KVKK Compliance Consulting: VERBIS, Policies and Audit Step by Step

TL;DR

KVKK compliance is not a one-time form-filling exercise, it is a living management system. Every organization operating in Turkey that processes personal data is obligated as a data controller under Law No. 6698 on the Protection of Personal Data (KVKK). In this article we walk through every compliance step in order, from VERBIS registration to the policy set, and from the data inventory to internal audit. The governing framework is the guidance issued by the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) and the operational manual for VERBIS. For a practical checklist on breach management, see our KVKK data breach notification article. For technical infrastructure compliance, see our how to obtain ISO 27001 guide, and for the forensic dimension, our Digital Forensics Process 2026 content.

Core Articles of the KVKK Framework

The starting point of compliance is the law itself. A manager does not need to memorize it, only to understand the logic of each article.

  • Article 4: General principles of personal data processing. Lawfulness, accuracy, a specific and legitimate purpose, proportionality, and retention for a limited period.
  • Article 5: Conditions for processing personal data. Explicit consent is the rule, but non-consent grounds also exist, such as being expressly provided for by law, the formation of a contract, a legal obligation, and legitimate interest.
  • Article 6: Special categories of personal data. Data such as health, biometrics, religious belief, union membership, and criminal convictions. Processing this category is subject to stricter conditions.
  • Article 12: Obligations regarding data security. Administrative and technical measures, auditing, and notification where a breach is detected.
  • Article 28: Exceptions. Processing that is not fully automated and is not part of any filing system, along with limited cases such as national security, crime prevention, and statistics.

Compared with the GDPR framework, KVKK is largely aligned, but it diverges on points such as the cross-border transfer regime and the definition of special category data.

Distinguishing the Data Controller from the Data Processor

These are the two roles most often confused in compliance projects.

  • Data controller: The party that determines the purposes and means of processing. The company owner, an institution, an association, or a government body.
  • Data processor: The party that processes data on behalf of and under the instructions of the controller. A cloud provider, a payroll firm, or a call center.

Engaging an external service without clearly setting out the contractual obligations means that all responsibility stays with you. In vendor contracts, the processor role, the limits of instructions, the sub-processor regime, and the deletion obligation must all be stated explicitly.

Who Is Required to Be KVKK Compliant?

A common misconception is the "we are a small company, this does not concern us" approach. That is not correct.

  • Every data controller established in Turkey is within scope.
  • Even an entity established abroad that processes data relating to people in Turkey must appoint a representative for the foreign data controller.
  • Sole traders, self-employed professionals, associations, and foundations are also within scope.
  • Keeping records only in physical form is not an automatic exemption. If the records form a systematic filing structure, the law applies.

For the VERBIS registration obligation, the thresholds set by the Authority based on employee count, annual turnover, or field of activity apply. A data controller below the threshold is exempt only from registration, not from compliance.

VERBIS Registration: Step by Step

VERBIS is the electronic registry in which data controllers declare their processing activities to the Authority. The registry pages are reached via VERBIS.

  1. Appoint a representative: Designate an internal contact person. This must be an employee or an authorized representative of the company, not an external proxy.
  2. Apply via e-Devlet: The representative logs in to the system through e-Devlet and enters the company details.
  3. Complete the form from the data inventory: Registration cannot be done without an inventory. Inventory first, then VERBIS.
  4. Data categories: Select which headings are processed, such as identity, contact, finance, health, and employee personnel records.
  5. Processing purposes: Human resources management, contract processes, marketing, legal obligations, and so on.
  6. Recipients of transfers: The Tax Office, SGK (Social Security Institution), a bank, a cloud provider, a consultant, a company abroad.
  7. Cross-border transfer: If a transfer takes place, to which country, and on the basis of which undertaking or decision?
  8. Retention period: The average retention period for each category.
  9. Security measures: The applicable measures from the security criteria list set by the Authority.
  10. Approval and registration: Registration is completed through the system and a registry number is issued.

Any changes after registration must be reflected in the system within 7 days. Filling in VERBIS once and forgetting it is one of the most common deficiencies we encounter during audits.

The 11+ Policy Set

KVKK compliance is built on written policies. Treat the set below as the minimum.

  1. KVKK General Policy: The overarching document, the umbrella for all other procedures.
  2. Privacy Notice Management Policy: Which notice is shown on which channel.
  3. Explicit Consent Management Policy: Obtaining consent, withdrawal, and proof.
  4. Personal Data Retention and Destruction Policy: Periods, and a periodic destruction calendar.
  5. Data Breach Response Procedure: 72 hours, who, what, and how.
  6. Employee Personal Data Processing Policy: Personnel records, performance, and monitoring.
  7. Customer Personal Data Processing Policy: CRM, after-sales, and marketing.
  8. Supplier and Business Partner Policy: Vendor due diligence and contract terms.
  9. Information Security Policy: Access, passwords, logs, and backups.
  10. BYOD and Remote Work Policy: Corporate data on personal devices.
  11. Cookie and Web Data Processing Policy: Tracking technologies on the website.
  12. Video and Audio Recording Policy: CCTV and the call center.
  13. Data Subject Request Management Procedure: The 30-day response period.

It is not enough for the policies to merely exist in print. There must also be training and assessment records that prove employees have read them.

Building the Data Inventory

The inventory is the engine of compliance. In practice, the following sequence works well.

  • Process-based approach: Handle each process separately, such as HR, sales, procurement, marketing, IT, legal, and finance.
  • Source scan: Scan the forms, software, spreadsheets, emails, and shared folders used in each process.
  • Extract data items: List each item one by one, such as first name, surname, national ID number, phone, email, IP, location, and medical report.
  • Map the legal basis: For each data item, record the basis under Article 5 or 6.
  • Transfer map: Who sends data to which party and to which country?
  • Retention period: Set by legislation (for example, 10 years for SGK), set by contract, or defined by policy.
  • Risk score: High, medium, or low, based on data volume, special category status, and external sharing.

The inventory can be started in Excel and later migrated to GRC tools. What matters is keeping it alive.

Explicit Consent and Privacy Notices

These two concepts are constantly confused.

  • Privacy notice: The controller's duty to inform. It always applies and is independent of consent.
  • Explicit consent: Required only when there is no other basis under Article 5/2 or 6/3.

Sample privacy notice skeleton (general)

"Our company processes the first name, surname, contact, and billing information it collects from you for the purposes of forming the contract and fulfilling legal obligations. The data is shared on a limited basis with our accountant and official institutions. It is destroyed at the end of the statutory retention period. You may exercise your rights under Article 11 via info@..."

Sample explicit consent skeleton (general)

"I give my explicit consent to the processing of my phone and email information for the purpose of sending me commercial electronic messages. I understand that I may withdraw this consent at any time."

On a form, the privacy notice and the consent must be separate checkboxes. A pre-ticked checkbox does not count as valid consent.

Retention and Destruction Policy

The most common mistake regarding retention periods is keeping all data far beyond the time it is needed. Example ranges:

  • Customer billing data: 5 years, driven by tax legislation.
  • SGK notification data: 10 years.
  • Job application CVs: A reasonable period after the position is closed, generally 6 to 12 months.
  • CCTV recordings: Generally 30 to 60 days, varying by line of business.
  • Marketing permissions: Until the permission is withdrawn.

Periodic destruction is carried out at intervals not exceeding 6 months, and destruction records are archived. A shredder is mandatory for physical documents, and secure erasure plus disk destruction records are mandatory for digital data.

Internal Audit and Continuous Control

Writing policies is not enough, you also have to audit them. A recommended cadence:

  • Monthly: Sampling of access logs, and request response-time metrics.
  • Quarterly: Vendor compliance checks, and a training attendance report.
  • Semi-annually: Inventory update, and periodic destruction.
  • Annually: A full KVKK internal audit, a report to senior management, and a check that VERBIS is up to date.

Audit findings should be tracked with a Corrective and Preventive Action (DÖF) form and archived with closure evidence.

Employee Training

A significant portion of KVKK breaches stem not from a technical vulnerability but from employee behavior.

  • KVKK orientation in the first week for every new hire.
  • Refresher training for all staff at least once a year.
  • Additional specialized training for high-risk units (HR, IT, the call center).
  • Phishing simulations and digital hygiene drills.
  • Recording training attendance and assessment scores.

Without training, a policy stays on the shelf.

Cross-Border Data Transfer (Article 9)

As cloud services have spread, cross-border transfer has become one of the most critical items in compliance.

  • If the destination country has been declared a safe country by the Authority, the transfer is carried out under a more flexible regime.
  • Transfers to countries not on that list are made using instruments such as an approved undertaking or binding corporate rules.
  • The data subject's explicit consent alone is not a sustainable instrument for continuous transfers.
  • The use of US-based SaaS should be supported by contractual and technical measures (encryption, key management, data minimization).

A Quick Look at the Breach Process

When a breach occurs, the clock starts at 72 hours.

  1. Detection and classification of the incident.
  2. Determining the scope and the affected data subjects.
  3. Urgent technical measures and stopping the leak.
  4. Notification to the Authority as soon as possible and within 72 hours at the latest.
  5. Informing affected individuals within a reasonable period.
  6. Chain of custody and a digital forensics examination for the legal dimension.
  7. Root cause analysis and corrective and preventive action.

For a step-by-step form and process, our KVKK data breach notification article provides a detailed template. For the evidentiary aspect of the incident, follow the chain of custody flow in our Digital Forensics Process 2026 content.

Patterns from KVKK Board Decisions

Without naming companies, the following are recurring patterns drawn from the publicly available decision summaries published by the Authority.

  • Fulfilling the privacy notice obligation in an incomplete manner or with generic wording.
  • Making explicit consent a condition of the service.
  • VERBIS registration being incomplete or not updated.
  • Failing to respond to data subject requests within 30 days.
  • Suffering a leak due to inadequate data security measures.
  • Sharing a third party's data as a result of an employee's unauthorized access.
  • Failing to disclose the recording purpose in advance at the call center.

The Board's decision summaries can be reached on the KVKK Authority website.

Factors That Determine Fines

When setting an administrative fine, the Board considers several core factors.

  • The nature and severity of the breach.
  • The number of data subjects and whether special category data is involved.
  • The degree of intent, negligence, or carelessness.
  • The capacity of the data controller.
  • The history of prior breaches and the attitude toward cooperation.
  • The corrective measures taken.

Active cooperation and a swift root cause resolution are decisive in the scale of the administrative penalty.

Combined Compliance with ISO 27001 and 27701

KVKK is not just a legal compliance project, it is also an information security management system. For this reason, mature companies in Turkey run three layers together.

  • KVKK: The legal framework, the policy set, and VERBIS.
  • ISO 27001: The information security management system, with technical and administrative controls.
  • ISO/IEC 27701: The privacy information management system, a privacy layer built on top of ISO 27001.

The combination of the three layers creates the impression of a "mature data controller" during audits. For the certification process, we shared a detailed roadmap in our how to obtain ISO 27001 article. In public sector projects, the Information and Communication Security Guide published by CBDDO also provides an audit framework that complements this trio.

Frequently Asked Questions (FAQ)

1. My company has 5 employees, is VERBIS registration mandatory? If you fall below the threshold you may be exempt from registration, but KVKK compliance is still mandatory. A policy set and an inventory must be prepared.

2. Is explicit consent always required? No. If there is another basis such as a contract, a legal obligation, or legitimate interest, consent is not required. Consent is typically needed only for marketing and special category data.

3. If I use a cloud service abroad, am I in breach? It is not an automatic breach. It can be made compliant with the right contract, technical measures, and choice of transfer regime.

4. Does the employer have the right to read an employee's email? If a notice has been given in advance, the policy defines monitoring authority, and proportionality is maintained, it is possible on a limited basis.

5. How long can I keep CCTV footage? It varies by line of business. The typical range is 30 to 60 days. It must be stated in the policy and there must be a notice sign at the entrance.

6. When a data subject request arrives, how quickly must I respond? Within 30 days at the latest. It is free of charge, although the Authority's tariff allows a small fee in certain exceptional cases.

7. Can a KVKK audit happen, and how does it start? The Board may launch an audit on its own initiative or upon a complaint. The first step is usually a written request for information.

8. I have an ISO 27001 certificate, is that enough for KVKK? No. It provides the technical foundation, but the legal compliance set (policies, VERBIS, privacy notices) must be completed separately.

9. When I engage a consultant, does responsibility pass to the consultant? No. The data controller status always remains with the company. The consultant sets up and maintains the process, but legal responsibility is not transferred.

KVKK Compliance with DSET

Our team at Hacettepe Teknokent in Ankara runs KVKK compliance projects end to end, from VERBIS registration to the policy set and internal audit. Whether you need a setup from scratch, the maturing of existing compliance, or a post-breach recovery project, let's schedule a free initial consultation.

Phone: +90 536 662 38 09 Location: Hacettepe Teknokent, Ankara

In the first meeting we measure your company's current compliance maturity and lay out your priority gaps and a 90-day roadmap.


Sources: Law No. 6698 (KVKK), KVKK Authority, VERBIS, GDPR, ISO/IEC 27701, CBDDO