Mevzuat Kategorileri
Hukuksal Düzenlemeler
Türkiye’de Kişisel Verilerin Korunması Kanunu, Sosyal Güvenlik Hukuku, Vergi Hukuku, İş Sağlığı ve Güvenliği Mevzuatı, Borçlar Hukuku, İş Hukuku, Ticaret Hukuku, Türk Parası Kıymetini Koruma Mevzuatı, Kambiyo Mevzuatı ve Vatandaşlık ve Göçmenlik Mevzuatı ile ilgili en güncel bilgilerin yer aldığı makalelere buradan ulaşabilirsiniz.
İkili Anlaşmalar
Türkiye ve diğer ülkeler arasında yapılan en güncel uluslararası ikili sosyal güvenlik ve vergi anlaşmalarının tarihlerine ve dokümanlarına buradan ulaşabilirsiniz.
23 Mart 2026
Yazar Ecem Kumsal Başyurt, Kategori KVKK - GDPR
The European Data Protection Board (EDPB) has published a comprehensive report under the 2025 Coordinated Enforcement Framework (CEF), examining how the right to erasure, as regulated under Article 17 of the GDPR, is implemented across Europe. Within the scope of this study, 764 controllers were assessed through investigations conducted by 32 data protection authorities, and the structural challenges encountered in the implementation of the right to erasure, as well as examples of good practices, were identified.
The report shows that the right to erasure is one of the most frequently exercised GDPR rights by data subjects. However, in practice, controllers often tend to view this right merely as a technical response to an individual request. In fact, the GDPR framework demonstrates that the right to erasure is not simply a request-handling process; rather, it constitutes a corporate compliance area directly linked to data retention policies, data lifecycle management, system architecture, and, in particular, back-up infrastructures.
In personal data protection law, the right to erasure is regarded as one of the most important safeguards enabling individuals to retain control over their personal data. It refers to the possibility for individuals to request the removal of their personal data from the controller where such data is no longer necessary for the purpose for which it is processed. Today, the most visible and systematic regulation of this right is found in Article 17 of the European Union General Data Protection Regulation (GDPR).
Under Article 17 GDPR, the right to erasure is frequently associated in public discourse with the "right to be forgotten" and is intended to enable individuals to regain control over data relating to them in the digital environment. Accordingly, a data subject may request the erasure of personal data where:
However, the right to erasure is not an absolute right. Article 17(3) GDPR provides that a controller may refuse an erasure request in circumstances involving:
The origins of the right to erasure in international data protection law are not limited to the GDPR. Council of Europe Convention 108 of 1981 and its updated version, Convention 108+, established that personal data should not be retained for longer than necessary for the relevant purpose and that individuals should have effective rights over their personal data. These conventions elevated the principles of data minimization and storage limitation to core principles of international data protection law.
In Turkish law, however, the right to erasure is not regulated directly under a separate heading such as "right to erasure," as it is under the GDPR. Instead, the system is constructed through the combined reading of data subject rights (Article 11 of the Turkish Personal Data Protection Law, "KVKK") and the obligation to erase, destroy, or anonymize data (Article 7 KVKK).
Within this framework, the data subject has the right to:
as well as the right to:
"request the erasure or destruction of personal data."
While this right is recognized as an application right under Article 11 KVKK, in practice it is also linked to the erasure regime regulated under Article 7 KVKK.
"Where the reasons requiring the processing of personal data cease to exist, personal data shall be erased, destroyed, or anonymized by the controller ex officio or upon the request of the data subject."
This provision demonstrates that, in Turkish law, the erasure mechanism is not solely a right operating upon request; it is also an obligation that the controller must fulfill on its own initiative.
Accordingly, although the GDPR and the KVKK employ different terminology, they are based on a common principle: personal data may not be retained indefinitely in active systems, archives, or back-up environments once its legal basis has ceased to exist.
Under the 2025 Coordinated Enforcement Framework, the EDPB conducted a broad review of the implementation of the right to erasure.
The report examined:
The main objectives of the report were stated as:
According to the EDPB, the right to erasure is one of the GDPR rights most frequently exercised by data subjects and constitutes a significant portion of complaints submitted to data protection authorities.
It was found that many controllers do not have clear and documented procedures on how erasure requests should be assessed. This creates risks such as:
The EDPB emphasizes that controllers should establish clear and tested internal policies and procedures for handling erasure requests.
A similar approach exists in Turkish law. Under the KVKK, controllers are required to prepare a personal data retention and destruction policy and to explain erasure processes within their policies and procedures. In this respect, a procedure-based approach constitutes a core element of compliance in both systems.
The EDPB has identified the following actions as good practices for controllers:
According to the EDPB, personnel in many organizations do not receive sufficient training on how to identify, classify, and process requests under Article 17 GDPR through the relevant internal procedures. This may lead to erasure requests being misinterpreted or handled late. The report highlights role-based training and periodic awareness activities as good practices.
Another issue highlighted in the report is the insufficient information provided to data subjects regarding the scope of the right to erasure, how to submit a request, applicable time limits, and possible grounds for refusal. The EDPB recommends that privacy notices should be clear and accessible and that data subjects should be adequately informed throughout the process.
Another major issue identified in the report is the failure to define retention periods on a data-category basis. The storage limitation principle set out in Article 5(1)(e) GDPR requires that personal data be kept only for as long as necessary for the purposes for which it is processed.
According to the EDPB, many controllers:
This directly makes the implementation of the right to erasure more difficult.
Under Turkish law, controllers are required to specify retention periods in their personal data processing inventory and to clearly indicate them in their retention and destruction policy. Moreover, where controllers meet the relevant criteria, they must register with the Data Controllers Registry Information System (VERBIS), where such retention periods must also be declared on a categorical basis. In this respect, the Turkish system ties the determination of retention periods to a more explicit procedural framework.
One of the justifications frequently invoked by controllers in the report is the following: "The data is retained due to a legal obligation."
However, in many cases, controllers fail to demonstrate in concrete terms:
According to the EDPB, abstract claims of legal obligation are not sufficient grounds to reject an erasure request.
One of the most striking issues identified in the EDPB's 2025 CEF report concerns the management of erasure processes in back-up systems. It was found that, although many controllers erase personal data from active systems, the same data often continues to be retained in back-up environments. This is a common implementation issue, particularly within large-scale IT infrastructures.
Back-up systems are critical infrastructures used to:
For this reason, many organizations consider it technically risky to directly alter back-up files, as doing so may compromise the structural integrity of the back-up.
While the EDPB acknowledges this technical reality, it also clearly emphasizes an important principle: "The existence of back-up systems does not eliminate the erasure obligation."
In other words, a controller may not allow personal data erased from active systems to remain indefinitely accessible or reusable in back-up environments.
A parallel approach exists in Turkish law. The definition of "recording medium" in the relevant Regulation covers all media on which personal data is stored.
The Turkish Erasure Guideline also defines erasure as "rendering personal data inaccessible and non-reusable for relevant users." Accordingly, the mere existence of personal data in back-ups does not automatically amount to unlawfulness; however, the fact that such data remains accessible and reusable creates legal risk.
Under the GDPR, the concept of "processing of personal data" is not limited to active databases. Any environment in which personal data is stored forms part of the processing infrastructure. This includes:
Accordingly, it is not sufficient to erase personal data only from production systems. The same data must also be brought under control within back-up systems.
That said, the EDPB report acknowledges that, due to technical realities, it may not always be possible to erase back-up data instantly. Therefore, the report states that controllers must establish alternative control mechanisms to comply with their erasure obligations.
In practice, one of the main challenges faced by controllers is that back-up files are generally stored as complete data sets. For this reason, isolating and erasing records relating to a single data subject from a back-up file may not always be feasible.
In such cases, controllers are advised to implement the following mechanisms:
1. Central recording of erasure requests
To ensure the erasure obligation can be enforced in back-up systems, erasure requests must first be centrally recorded.
These records should generally include:
These records are particularly important for determining which data must be erased again if a system is restored.
2. Re-erasure mechanism after restoration
According to the EDPB, the appropriate good practice is as follows: "if a system is restored and previously erased data is brought back from back-ups, that data must be erased again."
Controllers are therefore advised to establish mechanisms such as:
This approach preserves the integrity of back-up systems while preventing infringement of the right to erasure.
3. Determining back-up retention periods
The EDPB report found that many controllers do not define clear retention periods for back-up data.
Under a good practice approach, clear retention periods should be set for different back-up layers such as:
For example:
In this way, back-up data can be automatically overwritten and removed from the system in due course. This makes the erasure obligation technically manageable.
4. Access control for back-up data
Even where back-up data is not immediately erased, it must not remain accessible or usable.
For this reason, controllers should:
This approach is also consistent with the definition in the Turkish Erasure Guideline, namely that data should be rendered inaccessible and non-reusable for relevant users.
5. Anonymization or data masking
The EDPB report also notes that some controllers apply practices in back-up systems such as:
These methods reduce personal data risk without compromising the structural integrity of the back-up. The report also identifies the following as good practices used by some controllers:
The EDPB report also highlights another common mistake made by controllers: "treating account closure as equivalent to erasure."
However, these two concepts are different:
Account closure means terminating the user's access to the system. Erasure means the termination of the controller's authority to process the data and the removal of the data from the relevant systems.
Therefore, even if an account has been closed, erasure is not deemed to have taken place where the personal data continues to be retained in:
A similar approach also applies under Turkish law. Erasure does not mean merely removing visibility from the user interface; rather, it means rendering the data inaccessible and non-reusable for relevant users.
Although the EDPB report is not directly based on ISO standards, the problem areas it identifies largely overlap with the data governance approach reflected in ISO 27001 and ISO 27701.
From the perspective of ISO 27001, erasure processes are directly related to:
ISO 27701, on the other hand, requires the effective implementation of data subject rights in personal data processing activities.
Accordingly, a mature data protection program is expected to include at least the following elements:
The EDPB's 2025 CEF Report clearly demonstrates that the right to erasure cannot be treated merely as a technical response to an individual request. On the contrary, it constitutes a multi-layered area of compliance directly linked to the controller's retention policy, data lifecycle management, system architecture, back-up infrastructure, internal control mechanisms, and accountability obligations. The findings of the report show that issues such as the lack of written procedures, uncertainty regarding retention periods, misapplication of erasure exceptions, the inability to manage erasure in back-up systems, and the confusion between account closure and erasure continue to prevent organizations from approaching the right to erasure as a holistic data governance matter.
This situation is not unfamiliar from the perspective of Turkish law. The core conclusion reached by both systems is the same: personal data may not be retained indefinitely in active systems, archival environments, or back-up infrastructures once the legal basis for processing ceases to exist. Therefore, the real challenge for controllers is not merely responding to incoming requests, but establishing a sustainable compliance architecture that predetermines why data is processed, how long it is retained, where it is stored, under what conditions it will be erased, and how restoration or reuse risks will be managed.
In this context, an effective erasure regime under both the GDPR and the KVKK is only possible through clear retention periods, category-based data inventories, written and tested procedures, technical controls covering back-up and restoration scenarios, access restrictions, logging, and demonstrable processing records. The information security and privacy governance approach reflected in ISO 27001 and ISO 27701 further supports this need.
Ultimately, the right to erasure is no longer merely a legal obligation; it is a strategic governance issue situated at the intersection of corporate risk management, information security, data architecture, and regulatory compliance. In this respect, the EDPB Report once again underscores the need to maintain a living and sustainable data protection system.
You may access the relevant EDPB report here.
You may access the national reports here.
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.
About The Author
https://www.cottgroup.com
Algorithmic Transparency Within the Scope of GDPR
CottGroup Hukuk ve Mevzuat Ekibi
30 Temmuz 2021
Evaluation of Personal Data Breaches within the Scope of Turkish Penal Code
11 Mart 2024
Data Transfer within the Scope of KVKK and GDPR
Taylan Ege Günel
4 Aralık 2023
CJEU Decision on the Limits of the Right of Access under the GDPR
Ecem Kumsal Başyurt
30 Mart 2026