In Türkiye the Identity Problem Is Already Solved. The Reuse Problem Is Not

We do not operate any integration with the national population registry, and the section saying so is the point of this page. Nothing here is legal advice.

Why the pitch that works elsewhere does not work here

In most markets a vendor selling identity verification is selling a way to establish who somebody is, because there is no authoritative national answer to check against.

Türkiye is not that market. Every citizen has an eleven-digit identity number assigned once, for life. It is on the national card, on nearly every official document, and it is the anchor almost every regulatory system keys off: the telecoms regulator's SIM registration rule, the financial regulator's remote customer-identification rule, the hotel guest-notification system, and the national e-government login itself. Foreign residents get the same kind of identifier under a distinct prefix.

So a Turkish institution does not have an identity problem in the sense the global vendors describe. It has an authoritative registry and a legal path to query it.

Any pitch that opens by explaining why identity is hard will be answered, correctly, with we already know who our customers are.

What the actual problem is

The check is authoritative and it does not travel.

A citizen proves themselves at their bank. Then again at the exchange. Then again at the telco, the hotel, the marketplace, the second bank. Each of those institutions performs its own registry match, stores its own copy of the resulting document images, and carries its own retention and breach exposure for them.

The registry gives every one of those checks the same authoritative answer. Nothing lets the second institution rely on the first one having asked.

That is a reuse problem, not an identity problem, and it is the one worth solving in a market where the identity half already works.

The part a Turkish institution should weigh

Every domestic onboarding creates another copy of an identity document in another system. That is the exposure, it is duplicated per institution, and the registry does nothing about it because the registry answers a question rather than storing your customers' documents for you.

Reuse changes the number of copies. It does not change who is accountable for the check, and it does not remove any obligation your licence imposes.

Whether that trade is worth anything to you depends on how much of your onboarding volume is people who have already proved themselves elsewhere. In this market, for consumer financial services, that share is not small, and it is your number rather than ours.

What to ask any vendor selling into Türkiye

"Do you query the population registry directly, and under what authorisation?" The answer is a yes or a no with a legal basis attached. For us today it is no.

"What do you do for foreign nationals?" Different rails, different rule, and a vendor that has not separated the two cases has not read the regulation.

"What of my obligations does this remove?" None. It changes what satisfying them costs.

"Where do the document images go, and for how long?" The registry match does not answer this and it is where the durable risk sits.

Where this leaves a decision

If you need a vendor who can perform the authoritative registry match today, we cannot, and you should treat that as disqualifying for domestic onboarding until it ships.

Keep reading

In Türkiye the Identity Problem Is Already Solved. The Reuse Problem Is Not · Solidus