Data Controller Representative in Türkiye: What Foreign Companies Need to Know Under KVKK and VERBİS

Data Controller Representative in Türkiye: What Foreign Companies Need to Know Under KVKK and VERBİS



A data controller representative in Türkiyeveri sorumlusu temsilcisi in Turkish—is a Türkiye-based person or entity appointed to represent a relevant foreign-established data controller for the limited matters specified in the Regulation on the Data Controllers’ Registry.

__wf_reserved_inherit
Foreign data controller connecting with Türkiye’s data protection authority, individuals and VERBİS through a local representative.

The representative provides a local interface for communications with Türkiye’s Personal Data Protection Authority, data-subject applications under Article 13 of Law No. 6698, and work relating to the Data Controllers’ Registry, commonly known through its online system, VERBİS.

The important qualification is this: a foreign company does not need a representative merely because it has users or customers in Türkiye. The company must first assess whether the Turkish Personal Data Protection Law No. 6698 (KVKK) applies to the relevant processing and whether it is required to register with the Registry. If the company is a foreign-established controller that is required to register, the representative route under the VERBİS Regulation becomes relevant.

Quick guide

Türkiye DCR in 60 seconds

A limited local representative role under the VERBİS framework—not a transfer of the foreign controller’s compliance responsibility.

01

Legal basis

Regulation on the Data Controllers’ Registry, especially Article 11.

02

Who it serves

A relevant controller established outside Türkiye and required to register.

03

Why it exists

To provide a Türkiye-based interface for the Authority, individuals and Registry work.

04

Core function

Receive, record, forward and relay communications; carry out Registry transactions.

05

Not the same as

An irtibat kişisi, DPO, GDPR Article 27 representative, lawyer or general agent.

06

Responsibility

The foreign controller retains its underlying KVKK duties and substantive decisions.

Do not use a shortcut: Turkish users or customers alone do not establish that an appointment is required. Assess KVKK scope and VERBİS registration first.

What is a Data Controller Representative in Türkiye?

The Regulation defines a veri sorumlusu temsilcisi as a Türkiye-established legal person or a qualifying natural person authorized to represent a controller not established in Türkiye, at minimum, for the matters listed in Article 11(3).

In practical terms, the role gives the foreign controller a reachable interface in Türkiye. The Authority can communicate with the controller through the representative, and individuals can route qualifying Article 13 applications through that representative unless the Board has determined another method.

“Data Controller Representative” or “DCR” is a useful English description, but it should not be treated as a broader corporate title. The representative is not automatically the controller’s general legal representative, local branch, data protection officer, lawyer, or decision-maker.

The role exists to make regulatory and data-subject communications workable when the controller is established outside Türkiye. It also supports the foreign-controller route for Registry work. It does not relocate the controller’s accountability.

Who may need a representative?

The safest way to approach this question is as a sequence, not as a slogan.

Assess before appointing

This is a sequence of legal questions, not a “Turkish users = representative” rule.

Controller status

Does the foreign entity determine the purposes and means of the processing at issue?

KVKK applicability

Do the establishment, activities and processing links bring the activity within Turkish law?

Registry obligation

Is that controller required to register after applying the current statutory and Board framework?

Outcome

If all three answers support registration, the foreign-controller route under the Regulation requires the Registry process to be carried out through a data controller representative in Türkiye.

This component is a high-level triage model. It is not a substitute for a case-specific legal assessment.

1. Is the foreign organization acting as a data controller?

The controller is the person or entity that determines the purposes and means of processing personal data and is responsible for establishing and managing the relevant data-recording system. A foreign vendor processing data only on documented instructions may instead be acting as a processor for a particular activity. Roles must be assessed processing by processing.

2. Does KVKK apply to the relevant processing?

KVKK does not set out a single, detailed territorial-scope formula equivalent to GDPR Article 3. The Board has considered the Turkish connection in specific decisions. For example, in its Decision No. 2020/471, it treated the activities of a foreign bank’s representative office in Türkiye as closely connected with the bank’s processing and found the foreign bank subject to KVKK and Registry registration in that context.

That decision is useful, but it should not be turned into a universal rule based only on Turkish users, Turkish-language marketing, website availability, or one isolated commercial contact. The organization’s establishment and operational links, the processing at issue, the people affected, and relevant Board decisions all need to be considered together.

3. Is the controller required to register with the Registry?

KVKK Article 16 establishes the Registry framework and gives the Board power to create registration exceptions based on objective criteria. The Board’s registration decisions have treated controllers established outside Türkiye as a distinct category. For that reason, domestic employee-count or balance-sheet exemptions should not be applied mechanically to a foreign controller.

The correct question is not simply whether the foreign company is small. It is whether the particular controller and processing fall within KVKK and the current registration framework, taking account of statutory exclusions and Board-created exceptions that actually apply.

The practical conclusion

Where a foreign-established organization is acting as a controller, KVKK applies to the relevant processing, and the controller is required to register, the Regulation provides for registration through a data controller representative in Türkiye. If any of those propositions is uncertain, scope should be assessed before an appointment is presented as legally mandatory.

Who can act as the representative?

Under the Regulation, the representative may broadly be:

  • a legal person established in Türkiye; or
  • a qualifying natural person under the Regulation.

The regulatory definition refers to a Türkiye-established legal person or a Turkish-citizen natural person. Board Decision No. 2020/542 also describes a natural-person representative as a Turkish citizen resident in Türkiye. Organizations considering a natural-person appointment should therefore verify the current identity, residence, and system requirements before proceeding.

The foreign controller’s authorized body or person adopts the appointment decision. A certified copy of that decision is submitted to the Authority by the representative during the Registry application. The appointment decision must include, at minimum, the functions in Article 11(3).

Selection should not be based only on having a Turkish address. The representative needs reliable availability, secure recordkeeping, clear bilingual escalation, and enough KVKK/VERBİS familiarity to route time-sensitive communications correctly.

What does the representative do?

THE CONTROLLER RETAINS SUBSTANTIVE DECISION-MAKING AND COMPLIANCE RESPONSIBILITY.
AUTHORITY
Send Correspondence
Return Response
REPRESENTATIVE
Forward Correspondence
Relay Response
FOREIGN
CONTROLLER
INDIVIDUAL
ARTICLE 13 APPLICATION
Return Response
REPRESENTATIVE
Forward Application
Relay Response
CONTROLLER
CONTROLLER
APPROVED PROCESSING
INFORMATION
REPRESENTATIVE
HANDLE
VERBİS-RELATED
WORK


Article 11(3) sets a minimum mandate. The appointment decision must cover the representative’s authority to:

  1. Receive Authority notices and correspondence on behalf of the controller.
  2. Forward Authority requests to the controller and transmit the controller’s response back to the Authority.
  3. Receive Article 13 applications from data subjects on behalf of the controller and forward them to the controller, unless the Board has set another procedure.
  4. Deliver the controller’s response to the data subject, unless the Board has set another procedure.
  5. Carry out Registry-related work and transactions on behalf of the controller.

The verbs matter. For Authority requests and data-subject applications, the Regulation primarily describes a receive–forward–return channel. It does not say that the representative replaces the controller as the party that investigates the facts, determines the legal position, or owns the response.

A clear line between routing and deciding

Representative mandate

Receive, forward and maintain

  • Accept Authority notices and correspondence
  • Forward Authority requests and controller responses
  • Receive and forward Article 13 applications
  • Relay the controller’s response to the applicant
  • Carry out Registry-related work
Controller responsibility

Investigate, decide and remediate

  • Determine processing purposes, means and legal grounds
  • Decide the outcome of data-subject requests
  • Assess incidents and notification duties
  • Select transfer mechanisms and security measures
  • Keep Registry information accurate and lawful

What does the representative not automatically do?

Appointment under Article 11 does not, by itself, authorize the representative to:

  • decide whether to grant or reject a data-subject request;
  • determine the controller’s lawful bases or retention periods;
  • decide whether an incident is reportable;
  • select or approve an international-transfer mechanism;
  • rewrite the controller’s notices, contracts, or internal policies;
  • make every filing or sign every document for the company;
  • conduct a regulatory defence, lodge an appeal, or litigate;
  • act as the controller’s DPO, lawyer, branch, or general corporate representative; or
  • assume the controller’s responsibility for KVKK compliance.

Some of these services may be covered by a separate contract, power of attorney, professional engagement, or internal delegation where legally appropriate. They are not automatic consequences of the statutory representative appointment. Regulated legal services and formal legal opinions should be handled by appropriately qualified Turkish counsel.

The controller remains responsible

The foreign organization remains the data controller. It continues to determine the purposes and means of processing and remains responsible for the accuracy, currency, completeness, and lawfulness of the information submitted to the Registry.

It also remains responsible for the wider KVKK programme: processing conditions, transparency, data-subject rights, security measures, retention and deletion, international transfers, breach assessment and notification, processor governance, and implementation of Board decisions.

The Regulation expressly states that Registry registration does not remove the controller’s other KVKK obligations. The Authority’s official Registry information likewise explains that appointing a representative does not eliminate the foreign controller’s responsibility.

Appointment is therefore a compliance component, not a certificate of compliance.

Foreign Data
Controller
Türkiye Data Controller
Representative
Limited Local Interface
For data subjects & authority (KVKK)
VERBİS Workflow
İrtibat Kişisi
(Contact Person)
Does not have
representative authority.
Data Protection
Officer (DPO)
Distinct Appointment
Advisory & internal compliance
GDPR Article 27
Representative
Distinct Appointment
For certain non-EU controllers/processors
(EU legal framework)

DCR vs. irtibat kişisi, DPO and GDPR representative

These titles are often grouped together because they involve privacy communications. They are not interchangeable.

Four roles that should not be confused
Role Framework Primary purpose What it does not automatically mean
Data Controller Representative KVKK / VERBİS Regulation, Article 11 Local Authority and data-subject communication interface; Registry work for a relevant foreign controller DPO, lawyer, general agent, controller, or substantive decision-maker
İrtibat kişisi VERBİS Regulation Named natural person entered in the Registry to support communications and Registry operations Authorized representative of the controller; Article 11(4) expressly limits this
Data Protection Officer Organization’s applicable governance framework; GDPR where its DPO rules apply Privacy advice, monitoring, oversight and regulator/data-subject contact within the applicable mandate The Turkish Article 11 representative or the Registry contact person
GDPR Article 27 Representative EU GDPR, Articles 3(2) and 27 EU representative for certain non-EU controllers or processors within GDPR’s territorial framework A Türkiye DCR appointment or evidence that KVKK/VERBİS applies

The same provider may perform more than one role under separate appointments, but the legal basis, scope, conflicts and records should remain distinct.

DCR and irtibat kişisi are separate roles

For a controller established outside Türkiye, the representative enters an irtibat kişisi in the Registry. The irtibat kişisi must be a natural person and supports communication and VERBİS operations. Article 11(4) expressly says that this contact person is not authorized to represent the controller under the Law or Regulation.

The representative is therefore the formal local interface described by Article 11(3); the contact person is the named individual used within the Registry workflow. If the representative is a legal person, the distinction is especially clear: the company may be the representative while a specific natural person is entered as the contact person.

DCR and DPO are not the same

A data protection officer, where an organization has or chooses one, is generally a privacy-governance and oversight role. The Turkish DCR is a specific representative role under the Registry Regulation. Appointment as DCR does not automatically create a DPO mandate, and appointing a DPO does not automatically satisfy the Turkish representative route.

DCR and GDPR Article 27 representative are not the same appointment

The GDPR Article 27 representative belongs to the EU legal framework and is tied to GDPR Article 3(2). Türkiye’s representative is based on KVKK and the VERBİS Regulation. A provider might contractually offer both in the relevant jurisdictions, but each appointment must be assessed and documented under its own law.

How appointment and VERBİS registration work

The process can be understood at a high level in five stages.

Appointment and VERBİS: the high-level route

The filing should follow a documented scope decision and an inventory-based preparation process.

  1. Assess scope

    Confirm the entity, controller role, KVKK applicability and Registry obligation.

  2. Prepare the processing information

    Build or validate the inventory information that will support the Registry notification.

  3. Adopt the appointment decision

    Include the minimum Article 11(3) authorities and prepare the certified copy.

  4. Complete the Registry route

    The representative performs the foreign-controller VERBİS work and enters the contact person.

  5. Operate and maintain

    Keep secure routing, evidence, escalation contacts and Registry information current.

Important: a completed appointment or Registry entry does not prove that the controller’s wider processing activities comply with KVKK.

1. Confirm scope and registration status

Determine the relevant legal entity, whether it acts as controller for the processing in question, whether KVKK applies, and whether the entity is required to register. Do this before treating representative appointment as a box-ticking exercise.

2. Prepare the controller’s information

Registry information must be based on the controller’s personal data processing inventory. The controller should therefore map its processing purposes, data-subject groups, data categories, recipients, contemplated foreign transfers, retention periods, and security measures before completing the notification.

3. Adopt the appointment decision

The foreign controller’s authorized body or person adopts a decision appointing the representative. The decision should identify the parties and contain at least the authorities listed in Article 11(3). The certified copy is submitted through the representative during registration.

4. Complete the foreign-controller Registry route

The representative carries out the Registry work for the controller and enters the irtibat kişisi information. The exact system steps and supporting documents should be checked against the current VERBİS interface and Authority guidance at the time of filing.

5. Maintain an operating channel

Registration is not the end of the relationship. The controller and representative need a live process for receiving, authenticating, recording, escalating, and closing Authority correspondence and data-subject applications. Registry information must also remain accurate and up to date.

What a workable DCR operating model looks like

The Regulation defines minimum legal functions, but dependable execution requires operational detail. A foreign controller should agree at least the following with its representative:

  • named business-hours and urgent escalation contacts;
  • a secure channel for transferring applications and Authority correspondence;
  • acknowledgement and forwarding targets that leave the controller time to act;
  • a responsibility matrix showing who verifies identity, searches systems, decides the outcome, drafts the response, approves it, and sends it;
  • bilingual templates and translation responsibilities;
  • an auditable register of receipt, forwarding, instructions, responses, delivery, and closure;
  • absence and business-continuity coverage;
  • rules for keeping VERBİS information aligned with the processing inventory; and
  • a separate incident-escalation path that does not assume the representative decides reportability.

These are recommended controls, not additional powers granted automatically by Article 11. The service agreement should distinguish the legal minimum, agreed operational support, excluded services, and matters requiring legal counsel or additional authorization.

Key points for foreign companies

  • Having Turkish users or customers does not, by itself, settle whether a representative is required.
  • Assess KVKK applicability, controller status, and VERBİS registration before concluding that appointment is mandatory.
  • Do not apply domestic employee or balance-sheet exemptions mechanically to a foreign-established controller.
  • The representative’s minimum mandate is centered on Authority communications, Article 13 application routing, response transmission, and Registry work.
  • The irtibat kişisi is a different role and cannot represent the controller under KVKK or the Regulation.
  • The controller keeps responsibility for substantive compliance decisions and underlying KVKK duties.
  • Appointment and registration do not, on their own, make an organization KVKK compliant.
  • A strong service arrangement adds secure routing, evidence, escalation, and continuity without misdescribing the representative as the controller’s lawyer or decision-maker.

Frequently asked questions

Does every foreign company with customers in Türkiye need a DCR?

No. Turkish customers or users are relevant facts, but not a complete legal test. The organization should assess whether it is a controller, whether KVKK applies to the processing, and whether Registry registration is required.

Is the representative responsible for answering data-subject requests?

The minimum Article 11(3) mandate is to receive and forward the application and relay the controller’s response, unless the Board establishes another procedure. The controller remains responsible for evaluating and concluding the request. Any broader drafting or case-management support should be defined separately.

Can the representative reject a request or decide that an incident is not reportable?

Not merely because it has been appointed as the Article 11 representative. Those are substantive decisions of the controller unless a separate and legally effective authority applies. Even then, the controller’s statutory responsibility does not simply disappear.

Is a lawyer required to act as DCR?

The Regulation does not define the role as lawyer-only. It permits an eligible legal person or natural person. Legal representation, legal opinions, appeals, and litigation are separate matters that may require Turkish counsel and appropriate authority.

Is a DCR the same as a GDPR Article 27 representative?

No. The two roles arise under different laws and have different scope and appointment logic. A company potentially subject to both frameworks should assess and document each role separately.

Does VERBİS registration complete KVKK compliance?

No. The Regulation expressly states that registration does not remove the controller’s other KVKK obligations. Registration is one part of a wider compliance programme.

Conclusion

A Turkish data controller representative is best understood as a limited but important regulatory and communication interface for a relevant foreign-established controller. The representative receives and routes Authority communications and Article 13 applications, relays the controller’s responses, and performs Registry work. The controller remains responsible for the processing and for its substantive KVKK decisions.

Foreign companies should therefore avoid both extremes: assuming that every connection with Türkiye requires a representative, or assuming that a small size or overseas establishment removes the issue. A defensible approach begins with a documented scope and registration assessment, followed—where required—by a correctly framed appointment and a practical operating process.

How Kooch can help

Kooch supports foreign-established controllers with a structured Türkiye DCR service covering appointment onboarding, VERBİS-related coordination, secure receipt and forwarding of Authority correspondence, Article 13 application routing, recordkeeping, and escalation. Scope-sensitive legal questions and formal legal opinions can be coordinated with qualified Turkish counsel where needed.

Legal position checked as of 21 August 2026. This article provides general legal information and research analysis; it is not a formal legal opinion (hukuki mütalaa) or advice for a specific organization.

Related guidance and practical next steps

Sources / References