Law No. 5651 sets out substantial administrative fines for those who fail to comply. This article breaks down the current penalty amounts by type of business and walks through how the audit process works.
\n\nPenalties for Hosting Providers
\nUnder Article 5/6 of Law No. 5651, hosting providers that fail to meet their notification obligations face administrative fines ranging from 10,000 TL to 100,000 TL. (These amounts are revised each year in line with the 2026 revaluation rate.)
\nThe authority empowered to impose the penalty is the Information and Communication Technologies Authority (BTK).
\n\nPenalties for Mass-Use Providers
\nUnder Article 7/3 of Law No. 5651, when mass-use providers fail to meet their obligations, the highest-ranking local civilian administrator may impose an administrative fine ranging from 3,000 TL to 15,000 TL.
\nThis is the penalty most commonly encountered by businesses such as hotels, cafés, shopping malls and hospitals.
\n\nPenalties for Access Providers
\nFor access providers, Article 6/3 of Law No. 5651 provides for fines ranging from 50,000 TL to 500,000 TL. Revocation of the operating licence may also come into play.
\n\nThe Obligation to Remove Content
\nFailing to remove unlawful content within 4 hours of being notified by a BTK or Public Prosecutor's decision is itself subject to a separate penalty.
\n\nThe Audit Process
\nBTK audits generally consist of the following steps:
\n- \n
- Complaint or routine audit: Triggered by a criminal incident or a scheduled inspection. \n
- Log request letter: Traffic data is requested for a specific IP address and time range. \n
- Response window: Signed and timestamped logs are typically expected to be submitted within 15 days. \n
- In case of deficiencies: A violation report is issued and a written defence is requested. \n
- Decision: An administrative fine and/or a restriction on operations. \n
Practical Tips to Avoid Penalties
\n- \n
- Build a complete logging infrastructure: Every firewall and router should be configured to send syslog data. \n
- Check your time synchronization: If NTP is not working correctly, your logs may be deemed invalid. \n
- Use electronic signatures and timestamps: A log whose integrity cannot be proven is treated as if it does not exist. \n
- Back up your data: In a disaster, the absence of a backup means "no logs" — and that carries the same penalty. \n
- Audit regularly: Test your log-collection processes through internal audits. \n
- Train your staff: During an inspection, your IT personnel need to be well-versed in the regulations. \n
A Real-World Example
\nA shopping mall offered free Wi-Fi to its customers but did not authenticate users; someone then committed a crime over that network. The subsequent audit found that:
\n- \n
- no hotspot user authentication had been performed, \n
- the integrity of the log records could not be proven with an electronic signature; \n
- the mall's management was fined 12,000 TL, \n
- and was given 30 days to bring itself into compliance. \n
Reducing Risk with SignLogger
\nWith automated user authentication, e-signed log storage, TÜBİTAK timestamp integration and audit-ready report generation, SignLogger is the fastest way to protect yourself from penalties. SignLogger signs the daily logs every day with the authorized certification authority (TÜBİTAK Kamu SM) timestamp and e-signature. In SignLogger, signing approved by an authorized certification authority is carried out through integration with the TÜBİTAK Public Certification Authority (Kamu SM): during the integration step, each customer defines their own Kamu SM username and password in SignLogger and purchases the timestamp credit from Kamu SM in their own name. When no credit is available, daily logs are still signed using the server's own certificate and timestamp. Get in touch for a risk assessment.
\nHow Does the Audit Process Work?
\nIn practice, audits arrive through two channels:
\n- \n
- Incident-driven request: While a crime committed over your network (a threat, fraud, access to illegal content) is being investigated, law enforcement requests the logs for a specific date and time range. If the logs are missing or unsigned, liability falls back on the business. \n
- Administrative audit: The civilian administration or BTK may inspect whether a mass-use provider is meeting its obligations, checking for the existence of a logging system as well as timestamping and the retention period. \n
A Checklist for Avoiding Penalties
\n- \n
- ☐ Firewall/NAT logs are collected on a central server \n
- ☐ The guest network authenticates users through a captive portal \n
- ☐ Logs are sealed daily with a timestamp and e-signature (why is this essential?) \n
- ☐ A retention-period policy is defined and enforced (retention guide) \n
- ☐ Device clocks are synchronized via NTP \n
- ☐ Disk capacity and signing jobs are monitored and generate alerts \n
- ☐ When a request arrives, a report for the date-and-time range can be produced within minutes \n
To meet all of these requirements on a single platform, read our Law 5651 Logging Obligation guide and explore the SignLogger features.
\n\nThree Real-World Scenarios
\nScenario 1: No logs were ever collected
\nA threatening message sent from a café's network is investigated, but the business has no logging system in place. Because the individual cannot be identified, liability shifts to the business, and an administrative fine comes into play as well. This is the most costly scenario — logs cannot be generated retroactively.
\nScenario 2: Logs exist but are unsigned
\nThe requested records are submitted as a text file, and the other party objects that the records may have been altered after the fact. Because their integrity cannot be proven, the evidence becomes contestable and, in an audit, is treated as a compliance gap.
\nScenario 3: A fully compliant system
\nThe business queries the requested date-and-time range from SignLogger's reporting screen; the NAT + DHCP + hotspot chain is pulled from the signed archive within minutes and delivered together with the timestamp documents. For the business, the whole process amounts to a few minutes of email correspondence.
\nFrequently Asked Questions
\nDo the penalty amounts change every year?
\nYes — administrative fines are updated each year in line with the revaluation rate. The amounts in this article illustrate the lower- and upper-limit logic; for the current figure, you should check the rate for the relevant year.
\nI keep logs, but they are unsigned — is there a penalty risk?
\nYes. Records whose integrity cannot be proven may be treated as though they were never kept, and they also risk being rejected as evidence in legal proceedings.
\nWho pays the fine — the business or the IT firm?
\nThe obligation belongs to the mass-use provider, meaning the business itself. The contract you have with your IT service provider governs the relationship between you, but it does not transfer administrative liability.