Help Centre

Protect exported applicant and donor data in your institution’s secure environment

Excel, CSV, PDF, document, screenshot and similar files downloaded from the panel remain personal data. Use these copies only for the necessary purpose, through authorised people and in accordance with your institution’s obligations under Türkiye’s Personal Data Protection Law (KVKK).

Purpose limitationAuthorised accessSecure disposal
Core principle

Exporting data does not end data protection responsibilities

Downloading applicant or donor data does not remove its status as personal data. Your institution must manage who uses the copy, for which purpose, where it is stored and how long it is retained under its own data protection procedures.

  • Export only the data genuinely needed for the scholarship, donation or institutional process.
  • Limit the file to authorised people whose duties require access.
  • Do not use the data for a purpose unrelated to the export.
  • Do not create personal archives or keep files on personal devices or accounts.
  • Apply your institution’s retention and disposal policy when the work is complete.

The platform record and the downloaded copy are separate

Updating or deleting a record on bursverenler.org does not automatically delete copies previously downloaded by your institution. Your institution must separately track and manage every copy held in its own systems.

Data types

Which files may contain personal data?

The content, not the file name or format, determines whether it contains personal data. Information linked to an identifiable person may include:

  • Applicant identity, contact, education, family, income and application information
  • Proof of enrolment, transcripts, civil records, income documents and other application documents
  • Interview notes, assessment scores and scholarship decisions
  • A donor’s name, contact details, donation amount and date, supported organisation or programme, and preferences
  • Lists, reports, screenshots or correspondence that make a person identifiable

Card details are not exported

Card numbers, expiry dates and security codes are not stored on bursverenler.org or included in institution reports. Institutions should not request this information from donors.

Step by step

What should you do before and after exporting data?

1

Confirm the need and authority

Identify why the report is needed. If working in the panel is sufficient, do not create an unnecessary copy.

2

Minimise the data

Select only the necessary date range, records and fields. Do not include full documents or detailed identity data unless required.

3

Use a protected institutional environment

Create the file on a secured institutional device and move it to access-controlled and, where possible, encrypted storage approved by your institution.

4

Restrict and monitor access

Limit access to named institutional accounts. Do not use shared accounts, shared passwords or public links.

5

Manage copies after use

Delete, destroy or anonymise temporary downloads, email attachments, desktop copies and backups under your institution’s retention and disposal policy.

Storage and access

Use institution-approved systems instead of personal accounts

  • Do not store files in personal email, personal cloud storage, messaging apps or personal USB drives.
  • Do not upload personal data to unauthorised third-party storage, file-conversion, artificial-intelligence or analytics services.
  • Use screen locks, updated software, malware protection and, where possible, multi-factor authentication on institutional devices.
  • Remove access promptly when duties change or a user leaves the institution.
  • Keep printed lists secured and destroy them safely when no longer required.
  • Use masked or sample data instead of real personal data when requesting technical support.
Sharing limits

Share data only where lawful, necessary and proportionate

Lawfully obtaining data does not automatically permit unrestricted transfer. The purpose, legal basis, recipient and data scope must be assessed separately for every transfer.

  • Do not share applicant lists, documents or assessment notes through unauthorised people or channels.
  • Do not open the full applicant pool or application documents to donors. Where a specific selection process applies, use only approved and limited information necessary for that process.
  • Do not turn donor contact details into a promotional or marketing list without an appropriate separate legal basis.
  • Respect donor privacy and communication preferences.
  • Before sharing with a service provider, adviser or another institution, have your authorised data protection function assess the legal basis, contract, security and any international-transfer requirements.
  • Prefer aggregated or anonymised data for statistics and presentations.
Retention and disposal

Do not retain data indefinitely

Keep exported files only for as long as required by the relevant purpose, legal obligations and your institution’s retention and disposal policy. When the purpose and valid retention grounds end, delete, destroy or anonymise the data.

  • Consider the main folder, email, downloads folder, portable media and backups together.
  • Renaming a file or moving it to the recycle bin is not necessarily secure disposal.
  • Use the method and authorised unit defined by your institution.
  • Where required, retain an internal record of what was disposed of, why and when.

There is no single fixed retention period

The appropriate period may differ according to the institution, transaction, contract and applicable law. Determine it through your institution’s data inventory and retention-disposal policy.

Suspected data breach

Report incorrect disclosure, loss or unauthorised access immediately

Sending a file to the wrong person, losing a device or USB drive, exposing a public link, suspicious account access, malware or losing a printed list may create a personal-data breach risk.

  1. Stop the disclosure or access where possible, but do not alter logs or evidence.
  2. Report the incident immediately to your institution’s data protection, information-security, legal or authorised management function.
  3. Record the file contents, affected group, date, recipients and initial measures taken.
  4. Do not rely only on asking the unintended recipient to delete the file; still report the incident internally.
  5. The authorised institutional unit assesses notifications to affected people, bursverenler.org and the Personal Data Protection Board.

The 72-hour period applies to the data controller’s notification

Where personal data has been unlawfully obtained by others, the data controller must notify the Board without delay and no later than 72 hours after learning of the breach. Staff and institution users must therefore report an incident internally without waiting.

Frequently asked questions

What to know about exported data

May I send the Excel file to my personal email?

No. Use only the devices, accounts and secure sharing methods approved by your institution.

May a donor see information about every applicant?

No. Some scholarship types may allow a donor to choose among pre-assessed applicants, but only approved and limited information necessary for that process may be shared. The full applicant pool and documents are not open to donors.

May we use the donor list for a newsletter or promotion?

A donation alone does not authorise every type of promotional communication. The purpose, legal basis and donor preferences must be assessed separately.

May I upload the file to an AI tool?

Do not upload personal data to external AI, file-conversion or analytics services unless expressly approved by your institution. Prefer anonymised data and institution-approved tools.

How long should files be retained?

There is no single period for every institution. Follow the relevant purpose, legal obligations and your institution’s retention-disposal policy.

What should I do if I send a file to the wrong person?

Recall the message or close access where possible and immediately report the incident to your authorised data protection or information-security unit. Asking the recipient to delete the file is not sufficient on its own.

Official resources

Apply your procedures together with current KVKK guidance

This help page provides general information and does not replace your institution’s legal assessment, data inventory, policies or incident-response procedure.