As is well known, Article 16 of the Personal Data Protection Law No. 6698 (Law) states: “(1) Under the supervision of the Board, a Data Controllers’ Registry is kept by the Presidency, which is open to the public. (2) Natural and legal persons who process personal data must register with the Data Controllers’ Registry before starting data processing.” Accordingly, natural and legal person data controllers who process personal data are obliged to register and notify the Data Controllers’ Registry (Registry/VERBİS).
Additionally, in accordance with the provision in the Provisional Article 1 of the Law stating “Data controllers must register with the Data Controllers’ Registry within the time determined and announced by the Board,” all data controllers not covered by the exemption must have fulfilled their obligation to register and notify the Registry by 31.12.2021, as required by the decision of the Personal Data Protection Board (Board) dated 11.03.2021 and numbered 2021/238.
Furthermore, in line with the provision in the first paragraph of Article 18 of the Law stating, “(ç) An administrative fine ranging from 20,000 to 1,000,000 Turkish liras will be imposed on those who violate the obligation to register and notify the Data Controllers’ Registry as stipulated in Article 16,” and the provision in the third paragraph of the same article stating, “In the event that the actions listed in the first paragraph are committed within public institutions and organizations or professional organizations that qualify as public institutions, disciplinary actions will be taken against the relevant personnel and public officials, and the results will be reported to the Board,” the Board conducts ex officio investigations into data controllers who do not fulfill their obligation to register and notify the Registry.
In this context, of approximately 130,600 data controllers who were identified to have a registration and notification obligation to the Registry, around 16,350 who have not fulfilled this obligation are currently under VERBİS investigation by the Board in accordance with Article 18 of the Law. Following the investigation, administrative fines are imposed based on an algorithm table prepared according to the annual financial balance sheet active totals.
As a result of these investigations, as of 01.08.2024, an administrative fine of 503,935,000 TL has been imposed on both domestic and international natural and legal person data controllers who failed to fulfill their obligation to register and notify the Registry, and disciplinary measures have been applied to public institutions and organizations and professional organizations that qualify as public institutions.