A cafe offers free Wi-Fi. One day a question arrives from the authorities about activity originating from that cafe's internet address.

The owner did nothing. But the trail does stop at their name, and that is not a flaw in the system, it is how it works.

Why the trail stops at you

Every device on your premises shares one address facing the internet: your subscription's. From outside, the activity of twenty visitors appears to come from a single source.

When someone traces it, the provider can show that the address was registered to you at a given time. That is where the trail ends, unless you keep your own record of who was using it.

How address sharing works is explained in the guide to local IPs and DHCP.

Note. This is an educational summary, not legal advice. Assessing liability depends on circumstances that cannot be judged from a distance. For business decisions, consult a competent legal adviser.

Where you actually stand

Providing access does not by itself make you liable for what other people do. What is generally assessed is whether you took reasonable steps, and whether you can show the act did not originate with you.

Those two things are what you can prepare in advance.

SituationYour position
Open Wi-Fi, no records at allWeakest, nothing to show
Password-protected, no recordsSlightly better
Portal with terms of useEvidence that notice was given
Portal with session recordsCan show the time and the device

Four steps that reduce the risk

Separate the guest network

This is the first step, and its benefit is twofold. Besides protecting the till and work computers from visitors' devices, the separation makes clear that the guest network is its own space. How to do it is in the guide to separating a guest network.

Set a password, do not leave it open

Even a password stuck to the table changes the situation. It shows that access was given, not left free to anyone passing by.

Display short terms of use

One paragraph on the portal page is enough: that access is provided for reasonable use, not for unlawful activity, and can be withdrawn at any time. How portals work is covered in the guide to captive portals.

Keep session records, but only what is needed

Start time, end time, and a device identifier are enough. You do not need, and should not, record the content of visitors' traffic.

On records, and their limits

There is a tension here worth stating openly: the records that protect you are themselves personal data, which brings obligations of its own.

A device's MAC address and access times count as personal data under Law No. 27 of 2022. Storing them makes you a data controller, with the duties that follow, covered in the guide to the rules on collecting customer data.

A reasonable middle ground:

  • Store as little as possible, times and a device identifier, not traffic content.
  • Set a short retention period, say three months, and actually delete afterwards.
  • State in the terms of use that these records are kept and what for.
  • Limit who can open them.

For anyone selling access

If you sell vouchers or share a subscription with others, there is an extra layer to consider. Beyond responsibility for the traffic, there is a question about the status of the activity itself, covered in the guide to RT/RW Net and the guide to setting up Wi-Fi vouchers.

For boarding houses and guest accommodation, per-room records are far more useful than combined ones, they narrow any enquiry to one resident rather than the whole building. The arrangement is covered in the guide to Wi-Fi for boarding houses.

Kesimpulan

  1. Check whether your guest network is genuinely separate from operations.
  2. Make sure no network is left open without a password.
  3. Add one paragraph of terms of use to the portal, or put it up near the till if you do not use a portal.
  4. Check whether your equipment keeps session records, and for how long.

None of the four removes the risk entirely, nothing can. What they do is move you from having nothing to show, to being able to explain what you did.

Frequently asked questions

If someone uses my Wi-Fi for something unlawful, am I liable too?

Not automatically, but the trail leads to you first because the traffic leaves through your subscription's address. What then matters is whether you can show the reasonable steps you took and who was using it at the time.

Am I required to keep records of who connects?

For a small business there is no general obligation to keep detailed records. But simple records actually protect you, because without them you have no way of showing that whoever was using it was not you.

Is leaving Wi-Fi open without a password risky?

Yes, and the risks stack. Beyond anyone being able to use it without a trace, an open network also means your own devices share a room with unfamiliar equipment you know nothing about.