Single Blog Title

This is a single blog caption

GDPR Compliance Process for Companies: Information Notice, Explicit Consent, and VERBİS Obligations

Entrance

Today, companies are not merely commercial entities that offer goods or services. They are also structures that process a large amount of personal data belonging to customers, employees, suppliers, visitors, dealers, business partners, and website users. A company's collection of customer names, phone numbers, email addresses, delivery addresses, billing information, camera footage, employee personnel files, bank account information, health reports, IP addresses, or cookie data can be considered a personal data processing activity under the Law No. 6698 on the Protection of Personal Data.

Therefore, for companies, the GDPR compliance process is not simply about adding a "GDP text" to their website. A proper GDPR compliance effort should clearly demonstrate which personal data the company collects, for what purpose it processes this data, what legal grounds it relies on, to whom it transfers it, how long it stores it, how it destroys it, and what administrative and technical measures it takes for data security.

In particular, the information notice, the explicit consent notice , and the VERBİS (Personal Data Protection Authority) obligationare among the areas where companies make the most mistakes in the KVKK (Personal Data Protection Law) compliance process. Announcements published by the Personal Data Protection Authority in 2026 also emphasized that mixing explicit consent and information notices, using texts copied from other companies, and providing information with vague and misleading statements are frequently encountered legal violations.

What is the GDPR Compliance Process for Companies?

The KVKK (Personal Data Protection Law) compliance process involves bringing the company's personal data processing activities into compliance with Law No. 6698 and the Board's decisions. The aim of this process is not merely to prepare documents, but to make the company's data processing practices lawful, auditable, and sustainable.

For a company to be considered compliant with the Personal Data Protection Law (KVKK), it must first know what data it processes. For example, a textile company may process customer order information, employee payroll information, supplier account information, camera recordings, and website cookie data. A private healthcare institution, in addition to these, may also process special categories of personal data such as health data. Therefore, it is not correct to prepare a single, uniform KVKK text or a single compliance package for every company.

The KVKK (Personal Data Protection Law) compliance process varies depending on a company's field of activity, number of employees, annual financial size, data categories processed, whether it processes special categories of data, whether it transfers data abroad, and the structure of its digital systems. Therefore, the first step for companies is to create a personal data processing map.

Data Inventory Preparation

One of the fundamental steps in the GDPR compliance process for companies of a personal data processing inventory . The data inventory is the main document that systematically outlines the company's personal data processing activities. This inventory should include which personal data is processed, data subject groups, processing purposes, legal grounds, recipient groups, retention periods, parties to whom data is transferred, and security measures taken.

For example, a company's human resources department processes employee identification information, contact information, personnel files, salary information, and social security records. The sales department processes customer contact information and order history. The accounting department processes invoice and current account data. The IT department processes log records, IP addresses, and system access records. The security unit might process camera footage.

Therefore, in the GDPR compliance process, it is not sufficient for only the legal department or only the accounting department to work. Human resources, accounting, sales, marketing, IT, administrative affairs, and management departments must be evaluated together. Otherwise, the prepared disclosure statements will not reflect the company's actual data processing activities, and this will create legal risks.

What is a Privacy Notice?

The data protection notice is a document that informs the data subject whose personal data is being processed who is processing their data, for what purpose, on what legal grounds, by what method, and to whom their data may be transferred. The obligation to provide information is not dependent on the request of the data subject. Even if the individual does not explicitly request it, the data controller company is obligated to provide information before commencing personal data processing or at the latest at the time the data is obtained.

The Personal Data Protection Authority's announcements regarding its obligation to inform data state that clear, simple, and understandable language should be used in the information texts; vague, incomplete, misleading, or general statements should be avoided. Furthermore, it is stated that "processing purpose" and "legal basis" are separate elements, and it must be clearly indicated which processing condition under Article 5 or 6 of the Law the data processing is based on.

Therefore, a general statement such as "your personal data is processed within the scope of the KVKK (Personal Data Protection Law)" is insufficient in the privacy policy. The correct text should use clear and concrete expressions, such as "your identity and contact information are processed for the purpose of ensuring product delivery, based on the legal grounds of contract performance.".

How should a Privacy Policy be prepared?

When preparing data protection notices for companies, each data processing activity should be evaluated separately. Separate notices may be needed for employees, customers, suppliers, visitors, and website users. This is because the data of each group of individuals is not processed for the same purpose or based on the same legal grounds.

An employee information notice might cover topics such as payroll, social security reporting, personnel files, benefits, occupational health and safety, performance evaluation, and workplace security. A customer information notice could explain ordering, payment, delivery, invoicing, customer support services, and business communication processes. A camera information notice should also specify the security purpose, recording area, storage duration, and the possibility of transferring data to authorized persons.

It is extremely important that the privacy policy is consistent with the company's actual practices. If the company does not transfer data abroad, the privacy policy should not give the impression that it does. If the company does not process data for marketing purposes, stating in the policy that it is for marketing purposes in a general way may be incorrect. The Authority explicitly considers policies copied from other companies and not adapted to the data controller's own activities as problematic practices.

What is an Explicit Consent Form?

Explicit consent is an informed and free-willed approval given by an individual regarding a specific matter. However, one of the most common mistakes in practice is the belief that explicit consent is required for every data processing activity. In fact, under the KVKK (Personal Data Protection Law) system, explicit consent is only one of the conditions for processing personal data. The law also includes other conditions for processing personal data besides explicit consent.

For example, processing bank account information for employee salary payments can, in many cases, be considered within the scope of the performance of the employment contract or the employer's legal obligation. Obtaining a customer's delivery address may be necessary for the performance of a sales contract. Storing billing information may be based on a legal obligation arising from accounting and tax regulations. In such cases, obtaining explicit consent may not be required.

Conversely, explicit consent may be required for advertising, marketing, commercial electronic communications, certain processing activities of sensitive personal data, the use of biometric data, or certain international data transfer processes. Therefore, companies should first determine the legal basis for the data processing activity and only use explicit consent in areas where it is truly necessary.

The Information Notice and the Explicit Consent Notice must be separate

The information notice and the explicit consent notice are not the same thing. The information notice provides information to the data subject. The explicit consent notice, on the other hand, expresses the individual's approval for a specific data processing activity. Combining these two texts into a single document poses a serious risk in the application of the Personal Data Protection Law (KVKK).

In its public announcement regarding the Personal Data Protection Board's principle decision dated February 18, 2026, numbered 2026/347, it was stated that presenting the explicit consent text and the information text intertwined is one of the legal irregularities frequently encountered in the notifications and complaints received by the Board. The Board clarified that if the data processing activity is based on explicit consent, the information text and the explicit consent text should be prepared separately under different headings; even if they are to be placed on the same page, separate declarations should be obtained for both texts.

In this context, companies should avoid ambiguous statements such as, "I have read the privacy policy and I consent to the processing of my personal data." For the privacy policy, feedback such as "I have read it, I am informed" is sufficient. Explicit consent, if necessary, should be obtained through a separate text and a separate approval mechanism.

What should be considered when obtaining explicit consent?

For explicit consent to be valid, the data subject must clearly understand what they are consenting to. Consent must be specific to a particular matter, not general or unlimited. Statements such as "I consent to the processing of my personal data for any purpose" are legally risky. Instead, the purpose of data processing must be clearly stated.

For example, if an e-commerce company wants to send promotional SMS messages to its customers, the consent form must clearly state that the phone number will be processed for advertising, campaign, and promotional purposes. If an employer wants to share an employee's photo on the company's social media accounts, the purpose, platform, and scope of this sharing must also be clearly explained.

It is also important that explicit consent is given freely. Individuals should not be forced to give consent, nor should they be deprived of essential services for refusing to consent. Especially in employer-employee relationships, where there is an imbalance of power between the parties, it is crucial to carefully assess whether explicit consent obtained from employees is truly based on their free will.

What is VERBIS?

VERBİS is an abbreviation for the Data Controllers Registry Information System. Data controllers meeting certain conditions are obligated to register with VERBİS before commencing personal data processing. Article 16 of Law No. 6698 states that natural and legal persons processing personal data have an obligation to register with the Registry, but exceptions may be granted for certain data controllers based on objective criteria determined by the Board.

VERBİS registration ensures that the company provides the Authority with general information regarding its personal data processing activities. However, there is an important point to note here: registration with VERBİS alone does not mean compliance with the Personal Data Protection Law (KVKK). Even if a company registers with VERBİS, it may continue to violate the KVKK if it fails to fulfill its obligation to inform, incorrectly conducts explicit consent processes, does not take data security measures, or has not regulated its storage and destruction processes.

Therefore, VERBİS is only one part of the GDPR compliance process. Companies must first prepare their data inventory correctly, and then submit their VERBİS notifications in accordance with this inventory.

Which companies are required to register with VERBİS?

For VERBİS (Personal Data Protection Authority) obligations, the number of employees, the total annual financial statement, and the main field of activity of the company are important. According to current Board decisions, data controllers who are natural or legal persons and whose main field of activity is not the processing of special categories of personal data, and who have fewer than 50 employees annually and a total annual financial statement of less than 100 million TL, are exempt from the obligation to register with the Registry.

In addition, an exception was made for some small-scale data controllers whose main activity is the processing of special categories of personal data, with the Board Decision dated 04.09.2025 and numbered 2025/1572. Accordingly, data controllers who are natural or legal persons, whose main activity is the processing of special categories of personal data, but who have fewer than 10 employees annually and whose total annual financial balance is less than 10 million TL, are also exempted from the registration obligation in the Registry.

Furthermore, the Authority's announcement dated January 12, 2026, stated that for data controllers who do not keep books on an accrual basis, only the annual number of employees criterion will be considered, as information on the total annual financial balance is not available.

At this point, it is incorrect for companies to think they are exempt from VERBİS obligations simply by saying "we are a small business". The company's main field of activity, whether it processes special categories of data, the number of employees, its balance sheet status, and the Board's decisions should all be evaluated together.

What are the risks of not registering with VERBİS?

Failure to register with VERBİS, despite having an obligation to do so, creates a risk of administrative sanctions under the Personal Data Protection Law (KVKK). The Regulation on the Data Controllers Registry stipulates that those who act contrary to the registration and notification obligations to the Registry will be subject to the administrative fine stipulated in Article 18 of the Law.

Administrative fines under the Personal Data Protection Law (KVKK) are updated annually according to the revaluation rate at the beginning of each calendar year. The Personal Data Protection Authority has announced that the increased administrative fine amounts for the years 2017-2026 have been published in tabular form.

However, the risk for companies is not limited to administrative fines. A company's lack of VERBİS registration, absence of a data inventory, incorrect information texts, or faulty execution of explicit consent processes can also lead to customer complaints, employee applications, Board investigations, compensation claims, and reputational damage.

Administrative and Technical Measures Companies Must Take During the GDPR Compliance Process

The GDPR compliance process is not limited to preparing documents. Companies must also take administrative and technical measures regarding data security. Administrative measures include steps such as preparing internal company policies, providing GDPR training to employees, obtaining confidentiality agreements, creating personal data storage and destruction policies, preparing an authorization matrix, entering into contracts with data processors, and establishing a breach management process.

Technical measures relate to information security. Strong password policies, access authorization, log keeping, antivirus and firewall use, backups, encryption, user-based access restrictions, data leakage prevention systems, and regular security tests can be considered within this scope.

For example, allowing all personnel access to employee files, making customer lists accessible to unauthorized individuals, storing camera recordings uncontrollably for extended periods, not revoking system access for former employees, or storing customer data on personal phones all pose serious risks. The GDPR compliance process should also address these kinds of practical issues.

Storage and Disposal Processes

Companies cannot store personal data indefinitely. Each piece of personal data must be stored for as long as is necessary for the purpose of processing. After this period, personal data must be deleted, destroyed, or anonymized.

For example, accounting records may be kept for specific periods as required by tax legislation. Employee personnel files may be kept for specific periods as required by labor law and social security legislation. Camera recordings, on the other hand, should be kept for a reasonable period for security purposes and should not be kept for unnecessarily long periods. When determining the retention period, the relevant legislation, statutes of limitations, the possibility of disputes, and the purpose of data processing should be considered together.

Therefore, companies need to prepare personal data storage and destruction policies, define periodic destruction processes, and actually implement them. Simply having a policy in place but never deleting the data is not sufficient for compliance with the Personal Data Protection Law (KVKK).

The Most Common GDPR Mistakes Companies Make

One of the most common mistakes companies make during the GDPR compliance process is using privacy notices copied from other companies. These notices do not reflect the company's actual activities and often contain incorrect data categories, inaccurate data transfer information, or irrelevant legal grounds.

The second common mistake is including explicit consent and information disclosure in the same text. The Board's announcement dated 2026 clearly demonstrated that this practice is problematic. The third mistake is obtaining unnecessary explicit consent in areas where it is not required. This can weaken the company's legal basis for data processing.

The fourth mistake is believing that VERBİS registration is sufficient for GDPR compliance. However, VERBİS is only a registration notification. The fifth mistake is failing to provide GDPR training to employees and leaving data access rights uncontrolled within the company.

Conclusion

For companies, the GDPR compliance process is essential for ensuring that commercial activities are conducted securely and in accordance with the law. This process includes preparing a personal data inventory, drafting information texts that reflect the company's actual data processing activities, obtaining explicit consent only when necessary and in a separate and valid manner, and carefully evaluating VERBİS (Turkish Data Protection Authority) obligations.

In current GDPR (Personal Data Protection Law) practices, it is particularly important to prepare separate information notices and consent statements, clearly indicate the legal basis and purpose of processing, avoid using generic texts copied from other companies, and use simple and understandable language. Companies need to adapt their actual operations to GDPR compliance, not just produce documents.

In conclusion, the GDPR compliance process is not a one-time formality; it is a legal compliance area that must be continuously monitored by the company, encompassing its human resources, accounting, sales, marketing, IT, and management processes. A properly executed GDPR compliance effort protects the company from the risk of administrative fines, increases customer trust, secures employee data, and strengthens the company's position in potential legal disputes.

Leave a Reply

Call Now Button