Guide24 August 20264 min read782 words

Cloud or On-Prem? Law 5651 Log Retention

Cloud vs. on-prem for Law 5651 log retention across data residency, access and privacy; SignLogger runs on-prem and keeps data in-house.

#cloud 5651#on-prem 5651#data residency#law 5651 log retention

For Law 5651 log retention, the decisive difference between cloud and on-premises is where the data lives and who controls access to it. In the on-prem model, access and traffic records stay on the organization's own servers, while in the cloud model the same records reside on a third-party provider's infrastructure. SignLogger runs fully on-prem: it is installed in the organization's own virtualization environment (VMware/Hyper-V), and the data never leaves the organization's boundaries.

This content is for general information only and is not legal advice. The scope of obligations varies by organization type; consult the legislation and your legal counsel for a binding assessment.

The Core Distinction: Data Residency and Access

Because records under Law 5651 carry evidentiary value, where they are stored is a legal question as much as a technical one. In the on-prem approach, the physical location, backups, and access rights of the records are entirely under the organization's control. In the cloud, part of that control is shared with the provider; which country's data center holds the data, who accesses it, and how the provider handles access requests must each be verified separately.

  • Data residency: On-prem keeps data in-house; cloud may place it in a region the provider chooses.
  • Access control: On-prem authorization belongs solely to the organization; in the cloud, provider staff may also hold technical access to the infrastructure.
  • Privacy: Letting access logs that contain personal data leave the premises adds obligations under data protection law.
  • Independence: An on-prem solution is unaffected by internet outages or the termination of a provider contract.

Cloud vs. On-Prem Comparison

CriterionOn-Prem (SignLogger)Cloud
Data locationOrganization's own infrastructureProvider's data center
Access rightsOrganization onlyOrganization + provider
Internet dependencyNoneConstant connection required
Log signingAutomatic every day, Kamu SM timestamp + e-signatureDepends on provider
Privacy burdenData never leaves premisesTransfer/contract assessment needed
Exit easeData already in-houseMigration/format lock-in

Where Is Record Integrity Established?

Law 5651 compliance requires not only storing records but also being able to prove they were not altered afterward. SignLogger signs the collected logs every day with the timestamp and e-signature of TÜBİTAK Kamu SM, an authorized certificate authority, so that a record's existence on a given date and its integrity can be verified independently. Kamu SM services work on a credit (kontör) basis, so enough credits must be planned for signing. This integrity chain is produced and stored in the organization's own environment in an on-prem deployment; see the Law 5651 log signing solution page for details.

Why Is SignLogger On-Prem?

SignLogger is brand-independent and works with any RADIUS-capable firewall. Because installation happens in the organization's own virtual environment, all data — including hotspot, captive portal, and NAC records — stays on site. This approach preserves data sovereignty and keeps signed records in the organization's hands throughout the retention period. In hotspot scenarios that require authentication, captive portal RADIUS verification is done with PAP; for enterprise wireless, 802.1x/EAP can be preferred.

  • Data never leaves the organization; sovereignty is preserved.
  • Signed, timestamped records can be presented directly during an audit.
  • Works with existing firewall and hotspot management infrastructure.

Frequently Asked Questions

Is storing Law 5651 logs in the cloud prohibited?

The general rule is that records must be retained in a verifiably intact form for the prescribed period; there may be restrictions on storage location that vary by organization type. If the cloud is used, responsibility for data residency, access, and signing must be clarified.

How long must logs be kept in on-prem retention?

The retention period is determined by organization type and is based on the period prescribed in the legislation. SignLogger keeps the records in signed form throughout that period.

How do I prove cloud records were not altered?

Integrity is proven by signing records with a timestamp and e-signature. On-prem, SignLogger produces this every day in the organization's environment with a Kamu SM timestamp and e-signature.

Does SignLogger offer a cloud version?

SignLogger is designed to run on the organization's own infrastructure (VMware/Hyper-V), keeping data on site. This is the preferred model for organizations that prioritize data sovereignty and audit convenience.

Does on-prem logging stop when the internet goes down?

Log collection and storage run locally, so they are unaffected by internet outages. Only the Kamu SM signing step needs online access and is completed once the connection returns.

Can my cloud provider keep my data in another country?

Yes, in the cloud the data may reside in a region the provider selects, which requires additional assessment for privacy and access. The on-prem model removes this risk because the data never leaves the organization.

Last updated: 25 August 2026

See SignLogger Law 5651 compliance for yourself

Request a free demo