When businesses such as hotels, restaurants, cafés, shopping malls, hospitals, schools, and factories offer their guests free internet access, they fall under the definition of a "mass-use provider" and become obligated to comply with Law No. 5651.
What Is a Mass-Use Provider?
Article 2/1-(g) of Law No. 5651 defines a mass-use provider as follows:
"Natural or legal persons who provide individuals with the opportunity to use the internet environment at a specific location and for a specific period of time."
This definition covers every business that offers guest Wi-Fi, regardless of whether the access is paid or free.
Legal Obligations
- BTK Notification: Before commencing operations, a notification must be filed with the Information and Communication Technologies Authority (BTK).
- User Identification: The identity of anyone using the guest Wi-Fi must be identifiable (via national ID number, SMS verification, a social media account, a hotel room number, and so on).
- Internal Communication Rules: Traffic generated over the shared IP of the internet connection used on the premises must be recorded.
- Traffic Data: Source IP, source port, destination IP/port, and session start/end times must be retained for a period ranging from 6 months to 2 years.
- Time Synchronization: Log records must carry accurate time information (synchronized via NTP).
- Integrity: Logs must be secured against tampering through electronic signatures and timestamps.
User Identification Methods
The main legally accepted identification methods are:
- SMS Verification: A one-time password sent to the user's mobile phone. This is the most common method.
- National ID + Verification: Mandatory for government institutions, verified against MERNIS.
- Social Media Login: Sign-in with Facebook or Google (for accounts verified by phone).
- Hotel Room + Surname: PMS integration for hotel guests.
- Email + Confirmation Link: Low security; an additional SMS step is recommended.
Penalties for Non-Compliance
Businesses that fail to meet their mass-use provider obligations face an administrative fine ranging from 3,000 TL to 15,000 TL (updated each year in line with the revaluation rate).
The SignLogger Hotspot Solution
SignLogger provides a self-sufficient solution for guest Wi-Fi management:
- SMS, social media, national ID, and hotel PMS integration;
- Automatic captive portal (login page) with brand customization;
- Full compatibility with FortiGate, MikroTik, Cisco, Aruba, Ubiquiti, and Zyxel devices;
- Built-in log retention, electronic signing, and timestamping;
- Bandwidth quotas and content filtering.
To design the right hotspot configuration for your business, get in touch with our experts.
Authentication Methods: Which One Is Right for You?
| Method | How it works | Best-fit scenario |
|---|---|---|
| SMS verification | The user enters their phone number and logs in with the code they receive | Cafés, malls, public areas — the most common and practical method |
| Form / identity details | Registration with name, surname, and contact details | Event networks and businesses that keep visitor records |
| Sponsor approval | An employee inside the organization approves the visitor's access | Corporate offices and business towers |
| LDAP / Active Directory | Sign-in with a corporate account | Staff networks, schools, and universities |
| PMS integration | Verification by room number + surname (Elektraweb, Opera Cloud) | Hotels |
Note: Since the public service used for online verification of the Turkish national ID number has been discontinued, SMS-based methods have come to the fore for identity verification; for details, see this guide.
Deployment Architecture: Captive Portal + Log Server
A compliant guest Wi-Fi system consists of three components:
- Access layer: Access points and a guest VLAN — guest traffic is isolated from the staff network.
- Authentication layer (captive portal): Users are verified on a welcome page before reaching the internet, and the session is matched to their identity information.
- Logging layer: Firewall/NAT logs and hotspot session records are collected on a central server and signed with a timestamp. In SignLogger, certification-authority-approved signing is performed through integration with TÜBİTAK's Public Certification Authority (Kamu SM): during the integration step, each customer defines their own Kamu SM username and password in SignLogger and purchases the timestamp credit from Kamu SM in their own name; when no timestamp credit is available, daily logs are signed with the server's own certificate and timestamp. For the full process, see the Law No. 5651 Logging Obligation guide.
Setup Guides by Brand
SignLogger works with every brand that supports an external captive portal or RADIUS. Our step-by-step setup guides:
- FortiGate · Mikrotik · UniFi (Ubiquiti) · Cisco Meraki
- Aruba · Ruckus · TP-Link Omada · Huawei
- Zyxel · SonicWall · WatchGuard · Sophos · Palo Alto
Industry Scenarios
Hotels and hospitality
Guest numbers are high and user turnover is daily. PMS integration (Elektraweb, Opera Cloud) with room-number + surname verification both simplifies the guest experience and matches records to reservations. For details, see the hotel Wi-Fi management article.
Cafés and restaurants
The most practical method is SMS verification: the customer enters their number, connects with the code, and the session record is matched to their phone number. Setup is usually done by placing a guest VLAN and captive portal in front of the existing modem/AP.
Schools, universities, and dormitories
Students are verified with their LDAP/AD account and guests through sponsor approval. Because of seasonal peaks (exam weeks, enrollment periods), capacity planning for the logging infrastructure is important.
Hospitals and clinics
The patient and companion network must be strictly isolated from the staff network, and logging must be applied to both. Given the sensitivity under KVKK, presenting a disclosure notice on the portal is especially important.
Corporate offices and business towers
Visitors are verified through sponsor approval and staff through 802.1x/NAC. In business towers, floor- or tenant-based VLAN separation and central logging can be consolidated on a single SignLogger server.
Frequently Asked Questions
I offer free Wi-Fi — am I still covered?
Yes. The law makes no distinction between paid and free access; any business that provides internet use is a mass-use provider.
Isn't collecting guests' personal data contrary to KVKK?
No — logging under Law No. 5651 relies on the legal basis of a "legal obligation." Even so, you must present a disclosure notice on the portal screen; see How Do KVKK and Law No. 5651 Work Together?
Can a single device handle both hotspot and logging?
SignLogger delivers captive portal, RADIUS, syslog collection, and e-signed archiving together on a single virtual server; you can explore it on the features page.