
An organization’s backups contain almost all of the personal data held in its production systems: customer records, employee files, email archives and accounting data. That makes backups not just a business continuity tool but also a set of personal data that has to be protected under KVKK (Türkiye’s Personal Data Protection Law, Law No. 6698). A KVKK data backup approach means handling the backup of personal data together with encryption, access control, retention periods and a destruction policy, which makes it a core part of KVKK compliance.
This guide simplifies, for IT teams, the general data security framework of the Law, the technical measures recommended by the Personal Data Protection Authority and how to align backups with retention and destruction processes. The content is for general information only and is not legal advice.
Who Has Access to the Personal Data in Your Backups?
Production systems are usually tightly protected, while the backup repository is often overlooked. The MAV Cloud team is ready to review the current state of your backup infrastructure with you in terms of access, encryption and location.
What does KVKK data backup cover?
KVKK data backup covers the full lifecycle of every copy that contains personal data: taking the backup, transferring it, storing it, accessing it, restoring it and destroying it once its retention period expires. Backup software settings are only one part of this process. What really matters is that the rules governing those copies are defined and auditable.
When backing up personal data, the following data sets usually stand out:
- Database backups: Records from CRM, ERP, e-commerce and HR applications.
- File server copies: Contracts, personnel files and scanned documents.
- Email and collaboration data: Mailboxes and shared files on platforms such as Microsoft 365.
- Virtual machine images: Full copies taken together with all the application data inside them.
- Camera recordings and log archives: Footage and access records that make individuals identifiable.
Each of these sets may have a different retention period, different access needs and a different level of sensitivity. Keeping them all under the same rules within a single backup job makes it harder to handle destruction and access requests later on.
Where backup fits within KVKK technical measures
Article 12 of the Law requires data controllers to take technical and administrative measures that ensure an appropriate level of security in order to prevent unlawful processing of and access to personal data and to ensure its preservation. The Authority’s obligations regarding data security page (in Turkish) stresses that these measures are not one-size-fits-all; they should be determined according to the organization’s size, activities and risks.
The phrase “preservation of data” is directly relevant to backup. Being unable to recover lost or corrupted data is a security problem; at the same time, a backup that unauthorized people can access is just as much of a risk. A KVKK data backup plan has to balance both sides.
The same page also states that when data is processed through a service provider, the data controller and the data processor are jointly responsible for taking security measures. That is why it matters to review the provider’s security processes and the scope of the contract when choosing a cloud backup service.
Key measures in the Personal Data Security Guide
The Authority’s Personal Data Security Guide (Technical and Administrative Measures) (in Turkish) explains, with examples, the measures data controllers can adopt. The guide should be read as a reference rather than a binding checklist. For backup infrastructure, the key topics are:
- Backup and recovery: Having accessible copies in case data is lost or corrupted, and checking them regularly.
- Encryption: Encrypting backups both in transit and at rest.
- Access and authorization control: Only staff who need it can access the backup repository, using separate, strong credentials.
- Logging and monitoring: Logging backup, restore and deletion operations.
- Physical security: Protecting the areas that house backup media against unauthorized entry.
What these topics have in common is that backups are kept at the same security level as production systems. If multi-factor authentication is mandatory in production but the backup server can be accessed with a single password, the backup infrastructure is the weak link in terms of KVKK technical measures.
Data retention and destruction: what if deleted data remains in backups?
Destruction is the most overlooked aspect of KVKK data backup. Personal data deleted from a production system lives on in older backups until their retention period expires. This requires consistency between the organization’s data retention and destruction policy and its backup retention periods.
The Authority’s guide on the deletion, destruction or anonymization of personal data (in Turkish) covers deletion and destruction methods in detail. The practical takeaway for backup infrastructure is that each backup type should have a written retention period with its justification, and copies should be purged automatically when that period ends.
Where immutable backup is used, the lock period should also be set in line with this policy. While long lock periods are desirable for ransomware protection, they should not be so long that they conflict with the destruction obligation. The healthiest way to strike this balance is for the legal and IT teams to work together.
Keeping data in Türkiye and cross-border transfers
The country where backups are stored is a separate consideration in KVKK data backup planning. Sending a backup to a cloud region abroad may constitute a cross-border transfer of personal data. The Authority’s cross-border transfer page (in Turkish) explains that, following the 2024 amendments, transfers are now subject to a tiered structure: adequacy decisions, appropriate safeguards and exceptional cases.
Choosing to keep data in Türkiye simplifies this assessment. For backups stored in a data center in Türkiye, cross-border transfer procedures do not come into play, while the organization’s other obligations remain unchanged. You should also check whether data indirectly leaves the country through the backup software’s cloud layer, support access or monitoring services.
Common practice vs. the right approach
In many organizations, backing up personal data is seen as a technical routine and is left out of compliance work. The table below summarizes the difference between common practice in the field and a compliant setup.
| Topic | Common practice | Right approach |
|---|---|---|
| Inventory | Backups are not included in the data inventory | Each backup type is recorded in the inventory with the data categories it contains |
| Encryption | Only in transit, or not at all | Encryption in transit and at rest, with separate key management |
| Access | Same administrator account as production | Separate identity, multi-factor authentication, least privilege |
| Retention period | Until storage runs out | Justified period aligned with the destruction policy |
| Location | Unknown or left to the provider | Data location documented and verified |
| Logging | Restore and deletion operations are not tracked | All operations are logged and reviewed periodically |
Most of the gaps in the table do not require new investment; they can be closed by configuring existing backup software correctly and putting responsibilities in writing.
Keep Your Backups Encrypted and in Türkiye
MAV Cloud’s cloud backup service stores Veeam-based backups in an Equinix data center in Türkiye. Retention periods, access structure and the immutable copy setup are planned together with you according to your organization’s policies.
Process steps: how to prepare a KVKK data backup policy
When preparing the policy, start with the data, then the technology. The steps below show a typical sequence that legal and IT teams can carry out together:
- Mapping to the data inventory: Identify which personal data categories each system holds and which backup jobs those systems are included in.
- Defining retention periods: Write down a period for each backup type, consistent with the organization’s data retention and destruction policy.
- Deciding on location: Confirm the data center and country where backups will be stored, and check whether any flow requires a cross-border transfer.
- Encryption and key management: Enable encryption in transit and at rest, and decide who holds the keys and where.
- Access model: Define the roles that will access the backup infrastructure, and enforce separate identities and multi-factor authentication.
- Testing and logging: Put restore tests on a schedule, and log backup, restore and deletion operations.
- Periodic review: Reflect new systems, changing retention periods and audit findings in the policy.
The output of these steps is a written policy you can show during an audit, backed by the technical records that support it. The value of a KVKK data backup process is measured by your ability to prove it is actually applied.
Common mistakes and the right way to handle them
Even in organizations that have done compliance work, some gaps keep recurring in the backup infrastructure. The most common ones, and the right way to handle them, are:
- Unencrypted external drives: An unencrypted drive carried home or left in a car exposes all the personal data on it if it is lost. The right approach is an encrypted, automated copy in a separate location.
- Indefinite retention: Keeping backups for as long as storage allows can conflict with the destruction policy. Retention periods should be justified and enforced automatically.
- Real data in test environments: Uncontrolled use of production data restored from backup in test environments creates additional risk; masking or access restrictions should be applied.
- Not reviewing the provider contract: For a cloud backup service, data location, sub-processors and security measures should be clearly stated in the contract.
- Forgetting SaaS data: Personal data on email and collaboration platforms should also be included in the backup and retention policy.
Many of these mistakes stem from process rather than technology. Having the backup owner and the personal data compliance owner work together regularly helps catch gaps early.
Backup with MAV Cloud: infrastructure, standards and SLA targets
MAV Cloud delivers backup and disaster recovery services from an Equinix data center in Türkiye, using VMware infrastructure and Veeam-based backup. Its information security and personal data management processes are certified to international standards.
- Certifications: ISO/IEC 27001, ISO/IEC 27701 for personal data management, ISO 22301, ISO 9001 and ISO/IEC 20000.
- SLA target: A 99.9% monthly availability target for the backup service.
- First-response targets: 15 minutes for critical requests, 1 hour for high priority and 4 hours for medium priority.
- Support: 24/7 expert support and 24/7 system monitoring.
For the technical infrastructure, the cloud backup service, and for the policy and process side, KVKK security consulting can be considered together.
Frequently Asked Questions
Is data backup mandatory under KVKK?
The Law does not mandate a specific backup technology; it expects data controllers to take appropriate technical and administrative measures, including measures to preserve data. Backup is widely regarded as one of those measures. Seek legal support for an assessment specific to your organization.
Do you need explicit consent to back up personal data?
Backup is usually treated as a measure to secure an existing processing activity. However, since every organization’s processing conditions are different, this question should be assessed with your legal team for your specific case.
How long should backups be kept?
There is no single period. It is determined by considering the purpose of processing, retention requirements in the relevant legislation and the organization’s data retention and destruction policy together, and it should be put in writing.
What should you do if deleted personal data remains in backups?
Backup copies should be configured to be purged automatically when the defined retention period expires. During that period, a process should be in place to ensure that deleted data is not processed again when restoring from backup.
Is it a problem to store backups in a cloud outside Türkiye?
Sending backups to a region abroad may be considered a cross-border transfer of personal data and requires reviewing the transfer conditions in the Law. Keeping data in Türkiye simplifies this assessment.
Is encrypting backups enough?
Encryption is an important measure, but it is not enough on its own. It should be applied together with access control, operation logs, retention management and regular restore testing.
Does immutable backup conflict with the destruction obligation?
There is no conflict when the lock period is set in line with the destruction policy. The lock period should be defined by weighing the need for ransomware protection against the justification for retaining the data.
Should Microsoft 365 data be included in the policy?
Mailboxes and shared files contain large amounts of personal data. It is recommended that an independent backup of this data, along with its retention and access rules, be brought within the scope of your KVKK data backup policy.
Review Your Backup Infrastructure Through a Compliance Lens
A free assessment shows the location, encryption status, access structure and retention periods of your backups in a single report.
For organizations just starting to look into this, the first step is to check whether backups are included in the data inventory. IT teams unsure about encryption and location can get a concrete starting point by mapping the backup flow of one critical system from end to end. Businesses ready to put a policy into practice can finalize the technical infrastructure and process steps together with the MAV Cloud team.

