Guest Wi-Fi and Turkey's Law 5651: Is Logging Mandatory at the Office?

TL;DR: When you open your internet connection to others in Turkey, Law 5651's "mass-use provider" framework enters the picture: access records are expected to be kept and stored correctly. The core office practice is fourfold: separate the guest network from the internal one, keep identity-attributable records, store them time-stamped and integrity-protected, and rate-limit the bandwidth. On questions of scope, legal counsel's interpretation governs.
Everyone providing internet access in Turkey sits somewhere within the framework drawn by Law No. 5651. Cafés, hotels and malls that commercially open internet to customers are clearly "mass-use providers" — but what about an accountancy office, a showroom or a clinic offering Wi-Fi to waiting-room guests? That grey zone is usually crossed without a thought in the field — until an act performed on that network brings law enforcement to the address on the subscription. Because the technical fact does not change: your guest's traffic exits to the internet under your IP address.
The Law's Logic: Traceability
The business-facing side of the 5651 regime rests on one question: "Which user performed the act done on this network at this date and time?" Access records — who connected, with which internal IP, when — answer it; the timestamp and integrity protection give the record its evidentiary value. No record, no answer — and no answer means the investigation knots itself around the subscription holder: the business. The scope of the logging obligation and the retention periods are set by regulation and vary by establishment type; qualify your own situation with your counsel — our territory is building the technical arrangement that stands under whichever qualification results.
The Four Cornerstones of an Office Guest Network
1. Network Separation: Guests Never Touch the Internal Network
Guest Wi-Fi is a security topic before anything else: sharing the office password puts the guest on the same network as your server, your printers and your file shares. In a correct setup, guest traffic rides a separate virtual network (VLAN) and cannot reach internal resources. Separation is also logging's precondition: without segregated guest traffic, "who did what" cannot be answered cleanly.
2. Identified Access: the Captive Portal
A password taped to the wall produces no records. A captive portal passes the guest through a verification step before granting access — SMS phone verification is the common, practical route — and creates the "this person connected at this hour" record. For offices without heavy visitor traffic, a lighter middle path is possible: at minimum, a guest SSID that keeps device-level records.
3. Record Quality: Time-Stamped and Integrity-Protected
A record's evidentiary value lies in being able to show it was not altered. In 5651 practice, logs are therefore signed with timestamps and stored in an integrity-verifiable form; a record written to an ordinary text file cannot prove it was not edited later. Backing up the logs across the retention period is part of the arrangement — the business that keeps logs but loses them to a failed disk lands exactly where the one that never logged does.
4. Limits: Bandwidth and Content
Rate-limiting the guest network both protects the office line and deters misuse. In publicly accessible spots such as waiting areas, a content filter (closing illegal and inappropriate categories) is a layer that is both ethical and practical.
Tone by Sector
The same core arrangement thickens with visitor volume: an accountancy office hosting three visitors a day and a hundred-guest hotel do not share one need. The office scenario is the light end of the spectrum — light does not mean zero.
The Three Gaps We See Most in the Field
- One SSID, one password, everyone inside: guest, intern, service technician — all on the internal network. A network-security problem before it is ever a logging problem.
- The "the modem keeps logs" assumption: consumer modem records are short, thin and evaporate on reboot; they are not what 5651 practice requires.
- The installed-then-forgotten system: the logging appliance set up years ago — disk full, timestamp service stopped, nobody noticed. Logging is itself a system to be monitored; the standard is not "we installed it" but "it is running and filling".
How Yamanlar Bilişim Builds This
Guest network projects start with discovery: your visitor volume, your current network layout and the scenario that applies to you. Installation brings the guest VLAN, the captive portal, the time-stamped signed logging arrangement and the rate limit online as one package; for maintenance-agreement customers, log-system health (disk, timestamp service, backup) is a monthly check item. 5651-compliant logging is also a distinct line in our service catalogue.
FAQ
Frequently Asked Questions
If we simply never offer guest Wi-Fi, are we free of these obligations?
For the guest side, yes — a service not provided produces no records. Access records for the internal network your employees use remain good practice, however, and are expected in many scenarios; and the "we don't offer it" decision must actually hold: a password written on the wall is a service provided.
Isn't an SMS-verified portal overkill for a small office?
With low visitor traffic, lighter setups are possible; what is critical is that which device connected, and when, enters the record. As volume grows — showrooms, clinic waiting rooms — the SMS portal becomes standard for both record quality and deterrence.
Do the logs show which sites the guest visited — isn't that a privacy problem?
The core record in 5651 practice is access/mapping information (who, when, which internal IP), not traffic content. Purpose limitation and notice obligations under data-protection law are handled together with the record design — and the captive portal is also the right place to display the privacy notice.
How long must records be kept?
Retention periods are set by regulation and vary with the establishment's qualification; confirm the current period with counsel. On the technical side our rule is fixed: for whatever period applies, the record must remain both accessible and integrity-verifiable — meaning disk capacity, timestamping and backups sized to that period.
What happens if an offence is alleged to have come from our network?
The request arrives through official channels and asks for the mapping record at a specific date and time. With the arrangement in place, the answer is produced in minutes and the matter moves to the user concerned; without it, the questions stay with the subscription holder — the business. That picture is the clearest justification for the setup cost.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Network and Security solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Branch Connectivity Redundancy: What Happens When the VPN Drops?
When the tunnel linking a branch to head office drops, ERP screens, shared folders and internal telephony stop together. Why site-to-site tunnels fail, which redundancy pattern fits which topology, and the three settings that make a tunnel heal itself.

Backup Internet for the Office: A Failover Setup Guide for SMBs
When a single-line office loses its internet, phones, card payments and every cloud application stop at once. The four components of a dual-WAN failover setup, how to choose a second line that fails independently, and what users actually experience during the switchover.

Second Fibre or 4G/5G? Choosing the Right Backup Internet Line
Two strong candidates compete for the backup-line budget: a second wired circuit or a cellular 4G/5G solution. We compare them on infrastructure independence, CGNAT and static IPs, data quotas and latency — and give a clear recommendation for three typical office profiles.