Guide to Deletion, Destruction or Anonymization of Personal Data

ISBN: 978-975-19-6807-4
Publication Date: January 2018, Ankara
Personal Data Protection Authority
Address: Nasuh Akar Neighborhood Ziyabey Street 1407. Street No:6 Balgat /Çankaya / ANKARA / TURKEY
Phone: +90 312 216 50 50
Web: www.kvkk.gov.tr

The text, photographs and other contents in this book may not be partially or fully copied, reproduced, used, published or distributed without permission except for individual use. Legal action will be taken against those who do not comply with this prohibition pursuant to the Law on Intellectual and Artistic Works No. 5846. All rights reserved for the product.

Summary

This Guide explains the main methods for the deletion, destruction or anonymization of personal data processed in accordance with the Law on the Protection of Personal Data No. 6698 ("Law") and other relevant legislation, when the reasons requiring processing cease to exist. In the Guide, deletion and destruction methods are explained separately considering the environment where personal data is processed and stored, while anonymization methods and the breach of anonymity are explained in detail with practical examples.

Abstract

This Guide explains the major methods for the erasure, destruction or anonymization of personal data processed in accordance with the provisions of the Law on the Protection of Personal Data (Law No. 6698) and other relevant legislation, providing that no reason for processing that data is left. In the Guide, the erasure and destruction methods, considering the environment in which the personal data is processed and stored are explained separately. Besides, anonymization methods and de-anonymization are covered in detail along with the examples of implementation.

Keywords

Turkish: Personal data, deletion, destruction, anonymization, breach of anonymity.
English: Personal data, erasure, destruction, anonymization, de-anonymization.

Contents

  • I. Introduction
  • II. Deletion and Destruction of Personal Data
  • III. Anonymization of Personal Data
  • IV. Sources Used in Preparing the Guide and Documents Considered Appropriate for Review

I. Introduction

1.1. Purpose and Basis

Article 7, paragraph 3 of the Law states: "Procedures and principles regarding the deletion, destruction or anonymization of personal data shall be regulated by regulation." Pursuant to this provision and Article 22, paragraph 1(e) of the Law, the Personal Data Protection Board ("Board") prepared the Regulation on Deletion, Destruction or Anonymization of Personal Data ("Regulation"), published in the Official Gazette No. 30224 dated October 28, 2017. Based on this Regulation, the Board prepared and presented to the public the Guide on Deletion, Destruction or Anonymization of Personal Data ("Guide") to clarify how these processes should be performed in practice and to highlight various topics for good practice examples.

1.2. Scope

The first section of the Guide is the introduction, covering the purpose, basis, scope and definitions of the Guide. The second section explains the deletion of personal data, deletion methods and process, and destruction of personal data and related methods. The third section covers anonymization of personal data, related methods, how to select these methods, guarantees of anonymity and risks of breach of anonymity. The fourth section includes sources used in preparing the Guide and documents considered appropriate for review.

1.3. Definitions

  • Recipient group: The category of real or legal persons to whom personal data is transferred by the data controller.
  • Direct identifiers: Identifiers that alone directly reveal, disclose and distinguish the person they relate to.
  • Indirect identifiers: Identifiers that, combined with other identifiers, reveal, disclose and distinguish the person they relate to.
  • Data subject: The real person whose personal data is processed.
  • Relevant user: Real or legal persons who process personal data within the data controller organization or under its authority and instructions, excluding the person or unit responsible for technical storage, protection and backup of data.
  • Destruction: The deletion, destruction or anonymization of personal data.
  • Law: The Law on the Protection of Personal Data No. 6698 dated 24/3/2016.
  • Redaction: Processes such as crossing out, painting over or blurring the entirety of personal data so that it cannot be associated with an identified or identifiable real person.
  • Recording medium: Any environment where personal data processed fully or partially automatically or non-automatically as part of any data recording system is stored.
  • Personal data retention and destruction policy: The policy data controllers use as a basis for determining the maximum period personal data is processed for the purpose and for deletion, destruction and anonymization processes.
  • Masking: Processes such as deleting, crossing out, painting over or asterisking certain fields of personal data so that it cannot be associated with an identified or identifiable real person.
  • Data recording system: The recording system where personal data is structured and processed according to specific criteria.

Definitions not included in this Guide may be referred to in the Law and Regulation.

II. Deletion and Destruction of Personal Data

Deletion and destruction of personal data can be performed by the methods explained below in accordance with the principles specified in the personal data retention and destruction policy.

2.1. Deletion of Personal Data

Deletion of personal data is the process of making personal data inaccessible and unusable for relevant users in any way. The data controller is obliged to take all necessary technical and administrative measures to ensure that deleted personal data is inaccessible and unusable for relevant users.

2.1.1. Deletion Process of Personal Data

The process to be followed in the deletion of personal data is as follows:

  • Identification of personal data subject to deletion.
  • Determination of relevant users for each personal data using an access authorization and control matrix or a similar system.
  • Identification of the access, retrieval and reuse rights and methods of relevant users.
  • Disabling and removing the access, retrieval and reuse rights and methods of relevant users regarding personal data.

Figure 2.1. Deletion Process of Personal Data

2.1.2. Methods of Deletion of Personal Data

Since personal data can be stored in various recording media, they must be deleted using methods appropriate to the recording media. Examples are provided below:

  1. Cloud Solutions as a Service Application Types (such as Office 365, Salesforce, Dropbox): Data in the cloud system should be deleted by issuing a delete command. During this process, it must be ensured that the relevant user does not have the right to restore deleted data on the cloud system.
  2. Personal Data in Paper Form: Personal data in paper form should be deleted using the redaction method. Redaction involves cutting out personal data on the document where possible, or otherwise making it invisible to relevant users by using permanent ink so that it cannot be reversed or read by technological means. For example, when a person who applied to the data controller for deletion of their personal data but did not receive a result submits a petition to our Authority, a copy of that petition is shared with personal data redacted by crossing out, painting over or erasing to protect personal data.
  3. Office Files on Central Server: The file should be deleted using the delete command in the operating system or the access rights of the relevant user to the file or directory should be removed. It must be ensured that the relevant user is not also a system administrator during this process.
  4. Personal Data on Portable Media: Personal data on flash-based storage media should be stored encrypted and deleted using software appropriate for these media.
  5. Databases: Relevant rows containing personal data should be deleted using database commands (e.g., DELETE). It must be ensured that the relevant user is not also a database administrator during this process.

2.2. Destruction of Personal Data

Destruction of personal data is the process of making personal data inaccessible, irretrievable and unusable by anyone in any way. The data controller is obliged to take all necessary technical and administrative measures regarding the destruction of personal data.

2.2.1. Methods of Destruction of Personal Data

For destruction of personal data, all copies of the data must be identified and destroyed one by one using one or more of the methods below according to the type of systems where the data is stored:

  1. Local Systems: One or more of the following methods can be used to destroy data on these systems.
    • De-magnetization: The process of exposing magnetic media to a very strong magnetic field by passing it through a special device to render the data unreadable.

    Image 2.2. Degausser Device

    • Physical Destruction: Physically destroying optical and magnetic media by melting, burning or pulverizing. Processes such as melting, burning, pulverizing or passing through a metal grinder make data inaccessible. If overwriting or de-magnetization is unsuccessful for solid-state drives, physical destruction is required.

    Image 2.3. Physical Destruction

    • Overwriting: Writing random data consisting of 0s and 1s at least seven times over magnetic and rewritable optical media to prevent recovery of old data. This process is performed using special software.

    Image 2.4. Overwriting

  2. Environmental Systems: Destruction methods depending on the type of environment are as follows:
    • Network devices (switch, router, etc.): Storage media inside these devices are fixed. Products often have delete commands but no destruction feature. They must be destroyed using one or more of the appropriate methods mentioned in (a).
    • Flash-based media: Flash-based hard drives with ATA (SATA, PATA, etc.) or SCSI (SCSI Express, etc.) interfaces should use the <block erase> command if supported, or the manufacturer's recommended destruction method, or one or more of the appropriate methods in (a).
    • Magnetic tape: Media storing data on flexible tape using micro magnets. They must be destroyed by de-magnetizing with very strong magnetic fields or physical destruction methods such as burning or melting.
    • Magnetic disk units: Media storing data on flexible (platter) or fixed media using micro magnets. They must be destroyed by de-magnetizing with very strong magnetic fields or physical destruction methods such as burning or melting.
    • Mobile phones (SIM card and fixed memory areas): Portable smartphones have delete commands for fixed memory areas but mostly lack destruction commands. They must be destroyed using one or more of the appropriate methods in (a).
    • Optical disks: Data storage media such as CDs and DVDs. Physical destruction methods such as burning, shredding into small pieces or melting should be applied.