Law No. 5651 Guide: Logging Duty, Retention and Signing
Turkey's Law No. 5651 obliges anyone providing internet access to others — hotels, cafes, factories, schools, offices — to keep verifiable access records. This guide covers who is in scope, what must be retained and for how long, why qualified timestamps matter, and how compliance works in practice.
What is Law 5651?
Enacted in 2007, the law regulates online publications and ensures traceability of crimes committed over the internet. It defines content, hosting and access providers, plus mass-use providers — any organisation offering internet access to guests, customers, students or staff, paid or free.
What must be kept?
The core record set: verified user identity (typically an SMS-verified phone number), assigned internal IP and MAC, connection start/end times, and source/destination IP-port traffic records. Retention periods range from six months to two years depending on record type; keeping records for at least two years is the widely adopted safe practice.
Why qualified timestamps?
Keeping a record is not enough — you must prove it was never altered. Daily archives are hashed, chained, and stamped by a qualified timestamp authority (e.g. TÜBİTAK Kamu SM), giving records third-party verifiable integrity. See our Law 5651 logging page for details.
Consequences of non-compliance
Administrative fines apply and are revalued yearly. The heavier risk: if a crime is committed over your network and you cannot produce records, the trail ends with you.
Frequently Asked
This page is for general information only and does not constitute legal advice.
How many devices do you have? Let us work out the rest.
Fill in the two-minute wizard; we will send a tailored quote within one business day.
Start the quote wizard