
On August 6, 2026, the Ministry of Public Security officially issued the Measures for Cyberspace Security Supervision and Inspection by Public Security Organs (Ministerial Order No.176), which took effect on October 1, 2026. The new regulation expands its scope from original "internet security" to "cyberspace security" (covering cybersecurity, data security and information security). Hotels, categorized as public internet service providers, are explicitly listed as subjects for supervision and inspection.
Article 7 of Order No.176 mandates key inspections to verify "whether user registration information and internet access logs are recorded and retained in accordance with the law". Meanwhile, supervision has upgraded from periodic spot checks to continuous online oversight. Public security authorities may conduct remote online inspections through information scanning, vulnerability detection and penetration testing. Log retention is no longer a makeshift measure for audits, but a standard requirement for daily operations.
Less than two weeks after the new regulation came into force, penalties were already issued. The Public Security Bureau of Yijun County penalized a hotel for failing to implement real-name registration on its wireless network and issued a disciplinary warning. Another hotel in Xichang received a legal warning and an order for rectification within a time limit, because guests could connect to public Wi-Fi merely by scanning a QR code for a simple password, with no real-name verification at all.
There is no grace period for compliance. Order No.176 is officially in force. Hotels with log retention shorter than 180 days face inspection and fines at any time.
Compared with Ministerial Order No.151, Order No.176 introduces upgrades in three dimensions:
Order No.176 is not a simple revision of Order No.151; it represents a fundamental reshaping of regulatory logic. Log retention has shifted from an optional item to a mandatory requirement.
AINOPOL embeds log retention capabilities into the network architecture, instead of adding external storage devices as an afterthought. A single Mengxiang-series secure optical gateway addresses three core demands simultaneously: real-name authentication, 180-day log retention and security protection.
The AINOPOL Mengxiang-series secure optical gateway comes with built-in local hard drives, supporting automatic rolling local storage of complete logs for 180 days. Logs contain full core fields including MAC address, IP address, authenticated account (mobile phone number / ID number), internet access start & end time, accessed URLs and more. All log data is encrypted and tamper-proof. Data stays on-premises within the hotel to satisfy data residency requirements.
One device handles identity authentication, log retention and full-network security management. The underlying "session binding" technology natively links authenticated accounts with internet behaviors. No cross-device data correlation is needed during inspections. Authorized users can log into the EAAS cloud platform and export compliance reports in standard format with one click.
For chain hotels and multi-location brands, converged routers collect internet access logs uniformly and transmit data to the cloud log platform in real time. After headquarters configures compliance policies on the cloud management platform, all store locations synchronize settings automatically without manual configuration at each site. Headquarters can view the log status of any branch anytime. New hotel sites are deployed in line with group standards upon opening, without extra compliance configuration work.
Whichever solution is adopted, AINOPOL devices hold special security product certifications from the Ministry of Public Security, satisfying public security filing and inspection criteria.
Retaining logs for 180 days is not a technical hurdle, but an architectural choice. Plan log retention alongside network construction to avoid extra costs for retrofitted equipment, storage and labor later. One Mengxiang gateway fulfills real-name authentication, 180-day log storage and security protection in one package. New hotels achieve compliance immediately upon launch, while legacy hotels can be renovated without service suspension. Compliance capability should be built into the network foundation, rather than patched on later.
For hotels, compliance is not just "passing inspections", but a standard part of daily operation. When calculating total risks including fines and brand damage, the value of proactive compliance is clear.
Penalties have already been issued, and Order No.176 offers no grace period. Instead of scrambling to remedy gaps after inspections, get compliant in one go.
Q: What specific log retention requirements does Ministerial Order No.176 impose on hotels?
A: Article 7 of Order No.176 explicitly requires inspection of "whether user registration information and internet access logs are recorded and retained in accordance with the law". Logs must be kept for no less than 180 days, with tamper-resistant, exportable and auditable data. As public internet service providers, hotels must meet this requirement.
Q: Why am I still penalized even if real-name authentication is implemented?
A: Real-name authentication verifies "who is accessing the internet", while log retention records "what websites are visited and when". Order No.176 treats these two as separate inspection items. Failing to store logs or retaining logs for fewer than 180 days will result in non-compliance, even with real-name authentication in place.
Q: Why is the 180-day retention period mandatory?
A: Article 21 of the Cybersecurity Law explicitly mandates "retaining relevant network logs for no less than six months". Order No.176 further reinforces this requirement. Six months equals approximately 180 days; insufficient retention duration constitutes compliance risk.