Guide24 August 20264 min read876 words

What Is a Mass-Use Provider? Law 5651 Obligations

Definition of a mass-use provider (hotel, café, mall and business guest internet) and its Law 5651 duties: identity verification and signed log retention.

#mass-use provider#law 5651 obligation#guest wifi#captive portal#law 5651 fine

A mass-use provider is any natural or legal person that offers people internet access at a specific location for a limited time; hotels, cafés, restaurants, malls, hospitals, schools, dormitories and any business that opens a guest wireless network fall under this definition. Under Law No. 5651, such providers have two core duties: to tie each user they grant access to a verified identity, and to retain the records of that access in a tamper-evident, signed form.

This content is for general information only and is not legal advice. For the current scope of your obligations, rely on the legislation itself and a qualified legal advisor.

Who Counts as a Mass-Use Provider?

Unlike an access provider (ISP) whose core business is selling internet access, the legislation frames businesses that offer internet as a secondary amenity as "mass-use providers." The distinguishing test is that access is opened at a defined location, usually temporarily, to a limited body of users. Places that offer internet commercially may additionally need a permit from the relevant authority; the scope varies by business type .

  • Hospitality: hotel, guesthouse, apart-hotel and resort guest Wi-Fi.
  • Food and beverage: café, restaurant, bar and cafeteria customer networks.
  • Retail and public spaces: malls, stores, airports, bus terminals and hospital waiting areas.
  • Corporate: visitor and guest networks in offices, factories, schools and dormitories.

Core Obligations Under Law 5651

The mass-use provider's responsibility comes down to two headings. First, the user connecting to the network must be matched to an identity; second, the resulting traffic and access records must be stored in an unalterable and verifiable way. Together they let an investigation answer "which user, at what time, with which IP or session."

ObligationPurposeWhat it looks like
Identity verificationBind a session to a personSMS/sponsor/form verification via a captive portal
Record keepingAccumulate access/session dataTimestamped connection and session logs
Log signingProve integrityDaily signing with timestamp + e-signature
Retention periodBackward accessibilityHeld for the period the legislation requires

Identity Verification: How to Do It on Guest Internet

In practice the most common method is verifying the user through a captive portal (a landing page). When the user connects to the network they are redirected to the portal, complete verification, and only then reach the internet. SignLogger is brand-independent; it integrates with any RADIUS-capable firewall or access point. Captive portal RADIUS authentication is done with PAP only; EAP-based methods can be used in enterprise 802.1x scenarios. To manage your guest Wi-Fi end to end, see our hotspot management solution.

Signed Logs: Making a Record Legally Meaningful

A raw log is weak as evidence as long as it cannot be shown to be unchanged after the fact. For that reason SignLogger signs the collected logs every day with a timestamp and e-signature from TÜBİTAK Kamu SM, an authorized certificate authority. This makes it possible to verify that a record existed on a given date and has not been altered since. Kamu SM services run on credits (kontör), so the credit balance must be tracked to keep signing continuous. This whole process runs on the customer's own infrastructure (VMware/Hyper-V) and the data never leaves the organization. For details, see the Law 5651 log signing page.

Consequences of Non-Compliance

Failing to meet these duties can lead to administrative sanctions and, during an investigation, shift responsibility onto the business. The legislation provides for administrative fines for providers that do not verify identity or do not retain records properly; the lower and upper bounds of the fine and how it is applied are set by the current regulation . In practice the real risk is that, lacking a signed and verifiable record, the business cannot defend itself.

Frequently Asked Questions

I offer free Wi-Fi in my café; am I still liable?

Yes. What matters is not whether it is paid, but that you offer internet access to users at a specific location. A café that opens Wi-Fi to its guests is treated as a mass-use provider and falls under the verification and signed-log obligations.

Are an access provider and a mass-use provider the same thing?

No. An access provider is the operator that sells internet as its core service; a mass-use provider is a business that offers internet as a secondary amenity. The scope and type of obligations differ between these two roles.

Is just keeping logs enough?

Usually not. For a record to carry evidential value, its integrity must be provable, which requires signing with a timestamp and e-signature. SignLogger performs this signing automatically every day.

How do I verify guests?

The most common method is verification through a captive portal via SMS, sponsor approval or a similar step. When the user connects they are redirected to the portal, complete verification, and the session record is matched to their identity.

Does my data go to an external server?

No. SignLogger is installed to run on the customer's own virtualization infrastructure (VMware/Hyper-V); logs and personal data stay on-premises within the organization.

Does it work with my existing firewall?

Yes. SignLogger is brand-independent and integrates with any RADIUS-capable firewall or access point; you do not need to replace your existing hardware.

Last updated: 25 August 2026

See SignLogger Law 5651 compliance for yourself

Request a free demo