What Is VERBIS? Turkey's Data Controllers Registry and Who Must Register in 2026

TL;DR: VERBIS is the public registry where data controllers declare their personal-data processing under Turkey's data protection law (KVKK). As of 2026, companies with more than 50 employees OR an annual balance sheet above 100 million TRY must register, as must any organisation whose core business is processing sensitive personal data — and, regardless of size, foreign data controllers processing personal data in Turkey. Behind the registration form sits the real work: a data inventory of your systems.
If your company does business in Turkey — through a local subsidiary, a branch, or simply by serving Turkish customers — sooner or later a contract negotiation, a vendor audit or a lawyer will ask the same question: "Is your VERBIS registration in place?" This guide explains what the registry is, who must register under the 2026 rules, and what the registration actually commits you to.
What VERBIS Is
VERBIS (short for the Turkish name of the Data Controllers Registry Information System) is the online registry operated by Turkey's Personal Data Protection Authority. Its legal basis is Article 16 of the KVKK, Turkey's data protection law: natural and legal persons who process personal data must enrol in the registry before processing begins, unless they fall under an exemption defined by the Board.
Registration is a structured declaration: which categories of personal data you process, for which purposes, how long you retain them, which recipient groups you transfer them to, whether data leaves Turkey, and which security measures you apply. A summary of that declaration is publicly searchable — customers, competitors and auditors can look your entry up. VERBIS is therefore less a formality and more the public face of your data-processing practice.
Who Must Register in 2026?
The obligation is defined by Board decisions, and the thresholds have been revised over the years. Under the current framework there are four doors into the obligation:
| Trigger | Criterion | Typical example |
|---|---|---|
| Headcount | More than 50 employees annually | A manufacturer with 55 staff |
| Financial size | Annual balance sheet total above 100 million TRY | A 30-person wholesaler with a large balance sheet |
| Sensitive data | Core business is processing special categories of data — no size threshold | Private clinics, occupational-health providers, laboratories |
| Foreign controllers | Data controllers established abroad that process personal data in Turkey — no size threshold | A foreign SaaS company serving users in Turkey |
For the two threshold-based doors, meeting either criterion is enough. For the sensitive-data door, size is irrelevant: a three-person counselling practice is obliged to register because health data is its core business.
The Rule Foreign Companies Miss
The provision with the most practical consequences for international readers is the fourth one: a data controller established outside Turkey that processes personal data of people in Turkey falls under the registration obligation regardless of employee count or balance sheet, and must appoint a data controller representative in Turkey — a local point of contact registered in VERBIS. Market entry checklists built purely around GDPR often miss this step, because the GDPR has no directly equivalent public registry. If Turkey is a real market for your product, VERBIS registration belongs on the same checklist as tax registration.
Who Is Exempt?
Board decisions exempt several groups, including lawyers, notaries, mediators and customs brokers acting within their professional activity; associations, foundations and trade unions processing data only for their members and staff under their own legislation; and political parties. Businesses below the thresholds whose core activity is not sensitive-data processing are also outside the registration obligation.
The most common misunderstanding: exemption from the registry is not exemption from the law. The KVKK's substantive duties — informing data subjects, securing the data, answering data-subject requests, reporting breaches — apply to every controller, registered or not. VERBIS is the declaration layer, not the compliance itself.
What Non-Registration Costs
Failure to register and declare is an administrative offence under Article 18 of the KVKK. Fine amounts are revalued every year and reach into the millions of Turkish lira; on the data-security side of the law, 2026 upper limits approach 17 million TRY. Exact current figures are published annually by the Authority. The indirect cost is often felt sooner than the fine: in vendor security audits and public tenders, a missing VERBIS registration can be a single-line disqualifier.
The Real Work Behind the Form: the Data Inventory
The VERBIS declaration is a summary of your personal-data processing inventory. Without the inventory, the form either cannot be completed or degenerates into a copy-paste declaration that does not match reality — and a declaration that contradicts your actual practice is harder to defend in an audit than a late registration. Building the inventory is mostly technical discovery work:
- Which systems hold personal data? (ERP, CRM, email, file servers, HR software, CCTV, access-control systems)
- Where does the data physically live? (on-premises servers, Turkish data centres, foreign cloud regions)
- Who can access it, and which security controls apply? (permissions, encryption, backups, logging)
- How long is it retained, and what happens at the end of the period?
- Which third parties receive it? (accountants, couriers, messaging providers, foreign SaaS tools)
Where Yamanlar Bilişim Fits
The legal side of the declaration — legal bases, privacy notices, the wording of the registry entry — belongs to your counsel or KVKK consultant. Yamanlar Bilişim covers the technical side beneath it: a VERBIS technical readiness inventory that maps where personal data actually lives in your infrastructure, who can reach it, how it is protected and where it flows. The output serves two purposes: an accurate foundation for the registry declaration, and a concrete list of security findings — unencrypted shares, over-broad permissions, forgotten legacy systems — that is usually worth more than the registration itself.
FAQ
Frequently Asked Questions
Does a company with several branches register each branch separately?
No. Registration follows the legal entity, not the branch. Separate legal entities within a group, however, each assess their own obligation.
We crossed the threshold mid-year — what is our deadline?
The obligation arises on the date you become subject to it, and the application must be filed within 30 days of that date. Tracking that trigger is the controller's own responsibility.
Is VERBIS registration the same as KVKK compliance?
No. Registration is the declaration layer. Privacy notices, consent flows, security measures, retention-and-destruction policy and the data-subject request process are separate workstreams — and an inaccurate registry entry documents non-compliance rather than hiding it.
Is the threshold based on revenue or balance sheet?
The financial criterion is the annual balance sheet total, not turnover. Borderline cases should be assessed with your accountants on balance-sheet figures.
We are a foreign company with no office in Turkey. Does this really apply to us?
If you process personal data of individuals in Turkey as a controller, yes — the obligation applies regardless of your size, and it includes appointing a representative in Turkey. This is the item most often missing from market-entry plans built on GDPR assumptions alone.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Turkey's KVKK and Cross-Border Data Transfers: a Cloud Reality Check
If your company email or files are hosted in a data centre outside Turkey, the KVKK's cross-border transfer rules apply to you. The standard-contract regime introduced in 2024, the cloud service inventory, and the concrete IT-side steps — in plain language.

NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?
Europe's NIS2 directive obliges in-scope companies to secure their supply chains too. Turkish SMBs selling into the EU are now receiving security questionnaires and contract clauses — here is what will be asked, and how to be ready before it arrives.

Disposing of Old Computers Securely: the Data Destruction and e-Waste Guide
Old computers gathering dust in the store room are not assets — they are open filing cabinets with customer data on their disks. Why formatting is not enough, the right destruction method per disk type, the record-keeping, and the e-waste handover, step by step.