Law No. 5651 places an obligation on every business that lets other people use its internet — regardless of whether that is done for commercial purposes — to keep access records. It makes no difference whether it's a hotel, a cafe, an office, a factory or a school: the records must be kept for two years, their accuracy and integrity must be preserved, and the purpose is to be able to show afterward to whom a given transaction on the line belonged.
What is Law No. 5651
The official name of the law is the "Law on the Regulation of Publications on the Internet and Combating Crimes Committed Through Such Publications." The law was adopted on 4/5/2007 and entered into force upon publication in the Official Gazette dated 23/5/2007, No. 26530. Its law number is 5651.
The purpose and scope of the law are defined in its first article as follows:
"Bu Kanunun amaç ve kapsamı; içerik sağlayıcı, yer sağlayıcı, erişim sağlayıcı ve toplu kullanım sağlayıcıların yükümlülük ve sorumlulukları ile internet ortamında işlenen belirli suçlarla içerik, yer ve erişim sağlayıcıları üzerinden mücadeleye ilişkin esas ve usûlleri düzenlemektir."
"The purpose and scope of this Law is to regulate the obligations and responsibilities of content providers, hosting providers, access providers and public use providers, as well as the principles and procedures for combating certain crimes committed via the internet through content, hosting and access providers."
Law No. 5651, Art. 1/1 — unofficial translation — mevzuat.gov.tr
The law defines four main actors: content provider, hosting provider, access provider, and public use provider (toplu kullanım sağlayıcı). This guide focuses on the last group — public use providers — as the one that concerns your business the most. The "Regulation on Internet Public Use Providers," which translates the law's details into practice, entered into force upon publication in the Official Gazette dated 11/4/2017, No. 30035, and remains in effect today (the earlier regulation dated 1/11/2007 was repealed by Article 14 of this regulation). For the full articles of the Law and the Regulation, see the Law No. 5651 legislation page and the Regulation legislation page.
Key definitions
Two definitions determine what this Law covers for your business: public use provider and traffic information.
"Toplu kullanım sağlayıcı: Kişilere belli bir yerde ve belli bir süre internet ortamı kullanım olanağı sağlayanı,"
"Public use provider: A person who provides individuals with the means to use the internet environment, at a certain place and for a certain period of time,"
Law No. 5651, Art. 2/1-i — unofficial translation — mevzuat.gov.tr
The most critical feature of this definition is that it does not care who the internet is given to. There is no distinction between a customer, a guest, a student or an employee; any natural or legal person who gives "individuals" internet access at a certain place falls within this definition. The Regulation repeats the same definition, in a more operational form:
"İnternet toplu kullanım sağlayıcı: Kişilere belli bir yerde ve belli bir süre internet ortamı kullanım olanağı sağlayan gerçek ve tüzel kişileri,"
"Internet public use provider: Natural and legal persons who provide individuals with the means to use the internet environment, at a certain place and for a certain period of time,"
Regulation on Internet Public Use Providers, Art. 3/1-g — unofficial translation — mevzuat.gov.tr
The second key definition identifies which data the law is talking about:
"Trafik bilgisi: Taraflara ilişkin IP adresi, kaynak ve hedef port bilgisi, verilen hizmetin başlama ve bitiş zamanı, yararlanılan hizmetin türü, aktarılan veri miktarı ve varsa abone kimlik bilgilerini,"
"Traffic information: The IP address of the parties, source and destination port information, the start and end time of the service provided, the type of service used, the amount of data transferred, and subscriber identity information if any,"
Law No. 5651, Art. 2/1-j — unofficial translation — mevzuat.gov.tr
For public use providers, the Regulation defines this traffic information more concretely as "access records"; we cover that definition in detail below. For the field-by-field breakdown, see also the What Are Access Records? guide.
The law's other three actors — content provider, hosting provider and access provider — generally do not concern your business directly. A content provider is the party that produces and supplies information over the internet; a hosting provider is the party that operates the servers hosting that content; an access provider is the operator that gives its users the means to access the internet environment (for example, the internet service provider your subscription comes from). Your business acquires the status of "public use provider" the moment you share your own line with a guest, a customer or an employee; these four definitions are not interchangeable, and each carries different obligations.
Who is covered
Because the definition makes no distinction among customers, guests, students and employees, any setting where internet is provided falls within scope: hotels and lodging facilities, cafes and restaurants, factories and construction sites, schools and dormitories, hospitals, municipalities and public institutions, shopping malls and retail chains, coworking spaces, gyms and beauty salons, and ordinary workplaces and offices. They all share one thing in common: the internet line is registered in the business's name, and when a transaction made over that line is investigated, the first party addressed is the business itself.
This responsibility takes a different face in every sector: the hotel guest and the front-desk staff who host them, the customer ordering at a cafe and the cashier at the register, the shift worker at a factory and the subcontractor supervising them, the student connecting between classes at school and the teacher on duty. The role changes, but the question is always the same: which internal IP, which device, and which person was connected at that moment? Without a record, you cannot answer that question; with one, you can show who carried out the transaction and protect your business.
If you'd like to see industry-specific practices at this point, you can look at the hotels and hospitality, cafes and restaurants, workplaces and offices, factories and manufacturing or schools and education pages; these pages describe the same obligation through each sector's real roles.
A workplace that gives its employees internet access falls under the same definition too — the Law says "individuals," not "customers." A review of a transaction made over a corporate line starts with the business that owns that line; without a record, there is no way to determine who carried out the transaction, and the accountability question stays with the business. For more detail on this, see the Who Is Responsible for What an Employee Does Online? guide.
A visitor device connected to a factory's guest network is identified as the source of attack traffic outside working hours. The external IP traces back to the line registered to the factory.
The access record shows which internal IP, which MAC address and which NAT port were in use at that moment; the alias code matched to the visitor entry confirms the session belongs to the registered device.
The factory can check its own internal records to document which device carried out the action and the exact time window, and can respond to the authority's request fully and quickly.
Commercial vs. non-commercial providers
The Law and the Regulation split public use providers into two groups: general public use providers, and those that act "for commercial purposes." This distinction is the single most important factor in determining which provision applies to you. The Regulation defines a "commercial-purpose internet public use provider" as follows:
"Ticari amaçla internet toplu kullanım sağlayıcı: İnternet salonu ve benzeri umuma açık yerlerde belirli bir ücret karşılığı internet toplu kullanım sağlayıcılığı hizmeti veren veya bununla beraber bilgisayarlarda bilgi ve beceri artırıcı veya zeka geliştirici nitelikteki oyunların oynatılmasına imkân sağlayan gerçek ve tüzel kişileri,"
"Commercial-purpose internet public use provider: Natural and legal persons who, in internet cafes and similar places open to the public, provide internet public use provider services for a certain fee, or who, in addition, enable the playing of games on computers that are of an educational or skill/intelligence-enhancing nature,"
Regulation on Internet Public Use Providers, Art. 3/1-l — unofficial translation — mevzuat.gov.tr
In other words, "commercial purpose" is limited to "charging money for the internet itself" — internet cafes and similar venues. A hotel, cafe, restaurant, office or factory that offers free Wi-Fi to its customers or guests does not fall within this definition; such businesses are considered non-commercial public use providers and are subject to the general obligations in Article 4 of the Regulation. Telling a hotel or a cafe that they "must obtain an operating permit" or that they will be "fined 15,000 TRY" is a misapplication of this definition. You can find how the commercial-purpose category works in practice on the 5651 Compliance for Internet Cafes page.
Obligations
Article 7 of the Law regulates the obligations of public use providers. Its second paragraph sets out the baseline obligation that applies to everyone, without distinction:
"Ticari amaçla olup olmadığına bakılmaksızın bütün internet toplu kullanım sağlayıcılar, konusu suç oluşturan içeriklere erişimin engellenmesi ve kullanıma ilişkin erişim kayıtlarının tutulması hususlarında yönetmelikle belirlenen tedbirleri almakla yükümlüdür."
"Regardless of whether it is for commercial purposes or not, all internet public use providers are obliged to take the measures determined by regulation regarding the blocking of access to content that constitutes a criminal offense and the keeping of access records relating to use."
Law No. 5651, Art. 7/2 — unofficial translation — mevzuat.gov.tr
Article 4 of the Regulation makes this obligation concrete, and it applies to all public use providers:
"İnternet toplu kullanım sağlayıcılarının yükümlülükleri şunlardır: a) Konusu suç oluşturan içeriklere erişimi önleyici tedbirleri almak amacıyla içerik filtreleme sistemini kullanmak. b) Erişim kayıtlarını elektronik ortamda kendi sistemlerine kaydetmek ve iki yıl süre ile saklamak. c) Kamuya açık alanlarda internet erişimi sağlayan toplu kullanım sağlayıcılar, kısa mesaj servisi (sms) ve benzeri yöntemlerle kullanıcıları tanımlayacak sistemleri kurmak."
"The obligations of internet public use providers are as follows: a) To use a content filtering system in order to take measures that prevent access to content constituting a criminal offense. b) To record access records in electronic form in their own systems and retain them for a period of two years. c) Public use providers that provide internet access in publicly accessible areas shall set up systems that identify users through SMS (text message) or similar methods."
Regulation on Internet Public Use Providers, Art. 4/1 — unofficial translation — mevzuat.gov.tr
Under Article 4/2, a safe internet service may also be obtained as an additional measure alongside content filtering — this is optional, not mandatory. Content filtering itself is not a feature of izgate: filtering is performed by your firewall's own web filter; izgate collects and reports the blocking records that filter produces.
For commercial-purpose providers, Article 5 of the Regulation adds further obligations: obtaining an operating permit from the local civil authority, using a content filtering system and safe internet service, keeping the filter active and up to date, obtaining a static IP and reporting any change within 15 days, retaining access records for two years, and recording daily a value that confirms the accuracy, integrity and confidentiality of those records. These provisions concern businesses similar to internet cafes; they do not apply to non-commercial providers such as hotels, cafes or offices.
What access records are
The Regulation spells out the "access records" definition field by field:
"Erişim kayıtları: Kendi iç ağlarında dağıtılan IP adres bilgilerini, kullanıma başlama ve bitiş zamanını ve bu IP adreslerini kullanan bilgisayarların tekil ağ cihaz numarasını (MAC adresi) gösteren bilgileri, hedef IP adresi, bir veya birden fazla IP adresinin portlar aracılığı ile kullanıcılara paylaştırılması yöntemi ile sunulan internet erişim hizmetinde kullanıcıya tahsis edilen gerçek IP ve port bilgilerini,"
"Access records: Information showing the IP address information distributed on their own internal networks, the start and end time of use, and the unique network device number (MAC address) of the computers using those IP addresses; the destination IP address; and, where internet access service is provided by sharing one or more IP addresses among users through ports, the real IP and port information allocated to the user,"
Regulation on Internet Public Use Providers, Art. 3/1-e — unofficial translation — mevzuat.gov.tr
Simplified, that's five fields: internal IP, start/end time of use, MAC address, destination IP, and the NAT (real) IP and port information. You can find why each of these fields matters, with a sample log line, in the What Are Access Records? guide.
Retention period: two years
The Regulation sets the retention period for access records the same way for both general public use providers and commercial-purpose ones: two years.
"Erişim kayıtlarını elektronik ortamda kendi sistemlerine kaydetmek ve iki yıl süre ile saklamak."
"To record access records in electronic form in their own systems and retain them for a period of two years."
Regulation on Internet Public Use Providers, Art. 4/1-b — unofficial translation — mevzuat.gov.tr
For commercial-purpose providers, Article 5/1-d repeats the same period, and Article 5/1-e additionally requires that the integrity value of the records be kept for the same period. We cover where the two-year period comes from, and how izgate exposes it as a panel setting, in detail in the 5651 Log Retention Period guide.
The integrity value and timestamps
The legislation does not make the word "timestamp" mandatory for general public use providers. For commercial-purpose providers, Regulation Article 5/1-e requires that a value confirming the "accuracy, integrity and confidentiality" of the records be recorded daily:
"(d) bendi gereğince kaydedilen bilgileri ve bu bilgilerin doğruluğunu, bütünlüğünü ve gizliliğini teyit eden değeri kendi sistemlerine günlük olarak kaydetmek ve bu verileri iki yıl süre ile saklamak,"
"To record daily, in their own systems, the information recorded pursuant to clause (d) and the value confirming the accuracy, integrity and confidentiality of that information, and to retain that data for a period of two years,"
Regulation on Internet Public Use Providers, Art. 5/1-e — unofficial translation — mevzuat.gov.tr
Technically, this "value" can be strengthened with a timestamp. Law No. 5070, the Electronic Signature Law, defines a timestamp as follows:
"Zaman damgası: Bir elektronik verinin, üretildiği, değiştirildiği, gönderildiği, alındığı ve / veya kaydedildiği zamanın tespit edilmesi amacıyla, elektronik sertifika hizmet sağlayıcısı tarafından elektronik imzayla doğrulanan kaydı,"
"Timestamp: A record verified with an electronic signature by an electronic certificate service provider, for the purpose of determining the time at which an electronic data item was produced, altered, sent, received and/or recorded,"
Electronic Signature Law No. 5070, Art. 3/h — unofficial translation — mevzuat.gov.tr
The correct framing is this: a timestamp obtained from an authorized electronic certificate service provider (e.g., Kamu SM) independently proves that a record existed on a given date and was not altered afterward; it strengthens the evidentiary value of the records. Statements like "logs without a timestamp are invalid" or "it's a legal requirement for everyone" are not accurate — the legislation does not use this term for general public use providers. In izgate, records are protected hourly with a hash chain and a digital signature; in addition, a qualified timestamp is obtained once a day from Kamu SM, and an automatic integrity check runs every night. For details, see the What Is a Timestamp? and Log Integrity: Hash Chains, Digital Signatures and Verification guides.
Relationship with KVKK
Once access records are matched to a user's identity, they amount to the processing of personal data, which brings Law No. 6698 on the Protection of Personal Data (KVKK) into play. KVKK lists the circumstances under which personal data may be processed without seeking explicit consent:
"a) Kanunlarda açıkça öngörülmesi." ... "ç) Veri sorumlusunun hukuki yükümlülüğünü yerine getirebilmesi için zorunlu olması."
"a) It is explicitly provided for by law." ... "ç) It is mandatory for the data controller to fulfil its legal obligation."
KVKK, Art. 5/2-a and ç — unofficial translation — mevzuat.gov.tr
In other words, the legal basis for access records kept under Law No. 5651 comes directly from the law itself; obtaining separate "explicit consent" from a guest or employee is not required. KVKK Article 10, however, imposes a privacy-notice obligation on the data controller: you must inform the data subject of your identity, the purpose of processing, the parties to whom the data may be transferred, the method of collection, and the legal basis.
KVKK Article 12 further imposes a data-security obligation: you must take the technical and administrative measures necessary to achieve an appropriate level of security in order to prevent the unlawful processing of personal data, prevent unlawful access to it, and ensure its proper preservation. In practice, this is met by a system in which access records can only be viewed by authorized personnel, are stored encrypted, and cannot be altered by mistake or malicious intent. We cover this topic for guest Wi-Fi in the Guest Wi-Fi and KVKK guide, and its general framework on the KVKK and Access Records legislation page.
Sanctions: who they apply to
Paragraph 7/4 of the Law explicitly limits the sanction to "commercial-purpose public use providers":
"Bu maddede belirtilen yükümlülükleri ihlal eden ticari amaçla toplu kullanım sağlayıcılarına, ihlalin ağırlığına göre yönetmelikle belirlenecek usul ve esaslar çerçevesinde uyarma, bin Türk Lirasından on beş bin Türk Lirasına kadar idari para cezası verme veya üç güne kadar ticari faaliyetlerini durdurma müeyyidelerinden birine karar vermeye mahalli mülki amir yetkilidir."
"The local civil authority is authorized to decide, in accordance with the procedures and principles to be determined by regulation based on the severity of the violation, on one of the sanctions of issuing a warning, imposing an administrative fine ranging from one thousand to fifteen thousand Turkish Lira, or suspending commercial activities for up to three days, against commercial-purpose public use providers that violate the obligations specified in this article."
Law No. 5651, Art. 7/4 — unofficial translation — mevzuat.gov.tr
This administrative fine and closure sanction concerns only businesses that fall within the "commercial-purpose" definition (internet cafes and the like). For businesses such as hotels, cafes and offices, the correct statement is this: the Law (Art. 7/2) imposes the access-record obligation on everyone regardless of commercial purpose, but the fine provision written in the text is specific to commercial-purpose providers. This does not mean the record does not need to be kept — it only means that a generalization like "every cafe gets a 15,000 TRY fine" is legally incorrect. For non-commercial providers, the practical risk is less about a fine and more about being unable to show who carried out a transaction when a request arrives.
For commercial-purpose providers, Article 12 of the Regulation provides that the amount of the administrative fine is not fixed, but is determined according to aggravating and mitigating factors: the size of the economic gain obtained from the violation, the continuation of the violation, and repetition aggravate the penalty, while the absence of economic gain or the business's positive track record in the past mitigate it. This distinction applies only to the commercial-purpose category and is left to the discretion of the local civil authority. For more detail, see the 5651 Penalties and Sanctions guide.
Practical checklist
You can go through the list below in order to quickly assess your current setup; every "no" answer points to a concrete gap you may face when a request arrives.
- Are the access records from all access points on your network (firewall, hotspot device) collected centrally?
- Do the records fully include the internal IP, MAC, start/end time of use, destination IP, and NAT IP/port information?
- Are records retained for at least two years; if disk space runs out, are records silently deleted, or is a warning raised?
- Is the user's identity (guest, employee) automatically matched to the access record, or is only the IP kept?
- Is there a hash chain or signature that shows the records' integrity (that they have not been altered)?
- If you provide internet in a publicly accessible area, is there a system that identifies users via SMS or a similar method?
- Does your guest Wi-Fi portal carry a KVKK privacy notice?
- If you operate on a commercial-purpose basis (similar to an internet cafe), are your operating permit and static-IP notification up to date?
How izgate meets each provision
The table below maps the provisions the Regulation sets out for general public use providers to izgate's corresponding technical features.
- Art. 4/1-b — recording access records electronicallyizgate writes every session from your firewall and hotspot devices to a live database, together with the internal IP, MAC, destination IP, NAT IP/port, and timing information.
- Art. 4/1-b — two-year retentionLive and archive retention periods are each defined in days from the panel; two years is recommended by default for 5651, and records are never deleted even when disk space runs low — a warning is raised instead.
- Value confirming accuracy, integrity and confidentialityArchive segments are protected with a SHA-256 chain and an Ed25519 signature; a qualified timestamp is obtained from Kamu SM once a day; an automatic integrity check runs every night.
- Art. 4/1-c — a system that identifies usersThe guest Wi-Fi portal identifies the user via SMS verification, Turkish ID number, visitor code, admin approval, registered device, pre-registration, or corporate RADIUS/LDAP; an alias code, not the real identity, is written to the firewall logs.
- A complete response to a requestThe relevant date range can be verified from the Archive page, downloaded, and exported as a signed package; restoring it back to the live system is also possible.
Related guide and legislation pages
Pages that cover every topic touched on in this guide in more detail are listed below by category.
Legislation
- What Is a Public Use Provider, and Who Does It Cover?
- The 5651 Log Retention Period: Why Two Years?
- 5651 Penalties and Sanctions: Who Do They Apply To, and When?
- What Are Access Records? Internal IP, MAC and NAT Port
- What Is a Timestamp, and Why Does It Matter for Log Records?
- Guest Wi-Fi and KVKK: Privacy Notice and Legal Basis
- Law No. 5651 — the provisions that concern public use providers
- Regulation on Internet Public Use Providers (2017)
- KVKK (6698) and Access Records
- Electronic Signature Law No. 5070 and Timestamps
Practice
- Who Is Responsible for What an Employee Does Online? Internet Records in the Workplace
- What to Do When an Authority Requests Logs
- What Is a Hotspot and Captive Portal, and How Do They Work?
- Guest Verification: SMS, ID Number, or a Visitor Code?
- Content Filtering Obligations and Safe Internet Service
- Why Should Guest and Staff Networks Be Separated?
- How Do Printers, Robots and IoT Devices Get Through a Captive Portal?
- Log Integrity: Hash Chains, Digital Signatures and Verification
- What Happens If NAT and Port Information Isn't Logged?
Setup
- 5651 Logging and Captive Portal Setup with FortiGate
- MikroTik Hotspot and 5651 Logging Setup
- 5651 Logging with pfSense and OPNsense
Selection & Cost
- Appliance, Software or Cloud for 5651?
- 10 Criteria for Choosing 5651 Logging Software
- What Determines the Cost of 5651 Logging?
Frequently asked questions
Does Law No. 5651 only concern internet cafes?
No. The law's "public use provider" definition makes no distinction between customers, guests and employees; any business providing internet — a hotel, cafe, office, factory or school — is within scope. The operating-permit and administrative-fine provisions, on the other hand, concern only "commercial-purpose" businesses (internet cafes and similar venues that sell internet access for a fee).
I offer free Wi-Fi to my guests — do I need an operating permit?
No. The operating-permit obligation in Article 5 of the Regulation is set out only for a "commercial-purpose internet public use provider" (internet cafes and similar venues providing paid service). A hotel, cafe or office offering free guest Wi-Fi falls outside this definition.
How long do I need to keep access records?
Regulation Articles 4/1-b and 5/1-d require access records to be recorded electronically and retained for a period of two years. Phrases like "1 year" or "1-2 years" are not consistent with the legislation; the period is explicitly two years.
If I don't get a timestamp, are my records invalid?
The legislation does not make the word "timestamp" mandatory for general public use providers. For commercial-purpose providers, a value confirming the accuracy, integrity and confidentiality of the records must be recorded daily (Regulation Art. 5/1-e); a timestamp is a tool that strengthens that value and increases its evidentiary weight — it is not, on its own, a mandatory requirement.
Is my business responsible for what my employees do online?
The internet line is registered in the business's name; when a transaction made over that line is investigated, the question comes to the business first. Access records matched to an identity show who carried out the transaction, allowing the business to document it. This is not a legal guarantee; having the record simply makes it easier to respond fully to a request from an authority.
This page is for information only; for the current text of the legislation, refer to the official source (mevzuat.gov.tr).



