A cafe offers free Wi-Fi. One day a question arrives from the authorities about activity originating from that cafe's internet address.
The owner did nothing. But the trail does stop at their name, and that is not a flaw in the system, it is how it works.
Why the trail stops at you
Every device on your premises shares one address facing the internet: your subscription's. From outside, the activity of twenty visitors appears to come from a single source.
When someone traces it, the provider can show that the address was registered to you at a given time. That is where the trail ends, unless you keep your own record of who was using it.
How address sharing works is explained in the guide to local IPs and DHCP.
Note. This is an educational summary, not legal advice. Assessing liability depends on circumstances that cannot be judged from a distance. For business decisions, consult a competent legal adviser.
Where you actually stand
Providing access does not by itself make you liable for what other people do. What is generally assessed is whether you took reasonable steps, and whether you can show the act did not originate with you.
Those two things are what you can prepare in advance.
| Situation | Your position |
|---|---|
| Open Wi-Fi, no records at all | Weakest, nothing to show |
| Password-protected, no records | Slightly better |
| Portal with terms of use | Evidence that notice was given |
| Portal with session records | Can show the time and the device |
Four steps that reduce the risk
Separate the guest network
This is the first step, and its benefit is twofold. Besides protecting the till and work computers from visitors' devices, the separation makes clear that the guest network is its own space. How to do it is in the guide to separating a guest network.
Set a password, do not leave it open
Even a password stuck to the table changes the situation. It shows that access was given, not left free to anyone passing by.
Display short terms of use
One paragraph on the portal page is enough: that access is provided for reasonable use, not for unlawful activity, and can be withdrawn at any time. How portals work is covered in the guide to captive portals.
Keep session records, but only what is needed
Start time, end time, and a device identifier are enough. You do not need, and should not, record the content of visitors' traffic.
On records, and their limits
There is a tension here worth stating openly: the records that protect you are themselves personal data, which brings obligations of its own.
A device's MAC address and access times count as personal data under Law No. 27 of 2022. Storing them makes you a data controller, with the duties that follow, covered in the guide to the rules on collecting customer data.
A reasonable middle ground:
- Store as little as possible, times and a device identifier, not traffic content.
- Set a short retention period, say three months, and actually delete afterwards.
- State in the terms of use that these records are kept and what for.
- Limit who can open them.
For anyone selling access
If you sell vouchers or share a subscription with others, there is an extra layer to consider. Beyond responsibility for the traffic, there is a question about the status of the activity itself, covered in the guide to RT/RW Net and the guide to setting up Wi-Fi vouchers.
For boarding houses and guest accommodation, per-room records are far more useful than combined ones, they narrow any enquiry to one resident rather than the whole building. The arrangement is covered in the guide to Wi-Fi for boarding houses.
Kesimpulan
- Check whether your guest network is genuinely separate from operations.
- Make sure no network is left open without a password.
- Add one paragraph of terms of use to the portal, or put it up near the till if you do not use a portal.
- Check whether your equipment keeps session records, and for how long.
None of the four removes the risk entirely, nothing can. What they do is move you from having nothing to show, to being able to explain what you did.
Frequently asked questions
If someone uses my Wi-Fi for something unlawful, am I liable too?
Not automatically, but the trail leads to you first because the traffic leaves through your subscription's address. What then matters is whether you can show the reasonable steps you took and who was using it at the time.
Am I required to keep records of who connects?
For a small business there is no general obligation to keep detailed records. But simple records actually protect you, because without them you have no way of showing that whoever was using it was not you.
Is leaving Wi-Fi open without a password risky?
Yes, and the risks stack. Beyond anyone being able to use it without a trace, an open network also means your own devices share a room with unfamiliar equipment you know nothing about.