# Law No. 5651 (Türkiye)

> Law No. 5651 is the Turkish law regulating online publications and setting duties for content, hosting, access and collective-use providers.

Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed through Such Publications entered into force in Türkiye in 2007. It defines the parties involved in online publishing and assigns each different responsibilities. Content providers create or publish content. Hosting providers host it. Access providers are the ISPs that connect users to the internet. Collective-use providers give people internet access at a particular place and for a certain time.

The concept that affects the widest audience is the collective-use provider. Hotels, cafés, restaurants, malls, hospitals, schools, dormitories and internet cafés that offer internet access to guests all fall into this category. Under the Regulation on Collective-Use Providers, they must take measures to prevent access to criminal content. They must also record internal IP allocation logs (which IP address was given to which device during which time window) electronically, ensuring their accuracy, integrity and confidentiality. Commercial operators such as internet cafés must additionally obtain a permit from the local governorship.

The law requires hosting and access providers to retain traffic data for a period set by regulation of no less than one and no more than two years. Retaining records for two years is also a common, cautious practice at collective-use locations. The authority responsible for enforcement is BTK, which took over the duties of the Telecommunications Communication Presidency (TİB) when it was closed in 2016. Access providers must be members of the Association of Access Providers, which implements access-blocking orders. Failure to meet obligations can lead to administrative sanctions.

Technical compliance comes down to complete and trustworthy records. DHCP or hotspot session logs must be collected with accurate time. They must be archived so that their integrity can be proven, for example with RFC 3161 timestamps, and be quickly searchable when competent authorities request them. For access providers using CGNAT, public IP–port–subscriber mapping logs matter just as much. Because these records contain personal data, processes should be designed together with KVKK requirements, and the current legislation should always be checked against official sources.

---
Canonical: https://internetten.com.tr/en/glossary/law-5651
