A question that regularly confuses businesses: "Law No. 5651 obliges me to retain traffic data, but KVKK bans holding data I don't need. Which one do I follow?" The answer is both. In reality these two laws don't conflict; they complement each other.
What the Laws Share: Accountability for Data
Law No. 5651 and KVKK (Law No. 6698) are built on the same premise: whoever processes personal data is responsible for that data. Law No. 5651 makes keeping traffic data mandatory; KVKK governs how that keeping must be done.
Practical Points of Friction
1. Retention Period
Law No. 5651: Traffic data must be retained for a minimum of 6 months and a maximum of 2 years.
KVKK Art. 4: Data may only be kept for as long as the purpose of processing requires (the principle of proportionality).
The solution: Set the period that Law No. 5651 mandates (e.g. 1 year); once it expires, delete the data automatically or anonymize it. Keeping it longer than necessary constitutes a KVKK violation.
2. User Identification
Law No. 5651: A mass-use provider must establish the identity of the user.
KVKK Art. 4: Data must be "relevant, limited and proportionate to the purpose."
The solution: Perform identification for guest Wi-Fi (SMS, social media, room number), but do not collect additional data (occupational, financial, health). Only the minimum data suited to the purpose.
3. Transfer
Law No. 5651: Requests from the BTK and the Public Prosecutor's Office must be answered.
KVKK Art. 8: Transfer is only permitted with explicit consent or on a legal basis.
The solution: Transfer to authorized authorities is compliant under KVKK Art. 5/2-ç (legal obligation). Data is never transferred to third parties under any circumstances.
4. Rights of the Data Subject
KVKK Art. 11: The data subject may request that their data be deleted.
Law No. 5651: Traffic data must be retained by law.
The solution: For traffic data covered by Law No. 5651, a deletion request is refused under KVKK Art. 28 (legal exception). The data subject is given a reasoned response. The data is deleted automatically once the retention period expires.
The Ideal Compliance Workflow
- Draw up a data inventory: which data, why, and for how long is it kept?
- Update your disclosure notice: state the Law No. 5651 obligation explicitly.
- Set up hotspot identification: collect only the minimum data (phone number, email).
- Make your log infrastructure e-signed: for integrity and auditability.
- Establish an automatic deletion plan: logs are purged automatically when they expire.
- Keep an audit log: who accessed the data, and when?
- Be ready for breach notification: a 72-hour plan.
SignLogger Delivers This Workflow on a Single Platform
- Law No. 5651-compliant logging plus KVKK deletion and anonymization policies;
- Hotspot user data kept strictly limited to the purpose;
- Automatic retention rotation;
- User access audit logging;
- Data breach detection and notification readiness.
For details, see our Complete Law No. 5651 Guide and our KVKK disclosure notice.
Which Law Requires What? Division of Roles
| Topic | Law No. 5651 | KVKK |
|---|---|---|
| Keeping logs | Makes it mandatory | Provides the legal basis (Art. 5/2-ç) |
| Retention period | Sets a lower/upper bound (6 months – 2 years) | Requires destruction once the period expires |
| Data security | Requires integrity (timestamping) | Requires technical and administrative measures (Art. 12) |
| Notification | — | Disclosure obligation (Art. 10) |
| Purpose limitation | Presentation to judicial/administrative requests | Ban on use outside the stated purpose |
Implementation Checklist
- ☐ Logs are collected and signed in line with Law No. 5651 (setup guide)
- ☐ A KVKK disclosure notice is presented on the portal screen
- ☐ Access to the log server is role-based and every access is recorded
- ☐ The retention period is defined in policy; expired logs are destroyed automatically
- ☐ Logs are not used for out-of-purpose activities such as marketing
- ☐ The data inventory includes a "network traffic logs" category
To meet this checklist on a single platform, take a look at SignLogger's features: access control, an automatic retention/destruction cycle, and an e-signed archive all come together.
Frequently Asked Questions
If a user says "delete my data," are the logs deleted too?
No — a deletion request does not apply to data still subject to a retention obligation (KVKK Art. 28 and the related exceptions). The data is destroyed once the statutory period expires.
Can I back up my logs to a cloud service abroad?
This falls under KVKK's cross-border transfer regime and requires additional conditions. The most practical approach is to keep the signed archives domestically, on your own infrastructure — SignLogger's on-premise architecture is designed for exactly this need.