Personal Data Protection and Data Processing Information
This page has been prepared to provide information about the data processing processes carried out by Sivas Cumhuriyet University, the Presidency of European Union Affairs of the Ministry of Foreign Affairs of the Republic of Turkey, the European Union Education and Youth Programs Center (Turkish National Agency), and the European Commission regarding the processing of personal data within the scope of Erasmus+ program mobility and project processes.
Important Information
This page provides general information only. For individual applications, projects, mobility, system usage, grant agreements, audits, reporting, or legal obligations, the relevant institutions' published information texts, explicit consent statements, confidentiality declarations, project contracts, program rules, and applicable legislation provisions shall apply.
Scope of Information
In the Erasmus+ program processes, personal data may be processed in different systems, institutions and record environments for the purposes of application, evaluation, selection, placement, contract, payment, reporting, auditing, monitoring, statistics, archiving and fulfilling post-mobility obligations.
Sivas Cumhuriyet University Processes
University website, support system, document submission, electronic document management system (EDMS), office records, archives, correspondence, and institutional processes.
TurnaPortal Processes
Application, evaluation, announcement, results, document upload, candidate/beneficiary processes, and all processes carried out through the Turkish National Agency systems.
European Commission Systems
Beneficiary Module, Erasmus+ and European Solidarity Corps platforms, EU Login, project management, reporting and European Commission digital systems.
Data Controller, Processing Authority, and Corporate Roles
In Erasmus+ program processes, data responsibility and data processing authority are determined according to the system, purpose, institution, and legal basis under which the personal data is processed.
Sivas Cumhuriyet University
Personal data processing activities related to the university website, the Erasmus+ Institutional Coordinator support system, document submission, institutional correspondence, EBYS processes, office records, archives, and internal university administrative processes are carried out within the framework of Sivas Cumhuriyet University's relevant policies and legislation.
Sivas Cumhuriyet University's Personal Data Protection Law (KVKK) Policy, Cookie Policy, Data Storage and Destruction Policy, and Policy on the Processing and Protection of Special Categories of Personal Data are reserved.Turkish Ministry of Foreign Affairs, Presidency of European Union Affairs, European Union Education and Youth Programs Centre (Turkish National Agency)
TurnaPortal's data processing activities related to Erasmus+ applications, evaluations, announcements, reporting, program management, and national-level Erasmus+ processes can be carried out within the scope of this institution's duties and responsibilities.
Information texts, explicit consent statements, and application documents published in the relevant systems and processes shall be taken as the basis.European Commission
The Beneficiary Module, Erasmus+ and European Solidarity Corps platforms, EU Login-linked project management, reporting, monitoring and data processing activities in terms of European Commission digital systems are carried out within the framework of the relevant confidentiality statements of the European Commission and the provisions of Regulation (EU) 2018/1725.
The European Commission's privacy statements list the Directorate-General for Education, Youth, Sport and Culture, Unit B.4 – Erasmus+ Coordination as the relevant data controller.Partner Institutions and Host Organizations
In processes carried out by partner institutions, host universities, consortium partners, internship institutions, public institutions, or relevant third parties within the scope of mobility, the respective institution's own data protection regulations, privacy statements, and corporate policies may apply.
In international mobility, the transfer of personal data may be carried out within the scope of the nature of the mobility and relevant legal obligations.Policies Implemented Under the Law on the Protection of Personal Data
Institutional documents published by Sivas Cumhuriyet University regarding the protection of personal data, the use of cookies, and data storage/destruction processes can be accessed via the links below.
TurnaPortal Personal Data Processing and Explicit Consent Information
In Erasmus+ processes conducted through TurnaPortal, personal data may be processed within the framework of the information and explicit consent texts published by the Presidency of European Union Education and Youth Programs of the Ministry of Foreign Affairs of the Republic of Turkey.
Categories of Data That Can Be Processed
- Identity information
- Contact Information
- Information on education, personnel, institutions, and projects.
- Application, evaluation, placement, and results information.
- Information on mobility, grants, payments, contracts, and reporting.
- Internet access information obtained using the corporate network.
- Campus entry and exit information
- Camera, photographs and visual recordings
- Special categories of personal data where necessary.
Special Categories of Personal Data
Subject to being limited to the relevant process and complying with the conditions stipulated in the legislation, personal data of a special category such as nationality, criminal conviction and security measure information, blood type, health data, religion, sect and philosophical beliefs, biometric and genetic data, membership in associations, foundations and trade unions, political opinions and similar personal data may be processed.
Recording Media
- Information system servers
- Corporate applications
- Corporate computers
- Electronic storage media
- Printed documents and papers
- Office and archive records
Parties to whom it can be transferred
- Legally authorized public institutions and organizations
- Personal Data Protection Authority
- Law enforcement
- Information Technologies and Communications Authority
- Judicial authorities
- Consulting firms and lawyers for the purpose of conducting legal proceedings.
- Institutions, organizations and systems necessary for the implementation of the Erasmus+ process.
Beneficiary Module and European Commission Data Processing Procedures
The management, monitoring, budget and participant information processing, reporting, and closing procedures of Erasmus+ projects can be carried out through the Beneficiary Module and the relevant digital systems provided by the European Commission.
Processing within the Beneficiary Module
- Viewing, updating, and managing project information.
- Processing of beneficiary organization and project staff information.
- Participant, mobility, budget and activity information must be entered into the system.
- Interim report, final report, monitoring, control and audit processes are carried out.
- The European Commission, the Turkish National Agency, and authorized users have access to the system within the scope of their duties.
- Authorization and authentication processes are carried out via EU Login.
European Commission Data Controllership
- Personal data may be processed in the European Commission's digital systems within the scope of Regulation (EU) 2018/1725.
- The European Commission implements technical and organizational measures to protect personal data and ensure privacy.
- The European Commission's privacy statements indicate the Directorate-General for Education, Youth, Sport and Culture, Unit B.4 – Erasmus+ Coordination as the relevant data controller.
- With regard to European Commission systems, relevant individuals can exercise their rights before the European Commission Data Protection Officer and the European Data Protection Supervisor within the framework of applicable legislation.
Beneficiary Module User Authorization
Individuals who will be working with the Beneficiary Module and project management processes may need to be authorized as a project officer or project beneficiary and log in to the system with a valid EU Login account. Unauthorized access, incorrect user account usage, or data entry outside of assigned duties should be avoided.
Purposes of Processing Personal Data
Personal data may be processed for the following purposes, within the scope of the duties and powers of the data controllers:.
Legal Grounds and Conditions for Procedure
Personal data may be processed in accordance with the Law No. 6698 on the Protection of Personal Data, relevant secondary legislation, Erasmus+ program rules, grant agreements, legislation relating to the conduct of public service, and applicable European Union data protection provisions in terms of European Commission systems.
Within the scope of the Personal Data Protection Law (KVKK)
- Explicitly provided for in the laws
- Fulfillment of legal obligation
- It must be directly related to the formation or performance of a contract.
- Establishment, exercise or protection of a right
- The execution of public services and institutional administrative processes.
- The explicit consent of the relevant person is required.
- With regard to special categories of personal data, the conditions stipulated in the Law and related legislation must be met.
European Union Data Protection Framework
- Personal data processing activities of European Union institutions, bodies, offices and agencies under Regulation (EU) 2018/1725
- The performance of the duty in the public interest or through the exercise of official authority.
- Fulfillment of legal obligations to which the data controller is subject.
- Fulfillment of monitoring, evaluation, reporting, auditing and program management obligations.
- Data security, access authorization, confidentiality, and processing based on the "need-to-know" principle.
GDPR Principles and International Transfer Information
Since Erasmus+ mobility and project applications are international in nature, personal data may be transferred to authorized institutions, organizations, and systems located domestically or abroad within the scope of relevant legislation and program rules.
Transparency
Data subjects should be informed about the purposes, scope, and parties involved in processing their data.
Limitation of Purpose
Personal data should be processed only for specific, explicit, and legitimate purposes.
Data Minimization
It is essential that personal data not required for the process is not requested or processed.
Storage Time
Personal data should be stored for a period limited to the purpose of processing and the periods stipulated in the legislation.
Privacy and Security
Personal data must be protected against unauthorized access, loss, alteration, or unlawful processing.
Data Subject Rights
Individuals concerned may have the right to access, correct, delete, object, restrict, and apply under applicable legislation.
Storage and Destruction of Personal Data
Personal data is stored in accordance with relevant legislation, Erasmus+ program rules, grant agreements, audit obligations, reporting requirements, archiving regulations, and institutional retention and destruction policies.
SCU GDPR Storage and Destruction Policy
Our university's institutional policy regarding the storage, deletion, destruction, and anonymization of personal data can be accessed via the following link.
View Storage and Disposal PolicyRights under the Turkish Personal Data Protection Law (KVKK) and European Union Data Protection Legislation
Data subjects may have the following rights under Article 11 of the Law No. 6698 on the Protection of Personal Data and, where applicable, European Union data protection legislation.
Exercise of Rights and Application Authorities
Requests regarding your personal data should be directed to the relevant data controller, according to the system and process by which the data is processed.
Sivas Cumhuriyet University Processes
Applications related to our university's website, cookies, support system, document submission, corporate correspondence, electronic document management system (EBYS), office records, and archiving processes are evaluated within the framework of Sivas Cumhuriyet University's Personal Data Protection Law (KVKK) processes and corporate application procedures.
European Commission and Beneficiary Module Processes
Applications concerning personal data processing activities carried out within the scope of the Beneficiary Module, EU Login, Erasmus+ and European Solidarity Corps platforms and the European Commission's digital systems may be evaluated through the data controller, Data Protection Officer and European Data Protection Supervisor application channels specified in the relevant privacy statements of the European Commission.
TurnaPortal and Turkish National Agency Processes
TurnaPortal processes applications, evaluations, results, reporting, and procedures related to Erasmus+ applications and the Turkish National Agency systems. These applications are evaluated by the Turkish Ministry of Foreign Affairs, the Presidency of European Union Affairs, the Presidency of the European Union Education and Youth Programs Center, and according to the procedures determined by the relevant institution.
Partner Institution and Host Organization Processes
For processes carried out by partner institutions, host universities, internship organizations, consortium partners, or third-party systems within the scope of mobility, the relevant institution's own data protection policies and application mechanisms may apply.
Declaration of Explicit Consent, Accuracy, and Timeliness
In cases requiring explicit consent, personal data may be processed only for the stated purposes and after the data subject has been adequately informed.
Explicit Consent and Information Texts
You can access the Sivas Cumhuriyet University information texts, explicit consent forms, and data subject application forms related to the Erasmus+ program processes below.
Information Texts
Information and Explicit Consent Texts
Erasmus+ Program Information Texts
Erasmus+ Programme Explicit Consent Texts
Data Subject Application
All GDPR Texts
All personal data protection documents, information notices, explicit consent documents, and application forms published by Sivas Cumhuriyet University can be accessed from the university's official GDPR page.



