VERBİS — the Data Controllers’ Registry Information System — is the best-known and least-understood obligation under KVKK, Turkey’s Personal Data Protection Law No. 6698. Most companies see it as “filling in a form for the government”, hand it off to the accountant or HR, and get it done in an afternoon. The problem is that every piece of information you enter into VERBİS is a public declaration, and it is the first place the Board — the Personal Data Protection Board (Kurul) — looks when it opens an investigation. If your declaration does not match what you actually do, having registered does not protect you; on the contrary, you have documented the inconsistency.
This post is for general information purposes and is not legal advice. Because the thresholds and exemptions can change through Board decisions, check the current announcements before registering.
What VERBİS Is, and What It Is Not
VERBİS is the online registry in which data controllers (veri sorumlusu) — the parties that determine the purposes and means of processing — declare which categories of personal data they process, for what purpose, who they transfer it to, how long they retain it and which security measures they have taken. Anyone can query the registry and see your company’s declaration.
What it is not: the personal data itself is not entered into VERBİS. You do not upload your customer list. You enter category-level information such as “we process customers’ identity and contact data for the purpose of performing a contract, retain it for 10 years, and share it with the courier company.”
And most importantly: VERBİS registration is not KVKK compliance. It is only one step of it. For the big picture, see our 8-step compliance roadmap.
Who Has to Register?
As a rule, every data controller has to register; certain groups have been exempted through Board decisions. In practice the picture looks like this:
| Situation | VERBİS registration |
|---|---|
| Annual number of employees above 50 or annual balance sheet total above 100 million TL | Mandatory |
| Fewer than 50 employees and balance sheet below 100 million TL, core activity is not processing special categories of data | Exempt |
| Core activity is processing special categories of personal data (private clinic, laboratory, health technology, etc.) | Mandatory — lower thresholds apply to small-scale ones |
| Data controller established abroad (if it processes the data of people in Turkey) | Mandatory — regardless of size |
| Public institutions and organizations | Mandatory |
Three points to watch:
The conditions are cumulative. To benefit from the exemption, the number of employees has to be below 50 and the balance sheet total has to be below 100 million TL. A trading company with 12 employees but a balance sheet of 140 million TL has to register.
Balance sheet total is not revenue. The threshold is determined by the total assets in your year-end financial statements; not by monthly sales or revenue. With inflation, more companies quietly cross this threshold every year — put a check in the calendar for when your year-end balance sheet closes.
The exemption is not an exemption from the law. Even if you have no registration obligation, your obligations to inform data subjects, keep data secure, respond to requests and notify breaches continue exactly as they are.
In addition, certain groups such as notaries, lawyers, certified public accountants, associations, foundations and political parties have been exempted by Board decision, only with respect to the activities that fall within the scope of their own legislation.
Before Registering: No Inventory, No VERBİS
The information the VERBİS screens ask you for is a summary of your personal data processing inventory. If you do not have an inventory, you will tick the boxes on the screen by guesswork — and those guesses become your public declaration.
A solid inventory contains the following for each processing activity: data category, data subject group (customer, employee, candidate, visitor), purpose of processing, legal basis, retention period, recipient groups the data is transferred to, whether there is a cross-border transfer, and the security measures taken.
Do not build the inventory from department interviews alone. Scan the databases, integrations and logs as well; because nothing tells you what your systems actually store more accurately than your systems.
The Registration Process, Step by Step
- Opening the data controller administrator account. An application form is filled in on VERBİS, then signed and sent to the Authority — the Personal Data Protection Authority (Kurum) — by registered e-mail (KEP) or by post. The Authority sets up the login credentials for the system.
- Appointing the contact person (irtibat kişisi). By logging in with the administrator account, a natural person resident in Turkey is appointed as the contact person. The contact person logs into the system via e-Devlet, Turkey’s e-government portal.
- Making the notification. The contact person enters the data categories, processing purposes, data subject groups, recipient groups, cross-border transfers, retention periods and security measures.
- Approval and publication. Once the notification is approved, it becomes publicly accessible in the registry.
The contact person is not the legally liable person — liability rests with the legal entity. But they are the point of contact for the Authority and for data subjects; which is why this is also usually the first piece of information that nobody remembers to update when that person leaves the company.
Data controllers established abroad run the process through a data controller representative (veri sorumlusu temsilcisi) that they appoint in Turkey.
The 6 Mistakes We See Most Often
1. Ticking every box on the screen. Selecting all data categories and all purposes “just in case” means declaring that you process data you do not process. You end up painting a picture that contradicts the principle of proportionality.
2. Making up retention periods. Writing “indefinite”, or “10 years” for everything. For each category, the period has to be justifiable on the basis of the legislation it relies on or a legitimate need. And that period has to actually be enforced in your system.
3. Saying “none” for cross-border transfers. If your corporate e-mail, your CRM or your analytics tool runs on servers abroad, you are transferring data abroad. For details, see our post on cross-border transfers.
4. Declaring measures you have not taken. The boxes for “penetration tests are performed” and “log records are kept in a way that prevents user interference” get ticked, but in reality none of it happens. In a post-breach investigation, you are asked about these declarations one by one.
5. Registering once and forgetting about it. A new product, a new mobile app, new HR software — as your processing activities change, the registration has to be updated too. Changes are expected to be reflected in VERBİS within seven days.
6. Not noticing you have crossed the threshold. Registration has to be completed within 30 days after the registration obligation arises. Growing companies often notice months later that their headcount has passed 50 or that the balance sheet threshold has been exceeded.
The Price of Not Registering or of a False Declaration
The administrative fine for 2026 for breaching the VERBİS registration and notification obligation is between 341,809 TL and 17,092,242 TL. In past years the Board has publicly announced that it fined a large number of data controllers that failed to meet the registration obligation on time; this is not a sanction that exists only on paper.
Independently of the fine, the absence of a VERBİS registration has also become one of the first items enterprise customers look at in their supplier assessments.
After Registering: Keeping the Declaration Alive
The way to make VERBİS sustainable is to tie it to the inventory, and the inventory to your change processes:
- When a new system, form or integration goes live, have the question “does it process personal data?” on your checklist
- Verify the inventory at least once a year, by scanning the systems
- Tie contact person changes to the HR offboarding process
- Do not stop at declaring retention periods; automate the destruction operations
Need Help?
The form part of VERBİS is a day’s work. The real work is the inventory that makes sure the information entered into that form is correct — and the inventory being correct depends on someone actually looking at your systems.
At IWWOMI, we build the inventory by examining your databases, integrations and data flows, base your VERBİS notification on that inventory, and then set up the process that keeps it up to date afterwards. If you are not sure whether you have a registration obligation, or you doubt that your existing registration reflects reality, drop us a line.
Sources: VERBİS — Personal Data Protection Authority · Regulation on the Data Controllers’ Registry and Board decisions