Under Turkey's data protection law (KVKK), log retention means keeping log records that contain personal data only for the period set by law or needed for the purpose of processing, and no longer. Log integrity means being able to show that those records were not altered after they were written. KVKK itself sets no fixed period for logs.
Written for IT, security and compliance leads of foreign-owned groups with an entity in Turkey (Türkiye); English quotations of Turkish texts are unofficial. This page is for information only and is not legal advice; consult your legal and information-security advisers on how the measures apply to your organisation.
A group retention schedule and a central SIEM do not remove the Turkish entity's own obligations as a data controller (veri sorumlusu) under Law No. 6698. Logging itself is covered in our article on KVKK technical measures for logs and access security; this one covers retention, destruction and integrity.
Are logs personal data under KVKK?
In most cases, yes. Article 3/1-d of Law No. 6698 defines personal data as "any information relating to an identified or identifiable natural person". A user name in a sign-in event, a source IP in a VPN log or a device name in a file-server audit record qualifies when it can be linked to an employee or customer.
Does KVKK set a fixed log retention period?
No. Article 4/2-d requires personal data to be kept "for the period laid down in the relevant legislation or necessary for the purpose for which they are processed". That leaves two cases:
- Another Turkish rule sets a period. If your office network gives staff or guests internet access, the Regulation on Internet Collective-Use Providers (İnternet Toplu Kullanım Sağlayıcıları Hakkında Yönetmelik), art. 4/1-b, requires access records to be stored electronically for two years. This is a separate, well-defined job under Law 5651, which we run as a 5651 logging service (in Turkish).
- No rule sets a period. Then the purpose decides: how far back you need to look to investigate an incident, scope a breach or answer a claim. Document why.
Controllers that must register with the Data Controllers' Registry (VERBİS) also prepare a personal data retention and destruction policy (saklama ve imha politikası) under the Regulation on the Deletion, Destruction or Anonymisation of Personal Data (the "Deletion Regulation", art. 5/1), with a table of retention and destruction periods (art. 6/1-g). Their registry application states the "maximum retention period" of the data (Regulation on the Data Controllers' Registry, art. 9/1-f). Logs belong in that table as their own line.
What must happen when the retention period ends?
Under art. 7/1 of Law No. 6698, once the reasons for processing no longer exist, personal data is erased, destroyed or anonymised. The Deletion Regulation puts this on a calendar:
- A controller with a retention and destruction policy erases, destroys or anonymises the data at the first periodic destruction after the obligation arises (art. 11/1); the interval is set in the policy and may not exceed six months (art. 11/2).
- A controller without the obligation to prepare a policy has three months (art. 11/3).
- Every erasure, destruction and anonymisation operation is recorded, and those records are kept for at least three years, other legal obligations aside (Deletion Regulation, art. 7/3).
Two traps follow for groups. A long global schedule does not by itself justify keeping Turkish personal data that long. And copies count: logs forwarded to a group SIEM, backups and exports follow the same destruction cycle.
How do you set a defensible retention period?
- List the Turkish entity's log sources: directory, VPN and firewall, systems holding personal data, e-mail, endpoint protection.
- Record each source's purpose: security monitoring, breach investigation, legal obligation.
- Map any Turkish rule that fixes a period, such as Law 5651 access records; otherwise justify a purpose-based period.
- Write it down: category, source, period, justification, destruction method, owner.
- Destroy on time and log it: at periodic destruction (at most six months apart), or within three months without a policy obligation; keep records for three years.
- Check where the logs go. If logs containing personal data leave Turkey, for example to a group SIEM abroad, KVKK's cross-border transfer rules (art. 9, amended in 2024) need a separate assessment.
What do Turkish authorities say about log integrity?
The Law, the Deletion Regulation and the Guide do not use the phrase "immutable logs", but three texts from the Board show the expectation of integrity:
- The Personal Data Security Guide (Kişisel Veri Güvenliği Rehberi, January 2018), prepared by the Personal Data Protection Board, lists "regularly keeping records of all users' actions (such as log records)" and says that in incidents such as breaches of confidentiality and integrity, "evidence should be collected and stored securely".
- Personal Data Protection Board decision No. 2018/10 of 31 January 2018 lists "secure logging of the transaction records of all actions performed on the data" among the adequate measures for systems that process special categories of personal data electronically.
- Board decision summary No. 2020/216 of 12 March 2020, on a breach notification, treats measures introduced only after the breach — including "timestamping log records so that they can be used as evidence in forensic cases" and "ensuring the correlation of logs" — as a sign that the necessary technical and administrative measures had not been taken.
How do you make logs tamper-evident in practice?
These are common methods, not requirements listed in the law; they apply to directory, application and database logs as much as to Law 5651 records.
- One clock: synchronise every log source to the same trusted time source; events from drifting clocks cannot be correlated.
- Central, separated storage: collect logs away from the systems that produce them, in a store that the administrators of those systems cannot alter or delete. A central SIEM does this, whether your team runs it or you use a managed SIEM service (in Turkish).
- Hashes and timestamps: produce periodic hash values for log files and store them with a timestamp. In the legal sense, a timestamp is a record verified with an electronic signature by an electronic certificate service provider (Electronic Signature Law No. 5070, art. 3/h).
- Append-only archive: restrict delete and overwrite rights until the retention period ends, then destroy through the documented procedure.
- Watch group-level locks: if Turkish logs sit in a group archive whose immutability lock follows the global schedule, the lock can stop you destroying them on the Turkish timetable. Give them their own retention class.
- Record verification: recompute hashes periodically and keep the result; an unrecorded check cannot be shown to an auditor.
For commercial collective-use providers (businesses that sell internet access, such as internet cafés), the Law 5651 regulation sets a related obligation (art. 5/1-e): a value confirming the accuracy, integrity and confidentiality of access records is recorded daily and kept for two years. It does not say how that value is produced. For everyone else, the methods above are not an explicit requirement but a defensible way to meet the security obligation in KVKK art. 12/1.
Frequently asked questions
Does KVKK require logs to be kept for a minimum number of years?
No. KVKK sets neither a minimum nor a maximum number of years for logs; the period comes from the relevant legislation or the purpose of processing. Where another rule sets one, such as two years for internet access records under Law 5651, it applies.
Can our Turkish entity simply follow the group's global log retention schedule?
Only if its periods are justified for the Turkish processing purposes and the Turkish destruction deadlines described above are still met, with destruction records kept for at least three years.
Is timestamping log files mandatory under KVKK?
The Law, the Deletion Regulation and the Guide contain no general timestamping obligation for all logs. In decision summary No. 2020/216 on a specific breach, however, the Board treated timestamping and log correlation as measures that should have been in place before the breach.
Do we need to record the destruction of logs?
Yes. Under art. 7/3 of the Deletion Regulation, every erasure, destruction and anonymisation operation is recorded and kept for at least three years, other legal obligations aside.
Sources
The official texts are in Turkish. English renderings in this article are unofficial.
- Personal Data Protection Law No. 6698 (mevzuat.gov.tr, Turkish) — arts. 3, 4, 7, 9, 12
- Regulation on the Deletion, Destruction or Anonymisation of Personal Data (mevzuat.gov.tr, Turkish) (Official Gazette 28.10.2017, No. 30224) — arts. 5, 6, 7, 11
- Regulation on the Data Controllers' Registry (kvkk.gov.tr, Turkish) — art. 9
- Personal Data Security Guide — Technical and Administrative Measures, January 2018 (kvkk.gov.tr, PDF, Turkish)
- Personal Data Protection Board decision No. 2018/10 of 31.01.2018 (kvkk.gov.tr, Turkish)
- Personal Data Protection Board decision summary No. 2020/216 of 12.03.2020 (kvkk.gov.tr, Turkish)
- Regulation on Internet Collective-Use Providers (mevzuat.gov.tr, Turkish) (Official Gazette 11.04.2017, No. 30035) — arts. 4, 5
- Electronic Signature Law No. 5070 (mevzuat.gov.tr, Turkish) (Official Gazette 23.01.2004, No. 25355) — art. 3
This article is for general information and does not constitute legal advice. Article numbers and periods reflect the consolidated texts on mevzuat.gov.tr on the date of publication; verify the current text there. The official texts are in Turkish; where this page and the official text differ, the official text prevails.