Law No. 5651 sets out substantial administrative fines for those who fail to comply. This article breaks down the current penalty amounts by type of business and walks through how the audit process works.
Penalties for Hosting Providers
Under Article 5/6 of Law No. 5651, hosting providers that fail to meet their notification obligations face administrative fines ranging from 10,000 TL to 100,000 TL. (These amounts are revised each year in line with the 2026 revaluation rate.)
The authority empowered to impose the penalty is the Information and Communication Technologies Authority (BTK).
Penalties for Mass-Use Providers
Under Article 7/3 of Law No. 5651, when mass-use providers fail to meet their obligations, the highest-ranking local civilian administrator may impose an administrative fine ranging from 3,000 TL to 15,000 TL.
This is the penalty most commonly encountered by businesses such as hotels, cafés, shopping malls and hospitals.
Penalties for Access Providers
For access providers, Article 6/3 of Law No. 5651 provides for fines ranging from 50,000 TL to 500,000 TL. Revocation of the operating licence may also come into play.
The Obligation to Remove Content
Failing to remove unlawful content within 4 hours of being notified by a BTK or Public Prosecutor's decision is itself subject to a separate penalty.
The Audit Process
BTK audits generally consist of the following steps:
- Complaint or routine audit: Triggered by a criminal incident or a scheduled inspection.
- Log request letter: Traffic data is requested for a specific IP address and time range.
- Response window: Signed and timestamped logs are typically expected to be submitted within 15 days.
- In case of deficiencies: A violation report is issued and a written defence is requested.
- Decision: An administrative fine and/or a restriction on operations.
Practical Tips to Avoid Penalties
- Build a complete logging infrastructure: Every firewall and router should be configured to send syslog data.
- Check your time synchronization: If NTP is not working correctly, your logs may be deemed invalid.
- Use electronic signatures and timestamps: A log whose integrity cannot be proven is treated as if it does not exist.
- Back up your data: In a disaster, the absence of a backup means "no logs" — and that carries the same penalty.
- Audit regularly: Test your log-collection processes through internal audits.
- Train your staff: During an inspection, your IT personnel need to be well-versed in the regulations.
A Real-World Example
A shopping mall offered free Wi-Fi to its customers but did not authenticate users; someone then committed a crime over that network. The subsequent audit found that:
- no hotspot user authentication had been performed,
- the integrity of the log records could not be proven with an electronic signature;
- the mall's management was fined 12,000 TL,
- and was given 30 days to bring itself into compliance.
Reducing Risk with SignLogger
With automated user authentication, e-signed log storage, TÜBİTAK timestamp integration and audit-ready report generation, SignLogger is the fastest way to protect yourself from penalties. In SignLogger, signing approved by an authorized certification authority is carried out through integration with the TÜBİTAK Public Certification Authority (Kamu SM): during the integration step, each customer defines their own Kamu SM username and password in SignLogger and purchases the timestamp credit from Kamu SM in their own name. When no credit is available, daily logs are still signed using the server's own certificate and timestamp. Get in touch for a risk assessment.
How Does the Audit Process Work?
In practice, audits arrive through two channels:
- Incident-driven request: While a crime committed over your network (a threat, fraud, access to illegal content) is being investigated, law enforcement requests the logs for a specific date and time range. If the logs are missing or unsigned, liability falls back on the business.
- Administrative audit: The civilian administration or BTK may inspect whether a mass-use provider is meeting its obligations, checking for the existence of a logging system as well as timestamping and the retention period.
A Checklist for Avoiding Penalties
- ☐ Firewall/NAT logs are collected on a central server
- ☐ The guest network authenticates users through a captive portal
- ☐ Logs are sealed daily with a timestamp and e-signature (why is this essential?)
- ☐ A retention-period policy is defined and enforced (retention guide)
- ☐ Device clocks are synchronized via NTP
- ☐ Disk capacity and signing jobs are monitored and generate alerts
- ☐ When a request arrives, a report for the date-and-time range can be produced within minutes
To meet all of these requirements on a single platform, read our Law 5651 Logging Obligation guide and explore the SignLogger features.
Three Real-World Scenarios
Scenario 1: No logs were ever collected
A threatening message sent from a café's network is investigated, but the business has no logging system in place. Because the individual cannot be identified, liability shifts to the business, and an administrative fine comes into play as well. This is the most costly scenario — logs cannot be generated retroactively.
Scenario 2: Logs exist but are unsigned
The requested records are submitted as a text file, and the other party objects that the records may have been altered after the fact. Because their integrity cannot be proven, the evidence becomes contestable and, in an audit, is treated as a compliance gap.
Scenario 3: A fully compliant system
The business queries the requested date-and-time range from SignLogger's reporting screen; the NAT + DHCP + hotspot chain is pulled from the signed archive within minutes and delivered together with the timestamp documents. For the business, the whole process amounts to a few minutes of email correspondence.
Frequently Asked Questions
Do the penalty amounts change every year?
Yes — administrative fines are updated each year in line with the revaluation rate. The amounts in this article illustrate the lower- and upper-limit logic; for the current figure, you should check the rate for the relevant year.
I keep logs, but they are unsigned — is there a penalty risk?
Yes. Records whose integrity cannot be proven may be treated as though they were never kept, and they also risk being rejected as evidence in legal proceedings.
Who pays the fine — the business or the IT firm?
The obligation belongs to the mass-use provider, meaning the business itself. The contract you have with your IT service provider governs the relationship between you, but it does not transfer administrative liability.