There is no single fixed retention period. In Turkey’s healthcare tourism sector, the passport, identity, and travel information you provide to a clinic may be kept for different periods depending on whether it is used only for treatment planning, official notifications, financial records, or the management of potential legal proceedings. When determining how long to retain the data, the clinic, healthcare tourism intermediary, or another jointly operating company should consider the applicable legislation, the purpose of processing, and its own retention policies.

For this reason, it would not be accurate to give you a specific number of years or months without reviewing the relevant documents. The most reliable approach is to ask in writing why your data is being processed, how the retention period is determined, and what action will be taken when that period ends.

Factors determining how long passport information is retained

Passport numbers, identity numbers, dates of birth, nationality, entry and exit details, and contact information are generally considered personal data. When assessed together with treatment information, they become more closely connected to healthcare services and may form a more sensitive data set.

For a clinic to retain this information, it is generally expected to process the data for a specific and legitimate purpose. For example, identity verification during an initial application, matching a treatment file to the correct person, coordinating accommodation or transportation, official reporting, billing, and managing medical records may be separate purposes. Each purpose may not require the same retention period.

  • Treatment and medical records: Examination, procedure, consent, and follow-up records may need to be linked to the correct person. Retaining these records does not automatically require keeping a passport copy indefinitely.
  • Identity verification and security: An organization may process certain identity details to verify that services are provided to the correct person or to reduce the risk of fraud.
  • Financial and accounting records: Documents related to payments, invoices, or contracts may be retained after treatment is completed because of relevant financial obligations.
  • Official notifications and healthcare tourism procedures: Depending on the nature of the healthcare service and the organization’s role, certain information may be shared with authorized institutions or retained for reporting purposes.
  • Disputes and legal claims: If there is a complaint, payment dispute, or claim relating to the medical process, data may be retained for longer when reasonably necessary to defend a position or pursue a legal right.

Because these categories may apply independently, no general conclusion can be drawn that “all data is deleted immediately when treatment ends” or that “passport information is always kept for years.”

What information should you request under the Turkish Data Protection Law?

In Turkey, the Personal Data Protection Law (KVKK) and related secondary regulations are important when personal data is processed. The KVKK does not provide a single retention schedule applicable to every type of data and every organization. Instead, it establishes a framework requiring factors such as the purpose of processing, the legal basis, necessity, and proportionality to be assessed together.

The privacy notice provided to you should generally explain who the data controller is, which data is processed, the purposes of processing, the parties to whom the data may be transferred, and the method of collection. If the retention period or how it is determined is not clearly stated, you may ask about this separately.

A service provider’s statement that “you gave consent, so we can keep it for as long as we want” is not, by itself, an adequate explanation. Explicit consent may be one of the legal bases used in certain data-processing situations, but it does not grant unlimited authority to retain data for every purpose. Data is expected to be retained only as long as it is connected to, necessary for, and proportionate to the purpose.

Checklist of questions to ask the clinic in writing

Asking the following questions by email or through the organization’s official communication channel, either during your initial application or after treatment, will create a more reliable record than relying on verbal explanations:

  • For which specific purposes are my passport or identity details being processed?
  • Who is the data controller for my information? If the clinic and intermediary company are separate organizations, what is each party’s role?
  • Is a complete copy of my passport really necessary, or is recording only certain details sufficient?
  • What is the separate retention period or retention criterion for my passport image, identity number, and travel details?
  • Which companies, healthcare organizations, accommodation providers, or transportation providers may receive my data?
  • Will my data be sent to a system, cloud service, or group company outside Turkey?
  • When the retention period ends, how will my data be deleted, destroyed, or anonymized?
  • After the processing purpose ends, can I request that the passport copy be deleted or access to it be restricted?
  • Which notification channel should be used in the event of a privacy breach or if information is sent to the wrong person?

Obtaining answers to these questions before treatment begins can make it easier to determine which organization is responsible later. If you are asked to send an identity document through a messaging application, also request information about the channel’s security, access permissions, and who will be able to view the file.

Requesting deletion of your data or restriction of access

Although application rights under the KVKK vary depending on the circumstances, you may be able to request information about the personal data being processed, ask for the data to be corrected, and, where the conditions are met, request its deletion, destruction, or anonymization. Having the right to apply does not mean that every request will automatically be accepted.

If the organization is required to retain the data because of a legal obligation, an ongoing medical-record requirement, or the protection of a legal right, a deletion request may be rejected in whole or in part. In such cases, you may ask the organization to explain in writing which data will continue to be retained and why, as well as with whom access to it will be limited.

When submitting your request, clearly state which documents you shared and when, where you believe they are stored, and the scope of your request. The organization may have its own official application procedure. This procedure and the current contact details should be confirmed directly from the data controller’s privacy notice or official channels.

International data transfers and third parties

If you live abroad, it is important to ask separately whether your data will be transferred from the clinic in Turkey to another country. The clinic, intermediary organization, call center, cloud storage provider, or insurance company may be located in different countries. In that case, you should be informed of the purpose of the transfer, which data will be sent, and the legal framework used for the transfer.

Keeping passport scans and medical reports in the same email thread or shared online folder may increase the risk of giving access to more people than necessary. You may request that recipients who do not need the information for treatment be excluded from data sharing and that access be limited according to job responsibilities.

Passport copy risks to consider

A passport copy does more than confirm your name; it may also contain a document number, date of birth, nationality, and visual identity details. Therefore, do not accept general statements involving indefinite retention or unrestricted sharing before understanding why the document is required.

Before sending the document, read the privacy notice, privacy policy, and any applicable service agreement. If the retention period is unclear, do not rely on a verbal statement such as “for the duration of treatment”; obtain written confirmation of the criterion used to determine the period and which data will be retained after the process is completed.

The information on this page is provided for general informational purposes and does not constitute legal advice. If you are dealing with a specific deletion request, data breach, or cross-border transfer issue, review current official sources and, if necessary, seek advice from an independent professional experienced in Turkish personal data law.

Related questions

  • For what purposes and with whom may my health information be shared in Turkey?
  • Can I request the deletion of the medical reports I sent to the clinic?
  • How can I determine whether a healthcare tourism intermediary is a data controller or a data processor?