VERBIS registration is how a data controller in Türkiye records its personal data processing with the Personal Data Protection Authority's Data Controllers' Registry Information System. Organisations with 50 or more employees, or a balance sheet above the Board's threshold, must register. What you declare has to match your data inventory and be kept up to date.
What VERBIS is, and why it is so often neglected
Article 16 of Türkiye's Personal Data Protection Law (KVKK, Law No. 6698) requires a public Data Controllers' Registry kept under the supervision of the Personal Data Protection Board. VERBIS is the online version of that registry. Unless an exemption applies, individuals and organisations that process personal data must register before they start processing.
There is no direct GDPR equivalent: the EU dropped general registration in favour of internal records, while Türkiye kept a public register.
Problems begin when registration is treated as a one-off job. Many companies filed in a hurry around the first deadlines, often from a template. Since then they have added new software, moved services to overseas clouds and installed CCTV or attendance terminals, yet the registry still shows the picture from day one. Another common case is the growing company that never notices it has crossed the threshold: when headcount passes 50, the obligation arises automatically and nobody sends a reminder.
The cost of skipping registration
The Board's enforcement figures show this is the duty it penalises most often:
According to the KVKK 2025 Annual Activity Report, 594 of the 876 data controllers fined in 2025, more than two thirds, were penalised under the obligation to register with and notify the Data Controllers' Registry.
That makes VERBIS the easiest gap to spot: the registry is public, and anyone can check in seconds whether a company is listed. Complaints can start the same way. The same annual report records 12,512 complaints and reports received in 2025, and a complaint from an employee or customer can widen into a review of your registration.
Being registered is not enough on its own either. If a company declares a maximum retention period or "no overseas transfers", and it turns out data is kept indefinitely or sent to a foreign service, the gap between declaration and practice becomes the issue. After a breach, the security measures you declared are among the first things the Board will examine.
VERBIS registration in Turkey: who must register, and who is exempt?
Through a series of decisions, the Board has exempted certain data controllers from registration. The general framework looks like this:
| Situation | VERBIS registration |
|---|---|
| 50 or more employees per year | Required |
| Annual balance sheet above the threshold set by the Board | Required, regardless of headcount |
| Main activity is processing special category data (e.g. a clinic handling health data) | Required, even below the thresholds |
| Data controller established outside Türkiye | Required, through an appointed representative |
| Fewer than 50 employees, balance sheet below threshold, main activity not special category data | Exempt |
| Professions and bodies listed in Board decisions (e.g. notaries, lawyers, accountants, mediators, associations and foundations) | Exempt within the scope of the decision |
The balance-sheet threshold is updated by Board decision from time to time, so base your assessment on the latest decision published on the Authority's website. An exemption only removes the registration duty; the obligations to inform, keep data secure, retain and dispose of it properly and report breaches still apply.
VERBIS registration step by step
- Prepare the inventory first. VERBIS looks like form-filling, but every answer comes from your personal data inventory. Without one, registration is guesswork. Our KVKK compliance roadmap explains how to build it.
- Document the obligation and timing. Record the source and date of your headcount and balance-sheet figures. When a threshold is crossed, confirm the registration deadline from the Authority's current announcements.
- Appoint a contact person. Legal-entity data controllers appoint a contact person who handles communication with the Authority. This is usually the person who files and maintains the entry, so replace them promptly if they leave.
- Complete the controller registration and contact person login. An application is made on behalf of the data controller, then the contact person logs in with their own identity to prepare the notification. Check the Authority's VERBIS guidance for the current login and application channels, as they change over time.
- Enter your processing activities. Under Article 16, the registry covers the purposes of processing, groups of data subjects and data categories, recipient groups, data expected to be transferred abroad, security measures taken and maximum retention periods.
- Align retention periods with your policy. The maximum periods in VERBIS must match those in your data retention and disposal policy.
- Confirm the notification and keep evidence. Add the system output and its date to your compliance file.
- Update after every change. Under the Registry Regulation, changes to registered information should be reported within 7 days. New software, a new overseas service or a new group of data subjects are all triggers.
Example: what does a 60-person manufacturer declare?
A concrete case makes it clearer. Take a manufacturer in Adana with 60 employees. Headcount is above 50, so registration is mandatory.
The inventory work identifies these groups of data subjects: employees, job applicants, visitors, supplier contacts and customer contacts. For employees, the categories include identity, contact, personnel file, finance (payroll), professional experience and physical site security (card access logs and CCTV footage); if fingerprint readers are used, biometric data is added.
Recipient groups include authorised public bodies such as the social security institution and tax office, the occupational health and safety provider and the payroll software vendor. If email or backups run on a server abroad, that is recorded as a cross-border transfer.
Each category's maximum retention period is copied from the retention and disposal policy. None of this detail can come from a template; it can only come from the inventory.
The VERBIS mistakes we see most often
- Ticking everything. Selecting every data category and purpose "just in case" means declaring processing you do not actually carry out.
- Forgetting CCTV and attendance systems. Camera footage and card or biometric access data are often missed. If you use fingerprint readers, you are processing special category data; see biometric attendance and data protection.
- Leaving email without a retention period. Mail archives hold data on many groups of people; the table in email archiving and data protection helps set the period.
- Declaring measures that do not exist. If you state that access is logged or a permission matrix is in place, the systems must back that up. Our guides to file sharing permissions and the SME cyber security checklist help close the gap.
- Treating breach response as separate. Declared measures are among the first documents reviewed after an incident, so keep our 72-hour breach notification guide in the same file.
How we handle VERBIS and the data inventory at Digital Bridge
In our data protection compliance consultancy we treat VERBIS as an output of the inventory, not a separate form. We interview process owners, then verify what they tell us in the systems themselves: which table holds which personal data, which software sends it where, and where the backups are.
- We extract data categories and recipient groups from HR, payroll and personnel management systems, where staff data is most concentrated.
- We build retention periods per document type into document management systems and align them with the VERBIS entries.
- We clarify data ownership and duplicate personal records across applications through data governance and quality work.
- With our cyber security consultancy team we check that the declared technical measures genuinely exist.
We do not sell off-the-shelf packages; after a needs analysis we prepare a written proposal covering scope, phases and cost.
Next step
Start with three questions. What was your average headcount last year? Are you on the registry, and if so, when was the entry last updated? Which new software or services have you adopted since then?
Send us your answers through our contact page and we will compare your registry entry with your inventory and list the gaps together.