VERBIS Registration for Foreign Companies
VERBIS — the Data Controllers' Registry Information System — is a public registry maintained by Turkey's Personal Data Protection Authority. Obligated controllers declare what personal data they process, why, with whom they share it and how long they keep it.
There is no GDPR equivalent, which is why international teams frequently overlook it.
Note: General information, not legal advice. Registration criteria and procedures are set out in Board decisions and can be updated; verify current requirements before acting.
Is it public?
Yes. Anyone can search the registry and see a controller's declaration. Two practical consequences:
- Your declaration and your published privacy notice must tell the same story
- Competitors, customers and journalists can read it
Who has to register?
Obligation is assessed on criteria including annual employee numbers, annual balance sheet totals and main field of activity, with specific treatment for controllers whose core business involves special category data and for controllers established abroad.
Key point for international companies: being established outside Turkey does not by itself remove the obligation. Where a foreign controller falls within scope, Turkish rules also contemplate the appointment of a representative in Turkey — and in that case, registration is generally expected to be completed before processing begins.
Because thresholds and exemption lists change, treat this as a question for Turkish counsel rather than a self-assessment.
What the declaration asks for
Have this ready before you start — it is essentially your processing inventory:
| Field | What to prepare |
|---|---|
| Controller identity | Legal name, tax/registry numbers, address, contact details |
| Representative (if applicable) | Details of the Turkey-based representative |
| Contact person | A natural person for correspondence |
| Data categories | Identity, contact, financial, HR, health, transaction security, etc. |
| Data subject groups | Customers, employees, candidates, suppliers, visitors |
| Purposes | Concrete, per-process purposes |
| Recipients | Accountants, cloud providers, payment institutions, public authorities |
| Cross-border transfers | Countries and mechanisms |
| Retention periods | Per data category |
| Security measures | Technical and organisational measures actually in place |
If you don't yet have an inventory, build it first — see the compliance checklist.
After registration
- 30-day rule: any change (new vendor, new data category, address change) must be reflected within 30 days
- Keep it consistent: update the privacy notice and the declaration together
- Annual review: read your own declaration once a year and confirm it still describes reality
Common mistakes by international teams
- Assuming EU registration covers it — there is no mutual recognition
- Naming a contact person who never checks the mailbox — official correspondence goes unread
- Declaring aspirational security measures — declare what you actually do
- Registering once and forgetting — the update obligation is where breaches accumulate
- Copying the group privacy notice without reflecting Turkish lawful bases
FAQ
Is there a fee?
The Authority does not charge a registration fee. Costs are internal preparation time or advisory fees.
Can our Turkish law firm register on our behalf?
Someone you authorise can complete the submission, but the accuracy of the declaration remains the controller's responsibility.
Do branches register separately?
Registration follows legal personality. Branches of the same legal entity are not registered separately; distinct legal entities are.
What if we conclude we're not obligated?
Keep the evidence supporting that conclusion (headcount, balance sheet, activity description). Other KVKK obligations still apply regardless.
Prepare in one pass: KVKK Otomat builds the inventory and a VERBIS preparation list from your process map, so the declaration becomes data entry rather than research. Background reading: Turkish data protection law guide.


