Your company runs a guest Wi-Fi network in Turkey. One Friday an official request lands: the authorities want the access records for a session six months ago. You open the logs and find gaps, no timestamps, and no way to prove the data is unaltered. Any foreign company operating in Turkey can hit this moment, because Law No. 5651 governs exactly this scenario. This guide covers the law's scope, what to log, retention periods, the timestamp requirement, and the penalties.
Who the Law Covers: Hosting and Access Providers
Law No. 5651 regulates online publications and access records in Turkey. Two roles sit at its center: the hosting provider, which supplies the systems that store services and content, and the access provider, which offers connectivity to end users. Knowing your role tells you which duty applies.
Many organizations become access providers without realizing it. A hotel offering guest Wi-Fi, an office giving staff internet, or a cafe opening a connection for customers all deliver an access service.
- Hosting provider: Stores content; responsible for the access records tied to that content.
- Access provider: Delivers connectivity; generates and retains the traffic data.
- Mass-use provider: A business offering internet at a given location (hotel, cafe, workplace).
Providers offering access commercially carry broader duties than those offering it free. A common misconception is that a non-internet business is out of scope; in reality, any business that opens a network to guests is covered. Built to automate this duty, our 100% domestic ERBE SIEM platform keeps records covered by Law No. 5651 in an on-premise architecture.
Which Logs to Keep, and for How Long
The duty reduces to one sentence: record who connected, when, and where to. You keep the trace of the access, not the content, meaning connection metadata rather than what people browsed.
Access records typically include these fields:
| Record field | Description |
|---|---|
| Time data | Start and end of the connection |
| IP address | Internal and external IP assigned to the user |
| Port data | Port that identifies the user behind NAT (address translation) |
| Destination data | The server or domain that was reached |
Retention periods vary by provider type:
| Provider type | Retention framework in the regulation |
|---|---|
| Access provider | Typically a one-to-two-year range |
| Mass-use provider (commercial) | Up to two years |
| Hosting provider | A one-to-two-year range |
Exact periods depend on the business type and current regulation, so verify your own duty. The Information and Communication Technologies Authority (BTK) is the authoritative source, and the full law text sits in the official legislation database. Keeping the record is not enough; its integrity must also be preserved.
The Timestamp Requirement: RFC 3161 and TÜBİTAK
Keeping a log is not enough by itself. You must prove the record existed when it was taken and has not changed since, and a timestamp provides that proof. It is an electronic seal that independently verifies data existed at a specific moment. Without one, a log is legally fragile: the other side can claim it was produced after the fact.
The international standard is RFC 3161 (Time-Stamp Protocol). In Turkey, the authorized body is TÜBİTAK, whose service produces RFC 3161-compliant seals. A valid timestamp delivers three concrete benefits:
- Proof of integrity: It is mathematically shown that the record was not altered.
- Legal validity: The record carries evidentiary weight in an administrative or judicial request.
- Non-repudiation: It becomes indisputable that the record existed at a given moment.
ERBE SIEM integrates the TÜBİTAK RFC 3161 timestamp directly into the record flow.
Administrative Penalties
Failure to meet these duties leads to administrative fines that vary by the shortfall and the provider category. Most penalties stem from neglect, not bad intent: a business assumes it is logging when the system stopped months ago, or keeps logs but never configured the timestamp. The main headings are:
- Not keeping records: Failing to retain traffic and access records at all is among the most serious violations.
- Failing to ensure integrity: A missing timestamp falls under this heading.
- Unable to produce the record: No record can be supplied when the authority requests it.
- Incorrect or incomplete records: The record does not reflect reality.
Beyond the fine sits a heavier risk: a business that cannot produce records cannot defend itself in a criminal investigation, where the log is often the only evidence that clears it. Because fine amounts change yearly, tie the duty to a system that runs continuously rather than memorize a penalty table.
ERBE SIEM and Law No. 5651 Compliance
Sustaining compliance by hand is difficult. Collecting, timestamping, and storing logs demands a continuous mechanism, and ERBE SIEM provides it. SIEM (Security Information and Event Management) collects and correlates records from many sources in one place; our guide to what SIEM is fills in the wider context.
| Attribute | Value |
|---|---|
| Modules | 27 modules |
| Dashboards | 31 dashboard screens |
| Tests | 111 tests |
| Version | 1.0.0 |
| Sovereignty | 100% domestic |
| Deployment | On-premise |
A SIEM is more than a log archive: it correlates records into meaningful events, so the logs kept for Law No. 5651 also help you spot an attack early. On-premise deployment is decisive here. Logs stay on systems the organization controls, with no cloud transfer, which matters for data sovereignty and Turkish personal-data rules. Under KVKK (Turkey's Personal Data Protection Law), foreign companies operating locally should note that keeping records in-country simplifies compliance; our KVKK compliance process guide shows the full path.
Our own deployments illustrate the value. In one installation over 24 hours, we recorded 262 attack attempts and 104 distinct IPs, peaking at 16 attempts per second, all stored on-premise with 0 cloud transfer. Those records satisfy the Law No. 5651 duty and supply evidence during incident response. For expert oversight, our Managed SOC / MDR service turns them into meaningful alerts.
Conclusion
Law No. 5651 is a technical duty that touches nearly every business offering internet access in Turkey. Records must be kept with the correct fields, for a sufficient period, and with a TÜBİTAK timestamp. Running this by hand is laborious and risky. To automate the duty end to end, explore our on-premise, compliance-ready domestic SIEM platform.
Frequently Asked Questions
Must my hotel keep 5651 logs for guest Wi-Fi?
Yes. A hotel offering internet to guests is treated as a mass-use provider in practice. Access made from the guest network must be logged and stored with a timestamp, and offering it for free does not remove the duty. The records must be presentable, with provable integrity, whenever an authorized body requests them.
Which timestamp service counts as valid for 5651?
A valid timestamp is an electronic seal that complies with RFC 3161 and is produced by an authorized body. In Turkey, the authorized institution is TÜBİTAK. A simple date written by your server's own clock does not count; the record's integrity must be secured by an independent, verifiable seal that a third party can confirm.
Can I store my 5651 logs on a cloud server?
Technically, logs can be held in different environments, but most organizations prefer on-premise storage because of data sovereignty and KVKK sensitivities. In an on-premise architecture, records stay under the organization's control and are not sent outside. Using an overseas cloud can create extra duties around personal-data transfer, so it warrants careful assessment.
Tags
- Law No. 5651
- log retention
- timestamping