A company established in Turkey that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance acts as that EU representative, established in the EU and named in your privacy notice. Turkish companies often know the KVKK requires a representative in Turkey for foreign controllers, and read across from that to assume the EU is handled. It is not: the EU obligation is separate, and the two representatives sit in different countries under different laws.
Key takeaways
- GDPR Article 27 applies to Turkish companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow.
- This is a different appointment from the KVKK representative that VERBIS registration requires inside Turkey. One sits in the EU under EU law, the other sits in Turkey under the KVKK.
- Most Turkish companies caught by the EU obligation are also caught by the separate UK one, and each is appointed independently.
- We act as your EU representative directly. The KVKK representative has to be based in Turkey, so we arrange that through a local partner rather than claiming to perform it ourselves.
How does a Turkish company get caught by GDPR?
GDPR reaches beyond the EU through Article 3(2): a company with no EU establishment is inside the Regulation when its processing relates to offering goods or services to people in the EU, whether or not payment is required, or monitoring their behavior as far as it happens in the EU.
A Turkish ecommerce, travel or SaaS business selling to consumers in Germany, France or the Netherlands, with EU-language checkout and euro pricing, is offering goods or services to people in the EU. A Turkish app or adtech company tracking EU users is monitoring behavior. Both are the ordinary shape of a Turkish business reaching the EU market without an EU entity, and both trigger Article 27.
How is this different from the KVKK VERBIS representative?
Turkey has its own data protection law, and it imposes its own local representative duty on foreign controllers, which is where the confusion starts.
The KVKK (Law No. 6698 on the Protection of Personal Data) creates the Data Controllers’ Registry, VERBIS, under its Article 16. The registry by-law then requires a data controller not established in Turkey to register with VERBIS through a representative, and defines that representative as a legal person established in Turkey or a Turkish-citizen individual authorized to represent the foreign controller. So an in-scope foreign controller both registers with VERBIS and appoints a Turkey-based representative to do it.
That representative sits in Turkey and answers to the Turkish authority. It does nothing for your EU position. The GDPR Article 27 representative sits in the EU, is named in your EU privacy notice, and is the contact point for EU supervisory authorities and for people in the EU. A Turkish company inside both regimes needs both, and neither one covers the other.
Who regulates this?
In the EU, the supervisory authority in the member state where your representative sits, coordinated through the European Data Protection Board. In Turkey, the Personal Data Protection Authority, whose decision-making body is the Personal Data Protection Board (the KVKK Board), oversees the KVKK and VERBIS.
Do Turkish companies also need a UK representative?
Usually, where the company also offers goods or services to, or monitors, people in the UK. The UK GDPR carries its own separate Article 27, enforced by the Information Commissioner’s Office, and an EU representative does not cover the UK. We can take both as separate mandates.
What does Engage do?
Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account.
The KVKK representative is different: it has to be based in Turkey, so where you need it we arrange it through a local partner and say so in writing, rather than presenting a partner-delivered role as something we perform ourselves. Where you also need a named DPO, we cannot be both for the same company on the European Data Protection Board’s reasoning, so we take one role and arrange the other through a partner entity.
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.
What to do next
If you are a Turkish company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation, separate from your VERBIS position. Read do I need an EU representative, see how the EU representative service works, or contact us and we will tell you plainly what applies and what the appointment involves.
Sources and references
- GDPR Article 3, territorial scope, Regulation (EU) 2016/679, EUR-Lex
- GDPR Article 27, representatives of controllers or processors not established in the Union, Regulation (EU) 2016/679, EUR-Lex
- Law No. 6698 on the Protection of Personal Data (KVKK), Personal Data Protection Authority of Turkey
- By-Law on the Data Controllers’ Registry (VERBIS), Personal Data Protection Authority of Turkey
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)