Legislation

Guest Wi-Fi and KVKK: privacy notice and legal basis

The moment you ask your guest for a phone number or a Turkish ID number, KVKK comes into play. This guide explains why obtaining a guest's "explicit consent" is not mandatory, which obligations remain in its place, and how izgate meets this on the portal.

The moment you collect a phone number, a Turkish ID number, or a full name on your guest Wi-Fi, you are processing personal data, and that brings Law No. 6698 on the Protection of Personal Data (KVKK) into play. The good news: for access records kept under 5651, the legal basis comes directly from the law, and you are not required to separately obtain "explicit consent" from the guest. The privacy-notice and data-security obligations, on the other hand, still apply. In this guide, we address each obligation separately and show the concrete screens and settings izgate's guest portal uses to meet them.

Short answer

You do not need to obtain explicit consent from your guest in order to keep access records under 5651; the legal basis comes from the exceptions in KVKK Article 5/2. You do, however, need to inform your guest about who is processing their data, for what purpose, and by what method (KVKK Art. 10), and to keep that data secure (KVKK Art. 12).

Legal basis: explicit consent is not required

KVKK lists the circumstances under which personal data may be processed without seeking explicit consent; two of these are directly relevant in the 5651 context:

"a) Kanunlarda açıkça öngörülmesi." ... "ç) Veri sorumlusunun hukuki yükümlülüğünü yerine getirebilmesi için zorunlu olması."

"a) It is explicitly provided for by law." ... "ç) It is mandatory for the data controller to fulfil its legal obligation."

KVKK, Art. 5/2-a and ç — unofficial translation — mevzuat.gov.tr

Because Law No. 5651, Article 7/2, directly mandates the keeping of access records by law, and this is a legal obligation, a separate consent checkbox on your guest Wi-Fi portal — such as "we record your data under 5651, do you agree?" — is not mandatory. A consent checkbox may be needed only if you process data for an additional purpose outside the scope of 5651 (for example, marketing communications) — that requires a different legal basis and should be assessed separately from your 5651 record-keeping.

The privacy-notice obligation

Not requiring explicit consent does not mean you don't need to inform the guest at all. KVKK Article 10 imposes a privacy-notice obligation on the data controller:

"Kişisel verilerin elde edilmesi sırasında veri sorumlusu veya yetkilendirdiği kişi, ilgili kişilere; a) Veri sorumlusunun ve varsa temsilcisinin kimliği, b) Kişisel verilerin hangi amaçla işleneceği, c) İşlenen kişisel verilerin kimlere ve hangi amaçla aktarılabileceği, ç) Kişisel veri toplamanın yöntemi ve hukuki sebebi, d) 11 inci maddede sayılan diğer hakları, konusunda bilgi vermekle yükümlüdür."

"When collecting personal data, the data controller or the person it authorizes is obliged to inform the data subjects of: a) The identity of the data controller and its representative, if any, b) The purpose for which the personal data will be processed, c) The parties to whom and the purpose for which the processed personal data may be transferred, ç) The method and legal basis of personal data collection, d) The other rights listed in Article 11."

KVKK, Art. 10/1 — unofficial translation — mevzuat.gov.tr

In practice, this means that a short, readable privacy notice should appear on your guest Wi-Fi login portal: your business's identity, the purpose the data is processed for (keeping access records under 5651), to whom it may be transferred (authorities, upon request), and the data subject's rights. This text doesn't need to look like a long, legalistic contract; it serves the purpose better when it's written in plain language that a guest can read in a few lines before completing the login step.

KVKK Article 11 also grants the data subject (the guest) certain rights: to learn whether data about them is being processed, to ask about the purpose of processing, to know the third parties to whom data is transferred domestically or abroad, and to request correction or deletion of the data. Your privacy notice is expected to state that these rights exist and how they can be exercised (for example, by providing an email address).

The data-security obligation

KVKK Article 12 requires you to protect the data you collect:

"Veri sorumlusu; a) Kişisel verilerin hukuka aykırı olarak işlenmesini önlemek, b) Kişisel verilere hukuka aykırı olarak erişilmesini önlemek, c) Kişisel verilerin muhafazasını sağlamak, amacıyla uygun güvenlik düzeyini temin etmeye yönelik gerekli her türlü teknik ve idari tedbirleri almak zorundadır."

"The data controller is obliged to take all necessary technical and administrative measures to achieve an appropriate level of security in order to: a) Prevent the unlawful processing of personal data, b) Prevent unlawful access to personal data, c) Ensure the preservation of personal data."

KVKK, Art. 12/1 — unofficial translation — mevzuat.gov.tr

In the guest Wi-Fi context, this means that data such as a phone number or Turkish ID number should only be visible to authorized panel users, should be stored encrypted, and should not be written to firewall logs in raw form.

Data minimization: the masked identity

One of KVKK's general principles is that data processing must be limited to, and proportionate with, its purpose. izgate implements this principle technically as follows: the guest is assigned a fixed alias code at login (for example, mg-4a300c); the firewall and RADIUS logs carry this code, not the real identity, in the username and user= field. The mapping between the alias code and the real person (name, masked phone/ID) is kept only in izgate, encrypted, and is resolved only on the authorized search screen. This way, the real identity information is never spread to systems (firewall, log files) that don't need it. This approach aligns with the principle in KVKK Article 4/2-ç, which requires personal data to be relevant, limited, and proportionate to the purposes for which they are processed: the purpose of the access record is to be able to identify who was connected, and that purpose does not require the real identity to be visibly exposed in every system.

Guest Wi-Fi portal design and privacy-notice editor in the izgate panel
Portal editor: the KVKK privacy notice and the service agreement are filled in with your company details and added to the login screen.

Employee (staff Wi-Fi) data

The same legal basis and privacy-notice logic also applies to the office/staff Wi-Fi assigned to your employees. A transaction made by an employee from the corporate network is also kept as an access record under 5651; informing the employee about this (for example, through an employment contract or an internal policy) satisfies your privacy-notice obligation. Unlike guest Wi-Fi, the staff network generally involves a defined, recurring group of users; it is therefore sufficient to provide this notice once, at onboarding, and update it as needed. We cover this topic in detail in the Who Is Responsible for What an Employee Does Online? guide.

The privacy notice in the izgate portal

izgate's guest Wi-Fi portal comes with a default KVKK privacy-notice template and an Internet Use Service Agreement template; these templates are filled in with your company's details and integrated into your portal design (logo, color, language). Whatever login method you choose — SMS, Turkish ID number, visitor code, admin approval, registered device, or corporate RADIUS/LDAP — the privacy notice is shown to the guest before the login step. The text can be prepared in Turkish/English, so your foreign guests can also read the same notice in their own language.

Checklist

  • Does your guest Wi-Fi portal have a KVKK privacy notice?
  • Does the notice state the data controller's identity, the purpose of processing, the parties the data may be transferred to, and the legal basis?
  • Is the guest's real identity information (phone, ID) written to firewall logs in raw form, or carried via a masked/alias code?
  • Who can access this data; is access restricted to authorized personnel?
  • Have your employees been informed that their internet use on the corporate network is being recorded?

Frequently asked questions

Do I need to obtain explicit consent from a guest to log in to Wi-Fi?

Not for keeping access records under 5651; the legal basis comes from KVKK Article 5/2-a and ç (provided for by law, mandatory legal obligation). Consent may be needed only if you process data for an additional purpose outside of 5651 (for example, marketing).

Is a privacy notice mandatory on the portal?

Yes, KVKK Article 10 imposes a privacy-notice obligation on the data controller: you must inform the guest of your identity, the purpose of processing, the parties the data may be transferred to, the collection method, and the legal basis.

Is a guest's real phone number written to the firewall?

Not in izgate. The guest is assigned a fixed alias code; the firewall and RADIUS logs carry this code, and the real identity is kept only in izgate, encrypted, resolved only on the authorized search screen.

Do I need to provide a notice for my employees too?

Yes, an employee's internet use on the corporate network is also recorded under 5651; informing the employee about this (through a contract, internal policy, etc.) satisfies the privacy-notice obligation.

This page is for information only; for the current text of the legislation, refer to the official source (mevzuat.gov.tr).

Launch your guest Wi-Fi with a KVKK-compliant portal.

A ready-made privacy notice, masked-identity matching, and portal design adapted to your brand — all in one package.