
The moment guests connect to hotel Wi‑Fi, the hotel begins processing their personal information: mobile numbers, ID numbers, room numbers, internet browsing trails and access records.
This data resides in the hotel PMS system, travels across the hotel network and is stored on log servers. Once leaked, guests may suffer nuisance calls, targeted fraud and malicious marketing. What liabilities will the hotel bear?
Many hoteliers previously believed: “We do not actively disclose the data externally, so we bear no responsibility.” However, Decree No.176 issued by the Ministry of Public Security, effective October 1, 2026, brings this issue fully under regulatory scrutiny.
Issued on August 6, 2026, Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs (Decree No.176) takes effect on October 1, 2026, and repeals Decree No.151.
The core difference between the old and new rules can be summarised in one sentence: Decree No.151 governed “internet security”, while Decree No.176 governs “cyberspace security”, integrating network security, data security and information security.
Article 2 authorises public security organs to inspect network operators, data processors and personal information handlers for their compliance with network, data and information security obligations. Article 7 lists 11 key inspection items, two of which directly relate to data security:
This means hotel PMS databases, guest records and employee information repositories fall within public security supervision, even if never published externally. The old mindset — no external release equals no governance requirement — is no longer valid.
Inspection mechanisms have also changed. Article 4 grants public security organs statutory authority for online patrols and remote technical detection, forming a three-layer model: online patrol, remote detection and on-site verification. Public security authorities at prefecture level and above can perform remote testing through vulnerability scanning and penetration testing, with three working days’ advance notice.
AINOPOL all-optical convergence solution follows a core principle: data security cannot be achieved simply by adding standalone appliances. Instead, the network architecture itself ensures data cannot leak out, cannot be intercepted and cannot be viewed by unauthorised parties.
Optical fibre transmits light signals without electromagnetic radiation, eliminating the electromagnetic leakage risks found in copper cables. The all-optical network features native encryption. The PON link encrypts every business frame with AES‑128, and each ONU negotiates an independent encryption key. Even if attackers physically access the fibre cable, captured data is merely ciphertext.
The all-optical network adopts a flat two-tier core-access architecture. VLAN plus hardware isolation fully segregates guest network, office network and IoT device network.
Compromise of one network segment cannot enable attackers to move laterally into core business systems. Isolation policies are configured and distributed centrally at the core layer and take effect across the whole network. This avoids the classic vulnerability in traditional networks, where missing configuration on one switch creates a security backdoor.
Each ONU port enforces 802.1X access control, paired with MAC whitelisting and identity authentication. MAC addresses of all authorised hotel devices (cameras, access controllers, room control panels, IPTV set-top boxes) are preloaded into the whitelist. Unknown devices attempting to connect are blocked automatically.
This fundamentally prevents penetration by attackers using spoofed terminals to steal data from the hotel internal network.
The solution supports fine-grained hierarchical access control for PMS systems. Front desk staff can only view basic information of in-house guests; managers may access historical records; finance staff can only retrieve billing-related data. Export of sensitive information requires multi-step approval, and all operations are fully logged. Every query and export action, including operator, timestamp and target guest information, is traceable.
Decree No.176 mandates log retention of no less than six months, with complete audit-ready evidence chains. AINOPOL’s solution centrally aggregates internet access logs and screen-casting logs on one unified platform. Authentication and log data are generated within the same system, transmitted over the same link and stored under the same architecture.
Structured logs are saved locally with automatic cyclic rotation, retained for 180 days by default, with no gaps, forced clearing or tampering. Multi-dimensional filtering by room number, real-name user or time period is supported, alongside one-click export of compliance reports. In the event of a data security incident, hotels can quickly provide complete audit trails to prove they have fulfilled data protection obligations.
Traditional hotel data security deployments require separate procurement of firewalls, log servers, authentication systems and encryption appliances from multiple vendors. Fragmented hardware creates complex configuration and management gaps.
AINOPOL Dream Series secure optical gateways integrate routing, switching, all-optical networking, security, AC, IPPBX, log audit and data encryption in one hardware unit, replacing multiple discrete devices. Built-in security engines include IPS intrusion prevention, AV antivirus and WAF web application firewall. The IPS engine contains over 10,000 attack signatures; the AV virus library covers more than 4 million virus samples; the WAF defends against SQL injection, XSS and Webshell uploads.
The gateway supports routing, bridge and bypass deployment modes. Existing hotels can deploy in bypass mode without modifying the original network, completing compliance networking for an entire hotel within half a day.
Decree No.176 upgrades data security from optional best practice to a mandatory technical requirement. A hotel in Xuzhou was penalised for unencrypted accommodation data; a Ji Hotel faced fines up to 5 million RMB after employee leakage of guest remarks; vulnerabilities in smart speakers at another hotel exposed thousands of guest records. These cases share one common trait: the incidents were not caused by large-scale hacking, but obvious gaps in data protection.
Unencrypted transmission, missing internal network isolation, lack of terminal admission control and insufficient log retention — any of these four gaps can become a channel for data leakage.
AINOPOL all-optical convergence solution delivers five layers of protection: transmission encryption, network isolation, terminal admission control, permission governance and log auditing. It blocks every possible leakage channel at the architectural level. Instead of fixing breaches after incidents, it eliminates leakage vectors from the start.
Q: What new data security requirements does Decree No.176 impose on hotels?
A: Decree No.176 expands supervision scope from internet security to cyberspace security, covering network, data and information security. The Data Security Law and Personal Information Protection Law serve as enforcement grounds. Hotels must implement data encryption, access permission control, log retention and personal information protection. Internal systems and data assets are also subject to inspection.
Q: What are the main risk points for hotel guest data leakage?
A: Three primary risks: unencrypted transmission, making data easy to intercept; lack of internal network isolation, allowing lateral movement once one terminal is compromised; inadequate internal permission management enabling staff to freely view, export and copy guest information.
Q: What is the worst consequence without data security protection?
A: Under the Data Security Law and Personal Information Protection Law, improper handling of personal information can incur fines up to 5 million RMB. Severe violations may constitute the criminal offence of infringing citizens’ personal information. Cyberspace authorities in Hunan have already imposed administrative penalties on hotels under the Personal Information Protection Law.