Internet Public Use Providers Regulation: who has to do what
Issued on the basis of Article 7 of Law No. 5651, this Regulation defines fundamental terms like "access records" and lists, separately, the obligations of public use providers (everyone) and of commercial internet public use providers (internet-café-like venues). This page presents the Regulation's articles with the verbatim text and a plain-language explanation.
Official Gazette: 11.04.2017 · Legal basis: Law No. 5651. This Regulation is in force in place of the former Regulation dated 1/11/2007 (see Article 14).
Article 1 — Purpose and scope
MADDE 1 – (1) Bu Yönetmeliğin amacı, internet toplu kullanım sağlayıcıları ve ticari amaçla internet toplu kullanım sağlayıcılarının yükümlülükleri ve sorumlulukları ile denetimlerine ilişkin esas ve usulleri düzenlemektir.
"ARTICLE 1 – (1) The purpose of this Regulation is to regulate the principles and procedures relating to the obligations and liabilities of internet public use providers and commercial internet public use providers, and to their oversight."
Regulation on Internet Public Use Providers, Art. 1 — unofficial translation — mevzuat.gov.tr
What this means: From the outset, the Regulation separates two different groups: (1) internet public use providers — anyone offering internet access, and (2) commercial internet public use providers — internet-café-like venues selling internet access for a fee. This distinction determines, throughout the Regulation, who each obligation applies to.
Article 3 — Definitions
MADDE 3 – (1) Bu Yönetmeliğin uygulamasında; […]
e) Erişim kayıtları: Kendi iç ağlarında dağıtılan IP adres bilgilerini, kullanıma başlama ve bitiş zamanını ve bu IP adreslerini kullanan bilgisayarların tekil ağ cihaz numarasını (MAC adresi) gösteren bilgileri, hedef IP adresi, bir veya birden fazla IP adresinin portlar aracılığı ile kullanıcılara paylaştırılması yöntemi ile sunulan internet erişim hizmetinde kullanıcıya tahsis edilen gerçek IP ve port bilgilerini,
[…]
g) İnternet toplu kullanım sağlayıcı: Kişilere belli bir yerde ve belli bir süre internet ortamı kullanım olanağı sağlayan gerçek ve tüzel kişileri,
ğ) İşyeri: Ticari amaçla internet toplu kullanım sağlayıcı olarak faaliyet gösteren gerçek veya tüzel kişiler tarafından açılan ve işletilen umuma açık yeri,
[…]
l) Ticari amaçla internet toplu kullanım sağlayıcı: İnternet salonu ve benzeri umuma açık yerlerde belirli bir ücret karşılığı internet toplu kullanım sağlayıcılığı hizmeti veren veya bununla beraber bilgisayarlarda bilgi ve beceri artırıcı veya zeka geliştirici nitelikteki oyunların oynatılmasına imkân sağlayan gerçek ve tüzel kişileri,
ifade eder."ARTICLE 3 – (1) For the purposes of this Regulation; […]
Regulation on Internet Public Use Providers, Art. 3/1-e, g, ğ, l — unofficial translation — mevzuat.gov.tr
e) Access records: Information showing the IP addresses distributed on the provider's own internal networks, the start and end time of use, and the unique network device number (MAC address) of the computers using those IP addresses; the destination IP address; and, in internet access service provided by sharing one or more IP addresses with users via ports, the real IP and port information assigned to the user;
[…]
g) Internet public use provider: Real and legal persons who provide persons with the ability to use an internet environment at a given place, for a given period of time;
ğ) Place of business: A venue open to the public that is opened and operated by a real or legal person acting as a commercial internet public use provider;
[…]
l) Commercial internet public use provider: Real and legal persons who provide commercial public internet use services for a fee in internet cafés and similar venues open to the public, or who, together with this, enable the playing of games of an informative, skill-enhancing, or intelligence-developing nature on computers;
shall mean the following."
What this means: The definition of "access records" (subparagraph e) is the exact list of data that must be kept: the IP distributed on the internal network, the start/end time of use, the MAC address, the destination IP, and the real IP/port information shared via NAT. The "commercial basis" definition (subparagraph l) is the determining factor: venues like internet cafés that sell internet access for a fee. A hotel, café, office, or hospital offering free Wi-Fi to its customers/guests/employees doesn't fall under this definition; it's subject to the general obligations in Art. 4.
izgate's counterpart: izgate automatically extracts every field in the access-records definition (internal IP, start/end time, MAC, destination IP, NAT IP:port) from firewall logs and writes it to the signed archive.
Article 4 — Obligations of all public use providers
MADDE 4 – (1) İnternet toplu kullanım sağlayıcılarının yükümlülükleri şunlardır:
a) Konusu suç oluşturan içeriklere erişimi önleyici tedbirleri almak amacıyla içerik filtreleme sistemini kullanmak.
b) Erişim kayıtlarını elektronik ortamda kendi sistemlerine kaydetmek ve iki yıl süre ile saklamak.
c) Kamuya açık alanlarda internet erişimi sağlayan toplu kullanım sağlayıcılar, kısa mesaj servisi (sms) ve benzeri yöntemlerle kullanıcıları tanımlayacak sistemleri kurmak.
(2) İnternet toplu kullanım sağlayıcılar, konusu suç oluşturan içeriklere erişimi önleyici tedbirleri almak amacıyla içerik filtreleme sisteminin yanı sıra, ilave tedbir olarak güvenli internet hizmeti de alabilirler."ARTICLE 4 – (1) The obligations of internet public use providers are as follows:
Regulation on Internet Public Use Providers, Art. 4 — unofficial translation — mevzuat.gov.tr
a) To use a content filtering system in order to take measures that prevent access to content constituting a crime.
b) To record access records electronically on their own systems and to retain them for a period of two years.
c) Public use providers offering internet access in publicly open areas shall establish systems to identify users by short message service (SMS) or similar methods.
(2) Internet public use providers may, in addition to a content filtering system used to take measures that prevent access to content constituting a crime, also obtain a safe internet service as an additional measure."
What this means: This article — the Regulation's broadest-reaching one — applies to everyone, including hotels, cafés, offices, schools, and hospitals: (a) use a content filtering system, (b) record access records electronically and retain them for two years, (c) identify users in publicly open areas (such as a guest network open to "the general public") by SMS or a similar method. The retention period here is clearly written as "two years" — statements like "at least 1 year" or "1–2 years" are not supported by this article.
izgate's counterpart: izgate's guest Wi-Fi module offers user identification methods like SMS verification, Turkish ID, and a visitor code; access records are kept in parallel in live and archive form, and the retention period is set from the panel (two years is the recommended/default value). Content filtering is not izgate's own feature — it's done through your firewall's web filter; izgate records and reports the blocking logs that filter produces.
Article 5 — Obligations of commercial internet public use providers
MADDE 5 – (1) Ticarî amaçla internet toplu kullanım sağlayıcılarının yükümlülükleri şunlardır:
a) Mülki idare amirinden izin belgesi almak,
b) Ailenin ve çocukların korunması ile konusu suç oluşturan içeriklere erişimi önleyici tedbirleri almak amacıyla içerik filtreleme sistemini ve güvenli internet hizmetini kullanmak,
c) Kullanılan içerik filtreleme sistemini aktif ve güncel halde bulundurarak, herhangi bir müdahale ile devre dışı kalmasını önlemek,
ç) Erişim sağlayıcılardan sabit IP almak, sabit IP kullanmak ve sabit IP değişikliklerini on beş gün içerisinde mülki idare amirliklerine bildirmek,
d) Erişim kayıtlarını elektronik ortamda kendi sistemlerine kaydetmek ve iki yıl süre ile saklamak,
e) (d) bendi gereğince kaydedilen bilgileri ve bu bilgilerin doğruluğunu, bütünlüğünü ve gizliliğini teyit eden değeri kendi sistemlerine günlük olarak kaydetmek ve bu verileri iki yıl süre ile saklamak,
f) 14/7/2005 tarihli ve 2005/9207 sayılı Bakanlar Kurulu Kararıyla yürürlüğe konulan İşyeri Açma ve Çalışma Ruhsatlarına İlişkin Yönetmeliğe göre işyerinin kapatılmasının veya devrinin on beş gün içinde yetkili mülki idare amirliğine bildirmek ve izin belgesini teslim etmek."ARTICLE 5 – (1) The obligations of commercial internet public use providers are as follows:
Regulation on Internet Public Use Providers, Art. 5 — unofficial translation — mevzuat.gov.tr
a) To obtain an operating permit from the local civil authority;
b) To use a content filtering system and a safe internet service in order to take measures protecting the family and children and preventing access to content constituting a crime;
c) To keep the content filtering system used active and up to date, preventing it from being disabled by any intervention;
ç) To obtain a fixed IP from access providers, to use that fixed IP, and to notify the local civil authorities of any change of fixed IP within fifteen days;
d) To record access records electronically on their own systems and to retain them for a period of two years;
e) To record daily, on their own systems, the information recorded under subparagraph (d) and a value confirming the accuracy, integrity, and confidentiality of that information, and to retain this data for a period of two years;
f) To notify the competent local civil authority, within fifteen days, of the closure or transfer of the place of business, and to surrender the operating permit, in accordance with the Regulation on Business Opening and Operating Licenses enacted by Council of Ministers Decision No. 2005/9207 dated 14/7/2005."
What this means: This article only concerns internet-café-like venues selling internet access for a fee (the Art. 3/l definition); it does not apply to general businesses (hotels, cafés, offices offering free Wi-Fi). Subparagraph (e) stands out: it requires a value confirming the "accuracy, integrity, and confidentiality" of the access records to be recorded daily — this is an integrity value showing the record hasn't been altered afterward (a hash/signature/timestamp-like mechanism); the legislation doesn't use the word "timestamp" for this and leaves the technical method open.
izgate's counterpart: izgate protects archive segments with a SHA-256 chain and an Ed25519 signature; a qualified timestamp (Kamu SM, a central service) is obtained once a day for these segments. This is a technical implementation that strengthens the "value confirming accuracy, integrity, and confidentiality" that Art. 5/1-e points to; the legislation doesn't name the timestamp as mandatory, but izgate offers it as an additional safeguard.
Article 9 — Rules to be followed at places of business (commercial providers)
This article, which concerns only commercial internet public use providers (internet-café-like venues), lists venue rules such as age limits, camera recording, and content restrictions. The provisions worth highlighting:
MADDE 9 – (1) İşyerlerinde uyulması gereken kurallar şunlardır:
a) 12 yaşından küçükler, ancak yanlarında veli veya vasileriyle işyerlerine girebilirler.
b) 15 yaşından küçükler yanlarında veli veya vasileri olmadan saat 20.00'den sonra işyerlerine alınmazlar.
[…]
ğ) Güvenlik amacıyla işyerlerinin giriş ve çıkışlarını görecek şekilde yüksek çözünürlüklü (en az 3 mega piksel) ve "IR" (gece görüşlü) kamera kayıt sistemi kurulur. Bu sistem aracılığıyla elde edilen kayıtlar doksan gün süreyle saklanır ve bu kayıtlar yetkili makamlar haricindeki kişi ve kuruluşlara verilemez."ARTICLE 9 – (1) The rules to be followed at places of business are as follows:
Regulation on Internet Public Use Providers, Art. 9/1-a, b, ğ — unofficial translation — mevzuat.gov.tr
a) Persons under the age of 12 may only enter places of business accompanied by a parent or guardian.
b) Persons under the age of 15 shall not be admitted to places of business after 20:00 without a parent or guardian.
[…]
ğ) For security purposes, a high-resolution (at least 3 megapixels) "IR" (night-vision) camera recording system shall be installed so as to cover the entrances and exits of the place of business. Recordings obtained through this system shall be retained for a period of ninety days, and these records may not be given to any person or organization other than the competent authorities."
What this means: The article also includes provisions on bans on tobacco/alcohol, measures against copyright infringement, a ban on keeping electronic/mechanical gaming machines, and a ban on playing games with harmful content (subparagraphs b, c, ç, d, e, f, g). These rules concern internet cafés and similar places of business, not general businesses (hotels, cafés, offices); for this reason, claims based on this article are not made on other sector pages.
Articles 10–12 — Oversight and administrative sanctions
MADDE 10 – (1) Ticari amaçla internet toplu kullanım sağlayıcılar; a) Mülki idare amirlikleri bünyesinde oluşturulan denetleme komisyonu tarafından, 5 ve 9 uncu maddelerde yer alan yükümlülükler ve şartlar açısından denetlenir. […] b) Kolluk tarafından genel güvenlik ve asayiş yönünden denetlenir […]
"ARTICLE 10 – (1) Commercial internet public use providers; a) Shall be inspected, with regard to the obligations and conditions set out in Articles 5 and 9, by an inspection commission established within the local civil authorities. […] b) Shall be inspected by law enforcement with regard to general security and public order […]"
Regulation on Internet Public Use Providers, Art. 10/1 — unofficial translation — mevzuat.gov.tr
MADDE 11 – (1) 5 inci maddenin birinci fıkrasındaki yükümlülüklere aykırı hareket ettiği belirlenen ticari amaçla internet toplu kullanım sağlayıcılara, mülki idare amiri tarafından ilk ihlalde yazılı olarak uyarma; ihlalin devamı halinde üç güne kadar kapatma; ihlalin tekrarı halinde ise bin Türk Lirasından on beş bin Türk Lirasına kadar idarî para cezası vermeye mahalli mülki amir yetkilidir.
(2) 9 uncu maddeye aykırılık halinde mülki idare amiri tarafından, 4/7/1934 tarihli ve 2559 sayılı Polis Vazife ve Salâhiyet Kanununun 6 ncı maddesinin birinci fıkrasının (d) bendi uyarınca idari para cezası verilir."ARTICLE 11 – (1) The local civil authority is authorized to impose, against a commercial internet public use provider found to have acted in violation of the obligations in the first paragraph of Article 5: a written warning for a first violation; closure for up to three days if the violation continues; and an administrative fine from one thousand to fifteen thousand Turkish Lira if the violation is repeated.
Regulation on Internet Public Use Providers, Art. 11 — unofficial translation — mevzuat.gov.tr
(2) In the event of a violation of Article 9, an administrative fine shall be imposed by the local civil authority pursuant to subparagraph (d) of the first paragraph of Article 6 of the Law on the Duties and Powers of the Police, No. 2559, dated 4/7/1934."
What this means: The oversight (Art. 10) and sanction (Art. 11) regimes are also limited to commercial internet public use providers, and are tied to Articles 5 and 9. Article 12 sets out that the amount of the fine is determined based on aggravating factors (the scale of the economic gain, continuation of the violation, repetition) and mitigating factors (lack of gain, a positive track record).
Article 14 — Repeal of the former regulation
MADDE 14 – (1) 1/11/2007 tarihli ve 26687 sayılı Resmî Gazete'de yayımlanan İnternet Toplu Kullanım Sağlayıcıları Hakkında Yönetmelik yürürlükten kaldırılmıştır.
"ARTICLE 14 – (1) The Regulation on Internet Public Use Providers published in the Official Gazette No. 26687, dated 1/11/2007, is hereby repealed."
Regulation on Internet Public Use Providers, Art. 14 — unofficial translation — mevzuat.gov.tr
What this means: The 2007 regulation has been fully repealed; the current and binding text is this Regulation, dated 11.04.2017. References to the old regulation (as still found in some older guides circulating online) are no longer valid.
Frequently asked questions
How many years is the access-record retention period?
Two years. This period is written the same way, as "two years," both for all public use providers in Art. 4/1-b and for commercial providers in Art. 5/1-d and 5/1-e.
Does my hotel/café need an operating permit?
No, a hotel or café offering free Wi-Fi to its customers/guests doesn't fall under the definition of "commercial internet public use provider" (Art. 3/l); the operating permit, fixed IP, and other related obligations (Art. 5) apply only to internet cafés and similar businesses selling internet access for a fee.
Who provides the content filtering system?
The Regulation says "to use a content filtering system" (Art. 4/1-a); this is generally provided through your firewall/network device's web filter. izgate itself is not a filtering product; it collects and reports the filter/blocking logs your firewall produces.
Do the camera-recording and age-limit rules in Art. 9 apply to me too?
They only apply to businesses that fall under the definition of "place of business" (Art. 3/ğ) — that is, businesses set up as commercial internet public use providers. A general office, hotel, or café is not within this scope.
This page is for information only; for the current text of the legislation, refer to the official source (mevzuat.gov.tr).
Making your network Law No. 5651 compliant is a one-day job.
Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.
