News website operators most often reason like this: “My publishing activity falls within the KVKK exemption, so I do not need to register with VERBİS.” The inference is incomplete. Article 16 of Personal Data Protection Law No. 6698 (“KVKK”) makes registration with the Registry the rule and exemption the exception; and no numerical threshold for that exemption is written either in the Law or in the regulation. This guide opens up Article 16 and the Regulation on the Registry of Data Controllers (Official Gazette 30.12.2017/30286) provision by provision, and shows which activity of a news website falls under which regime.

The legal basis: what does Article 16 of KVKK say?

Article 16(1) — “A Data Controllers' Registry shall be kept, publicly accessible, by the Presidency under the supervision of the Board.” The fact that the Registry is public matters: the information in your entry can be seen by third parties. The substantive obligation is in the second paragraph. Article 16(2) — “Natural and legal persons who process personal data are obliged to register with the Data Controllers' Registry before they begin processing data. However, taking into consideration objective criteria to be determined by the Board, such as the nature and the number of the personal data processed, whether the processing arises from a law, or whether the data are transferred to third parties, the Board may introduce exceptions to the obligation to register with the Data Controllers' Registry.” Underline two points: the obligation arises before processing begins, not afterwards; and the exception is introduced by the Board (the Personal Data Protection Board), not by the legislator.

Information to be declared in the registration application (Article 16(3))

  • a) Identity and address details of the data controller and, if any, of its representative.
  • b) The purpose for which the personal data will be processed.
  • c) Explanations concerning the group and groups of data subjects and the data categories relating to those persons.
  • ç) The recipients or groups of recipients to whom the personal data may be transferred.
  • d) Personal data envisaged to be transferred to foreign countries.
  • e) Measures taken regarding personal data security.
  • f) The maximum period necessary for the purposes for which the personal data are processed.

Article 16(4) — “Changes occurring in the information provided pursuant to the third paragraph shall be notified to the Presidency immediately.” The Regulation gives that “immediately” a concrete shape; see the table of deadlines below.

Who is the data controller?

Article 3(1)(ı) of the Law: “Data controller: means the natural or legal person who determines the purposes and means of processing personal data and who is responsible for the establishment and management of the data filing system.” The company or the individual operating the news website is inside this definition. The hosting provider, the CDN, the email newsletter service and the analytics provider are typically data processors within the meaning of Article 3(1)(ğ) — but under Article 12(2) responsibility for taking security measures is joint.

Article 5(1)(a) of the Regulation: “Data controllers are obliged to register with the Registry before they begin processing personal data.” Article 5(1)(b): “Data controllers not established in Turkey are obliged to register with the Registry through a data controller representative before they begin processing data.” A site incorporated abroad but publishing towards Turkey registers through a representative once the obligation arises; being established outside Turkey does not by itself create an exemption.

The exemption threshold: there is no figure in the Law or in the Regulation

Anyone looking for the statutory footing of the sentences circulating in the market — “if you are below such-and-such a number of employees you do not need to enter VERBİS” — should know this: not a single numerical threshold appears either in Law No. 6698 or in the Regulation on the Registry of Data Controllers. The Regulation only lists the criteria the Board will look at.

Article 16(1) of the Regulation, “Exemption criteria” — “The Board may introduce exceptions to the registration obligation taking the following criteria into consideration:”

  • a) The nature of the personal data.
  • b) The number of the personal data.
  • c) The purpose for which the personal data are processed.
  • ç) The field of activity in which the personal data are processed.
  • d) Whether the personal data are transferred to third parties.
  • e) Whether the personal data processing activity arises from laws.
  • f) The period for which the personal data are retained.
  • g) The group of data subjects or the data categories.
  • ğ) (Added: Official Gazette 28/4/2019-30758) Information on the data controller's annual number of employees or annual financial balance sheet total.

As can be seen, subparagraph (ğ) lists “annual number of employees” and “annual financial balance sheet total” only as criteria to be looked at; it gives no figure whatsoever. The power to set a figure is left to the Board by Article 16(2): “The Board is empowered to take decisions in order to determine the scope of the exceptions established within the framework of the criteria listed in the first paragraph, and the procedures and principles for their application. The Board announces these decisions to the public by publishing them through appropriate means.”

Activity-based exemptions — Article 15 of the Regulation

Separately from any numerical threshold, some activities carry no obligation to register with the Registry and to notify. Article 15 of the Regulation: “The data controller has no obligation to record in the Registry and to notify the following personal data processing activities:”

  • a) Where the personal data processing is necessary for the prevention of the commission of an offence or for a criminal investigation.
  • b) The processing of personal data made public by the data subject themselves.
  • c) Where the personal data processing is necessary, on the basis of the authority conferred by law, for the performance of supervisory or regulatory duties and for disciplinary investigations or prosecutions by public institutions and organisations and by professional bodies having the status of a public institution.
  • ç) Where the personal data processing is necessary for the protection of the economic and financial interests of the State in relation to budgetary, tax and financial matters.

These subparagraphs are word for word identical to the subparagraphs of Article 28(2) of the Law. The critical point: these are activity-based exemptions; they do not exempt the data controller wholesale. For a news website the subparagraph that operates in practice is (b) — data the person has made public themselves. An email address collected through the comment system, or a subscriber list, is not within the scope of that subparagraph.

Publishing is exempt — and the rest?

Processing of personal data inside news content is assessed under Article 28(1)(c) of KVKK; where the conditions of that subparagraph are met, the Law in its entirety — including the VERBİS obligation in Article 16 — does not apply. But this full exemption has eight separate limits attached to it and covers only the publishing activity; we deal with the subject in detail in the KVKK exemption for journalistic activity. A news website, however, does not only publish news: the same legal entity simultaneously registers subscribers, sends newsletters, collects comments, employs reporters, and runs advertising and analytics infrastructure. None of these activities falls within Article 28(1)(c).

ActivityFull exemption under Art. 28(1)(c)Consequence for VERBİS
Use of a name, photograph or statement in news copyYES, if the eight limits are observedThe Law does not apply; no registration is sought for this activity
Membership / subscription recordsNOThe whole Law applies; the registration obligation is assessed
Email newsletter listNOLaw No. 6698 and Law No. 6563 apply together
Reader comments and IP logsNOThe whole Law applies
Reporter and employee HR filesNOThe whole Law applies
Advertising and analytics trackingNOThe whole Law applies
Data made public by the person themselvesPartial — Art. 28(2)(b)Reg. Art. 15(1)(b): this activity is not notified to the Registry

Article 5(1)(f) of the Regulation reinforces this distinction expressly: “Without prejudice to the situations set out in Article 28 of the Law, the fact that data controllers meeting certain conditions on the basis of the objective criteria set out in Article 16 of this Regulation are not held by the Board to be under an obligation to register with the Registry does not remove their obligations under the Law.

Deadlines: when do you register, and within how many days is a change notified?

Article 8(1) of the Regulation: “Data controllers are obliged to fulfil their obligation to register with the Registry before they begin processing personal data.” Article 8(2): “Data controllers who are not under a registration obligation but who subsequently become subject to it shall register with the Registry within thirty days after becoming subject to the obligation.” Under Article 8(3), in the event of factual, technical or legal impossibility, an application in writing may be made to the Authority within seven business days at the latest from the date on which that impossibility arose, requesting additional time; the Authority may grant additional time on a one-off basis and in any event not exceeding thirty days.

Article 13 (as amended: Official Gazette 28/4/2019-30758): “Where there is a change in the information registered in the Registry, data controllers shall notify the Authority through VERBİS of the changes that have occurred within seven days of the date on which the change occurred.”

StepDeadlineLegal basis
First registrationBefore processing beginsKVKK Art. 16(2) · Reg. Art. 5(1)(a), Art. 8(1)
Registration of a controller who later becomes subject30 daysReg. Art. 8(2)
Request for additional time in case of impossibilityApplication within 7 business daysReg. Art. 8(3)
Additional time the Authority may grantOne-off, at most 30 daysReg. Art. 8(3)
Notification of a change in registered information7 daysReg. Art. 13

Two obligations that arrive with registration: the inventory and the destruction policy

Registration on its own is not enough. Article 5(1)(ç) of the Regulation: “Data controllers who are obliged to register with the Registry are obliged to prepare a Personal Data Processing Inventory. The information to be disclosed to the Registry in registry applications is prepared on the basis of the Personal Data Processing Inventory.” In other words the inventory is a precondition of registration; it is not a by-product generated while filling in the VERBİS screens.

The second is the destruction policy. Article 5(1) of the Regulation on the Erasure, Destruction or Anonymisation of Personal Data: “Data controllers who are obliged to register with the Data Controllers' Registry pursuant to Article 16 of the Law are obliged to prepare a personal data retention and destruction policy in accordance with the personal data processing inventory.” The third paragraph of the same article says that those who are not obliged to prepare a policy nonetheless remain under the destruction obligation.

The periodic destruction interval in the policy may not in any event exceed six months, under Article 11(2) of the Erasure Regulation. A data controller who is not obliged to prepare a policy erases, destroys or anonymises the data within three months following the date on which the obligation arose, under Article 11(3). Records of destruction operations are kept for at least three years under Article 7(3).

The sanction for failing to register

Article 18(1)(ç) of KVKK: an administrative fine “from 20,000 Turkish lira to 1,000,000 Turkish lira” is imposed on “those who act contrary to the obligation to register with and notify the Data Controllers' Registry provided for in Article 16”. Article 17(1) of the Regulation refers directly to that subparagraph.

Under Article 18(2) as amended by Law No. 7499, this fine is applied to the data controller. The newly added Article 18(3) clarifies the avenue of appeal: “Actions may be brought before the administrative courts against administrative fines imposed by the Board.”

A practical roadmap

Apply the sequence below inside your own organisation. Separating the publishing activity from the other activities at the very first step makes every step that follows easier.

text
VERBİS PRELIMINARY ASSESSMENT — NEWS WEBSITE

1. SEPARATION OF ACTIVITIES
   [ ] Publishing / news content ......... assess under Art. 28(1)(c)
   [ ] Membership / subscription ......... the whole Law
   [ ] Newsletter list ................... Law 6698 + Law 6563
   [ ] Comment system + IP logs .......... the whole Law
   [ ] Employee / reporter HR files ...... the whole Law
   [ ] Advertising, analytics, metrics ... the whole Law
   [ ] Contact / imprint forms ........... the whole Law

2. INVENTORY (Reg. Art. 5(1)(ç))
   For each activity:
   - data category         : ...........................
   - category of subjects  : ...........................
   - purpose of processing : ...........................
   - legal ground          : KVKK Art. 5(2)(...) or explicit consent
   - recipients            : ...........................
   - transfer abroad       : yes / no
   - maximum retention     : ....... months/years
   - measures taken        : ...........................

3. CHECKING THE REGISTRATION OBLIGATION
   [ ] Does the activity fall under one of the four subparagraphs of Reg. Art. 15?
   [ ] Am I within the scope of a Board exemption decision in force?
       (No thresholds in the Law — verify from the current Board decision)

4. AFTER REGISTRATION
   [ ] Retention and destruction policy prepared (Erasure Reg. Art. 5)
   [ ] Periodic destruction interval set (max 6 months — Art. 11(2))
   [ ] Privacy notices placed on every form (Art. 10)
   [ ] Request channel opened, 30-day response flow built (Art. 13(2))
   [ ] Internal 7-day alert built for change notifications (Reg. Art. 13)

The outputs of this inventory work feed directly into the content of the site's privacy notice for reader data; derive the two documents from a single data map rather than separately. The same map lets you determine the scope of a personal data breach notification within minutes if there is a leak. VERBİS registration is only one line item alongside these; track it holistically, together with headings such as the imprint, the notification of the responsible editor and content retention, through the legal compliance checklist for internet news sites. If you send newsletters, assess the consent requirement for newsletters separately.