ACADEMIC DATA MANAGEMENT SYSTEM POLICY
1. Purpose
The purpose of this Policy is to determine the institutional principles that regulate the entire life cycle of academic data produced, collected, processed, transferred, stored, analyzed, reported and archived at the Turkish-Japanese Science and Technology University. The policy aims to establish and sustainably operate an integrated Academic Data Management System that will ensure that the University's academic decisions are based on accurate, up-to-date, reliable, comparable and, when necessary, verifiable data.
Academic Data Management System is not considered just a software application where data is stored electronically. System; It is a corporate governance model that covers the rules, authorities, business processes, technical infrastructure and responsibilities regarding the identification, production, verification, protection, sharing, reporting and use of academic data.
The main purpose of the system is to create a single and reliable source of institutional information about the University's education, research, internationalization, quality assurance, human resource planning and social contribution activities. Thus, it is aimed to reduce duplicate or contradictory records kept in different units, to accelerate academic decision processes, to make accurate national and international reporting, and to preserve the institutional memory of the University.
Taking into consideration TJU's distinctive establishment model between Türkiye and Japan, the system will be ensured to produce reliable data on academic mobility, joint assignments, joint courses, research projects, thesis consultancies and institutional partnerships between the two countries. In addition, compliance with the legislation of the Republic of Türkiye, security and confidentiality of personal and corporate data will be protected at every stage.
2. Scope
This Policy; It covers all academic and administrative units of the university, faculties, institutes, colleges, departments, programs, research centers, laboratories, project units, technology transfer structures, international relations units and other organizations related to academic activities.
The scope of the policy includes academic data held about faculty members, researchers, students, graduates, guest lecturers, jointly appointed academics, postdoctoral researchers, project personnel and administrative personnel who produce or use data related to academic processes.
System; It works integratedly with the student information system, academic personnel system, research and project management system, learning management system, electronic document management system, library system, ethics committee system, international mobility system, graduate system, quality management system and financial management systems in terms of academic processes.
Cloud services, software applications, laboratory platforms, survey systems and research data repositories operated by third parties on behalf of the University are also subject to the relevant provisions of this Policy. Procuring services from outside the university does not eliminate institutional responsibility for academic data.
3. Legal and Institutional Basis
This Policy; It is implemented within the framework of the Constitution of the Republic of Türkiye, the Higher Education Law no. 2547, the Law on the Establishment of the Turkish–Japanese Science and Technology University no. 7034, the Personal Data Protection Law no. 6698, relevant archive legislation, electronic document and signature regulations, intellectual and industrial property legislation, regulations of the Council of Higher Education and other policies and directives of the University.
All personal data processing activities carried out on the system are based on the principles of compliance with the law and the rules of honesty, being accurate and up-to-date, being processed for specific, clear and legitimate purposes, being related to the purpose for which they are processed, being limited and proportionate, and being kept for the period foreseen in the relevant legislation or required for the purpose for which they are processed.
This Policy does not replace relevant legislation. If there is a difference between policy provisions and laws, international agreements or other binding regulations, higher legal norms apply. The university uses the application area left to it by the legislation in line with the principles of data security, academic freedom, research integrity and institutional accountability.
4. Main Goals of Academic Data Management
The first goal of the Academic Data Management System is to manage the academic data produced within the University through a singular, reliable and consistent institutional source. Conflicting records about the same student, academician, program, course, publication or project in different systems will be prevented.
The system will support academic decisions to be based on verified data rather than personal opinions or incomplete information. Decisions such as determining student quotas, academic staff planning, opening new programs, research investments, laboratory capacity and internationalization targets will be made using the current data in the system.
Accurate and timely transfer of academic data to national and international systems will be ensured. The data sent to YÖKSİS, YÖK Academic, YÖK Atlas, Higher Education Information Management System and other necessary public systems will be compatible with the approved records in the University's internal systems.
The system will also have the capacity to produce the necessary indicators for the University's quality assurance, accreditation, strategic planning, performance program, activity report, institutional evaluation and international ranking processes.
5. Basic Principles
In academic data management, the principles of accuracy, integrity, timeliness, reliability, security, transparency, accountability, accessibility, data minimization and purposeful limitation are applied. All data is collected and used solely for a defined academic or administrative purpose.
If a data will be used for different purposes, the legal basis of this use, institutional necessity and the rights of the relevant persons are also evaluated. The presence of data in the system does not mean that the data can be used unlimitedly by all users within the University.
Academic data is taken from the source where the data was first produced whenever possible. It is essential to share secure data from an authorized source rather than requesting the same information repeatedly from different units.
The use of statistical data that is free from personal data, anonymized or aggregated is prioritized in planning and reporting processes. If information that directly identifies the person is not required for the decision, identification information is not used.
6. Definitions
Academic data; It refers to all kinds of structured or unstructured information produced within the scope of education, training, research, publication, project, academic staff, student, program, course, quality, mobility, graduate and social contribution processes.
Personal data is any information regarding an identified or identifiable natural person. Background information of academic staff, registration and success information of students, contact information, identity information, assignments and system usage records can be evaluated within this scope.
Special personal data; It refers to health, biometric, genetic and similar data categories that are subject to special protection in the relevant legislation. This data is only processed if there is a clear legal requirement and appropriate security measures.
Research data; It refers to the data produced or used by observation, experiment, measurement, survey, interview, simulation, imaging, calculation or other methods in a scientific research process. Metadata; information explaining the meaning, source, production date, format, responsible unit, access conditions and other features of a data.
Master data; These are basic institutional records used by multiple systems throughout the University, such as students, academic staff, academic units, programs, courses, projects and publications.
Reference data; It refers to country codes, academic titles, program types, course levels, scientific fields, publication types and similar standard classifications. Data controller is the legal person who determines the purposes and means of processing personal data; Data processor refers to the party that processes personal data on behalf of the data controller, based on the authority given by the data controller.
A data manager or data steward is the corporate officer responsible for the definition, quality, validation and currency processes of a specific data field. This duty is different from the concept of data controller in personal data protection legislation. Data controller unit refers to the academic or administrative unit that first produces, verifies or converts a particular academic data into an official record.
7. Academic Data Categories
Academic data in the system is basically classified in the categories of student, education program, academic staff, research, project, publication, internationalization, quality, graduate, intellectual property and social contribution.
Student data; It includes application, registration, student status, program, course registration, grades, academic progress, internship, mobility, thesis, graduation and graduate information. Sensitive student data, such as health or special support needs, is separated from general academic records and managed with more limited access.
Program and course data; It includes academic unit structure, program name, qualification level, language of instruction, course plan, course outcomes, credits, instructor, classroom, laboratory, measurement and evaluation methods and accreditation information.
Academic staff data; It includes title, staff, field of expertise, educational background, course load, consultancy, research, publication, project, patent, assignment, administrative duty, award and academic performance information.
Research and project data; includes project proposals, budgets, teams, ethical clearances, funding sources, contracts, research data, publications, patents, prototypes, technology transfer and social impact outputs.
Internationalization data; It covers student and staff mobility, joint programs, international protocols, joint courses, joint research, contributions of Japanese academics and international project information.
8. Data Classification System
Academic data is classified according to the level of security and access as “public”, “in-house”, “confidential” and “highly sensitive”. The data class is determined by taking into account the content of the data, its legal nature, the risk that may occur in case of disclosure, and the purpose of academic use.
Publicly available data; It includes information deemed appropriate to be published on the university's website, activity reports, academic catalogs or open science platforms. Program names, publicly available academic staff profiles, published research outputs and aggregated statistics may be included in this group.
Internal data is information that is used in the daily academic and administrative functioning of the University but is not publicly available. Curriculum drafts, internal performance reports and unit study data can be evaluated in this context.
Confidential data is data whose unauthorized disclosure could harm the rights of individuals, the functioning of the University or contractual obligations. Individual student grades, evaluation files, unpublished project results and personnel files may fall into this class.
Highly sensitive data includes sensitive personal data, authentication information, critical research data, security vulnerabilities, strategic technology information and other records whose disclosure could cause serious harm. Access to this data is subject to specific authorization, strong authentication and detailed record keeping mechanisms.
9. Academic Data Governance Structure
An Academic Data Governance Board is established for the institutional coordination of the Academic Data Management System. The Board is chaired by a vice-rector appointed by the Rectorate; It consists of representatives responsible for academic units, IT, student affairs, personnel, research, quality, international relations, law, personal data protection and archive services.
The Board prepares institutional decisions regarding the definition, classification, quality standards, system integrations, access authorizations and reporting principles of academic data. The Board does not directly undertake the day-to-day operation of technical systems; It serves as the governance body that determines the rules and responsibilities for data management.
Board decisions must be in compliance with the relevant legislation and the decisions of the authorized bodies of the University. Academic policy or matters requiring Senate decision are submitted to the Senate; Issues requiring financial, administrative or technical resources are submitted to the authorized management bodies.
Every year, the Academic Data Governance Board evaluates the system's data quality, security, user satisfaction, integration, reporting and regulatory compliance performance and submits a report to the Rectorate.
10. Academic Data Management Coordination Unit
Academic Data Management Coordination Unit can be established for daily coordination of the system. The unit is responsible for standardizing academic data, managing the data dictionary, monitoring inter-system integrations, and providing technical and managerial support to the units.
The Coordination Unit does not have academic decision-making authority. The unit cannot substitute academic data for the relevant source units; It detects errors and inconsistencies and sends correction requests to authorized units.
The unit checks the compatibility of the data to be sent to YÖKSİS and other national systems with the relevant source systems. Validation rules are run before data transfer and incorrect records are prevented from being sent.
The Coordination Unit provides regular training to academic and administrative staff on data quality, data entry, reporting, protection of personal data and system security.
11. Data Area Controllers and Data Managers
A data controller and data manager are determined for each core data field. The source of student registration and graduation information is the Student Affairs unit; Source of academic staff and assignment information: Personnel unit; The source of program and curriculum data is the relevant academic boards; The source of project data may be research and project units.
Data managers manage the definitions of the data field they are responsible for, data entry rules, mandatory fields, quality criteria and update processes. Data managers do not have unlimited access to all records in the system; Their access is limited to their field of duty.
When it is necessary to make changes to the data, it is recorded who made the transaction, on what date, for what reason and at what previous value. In particular, data with official results such as diplomas, grades, appointments, assignments and project budgets cannot be changed without an authorized decision or document.
12. Single and Reliable Data Source Principle
An "official registration system" is determined for each academic data field. Although copies of the same information may be found in other systems, it is clearly defined which record will be taken as basis.
The student's official grade is an approved record in the student information system; Approved record of academic staff's staff information in the personnel system; The official name of the program is academic unit registration based on the decision of the authorized board and national system records.
Analytical reporting systems may include copies of source data; However, these systems cannot be used as transaction systems that change the official record. An error detected in the data warehouse is corrected in the actual source system rather than being corrected directly on the analytical data.
13. Academic Data Dictionary and Metadata Management
A central Academic Data Dictionary is created to ensure a common understanding of academic concepts used throughout the university. For each data item, its name, definition, format, data type, source, responsible unit, update frequency, security class and intended use are determined.
Definitions of “international student”, “active student”, “joint publication”, “Japanese joint project”, “graduation rate”, “faculty member per student” and similar indicators are clearly included in the system. This prevents different units from using different calculation methods for the same concept.
Metadata records are kept to show which source the data comes from, what transformations it has undergone and in which reports it is used. This process is managed as data lineage or data lineage.
14. Master Data and Reference Data Management
Unique identifiers are used for academic units, programs, courses, individuals, projects, publications, and institutions. Automatic controls are implemented to prevent duplicate records for the same person or academic unit.
The Republic of Türkiye identification number or passport number is not used as a general technical key between systems. To the extent possible, singular and meaningless corporate identification numbers created by the University are used.
The use of persistent researcher identifiers such as ORCID is supported for international visibility of researchers and matching of publication information. Appropriate persistent object identifiers can be used in publications, datasets, and project deliverables.
Reference lists such as country, language, field of science, publication type and academic title are managed centrally. Units cannot create different codes or spellings for the same concept.
15. Multilingual Data Structure
Due to TJU's Türkiye-Japan joint structure, the system will support Turkish and English data; It will allow records to be kept in Japanese in areas where they are needed. The official Turkish and English equivalents of academic unit, program, course and research center names are managed centrally.
The original spelling of Japanese personal and institutional names, their transposition into the Latin alphabet, and their use in English can be kept in separate areas. Duplicate records resulting from different spellings for the same person or institution are prevented.
Official Turkish registration is taken as basis for legislation and administrative procedures in Türkiye. English and Japanese equivalents are used in international communication, joint education and research.
16. Data Generation and Entry Processes
Academic data is entered into the system as soon as possible and directly by the authorized user as soon as the transaction takes place. Post-entry of data in bulk form and from uncertain sources is limited.
Mandatory field, format, date, code and relationship checks are applied on data entry screens. For example, if the credit information for a course, the language of instruction, or the program it is affiliated with is left incomplete, the system may not allow the registration to be completed.
Critical academic data may be subject to a two-stage control or approval process. Records such as course grades, program changes, graduation decisions, academic appointments, project budgets and international assignments are not finalized until they are approved by a second authorized user. In bulk data uploads, file source, uploader user, upload time, operation result and error records are stored. Failed or partially completed uploads are clearly reported by the system.
17. Data Quality Management
Academic data quality; It is evaluated on the dimensions of accuracy, completeness, consistency, timeliness, uniqueness, validity and timely accessibility.
Accuracy means that the data is compatible with its actual state and the underlying document; Completeness means that the required fields are complete; Consistency means that records in different systems do not contradict each other.
Data quality checks are carried out by automatic and manual methods. The system can automatically flag inconsistencies such as continuing active student status after the graduation date, academic title and staff information not matching, or continuing expenditure records after the project end date.
Quality targets and error thresholds are determined for each data field. Critical errors are corrected without delay, and other errors are corrected within the specified correction schedule.
Data quality issues are examined for business processes, system design, lack of training, and integration issues before being considered a personal fault of users. Root cause analysis is performed for recurring errors.
18. Data Verification and Correction Process
When incorrect or incomplete academic data is detected, the data source and authorized unit are determined and the official correction process is initiated. Corrections are made on the basis of the underlying document or authorized decision.
A user is not allowed to directly change the official data of another unit. The user creates an error report or correction request; The correction is evaluated by the authorized data administrator.
In critical data, the old value, new value, transaction date, user who performed and approved the transaction, and the correction reason are stored in unchangeable transaction records. Individuals' rights to claim that there are errors in the academic data held about them and to request correction within the framework of the legislation are protected.
19. System Architecture
Academic Data Management System is built on a modular, secure, scalable and inter-system interoperable architecture. The system provides secure integration of expert systems rather than forcibly combining all academic processes within a single software.
The architecture may include transaction systems, integration layer, master data management, academic data warehouse, reporting and dashboards, research data warehouse, corporate archive and user access layers.
Data transfer between systems is carried out as much as possible through defined and documented application programming interfaces. Sending tables kept on personal computers via e-mail is not used as a permanent data integration method. In data integrations, the transferred fields, transfer purpose, frequency, source system, target system, security method and error management process are recorded.
20. Identity Management and Single Sign-On
Access to the system is done through the University's central identity management infrastructure. Each user is given a personal and unique account. The use of joint user accounts is prohibited except in cases where it is technically necessary and specifically approved.
Academic staff, student, administrative staff, guest researcher and external stakeholder accounts are managed with different user profiles. When the user's relationship with the University ends or his/her role changes, access authorizations are updated without delay.
Multi-factor authentication is implemented in critical systems. Password policies, session durations, failed login checks and account locking processes are determined in accordance with information security standards.
21. Access Authorization
Access to academic data is based on the principles of least authority and dutiful knowledge. A user is not allowed to access data that is not necessary for their role. Authorizations are defined on a role-based basis. The instructor only provides the necessary data regarding the courses he teaches and the students he advises; The department head can access their department's management data; Central units, on the other hand, access corporate data appropriate to their areas of duty.
Additional approval, strong authentication and detailed transaction logging apply for access to sensitive or highly sensitive data. System administrators' technical access is not unlimited, and transactions are recorded in an auditable manner.
Authorizations given due to temporary duty, commission membership or project work are defined as temporary. At the end of the period, access automatically ends.
22. Review of User Authorizations
System access authorizations are reviewed regularly. Unit administrators and data administrators control the alignment of tasks and access levels of users in their domain.
In cases of change of position, change of academic unit, leave, assignment, retirement, graduation or departure from the University, access is updated with automatic or controlled workflows. Accounts that are not used for a long time will be suspended. Before closing the accounts of departed personnel, corporate data and documents are transferred to the appropriate unit.
23. Transaction Records and Audit Trails
Data viewing, adding, changing, deleting, exporting and authorization operations performed in the system are recorded in accordance with the risk level.
Transaction records may include user, date, time, transaction type, affected data, source device or connection information, and transaction result. The content of the records is determined by taking into account personal data protection and security principles.
Audit logs can be used to detect unauthorized access, data modification, bulk data downloading and unusual user behavior. Records are not used for general and continuous surveillance of employees. Technical measures are taken to prevent unauthorized modification or deletion of critical records.
24. Protection of Personal Data
The University acts as a data controller within the framework of the relevant legislation in terms of activities in which it determines the purposes and means of processing personal data. The duties and security obligations of service providers who process data on behalf of the university are clearly regulated in the contracts.
Personal data cannot be processed except for specific and legitimate academic or administrative purposes. Uncertain and unlimited data cannot be collected with the thought that it may be useful in the future.
In cases where explicit consent is not a condition for legal processing, explicit consent is not requested from the person unnecessarily. In cases where explicit consent is relied upon, it is ensured that the consent is related to a specific subject, is based on information and is expressed with free will.
Appropriate information is provided to relevant persons regarding the purpose for which their personal data is processed, with which units or parties it may be shared, storage principles and rights.
25. Privacy-Focused Design
When creating a new academic system, module or data processing process, the protection of personal data is considered as an initial element of the design, not as a control to be added later.
By default, systems collect only the necessary data, show it to the necessary people, and retain it for the required period of time. When implementing new features, the effects of data minimization, access authorizations, international transfer, storage and deletion are evaluated in advance. Legal, technical and ethical risk assessments can be made for high-risk data processing activities. The system is not put into the production environment until risk mitigation measures are completed.
26. Special Personal Data
Health, disability, biometric and other special personal data are processed by separating them from general academic records. Only expressly authorized personnel have access to this data.
Transfer of sensitive data via e-mail, portable memory or unauthorized cloud environments is not allowed. If transfer is mandatory, secure and registered institutional methods are used. Additional encryption, access logging, user training, physical security and regular authorization checks are applied to the systems where this data is processed.
27. Data Sharing Between Türkiye and Japan
Academic data sharing with Japanese universities, research institutions or companies is evaluated separately, taking into account the purpose of sharing and the data category. Carrying out a joint course, student mobility, joint thesis consultancy or research project does not result in the automatic and unlimited disclosure of personal data to partners in Japan. Only data necessary for the relevant activity is shared.
When transferring personal data abroad, one of the legal transfer conditions stipulated in the current legislation must be met. When necessary, no transfer is made without using a standard contract, letter of undertaking or other relevant assurance mechanisms.
If the access granted to the partner abroad is in the form of direct system access, the scope of users, data, duration and processing are clearly limited. Accesses are recorded and removed when the collaboration ends. Where possible, anonymized, aggregated or pseudonymized data is used instead of personal data.
28. Research Data Management
For scientific research projects, it is encouraged to prepare a Data Management Plan appropriate to the nature of the research. A Data Management Plan may be required in projects deemed necessary by the university or external funder.
The Data Management Plan explains the types of data to be produced or used, data formats, storage space, backup, access rights, ethical and legal obligations, sharing, storage, destruction and the future of the data after research.
The project manager is responsible for the appropriate management of project data. In addition, the University provides secure storage, corporate data repository, technical support, training and consultancy infrastructure.
Research data cannot be kept in a single copy on personal computers, individual cloud accounts, or portable media. Critical research data must be stored in corporately managed and backed-up environments.
29. Ownership and Responsibility for Research Data
Legal and institutional status of research data; It is determined by taking into account funder conditions, project contract, intellectual property provisions, researcher contributions and relevant legislation.
The researcher's right to use the data for scientific purposes is balanced with the University's responsibility to protect research integrity, project obligations and institutional memory.
If the researcher leaves the University, appropriate transfer of research data related to ongoing projects and published results is made. Data is not allowed to become inaccessible on a single person's account or device.
30. Open Science and Open Data
TJU supports open access of scientific publications and appropriate research data. Research outputs are encouraged to be made available through institutional repositories, open data repositories, or field repositories.
The open data principle does not mean that all data should be made public unconditionally. Personal data, trade secrets, intellectual property, national security, contractual confidentiality, ethical limitations, and the rights of research participants are protected.
Data sets made available for open access include data description, method, file format, license, version, manufacturer, date and appropriate citation information. Sufficient metadata is provided for data reusability.
For research data that cannot be shared, the justification for access restriction and the data access request process can be defined.
31. Scientific Publications and Researcher Profiles
Publications, projects, patents, awards and other academic activities of academic staff are kept in central researcher profiles. System integrations are used instead of researchers repeatedly presenting the same information to different units.
Publication information can be matched with DOI, ORCID, international bibliographic databases and institutional verification processes. Automatically transferred publications are not converted into official performance records without verification by the researcher or authorized unit.
Deduplication controls are implemented to prevent the same post from being counted multiple times with different spellings. The status of publications that have been retracted, corrected or subject to ethical review is reflected in the records.
In academic performance evaluations, not only the numerical data in the system is used; The data are evaluated in terms of scientific field, publication quality and real academic contribution.
32. Project and Funding Data
A unique project record is created for all research projects. The project's name, coordinator, team, funding source, budget, start and end date, ethical permissions, reports and outputs are associated under the same project identity.
Project proposal, acceptance, contract, budget, expenditure, reporting and closing stages can be monitored through the system. Necessary integration is provided between academic and financial records.
Türkiye-Japan joint projects are further classified to show the contributions of Japanese researchers and institutions. However, statistical classification does not eliminate personal or contractual confidentiality rules.
33. Student Success and Learning Analytics
The system may use learning analytics tools to evaluate students' academic progress, course achievement, achievement of program outcomes, and support needs.
Learning analytics is not used to stigmatize, penalize students, or make academic decisions based solely on automated scores. Risk indicators are evaluated by faculty and advisors to provide early support to the student.
Decisions that have significant consequences on the student's success are not based solely on automatic system output. Authoritative academic evaluation and, where necessary, the student's explanation are taken into account. The methodology, data scope, limitations and possible errors of the analyzes produced from student data are explained to the relevant decision makers.
34. Use of Artificial Intelligence and Advanced Analytics
The use of artificial intelligence, machine learning and predictive analysis tools on academic data is subject to the principles of legality, transparency, accuracy, non-discrimination and human control.
If an artificial intelligence system produces recommendations on student success, academic performance, admissions, scholarships, assignments, or similar issues, the data sources and decision logic used should be explainable to the extent possible.
Regular impact and fairness assessments are conducted to prevent biases found in historical data from being reproduced through automated decision systems.
Confidential or personal academic data may not be uploaded to general-purpose external AI systems without the University's approval and appropriate contractual assurance.
35. Reporting and Dashboards
Academic Data Management System produces authorized reports and dashboards for different management levels. Users at the rectorate, faculty, department, program, research center and project level only access reports related to their field of duty.
The definition, data source, calculation method, update date and responsible unit of each indicator used in the indicator panels must be visible. Decision makers are informed about the data quality status of the reports to avoid reaching misleading conclusions based on outdated or incomplete data.
Management reports use aggregated data whenever possible instead of personal details. In reporting small groups, the risk of indirectly identifying individuals is evaluated.
36. Strategic Planning and Quality Assurance
The system regularly produces the performance indicators required for the University's strategic plan and quality assurance system.
Student satisfaction, graduation rate, employment, international mobility, research funds, publication impact, patent, joint project and social contribution indicators are calculated from verified data sources.
The performance of academic units is not evaluated only with quantitative data. Numerical indicators are considered together with qualitative evaluations, peer opinions, external evaluation results and the development stage of the unit.
37. Integration with National Systems
The data to be transferred to YÖKSİS and other national higher education systems are taken from specified source systems. If manual data entry is mandatory, the second control mechanism is applied.
Regular reconciliation is made between the data sent to the national system and the University's internal records. When a difference is detected, which record is correct is determined based on the underlying documents.
The equivalents of academic unit, program and personnel codes in national systems are kept in the Academic Data Dictionary. Code changes are prevented from corrupting historical data.
Access rights to national systems are granted to individual users and in a limited manner. Users are not allowed to share passwords or use joint accounts.
38. International Systems and Ranking Data
Before data is sent to international ranking, accreditation and comparison bodies, data definitions, reporting period, scope and calculation method are examined. It is taken into account that different organizations may use different definitions for the same indicator. Before the university's internal indicator is transferred directly to the external system, definition compliance is checked.
Data sent to international organizations is verified by authorized academic and administrative units. False, incomplete or misleading data cannot be submitted in order to increase the visibility of the university. The source of the submitted data, calculation file, responsible persons and approval process are archived. This way, data comparison and verification can be done in subsequent years.
39. Data Sharing
Data sharing within the university is limited to mission and purpose. The fact that a unit needs a certain data does not give it the right to access the entire data set. In data requests, the requesting unit, purpose of data use, required fields, duration of use and sharing method are specified. Permanent and documented integration processes are created for regular data sharing.
When sharing personal data with external institutions, the legal basis, protocol, contract, disclosure obligation and security measures are evaluated. Even in statistical and aggregated data sharing, the risk of re-identification of individuals is taken into account.
40. Data Export and Portable Media
Bulk academic data export authorization is granted to a limited number of users. Export transactions are recorded and unusually large transactions may be subject to security review.
Transfer of personal or confidential data to USB memory sticks, external disks or personal devices is restricted as a rule. In cases of necessity, corporately managed encrypted environments are used. Sending data files via personal email accounts, messaging applications or unapproved file sharing platforms is not allowed.
41. Information Security
Technical and administrative measures appropriate to the risk level are taken to protect the confidentiality, integrity and accessibility of academic data. Data is protected by appropriate cryptographic methods during transmission and in the storage medium. Critical systems are subject to network segmentation, firewalls, anti-malware, vulnerability management and secure configuration controls.
System software and infrastructure components are updated regularly. Vulnerabilities are prioritized and remedied based on risk level. Information security is not considered solely the responsibility of the Information Technology Unit. All staff and students using the system are obliged to comply with the rules regarding the protection of user accounts, devices and data.
42. Backup and Business Continuity
Critical academic data is backed up regularly. Some of the backups are kept in secure environments independent of the main system. Whether backup operations are successful or not is automatically monitored. Having reserves is not considered sufficient; restore tests are performed regularly.
Business continuity plans are prepared for critical academic times such as student registration, exams, grades, graduation and project deadlines. Temporary processing methods to be used in system outages, processes for transferring data to the system later and preventing duplicate records are defined in advance.
43. Disaster Recovery
A disaster recovery plan is prepared to enable critical academic systems to restart in case of natural disaster, cyber attack, hardware failure, power outage or other extraordinary situations. Acceptable data loss and return-to-service targets are determined for critical systems. Goals are differentiated according to the academic importance of the system and the intensity of use. By utilizing the earthquake and disaster management experiences of Türkiye and Japan, the resilience of academic data against physical and digital disasters is strengthened.
44. Data Breach and Incident Management
Unauthorized access, data loss, sending to the wrong recipient, malware, account takeover or unlawful disclosure of data are considered information security incidents. Users report any security incidents they notice to the designated notification channel without delay. The person making the report should not try to solve the incident or delete the evidence on their own. The scope of the incident, affected data, persons involved, possible damages and measures to be taken are evaluated by the authorized incident response team. In cases of personal data breach, notifications to relevant institutions and individuals are made in accordance with the time periods and methods stipulated in the legislation. After each incident, a root cause analysis is performed and technical, administrative or educational measures are implemented to prevent recurrence.
45. Storage, Archiving and Destruction
Retention periods are determined for each category of academic data based on legal, academic, administrative and historical requirements. A single, unlimited retention period does not apply to all data. Documents of long-term or permanent value, such as diplomas, transcripts, board decisions, program and academic unit records, are protected in accordance with the relevant archive legislation and institutional storage plan. Personal data whose processing purpose and storage obligation have expired are deleted, destroyed or anonymized. Destruction operations are carried out by authorized persons, recorded and with irreversible methods. Deleting data from the active system or keeping it in archives or backup copies indefinitely in violation of the legislation should not have any consequences. The lifecycle of data in backups is also managed. Temporary storage measures may be applied for data that need to be protected due to legal dispute, audit, ethical review or research integrity investigation.
46. Electronic Documents and Official Records
Official academic decisions and documents are linked to the University's electronic records management system. An accessible link can be provided through the system to the decisions of the Senate, faculty, institute, department or board of directors, which are the basis for academic data recording. Transactions requiring secure electronic signature or corporate electronic approval are carried out through authorized systems. Email confirmation is not to be used as a substitute for a formal decision or signature. Version, signature, date, number and document integrity information of electronic documents are preserved. It is possible to verify whether a document has been modified subsequently.
47. Third Party and Cloud Services
Before purchasing a software or cloud service that processes academic data, issues such as security, protection of personal data, data placement, international transfer, service continuity, data portability and return of data when the contract ends are evaluated. The service provider is not allowed to use the data for its own purposes or evaluate it for advertising or profiling activities.
The contract regulates security measures, sub-service providers, breach notification, right to audit, data deletion, backups, intellectual property and transition support when the service ends. To prevent the university from becoming dependent on a service provider, data can be exported in common, documented and portable formats.
48. Software Development and Change Management
New developments or significant changes in academic systems are evaluated with the participation of the business unit, data manager, information security and, when necessary, the legal unit. Developments are not made directly on the live system. Test, acceptance and production environments are separated. Real personal data is not used as much as possible in test environments. Where real data is mandatory, masking, pseudonymization and limited access are applied. The impact of system changes on data definitions, reports, integrations and historical records is analyzed before deployment.
49. User Responsibilities
Users access the system only with the personal accounts given to them and cannot share their account information with other people. Users use academic data they access in the course of their duties only for authorized purposes. Data may not be viewed due to curiosity, personal relationship, academic dispute, or other unauthorized reason. Users are responsible for checking the timeliness, scope and confidentiality level of the reports they receive from the system. Data cannot be taken out of context and presented in a misleading manner. In case of change of position or departure, the personnel transfers their corporate documents, data sets and system records to the relevant unit.
50. Rights of Students and Academic Staff
Students and academic staff may request information regarding the processing of data held about them and may request correction of inaccurate records. This right does not grant unrestricted access to exam questions, jury evaluations, confidential referee opinions, third party data or information that must be kept confidential in accordance with the legislation. Applications are evaluated within the procedures and periods specified in the relevant legislation. The applicant is informed of the reason for the positive or negative decision.
51. Academic Freedom and Data Management
The Academic Data Management System cannot be used to control the scientific opinions or research agenda of academic staff. Academic performance data cannot be turned into a mechanism that directs faculty members to numerical targets only or evaluates different fields of science with a single criterion. Access controls to research data should not unduly hinder scientific collaboration; however, it must protect the rights of research participants, intellectual property, confidentiality, and project obligations. Analyzes made through the system do not replace the scientific and qualitative evaluation of the boards with academic appointment and promotion authority.
52. Ethical Use
Academic data cannot be used to produce misleading results about a person or unit, to damage reputation, to discriminate or to create an unauthorized profile. In statistical analyses, data selection, calculation method and excluded records are transparently documented. No selective or misleading manipulation can be done on the data to achieve the desired result. Altering, fabricating, concealing or deliberately misclassifying data within the scope of research or corporate reporting is considered an ethical violation.
53. Education and Data Culture
The success of the system depends not only on the technical infrastructure but also on creating a strong data culture throughout the University. Newly appointed academic and administrative staff are given orientation on academic data management, data quality, protection of personal data, information security and system use.
Advanced training is organized for data managers and critical system users. Training covers not only the use of system screens, but also why data must be kept accurate, up-to-date and secure. Instead of constantly penalizing user errors, understandable system design, guides, automatic controls and support mechanisms are developed.
54. Performance Indicators
Performance of the Academic Data Management System; It is evaluated on indicators such as data completeness rate, duplicate record rate, data correction time, compatibility with national systems, integration success, report generation time, system usability, number of security incidents and user satisfaction. Data quality indicators are not used to penalize units, but to identify problematic processes and development needs. Higher quality and timeliness targets can be set for critical data fields. Error tolerance is kept at the lowest level in areas that have legal or financial consequences, such as diplomas, transcripts, appointments and project budgets.
55. Audit
Academic Data Management System; It is regularly audited in terms of information security, protection of personal data, data quality, access rights, archiving and business continuity. Audits may take the form of internal audit, independent technical assessment, penetration testing, regulatory compliance review or data quality control. Audit findings are classified according to importance and risk level. For high-risk deficiencies, the responsible unit and completion date are determined. The audit process cannot be used as a means of unnecessarily monitoring or limiting the scientific activities of academic staff.
56. Implementation Stages
Academic Data Management System is established gradually. In the first stage, an inventory of existing systems, data sources, users, duplicate records, integrations and security risks is prepared. In the second stage, the data governance structure, responsible units, data managers, data dictionary, master data model and access roles are defined. In the third stage, priority integrations are established between students, staff, program, research and quality systems. Data reconciliation is achieved with YÖKSİS and other external systems. In the fourth stage, the data warehouse, dashboards, researcher profiles, research data repository and international reporting modules are put into operation. At each stage, user tests, data cleaning, training, information security and personal data protection checks are not completed before proceeding to the next stage.
57. Priority Modules
During the establishment period, priority may be given to the Academic Unit and Program Management Module, Academic Personnel Profile Module, Student and Alumni Analytical Module, Research and Project Management Module, Publication and Intellectual Property Module and Türkiye-Japan Academic Cooperation Module.
Academic Unit and Program Management Module manages faculty, institute, department, program, course, curriculum and academic board decisions in an integrated manner.
Academic Staff Profile Module; It combines education, expertise, courses, publications, projects, patents, assignments and international activity information in a single profile. Türkiye–Japan Academic Cooperation Module; Japanese academics produce institutional data on joint assignments, joint courses, thesis consultancies, projects, mobility and joint outcomes.
58. Responsibilities
The Rectorate is responsible for institutional ownership of the Academic Data Management System and providing the necessary resources. The Senate determines the basic principles regarding academic data definitions, academic reporting principles and processes that produce academic results. The Academic Data Governance Board coordinates data policies, standards, and institutional priorities. The Information Technology Unit is responsible for system infrastructure, integrations, access management, backup and technical security. Units responsible for legal and personal data protection processes provide consultancy and coordination regarding the compliance of data processing activities with the legislation. Academic and administrative units are responsible for the accuracy, up-to-dateness and timeliness of the data produced in their own resources and entering the system into the system on time. All users are responsible for protecting the confidentiality and security of the data they access.
59. Violation of Policy
Any behavior that violates this Policy, such as unauthorized access, data sharing, data modification, data hiding, bulk downloading, personal data breach or endangering system security will be examined. In the investigations, the nature of the act, its intent, its effect, the duty of the person concerned, the measures taken and the damage caused are taken into account. In necessary cases, access authorization may be temporarily suspended, security measures may be implemented and the matter may be forwarded to the relevant disciplinary, ethical, legal or judicial authorities. Individuals who report bugs in good faith or report vulnerabilities through corporate channels cannot be subject to retaliation.
60. Enforcement and Review
This policy comes into force on the date it is accepted by the University Senate. Technical standards, procedures, data dictionaries and job descriptions regarding the implementation of the policy are prepared by the relevant units. Policy; It is reviewed at least every three years, taking into account legislative changes, technological developments, information security risks, Türkiye-Japan cooperation needs and implementation results. In case of transfer of personal data abroad, artificial intelligence systems, open science, cyber security or significant changes in national higher education systems, the update will be made without waiting for a three-year period.
CONCLUSION
TJU Academic Data Management System should be designed not as an ordinary information system that digitizes the academic and administrative processes of the University, but as a strategic infrastructure that supports the reliability of institutional decisions, research quality, educational performance and international visibility.
The success of the system is not due to the collection of large amounts of data; It depends on the use of the right data, from the right source, at the right time, by people with the necessary authority and for a clear purpose. Data quality, information security, protection of personal data and academic freedom are not alternatives to each other, but complementary elements of effective academic data management.
TJU's joint structure between Türkiye and Japan creates significant opportunities for international data sharing and collaboration. However, these collaborations should be carried out on the basis of legal guarantees, data minimization, secure access and clear liability regulations.
Academic Data Management System to be established within this framework; It will preserve the institutional memory of the university, produce data compatible with YÖKSİS and other national systems, support research and quality processes, and contribute to the development of TJU as a reliable, transparent and data-based research university on an international scale.