KVKK Otomat

VERBIS Registration for Foreign Companies: What You Need to Know

September 1, 2026 · 3 min read · KVKK Otomat

VERBIS Registration for Foreign Companies

VERBIS — the Data Controllers' Registry Information System — is a public registry maintained by Turkey's Personal Data Protection Authority. Obligated controllers declare what personal data they process, why, with whom they share it and how long they keep it.

There is no GDPR equivalent, which is why international teams frequently overlook it.

Note: General information, not legal advice. Registration criteria and procedures are set out in Board decisions and can be updated; verify current requirements before acting.

Is it public?

Yes. Anyone can search the registry and see a controller's declaration. Two practical consequences:

  1. Your declaration and your published privacy notice must tell the same story
  2. Competitors, customers and journalists can read it

Who has to register?

Obligation is assessed on criteria including annual employee numbers, annual balance sheet totals and main field of activity, with specific treatment for controllers whose core business involves special category data and for controllers established abroad.

Key point for international companies: being established outside Turkey does not by itself remove the obligation. Where a foreign controller falls within scope, Turkish rules also contemplate the appointment of a representative in Turkey — and in that case, registration is generally expected to be completed before processing begins.

Because thresholds and exemption lists change, treat this as a question for Turkish counsel rather than a self-assessment.

What the declaration asks for

Have this ready before you start — it is essentially your processing inventory:

Field What to prepare
Controller identity Legal name, tax/registry numbers, address, contact details
Representative (if applicable) Details of the Turkey-based representative
Contact person A natural person for correspondence
Data categories Identity, contact, financial, HR, health, transaction security, etc.
Data subject groups Customers, employees, candidates, suppliers, visitors
Purposes Concrete, per-process purposes
Recipients Accountants, cloud providers, payment institutions, public authorities
Cross-border transfers Countries and mechanisms
Retention periods Per data category
Security measures Technical and organisational measures actually in place

If you don't yet have an inventory, build it first — see the compliance checklist.

After registration

Common mistakes by international teams

  1. Assuming EU registration covers it — there is no mutual recognition
  2. Naming a contact person who never checks the mailbox — official correspondence goes unread
  3. Declaring aspirational security measures — declare what you actually do
  4. Registering once and forgetting — the update obligation is where breaches accumulate
  5. Copying the group privacy notice without reflecting Turkish lawful bases

FAQ

Is there a fee?

The Authority does not charge a registration fee. Costs are internal preparation time or advisory fees.

Can our Turkish law firm register on our behalf?

Someone you authorise can complete the submission, but the accuracy of the declaration remains the controller's responsibility.

Do branches register separately?

Registration follows legal personality. Branches of the same legal entity are not registered separately; distinct legal entities are.

What if we conclude we're not obligated?

Keep the evidence supporting that conclusion (headcount, balance sheet, activity description). Other KVKK obligations still apply regardless.


Prepare in one pass: KVKK Otomat builds the inventory and a VERBIS preparation list from your process map, so the declaration becomes data entry rather than research. Background reading: Turkish data protection law guide.