1. Introduction
This article has been prepared within the scope of the Turkish Personal Data Protection Law (“Law”) and the jurisdiction of the Law, with a view to identifying the foreign data controllers’ obligation for the registration to Data Controllers’ Registry (“Registry” or “VERBIS”) and the future steps that can be taken to ensure compliance with the Law for the data processing activities undertaken.
The Law defines the data controller as “the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system”, while the data processor is defined as “the natural or legal person who processes personal data on behalf of the data controller upon its authorization”. As can be seen from the definitions provided, the data controller and data processor concepts are identical to those provided under the European Union’s General Data Protection Regulation (“GDPR”). Consequently, any data controller/data processor assessments made under Law will be also identical to those that have been made within EU jurisdiction.
2. Registration Obligation with Registry
Within the scope of Article 16 of the Law and the Regulation on the Data Controllers Registry (“Regulation”), non-resident data controllers that process personal data of data subjects located in Türkiye are under the obligation to register to the VERBIS before initiating such personal data processing activities.
Therefore, in order to comply with this registration obligation, foreign data controllers must fulfill the following steps before starting processing data of those located in Türkiye:
- Appointing a data controller representative who must be either a Turkish national or a legal entity established in Türkiye ,
- Filling out the sign-up form,
- Applying for a username and password,
- Appointing contact person and registration to VERBIS,
- Upon the preparation of a personal data processing inventory, uploading the required information.
2.1. Appointing a data controller representative who must be either a Turkish national or a legal entity established in Türkiye
• A representative of the data controller should be appointed in order to ensure communication with the Data Protection Authority (“Turkish DPA”) regarding the obligations under the Law and the secondary regulations to be issued on the basis of this Law.
• This representative can be a natural or legal person residing in Türkiye.
2.2. Carry out the initial registration request from the system (requesting a username and password from the Turkish DPA)
- The application form should be filled in on the VERBIS registration screen on the website of the Turkish DPA.
- If the registered electronic mail (KEP) address is provided when the application form is issued, the information form in PDF format must be sent to the Turkish DPA via the KEP address provided.
- If the KEP address is not indicated on the application form, the information form in PDF format must be printed out and sent to the Turkish DPA by post. Applications sent by this method must be wet signed and stamped.
- Once the PDF of the relevant application form has been sent to the Turkish DPA, the Turkish DPA will send a username and password to the email address provided by the data controller representative in the form.
2.3. Preparation of a personal data processing inventory
- In subparagraph (h) of Article 4 of the Regulation, personal data processing inventory is defined as “the inventory in which data controllers detail the personal data processing activities they carry out depending on their business processes by associating them with the purposes and legal grounds for processing personal data, the data category, the transferred recipient group and the data subject group and by explaining the maximum retention period required for the purposes for which personal data are processed, the personal data foreseen to be transferred to foreign countries and the measures taken regarding data security”.
- Article 5 of the relevant Regulation states that “Data controllers who are obliged to register with the Registry are obliged to prepare a Personal Data Processing Inventory. The information to be disclosed to the Registry in the registry applications shall be prepared based on the Personal Data Processing Inventory.”
- Accordingly, a personal data processing inventory must be prepared by foreign data controllers. Based on the information contained in the relevant inventory, the relevant information should be registered to VERBIS on a categorical basis.
3. Intersection of Standard Contractual Clauses and the Registry
According to the Law, standard contractual clauses signed between the data exporters and data importers are notified to the Turkish DPA within 5 (five) business days of its signing. This creates a practical risk for controllers who are not registered to the Registry but are parties to these standard contractual clauses.
There are four modules of standard contractual clauses that can be signed according to the Law. These are:
- Controller-Controller (Module 1)
- Controller-Processor (Module 2)
- Processor-Processor (Module 3)
- Processor-Controller (Module 4)
Regarding modules 1 and 4, the foreign entity signs a standard contractual clause stating that it is acting as a controller according to the Law. Since these standard contractual clauses are notified to the Turkish DPA, the Turkish DPA can cross-check its records on the Registry and initiate an investigation to the foreign controller who is not registered. Therefore, if the foreign entity will sign modules 1 and 4 of standard contractual clauses in Türkiye, it is advised for these entities to also conduct the necessary operations in order to register to VERBIS.
We would like to note that non-compliance with the VERBIS registration obligation might result in an administrative fine from TRY 341.809 (approx. EUR 6.424) up to TRY 17.092.242 (approx. EUR 321.077). Additionally, according to 2025 Activity Report of the Turkish DPA, a total of TRY 818.567.000 (approx. EUR 15,386,597) administrative fine has been issued to local and foreign data controllers who did not have a registration in the Registry.
Regarding the detection of the registration obligation, please see the graph below:

4. The Likelihood of Turkish Regulators Asking for Access to Personal Data
4.1. Government Access to Personal Data Held by Companies
The Turkish legal system often grants broad powers to public authorities to request information and documents from private entities (such laws will be referred as “Data Access Laws”). Hereinafter, we will discuss the potential practical impact of these Data Access Laws in relation to routine business operations of private entities:
4.2. Likely Practical Risk of Receiving Data Access Requests
Most Turkish companies do not handle any information of interest to the Turkish intelligence agency, namely, the National Intelligence Organization and are not likely to receive requests based on the State Intelligence Services and the National Intelligence Organization Law No. 2937. Companies engaged in providing ordinary commercial products or services, and whose EU-TR transfers of personal data involve ordinary commercial information like employee, customer, or sales records, would have no basis to believe the Turkish intelligence agency would seek to collect this data.
Additionally, requests from the police (Law No. 2559 on the Duties and Authorities of Police), gendarmerie (Law No. 2803 on the Organization Duties and Powers of Gendarmerie) and courts (Criminal Procedure Law No. 5271) are only likely to be in question in case of a pending lawsuit or a criminal investigation directly concerning the persons whose personal data are requested.
As for the rest of the authorities, their requests are mainly limited to their own field of operation, such as protection of competition, combatting money laundering etc. To the extent that, under the respective specific laws these government authorities may request disclosure or seek access to personal data, the access requests are generally only incidental to the sector specific investigations and only occur in single regulated cases in the specific market or sector. Therefore, these laws are no concern of disproportionate access to personal data since powers granted to public authorities to request disclosure or seek access to data are based on clear and precise rules accessible to the public and do not exceed what is necessary and proportionate in a democratic society to safeguard national security, defense and public security. In particular, these laws do not empower government authorities to access personal data arbitrarily and without any limitations in scope and purposes of data access and requests. Also, these laws provide for independent and impartial oversight systems and effective rights and remedies are available to the affected individuals.
However, it is important to note that when any information is of interest to any of the authorities mentioned they may tend to request more information than necessary and fail to make the reasoning of their requests very clear in practice. Within this scope the Turkish DPA has rendered decisions stating that real or legal persons who are faced with requests from governmental authorities must only provide information and comply with the requests of these authorities to the extend necessary and must refrain from providing excessive amounts of personal data within this framework in line with the Law. Turkish DPA’s stance against excessive data request is a positive sign in terms of the protection of personal and also non-personal information held by private entities and real persons.
4.3. Public Body Specific Considerations
- (i) Judicial Instances: Courts and prosecutors have a very wide authority to request all kinds of information from private entities and real persons. Basically, such request should be made written and based on a procedure prescribed within the criminal or civil procedure laws. Therefore, we can say that information requests to be made by such authorities are subject to strict regulations. However, in practice, the authorities may tend to issue information requests that are not well described or unproportionate considering the objective of such requests. In case of such request, all entities and real persons have the right to object to such request stating that the information request should be rendered in a proportionate way which is strictly limited with purposes of the relevant criminal or civil investigation or procedure.
- (ii) Security Forces: Information request to be rendered by security forces (police, intelligence service and military police (gendarmerie) may be the most problematic issue in terms of the daily practices of the private entities and real persons. Security forces, while fulfilling their duties vested by the relevant legislation and court decisions, need to carry out certain investigation activities which certainly may require information gathering tools. Security forces may conduct some legal interception (monitoring/surveillance) activities that need to be grounded on court decisions. These monitoring activities generally regard voice calls and correspondences. Monitoring should be limited with a certain time period and information should be gathered only with respect to the purposes of the subject matter investigation. Security forces may also make written information requests, similar to other authorities. We need to note that such requests may tend to be too broad and challenging in certain ways. Firstly, depending on the nature of the investigation, security forces may request a very broad scope or time period, for instance, particularly with terror investigations, they may be looking for the integrality of a certain database consisting of monetary transactions or purchase of certain goods. They may also be looking for digital activity records (logs) and/or IPs of certain people who are suspected of committing certain crimes. In any cases, private entities and real persons located in Turkey, are obliged to comply with such request provided that the requests are issued in compliance with the procedure laws and they are drafted in a proportionate and reasonable manner. On case of failure to comply with such a request, security forces are well equipped with legal instruments allowing them to enforce their requests by collecting digital copies of evidence or confiscating relevant hardware.
- (iii) Other Public Entities: Other public entities are also entitled to make information requests depending on their scope of activities; for instance, the Revenue Administration may issue formal requests in order to ask for records relating to taxpayers. In each specific case, a detailed assessment should be carried out to determine whether the requesting authority is entitled to ask for this specific information. In case of excess of their legal capacity, private entities and real persons, may object to such request.