex officio, whichever of the Deletion, Destruction, or Anonymisation methods is appropriate according to technological possibilities and the cost of implementation, and explains the rationale for the method chosen upon the Data Subject's request.
(a) Methods of Deleting Personal Data
The Deletion of personal data is the process of rendering personal data inaccessible and unusable in any way whatsoever for relevant users. Our Association takes all necessary technical and administrative measures, according to technological possibilities and the cost of implementation, to ensure that deleted personal data is inaccessible and unusable for relevant users.
In this context, our Association applies the following methods for the Deletion of personal data: personal data held in databases is classified by field and its retention period is determined accordingly. System fields are periodically checked (weekly/monthly) and data that needs to be deleted is reported to the relevant managers. Data will be deleted by system administrators, and the record will be closed once deleted.
(b) Methods of Destroying Personal Data
The destruction of personal data is the process of rendering personal data inaccessible, irretrievable, and unusable by anyone, in any way whatsoever. Our Association takes all necessary technical and administrative measures related to the destruction of personal data, according to technological possibilities and the cost of implementation.
In this context, our Association applies the following methods for the Destruction of personal data:
Electronic/Magnetic Media: For personal data on electronic/magnetic media whose required retention period has ended, physical destruction methods such as melting, incinerating, or pulverising are applied. In addition, magnetic media is passed through a special device and exposed to a high-value magnetic field so that the data on it is rendered unreadable.
(c) Methods of Anonymising Personal Data
The Anonymisation of personal data is rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even when matched with other data. For personal data to be considered anonymised, it must be rendered incapable of being associated with an identified or identifiable natural person even through the use of techniques appropriate to the recording medium and the relevant field of activity — such as reversal or matching with other data — by our Association, the recipient, or recipient groups. Our Association takes all necessary technical and administrative measures related to the Anonymisation of personal data, according to technological possibilities and the cost of implementation.
7. Technical and Administrative Measures Taken for the Secure Storage of Personal Data and to Prevent Unlawful Processing and Access
Our Association exercises the utmost care and diligence regarding the secure storage of personal data and the prevention of its unlawful processing and access, and takes the necessary technical and administrative measures, according to technological possibilities and the cost of implementation, in accordance with Article 12 of the Law, the provisions of the Regulation, the general principles stated above, this Policy, and Board decisions, including the following:
- Through periodic penetration tests, risks, threats, vulnerabilities, and any weaknesses in our Association's information systems are identified and the necessary measures are taken.
- Necessary measures are taken for the physical security of the Association's information systems equipment, software, and data.
- To ensure the security of information systems against environmental threats, hardware measures (an access control system that allows only authorised personnel into the server room, a 24/7 monitoring system, physical security of the edge switches forming the local area network, a fire suppression system, a climate control system, etc.) and software measures (firewalls, intrusion prevention systems, network access control, systems that block malicious software, etc.) are taken.
- Risk assessment studies regarding information systems are carried out within the Association as part of information security.
- The Association is working to establish an appropriate system and infrastructure to notify the relevant person and the Board in the event that personal data is unlawfully obtained by others.
- Security vulnerabilities are monitored, appropriate security patches are installed, and information systems are kept up to date.
- Strong hardware is used within the scope of the password management policy in electronic media where personal data is processed.
- Secure logging systems are used in electronic media where personal data is processed.
- Access to personal data stored in electronic or non-electronic media is restricted according to access principles.
- Training is provided to employees, aimed at improving their competence, on preventing the unlawful processing of personal data, preventing unlawful access to personal data, ensuring the safeguarding of personal data, communication techniques, technical skills, and information security.
- Confidentiality agreements are signed by employees in relation to the activities carried out by the Association.
- Before starting to process personal data, the Association fulfils its obligation to inform the relevant data subjects.
- A personal data processing inventory has been prepared.
- The Association carries out the necessary periodic internal controls within the scope of its current internal policies and established systems.
8. Titles, Units, and Job Descriptions of Those Involved in the Personal Data Retention and Destruction Processes
Our Association informs and trains the persons involved in the processes of retaining and destroying personal data on personal data protection law and the lawful processing of personal data. In this context, our Association's employees and persons who learn personal data due to their duties retain and destroy such information in compliance with the Law and other applicable legislation. This obligation continues even after the persons concerned leave their duties.
9. Retention and Destruction Periods
Our Association retains and destroys personal data only for the period stipulated in the applicable legislation it is obliged to comply with, or for the period required for the purpose for which it is processed. In this context, our Association retains and destroys personal data for the maximum periods specified in the Retention and Destruction Periods Table in Annex-1 [EK-1].
Where a Data Subject applies to our Association and requests the destruction of their personal data, our Association will:
(a) If all of the conditions for processing the personal data have ceased to exist: Conclude the Data Subject's request within thirty days at the latest and inform the Data Subject; and if the personal data subject to the request has been transferred to third parties, notify this to the third party and ensure that the necessary actions are taken by the third party.
(b) If not all of the conditions for processing the personal data have ceased to exist, the Data Subject's request may be rejected by explaining the justification pursuant to the third paragraph of Article 13 of the Law, and the rejection response will be notified to the Data Subject in writing or electronically within thirty days at the latest.
10. Periodic Destruction Periods
Our Association destroys personal data at the first periodic destruction process following the date on which the obligation to destroy the personal data arises. In this context, whenever the obligation to destroy personal data arises, our Association subjects the personal data to the destruction process. This period does not, under any circumstances, exceed the maximum periodic destruction period specified in Article 11 of the Regulation.
11. Entry into Force
This Policy entered into force on 6 June 2025. The Policy may be updated from time to time in order to comply with changing conditions and legislation. The current Policy will enter into force on the date it is published on the Association's notice board.
In the event of any conflict between this Policy and the provisions of the Law and the Regulation, the provisions of the Law and the Regulation shall prevail.
Version: saklama-v1
