Follow us :
Data Security

Law 5651 and Guest Wi-Fi: Must Your Business Keep Logs?

Close-up of networking and logging hardware — Xen Bilişim Data Security

“Law 5651 doesn’t concern us, we’re not an internet café.” I hear this in the field all the time. Yet a hotel that hands a guest a Wi-Fi password, a café with “free Wi-Fi” on its tables, an office that opens internet for a visitor in the meeting room — under Türkiye’s Law No. 5651, each of these can be what the law calls a mass-use provider (toplu kullanım sağlayıcı). You don’t have to be a café; offering internet to other people is enough.

So does that really mean you have to keep logs? Short answer: most likely yes. The longer answer is below.

Who counts as a “mass-use provider”?

The law draws a line. Giving internet to your own employees is one thing; opening it to third parties — customers, guests, visitors — is another. If you do the second, you’re a mass-use provider.

A commercial dimension then sharpens it:

  • Commercial providers (hotels, cafés, restaurants, shopping malls, salons, training centres, clinic waiting rooms) carry heavier obligations.
  • Non-commercial settings carry lighter duties — but not zero.

In other words, that separate “guest network” SSID is exactly what pulls you into scope.

What must you keep, and for how long?

The goal is simple: if a crime is committed, it should be possible to trace which device the traffic came from. So you store “who used which IP, and when” — the connection metadata, not the content.

What is keptDetail
Internal IP allocation logsWhich device (MAC) got which internal IP, and when
Connection time dataSession start and end date/time
Authentication recordHow the user was verified on join (SMS, ID, room number, etc.)
Timestamp / integrityA signature proving the records weren’t altered later

On retention, the legislation frames a window of up to two years for access and traffic records; many businesses apply the same period to their internal IP logs. Because the exact period and technical details can be updated by regulation, I’d verify the current Mass-Use Provider Regulation with a lawyer before building the system — the figures here are the general picture, and your specific case or an exemption may differ.

One caveat: you are not logging content. You don’t have to record which sites someone visited — and under KVKK (Türkiye’s data-protection law, Law No. 6698) that would actually be collecting too much. What you keep is the record of who a given IP was assigned to.

Permit, static IP and filtering

Keeping logs isn’t the whole story. Commercial mass-use providers also face:

  • A permit: a document obtained from the local civil administration authority (the district or provincial governor’s office) during the business-licensing process. It’s usually handled at the license stage — but businesses that added Wi-Fi later often skipped this step.
  • A static IP: you’re expected to obtain a static IP from your ISP and report changes promptly.
  • Safe-internet / filtering: an obligation to filter illegal content and protect minors.

The cost of non-compliance isn’t only a fine. The authority first issues a written warning; if the breach continues, it can escalate to temporarily closing the business. Administrative fines, meanwhile, are revalued every year — don’t look at figures from a few years ago and call them small.

5651 says “keep it”, KVKK says “keep it but protect it”

Here’s the part that trips people up most. The logs you keep — IP, MAC, phone number, room number — are personal data. So you sit under two frameworks at once:

  • Law 5651 makes retention mandatory. In KVKK terms, that means you process the data under a “legal obligation” — and you can do so without collecting explicit consent.
  • KVKK then requires you to keep that data purpose-limited, store it securely, delete it once the period ends, and inform the guest.

They don’t conflict; they’re managed together. In practice, don’t skip these three:

  1. Notice: put a short privacy notice on the Wi-Fi login page (captive portal) — say what you collect and why.
  2. Minimisation: don’t ask for more than you need. Collecting full names or ID scans is usually needless risk.
  3. Disposal: auto-delete logs once their retention period ends. The “let it sit just in case” habit is itself a KVKK breach.

How do you actually stay compliant?

For a small business, none of this needs to be dramatic. Usually these steps are enough:

  • Separate the guest network from your corporate network (own VLAN/SSID).
  • Use a solution that handles logging and authentication — most business firewalls do this with a hotspot module.
  • Sign records with a timestamp, store them securely, auto-dispose when the period ends.
  • Check your permit and static-IP status once.

Set up correctly once, this runs itself in the background. The problem almost always comes from it never having been set up at all.

FAQ

If only my employees use it, do I still keep logs? If you don’t give internet to third parties, you’re not a mass-use provider. Corporate logging is still useful for incident investigation and KVKK technical measures.

Does it apply to password-protected, open guest Wi-Fi too? Yes. Writing the password on the table doesn’t take access out of “mass use.” What matters is who reaches the internet through you.

Will a cloud hotspot solution keep 5651-compliant logs? It depends on the product. You need a system configured for Türkiye’s obligations, with timestamped, time-bound retention — not every generic guest-Wi-Fi panel meets that.

I don’t keep logs and I’ve had no trouble so far. Is the risk real? The risk surfaces the moment a criminal investigation lands on your IP. You can’t produce records retroactively then, and the liability stays with the business. Compliance is cheap when done before an incident.

If you’re unsure where your guest network stands against 5651 and KVKK, let’s review your current setup together: contact us.

Share this post
Türkçe oku

Related Posts