This question arrives in a characteristic order. Someone opens a café, sets up guest Wi-Fi, then hears that "Wi-Fi providers must keep logs". What usually follows is one of two things, and both are wrong: storing everything, or storing nothing.

The middle ground isn't complicated, but it requires one step that's often skipped, first establishing whether the duty applies to you at all.

Who the duty attaches to

The distinction that decides everything is between providing internet service and using a connection and sharing it.

Service providerCustomer sharing a connection
ExampleLicensed internet providerCafé, office, boarding house, clinic
Sells accessYes, as the core businessNo, or merely as an amenity
Registered as a providerYesNo
Retention dutyAttachesGenerally not

A café that subscribes to internet like a household and shares it with guests sits in the right column. The legally binding records are kept by its internet provider, not by the café.

The line shifts if you sell the access. Selling vouchers to neighbours, taking monthly fees from several households, or reselling the connection to other units as a paid service moves you toward the left column. That's discussed in the guide to community network legality.

Why keep anything at all

The absence of a duty isn't a reason to record nothing. Three practical needs remain, and all three are yours.

  • Tracing faults. When the network slows at certain hours, records of device counts and usage are the only way to answer it definitively, see the guide to internet slowing at certain hours.
  • Spotting unusual usage. One device consuming all capacity, or devices connected outside opening hours, see the guide to seeing who's on your Wi-Fi.
  • Responding to an official request. If one ever arrives, having tidy timestamps is far better than having nothing.

What's reasonable to record

The principle: record what answers "when and how much", not "who and what were they viewing".

ReasonableBetter not
Connect and disconnect timesLists of sites visited
Device counts per hourTraffic contents in any form
Total data consumedPasswords or form entries
MAC addresses, where genuinely neededPersonal data you don't need
Technical events: failed joins, restartsRecordings of conversations or messages

The right column isn't merely inadvisable. Intercepting other people's traffic contents raises a different kind of issue, and isn't justified simply because the network is yours. A summary of what attaches to you as a provider is in the guide to Wi-Fi owner responsibility.

On MAC addresses

This is the most commonly misunderstood part. A MAC address is often treated as a mere technical number, yet it's fixed permanently to a device and cannot be changed by its owner. Once it can be linked to a person, through a registration form, for instance, it's treated as personal data.

Storing it isn't a violation. Three things demand attention:

Have a purpose you can state

"Just in case" isn't a purpose. "To link a portal session to the login process" is.

Set the duration from the outset

Not decided later when storage fills up. Once it passes, blank the column, the row can stay for statistics.

Don't send it to third parties

Including accidentally. A page address containing a MAC is sent as the referrer to every service that page calls, and that happens with nobody noticing.

The general rules are in the guide to personal data protection, and the collection side in the guide to collecting customer data.

How long

There's no figure that fits everyone, but there is usable logic: keep records while they still answer questions you might ask.

  • Technical records: three months. Nearly every fault worth tracing surfaces within days, not months.
  • Any personal data: as briefly as possible. If the purpose is fulfilled once the guest is connected, there's no reason to keep it overnight.
  • Summary figures: indefinitely is fine. Daily visitor counts point at nobody in particular.

Keeping longer adds obligations, not protection. Records in your possession are records you must protect, and must answer for if they leak. What's already deleted cannot leak.

If the records leak

The duty most often forgotten: once you store personal data, you have a duty to notify if it leaks, and the deadline is short.

The steps, including to whom and within what period, are in the guide to reporting a data breach.

This is the strongest practical argument for not collecting what you don't need: every extra column is an extra obligation if something happens.

What to do in practice

Establish where you stand

Subscribing as a customer and sharing, or selling access as a business. That answer determines everything else.

Separate guests from business equipment

This reduces what you have to protect in the first place, see the guide to separating guest networks.

Enable the router's built-in logging, nothing more

Most routers already record joins and disconnects. That's adequate operationally, and it doesn't touch traffic contents.

Write the policy down, however briefly

What's recorded, why, for how long. One paragraph on your terms page is enough, see the guide to guest Wi-Fi terms.

Set a reminder to delete

Deletion that depends on memory never happens. Schedule it, or configure it to rotate on its own.

Conclusion

Retention duties attach to internet service providers, not to every venue sharing its connection. Cafés, offices, and boarding houses generally sit outside them.

What remains sensible is modest technical records, with a purpose you can state and a limit set from the outset. Storing more doesn't make you safer, it merely moves the risk from your internet provider onto your own desk.

Frequently asked questions

Is a café required to keep Wi-Fi usage logs?

Retention duties attach to registered internet service providers, not to every venue that shares its connection. A café subscribing as an ordinary customer is generally outside that duty, the records are kept by its internet provider.

If it isn't required, should logs be kept at all?

Modest technical records are useful for your own purposes: tracing faults, spotting unusual usage, and responding if an official request arrives. What to avoid is storing traffic contents or personal data you don't need.

How long should records be kept?

For operational purposes three months is usually more than enough, nearly every issue worth tracing appears within days. Keeping longer adds no benefit but adds risk if there's ever a breach.

Does storing MAC addresses count as personal data?

A MAC address is an identifier fixed to a device that its owner cannot change, so under many readings it's treated as personal data once it can be linked to a person. Storing it isn't a violation, but it demands a stated purpose and a time limit.