The 1,000-15,000 TRY administrative fine, warning, and up-to-three-day activity suspension sanctions in Law No. 5651 are written only for "commercial-purpose public use providers" — that is, businesses such as internet cafes and similar venues that offer the internet itself for a fee. Businesses offering free Wi-Fi, such as hotels, cafes and offices, are not the direct target of this penalty provision; but that does not mean the record-keeping obligation disappears.
Short answer
Law Article 7/2 imposes the access-record obligation on every public use provider, regardless of whether it is for commercial purposes. However, the administrative fine, warning and activity-suspension sanction in paragraph 4 of the same article is explicitly limited in the text to "commercial-purpose public use providers." Confusing these two sentences is the most common legal mistake seen in the market.
Law Article 7/4
This guide first lays out the full text of the sanction provisions in the Law and the Regulation, and then addresses who these provisions apply to and what the real risk is for a non-commercial business.
The relevant paragraph of the Law reads as follows:
"Bu maddede belirtilen yükümlülükleri ihlal eden ticari amaçla toplu kullanım sağlayıcılarına, ihlalin ağırlığına göre yönetmelikle belirlenecek usul ve esaslar çerçevesinde uyarma, bin Türk Lirasından on beş bin Türk Lirasına kadar idari para cezası verme veya üç güne kadar ticari faaliyetlerini durdurma müeyyidelerinden birine karar vermeye mahalli mülki amir yetkilidir."
"The local civil authority is authorized to decide, in accordance with the procedures and principles to be determined by regulation based on the severity of the violation, on one of the sanctions of issuing a warning, imposing an administrative fine ranging from one thousand to fifteen thousand Turkish Lira, or suspending commercial activities for up to three days, against commercial-purpose public use providers that violate the obligations specified in this article."
Law No. 5651, Art. 7/4 — unofficial translation — mevzuat.gov.tr
The subject of the provision is clear: "commercial-purpose public use providers." The Regulation, in Article 3/1-l, defines this term as businesses that "provide internet public use provider services for a certain fee in internet cafes and similar places open to the public." A hotel or cafe offering free Wi-Fi falls outside this definition; this paragraph therefore does not apply to them directly.
Regulation Article 11
The Regulation ties the sanction to a graduated sequence, and again explicitly limits it to commercial-purpose providers:
"5 inci maddenin birinci fıkrasındaki yükümlülüklere aykırı hareket ettiği belirlenen ticari amaçla internet toplu kullanım sağlayıcılara, mülki idare amiri tarafından ilk ihlalde yazılı olarak uyarma; ihlalin devamı halinde üç güne kadar kapatma; ihlalin tekrarı halinde ise bin Türk Lirasından on beş bin Türk Lirasına kadar idarî para cezası vermeye mahalli mülki amir yetkilidir."
"The local civil authority is authorized to issue, through the local civil administration, a written warning on the first violation, closure for up to three days if the violation continues, and an administrative fine ranging from one thousand to fifteen thousand Turkish Lira if the violation is repeated, against commercial-purpose internet public use providers found to have acted contrary to the obligations in the first paragraph of Article 5."
Regulation on Internet Public Use Providers, Art. 11/1 — unofficial translation — mevzuat.gov.tr
What's worth noting is that the sanction does not jump straight to the harshest penalty: first a written warning, then closure for up to three days if the violation continues, then an administrative fine if the violation is repeated. This graduated structure is applied only in the case of non-compliance with the obligations in Article 5 (operating permit, content filtering, static IP, access records, integrity value) and only for commercial-purpose providers.
Aggravating and mitigating factors
The amount of the administrative fine is not fixed; Regulation Article 12 lists the criteria that determine it:
"Ağırlaştırıcı nedenler şunlardır: a) İhlal sonucunda elde edilen ekonomik kazancın büyüklüğü, b) İhlalin devam etmesi, c) Tekerrürün varlığı. Hafifletici nedenler şunlardır: a) İhlal sonucunda herhangi bir ekonomik kazanç elde edilmemiş olması veya elde edilmişse önem derecesinin düşüklüğü, b) İşyerinin kurallarına uymada geçmiş dönemde gösterdiği olumlu tutum."
"Aggravating factors are: a) The size of the economic gain obtained as a result of the violation, b) The continuation of the violation, c) The existence of repetition. Mitigating factors are: a) The absence of any economic gain as a result of the violation, or the low significance of any gain obtained, b) The business's positive track record of compliance in the past."
Regulation on Internet Public Use Providers, Art. 12 — unofficial translation — mevzuat.gov.tr
These criteria, too, apply to the commercial-purpose providers covered by Article 11, and the decision is left to the discretion of the local civil authority.
The real risk for non-commercial providers
For a non-commercial public use provider such as a hotel, cafe, restaurant, office, factory or school, the correct framing is this: Law Article 7/2 imposes the access-record obligation on you as well, but the 1,000-15,000 TRY administrative fine provision written in the Law does not target you directly. In practice, this does not mean "there is no penalty risk" — the real risk lies elsewhere: if your record is missing or incomplete when a transaction made over your line is investigated, you cannot show who carried it out, and the accountability question stays with your business.
This is not a matter of legal guarantee but of practical risk: a recorded, identity-matched access record lets you respond fully to a request from an authority; the absence of a record leaves your business exposed to being associated with a transaction it did not carry out. This risk takes a different shape by sector: at a factory, it's the subcontractor's employee; at a school, the student; at a hospital, the patient's visitor — their actions always trace back first to the business's line. We cover this topic in detail in the Who Is Responsible for What an Employee Does Online? and What to Do When an Authority Requests Logs guides.
Concrete examples
A hotel guest accesses unlawful content over the hotel's Wi-Fi during their stay. A complaint reaches the hotel's IP address.
The hotel pulls the access record (internal IP, MAC, time, NAT port) matched to the guest's check-in record from the panel, showing which device in which room was connected at that time.
The hotel responds to the inquiry by sharing the record; the person who carried out the transaction is documented, and because the hotel is not in the commercial-purpose category, the 7/4 penalty does not apply to it.
By contrast, if an internet cafe (a commercial-purpose provider) is found, upon inspection, not to have kept access records or to have disabled content filtering, it first receives a written warning; if the violation continues, closure for up to three days; and if it is repeated, it may face a 1,000-15,000 TRY administrative fine. You can find this scenario on the 5651 Compliance for Internet Cafes page.
How izgate reduces the risk
izgate's role here is not to provide immunity from a fine — no one can guarantee you that. What izgate provides is keeping every transaction over your line ready, as an identity-matched, integrity-preserved access record, so that when a request arrives, you are never left saying "we have no record."
In practice this consists of three parts: first, collecting the traffic from your firewall and hotspot devices completely and without loss; second, automatically matching the guest or employee identity to the session, so the question "who was on this IP at that moment" can be answered instantly; third, protecting records with a hash chain and a digital signature so it can be shown they have not been altered afterward. Together, these three parts let you respond to a request by saying "we have the record, and it has not been changed."
Frequently asked questions
Does every business get fined 1,000-15,000 TRY?
No. This fine under Law Article 7/4 is written only for "commercial-purpose public use providers" (businesses such as internet cafes and similar venues that offer the internet itself for a fee). Businesses offering free Wi-Fi, such as hotels, cafes and offices, are not the direct target of this provision.
If the penalty provision doesn't apply to me, do I still need to keep records?
Yes, the obligation remains. Law Article 7/2 imposes the access-record obligation on everyone, regardless of commercial purpose; only the fine provision is specific to commercial-purpose providers. Without a record, the real risk is being unable to show who carried out a transaction when a request arrives.
Does the fine apply directly to an internet cafe?
No, Regulation Article 11 sets out a graduated sequence: a written warning on the first violation, closure for up to three days if it continues, and an administrative fine of 1,000-15,000 TRY on repetition.
Is the fine amount always the same?
No. Regulation Article 12 provides that the amount is determined by aggravating factors — such as the economic gain from the violation, its continuation and repetition — and mitigating factors, such as the absence of economic gain or a positive track record.
This page is for information only; for the current text of the legislation, refer to the official source (mevzuat.gov.tr).



