The short version
- With the amendment to § 8 TMG, Störerhaftung fell away: operators are largely no longer liable for third parties' infringements over an open wireless network.
- The exemption applies as long as the operator did not initiate the transmission, did not select the recipient and did not modify the information transmitted.
- There is no general duty to register and log users. Information and data protection duties under German telecoms law and the GDPR do remain.
- The most important point is technical rather than legal: the guest network has to be separated from the company network, usually by its own VLAN.
For years, guest wireless was a source of anxiety in German companies. Fear of copyright warnings produced sign-up forms, voucher systems and logs nobody ever evaluated. That legal basis has fallen away — and yet work remains, just different work.
What changed legally
The reform of the German Telemedia Act introduced § 8 paragraph 3 TMG. It places providers who give users internet access over a wireless local network on the same footing as other access providers. That removed operator liability for third parties' copyright infringements over an open wireless network.
The exemption comes with conditions that a normal guest network meets without effort: the operator did not initiate the transmission, did not select the recipient and did not modify the information transmitted. Anyone acting themselves — for example by injecting content — remains liable for their own conduct.
Which duties remain
- No registration duty. There is no general obligation to register and log users. Anyone who does so anyway needs a reason and a legal basis.
- Information duty. Even on an open network, IP addresses and connection data are processed. Users have to be informed about that processing.
- Data protection for everything you collect. As soon as you ask for names, room numbers, email addresses or mobile numbers, the usual rules apply — purpose limitation, retention periods, processing agreements with the portal provider.
- Several laws interacting. Depending on the design, telecoms law, telemedia law and the GDPR apply side by side. A lean offering is therefore also the legally simpler one.
The point that really counts: separation
The legal all-clear sometimes obscures the actual risk. A guest on the network is no longer a liability problem — but an unknown device remains an unknown device. Guest wireless has to run separately from the company network, usually over its own VLAN.
Its own VLAN, its own path to the internet
Guest traffic never reaches the company network but goes straight to the connection. No access to servers, printers, point-of-sale systems or network storage.
Separate guests from each other
Client isolation stops devices on the guest network from seeing one another. It protects your visitors from each other and is a single checkbox.
Cap the bandwidth
A per-device limit stops one download from occupying the line your telephony and point-of-sale systems also depend on.
Own credentials, rotated on a plan
A password that has hung at reception for three years is effectively an open network. Rotating credentials or a simple portal solve that without collecting data.
Name it visibly separate
A distinct network name stops staff from landing on the guest network by accident and then wondering why access is missing — the most common support call after commissioning.
Cloud-managed access points take most of this off your hands: guest network, isolation, bandwidth limit and portal are configuration switches rather than assembly work. How we set up and support such environments is described under Cisco Meraki and, for smaller sites, under smaller companies.
What you can probably switch off
Many guest networks still carry the equipment of the liability era: sign-up forms asking for names, voucher printers, logs retained for months. Today those components mainly generate duties — privacy notices, retention concepts, processing agreements — without providing protection that is still legally required.
The review is worth it: what do we collect, why, how long do we keep it, and who could demand it? If the second question has no good answer, the simplest fix is to stop collecting.
Sources
Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.
- Störerhaftung: can guest wireless be used without concern?opens in a new tab
Dr. Datenschutz · retrieved 2 August 2026
- Designing wireless and guest access in line with data protection lawopens in a new tab
FFD Forum für Datenschutz · retrieved 2 August 2026

