What is a data inventory?
A data inventory is a list of the personal data your company processes. Each row answers these questions: which data category, collected from whom, for what purpose, on what legal basis, where it is stored, who has access, to whom it is transferred and how long it is kept.
Under KVKK (Türkiye's Personal Data Protection Law), the inventory is also the foundation for your filing in VERBIS (Türkiye's data controller registry). Whether you are required to register depends on your number of employees, balance sheet size and line of business; we recommend making that assessment with your lawyer.
The inventory on the software side
An inventory is usually prepared as a spreadsheet, but the real data lives inside your systems. We scan the following sources and add their technical counterpart to the inventory:
- Website form submissions and email notifications
- E-commerce member, order and address tables
- CRM and proposal records
- B2B dealer portal users
- Server and application access logs
- Backups
- Third-party services (email marketing tool, shipping integration, payment platform)
For example, on an e-commerce site it is common to find contact form messages stored both in the database and in a mailbox that hasn't been cleaned out for years, or an Excel file from an old campaign forgotten on the server.
Retention periods
Personal data is kept only as long as needed for the purpose it was processed for, or for the period required by the relevant legislation. For instance, invoice details are subject to the retention period in tax legislation, while there is usually no reason to keep an answered contact form message for years. We set the periods together with your lawyer and then build them into the system.
| Data | Example logic for setting the period |
|---|---|
| Contact form | A reasonable period after the request is resolved |
| Orders and invoices | The period set by commercial and tax legislation |
| Marketing permission | Until consent is withdrawn |
| Access logs | Based on security and legal requirements |
| Inactive membership | After a set period of inactivity |
Destruction — deletion, destruction and anonymization
The regulation on the deletion, destruction or anonymization of personal data requires a retention and destruction policy and periodic destruction; the maximum interval for periodic destruction under the regulation is six months. On the software side, we implement this with:
- Scheduled jobs that find records whose retention period has expired
- Anonymized storage of data needed for statistics
- Making sure deleted records also disappear from backups once their period ends
- Logging every destruction run with its date and scope
Checklist
- Has the inventory been checked against the actual systems?
- Is a retention period set for every data category?
- Is there an automated process that deletes expired data?
- Are backups covered by the destruction policy?
- Are destruction runs recorded?
This work is part of our KVKK compliance service. Consolidating scattered data often goes hand in hand with an integration or custom software project.
Frequently asked questions
Can't we just archive instead of deleting?
Archived data is still personal data and is subject to retention rules. If you need to keep it for a long time, anonymization is the right approach.
Do you prepare the data inventory?
We map the technical part — which data sits in which system. The purpose and legal basis columns are completed together with your lawyer.
For questions, call +90 850 432 55 13 or use the contact page.