Home  /  Blog  /  Security

Guest Wi-Fi log retention in Türkiye: who must comply?

If you offer Wi-Fi to guests in Türkiye, this obligation applies to you.

Businesses that provide internet access in Türkiye must retain access records. The law that requires this, No. 5651, is an obligation most business owners are unaware of — until a request arrives.

Who is in scope?

Broadly: anyone providing internet access to people other than their own staff.

  • Hotels, guest houses and serviced apartments offering Wi-Fi
  • Cafés, restaurants, shopping centres and retail
  • Hospitals, clinics and laboratories
  • Workplaces giving visitors network access
  • Schools, training centres and student residences
  • Co-working spaces and business centres

If you are a closed office network used only by employees the position differs — but keeping logs is still worth doing for your own security.

What has to be retained?

Not content — connection data. Not what someone wrote, but which user connected, when, and to what address.

Three things matter:

  • User attribution. The record must be traceable to a person. On a single Wi-Fi network where everyone shares one password, that is impossible.
  • Accurate time. If the device clock is wrong the record carries no evidential weight. NTP synchronisation is essential.
  • Integrity. You must be able to show the record has not been edited afterwards.

How it is implemented

Two parts.

The part that produces the record: usually the firewall. FortiGate already generates it; the configuration just has to be correct.

The part that stores it: keeping logs in the appliance's own memory is not enough — that holds a few hours and clears on reboot. A separate collector is needed. On the Fortinet side that is normally FortiAnalyzer.

For the guest network a captive portal is also set up: the user is verified by mobile number, which makes the record attributable to a person.

Common mistakes

  • A single shared Wi-Fi password. If everyone uses the same credential you cannot attribute the record.
  • Unsynchronised clocks. A log with wrong timestamps is no better than no log.
  • Relying on the router log. Consumer-grade equipment does not produce an adequate record.
  • No defined retention period. How long records are kept should be a deliberate decision.
  • No access control. Who viewed the logs should itself be recorded.

Where to start

First establish the simple question: do you give guests internet access? If yes, you are in scope.

The rest is configuration. If you already have a firewall, the right settings plus a collector are usually enough — a rebuild is rarely necessary.

If you are unsure, ask. We will assess whether you fall within scope and design the setup if you do.

Need help with this?

Ask us about fortinet firewall installation, or request a free assessment directly.

Fortinet firewall installation
Blog

More articles

Security

Ransomware has hit: what to do in the first 24 hours

The first hour determines how bad the next month is. What to do, in order.

Security

Backup for small businesses: the 3-2-1 rule

Most businesses have backups. Far fewer have a backup that survives ransomware — and that is a different thing.

Security

The first hour after data loss: what to do and what not to

The data is usually still there. The real loss happens during recovery attempts.