CUSTOM SOFTWARE

CYBER SECURITY

WEBSITE

IT SUPPORT

CLOUD SOLUTIONS

5651 logging and KVKK-aware data handling

Cloud Bilişim implements network logging infrastructure for businesses in Türkiye, including timestamping, retention and access controls. The technical setup supports requirements associated with Law No. 5651 and KVKK-aware data handling; it does not by itself establish legal compliance.

What should a logging project verify?

Agree which access events must be recorded, how timestamps and identity records are handled, who can retrieve records and when data is deleted. Applicable legal duties and retention periods require organisation-specific assessment.

Related services and next steps

AI-powered antivirus and endpoint security, Cyber security tailored to your industry, Contact Cloud Bilişim.

Make Network Access Records Manageable

5651 logging, it is the obligation of parties providing internet access to keep records of this access and retain them for a specified period. Businesses that provide internet to their guests, customers, or visitors over their own network are under this obligation. The scope is not limited to large organisations; it includes hotels, cafes, stores, clinics, and any office with a guest network.

The point where businesses struggle the most in practice is not just keeping the record, but being able to prove that it has not been altered afterwards. For this reason, records need to be signed with a timestamp, stored in a secure environment, and fully reportable upon request.

Another critical point is the KVKK side. The records kept are considered personal data. This means that it’s not just about legal retention; access authorisation, destruction at the end of the retention period, and informing users must also be correctly configured.

As Cloud Bilişim, we address these two sides together: while your records are produced in accordance with the law, personal data security is not overlooked.

What Is 5651 Logging?

The law numbered 5651 regulates the responsibilities of parties providing internet access. Businesses that offer internet to third parties over their own network are defined in the legislation as “public access providers” and are obliged to keep records of internal IP allocations.

The purpose is that in the event a crime is committed over the internet, it can later be determined which device and user the relevant access belongs to. Incomplete or unverifiable records may complicate incident investigation; legal responsibility should be assessed according to the specific case and applicable legislation.

Businesses in Türkiye that may be collective internet access providers under Law No. 5651, including hotels, cafés, shopping centres, hospitals, offices, schools, event venues and public institutions.

Is Your Business Within This Scope?

The nature of the internet access provided by the business and the definitions in the relevant legislation should be evaluated together. The obligations and retention conditions of institutions should not be reduced to a single technical criterion.

Businesses providing collective use for commercial purposes must also obtain a permit from the local administrative authority and implement measures to block access to content that constitutes a crime.

If you are not sure which category you fall into, we can review your existing network structure and clarify your status together.

Scope of Our Logging Solutions

  1. User Authentication
    Users connecting to the guest network are identified via SMS, e-Government, or corporate account verification; the method to be used and the data to be collected are determined according to the institution’s requirements.
  2. Hotspot and Guest Network Setup
    The welcome screen is designed according to your institution’s identity, and the terms of use and disclosure statement are displayed at the time of connection.
  3. Internal IP Distribution Records
    Which device uses which IP address during which time period is fully recorded.
  4. Timestamped Signing
    Records are signed and made unchangeable afterwards; thus the integrity of the record can be proven.
  5. Encrypted and Redundant Storage
    Records are stored in an environment that is encrypted, backed up, and inaccessible to unauthorised access for the period required by legislation.
  6. Guest and Staff Network Separation
    Guest traffic is isolated from the corporate network; visitors cannot access your internal systems.
  1. Reporting and Querying
    When an official request is received, records for the relevant period are quickly queried and reported in the requested format.
  2. Access Authorisation
    Who can access the records is limited by roles, and access activities are also recorded separately.
  3. Retention and Disposal Policy
    What will happen to the records when the period expires is defined and automated in accordance with your retention and disposal policy KVKK.
  4. Content Filtering Integration
    Access to content that constitutes a crime or is against your organisation’s policy is blocked by filtering rules.
  5. System Health Monitoring
    Situations where record production is interrupted are monitored and alerts are generated; the risk of unintentionally remaining unrecorded is prevented.
  6. Post-Installation Support
    Updates, rule changes, and audit preparation are carried out by us under the maintenance agreement.
Six-stage lifecycle of a 5651 log record: identity verification, log creation, timestamping, secure archiving, authority request and policy-based disposal under Turkish law and KVKK.

Records are managed within a traceable and verifiable cycle from the moment they are created until they are destroyed.

KVKK Compliance: Keeping Records Is Not Enough

Logs are considered personal data because they contain information about users’ online activities. Therefore, 5651 compliance and KVKK compliance cannot be considered separately.

In the structures we have established, data minimization is observed; only the records required by legislation are kept. Access to records is restricted by roles, a destruction process is defined at the end of the retention period, and users are informed with a disclosure notice at the time of connection. These technical measures should be considered together with the institution’s legal assessment and data protection processes.

Note: The information on this page is for general informational purposes and does not constitute legal advice. Retention periods and the scope of obligations may vary depending on changes in legislation; we recommend evaluating your specific situation with your legal advisor.

Technical acceptance criteria of the logging project

When selecting a logging solution, list which records will be obtained from which devices. IP allocation, user or session information, and consistency of device clocks are important for making sense of the logs later. It should be tested that an alert is generated when the log stream stops and that an authorised person can export the report.

In capacity calculation, the daily log volume and the defined retention period, in addition to the number of devices, are taken into account. Access permissions, integrity checks, backup, and deletion operations to be applied at the end of the period should also be included in the scope.

Installing a software alone does not guarantee legal compliance. The obligations to be applied and retention periods should be determined with your legal advisor within the scope of your activity, the type of records, and the relevant legislation. The technical solution should be configured according to these requirements.

Frequently Asked Questions

5651 logging is the practice of parties providing internet access keeping records of this access and storing them for a specified period. The purpose is to be able to subsequently determine which device and user the relevant access belongs to in the event of a crime committed over the internet.

Businesses that provide internet to third parties through their own network are defined in the legislation as public access providers. Hotels, cafes and restaurants, shopping malls and stores, hospitals and clinics, schools and dormitories, sports and event venues, public institutions, and offices with guest networks fall within this scope. It should also be separately verified how your institution is evaluated and what obligations will apply.

A public access provider is the party that provides individuals with the opportunity to use the internet at a certain place and for a certain period. Businesses that provide public access for commercial purposes must also obtain a permit from the local administrative authority and implement measures to block access to content that constitutes a crime.

No. It must be possible to prove that the record has not been altered afterwards. For this purpose, the records are signed with a timestamp, stored in a secure and backed-up environment, and ensured to be fully reportable upon official request.

Yes. Logs are considered personal data because they contain information about users’ activities on the internet. Therefore, data minimization should be observed, access to the records should be limited by roles, a destruction process should be defined at the end of the retention period, and users should be informed with a disclosure statement at the time of connection.

Yes. Guest traffic should be isolated from the corporate network. This way, visitors cannot access internal systems, servers, or corporate data; additionally, the recording of guest traffic can be managed separately from corporate traffic.

Users connecting to the guest network are identified through SMS, e-Government, or corporate account verification. A session record is created according to the information verified by the method; SMS verification alone does not guarantee the legal identity of the person. We set up this structure in open areas with our hotspot solutions . What happens if logs are not kept?

Our Complementary Security Services

firewall Business firewall solutions our solutions, for the endpoints AI-based antivirus programs to see our service and the weak points of your current structure penetration testing You can evaluate our service together.

Let’s Evaluate Your Current Structure for Free

Are you currently keeping records, are the records kept verifiable, is your retention period and destruction process defined? We examine your existing network structure, identify the gaps, and suggest a logging solution suitable for the scale of your business.

Installation, guidance in permit processes, and post-installation maintenance are carried out in a single workflow. To clarify your situation together you can contact us.