Switch to main content
  • Medicus
  • Clinic
  • Home visits
  • Our Services
  • Contact Us
  • +90 242 753 11 11
  • TR – Türkçe|EN – English|DE – Deutsch
Medicus
  • Clinic
  • Home visits
  • Our Services
  • Corporate
  • Service information
  • Frequently Asked Questions
TR – Türkçe|EN – English|DE – Deutsch
© 2026 Medicus

Personal Data Retention and Disposal Policy

1. Purpose

The purpose of this Policy is to ensure the secure storage of personal data processed by Medicus Clinic Özel Sağlık Hizmetleri ve Tic. Ltd. Şti. (“Medicus Clinic” or “Company”) for the period required by the purposes and legal grounds for processing, and to determine the procedures, principles, responsibilities and control mechanisms for deleting, destroying or anonymizing personal data in case all processing conditions are eliminated.

2. Scope

This Policy covers the following groups of relevant persons whose personal data are processed within the scope of Medicus Clinic's activities and the electronic or physical records belonging to these persons:

  • Patients, prospective patients, patient relatives and companions;
  • Employees, former employees, interns and prospective employees;
  • Visitors;
  • Suppliers, service providers, consultants and their authorized/employees;
  • Legal representatives and authorized third parties.

3. Legal Basis

The Policy has been prepared by taking into account the Personal Data Protection Law No. 6698 (“KVKK”), the Regulation on Deletion, Destruction or Anonymization of Personal Data, special legislation on health services and personal health data, and labor, social security, tax, trade, occupational health and safety and other applicable legislation. If a longer or special storage period is stipulated in special legislation, the relevant special regulation is applied first.

4. Definitions

Anonymization: Making personal data unable to be associated with an identified or identifiable natural person, even if it is matched with other data.

Destruction: Deletion, destruction or anonymization of personal data.

Relevant person: The real person whose personal data is processed.

Relevant user: The person who processes personal data within the Company or on the instructions of the Company, other than those responsible for the technical storage, protection and backup of data.

Recording environment: It is the environment in which personal data is stored by fully/partially automatic or non-automatic means, provided that it is part of the data recording system.

Periodic destruction: It is the ex officio destruction process carried out at recurring intervals specified in the Policy in case all personal data processing conditions are eliminated.

Deletion: Making personal data inaccessible and unusable for the relevant users in any way.

Destruction: Making personal data inaccessible, irretrievable and unusable by anyone.

5. Basic Principles

  • Personal data is kept accurate and updated when necessary, in accordance with the law and the rules of honesty.
  • Data for specific, clear and legitimate purposes; It is processed in a limited and measured manner in connection with the purpose.
  • Data are retained for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed.
  • When all processing conditions are eliminated, the data is deleted, destroyed or anonymized in accordance with the applicable legislation.
  • Stricter access, authorization and security measures are applied for health data and other special personal data.

6. Personal Data Recording Environments

  • Electronic patient/clinical information systems, appointment and registration systems;
  • Servers, computers, portable enterprise devices and authorized cloud/hosting environments;
  • Email, corporate communication and support systems;
  • Human resources, payroll, PDKS and accounting systems;
  • CCTV/camera recording systems;
  • Website, log records and cookie/preference records;
  • Physical patient files, personnel files, contracts, forms, minutes and archives;
  • Backup media and other recording media that comply with the legislation.

7. Contact Groups and Data Categories

Contact person Major data categories
Patient / patient relative Identity, communication, health, appointment, examination, diagnosis, examination, treatment, prescription, finance, insurance/SGK, transaction security, visual recording and, where necessary, legal transaction data.
Employee / candidate Identity, communication, personnel, payroll/finance, SGK, PDKS, training, performance, leave, OHS/health, discipline, camera and legal transaction data.
visitor Entry-exit, identity/communication when necessary, camera footage and security/event records.
Supplier / service provider Authorized/employee identity and contact information, contract, offer, invoice, payment/bank, correspondence, access and legal transaction records.

8. Reasons for Storage

  • Providing healthcare services, ensuring the integrity of patient records and continuity of care;
  • Fulfillment of legal obligations, official notification and audit obligations;
  • Obligations arising from the establishment, execution and termination of contracts;
  • Labor and social security, tax, accounting, trade and OHS obligations;
  • Establishment, exercise or protection of a right and management of legal disputes;
  • Ensuring information and physical space security;
  • In activities based on the valid explicit consent of the relevant person, the period during which the explicit consent is valid.

9. Reasons Requiring Destruction

Destruction is evaluated in cases such as the disappearance of the legal reason or purpose requiring the processing of personal data, expiration of the storage period, withdrawal of consent in processing based on explicit consent and the absence of any other processing condition, change in the relevant legislation or justified request of the relevant person. If another legal storage obligation remains, the data is blocked/restricted for use only for the relevant purpose; It is not destroyed before the mandatory storage period expires.

10. Determination of Storage Periods

Storage periods are determined based on the data category, processing purpose and legal reason. This Policy alone does not provide for a fixed number of years for all registrations. Special periods in the relevant health legislation, especially for patient and health records; labor, SSI, tax and OHS legislation in employee records; Contractual, trade and tax obligations are taken into account in supplier records. The table below shows the storage logic to be implemented with Medicus Clinic's data inventory; Lines that require a precise period are verified with the relevant legislation and the actual system inventory and recorded in the corporate storage schedule.

11. Storage and Disposal Periods Table

Registration group of people Data Storage approach destruction
Patient file/medical records sick health, identity Mandatory period in relevant health legislation; After the period has expired and there is no legal reason Deletion / destruction / anonymization if appropriate
Examination, laboratory, imaging and prescription records sick health The period determined in accordance with the relevant health legislation and clinical record integrity Deletion / destruction / anonymization
Appointment and communication records sick communication, transaction Until the service and dispute requirement ends and the relevant retention obligation is fulfilled. Deletion / anonymization
Finance, invoice, payment, insurance/SGK records sick Finance Tax, accounting, SSI and related special legislation periods Delete/destroy
camera recordings Patient/employee/visitor visual Short clinically determined safety period; If there is an incident/evidence, it will be kept separately until the end of the dispute or official process. Automatic overwrite/secure erase
Employee personnel file Employee personnel Taking into account employment, SSI, tax and statute of limitations periods Physical destruction / digital secure deletion
Payroll, wages, banking and accounting records Employee Finance Deadlines in tax, SSI, labor and accounting legislation Delete/destroy
OHS and employee health records Employee Health/OHS Special periods in OSH and health legislation Delete/destroy
PDKS / input-output Employee Transaction security Time required for working relationship, wage/overtime and dispute needs Delete
Job application/CV records candidate Identity, communication, professional Until the application process and valid candidate pool purpose, if any, ends. Delete/destroy
Visitor login records visitor ID/transaction Short time required for physical security and incident management; If there is an incident, throughout the legal process Delete/destroy
Supplier contracts and correspondence Supplier Identity, communication, legal action Relevant tax/trade/prescription periods after termination of the contract and commercial relationship Delete/destroy
Invoice and payment records Supplier Finance Deadlines in tax and accounting legislation Delete/destroy
Web server/log records web user Transaction security Time required for security, regulatory and incident investigation Deletion / anonymization
Cookies and preference records web user digital preference Depending on the purpose of the cookie, its validity period and revocation of the user's preference Delete / refresh
KVKK application and response records All groups legal action Time required for application/dispute and burden of proof Delete/destroy
Destruction process records All groups audit trail At least 3 years from the date of destruction; If there is a longer legal obligation, then Safe destruction at the end of the period

12. Periodic Destruction

Medicus Clinic's periodic destruction interval is determined as 6 months. Personal data where all processing conditions are determined to be eliminated are deleted, destroyed or anonymized in the first periodic destruction process following the date on which the liability arises. If necessary, destruction can be done at shorter intervals.

13. Destruction Methods

13.1 Deletion

In electronic systems, removal of access authorizations, secure deletion at the application/database level, closure of archive access so that relevant users cannot access the data, and other appropriate methods are used.

13.2 Destruction

Paper records are irreversibly shredded or destroyed through a secure shredding service. Unusable disks, optical/magnetic media and devices are destroyed physically or technically by secure methods that will prevent data recovery.

13.3 Anonymization

If statistical, quality or reporting purposes are to be maintained; Masking, aggregation, generalization or other appropriate anonymization techniques may be applied that irreversibly eliminate association with an identified or identifiable person. Mere use of a pseudonym alone is not considered anonymization.

14. Technical and Administrative Measures

  • Role and task based access authorization; periodic authorization review;
  • Increased access control and confidentiality obligations for sensitive personal data;
  • Strong password, convenient multi-factor authentication, logging and secure backup;
  • Up-to-date security software, patch management, network security and malware precautions;
  • Keeping physical archives in controlled areas and preventing unauthorized access;
  • Personnel KVKK, privacy, information security and destruction training;
  • Data security and confidentiality provisions in supplier contracts;
  • Execution of destruction procedures by authorized persons, creation of minutes/records and double checks when necessary.

15. Backups and Disaster Recovery Copies

If data deleted from the active system is found in backups, the normal cycle and security architecture of the backups are taken into account. If the data on the backup is returned to the active system, technical and administrative controls are applied to ensure that records that have previously been subject to destruction are not re-used.

16. Deletion/Destruction Request of the Relevant Person

The patient, employee, visitor or supplier may request the deletion or destruction of their personal data as a relevant person. If all processing conditions are eliminated, the necessary destruction is carried out; If the conditions continue, the request is concluded by explaining the legal justification. Applications are answered within the deadlines specified in KVKK.

17. Recording of Destruction Procedures

Deletion, destruction and anonymization operations are recorded. Destruction records; It is kept for at least three years, without prejudice to other legal obligations. The record includes, at a minimum, the data/record category, reason for destruction, method, date, and information about the authorized person who performed and controlled the transaction.

18. Duties and Responsibilities

Unit/Role Responsibility
Company Management / Data Controller Approval of policy, provision of resources, top oversight.
KVKK contact/responsible unit Up-to-dateness of the inventory-storage schedule, relevant person applications, periodic destruction coordination and records.
Computing / IT Electronic deletion, access restriction, backup, log and technical security measures.
Human Resources Storage/destruction tracking of employee and candidate records.
Patient Services / Clinical units Processing of patient records only for authorized purposes and management in accordance with retention obligations.
Accounting / Finance Keeping and destroying financial and commercial records in accordance with the legislation.
Security / Administrative Affairs Management of visitor and camera records in accordance with the purpose and duration.
Purchasing / Contract responsible Management of supplier and service provider records.

19. Periodic Review

Policy and its attached storage schedule; It is reviewed regularly when there are changes in legislation, clinical activities, information systems used, data inventory or organizational structure. Before starting a new data processing activity, the relevant storage and destruction rule is determined.

20. Enforcement and Publication

This Policy comes into force with the approval of Medicus Clinic management. The public version of the policy may be published on the website; Internal procedures and destruction reports containing operational security details are not made public.

21. Consent

Prepared by
Controller
Approved by
Effective Date

Related documents

  • Privacy Notice
  • Personal Data Processing and Protection Policy
  • Data Retention and Disposal Policy
  • CCTV Privacy Notice
  • Privacy Policy
  • Cookie Policy
  • Patient Rights
  • Legal Notice and Terms of Use
  • Contact
  • Karabekir 50 Side
    07330 Antalya Turkey
  • +90 242 753 11 11
  • info@medicus.com.tr
  • Corporate
  • About Us
  • Company Information
  • Certificates
  • Service information
  • Patient Rights
  • Frequently Asked Questions
  • Personal Data Protection
  • Privacy Notice
  • Personal Data Protection Policy
  • Data Retention and Disposal Policy
  • Video Surveillance Privacy Notice
  • Legal / Policies
  • Privacy Policy
  • Cookie Policy
  • Legal Notice and Terms of Use
  • Social Media
  • fFacebook
  • XX / Twitter
  • ▶YouTube
  • inLinkedIn

© 2026 Medicus