Skip to content
Guide

Log Retention Periods: Which Records to Keep and for How Long

Law 5651 puts a two-year retention duty on any organization offering guest Wi-Fi. What KVKK, BDDK and ISO 27001 require, and how to meet the integrity requirement.

Oğuzhan Gerçek··4 min read
Log Retention Periods: Which Records to Keep and for How Long

Short answer: Log retention in Türkiye is not governed by a single regulation. Law 5651, KVKK, industry regulations and ISO 27001 impose different periods and conditions on different records. Beyond the periods, auditors also ask about two things: the integrity of the record and whether it can be produced when requested.

The topic usually comes up at one of two moments: an audit letter arrives, or an incident happens and someone needs to look back. In both cases it is already too late, because log collection cannot be set up retroactively.

This article covers which records are kept and why, and where things go wrong in practice.

How long is only part of the question

Organizations usually ask "how many years must we keep this?" Auditors ask about three things:

Scope. Which systems are you collecting logs from? Servers are usually in scope, but network devices, the firewall, VPN, the authentication system and the application layer are frequently left out.

Integrity. How do you show the record has not been altered? A log infrastructure where a system administrator can erase their own tracks does not count as a log for audit purposes. This is why central collection and write-protected storage are required.

Accessibility. When a request arrives, how long does it take you to produce records for a given date range? "It is in the archive but restoring takes three days" is inadequate in most scenarios.

What does each regulation require?

Law 5651 defines three roles and gives each a different range:

    Access provider: traffic records for no less than six months and no more than two years.Hosting provider: traffic records for no less than one year and no more than two years.Mass-use provider: access records for two years.

That third line applies directly to most organizations: hotels, hospitals, shopping centers, cafés and offices offering guest Wi-Fi all fall under it. The law also goes beyond the retention period; ensuring the accuracy, integrity and confidentiality of the records is part of the obligation. So "we have logs" is not enough. You have to be able to say "these logs have not changed".

KVKK requires that access to personal data be recorded. Just as important as the period is the fact that the record itself contains personal data: storing the log is also a processing activity and needs its own legal basis. Under KVKK, keeping logs indefinitely increases your risk instead of reducing it. We covered the cross-border dimension in KVKK and cross-border data transfer.

Industry regulations impose their own recording and retention requirements, and the longest periods are usually found there. On the banking side, where the record is kept is also regulated; the detail is in BDDK treats cloud as outsourcing.

ISO 27001 does not impose a specific period but requires a defined policy, a retention period and a disposal procedure for records management. You decide the answer to "how long", but you have to put it in writing and then apply it.

Where the four overlap, the longest period and the strictest condition apply.

The four mistakes we see most often

The log stays on the server. A record held on the server is the first thing deleted when that server is compromised. Central collection is essential both for forensics and for integrity.

Retention is set by the disk. The oldest entries are deleted when the disk fills up, so disk capacity sets the retention period, not a policy. When the auditor asks "what does your policy say?", there is no answer.

No time synchronization. If different systems' clocks drift by even a few minutes, building an incident timeline becomes impossible. NTP is the cheapest compliance investment there is.

Nobody records who looked. Access to the log must itself be logged. This is one of the questions an auditor will ask.

Work out capacity up front

Two-year retention means twice the disk of one-year retention, and this is usually discovered mid-project. A simple estimation method: measure a week of raw log volume, apply the compression ratio, multiply by the retention period, and add headroom for growth.

As retention periods get longer, tiered storage starts to make sense: the last 90 days in a fast, accessible hot tier, the rest in cheap write-protected archive. The one thing to watch is that retrieval from the archive is still fast enough to meet an audit request.

A practical rollout order

If you are building from scratch, we recommend this order: authentication and privileged access records first, then firewall and VPN, then server system logs, and application logs last. That order starts with what auditors ask about most and what helps most during an incident.

One more note: collecting logs and monitoring logs are not the same thing. A record collected and never looked at passes the audit but does not prevent the incident. We covered why alerts arrive late in everyone runs Prometheus. Treating the two as one project makes it hard to budget correctly.

You can see how we build this layer on the centralized logging and telemetry page.

Sources


This article is general information, not legal advice. We recommend determining the periods and scope applicable to your organization together with your legal team.