Every time you fill in a form on a cafe's Wi-Fi login page, an exchange takes place: internet access for a quantity of personal data. Since Law Number 27 of 2022 on Personal Data Protection came fully into force, that exchange has a clear legal framework.
What follows is a summary from both sides: as the person whose data is collected, and as the party collecting it.
Note: this article is educational and is not legal advice. For how it applies to a specific situation, consult a competent legal adviser.
Two categories of personal data
The PDP Law separates personal data into two groups with different levels of protection.
| Category | Examples | Level of protection |
|---|---|---|
| General personal data | Full name, sex, nationality, religion, email address, phone number | Standard |
| Specific personal data | Health data, biometrics, genetics, criminal records, children's data, personal financial data | Stricter |
The distinction matters in the context of public Wi-Fi. A portal asking for a name and email sits in the first category. A portal asking for national identity details or financial information enters far more sensitive territory, and needs strong justification.
Your rights as a data subject
The law grants a set of rights you can exercise. The ones most relevant day to day:
- The right to be informed. You are entitled to know the controller's identity, the purpose of processing, and the retention period before handing over data.
- The right of access. You can request a copy of the personal data held about you.
- The right to rectification. Inaccurate data can be corrected on request.
- The right to erasure. You can request deletion of data no longer needed.
- The right to withdraw consent. Consent once given can be withdrawn at any time.
- The right to object. You can refuse processing for marketing purposes and automated decision-making.
Obligations of a public Wi-Fi operator
If you run a guest network that collects visitor data, you act as a data controller. The main obligations:
Have a lawful basis for processing
Consent is the most common basis in a guest Wi-Fi context. It must be given knowingly, be specific to each purpose, and must not be imposed as a hidden condition.
Give clear notice
The privacy policy must be reachable directly from the portal page, written in language a layperson understands, and explain what data is collected and what for.
Limit collection to what is needed
The data minimisation principle means collecting only what the stated purpose requires.
Apply adequate security
Encryption in storage and in transit, restricted staff access, and activity logging are a reasonable minimum standard.
Set a retention period
Data must not be kept forever. Decide on a period, state it in the policy, and delete regularly.
Prepare an incident procedure
If a data protection failure occurs, the controller is obliged to notify the relevant parties within the deadline set by the regulations.
Practical steps to protect yourself
Use a dedicated email address for sign-ups
Creating one separate address for free-service registrations keeps your main inbox clear of promotions, and limits the fallout if a leak occurs.
Fill in only the required fields
Many forms collect more than they need. Optional fields can be skipped without affecting the service.
Read the checkboxes rather than just clicking
Look for a separate marketing box and check whether it is pre-ticked. Consent that arrives already ticked does not meet the lawful standard.
Make use of randomised MAC addresses
Modern Android and iOS offer per-network MAC randomisation, which makes tracking across locations harder. It is on by default on most recent devices.
Review app permissions periodically
Apps requesting constant location access or your contact list without a clear reason are worth re-evaluating, regardless of which network you are on.
Signs of unreasonable data collection
- Asking for a national identity number for a service that does not need one.
- No privacy policy provided, or the link does not work.
- The marketing consent box arrives pre-ticked.
- No information about who the data controller is.
- Asking for the password to another service.
- No way to unsubscribe from the promotional messages sent.
Finding even one of these is reason enough to abandon the sign-up and use mobile data instead.
Understanding the roles: controller and processor
The law distinguishes two roles that determine who is responsible for what.
- The personal data controller decides the purpose and directs the processing. In a venue Wi-Fi context, the business owner is usually the controller.
- The personal data processor processes data on the controller's behalf. A captive portal platform provider is generally the processor.
This distinction matters because the controller remains responsible even when the technical processing is carried out by someone else. A written agreement with the platform provider setting limits on data use is therefore a sensible step, and one small businesses often skip.
A compliance checklist for small venues
| Aspect | Question to answer |
|---|---|
| Basis for processing | What is our lawful basis for collecting this? |
| Minimisation | Is every field genuinely necessary? |
| Notice | Can the privacy policy be opened from the portal? |
| Marketing consent | Is it separate and not pre-ticked? |
| Retention | How long is data kept, and who deletes it? |
| Internal access | Who on the team can see this data? |
| Processor | Is there a written agreement with the platform provider? |
| Data subject requests | Who handles them, and within what period? |
| Incidents | What is the first step if there is a leak? |
Answering these nine questions in writing, even on a single page, already puts your business well ahead of most comparable venues.
Daily habits that protect your data
- Use a password manager so every service has a different password.
- Turn on two-factor authentication for your main email first, since that account is the recovery key for the others.
- Review the list of apps connected to your Google or social media accounts every few months.
- Check whether your email address has appeared in any publicly known breach. If your data did leak, the steps to secure things and the routes for complaining are in the guide to reporting a personal data breach.
- Limit what you share on any online form, not only Wi-Fi portals.
Effective data protection is not the result of one big action, but the accumulation of small habits applied consistently.
Closing
The PDP Law shifts the balance towards the individual, but a law only works when its rights are used. Reading a form before filling it in, refusing excessive requests, and exercising the right to erasure are simple habits with real effect.
For venue operators, compliance is more than avoiding penalties. Transparent data practice is one of the most effective ways to build trust, capital that no marketing budget buys easily.
See also the guide to compliant Wi-Fi marketing and the 12 steps to public Wi-Fi safety.