Business Support

Technical Support

About Guangxun

About Ainopol

E-sports Hotel in Deyang Fined RMB 10,000: With Real-Name Authentication in Place, Why Penalty for Log Retention?
2026-08-22 14:46:32 21

E-sports Hotel in Deyang Fined RMB 10,000: With Real-Name Authentication in Place, Why Penalty for Log Retention?

“Many businesses assume they are only victims when their websites get hacked. In fact, failure to fulfil cybersecurity protection obligations constitutes a violation in itself.”

The statement was made by an officer from the Cybersecurity Brigade of the Economic Development Zone Public Security Sub-bureau in Deyang City.

In July 2026, during the Special 100-Day Crackdown on Summer Public Security Risks, the Cybersecurity Brigade of Deyang Economic Development Zone Public Security Sub-bureau penalised multiple local entities that failed to perform cybersecurity protection duties. Among them, an e-sports hotel received a warning, an order to rectify within a time limit, and a fine of RMB 10,000 due to inadequate technical protection measures and failure to record cybersecurity event logs as required.

After the news broke, many hotel operators were confused: guests completed real-name authentication for internet access, so why was there still a fine?

I. What Caused the Penalty for the E-sports Hotel?

The e-sports hotel did not completely skip compliance work.

In conventional understanding, it had implemented real-name authentication for Wi-Fi access — guests needed to verify their mobile phone numbers or IDs to connect to the network. However, public security inspectors concluded that technical safeguards were insufficient, and cybersecurity event logs were not kept in accordance with regulations.

Deyang Public Security stated clearly in its notice: “Weak passwords, unencrypted transmission and missing logs all qualify as typical ‘unprotected network exposure’.”

The core issue lay in the “missing logs”.

A person in charge of the public security cybersecurity brigade explained that the Cybersecurity Law of the People’s Republic of China mandates network log retention for no less than six months. Although the e-sports hotel carried out real-name authentication, it failed to retain logs as required — whether the retention period was insufficient, log fields were incomplete, or logs could not be exported. In the eyes of regulators, this still counts as “failure to fulfil cybersecurity protection obligations”.

This e-sports hotel was not the only penalised entity in the enforcement round. A training centre was penalised for lacking formal cybersecurity management rules and unauthorised access caused by weak passwords for website backend administrator accounts. An online commercial company received penalties due to unauthorised access vulnerabilities on its website and inadequate log monitoring and recording. Deyang Economic Development Zone Public Security has prioritised platform enterprises, e-sports hotels and public service websites for regulatory oversight.

II. Three Hidden Pitfalls of Log Retention

Most hotels do not intentionally omit log storage; they simply do not realise their log storage configuration is non-compliant.

Pitfall 1: Assuming router-based log storage is sufficient
Most hotel routers only have storage capacity ranging from several hundred megabytes to a few gigabytes. Storage fills up within days, and new logs automatically overwrite old entries. Legally, retaining logs for 7 days versus 180 days is the difference between “having logs” and “having no logs at all”. During inspections, logs retained for less than six months are treated as non-existent.

Pitfall 2: Believing records of IP addresses and timestamps constitute valid logs
Compliant logs must include complete core fields: MAC address, IP address, authenticated account, internet access start and end time, access records and more. Many devices can only log “who connected to Wi-Fi” without recording “which websites were visited”. Incomplete log fields are deemed equivalent to missing logs.

Pitfall 3: Thinking stored logs are enough, regardless of export capability
During inspections, regulators do not merely check whether logs exist. They ask three direct questions: “Are the logs available? How far back can records be retrieved? Can logs be exported by time frame, room and IP address?” Logs scattered across separate devices, lacking unified export functions or compatibility with public security network monitoring platforms are considered non-compliant.

The Deyang Public Security notice explicitly states: “Refusal to rectify violations or resultant hazardous consequences may incur fines up to RMB 500,000.” The newly revised Cybersecurity Law effective in 2026 raises the maximum corporate fine to RMB 10 million.

III. AINOPOL All-in-One Solution for Compliance

The AINOPOL all-optical converged solution embeds native real-name authentication and log retention capabilities into the all-optical network foundation. No additional third-party hardware procurement is required; the system meets the requirements of Public Security Order No.151 and Classified Protection of Cybersecurity 2.0 out of the box.

Real-name Authentication: Multiple Modes, Ready for Immediate Use
Supports over 20 authentication methods including room number verification, ID card scanning, WeChat authentication and SMS verification. It seamlessly integrates with PMS systems to enable authentication upon check-in and one-click internet access. The hardware includes built-in compliant SMS qualifications, eliminating the need for hotels to apply for SMS permissions separately.

Log Retention: Automatic Collection, Local Tamper-Proof Storage
All internet access logs are automatically captured with complete fields including MAC address, IP address, authenticated account, access time window and visit records. Logs are encrypted and stored locally at the hotel, protected against tampering and deletion. The default retention period is 180 days with an intelligent rolling retention mechanism that automatically overwrites expired data without data loss or redundant storage.

One-Click Export: Stress-Free Public Security Inspections
Supports multi-dimensional log queries by mobile number, MAC address, time period and more. One-click generation of compliance reports formatted for public security requirements, with support for real-time data submission to network monitoring platforms. No manual log sorting is required during inspections; compliant documentation can be generated within seconds.

The AINOPOL Dream Series Secure Optical Gateway natively integrates real-name authentication, 180-day log retention, IPS/AV/WAF security engines and all-optical transmission within a single hardware unit. One device handles authentication, log management and network security, removing the need for assembled third-party hardware or external log servers.

The RMB 10,000 fine imposed on the Deyang e-sports hotel was not due to missing real-name authentication — authentication was implemented. The violation stemmed from authentication without compliant log retention.

Public Security Order No.151 sets clear requirements: real-name authentication plus 180-day log retention. Both obligations must be fulfilled.

If your hotel still relies on outdated mindsets such as “a Wi-Fi password is enough”, “7 days of log storage suffices” or “real-name authentication guarantees full compliance”, you could be the next recipient of a penalty notice.

Real-name authentication serves as the entry pass, while log retention acts as compliance protection. Completing only authentication without proper safeguards creates an illusion of compliance, leaving the business continuously exposed to regulatory penalties.

FAQ

Q: My hotel already implements Wi-Fi real-name authentication. Why could we still face fines?
A: Real-name authentication and log retention are two mandatory, inseparable requirements. Although the Deyang e-sports hotel enabled real-name authentication, it was fined RMB 10,000 for failing to retain cybersecurity logs as stipulated.

Q: Does password-protected hotel Wi-Fi count as real-name authentication?
A: No. Real-name authentication binds internet behaviour to verified real identities such as mobile phone numbers or ID numbers. A shared universal Wi-Fi password cannot trace online activities to specific individuals.

Q: What is the worst-case consequence of skipping log retention?
A: In the event of cybersecurity incidents, traceability becomes impossible, and the hotel bears full liability. Under the newly revised Cybersecurity Law, enterprises may face fines up to RMB 10 million. Refusal to rectify violations may result in fines as high as RMB 500,000.