VERBIS Registration Deadline: Was It Extended? Current 2026 Dates

TL;DR: With the 2026 update to registration thresholds, the deadline for data controllers newly falling into scope was extended by Board announcement to 5 June 2026. Missing the date does not dissolve the obligation — the correct move is to complete registration as fast as an honest declaration allows. Controllers who become subject later (for example by crossing a threshold) always have 30 days from that date.
Deadline questions dominate VERBIS searches for a simple reason: the calendar is not fixed. Thresholds are revised by Board decisions and deadlines get extended by announcement, and every revision re-opens the same two questions — are we in scope now, and how long do we have? This page tracks the current answer and stays updated as the calendar moves.
The Current Position: 5 June 2026
The 2026 revision updated the registration scope: controllers with more than 50 employees OR an annual balance sheet above 100 million TRY, and organisations whose core business is processing sensitive personal data, fall within it — as do foreign-established controllers processing personal data in Turkey, with no size threshold. For controllers newly in scope, the registration deadline was extended by Board announcement to 5 June 2026. The full scope rules are covered in the who-must-register guide.
Who the Deadline Applies To
- Newly in-scope controllers: organisations brought into the obligation by the revised criteria — the announced deadline is theirs.
- Already-obliged controllers who never registered: the extension is not an amnesty; their obligation predates it, and registration should be completed without further delay.
- Controllers whose obligation starts later: crossing a threshold or changing activity triggers the standing rule — application within 30 days of the obligation arising, independent of any announced calendar.
If You Have Already Missed the Deadline
A passed deadline does not extinguish the duty; every unregistered month extends the exposure. Non-registration is an administrative offence with fines revalued annually, reaching into the millions of lira. The plan is short: confirm your scope position today, start the data-inventory work immediately — it is the precondition for a truthful declaration — and file the application without waiting for the inventory to finish, since the application step itself needs no inventory. The steps are laid out in the step-by-step registration guide. The one shortcut to avoid: filing a copy-paste declaration to look fast. A declaration that contradicts reality is a worse position than a late one.
The 2026 Calendar at a Glance
| Situation | Applicable period |
|---|---|
| Controllers newly in scope under the revised criteria | 5 June 2026 (extended by Board announcement) |
| Obligation arising later (threshold crossed, activity changed) | 30 days from the date the obligation arises |
| Changes to registered information | Update within 7 days of the change |
Will the Date Move Again?
History says extensions happen — this one continues an established pattern. Planning around "it will surely slip again", however, is a gamble: extensions arrive by announcement and are never guaranteed. The sound approach is to verify the current date against the Authority's official announcements and finish the preparation regardless of the calendar.
Spend the Extension on Preparation, Not Waiting
The most productive use of an extended deadline is the inventory work. Yamanlar Bilişim's VERBIS technical readiness inventory establishes the factual state of the declaration's four technical headings — systems, hosting locations, data flows, security controls — and hands your legal adviser a foundation to draft the entry on facts. The same exercise routinely surfaces security findings worth fixing whatever the registry says.
FAQ
Frequently Asked Questions
We cannot make the deadline. What is the first move?
File the application step now — it requires no inventory and puts you formally into the process — then run the inventory and declaration in parallel and enter an honest declaration as soon as it is ready.
We crossed the threshold this year. Does 5 June or the 30-day rule apply?
Announced bulk deadlines belong to the group covered by the announcement. An obligation arising from a threshold crossing follows the standing rule: 30 days from the date it arises.
We are registered but our entry is outdated. Does the extension buy us time?
No. The update duty for registered controllers runs independently of deadline announcements: changes to recorded information carry a 7-day update period, which in your case is already running.
Can you state the exact fine amounts?
Amounts change every year with revaluation, so this page avoids fixed figures; the current bands are published annually by the Authority. The decision-relevant fact is the order of magnitude: a sanction that reaches into the millions of lira, not a symbolic fee.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Turkey's KVKK and Cross-Border Data Transfers: a Cloud Reality Check
If your company email or files are hosted in a data centre outside Turkey, the KVKK's cross-border transfer rules apply to you. The standard-contract regime introduced in 2024, the cloud service inventory, and the concrete IT-side steps — in plain language.

NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?
Europe's NIS2 directive obliges in-scope companies to secure their supply chains too. Turkish SMBs selling into the EU are now receiving security questionnaires and contract clauses — here is what will be asked, and how to be ready before it arrives.

Disposing of Old Computers Securely: the Data Destruction and e-Waste Guide
Old computers gathering dust in the store room are not assets — they are open filing cabinets with customer data on their disks. Why formatting is not enough, the right destruction method per disk type, the record-keeping, and the e-waste handover, step by step.