Legislation

KVKK and access records: how personal data is processed on guest Wi-Fi

The access records kept under 5651, along with information such as a phone number or Turkish ID number collected on the guest Wi-Fi portal, also fall within the scope of Law No. 6698 on the Protection of Personal Data (KVKK). This page explains KVKK's general principles, the processing condition, the duty to inform, and the data-security provision, with the verbatim text, in the context of access records and guest Wi-Fi.

Law No.: 6698 · Date of enactment: 24/3/2016 · Official Gazette: 7/4/2016, issue 29677.

Definitions

MADDE 3- (1) Bu Kanunun uygulanmasında; […]
a) Açık rıza: Belirli bir konuya ilişkin, bilgilendirilmeye dayanan ve özgür iradeyle açıklanan rızayı,
[…]
ç) İlgili kişi: Kişisel verisi işlenen gerçek kişiyi,
d) Kişisel veri: Kimliği belirli veya belirlenebilir gerçek kişiye ilişkin her türlü bilgiyi,
e) Kişisel verilerin işlenmesi: Kişisel verilerin tamamen veya kısmen otomatik olan ya da herhangi bir veri kayıt sisteminin parçası olmak kaydıyla otomatik olmayan yollarla elde edilmesi, kaydedilmesi, depolanması, muhafaza edilmesi, değiştirilmesi, yeniden düzenlenmesi, açıklanması, aktarılması, devralınması, elde edilebilir hâle getirilmesi, sınıflandırılması ya da kullanılmasının engellenmesi gibi veriler üzerinde gerçekleştirilen her türlü işlemi,
[…]
ı) Veri sorumlusu: Kişisel verilerin işleme amaçlarını ve vasıtalarını belirleyen, veri kayıt sisteminin kurulmasından ve yönetilmesinden sorumlu olan gerçek veya tüzel kişiyi,
ifade eder.

"ARTICLE 3- (1) For the purposes of this Law; […]
a) Explicit consent: Consent relating to a specific matter, based on being informed, and expressed by free will;
[…]
ç) Data subject: The natural person whose personal data is processed;
d) Personal data: Any information relating to an identified or identifiable natural person;
e) Processing of personal data: Any operation performed on data, such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, taking over, making retrievable, classifying, or preventing the use of personal data, wholly or partly by automatic means, or by non-automatic means provided that it forms part of a data recording system;
[…]
ı) Data controller: The natural or legal person who determines the purposes and means of processing personal data and who is responsible for establishing and managing the data recording system;
shall mean the following."

Law No. 6698 (KVKK), Art. 3/1-a, ç, d, e, ı — unofficial translation — mevzuat.gov.tr

What this means: In the guest Wi-Fi context: a guest's phone number, Turkish ID number, or name is "personal data"; the guest is the "data subject"; since your business decides for what purpose and how this information is processed, you (your business) are the "data controller," and izgate is the "data processor" providing the technical infrastructure on your behalf.

Article 4 — General principles

MADDE 4- (1) Kişisel veriler, ancak bu Kanunda ve diğer kanunlarda öngörülen usul ve esaslara uygun olarak işlenebilir.
(2) Kişisel verilerin işlenmesinde aşağıdaki ilkelere uyulması zorunludur:
a) Hukuka ve dürüstlük kurallarına uygun olma.
b) Doğru ve gerektiğinde güncel olma.
c) Belirli, açık ve meşru amaçlar için işlenme.
ç) İşlendikleri amaçla bağlantılı, sınırlı ve ölçülü olma.
d) İlgili mevzuatta öngörülen veya işlendikleri amaç için gerekli olan süre kadar muhafaza edilme.

"ARTICLE 4- (1) Personal data may only be processed in accordance with the procedures and principles set out in this Law and other laws.
(2) The following principles must be complied with when processing personal data:
a) Lawfulness and fairness.
b) Being accurate and, where necessary, kept up to date.
c) Being processed for specified, explicit, and legitimate purposes.
ç) Being relevant to, limited to, and proportionate with the purposes for which they are processed.
d) Being retained for the period stipulated by the relevant legislation or for the period required for the purpose for which they are processed."

Law No. 6698 (KVKK), Art. 4 — unofficial translation — mevzuat.gov.tr

What this means: These five principles have practical consequences for access records and guest data: under principle (ç), only the information necessary for verification is requested from the guest, nothing more is collected. Under principle (d), the retention period is limited to the period stipulated by the legislation (two years for 5651) — indefinite retention would be contrary to this principle.

Article 5 — Processing conditions and legal basis

MADDE 5- (1) Kişisel veriler ilgili kişinin açık rızası olmaksızın işlenemez.
(2) Aşağıdaki şartlardan birinin varlığı hâlinde, ilgili kişinin açık rızası aranmaksızın kişisel verilerinin işlenmesi mümkündür:
a) Kanunlarda açıkça öngörülmesi.
[…]
ç) Veri sorumlusunun hukuki yükümlülüğünü yerine getirebilmesi için zorunlu olması.
[…]

"ARTICLE 5- (1) Personal data may not be processed without the explicit consent of the data subject.
(2) Personal data may be processed without seeking the explicit consent of the data subject where one of the following conditions exists:
a) It is explicitly provided for by law.
[…]
ç) It is mandatory for the data controller to fulfill its legal obligation.
[…]"

Law No. 6698 (KVKK), Art. 5/1, 5/2-a, ç — unofficial translation — mevzuat.gov.tr

What this means: Law No. 5651 and its related Regulation explicitly require that access records be kept (Art. 5/2-a), and this is, at the same time, the data controller's (your business's) legal obligation (Art. 5/2-ç). For this reason, obtaining separate "explicit consent" from the guest for keeping access records is not required — the legal basis comes directly from the law. However, displaying a KVKK privacy notice on the guest Wi-Fi portal (see Art. 10 below) is a separate and independent obligation.

Article 10 — Duty to inform

MADDE 10- (1) Kişisel verilerin elde edilmesi sırasında veri sorumlusu veya yetkilendirdiği kişi, ilgili kişilere;
a) Veri sorumlusunun ve varsa temsilcisinin kimliği,
b) Kişisel verilerin hangi amaçla işleneceği,
c) İşlenen kişisel verilerin kimlere ve hangi amaçla aktarılabileceği,
ç) Kişisel veri toplamanın yöntemi ve hukuki sebebi,
d) 11 inci maddede sayılan diğer hakları,
konusunda bilgi vermekle yükümlüdür.

"ARTICLE 10- (1) At the time personal data is obtained, the data controller or the person it authorizes is obliged to inform data subjects about;
a) The identity of the data controller and its representative, if any;
b) The purpose for which personal data will be processed;
c) To whom, and for what purpose, the processed personal data may be transferred;
ç) The method and legal basis of collecting personal data;
d) The other rights listed in Article 11."

Law No. 6698 (KVKK), Art. 10 — unofficial translation — mevzuat.gov.tr

What this means: Every person connecting to guest Wi-Fi must be clearly shown, at the moment of access (e.g. on the login/portal screen), who you are, for what purpose you're collecting their data, to whom you may transfer it, your collection method/legal basis, and what their rights are.

izgate's counterpart: izgate's guest portal carries a default KVKK privacy notice and an Internet Use Service Agreement template, filled in with your company information; access is not opened until the guest approves this text.

Article 12 — Data security obligations

MADDE 12- (1) Veri sorumlusu;
a) Kişisel verilerin hukuka aykırı olarak işlenmesini önlemek,
b) Kişisel verilere hukuka aykırı olarak erişilmesini önlemek,
c) Kişisel verilerin muhafazasını sağlamak,
amacıyla uygun güvenlik düzeyini temin etmeye yönelik gerekli her türlü teknik ve idari tedbirleri almak zorundadır.

"ARTICLE 12- (1) The data controller is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security, for the purpose of;
a) Preventing the unlawful processing of personal data;
b) Preventing unlawful access to personal data;
c) Ensuring the preservation of personal data."

Law No. 6698 (KVKK), Art. 12/1 — unofficial translation — mevzuat.gov.tr

What this means: The system holding access records and guest identity information needs to be protected with technical measures against unauthorized access and unlawful processing — encryption, access control, authorization, and similar measures.

izgate's counterpart: The guest's real identity (phone/Turkish ID number) is stored encrypted; only a fixed alias code is ever written to the firewall and the traffic logs — the raw identity is never written to the firewall or to a log line. The alias-code-to-person mapping is kept encrypted only inside izgate and is resolved only on the authorized search screen. API tokens, the RADIUS shared secret, and the SMS provider secret are stored encrypted.

Application to 5651 access records and guest Wi-Fi

Combining these four articles in the context of access records and guest Wi-Fi produces the following practical framework:

  • Legal basis: You don't need to ask the guest for explicit consent to keep access records; the basis comes directly from 5651 and the related Regulation (Art. 5/2-a, ç).
  • Informing is still required: Even though explicit consent isn't required, you must still show the guest who you are, what data you collect for what purpose, and what their rights are (Art. 10, Art. 11).
  • Alias identity: Writing only an alias code to firewall logs, instead of the raw identity (phone/Turkish ID number), is a design choice consistent with the "proportionality" principle in Art. 4 and the data-security obligation in Art. 12.
  • Retention-period limit: Under the principle in Art. 4/2-d, access records must be kept only for the period stipulated by the relevant legislation (two years for 5651), not indefinitely.

Frequently asked questions

Do I need explicit consent to keep access records on guest Wi-Fi?

You don't need separate explicit consent to keep access records; the legal basis comes directly from 5651 and the related Regulation under KVKK Art. 5/2-a and ç. You do, however, need to inform the guest under KVKK Art. 10.

Is writing the guest's Turkish ID number to the firewall against KVKK?

Writing raw identity information (phone/Turkish ID number) to the firewall and traffic logs can conflict with KVKK's proportionality (Art. 4) and data-security (Art. 12) principles. This is why izgate only writes a fixed alias code to the firewall; the real identity is kept encrypted inside izgate.

Can I keep access records indefinitely?

No. KVKK Art. 4/2-d requires data to be retained "for the period stipulated by the relevant legislation or for the period required for the purpose for which it is processed." For access records under 5651, that period is set at two years in the Regulation.

Is izgate a data controller or a data processor under KVKK?

Since your business decides for what purpose and how your guests' and employees' data is processed, you are the data controller under KVKK. izgate is the data processor providing the technical infrastructure (recording, encryption, access control) on your behalf.

This page is for information only; for the current text of the legislation, refer to the official source (mevzuat.gov.tr).

Making your network Law No. 5651 compliant is a one-day job.

Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.