How to Register with VERBIS: A Step-by-Step Guide for Companies in Turkey

TL;DR: VERBIS registration runs in five steps: the application form on verbis.kvkk.gov.tr, delivery to the Authority (registered e-mail or post), login credentials, appointing a contact person, and entering the declaration. Eighty percent of the effort is preparing step five — the declaration cannot be filled truthfully without a data inventory. Once registered, changes to your recorded information must be updated within 7 days.
Once you have established that your company must register — if you are not sure, start with the thresholds and exemptions guide — the process itself is more methodical than difficult. The difficulty is rarely the form; it is that the form asks for information most organisations have never written down in one place.
Before You Start: the Preparation List
- Company identifiers: trade registry details, tax number, and a registered electronic mail (KEP) address for official correspondence
- A contact person decision: the individual who will front communications with the Authority and with data subjects
- A personal-data processing inventory: which data categories are processed, for which purposes, in which systems, for how long, and shared with whom
- A realistic list of security measures: the technical and organisational controls you actually operate
Step 1: Complete the Application Form
On verbis.kvkk.gov.tr, the data-controller manager section opens the application for entities established in Turkey. The form covers company identity, address and the KEP address for electronic notification. Foreign-established controllers follow the parallel track through a locally appointed data controller representative.
Step 2: Deliver the Form to the Authority
The completed form reaches the Authority in one of two ways: electronically from your corporate KEP address, or as a wet-signed printout by post. The KEP route is markedly faster — and if the company does not yet hold a corporate KEP account, acquiring one pays for itself in every later official exchange.
Step 3: Receive Your Credentials
Once the application is reviewed and accepted, login credentials for the registry are delivered to your registered channel. Treat them as corporate credentials, not personal ones: they are the key to the company's official declaration and belong in the corporate password vault with defined access.
Step 4: Appoint the Contact Person
On first login the contact person is appointed and confirms the appointment through their own e-government identity. This person is the address for Authority correspondence and data-subject requests — keeping their contact details current is part of the obligation, because a request that expires unanswered in a former employee's mailbox becomes the company's problem, not theirs.
Step 5: Enter the Declaration
This is the substantive act of registration. The declaration covers your data categories, processing purposes, retention periods per category, recipient groups, whether data is transferred abroad, and the security measures you apply. Each of these headings should trace back to the inventory prepared beforehand — the declaration is a category-and-purpose level summary, not a system-by-system listing.
The Declaration Mistakes That Cost the Most
- Filing without an inventory: a template declaration copied from the internet completes the form and misrepresents the company; in an audit, the gap between declaration and reality is harder to defend than a late filing.
- Retention declared as "indefinite": purpose-limited, time-bound retention is a core principle of the law; "indefinite" contradicts it on the face of the record.
- Ticking "no international transfer" while running foreign cloud services: if your email, file storage or CRM is hosted abroad, the transfer exists and the declaration must say so.
- Declaring aspirational security measures: list the controls you actually run. In a breach investigation, a declared-but-absent control converts your own registry entry into adverse evidence.
After Registration: the Entry Is a Living Record
The declaration is not a one-off filing. When recorded information changes — a new data category, a new cloud provider, a revised retention policy, a new contact person — the registry must be updated within 7 days. The practical way to honour that deadline is to attach a standing question to procurement and change processes: "does this change our VERBIS entry?"
Doing the Technical Groundwork with Yamanlar Bilişim
Four of the declaration's six headings are answered by technical discovery: which systems hold the data, where they are hosted, where the data flows, and which controls protect it. Yamanlar Bilişim's VERBIS technical readiness inventory establishes the factual baseline for those four headings, so that your legal adviser drafts the declaration on facts rather than assumptions — and the same discovery routinely surfaces findings worth fixing regardless of the registry: uncontrolled permissions, unencrypted shares, forgotten systems still holding personal data.
FAQ
Frequently Asked Questions
How long does the whole process take?
The Authority's review time varies with application volume, and KEP applications move faster than postal ones. The declaration step is entirely a function of your own preparation: with an inventory in hand it is a day's work; without one it stretches into weeks.
Should we file the declaration ourselves or through an adviser?
Whoever operates the keyboard, responsibility for the declaration stays with the data controller. The workable division of labour: technical inventory by IT or an IT partner, legal qualification by a KVKK adviser or counsel, and the entry itself built on those two inputs.
What happens when the contact person leaves the company?
That is a change to recorded information and must be updated in the registry. Leaving a departed employee as the registered contact quietly orphans Authority correspondence and data-subject requests — add the check to your offboarding procedure.
Do we list every system we use?
No. The declaration is made at the level of data categories and purposes, not product names. The system list is the inventory behind the declaration, not the declaration itself.
Who should hold the VERBIS credentials?
The registry account is the company's official declaration channel. Store the credentials in the corporate password vault with defined access, and include them in the handover list whenever the contact person or responsible manager changes.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Turkey's KVKK and Cross-Border Data Transfers: a Cloud Reality Check
If your company email or files are hosted in a data centre outside Turkey, the KVKK's cross-border transfer rules apply to you. The standard-contract regime introduced in 2024, the cloud service inventory, and the concrete IT-side steps — in plain language.

NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?
Europe's NIS2 directive obliges in-scope companies to secure their supply chains too. Turkish SMBs selling into the EU are now receiving security questionnaires and contract clauses — here is what will be asked, and how to be ready before it arrives.

Disposing of Old Computers Securely: the Data Destruction and e-Waste Guide
Old computers gathering dust in the store room are not assets — they are open filing cabinets with customer data on their disks. Why formatting is not enough, the right destruction method per disk type, the record-keeping, and the e-waste handover, step by step.