Back to Blog
Legal Compliance

What Is Law No. 5651? A Short, Clear Guide for Companies (2026)

What Is Law No. 5651? A Short, Clear Guide for Companies (2026)
What is Turkey’s Law No. 5651 for companies? Who is obligated, which logs, timestamps, retention, KVKK differences, and a practical checklist.
Published
August 02, 2026
Updated
August 02, 2026
Reading Time
12 min read
Author
LeonX Expert Team

What is Law No. 5651? Often called Turkey’s “logging law,” Law No. 5651 frames how internet-access records must be kept—and preserved with evidentiary integrity—to help combat online crime. Short answer: a company that lets employees, guests, or customers use its internet is often treated as a mass-use provider; “firewall logging is on” is not enough without DHCP/NAT logs, correct time, timestamps, and retention. Compliance = right records + integrity + retention + access procedure.

This guide is written for:

  • SMB and enterprise leaders who provide internet access
  • IT/network teams expected to implement 5651 technically
  • Hotels, cafés, plazas, and offices running guest Wi-Fi
  • Decision makers placing 5651 next to KVKK / ISO 27001

Quick Summary

  • 5651 does not mean “log every click”; it produces evidence for who used internet access, when, and via which IP/port.
  • Office staff Wi-Fi or customer Wi-Fi usually puts a company in scope.
  • Minimum technical pack: DHCP + NAT/PAT logs, NTP, timestamping, central retention.
  • Retention must be written in policy; practice often references a 2-year archive.
  • 5651 ≠ KVKK—purpose and data sets differ: 5651 vs KVKK.
  • Deeper technical frame: What Is 5651 Logging?.

Table of Contents

What is Law No. 5651 for companies

Image: Wikimedia Commons - Cisco Sourcefire 3D 7120 (example enterprise security/log-source appliance form factor).

What Is 5651? (In Company Language)

The official title of Law No. 5651 is long; for a company leader the core is this: an organization that shares internet access must keep access records in a form that can serve as legal evidence. The goal is not a personal-data inventory—it is answering “which internal user/device used that public IP at that time?”

Short definition:

Law No. 5651 is the legal framework requiring companies that provide internet access to generate access logs, protect their integrity (typically via timestamps), and retain them for a defined period.

Technical depth: 5651 Logging. Network design pitfalls: 5651 Network Architecture Mistakes.

Is Your Company Obligated?

Most companies fall into scope via one of these scenarios:

ScenarioTypical outcome
Staff office internet / Wi-FiHigh mass-use-provider risk
Guest / plaza Wi-FiSame; plan identity/Captive Portal
Free customer Wi-Fi (café, hotel, mall)Obligation + operational process
Only servers/DMZ, no user internetScope may be narrower; still get legal review

“We are a small company” is not an exemption. Shared lines and mass use drive the factual analysis. Treat this guide as a technical-operational frame; confirm legal interpretation with counsel and the statute text.

Which Records Must Be Kept?

Practical minimum set on the company side:

  1. DHCP / IP assignment logs — which MAC got which private IP, and when
  2. NAT/PAT logs — private IP + source port ↔ public IP + port mapping
  3. Time — NTP-synced clocks and a consistent timezone
  4. Identity binding (where possible) — Captive Portal, 802.1X, AD user mapping

A “destination URL list” or a thin firewall traffic summary often fails to prove the internal user. NAT port mapping plus the DHCP chain are essential. Architecture: SIEM, Syslog and 5651. Firewall example: FortiGate Logging.

Pro Tip: In single-public-IP offices, “who did it?” almost always comes down to NAT source port + DHCP lease. Without those two logs, the evidence chain breaks.

Timestamps, NTP, and Retention

ComponentWhy it mattersPractical note
NTPClock drift kills evidenceTarget offset <1–2 s
TimestampingIntegrity / evidentiary value“Existed and unchanged” claim
Central archiveDisk overwrite riskSIEM / log server / legal archive
RetentionLegal + corporate policyCommon practice frame: 2 years
Access rightsNot everyone may delete logsSeparate admins, audit trail

Integrity: Log Integrity under 5651. Archiving: 5651 Archiving and Retention.

5651 vs KVKK vs ISO 27001

FrameworkWhat it wants from a companyConfusion risk
5651Internet-access evidenceAssuming “firewall log = 5651”
KVKKPersonal-data processing & securityDumping every log into the KVKK inventory
ISO 27001ISMS monitoring/evidenceTreating a 5651 archive as SoA review

All three can feed one SIEM; purpose, retention, and access policies must still be written separately. Integration: KVKK and ISO 27001 Integration, 5651 vs KVKK.

A 5-Step Roadmap for Companies

  1. Map scope — who gets internet? (staff, guests, customers)
  2. List log sources — firewall NAT, DHCP, Wi-Fi controller, Captive Portal
  3. Centralize collection — syslog/SIEM; do not trust on-box disk alone
  4. Time + timestamp + retention — NTP, signing, 2-year (or policy) archive
  5. Write the process — who accesses, who deletes, how legal requests are answered (e.g. 1–3 business days SLA)

To avoid network mistakes, read 5651 Network Architecture Mistakes.

Most Common Mistakes

  • Saying “we are not an ISP, so 5651 does not apply”
  • Enabling only firewall traffic logs and skipping DHCP/NAT
  • Opening guest Wi-Fi with no logging
  • Archiving for years with wrong NTP/timezone
  • Treating untimestamped logs as courtroom evidence
  • Merging 5651 and KVKK into one procedure

Related Articles

Checklist

  • Groups using internet (staff/guest/customer) are inventoried.
  • DHCP + NAT/PAT logs land in a central archive.
  • NTP is correct; timezone is consistent.
  • Timestamp / integrity method is defined.
  • Retention is written (common frame: 2 years).
  • Log-delete rights are separated.
  • Guest Wi-Fi has an identity/Captive Portal plan.
  • Legal-request response procedure is written.
  • 5651 and KVKK policies are kept separate.

Next Step with LeonX

For companies, 5651 is not “one logging appliance”—it is network + records + retention + process. Under Business Management Services, LeonX surfaces gaps via Cybersecurity Assessment; on the technical side we build auditable logging through SIEM and Security Event Management Integration and Network Security, Firewall and IPS/IDS. Start at Contact.

Frequently Asked Questions

What is 5651, and why do companies care?

It is the law framing evidentiary internet-access logging. Companies that give staff or guests internet usually fall under obligation.

Are small offices in scope?

Often yes—shared lines and mass use are factual tests. “Small company” is not an automatic exemption; clarify scope legally and technically.

Are firewall logs alone enough?

Usually no. Proving the internal user needs DHCP and NAT/PAT mapping: 5651 Logging.

How long should logs be kept?

Write it in policy; practice often references 2 years. Do not rely on disk overwrite: Archiving.

Does 5651 replace KVKK?

No. Different purposes; design them together, do not substitute one for the other: 5651 vs KVKK.

Sources

Internal Link Path

Continue to the most relevant service pages

Use the links below to move from this article to the primary service, the most relevant detail page and the contact flow.

Share this article

Related Posts

Discover more on similar topics

How to Combine Zero Trust with Law No. 5651 Compliance (2026)
Legal Compliance
2026-08-04
14 min read

How to Combine Zero Trust with Law No. 5651 Compliance (2026)

Zero Trust and 5651 together: identity, segmentation, Captive Portal, NAT/DHCP logs, ZTNA, and the evidence chain in one architecture.

Read Article
Law No. 5651, Cybersecurity, and Evidentiary Value: An IT View (2026)
Legal Compliance
2026-08-03
13 min read

Law No. 5651, Cybersecurity, and Evidentiary Value: An IT View (2026)

How IT should read 5651 logs for cybersecurity and evidentiary value: chain of custody, NTP, NAT/DHCP, timestamps, SIEM, and a practical checklist.

Read Article
Common Mistakes in Designing 5651 Compliant Network Architecture
Legal Compliance
2026-07-10
9 min read

Common Mistakes in Designing 5651 Compliant Network Architecture

We examine the most common technical and architectural mistakes made when designing network infrastructure to ensure compliance with Law No. 5651, their cybersecurity risks, and correct solutions.

Read Article

Subscribe to Our Newsletter

Get the latest insights, trends, and expert advice delivered directly to your inbox. Join our community of IT professionals.

We respect your privacy. Unsubscribe at any time.