Data Protection
KVKK & GDPR Information
Sivas Cumhuriyet University respects the privacy and protection of personal data processed in connection with Erasmus+ mobility and international cooperation activities.
This page provides general information about personal data processing under Türkiye’s Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the European Union General Data Protection Regulation (GDPR).
KVKK and GDPR do not automatically apply in the same way
Personal data processing carried out by Sivas Cumhuriyet University in Türkiye is primarily governed by the Turkish Personal Data Protection Law No. 6698 (KVKK) and other applicable Turkish legislation.
GDPR may additionally be relevant where personal data are processed by European Union institutions, partner universities or other organisations subject to GDPR, or where a particular processing activity otherwise falls within the territorial scope of the Regulation.
When May Your Personal Data Be Processed?
Personal data may be required at different stages of an Erasmus+ mobility in order to manage the mobility and fulfil institutional, programme and legal obligations.
Nomination
Identification, contact and home-institution information may be received from your sending institution.
Application
Personal, academic and mobility information may be collected to assess and process your application.
Acceptance
Information may be used to prepare institutional acceptance and mobility documentation.
Mobility
Data may be processed for academic, administrative and practical arrangements during your stay.
Reporting
Erasmus+ programme requirements may involve monitoring, reporting, statistical and audit-related processing.
Archiving
Records may be retained in accordance with applicable legislation, programme rules and institutional retention requirements.
What Information May Be Processed?
The categories of personal data depend on your mobility type, programme requirements and the specific procedure being carried out.
Identity Information
Name, surname, nationality, date of birth, passport or identification information where required.
Contact Information
E-mail address, telephone number, address and other contact information relevant to mobility administration.
Academic Information
Home institution, study programme, transcript, Learning Agreement and academic mobility information.
Mobility Information
Mobility type, dates, host unit, Erasmus+ project information and related documentation.
Administrative Documents
Passport, visa, residence-related and other documents required for applicable administrative procedures.
Special Circumstances
Accessibility, inclusion or health-related information may be processed only where required for the relevant mobility procedure and in accordance with applicable law.
How Should Personal Data Be Handled?
Personal data processing should follow fundamental principles of lawfulness, transparency, necessity and security.
Lawful & Transparent Processing
Individuals should be informed about why their data are processed and how the relevant processing operates.
Defined Purposes
Personal data should be collected and processed for specified, explicit and legitimate purposes.
Only What Is Necessary
Processing should be limited to information necessary for the relevant Erasmus+ or institutional procedure.
Correct & Up to Date
Reasonable measures should be taken to keep relevant personal data accurate and up to date.
Retention for Required Periods
Personal data should not be retained longer than required by the processing purpose, legislation or applicable programme obligations.
Integrity & Confidentiality
Appropriate technical and organisational measures should protect data against unauthorised access, loss or unlawful processing.
Where May Data Be Processed?
Erasmus+ mobility is an international process and may require the use of systems operated by different authorised institutions.
University Systems & Records
Personal data may be processed within authorised University systems, official correspondence, mobility files and administrative records.
Türkiye National Agency Systems
Where applicable, Erasmus+ programme procedures may involve systems and processes administered by the Turkish National Agency.
European Commission Systems
Erasmus+ project management, reporting and mobility administration may require use of authorised European Commission platforms.
Sending & Partner Universities
Necessary mobility information may be exchanged with authorised representatives of your home or partner institution for Erasmus+ purposes.
Erasmus+ is an international mobility programme
Where required for Erasmus+ implementation, authorised personal data may be transferred to institutions, organisations or systems located in Türkiye or abroad, subject to the applicable legal framework, programme requirements and appropriate data protection safeguards.
Your Rights
Your specific rights depend on the applicable data protection legislation and the organisation responsible for the relevant processing activity.
Under Article 11 of Law No. 6698, data subjects may, subject to the conditions of the law, request information regarding the processing of their personal data.
- Learn whether personal data are being processed
- Request information about processing
- Learn the purpose of processing and whether data are used in accordance with that purpose
- Learn about third parties to whom data have been transferred
- Request correction of incomplete or inaccurate data
- Request deletion or destruction where the legal conditions are satisfied
- Request notification of relevant correction or deletion operations to recipients where applicable
- Object to certain adverse results arising solely from automated analysis
- Claim compensation where damage results from unlawful processing
Where GDPR applies to a particular processing operation, individuals may have additional rights subject to the conditions and limitations set out in the Regulation.
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability where applicable
- Right to object in applicable circumstances
- Rights relating to automated decision-making and profiling
How to Submit a Data Protection Request
Requests concerning personal data should be submitted to the data controller responsible for the relevant processing operation in accordance with the applicable procedure.
Data Subject Applications
Sivas Cumhuriyet University publishes institutional privacy policies, information notices and data subject application documents through its official Personal Data Protection website.
Storage, Archiving & Data Security
Required Retention Periods
Mobility records may be retained for periods required by legislation, Erasmus+ programme rules, financial and audit requirements or institutional record-management policies.
End of Processing Need
Personal data are subject to applicable institutional retention and destruction procedures when the relevant legal and processing requirements no longer apply.
Restricted Access
Access to personal information should be limited to authorised persons and handled according to institutional security and confidentiality requirements.
Policies & Legal Information
Please consult the official sources below for detailed and legally authoritative information.
This page does not replace a specific privacy notice
This page is intended as general information for Incoming Erasmus+ participants. For a specific application, mobility, system, project, agreement or processing activity, the applicable privacy notice, explicit consent text where required, institutional policy, programme documentation and current legislation shall prevail.
Questions about your Erasmus+ personal data?
For mobility-related information, you may contact the Erasmus+ Institutional Coordination Office. Formal data subject requests should follow the University’s applicable KVKK procedures.