What the DoT and CERT-In rules ask of a hotel, hostel or office that gives people internet access - and how iberry records who was online, on which device and when, so you can answer the question when it comes.
Sooner or later a hotel receives a letter or a visit: a public IP address belonging to your broadband connection was used at a certain date and time, and the investigating officer wants to know who it was. The ISP can only point at the property. The property has to point at a guest.
Without per-user logins and connection records that question has no answer, and a property that cannot answer it carries the problem itself. With them, the front office looks up the time window and hands over a name, a mobile number, a room and a device. That is what the rules below are for, and it is what a managed hotspot and captive portal is built to do.
Summarised from the published texts. General information, not legal advice.
Public hotspot users are given temporary credentials either against a copy of photo ID or by a login sent by SMS to their mobile number, which then stands as their identity. Authentication happens on a centralised server, and the identity records are kept for one year. The direction is addressed to licensed providers and their franchisees; in practice it is the standard a property is measured against when someone asks who was online.
Body corporates - which includes most hotel and hostel companies - must keep the logs of their ICT systems securely for a rolling 180 days, within India, synchronise those systems' clocks to the NIC or NPL time servers (or servers traceable to them), and report listed cyber incidents to CERT-In within 6 hours of noticing them.
Under the PM-WANI framework users authenticate through a WANI app, and the aggregator (PDOA) stores user data for one year within India. DoT circulars of 22 May 2026 added QR-based login for a second device and short 15, 30 and 60-minute data plans. Most hotels do not register as PDOs, but if you do, these rules apply on top.
Attribution is a chain. Break any link and the public IP address in the officer’s letter no longer leads to a person. These are the records iberry keeps for each session:
| Record | What it captures |
|---|---|
| Who | The guest's verified mobile number (SMS OTP), room and surname from the PMS, or the voucher issued at the desk |
| Which device | The device's MAC address and the private IP address it was given |
| When | Login and logout times, from router clocks kept on NTP |
| How much | Data uploaded and downloaded per session |
| Which public IP and port | The NAT translation - the record that turns the ISP's public IP and port into one guest, essential behind carrier-grade NAT |
The last row is the one most setups miss. Indian ISPs increasingly put customers behind carrier-grade NAT, so the same public IP is shared by many guests at once; only the router’s connection translation record, with its source port and an accurate timestamp, separates them.
Guests log in on the captive portal by SMS one-time password, by room number and surname checked against your PMS, or with a voucher issued at the desk. Authentication runs on iberry’s central cloud AAA service rather than on a box in the back office, which is the arrangement the DoT direction describes.
The property’s MikroTik router keeps its clock on NTP and forwards session and connection logs over an encrypted WireGuard tunnel to the iberry log server in India, where they are kept for the retention period agreed for the property - set to the 180-day CERT-In period - and produced to the property on request. The guest network is firewalled off from your own systems, so the logs describe guests and nothing else.
One thing the property has to do itself: keep a single internet path. A second broadband line plugged straight into an access point, bypassing the router, creates traffic that nobody logged.
Plan for at least 180 days. The CERT-In Directions of 28 April 2022 require body corporates to keep the logs of their ICT systems for a rolling 180 days within India, and the older DoT direction on public Wi-Fi keeps identity records for one year. Which one binds your property depends on how it is set up, so take advice on your own case - but a property that can produce 180 days of attributable records is in a far stronger position than one that cannot produce any.
No. A shared password tells you nothing about who was connected. When the police or your ISP ask which guest used a public IP address at a given time, the answer has to come from per-user logins plus the router's connection records - and a single password shared by every room gives you neither.
It is the method the 2009 DoT direction itself describes: a login sent by SMS to the user's mobile number, with the mobile number kept as their identity. iberry supports SMS OTP on the captive portal, alongside PMS login by room number and surname, which ties the session to a registered guest.
Per guest session: the verified mobile number, room or voucher; the device's MAC and IP address; login and logout times; data used; and, on sites with full logging, the router's connection translation records that map a public IP and port back to one guest. Logs travel from the property router to the iberry log server over an encrypted WireGuard tunnel and are stored in India. Retention is set up per property, to the 180-day CERT-In period.
Yes. The records belong to the property and are produced on request for a given time window, so a front office can answer an investigating officer's query in hours rather than say it has nothing.
No. This page summarises the published rules as we apply them on the networks we manage. For a decision about your own obligations, speak to your lawyer.
Tell us how guests get online now and we will tell you plainly what is missing. See also UTM and firewall, WiFi for hostels, PGs and campuses and pricing.
Talk to an Engineer