Skip to content
CONFIGLANE

Wireless · Law and engineering

Guest wireless: operator liability is gone — the duties are not

The old fear of a legal warning has been settled in law. The reason to build a guest network properly has become a different — and better — one: it is no longer about liability but about your own network.

By ConfiglanePublished 6 min readCisco Meraki

The short version

  • With the amendment to § 8 TMG, Störerhaftung fell away: operators are largely no longer liable for third parties' infringements over an open wireless network.
  • The exemption applies as long as the operator did not initiate the transmission, did not select the recipient and did not modify the information transmitted.
  • There is no general duty to register and log users. Information and data protection duties under German telecoms law and the GDPR do remain.
  • The most important point is technical rather than legal: the guest network has to be separated from the company network, usually by its own VLAN.

For years, guest wireless was a source of anxiety in German companies. Fear of copyright warnings produced sign-up forms, voucher systems and logs nobody ever evaluated. That legal basis has fallen away — and yet work remains, just different work.

What changed legally

The reform of the German Telemedia Act introduced § 8 paragraph 3 TMG. It places providers who give users internet access over a wireless local network on the same footing as other access providers. That removed operator liability for third parties' copyright infringements over an open wireless network.

The exemption comes with conditions that a normal guest network meets without effort: the operator did not initiate the transmission, did not select the recipient and did not modify the information transmitted. Anyone acting themselves — for example by injecting content — remains liable for their own conduct.

Which duties remain

  • No registration duty. There is no general obligation to register and log users. Anyone who does so anyway needs a reason and a legal basis.
  • Information duty. Even on an open network, IP addresses and connection data are processed. Users have to be informed about that processing.
  • Data protection for everything you collect. As soon as you ask for names, room numbers, email addresses or mobile numbers, the usual rules apply — purpose limitation, retention periods, processing agreements with the portal provider.
  • Several laws interacting. Depending on the design, telecoms law, telemedia law and the GDPR apply side by side. A lean offering is therefore also the legally simpler one.

The point that really counts: separation

The legal all-clear sometimes obscures the actual risk. A guest on the network is no longer a liability problem — but an unknown device remains an unknown device. Guest wireless has to run separately from the company network, usually over its own VLAN.

  1. Its own VLAN, its own path to the internet

    Guest traffic never reaches the company network but goes straight to the connection. No access to servers, printers, point-of-sale systems or network storage.

  2. Separate guests from each other

    Client isolation stops devices on the guest network from seeing one another. It protects your visitors from each other and is a single checkbox.

  3. Cap the bandwidth

    A per-device limit stops one download from occupying the line your telephony and point-of-sale systems also depend on.

  4. Own credentials, rotated on a plan

    A password that has hung at reception for three years is effectively an open network. Rotating credentials or a simple portal solve that without collecting data.

  5. Name it visibly separate

    A distinct network name stops staff from landing on the guest network by accident and then wondering why access is missing — the most common support call after commissioning.

Cloud-managed access points take most of this off your hands: guest network, isolation, bandwidth limit and portal are configuration switches rather than assembly work. How we set up and support such environments is described under Cisco Meraki and, for smaller sites, under smaller companies.

What you can probably switch off

Many guest networks still carry the equipment of the liability era: sign-up forms asking for names, voucher printers, logs retained for months. Today those components mainly generate duties — privacy notices, retention concepts, processing agreements — without providing protection that is still legally required.

The review is worth it: what do we collect, why, how long do we keep it, and who could demand it? If the second question has no good answer, the simplest fix is to stop collecting.

Sources

Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.

FAQ

Frequently asked questions about guest wireless

What should a guest access policy for a wireless network cover?

Four things, and deliberately not more. First, separation: the guest WiFi must not reach the company network — that is the substance of the policy, not the paperwork. Second, the data protection notice for whatever the network does record, kept to what is technically necessary under the GDPR. Third, a deletion schedule for those records. Fourth, a rule for staff devices, so the guest network does not quietly become a second corporate network. Registration forms, voucher printers and long log retention are leftovers from the liability era: today they create duties without buying protection.

Do we have to record who logs into the guest network?

There is no general duty to register and log. You may log if you have a reason and a legal basis — but then the full data protection duties apply. In most cases collecting less is both simpler and legally cleaner.

Is a separate wireless password enough as separation?

No. A second network name with a different password lands on the same network as your servers unless configured otherwise. What is needed is real separation — a dedicated VLAN whose traffic goes straight to the internet connection and which has no access to your company network.

Should we filter content?

Nothing legally compels it for a normal guest network. A simple filter against known malicious sites is still sensible — not because of liability but because it stops an infected guest device from causing damage over your connection. Far-reaching content filtering raises its own questions.

What about staff using the guest network?

That is the most common situation in practice and usually uncritical, as long as it is clear they get no access to company resources that way. It becomes a problem when the guest network is used as a convenient way around restrictions — at which point the issue is not the wireless but the rule being bypassed.

Cisco Meraki

Meraki wireless built around your working day.

Office video calls, mobile devices on the floor and separate guest access have different requirements. We design your Meraki wireless network together with the underlying LAN and verify it using the applications your business actually needs.

Discuss Meraki wireless

Assessment → first dependable change