
Everyone wants to be online at all times. To this end, citizens should be provided with public Wi-Fi via so-called “hotspots” in municipal facilities, public transport and also privately run businesses such as cafés, restaurants and hotels. What is already a reality internationally is still in its infancy in Germany. The reason for this is the so-called “Breach of Duty of Care”. According to this, the operator of a public WLAN can be held liable for injunctive relief for legal violations committed by third parties via their connection. This liability risk stands in the way of the widespread provision of public hotspots.
What has the legislator changed?
On July 21, 2016, the legislator limited itself to adding a paragraph to the liability privilege for access providers regulated in Section 8 of the German Telemedia Act (TMG):
“(3) Paragraphs 1 and 2 shall also apply to service providers pursuant to paragraph 1 who provide users with Internet access via a wireless local area network.”
But what exactly does this change? Can the operator of a hotspot be held liable for injunctive relief in future if a third party illegally distributes music or films via the internet (so-called “file sharing”) and uses the hotspot as an internet access point? The liability of the access provider for injunctive relief is not addressed by the amendment. The German government’s draft bill still provided for a formulation that would have clearly eliminated the liability for interference, namely that hotspot providers could not be held liable for the removal and omission of third-party infringements if they had taken reasonable measures to prevent an infringement.
As a result, the legislator has limited itself to casting the previous case law in legal form. It is already established case law that the operator of a WLAN connection is to be qualified as an access provider. The fact that an access provider can be held liable for injunctive relief regardless of culpability if the infringement can be adequately and causally attributed to him is a result of the legal institution of “Stoererhaftung” (Breach of Duty of Care), which has not been abandoned.
What does the ECJ say?
The ECJ was confronted with the expectation of shedding light on the issue of “Stoererhaftung” (Breach of Duty of Care), i.e. whether the previous German case law contradicted the European requirements and, for this reason, the legal regulation in Germany had to be interpreted in favor of the operators of public WiFi networks. However, in its ruling of 15.09.2016 (Case C-484/14), the ECJ confirmed that the previous German case law on “Stoererhaftung” (Breach of Duty of Care) complies with EU law.
In its ruling, the ECJ confirmed that anyone who makes network access available to the public is to be regarded as an access provider. Consequently, the WLAN operator cannot be accused of merely providing access due to the liability privilege. But does this mean that the WLAN operator is immune from any claims for infringement? No! Just like any other person who participates in legal transactions, an access provider must also observe due diligence obligations. Specifically, this involves the obligation to protect its WLAN from misuse as far as possible. In its decision, the ECJ confirmed the previous (German) case law that the WLAN operator can be held liable for injunctive relief and removal, even if it is neither the perpetrator nor a participant – i.e. merely a disturber. However, an obligation to pay damages presupposes further fault.
What are the consequences for hotspot operators?
Legal certainty for WLAN operators has certainly not been created by the change in the law or the ECJ ruling. As before, WLAN operators run the risk of being held liable for injunctive relief in the event of third-party infringements. In its ruling, the ECJ expressly confirmed that this liability for interference is in line with EU law. As before, the regulation only protects against claims for damages to the extent that the WLAN operator cannot be accused of inadequate security of its WLAN access. What exactly the WLAN operator must do to prevent unauthorized use of its WLAN access has been explained in various rulings: They must take reasonable measures in accordance with the current state of the art to secure the connection and, if necessary, seek professional help to do so.
As a result, everything remains the same: The operator of a hotspot must take the necessary measures to prevent misuse. If this is not otherwise possible, the ECJ has now ruled that the operator must secure access by means of passwords and user authentication.
This means that direct, nationwide access to the Internet at any time will probably remain a dream of the future for the time being.
© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.
KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.