What Is the Law No. 5651 Log Retention Obligation?
Law No. 5651 requires every organization and business that provides or lets others use internet access to record and retain the connection/traffic logs of its users’ internet activity for a defined period. The purpose is to make it possible to determine, after the fact, which user a given traffic belonged to if an unlawful content or act occurs. The obligation has four essentials: (1) recording the traffic/connection information, (2) sealing these records with a timestamp (and, where needed, an electronic signature) to prove they have not been altered, (3) retaining the records for the legal period, and (4) making guest Wi-Fi users’ identities verifiable. If you provide internet to employees or guests, you are most likely a “mass-use provider” within this scope. The records produced by a home-type modem do not satisfy this obligation; they must be signed, integrity-protected and searchable.
This page is for information only; consult the current legislation and a legal advisor for definitive obligations.
Who does the Law No. 5651 log obligation cover?
The law covers almost every actor that provides or lets others use internet service. In practice, most businesses fall under the mass-use provider role:
- Access providers: Internet service providers (ISPs).
- Hosting providers: Those offering hosting services.
- Content providers: Those running websites, apps or e-commerce.
- Mass-use providers: Hotels, cafes, restaurants, malls, hospitals, schools, dormitories, factories, offices — any business offering guest or staff Wi-Fi.
In short: if you offer an internet connection that others can use, you are within this scope. Venues that provide internet commercially (e.g. internet cafes) may face additional obligations such as obtaining a permit from the local civil authority.
Which logs must be kept?
For mass-use providers, the minimum set is the information that can trace a connection back to a person:
- User authentication: Who connected to the guest network and with which verification (e.g. SMS, form, Turkish ID or sponsor approval).
- Internal IP / DHCP record: The internal IP assigned to the device and its time.
- NAT record: Which public IP and port this internal IP used to reach the internet.
- Connection time: Session start/end information.
It is critical that these records are synchronized to the same time source (NTP); otherwise, minute-level drift between devices makes forensic matching impossible. We cover which device produces which record in the guide on what logs to keep for guest Wi-Fi.
How long must logs be retained?
Retention periods are set by the legislation and may vary by role. For mass-use providers, common practice is to retain traffic/connection records for at least 6 months and at most 2 years. [TO BE VERIFIED: exact minimum–maximum periods per role (access/hosting/mass-use provider) should be confirmed from the current regulation.] Throughout the period, preserving the integrity of the records (being able to prove they were not altered) is essential; simply “keeping a file somewhere” is not enough.
Why are timestamp and e-signature required?
For a log to carry evidential value, it must be possible to prove “when it was produced” and “that it was not altered afterwards.” The mechanism for this is the timestamp and, where needed, the electronic signature. An unsigned/untimestamped archive is open to the objection “it may have been produced later” during an audit. Because an unsigned/untimestamped log is not counted as evidence in an audit, this step is mandatory. In Türkiye, timestamping and signing are performed with the authorized certification authority (TÜBİTAK Kamu SM) timestamp and e-signature; this requires the organization to define its own credit (kontör). SignLogger signs the daily logs every day, automatically, with the authorized certification authority (TÜBİTAK Kamu SM) timestamp and e-signature. If no credit is defined, signing continues uninterrupted with the server’s own certificate and timestamp.
What is the penalty for non-compliance with Law No. 5651?
Failure to meet the obligations leads to administrative fines. Those who fail to fulfil hosting-provider obligations may face fines from TRY 10,000 to TRY 100,000, and those who breach mass-use provider obligations from TRY 3,000 to TRY 15,000. These amounts are updated every year at the revaluation rate, so the current figure changes accordingly. [TO BE VERIFIED: current-year amounts and application details should be confirmed from an official source.] Beyond the fine, failing to produce a record in a judicial case may create additional legal liability.
How do you meet the Law No. 5651 obligation with SignLogger?
SignLogger is a log management and hotspot solution that meets Law No. 5651’s technical obligations on a single platform:
- syslog collection from all brands — FortiGate, Cisco, MikroTik, Sophos, SonicWall, Palo Alto and others;
- daily, automatic signing and retention of logs with the authorized certification authority (TÜBİTAK Kamu SM) timestamp and e-signature;
- captive portal (guest Wi-Fi) with SMS, form, Turkish ID and sponsor verification;
- automatic log rotation, encrypted archiving and audit-ready search/export.
It installs on your own infrastructure as a VMware or Hyper-V image; typical setup takes about 30 minutes. Explore all features or request a free demo from the button below.
Frequently Asked Questions
My home/office modem already keeps logs — isn’t that enough?
No. Home/office modem records rotate quickly, are unsigned and carry no evidential value. Law No. 5651 expects records to be signed/timestamped and retainable for the legal period.
Is it enough to log only the guest network?
Usually no. The firewall/NAT records of the staff network may also fall within scope. Logging only the guest network is incomplete compliance in most scenarios.
How many months must logs be retained?
Common practice for mass-use providers is at least 6 months and at most 2 years; the exact period should be confirmed against your role and the current regulation.
Is a timestamp mandatory — can it be done without an e-signature?
A timestamp is practically essential to prove the integrity and time of records. In SignLogger, signing is done via TÜBİTAK Kamu SM; without credit it continues with the server’s own certificate.
Is the firewall’s own log enough for Law No. 5651?
On its own, usually not. Records must be signed, matched to user identity and stored searchably. We detail this in Is firewall logging enough for Law No. 5651?
How long does setup take?
As SignLogger is a ready virtual appliance, log collection, signing and captive portal setup can be completed the same day in most environments.
Are the penalties actually enforced?
Administrative fines are defined in the legislation and can be applied during audits; the amounts are updated yearly at the revaluation rate. Confirm the current figure from an official source.