One message reliably unsettles the owners of cafés, guesthouses, and small offices: a letter or a call stating that copyrighted material has been downloaded from their internet connection.
The first reaction is nearly always the same, confusion. They didn't download anything. They don't even know who did.
That confusion is reasonable, and resolving it starts with one technical fact that rarely gets explained: to the outside world, every device on your network appears as the same single address.
What outsiders actually see
When a device on your network contacts the internet, what gets recorded at the far end is not a person's name or a phone model, but one public IP address, the address your provider assigned to your connection, shared by everyone using it.
A guest's phone, an employee's laptop, the television in the waiting area: all leave through the same door. The mechanism is covered in the guide to NAT and CGNAT, and its consequence matters here, nobody outside can tell one device on your network from another.
With torrent-style file sharing, things are more open still. The design requires participants to know each other's addresses; that is precisely how they exchange pieces of a file. Anyone joining the same swarm, including parties whose job is to monitor it, sees that list without having to break into anything.
What they collect is three things: an IP address, a timestamp, and a file name. Not a name.
From IP address to subscriber
Only one party holds the link between address and identity: the internet provider. They alone know which address was assigned to which subscriber, and when.
That record isn't handed over on request. Disclosing it touches subscriber personal data, which is protected, see the guide to personal data protection law, so the route runs through legal process, not a private letter.
A notice arriving directly at your home address therefore means either that this step has already been taken, or that the letter was forwarded by your provider without your identity ever being disclosed to the sender.
Where the Wi-Fi owner stands
Here is the distinction that decides it. Providing access is not the same as infringing, and the law in many places does separate the two, conditionally.
What strengthens an access provider's position:
- Not knowing the infringement was taking place.
- Not profiting from it.
- Acting once notified, cutting off the device concerned rather than ignoring the matter.
What weakens it is the mirror image: knowing the network is used this way, allowing it, and continuing to provide access. At that point "I only provide the Wi-Fi" loses its footing, because the provision has become knowing.
This sits closely alongside the guide to Wi-Fi owner responsibility, which applies the same framework to other kinds of misuse.
Why records protect rather than expose
Many owners avoid keeping any records, reasoning that what doesn't exist can't be used against them.
On this particular question, that reasoning runs backwards.
With no records at all, exactly one name is available to attach to the connection: the subscriber's. Records showing which device was on the network at that hour are the only means of moving the question from you to the person actually involved.
Retention duties and periods are covered in the guide to log retention obligations. Worth underlining here: these records are not about inspecting what visitors do, but about knowing which device connected and when.
Precautions worth taking
Not every precaution earns its place. Most inconvenience visitors far more than they deter misuse. These ones are worth it.
Separate the guest network
Guests have no need to sit on the same network as the till or the security cameras. The separation is covered in the guide to separating the guest network, and it helps twice over here: guest activity is recorded apart, and your business devices aren't dragged in.
Cap speed on the guest network
This is a quiet and effective deterrent. Downloading large files needs both bandwidth and time; checking messages and opening maps needs neither. A cap that feels fine for ordinary use makes extraordinary use unattractive by itself. The method is in the guide to limiting Wi-Fi speed.
State the rules on the login page
The page shown before a visitor connects is the right place to say what isn't permitted. It works in both directions: it deters some people, and it demonstrates that you prohibited it. The wording is discussed in the guide to guest Wi-Fi terms and the guide to captive portals.
Recognise unusual usage
A single device pulling data continuously for hours has a different shape from ordinary browsing, and that shape is visible from the router's admin pages, the guide to seeing who is using your Wi-Fi shows where. If it needs stopping, the guide to blocking a user covers that.
What won't help
- Hiding the network name. Unrelated to this problem entirely, see the guide to hiding your Wi-Fi name.
- MAC filtering. Easily bypassed, and it obstructs legitimate guests far more, see the guide to MAC filtering.
- Running a VPN on the router for the whole network. This actively worsens your position: you would be concealing activity you don't know about, which is hard to present as not knowing. A VPN protects a user on someone else's network, see the guide to VPNs on public Wi-Fi, it isn't a tool for the network's provider.
- Shutting guest Wi-Fi down altogether. This removes the risk along with all the benefit. For most businesses it trades a rare problem for a daily loss.
If a notice does arrive
What matters is not how fast you reply, but how precisely.
- Admit nothing you haven't verified. A letter contains an allegation, not a finding.
- Check your records for the date and time cited.
- Keep evidence of the precautions already in place: guest network separation, speed caps, stated terms. Each shows your provision of access wasn't negligent.
- Ask for the basis and the details: IP address, date, time, time zone. IP addresses move between subscribers, and an error of a single hour can point at an entirely different connection.
- Take legal advice if the claim proceeds. This page is general explanation, not a substitute for advice on your own case.
In short
An IP address identifies a connection, not a person. That is why the first question always lands on the subscriber, and equally why that question is not a conclusion.
What moves you from suspect to reasonable access provider isn't locking everything down. It is three unremarkable things: a separated guest network, rules stated up front, and enough of a record to show that what happened wasn't you.