Guide24 August 20264 min read876 words

Law 5651 Guest Wi-Fi Solution for Malls and Business Centers

SMS-verified, branded captive portal and daily signed Law 5651 logs for high-concurrency guest Wi-Fi in malls, plazas and business centers.

#mall law 5651#business center guest wifi#captive portal#sms verification#law 5651 logging

Free guest Wi-Fi offered in malls, plazas and business centers must provide identified access and signed log records under Turkey's Law No. 5651. SignLogger identifies each visitor through an SMS-verified, branded welcome screen and stores every session record on the organization's own server, signing the logs every day with an authorized certificate authority timestamp and e-signature. In this way a busy mall with hundreds of concurrent users meets both guest experience and legal compliance on a single platform.

This content is for general information only and does not constitute legal advice. Confirm your obligations with your own legal counsel.

Why Guest Wi-Fi in Malls Demands a Different Scale

Unlike an office, malls and plazas see a visitor profile that shifts throughout the day; at lunch and evening peaks hundreds of devices try to join the network at once. At this density the solution must operate without bottlenecks and record every session separately and without interruption. The specific needs of a mall operation include:

  • A scalable architecture that supports very high concurrent user counts
  • Consistent access across zones such as stores, the food court and the car park
  • A welcome screen that reflects the mall brand and can host ads or campaigns
  • A single-step verification that does not tire the visitor
  • Reliable logging of every session under Law 5651

Identification via an SMS-Verified Captive Portal

SignLogger identifies the guest through a captive portal (welcome screen) before granting network access. The visitor enters a phone number, confirms the one-time SMS code that arrives, and only then reaches the internet. This method is practical for environments like malls, where there is no registered membership and a constant flow of new visitors, and it ties every session to an identity.

The RADIUS authentication between the captive portal and the firewall in SignLogger uses PAP only; EAP-based methods are not used in the portal scenario. SignLogger is brand-independent and works with any RADIUS-capable firewall, so it goes live without replacing your existing network hardware. Because the welcome screen can be customized with the mall's logo, colors and campaign visuals, guest Wi-Fi also becomes a communication channel.

Signed Logs Every Day: The Core of Law 5651 Compliance

The critical point under Law 5651 is being able to prove that the access records produced were not altered afterward. SignLogger secures this integrity by signing the logs every day with a TÜBİTAK Kamu SM (authorized certificate authority) timestamp and e-signature. The signing runs on credits (kontör) on the Kamu SM side; tracking the credit balance is recommended so signing is not interrupted when credits run out.

The records and signatures are kept on the organization's own infrastructure (on VMware or Hyper-V); data never leaves the mall and is not handed to a third-party cloud provider. The integrity of the records is preserved throughout the legal retention period .

NeedClassic Free Wi-FiGuest Wi-Fi with SignLogger
IdentificationNone / open networkSMS-verified captive portal
Log integrityUnsigned, alterableDaily timestamp + e-signature
Data locationUnclear / external cloudOrganization's own server (on-prem)
Brand experienceGeneric screenBranded welcome with campaigns
ConcurrencyLimitedScales to high user counts

You can review the end-to-end setup details designed for high-traffic facilities on the hotspot management solution page.

Deployment and Operation

SignLogger sits behind the mall's existing internet gateway and firewall. Typical rollout steps are:

  • Installing SignLogger on the virtualization environment (VMware/Hyper-V)
  • Defining RADIUS and captive portal redirection on the firewall
  • Designing the welcome screen to match the mall brand
  • Configuring the SMS provider and the Kamu SM credits for daily signing
  • Validating concurrent capacity with test sessions

Frequently Asked Questions

Is Law 5651 really mandatory for mall guest Wi-Fi?

Venues that offer public internet access fall under the obligation to keep access records and protect their integrity. Because malls and plazas provide internet to their guests commercially, they are within this scope; confirm the exact boundaries of your obligations with your legal counsel.

Will the system slow down if hundreds connect at once?

SignLogger is designed to scale for high concurrent user counts. Capacity is planned according to the allocated virtual server resources, and the mall's peak load is validated with test sessions before go-live.

Does the guest have to complete SMS verification every time?

The portal can be configured to remember devices that reconnect within a defined period. Regular visitors are therefore not forced to enter a code on every visit, while the session record is still kept reliably.

Where are the logs stored, and does data leave the premises?

All records and signatures are kept on the mall's own infrastructure (VMware/Hyper-V). Data stays on-prem and is not transferred to a third-party cloud provider; the only external contact is with the Kamu SM timestamp service for signing.

Can I customize the welcome screen with the mall brand?

Yes. The logo, colors, campaign visuals and guidance messages are designed to match the mall brand. This lets guest Wi-Fi double as a marketing and communication channel.

Do I need to replace my current firewall brand?

No. SignLogger is brand-independent and works with any RADIUS-capable firewall. You can keep your existing network hardware and add the captive portal and signed-log layer on top of it.

Last updated: 25 August 2026

See SignLogger Law 5651 compliance for yourself

Request a free demo