Protection of Personal Data

Sivas Cumhuriyet University

Personal Data Protection and Data Processing Information

This page has been prepared to provide information about the data processing processes carried out by Sivas Cumhuriyet University, the Presidency of European Union Affairs of the Ministry of Foreign Affairs of the Republic of Turkey, the European Union Education and Youth Programs Center (Turkish National Agency), and the European Commission regarding the processing of personal data within the scope of Erasmus+ program mobility and project processes.

Important Information

This page provides general information only. For individual applications, projects, mobility, system usage, grant agreements, audits, reporting, or legal obligations, the relevant institutions' published information texts, explicit consent statements, confidentiality declarations, project contracts, program rules, and applicable legislation provisions shall apply.

Scope

Scope of Information

In the Erasmus+ program processes, personal data may be processed in different systems, institutions and record environments for the purposes of application, evaluation, selection, placement, contract, payment, reporting, auditing, monitoring, statistics, archiving and fulfilling post-mobility obligations.

Sivas Cumhuriyet University Processes

University website, support system, document submission, electronic document management system (EDMS), office records, archives, correspondence, and institutional processes.

TurnaPortal Processes

Application, evaluation, announcement, results, document upload, candidate/beneficiary processes, and all processes carried out through the Turkish National Agency systems.

European Commission Systems

Beneficiary Module, Erasmus+ and European Solidarity Corps platforms, EU Login, project management, reporting and European Commission digital systems.

Data Controller and Areas of Authority

Data Controller, Processing Authority, and Corporate Roles

In Erasmus+ program processes, data responsibility and data processing authority are determined according to the system, purpose, institution, and legal basis under which the personal data is processed.

Sivas Cumhuriyet University

Personal data processing activities related to the university website, the Erasmus+ Institutional Coordinator support system, document submission, institutional correspondence, EBYS processes, office records, archives, and internal university administrative processes are carried out within the framework of Sivas Cumhuriyet University's relevant policies and legislation.

Sivas Cumhuriyet University's Personal Data Protection Law (KVKK) Policy, Cookie Policy, Data Storage and Destruction Policy, and Policy on the Processing and Protection of Special Categories of Personal Data are reserved.

Turkish Ministry of Foreign Affairs, Presidency of European Union Affairs, European Union Education and Youth Programs Centre (Turkish National Agency)

TurnaPortal's data processing activities related to Erasmus+ applications, evaluations, announcements, reporting, program management, and national-level Erasmus+ processes can be carried out within the scope of this institution's duties and responsibilities.

Information texts, explicit consent statements, and application documents published in the relevant systems and processes shall be taken as the basis.

European Commission

The Beneficiary Module, Erasmus+ and European Solidarity Corps platforms, EU Login-linked project management, reporting, monitoring and data processing activities in terms of European Commission digital systems are carried out within the framework of the relevant confidentiality statements of the European Commission and the provisions of Regulation (EU) 2018/1725.

The European Commission's privacy statements list the Directorate-General for Education, Youth, Sport and Culture, Unit B.4 – Erasmus+ Coordination as the relevant data controller.

Partner Institutions and Host Organizations

In processes carried out by partner institutions, host universities, consortium partners, internship institutions, public institutions, or relevant third parties within the scope of mobility, the respective institution's own data protection regulations, privacy statements, and corporate policies may apply.

In international mobility, the transfer of personal data may be carried out within the scope of the nature of the mobility and relevant legal obligations.
Sivas Cumhuriyet University

Policies Implemented Under the Law on the Protection of Personal Data

Institutional documents published by Sivas Cumhuriyet University regarding the protection of personal data, the use of cookies, and data storage/destruction processes can be accessed via the links below.

TurnaPortal and Turkish National Agency Processes

TurnaPortal Personal Data Processing and Explicit Consent Information

In Erasmus+ processes conducted through TurnaPortal, personal data may be processed within the framework of the information and explicit consent texts published by the Presidency of European Union Education and Youth Programs of the Ministry of Foreign Affairs of the Republic of Turkey.

Categories of Data That Can Be Processed

  • Identity information
  • Contact Information
  • Information on education, personnel, institutions, and projects.
  • Application, evaluation, placement, and results information.
  • Information on mobility, grants, payments, contracts, and reporting.
  • Internet access information obtained using the corporate network.
  • Campus entry and exit information
  • Camera, photographs and visual recordings
  • Special categories of personal data where necessary.

Special Categories of Personal Data

Subject to being limited to the relevant process and complying with the conditions stipulated in the legislation, personal data of a special category such as nationality, criminal conviction and security measure information, blood type, health data, religion, sect and philosophical beliefs, biometric and genetic data, membership in associations, foundations and trade unions, political opinions and similar personal data may be processed.

Recording Media

  • Information system servers
  • Corporate applications
  • Corporate computers
  • Electronic storage media
  • Printed documents and papers
  • Office and archive records

Parties to whom it can be transferred

  • Legally authorized public institutions and organizations
  • Personal Data Protection Authority
  • Law enforcement
  • Information Technologies and Communications Authority
  • Judicial authorities
  • Consulting firms and lawyers for the purpose of conducting legal proceedings.
  • Institutions, organizations and systems necessary for the implementation of the Erasmus+ process.
European Commission Systems

Beneficiary Module and European Commission Data Processing Procedures

The management, monitoring, budget and participant information processing, reporting, and closing procedures of Erasmus+ projects can be carried out through the Beneficiary Module and the relevant digital systems provided by the European Commission.

Beneficiary Module User Authorization

Individuals who will be working with the Beneficiary Module and project management processes may need to be authorized as a project officer or project beneficiary and log in to the system with a valid EU Login account. Unauthorized access, incorrect user account usage, or data entry outside of assigned duties should be avoided.

Processing Purposes

Purposes of Processing Personal Data

Personal data may be processed for the following purposes, within the scope of the duties and powers of the data controllers:.

Managing the Erasmus+ application, selection, evaluation, placement, contract and mobility processes.
Performing grant, payment, budget, accounting, reporting, and audit processes.
Managing user and project operations on TurnaPortal, Beneficiary Module, EU Login and related digital systems.
Responding to information requests from administrative and judicial authorities and authorized public institutions.
Conducting legal processes, ensuring compliance with legislation, and fulfilling legal obligations.
Monitoring and evaluating program implementations, conducting statistical analysis and impact analysis studies.
Ensuring the safety of the institution, campus, visitors, lives, and property.
Occupational health and safety and fulfillment of administrative obligations required by public service.
Fulfillment of archiving, storage, destruction, audit trail, reporting and record-keeping obligations.
Legal Basis

Legal Grounds and Conditions for Procedure

Personal data may be processed in accordance with the Law No. 6698 on the Protection of Personal Data, relevant secondary legislation, Erasmus+ program rules, grant agreements, legislation relating to the conduct of public service, and applicable European Union data protection provisions in terms of European Commission systems.

GDPR and International Data Protection

GDPR Principles and International Transfer Information

Since Erasmus+ mobility and project applications are international in nature, personal data may be transferred to authorized institutions, organizations, and systems located domestically or abroad within the scope of relevant legislation and program rules.

Transparency

Data subjects should be informed about the purposes, scope, and parties involved in processing their data.

Limitation of Purpose

Personal data should be processed only for specific, explicit, and legitimate purposes.

Data Minimization

It is essential that personal data not required for the process is not requested or processed.

Storage Time

Personal data should be stored for a period limited to the purpose of processing and the periods stipulated in the legislation.

Privacy and Security

Personal data must be protected against unauthorized access, loss, alteration, or unlawful processing.

Data Subject Rights

Individuals concerned may have the right to access, correct, delete, object, restrict, and apply under applicable legislation.

Storage, Archiving and Destruction

Storage and Destruction of Personal Data

Personal data is stored in accordance with relevant legislation, Erasmus+ program rules, grant agreements, audit obligations, reporting requirements, archiving regulations, and institutional retention and destruction policies.

SCU GDPR Storage and Destruction Policy

Our university's institutional policy regarding the storage, deletion, destruction, and anonymization of personal data can be accessed via the following link.

View Storage and Disposal Policy
Data Subject Rights

Rights under the Turkish Personal Data Protection Law (KVKK) and European Union Data Protection Legislation

Data subjects may have the following rights under Article 11 of the Law No. 6698 on the Protection of Personal Data and, where applicable, European Union data protection legislation.

To find out if your personal data is being processed.
Requesting information regarding the processing of personal data.
To understand the purpose of the processing and whether the data is being used appropriately for that purpose.
Knowing the third parties to whom personal data is transferred, whether domestically or internationally.
Requesting correction of incomplete or incorrectly processed data.
Requesting the deletion or destruction of personal data when the conditions are met.
Requesting that corrections, deletions, or destructions be notified to third parties to whom the data has been transferred.
Objection to an unfavorable outcome resulting from analysis conducted by automated systems.
Claiming compensation for damages incurred as a result of an unlawful act.
Application and Contact

Exercise of Rights and Application Authorities

Requests regarding your personal data should be directed to the relevant data controller, according to the system and process by which the data is processed.

Sivas Cumhuriyet University Processes

Applications related to our university's website, cookies, support system, document submission, corporate correspondence, electronic document management system (EBYS), office records, and archiving processes are evaluated within the framework of Sivas Cumhuriyet University's Personal Data Protection Law (KVKK) processes and corporate application procedures.

European Commission and Beneficiary Module Processes

Applications concerning personal data processing activities carried out within the scope of the Beneficiary Module, EU Login, Erasmus+ and European Solidarity Corps platforms and the European Commission's digital systems may be evaluated through the data controller, Data Protection Officer and European Data Protection Supervisor application channels specified in the relevant privacy statements of the European Commission.

TurnaPortal and Turkish National Agency Processes

TurnaPortal processes applications, evaluations, results, reporting, and procedures related to Erasmus+ applications and the Turkish National Agency systems. These applications are evaluated by the Turkish Ministry of Foreign Affairs, the Presidency of European Union Affairs, the Presidency of the European Union Education and Youth Programs Center, and according to the procedures determined by the relevant institution.

Partner Institution and Host Organization Processes

For processes carried out by partner institutions, host universities, internship organizations, consortium partners, or third-party systems within the scope of mobility, the relevant institution's own data protection policies and application mechanisms may apply.

Explicit Consent and Declaration

Declaration of Explicit Consent, Accuracy, and Timeliness

In cases requiring explicit consent, personal data may be processed only for the stated purposes and after the data subject has been adequately informed.

Sivas Cumhuriyet University

Explicit Consent and Information Texts

You can access the Sivas Cumhuriyet University information texts, explicit consent forms, and data subject application forms related to the Erasmus+ program processes below.

Data Subject Application

All GDPR Texts

All personal data protection documents, information notices, explicit consent documents, and application forms published by Sivas Cumhuriyet University can be accessed from the university's official GDPR page.

Go to all GDPR texts