Personal Data Protection and Data Processing Information
This page has been prepared to provide information about the data processing processes carried out by Sivas Cumhuriyet University, the Presidency of European Union Affairs of the Ministry of Foreign Affairs of the Republic of Turkey, the European Union Education and Youth Programs Center (Turkish National Agency), and the European Commission regarding the processing of personal data within the scope of Erasmus+ program mobility and project processes.
Important Information
This page provides general information only. For individual applications, projects, mobility, system usage, grant agreements, audits, reporting, or legal obligations, the relevant institutions' published information texts, explicit consent statements, confidentiality declarations, project contracts, program rules, and applicable legislation provisions shall apply.
Scope of Information
In the Erasmus+ program processes, personal data may be processed in different systems, institutions and record environments for the purposes of application, evaluation, selection, placement, contract, payment, reporting, auditing, monitoring, statistics, archiving and fulfilling post-mobility obligations.
Sivas Cumhuriyet University Processes
University website, support system, document submission, electronic document management system (EDMS), office records, archives, correspondence, and institutional processes.
TurnaPortal Processes
Application, evaluation, announcement, results, document upload, candidate/beneficiary processes, and all processes carried out through the Turkish National Agency systems.
European Commission Systems
Beneficiary Module, Erasmus+ and European Solidarity Corps platforms, EU Login, project management, reporting and European Commission digital systems.
Data Controller, Processing Authority, and Corporate Roles
In Erasmus+ program processes, data responsibility and data processing authority are determined according to the system, purpose, institution, and legal basis under which the personal data is processed.
Sivas Cumhuriyet University
Personal data processing activities related to the university website, the Erasmus+ Institutional Coordinator support system, document submission, institutional correspondence, EBYS processes, office records, archives, and internal university administrative processes are carried out within the framework of Sivas Cumhuriyet University's relevant policies and legislation.
Sivas Cumhuriyet University's Personal Data Protection Law (KVKK) Policy, Cookie Policy, Data Storage and Destruction Policy, and Policy on the Processing and Protection of Special Categories of Personal Data are reserved.Turkish Ministry of Foreign Affairs, Presidency of European Union Affairs, European Union Education and Youth Programs Centre (Turkish National Agency)
TurnaPortal's data processing activities related to Erasmus+ applications, evaluations, announcements, reporting, program management, and national-level Erasmus+ processes can be carried out within the scope of this institution's duties and responsibilities.
Information texts, explicit consent statements, and application documents published in the relevant systems and processes shall be taken as the basis.European Commission
The Beneficiary Module, Erasmus+ and European Solidarity Corps platforms, EU Login-linked project management, reporting, monitoring and data processing activities in terms of European Commission digital systems are carried out within the framework of the relevant confidentiality statements of the European Commission and the provisions of Regulation (EU) 2018/1725.
The European Commission's privacy statements list the Directorate-General for Education, Youth, Sport and Culture, Unit B.4 – Erasmus+ Coordination as the relevant data controller.Partner Institutions and Host Organizations
In processes carried out by partner institutions, host universities, consortium partners, internship institutions, public institutions, or relevant third parties within the scope of mobility, the respective institution's own data protection regulations, privacy statements, and corporate policies may apply.
In international mobility, the transfer of personal data may be carried out within the scope of the nature of the mobility and relevant legal obligations.Policies Implemented Under the Law on the Protection of Personal Data
Institutional documents published by Sivas Cumhuriyet University regarding the protection of personal data, the use of cookies, and data storage/destruction processes can be accessed via the links below.
TurnaPortal Personal Data Processing and Explicit Consent Information
In Erasmus+ processes conducted through TurnaPortal, personal data may be processed within the framework of the information and explicit consent texts published by the Presidency of European Union Education and Youth Programs of the Ministry of Foreign Affairs of the Republic of Turkey.
Categories of Data That Can Be Processed
- Identity information
- Contact Information
- Information on education, personnel, institutions, and projects.
- Application, evaluation, placement, and results information.
- Information on mobility, grants, payments, contracts, and reporting.
- Internet access information obtained using the corporate network.
- Campus entry and exit information
- Camera, photographs and visual recordings
- Special categories of personal data where necessary.
Special Categories of Personal Data
Subject to being limited to the relevant process and complying with the conditions stipulated in the legislation, personal data of a special category such as nationality, criminal conviction and security measure information, blood type, health data, religion, sect and philosophical beliefs, biometric and genetic data, membership in associations, foundations and trade unions, political opinions and similar personal data may be processed.
Recording Media
- Information system servers
- Corporate applications
- Corporate computers
- Electronic storage media
- Printed documents and papers
- Office and archive records
Parties to whom it can be transferred
- Legally authorized public institutions and organizations
- Personal Data Protection Authority
- Law enforcement
- Information Technologies and Communications Authority
- Judicial authorities
- Consulting firms and lawyers for the purpose of conducting legal proceedings.
- Institutions, organizations and systems necessary for the implementation of the Erasmus+ process.
Beneficiary Module and European Commission Data Processing Procedures
The management, monitoring, budget and participant information processing, reporting, and closing procedures of Erasmus+ projects can be carried out through the Beneficiary Module and the relevant digital systems provided by the European Commission.
Processing within the Beneficiary Module
- Viewing, updating, and managing project information.
- Processing of beneficiary organization and project staff information.
- Participant, mobility, budget and activity information must be entered into the system.
- Interim report, final report, monitoring, control and audit processes are carried out.
- The European Commission, the Turkish National Agency, and authorized users have access to the system within the scope of their duties.
- Authorization and authentication processes are carried out via EU Login.
European Commission Data Controllership
- Personal data may be processed in the European Commission's digital systems within the scope of Regulation (EU) 2018/1725.
- The European Commission implements technical and organizational measures to protect personal data and ensure privacy.
- The European Commission's privacy statements indicate the Directorate-General for Education, Youth, Sport and Culture, Unit B.4 – Erasmus+ Coordination as the relevant data controller.
- With regard to European Commission systems, relevant individuals can exercise their rights before the European Commission Data Protection Officer and the European Data Protection Supervisor within the framework of applicable legislation.
Beneficiary Module User Authorization
Individuals who will be working with the Beneficiary Module and project management processes may need to be authorized as a project officer or project beneficiary and log in to the system with a valid EU Login account. Unauthorized access, incorrect user account usage, or data entry outside of assigned duties should be avoided.
Purposes of Processing Personal Data
Personal data may be processed for the following purposes, within the scope of the duties and powers of the data controllers:.
Legal Grounds and Conditions for Procedure
Personal data may be processed in accordance with the Law No. 6698 on the Protection of Personal Data, relevant secondary legislation, Erasmus+ program rules, grant agreements, legislation relating to the conduct of public service, and applicable European Union data protection provisions in terms of European Commission systems.
Within the scope of the Personal Data Protection Law (KVKK)
- Explicitly provided for in the laws
- Fulfillment of legal obligation
- It must be directly related to the formation or performance of a contract.
- Establishment, exercise or protection of a right
- The execution of public services and institutional administrative processes.
- The explicit consent of the relevant person is required.
- With regard to special categories of personal data, the conditions stipulated in the Law and related legislation must be met.
European Union Data Protection Framework
- Personal data processing activities of European Union institutions, bodies, offices and agencies under Regulation (EU) 2018/1725
- The performance of the duty in the public interest or through the exercise of official authority.
- Fulfillment of legal obligations to which the data controller is subject.
- Fulfillment of monitoring, evaluation, reporting, auditing and program management obligations.
- Data security, access authorization, confidentiality, and processing based on the "need-to-know" principle.
GDPR Principles and International Transfer Information
Since Erasmus+ mobility and project applications are international in nature, personal data may be transferred to authorized institutions, organizations, and systems located domestically or abroad within the scope of relevant legislation and program rules.
Transparency
Data subjects should be informed about the purposes, scope, and parties involved in processing their data.
Limitation of Purpose
Personal data should be processed only for specific, explicit, and legitimate purposes.
Data Minimization
It is essential that personal data not required for the process is not requested or processed.
Storage Time
Personal data should be stored for a period limited to the purpose of processing and the periods stipulated in the legislation.
Privacy and Security
Personal data must be protected against unauthorized access, loss, alteration, or unlawful processing.
Data Subject Rights
Individuals concerned may have the right to access, correct, delete, object, restrict, and apply under applicable legislation.
Kişisel Verilerin Saklanması ve İmhası
Kişisel veriler; ilgili mevzuat, Erasmus+ program kuralları, hibe sözleşmeleri, denetim yükümlülükleri, raporlama gereklilikleri, arşiv mevzuatı ve kurumsal saklama-imha politikaları doğrultusunda saklanır.
SCÜ KVKK Saklama ve İmha Politikası
Üniversitemizin kişisel verilerin saklanması, silinmesi, yok edilmesi ve anonim hale getirilmesine ilişkin kurumsal politikasına aşağıdaki bağlantıdan erişilebilir.
Saklama ve İmha Politikasını GörüntüleKVKK ve Avrupa Birliği Veri Koruma Mevzuatı Kapsamındaki Haklar
İlgili kişiler, 6698 sayılı Kişisel Verilerin Korunması Kanununun 11. maddesi ve uygulanabilir olması halinde Avrupa Birliği veri koruma mevzuatı kapsamında aşağıdaki haklara sahip olabilir.
Hakların Kullanılması ve Başvuru Mercileri
Kişisel verilerinize ilişkin başvurular, verinin işlendiği sistem ve sürece göre ilgili veri sorumlusuna yöneltilmelidir.
Sivas Cumhuriyet University Processes
Üniversitemiz internet sitesi, çerezler, destek sistemi, belge teslimi, kurumsal yazışmalar, EBYS, ofis kayıtları ve arşiv süreçleriyle ilgili başvurular Sivas Cumhuriyet Üniversitesinin KVKK süreçleri ve kurumsal başvuru usulleri çerçevesinde değerlendirilir.
Avrupa Komisyonu ve Beneficiary Module Süreçleri
Beneficiary Module, EU Login, Erasmus+ and European Solidarity Corps platformları ve Avrupa Komisyonu dijital sistemleri kapsamında yürütülen kişisel veri işleme faaliyetleriyle ilgili başvurular, Avrupa Komisyonunun ilgili gizlilik beyanlarında belirtilen veri sorumlusu, Veri Koruma Görevlisi ve Avrupa Veri Koruma Denetçisi başvuru yolları çerçevesinde değerlendirilebilir.
TurnaPortal and Turkish National Agency Processes
TurnaPortal, Erasmus+ başvuru, değerlendirme, sonuç, raporlama ve Türkiye Ulusal Ajansı sistemleri kapsamında yürütülen işlemlerle ilgili başvurular, T.C. Dışişleri Bakanlığı, Avrupa Birliği Başkanlığı, Avrupa Birliği Eğitim ve Gençlik Programları Merkezi Başkanlığı nezdinde ve ilgili kurum tarafından belirlenen usuller çerçevesinde değerlendirilir.
Ortak Kurum ve Ev Sahibi Kuruluş Süreçleri
Hareketlilik kapsamında karşı kurum, ev sahibi üniversite, staj kurumu, konsorsiyum ortağı veya üçüncü taraf sistemler tarafından yürütülen işlemler için ilgili kurumun kendi veri koruma politikaları ve başvuru mekanizmaları geçerli olabilir.
Açık Rıza, Doğruluk ve Güncellik Beyanı
Açık rıza gerektiren hallerde kişisel veriler, ilgili kişiye gerekli aydınlatma yapıldıktan sonra ve yalnızca belirtilen amaçlarla sınırlı olmak üzere işlenebilir.
Açık Rıza ve Aydınlatma Metinleri
Erasmus+ programı süreçleriyle bağlantılı olan Sivas Cumhuriyet Üniversitesi aydınlatma metinleri, açık rıza metinleri ve ilgili kişi başvuru formuna aşağıdan ulaşabilirsiniz.
Aydınlatma Metinleri
Aydınlatma ve Açık Rıza Metinleri
Erasmus+ Programı Aydınlatma Metinleri
Erasmus+ Programı Açık Rıza Metinleri
İlgili Kişi Başvurusu
Tüm KVKK Metinleri
Sivas Cumhuriyet Üniversitesi tarafından yayımlanan tüm kişisel verilerin korunması metinlerine, aydınlatma metinlerine, açık rıza metinlerine ve başvuru formlarına kurumsal KVKK sayfasından erişebilirsiniz.



