Offering Wi-Fi to visitors looks like a simple amenity. Technically it is. In terms of responsibility, there are a few things that rarely get discussed until something goes wrong.
This article summarises what is relevant to a small business owner. It is a general explanation, not legal advice, for a specific case, consult a legal adviser.
The Personal Data Protection Law
Law Number 27 of 2022 applies to anyone processing personal data, small businesses included. The moment your captive portal asks for a name, an email, or a phone number, you become a data controller.
The obligations attaching to that role:
Give information before data is taken
Visitors are entitled to know who is collecting, what for, how long it is kept, and who it is shared with. This is what belongs on the privacy policy page linked from the portal.
Obtain valid consent
Consent must be specific and given knowingly. A pre-ticked box does not qualify. Consent to use the service must also be kept separate from consent to receive marketing.
Collect only what you need
The data minimisation principle. If your purpose is simply to grant internet access, a national identity number is plainly unnecessary. Every additional field you ask for adds responsibility without adding benefit.
Provide a way to exercise rights
Visitors are entitled to request a copy of their data, correct it, delete it, and withdraw consent. Provide one contact address that is genuinely read for requests of this kind.
Delete once the retention period ends
Set how long data is kept, write it into the policy, then apply it. Stating a six-month retention while never deleting anything actively worsens your position.
A portal that meets the requirements
A simple comparison between a problematic portal and a reasonable one:
| Aspect | Problematic | Reasonable |
|---|---|---|
| Data requested | Name, ID number, address, date of birth | First name and email, or no data at all |
| Consent | One box covering everything | Separate: service use and marketing |
| Privacy policy | Absent, or a dead link | Openable before filling anything in |
| Checkboxes | Pre-ticked | Empty, ticked by the visitor |
| How to opt out | Not mentioned | In the policy and in every message |
Portal design and how it works are covered separately in the guide to captive portals.
On session records
Recording when a device connected and for how long is common practice, and useful if an enquiry ever arises.
What needs understanding: those records themselves contain personal data. MAC addresses and IP addresses count. So session records fall under the same rules, a purpose, a retention period, restricted access.
Reasonable practice for a small business:
- Record start time, end time, and a device identifier
- Do not store traffic content or lists of sites visited
- Set a sensible retention period, say three to six months
- Limit who can read them
- Mention their existence in the privacy policy
Responsibility for how it is used
The internet connection is registered in your business's name. If unlawful activity takes place over that network, any enquiry points at your address first.
A few things help clarify your position:
- Terms of use shown before access is granted. Stating that the network must not be used for unlawful activity.
- Session records. These help show the access was used by many people, not only you.
- Basic filtering. Blocking clearly problematic categories of site through DNS. How that works is explained in the guide to public DNS.
None of these grants immunity. What they provide is evidence that you managed the facility with reasonable care.
The duty to keep data secure
If you store visitor data, you are obliged to protect it. For a small business, that does not mean an elaborate system. A few basics close off most of the risk:
- A strong admin password that is not shared with all staff
- A guest network kept separate from the operational network, see the guide to separating networks
- Network device firmware kept updated
- Access to the visitor database limited to those who genuinely need it
- Backups stored separately
The PDP Law also sets out an obligation to notify in the event of a data breach. If your visitor data leaks, there is a duty to inform those affected and the competent authority within a set deadline.
The simplest option
There is one route that avoids most of the obligations above: do not collect any data at all.
Guest Wi-Fi with a password printed on the receipt, no portal and no form, does not make you a personal data controller. Nothing is stored, nothing needs protecting, nothing needs deleting.
The downside is obvious: you lose a channel for communicating with customers. For some businesses that trade is worth it. For those genuinely building a customer base, well-organised data collection makes more sense, discussed in the guide to Wi-Fi marketing.
Ringkasnya
| What you do | Obligations that arise |
|---|---|
| Open Wi-Fi with no portal | Practically no data obligations |
| Portal with no data collection | Terms of use are enough |
| Portal collecting an email | Privacy policy, consent, retention, data subject rights |
| Portal plus sending promotions | All of the above, plus separate marketing consent and an opt-out |
| Keeping session records | Retention period, restricted access, mentioned in the policy |
The more you collect, the more there is to manage. That is not a reason to collect nothing, but a reason to collect deliberately.