Data Privacy & Compliance

Data Controller Representative in Türkiye

A Comprehensive Guide to KVKK Obligations, VERBİS Registration, and Compliance for Foreign Entities

The Protection of Personal Data Law No. 6698 (KVKK) establishes a rigorous framework for data processing within Türkiye. For entities operating outside Turkish borders but processing the data of individuals within the country, the role of the Data Controller Representative is a critical compliance requirement. This guide provides an in-depth look at the legal definitions, mandatory duties, and registration procedures involved in this role.

1. Legal Basis and Definition

Under the Regulation on the Data Controllers Registry, any data controller not resident in Türkiye is legally obligated to appoint a representative. The Data Controller Representative is defined as a legal entity resident in Türkiye or a Turkish citizen real person authorized to represent the foreign controller in specific matters related to the Law and secondary regulations. This individual or entity acts as the primary point of contact between the foreign data controller and the Personal Data Protection Authority (the Authority).

2. Mandatory Appointment for Foreign Controllers

Data controllers located abroad must complete their appointment and register with the Data Controllers Registry (Sicil) via their representative before they begin processing personal data in Türkiye. It is a common error for foreign entities to attempt registration using their own international details or those of a "Contact Person" instead of a formal representative; such applications are considered invalid and may lead to legal complications. Registration is facilitated through the Data Controllers Registry Information System (VERBİS), an internet-based informatics system managed by the Authority.

Important: Foreign entities cannot register using their own international details or those of a "Contact Person" — a formal Data Controller Representative is required for a valid application.

3. Essential Duties and Powers

The appointment of a representative is not a mere formality but carries specific legal responsibilities. According to Article 11 of the Regulation, the representative's authority must at least include:

  • Official Correspondence: Receiving and accepting notifications or correspondence from the Authority on behalf of the data controller.
  • Request Management: Relaying requests from the Authority to the controller and submitting the controller's responses back to the Authority.
  • Data Subject Applications: Receiving applications made by data subjects (individuals) to the controller and forwarding them to the controller.
  • Response Relaying: Forwarding the data controller's response to data subject applications, unless the Personal Data Protection Board specifies otherwise.
  • Registry Management: Performing all necessary actions and transactions regarding the Registry (VERBİS) on behalf of the controller.

4. The Appointment and Registration Process

The process of establishing a representative involves both legal documentation and technical registration steps.

Step 1: Formal Decision

The foreign data controller must take a formal decision through its authorized organ or person to appoint the representative. A certified copy of this decision must be prepared to be submitted to the Authority during the registration process.

Step 2: Accessing VERBİS

The representative accesses the VERBİS system via the Authority's official website at www.kvkk.gov.tr. On the VERBİS home page, the representative selects the option "Data Controller Residing Abroad" to begin the application.

Step 3: Data Entry

The representative enters the foreign controller's title, email, phone number, address, and country of residence. Crucially, they must also input the date and number of the representative appointment decision.

Step 4: Representative Identification

The representative then enters their own identification information (Turkish ID number for individuals or Tax Identification Number for legal entities). For individuals, the system verifies details through the MERNİS database, while for legal entities, it connects to the Revenue Administration (GİB) system.

Step 5: Submission of Physical Documents

After saving the information in VERBİS, the representative generates a PDF application form. This form must be printed, signed (and stamped/sealed if a legal entity), and sent to the Authority's headquarters in Ankara along with the certified copy of the appointment decision. Delivery can be made in person, via post, or courier. If the representative has a Registered Electronic Mail (KEP) address, the form and decision can be sent digitally to the Authority's KEP address.

Note: The registration process is not considered complete until the physical documents of the application reach the Authority's headquarters in Ankara.

5. Distinguishing the Representative from the Contact Person

A vital distinction exists between the Representative and the Contact Person (İrtibat Kişisi).

  • The Representative holds the legal authority to represent the foreign controller in legal matters.
  • The Contact Person is a real person appointed by the representative during the VERBİS process to facilitate day-to-day communication with the Authority.

The Contact Person is not authorized to represent the data controller under the Law or Regulation. Their role is purely communicative, and the representative must assign this person within the VERBİS portal after their own credentials have been approved.

6. Ongoing Compliance and Sanctions

Compliance is an ongoing obligation rather than a one-time registration. If any information registered in VERBİS changes — such as the representative's contact details or the controller's address — the representative must report these changes via VERBİS within seven days.

Failure to fulfill the obligation to register with the Registry through a representative is subject to administrative fines as outlined in Article 18 of Law No. 6698. It is also important to note that appointing a representative does not eliminate the data controller's inherent liability under the Law; the controller remains responsible for ensuring all data processing activities comply with Turkish standards.

Sanction Warning: Administrative fines for non-compliance with VERBİS registration obligations are severe. Changes to registered information must be reported within seven days.

7. What Steps Must a Foreign Data Controller Take for Registration?

The registration process involves the following steps:

Step 1: Appointment of a Data Controller Representative

Foreign data controllers are legally obligated to appoint a Data Controller Representative who must be either a legal entity resident in Türkiye or a Turkish citizen real person.

  • Formal Decision: The authorized organ of the foreign controller must take a formal decision to appoint the representative.
  • Certified Copy: A certified copy of this appointment decision must be prepared, as it is a required document for the application.

Step 2: Initial Online Application via VERBİS

The appointed representative initiates the registration through the Data Controllers Registry Information System (VERBİS) at www.kvkk.gov.tr.

  • Select Category: On the VERBİS home page, the representative selects "Data Controller Residing Abroad".
  • Data Entry: The representative enters the foreign controller's title, contact information, and residence country, along with the date and number of the representative appointment decision.
  • Representative Identification: The representative provides their own identification (Turkish ID or Tax Number) and contact details.

Step 3: Submission of Physical Documents

Registration is not complete until physical documents are submitted to the Personal Data Protection Authority.

  • Generate PDF: After saving the information in VERBİS, the system generates a PDF application form.
  • Sign and Deliver: This form must be printed, signed (and stamped if a legal entity), and sent to the Authority's headquarters in Ankara along with the certified copy of the appointment decision. This can be done via post, courier, or Registered Electronic Mail (KEP).

Step 4: Obtaining Credentials and Appointing a Contact Person

  • Credentials: Once the Authority approves the application, it sends a User Name and Password to the email address specified in the application.
  • Assign Contact Person: The representative uses these credentials to log into VERBİS and must appoint a "Contact Person" (İrtibat Kişisi). The Contact Person must be a real person resident in Türkiye and is responsible for facilitating communication with the Authority.

Step 5: Completing the Data Processing Notification

The final technical step is performed by the appointed Contact Person, who logs into VERBİS using their e-Devlet credentials.

  • Inventory-Based Entry: Based on the controller's Personal Data Processing Inventory, the Contact Person enters details regarding data categories, processing purposes, recipient groups, storage periods, and security measures.
  • Final Approval: The process is finalized when the Contact Person clicks "Onayla ve Kuruma Gönder" (Approve and Send to Authority), changing the status to "Valid Notification".
Note: Any changes to the registered information must be updated by the representative within seven days. Failure to comply with these registration obligations is subject to administrative fines.

Conclusion

For foreign data controllers, the Data Controller Representative is the cornerstone of their legal presence in Türkiye. By ensuring that the representative is properly qualified, formally appointed, and correctly registered in VERBİS, international organizations can maintain compliance with KVKK and foster a secure environment for processing personal data within the Turkish jurisdiction.

Need a Data Controller Representative?
We provide professional Data Controller Representative services for foreign companies, handling VERBİS registration and regulatory communication. Contact us to ensure full compliance.

Frequently Asked Questions About the Data Controller Representative

1. What is a Data Controller Representative?

A Data Controller Representative is a legal entity established in Turkey or a real person who is a citizen of the Republic of Turkey, authorized to represent data controllers not established in Turkey in specific matters such as accepting notifications, communicating with the Authority, and conducting VERBİS transactions.

2. Who is obliged to appoint a representative?

Data controllers not established in Turkey must appoint a representative and register with the Data Controllers Registry (VERBİS) through this representative before starting to process personal data in Turkey.

3. What are the primary duties and authorities of the representative?

The authorities of the representative must minimally include the following: Accepting notifications or correspondence made by the Authority. Forwarding the Authority's requests to the data controller and submitting the data controller's responses to the Authority. Receiving applications from data subjects and forwarding them to the data controller. Carrying out all works and transactions related to VERBİS on behalf of the data controller.

4. What is the difference between a Data Controller Representative and a Contact Person?

While the Data Controller Representative has the authority to legally represent the foreign data controller, the Contact Person is a real person appointed solely for the purpose of ensuring communication with the Authority and does not have representation authority. The representative registers the contact person's information into the Registry on behalf of the data controller abroad.

5. How does the representative appointment process work?

A decision must be taken by the authorized body of the foreign data controller regarding the appointment of a representative. A certified copy of this decision is submitted to the Authority by the representative during the registration application.

Frequently Asked Questions About VERBİS Registration and Processes

6. What is VERBİS?

VERBİS (Data Controllers Registry Information System) is an internet-accessible IT system that data controllers use for applying to the Registry and for other transactions related to the Registry.

7. What should be done if the registration information changes?

In case of any change in the information registered in the Registry, data controllers are obliged to notify the Authority of these changes via VERBİS within seven days from the date they occur.

8. How is the registration application completed via VERBİS?

After the information is entered into VERBİS, the system generates a PDF application form. This form must be sent to the Authority by the representative with a wet signature and stamp (or via KEP - Registered Electronic Mail). The registration process is not considered complete until the physical documents of the application reach the Authority.

9. Which data processing activities are exempt from the obligation to register with the Registry?

Certain activities necessary for the prevention of a crime, processing data made public by the data subject themselves, or protecting the economic and financial interests of the State are exempt from the registration obligation. Additionally, the Board may introduce exemptions based on criteria such as the annual number of employees or the annual financial balance sheet total.

10. What is the sanction for non-compliance with the registration obligation?

An administrative fine is imposed in accordance with the Law on those who act contrary to the obligation to register with and notify the Registry. If this non-compliance occurs in public institutions, disciplinary provisions are applied to the relevant personnel.

11. What steps must a foreign data controller take for registration?

The registration process involves: (1) Appointing a Data Controller Representative who must be either a legal entity resident in Türkiye or a Turkish citizen real person; (2) Initiating the online application via VERBİS at www.kvkk.gov.tr by selecting "Data Controller Residing Abroad"; (3) Submitting physical documents including a signed PDF application form and certified copy of the appointment decision to the Authority's headquarters in Ankara; (4) Obtaining credentials from the Authority and appointing a Contact Person (İrtibat Kişisi); (5) Completing the data processing notification by entering inventory details and clicking "Onayla ve Kuruma Gönder" (Approve and Send to Authority).