The question usually arrives as a worry: could a café owner be held responsible if a customer opens something they shouldn't over their Wi-Fi?
Answering it means separating two things that often get merged, and that separation saves a great deal of unnecessary work.
Filtering and monitoring
They sound similar. Their consequences are very different.
| Filtering | Monitoring | |
|---|---|---|
| What it does | Closes a route to something | Records who opened what |
| Personal data | None processed | Processed, with all its duties |
| The burden | Configure once | Storage, protection, deletion |
| Its status | Expected | Not required for content of activity |
What's expected of a Wi-Fi provider is the first. Filtering touches nobody's personal data, nothing recorded, nothing stored, nothing requiring protection.
The second is a far heavier burden, and most Wi-Fi providers aren't required to do it for what visitors actually do. What does need keeping is the technical connection record, which device, at what time, covered separately in the guide to log retention obligations.
Most of it already runs without your input
This is the least appreciated part: filtering in Indonesia is applied at the internet service provider level. It already applies to your connection, and to everyone using it.
So a café on an ordinary internet subscription is already inside that filtering without doing anything. How it works is explained in the guide to how site blocking works.
What that makes your duty isn't adding filtering, but not removing it: and this is where the most common mistake happens.
The common mistake: changing the network's DNS
Changing DNS is frequently recommended for speed, and for personal use that's reasonable, see the guide to changing DNS and the guide to public DNS and privacy.
But on a network you provide to the public, the consequence differs. Because filtering largely works through DNS, pointing an entire network at an external DNS deliberately removes filtering that should apply.
On your own home router, that's your decision. On Wi-Fi used by visitors it's a hard position to defend if questioned, particularly where children have access.
When additional filtering is genuinely warranted
For cafés, shops, and offices generally, the built-in filtering is adequate. Three situations differ:
- Schools and tutoring centres. The users are children, and adult supervision isn't always beside them. Network design is covered in the guide to Wi-Fi for schools and tutoring centres.
- Play areas and family waiting rooms. Children use their parents' devices, often unobserved.
- Boarding houses and guesthouses with residents under 18, see the guide to Wi-Fi for boarding houses.
In all three, filtering at your own network level is a reasonable step. Not because it's specifically demanded, but because negligence in places like these is far harder to explain.
How to comply without burden
The simplest and nearly free option: point the router's DNS at a service that filters adult content. Several public DNS providers offer a variant for exactly this.
Its advantages, and why it's the sensible choice:
- Configured once on the router, applies to every connected device.
- Records nothing about visitors.
- Doesn't slow the network.
- Needs no additional equipment.
On larger networks, filtering can differ by segment using the guide to VLANs, a student network filtered more tightly than a staff one, for instance.
At home, a similar need is met differently, per device and per hour, as in the guide to parental controls on a router.
Limits worth knowing
DNS filtering isn't perfect, and it matters not to promise more than it delivers:
- It can be bypassed by anyone changing DNS on their own device, or using a VPN, see the guide to VPNs on public Wi-Fi.
- It doesn't catch everything. Any filtering list lags behind what's new.
- It sometimes blocks what it shouldn't. Health and education sites are occasionally caught.
That imperfection doesn't negate its value. What determines your position isn't whether the filter can be bypassed but whether you put one in place. A provider taking reasonable steps stands somewhere very different from one that did nothing, the same framework as in the guide to Wi-Fi owner responsibility and the guide to copyright and illegal downloads.
State it; don't do it quietly
Disclosed filtering is stronger than hidden filtering, exactly as with workplace network monitoring, covered in the guide to monitoring employee internet use.
One line on the login page is enough: "This network filters inappropriate content." Wording is covered in the guide to guest Wi-Fi terms, and where it goes in the guide to captive portals.
It works in both directions: visitors know what applies, and you have evidence your provision of access wasn't negligent.
The bottom line
Filtering and monitoring aren't the same, and only the first is expected of a Wi-Fi provider. Filtering touches nobody's personal data, so it carries none of the duties that follow from it.
Most filtering already runs at the provider level without your involvement. The remaining duty is better described as not removing it, and the most common way of removing it, unintentionally, is pointing the whole network's DNS at an external service.
Where children have access, one additional step is worth it: a filtering DNS on the router, and one line on the login page saying so.
Frequently asked questions
Must public Wi-Fi providers filter content?
Internet service providers apply filtering at their level, and it already applies to your connection without any configuration. What falls to a Wi-Fi provider is not removing that filtering, and paying closer attention where children have access.
What's the difference between filtering and monitoring?
Filtering closes off a route to something, no personal data is processed. Monitoring records who opened what, which touches personal data along with every duty attached to it. What's expected is the former.
Is relying on the provider's filtering enough?
For cafés and shops generally, yes. For schools, tutoring centres, and children's play areas, additional filtering at your own network level is a reasonable and easily taken step.