Where KVKK compliance starts: from inventory to disposal
Most compliance projects start by writing policy and get stuck there. The right order starts with the inventory; policy is built on top of it.
- KVKK
- Compliance
- Data inventory
The most common mistake we see in compliance projects is the ordering. An organisation engages a consultant, a policy set arrives as the first deliverable, the texts go onto the intranet, and the job is considered done. A few months later, when a data subject request arrives or a customer asks for an audit, the truth surfaces: what the policy says has no counterpart in reality.
The problem is not that the policy was badly written. A policy assumes you know which data you process and for what purpose. Without that knowledge the text becomes a wish list.
The right order
1. Inventory. Which unit, which system, which personal data; processed for what purpose; where it comes from and where it goes. This step is dull, but everything else rests on it. The sentence we hear most while building an inventory is: "We keep that too?"
2. Legal basis. For each processing activity, identify which ground in article 5 of the Law you rely on. Explicit consent should be the last resort; relying on consent when performance of a contract or a legal obligation applies leaves you exposed the moment someone withdraws it.
3. Retention periods. Decide how long you keep each data category. "Indefinitely" is not an answer. Write down the basis for the period too — a statute, a limitation period, or a business need.
4. The texts. The privacy notice, and explicit consent text where required. By now you know what to write, because you have the inventory.
5. Processes. What happens when a data subject request arrives, who does what in a breach, how expired data gets disposed of.
6. Disposal. The most frequently skipped step. Defining a retention period means nothing if you never delete what has expired.
Where the burden of proof sits
Article 12 of the Law requires you to take the technical and organisational measures needed to secure data. In an audit the question is not "did you take measures" but "show that you did". What you can show is records: the inventory itself, policy versions, request records, disposal records, access reviews.
That is why compliance has to be treated as a record-keeping discipline rather than a documentation exercise. A document is written once; records accumulate every day.
A practical start
If you have nothing at all, start here: open a table with columns for unit, system, data category, purpose, source, recipient and retention period. Then sit down for half an hour with each unit owner. The first pass will be incomplete, and that is fine — an incomplete inventory beats no inventory.
As this table grows it stops being manageable by hand. At that point you need a system that runs the inventory, the requests and the disposal together; we do that with HEM KVK. But the order does not change: inventory first.
To see where you stand, our free initial assessment takes eight questions.
This article is for information and does not constitute legal advice. For the current text of the legislation, refer to mevzuat.gov.tr and kvkk.gov.tr.

