Blog01 August 20263 min read758 words

How to Comply with KVKK and Law No. 5651 Together: A Conflict and Compliance Guide

Turkey's Law No. 5651 requires you to retain traffic logs, while KVKK forbids holding unnecessary data — but the two laws complement rather than contradict each other. This guide maps the practical friction points and shows how to satisfy both in a single workflow.

#kvkk#law-5651#compliance#log-management

A question that regularly confuses businesses: "Law No. 5651 obliges me to retain traffic data, but KVKK bans holding data I don't need. Which one do I follow?" The answer is both. In reality these two laws don't conflict; they complement each other.

What the Laws Share: Accountability for Data

Law No. 5651 and KVKK (Law No. 6698) are built on the same premise: whoever processes personal data is responsible for that data. Law No. 5651 makes keeping traffic data mandatory; KVKK governs how that keeping must be done.

Practical Points of Friction

1. Retention Period

Law No. 5651: Traffic data must be retained for a minimum of 6 months and a maximum of 2 years.
KVKK Art. 4: Data may only be kept for as long as the purpose of processing requires (the principle of proportionality).

The solution: Set the period that Law No. 5651 mandates (e.g. 1 year); once it expires, delete the data automatically or anonymize it. Keeping it longer than necessary constitutes a KVKK violation.

2. User Identification

Law No. 5651: A mass-use provider must establish the identity of the user.
KVKK Art. 4: Data must be "relevant, limited and proportionate to the purpose."

The solution: Perform identification for guest Wi-Fi (SMS, social media, room number), but do not collect additional data (occupational, financial, health). Only the minimum data suited to the purpose.

3. Transfer

Law No. 5651: Requests from the BTK and the Public Prosecutor's Office must be answered.
KVKK Art. 8: Transfer is only permitted with explicit consent or on a legal basis.

The solution: Transfer to authorized authorities is compliant under KVKK Art. 5/2-ç (legal obligation). Data is never transferred to third parties under any circumstances.

4. Rights of the Data Subject

KVKK Art. 11: The data subject may request that their data be deleted.
Law No. 5651: Traffic data must be retained by law.

The solution: For traffic data covered by Law No. 5651, a deletion request is refused under KVKK Art. 28 (legal exception). The data subject is given a reasoned response. The data is deleted automatically once the retention period expires.

The Ideal Compliance Workflow

  1. Draw up a data inventory: which data, why, and for how long is it kept?
  2. Update your disclosure notice: state the Law No. 5651 obligation explicitly.
  3. Set up hotspot identification: collect only the minimum data (phone number, email).
  4. Make your log infrastructure e-signed: for integrity and auditability.
  5. Establish an automatic deletion plan: logs are purged automatically when they expire.
  6. Keep an audit log: who accessed the data, and when?
  7. Be ready for breach notification: a 72-hour plan.

SignLogger Delivers This Workflow on a Single Platform

  • Law No. 5651-compliant logging plus KVKK deletion and anonymization policies;
  • Hotspot user data kept strictly limited to the purpose;
  • Automatic retention rotation;
  • User access audit logging;
  • Data breach detection and notification readiness.

For details, see our Complete Law No. 5651 Guide and our KVKK disclosure notice.

Which Law Requires What? Division of Roles

TopicLaw No. 5651KVKK
Keeping logsMakes it mandatoryProvides the legal basis (Art. 5/2-ç)
Retention periodSets a lower/upper bound (6 months – 2 years)Requires destruction once the period expires
Data securityRequires integrity (timestamping)Requires technical and administrative measures (Art. 12)
NotificationDisclosure obligation (Art. 10)
Purpose limitationPresentation to judicial/administrative requestsBan on use outside the stated purpose

Implementation Checklist

  • ☐ Logs are collected and signed in line with Law No. 5651 (setup guide)
  • ☐ A KVKK disclosure notice is presented on the portal screen
  • ☐ Access to the log server is role-based and every access is recorded
  • ☐ The retention period is defined in policy; expired logs are destroyed automatically
  • ☐ Logs are not used for out-of-purpose activities such as marketing
  • ☐ The data inventory includes a "network traffic logs" category

To meet this checklist on a single platform, take a look at SignLogger's features: access control, an automatic retention/destruction cycle, and an e-signed archive all come together.

Frequently Asked Questions

If a user says "delete my data," are the logs deleted too?

No — a deletion request does not apply to data still subject to a retention obligation (KVKK Art. 28 and the related exceptions). The data is destroyed once the statutory period expires.

Can I back up my logs to a cloud service abroad?

This falls under KVKK's cross-border transfer regime and requires additional conditions. The most practical approach is to keep the signed archives domestically, on your own infrastructure — SignLogger's on-premise architecture is designed for exactly this need.

Last updated: 01 August 2026

Questions about SignLogger?

Contact us