Skip to content

How-to guide

Who must register in the data controllers' registry? Decide with three tests

The obligation runs through three separate tests, and passing any one is enough. The thresholds change yearly, the logic does not — the logic is what this explains.

Written for: Companies unsure whether registration applies, and aware that the wrong answer carries an administrative fineLast updated: 8 min read

In short

Does my company have to register in the data controllers' registry?

The registry obligation runs through three separate tests, and meeting one is enough: an annual average employee count threshold, an annual balance sheet total threshold, and having the processing of special category personal data as your main activity. Meeting none of them means you do not register — but your data protection obligations continue unchanged. Neuros runs this test before the architecture on corporate projects.

Steps

0 / 6 steps

  1. Run the special category test first

    If your main activity is processing data on health, sex life, biometrics, genetics, race, ethnic origin, religion, sect, philosophical belief, political opinion, dress, association/foundation/union membership or criminal conviction, the obligation arises with no threshold. Run this test first, because if you meet it the other two do not matter.

    Watch out: "Main activity" is what matters: keeping a medical certificate in a personnel file does not bring a company into this scope.

  2. Take the employee count from the filings

    Not an estimate or a payroll list: the basis is the employee count in the payroll declarations filed in at least seven of the twelve months of the completed year. Calculate the average with your accountant; that number is the first thing asked in an audit.

  3. Check the balance sheet total

    The measure here is not revenue but the total assets or total liabilities in the year-end financial statements. A company with high revenue but a small balance sheet does not meet this test, and the reverse is equally possible.

    Watch out: The threshold figures are updated annually; confirm the value in force on the authority's own page before applying.

  4. Build the inventory before registering

    What goes into the registry comes from the processing inventory: which data, for which purpose, on which lawful basis, retained how long, transferred to whom. Without the inventory the form cannot be completed; that is the long part of the work, not the registration itself.

  5. Appoint the contact person and register

    Data controllers established domestically appoint a contact person. That person is not the controller's representative; they handle communication with the authority. Registration cannot complete without the appointment.

  6. Keep the entries current

    Registration is not a one-off. When you start processing a new data category, make a new cross-border transfer or change retention periods, the entry has to be updated. An out-of-date entry is a different kind of violation from having no entry at all.

Who has to register with the data controllers' registry?

Three criteria decide the obligation, and they are alternatives to one another: meeting one is enough. An employee count threshold, a balance sheet total threshold, and having the processing of special category personal data as your main activity. Meeting none of the three means no registration obligation.

In practice the "alternative" relationship is what gets confused most. A company with few employees can be obliged because it crosses the balance sheet threshold; a health technology startup crossing neither becomes obliged through the third test. Looking at one test and concluding "we are out of scope" is the most common and most expensive mistake.

Searches this page answers

  • do we have to register with the data controllers registry
  • data controller registry requirements turkey
  • verbis registration under 50 employees
  • what happens if we do not register
  • who should be the contact person
  • how to build a personal data processing inventory
  • what counts as special category data
  • is registration free

What are the employee and balance sheet thresholds?

Because they change. Registration exemption thresholds are updated by board decisions, and most of the Turkish content online still carries a figure from several years ago — a company concluding "we are out of scope" against that figure is breaching its obligation without knowing it.

What is durable is the logic of the tests: three criteria, an alternative relationship, no threshold for special category data. Confirm the figure in force on the authority's own page along with the decision date, and keep that confirmation in your registration file. What an audit asks is how you knew the number.

If we are exempt from registering, are we exempt from the law?

Almost nothing. The registry is a register, not the law itself. A company below the threshold is equally obliged to meet its duty to inform, to obtain consent where consent is required, to apply technical and administrative measures, to set retention periods and delete once they pass, and to notify a data breach within the deadline.

The typical scenario in companies that miss this distinction: nothing is done because there is no registration obligation, then a breach happens and the audit finds neither an inventory, nor a privacy notice, nor a record of measures. What produces the penalty is not the absence of the registration but the absence of those.

How do you build a personal data processing inventory?

Every field the registry form asks for — data categories, processing purposes, lawful bases, recipient groups, retention periods, cross-border transfers — comes from the personal data processing inventory. A company without one can only fill the form by guessing, and that guess becomes evidence against it in every later audit.

The practical way to build an inventory is to work from the systems: which software holds personal data, which fields each one has, where the data comes from and where it goes. HR, accounting, CRM, e-commerce, the support system and camera recordings come out near the top of the list in almost every company.

Does a foreign company have to register?

Data controllers not established in the country fall under a different regime: they must appoint a representative and register through them. A subsidiary of a foreign group is assessed on its own legal personality — a group registration does not remove the subsidiary's obligation.

How long does registration take?

The registration itself is an hour's work. What sets the timeline is the inventory: a few days in a company with few systems, weeks in an organisation with many. The right order is inventory, privacy notices, retention and destruction policy, then registration; the reverse order speeds up the registration and makes its content wrong.

Is registration free?

Registration is free and done directly through the authority's own system. Intermediaries charging a fee are selling the preparation rather than the registration: building the inventory, privacy notices, retention and destruction policy. That work genuinely takes effort, but you do not have to pay for the registration itself. If you work with an intermediary, ask for the pricing line by line.

Are a privacy notice and consent the same thing?

No, and confusing them is one of the more expensive mistakes. A notice is an information duty; it applies to every processing and needs no approval. Consent is a lawful basis; it is only needed when no other basis applies. Companies collecting consent for everything have to stop processing when consent is withdrawn — even where a contract or legitimate interest would have sufficed.

Does employee data need registering too?

It has to appear in the inventory, yes. HR data is the largest set of personal data in almost every company: personnel files, payroll, leave records, medical certificates, camera recordings. Holding a medical certificate does not by itself bring the company into the special category scope, but it has to appear as its own category in the inventory with a defined retention period.

Who should do the registration?

Whoever technically enters it, the responsibility sits with the data controller — the company. In practice the person running it is usually legal, compliance or IT; what matters is that the people who actually know what is in the inventory contribute. A record filled in by one person from guesswork does not hold up when compared against the systems in an audit.

The registry is a register, not the law itself; exemption from registering is not exemption from the obligations.

Sources

  1. 016698 sayılı Kişisel Verilerin Korunması KanunuT.C. Mevzuat Bilgi Sistemi · 2016
  2. 02Veri Sorumluları Sicili (VERBİS)Kişisel Verileri Koruma Kurumu · 2026
  3. 03Kişisel Veri Güvenliği Rehberi (Teknik ve İdari Tedbirler)Kişisel Verileri Koruma Kurumu · 2018

Frequently asked

Questions we get asked

You may. Employee count is only one of the three tests. If your annual balance sheet total exceeds the threshold in force, or if your main activity is processing special category personal data, you are obliged whatever your headcount. Most small teams working in health, biometric verification and similar fields come into scope through that third test.

Non-compliance with the registration obligation carries an administrative fine, and the amounts are revalued each year. In practice the heavier consequence is this: the absence of a registration usually comes together with the absence of an inventory, privacy notices and a record of measures, and in an audit or a breach the penalty arises from that whole rather than from one gap.

The contact person is not the controller's representative; they handle communication with the authority and hold no decision-making authority for the company. Placing an external consultant in that role increases the risk of a letter from the authority getting lost inside the company. In practice the right choice is the internal owner who actually runs the process.

A template gives a skeleton, not the content. The value of an inventory is in showing which fields your systems actually hold; categories copied from a template do not match when compared against the systems in an audit, and that leaves a worse impression than having no inventory at all. The right route is working backwards from the systems.

The party deciding why and how data is processed is the controller; the party processing on instruction is the processor. A software firm operating your system is usually a processor, and a written contract has to exist between you. That distinction also decides the registration obligation: as a processor you do not register in your own name, but your responsibility does not disappear.

Let's walk these steps together

We can stand alongside you while you apply any of this to your own project.