Law No. 5651 is the Turkish regulation that took effect on 23 May 2007, officially titled the "Law on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications." It requires every organization that provides or makes internet access available to keep records of user traffic.
Who Does Law No. 5651 Cover?
The law applies to all of the following natural and legal persons:
- Access providers: internet service providers (Türk Telekom, Turkcell Superonline, and similar).
- Hosting providers: companies that provide web server or hosting services.
- Public-use providers: every business that offers guest Wi-Fi, such as cafés, hotels, shopping malls, hospitals, schools, factories, and offices.
- Content providers: those who operate a website, blog, or e-commerce platform.
If your business provides internet access to guests or employees, then you fall within the scope of Law No. 5651.
The Core Obligations Imposed by the Law
- Log retention: storing user traffic data (IP, session, port, destination address) for the legally required period.
- Log integrity: proving that the stored records have not been altered, using an electronic signature or timestamp.
- Hosting provider notification: notifying the Information and Communication Technologies Authority (BTK) of the relevant activity.
- User identification: ensuring that guest Wi-Fi users can be identified.
- Content removal: taking down unlawful content reported by the competent authorities.
Why Does It Matter? What Are the Penalties?
Failing to meet the obligations under Law No. 5651 leads to significant administrative fines. Under Article 5 of the law, hosting providers that do not fulfill their obligations may face fines ranging from 10,000 TL to 100,000 TL, while public-use providers that breach their obligations may face fines ranging from 3,000 TL to 15,000 TL (these amounts are updated each year at the official revaluation rate).
Steps to Take for Practical Compliance
- Review your network topology and identify log-collection points (firewall, router, syslog server).
- Store traffic data with a timestamp and an electronic signature.
- Configure the log retention period to be at least 6 months and at most 2 years.
- Provide user verification for guest Wi-Fi (SMS, email, or Turkish ID number).
- Establish regular backup and disaster recovery plans.
Law 5651 Compliance with SignLogger
SignLogger meets every technical obligation required by Law No. 5651 on a single platform:
- Syslog collection from FortiGate, Cisco, MikroTik, Sophos, SonicWall, Palo Alto, and every other device;
- Built-in electronic signature and TÜBİTAK timestamp integration;
- Hotspot authentication based on SMS, email, or social media;
- Automatic log rotation and encrypted archiving;
- Search and export that conform to BTK audit reports.
For more detail, explore our features or request a demo.
A Step-by-Step Roadmap to Law 5651 Compliance
Once you have confirmed that you fall within the scope of the law, the compliance process proceeds through these steps:
- Determine your role: the vast majority of businesses fall into the "public-use provider" role; if you offer guest Wi-Fi, you are definitely covered.
- Set up your logging infrastructure: collect the logs from your firewall, DHCP server, and access points on a central server. For the full process, see the Law 5651 Logging Obligation guide.
- Apply timestamping and electronic signatures: daily logs must be sealed with a TÜBİTAK-approved timestamp. In SignLogger, certificate-authority-approved signing is performed through the TÜBİTAK Public Certification Authority (Kamu SM) integration: during the integration step, each customer defines their own Kamu SM username and password in SignLogger and purchases the timestamp credit from Kamu SM in their own name; when no credit is available, daily logs are signed with the server's own certificate and timestamp. For details, see the Signed Logs and Timestamping article.
- Tie your guest network to authentication: use a captive portal with SMS, form, or sponsor verification to match sessions to real individuals.
- Define a retention and disposal policy: for the legal period, review the Log Retention Period guide.
Common Mistakes
- The "the modem already logs it" assumption: home-grade modem records rotate quickly, are unsigned, and hold no evidentiary value.
- Logging only the hotspot: the firewall/NAT logs of your staff network are in scope too; logging only the guest network leaves your compliance incomplete.
- Neglecting time synchronization: if devices are not synchronized via NTP, logs can drift by minutes relative to one another, making forensic correlation impossible.
- Unsigned archives: if logs are being collected but not timestamped, they are open to the "these could have been produced after the fact" objection during an audit.
Obligations by Role
| Role | Who? | Core obligations |
|---|---|---|
| Access provider | Internet service providers | Retain traffic data for 6 months–2 years, enforce access-blocking decisions, notify BTK |
| Hosting provider | Hosting companies | Obtain an activity certificate, retain traffic data for the content it hosts for 1–2 years, remove unlawful content |
| Content provider | Website/application owners | Responsibility for the content they produce, display of identifying information |
| Public-use provider | Businesses offering guest/staff internet | Verify users, capture internal IP allocation and access logs, sign them with a timestamp, and retain them for the legal period |
A business can hold more than one role at the same time: for example, a company that hosts its own website on its own server and offers guest Wi-Fi in its office is both a hosting provider and a public-use provider. Obligations are assessed separately for each role.
Which Traffic Does the Law Require You to Record?
For public-use providers, the minimum set expected to be recorded is: the identity under which the user connected to the network (hotspot verification), the internal IP assigned to the device (DHCP), the real IP and port through which that internal IP reached the internet (NAT), and the time of the connection. Having these four records synchronized to the same time source makes it possible, in a forensic request, to trace all the way down to the individual. For a breakdown of which device produces which record, see the Which Logs Must We Keep for Law 5651? article.
Frequently Asked Questions
Is BTK notification required for Law 5651 compliance?
Public-use providers that offer internet for commercial purposes (internet cafés and the like) must obtain permission from the highest local civil administrative authority; for other businesses, the logging and retention obligations are the core requirement. Consult an expert for any scenarios you are unsure about.
What is the sanction for not complying with the law?
Administrative fines and case-by-case legal liability arise; for details, see the Law 5651 Penalties article.
How quickly can I set up a compliant system?
With a ready-to-use virtual appliance like SignLogger, it is possible to complete log collection, signing, and captive portal setup within the same day. Explore the features or request a demo.