Offering Wi-Fi to visitors looks like a simple amenity. Technically it is. In terms of responsibility, there are a few things that rarely get discussed until something goes wrong.

This article summarises what is relevant to a small business owner. It is a general explanation, not legal advice, for a specific case, consult a legal adviser.

The Personal Data Protection Law

Law Number 27 of 2022 applies to anyone processing personal data, small businesses included. The moment your captive portal asks for a name, an email, or a phone number, you become a data controller.

The obligations attaching to that role:

Give information before data is taken

Visitors are entitled to know who is collecting, what for, how long it is kept, and who it is shared with. This is what belongs on the privacy policy page linked from the portal.

Obtain valid consent

Consent must be specific and given knowingly. A pre-ticked box does not qualify. Consent to use the service must also be kept separate from consent to receive marketing.

Collect only what you need

The data minimisation principle. If your purpose is simply to grant internet access, a national identity number is plainly unnecessary. Every additional field you ask for adds responsibility without adding benefit.

Provide a way to exercise rights

Visitors are entitled to request a copy of their data, correct it, delete it, and withdraw consent. Provide one contact address that is genuinely read for requests of this kind.

Delete once the retention period ends

Set how long data is kept, write it into the policy, then apply it. Stating a six-month retention while never deleting anything actively worsens your position.

A portal that meets the requirements

A simple comparison between a problematic portal and a reasonable one:

AspectProblematicReasonable
Data requestedName, ID number, address, date of birthFirst name and email, or no data at all
ConsentOne box covering everythingSeparate: service use and marketing
Privacy policyAbsent, or a dead linkOpenable before filling anything in
CheckboxesPre-tickedEmpty, ticked by the visitor
How to opt outNot mentionedIn the policy and in every message

Portal design and how it works are covered separately in the guide to captive portals.

On session records

Recording when a device connected and for how long is common practice, and useful if an enquiry ever arises.

What needs understanding: those records themselves contain personal data. MAC addresses and IP addresses count. So session records fall under the same rules, a purpose, a retention period, restricted access.

Reasonable practice for a small business:

  • Record start time, end time, and a device identifier
  • Do not store traffic content or lists of sites visited
  • Set a sensible retention period, say three to six months
  • Limit who can read them
  • Mention their existence in the privacy policy

Responsibility for how it is used

The internet connection is registered in your business's name. If unlawful activity takes place over that network, any enquiry points at your address first.

A few things help clarify your position:

  • Terms of use shown before access is granted. Stating that the network must not be used for unlawful activity.
  • Session records. These help show the access was used by many people, not only you.
  • Basic filtering. Blocking clearly problematic categories of site through DNS. How that works is explained in the guide to public DNS.

None of these grants immunity. What they provide is evidence that you managed the facility with reasonable care.

The duty to keep data secure

If you store visitor data, you are obliged to protect it. For a small business, that does not mean an elaborate system. A few basics close off most of the risk:

  • A strong admin password that is not shared with all staff
  • A guest network kept separate from the operational network, see the guide to separating networks
  • Network device firmware kept updated
  • Access to the visitor database limited to those who genuinely need it
  • Backups stored separately

The PDP Law also sets out an obligation to notify in the event of a data breach. If your visitor data leaks, there is a duty to inform those affected and the competent authority within a set deadline.

The simplest option

There is one route that avoids most of the obligations above: do not collect any data at all.

Guest Wi-Fi with a password printed on the receipt, no portal and no form, does not make you a personal data controller. Nothing is stored, nothing needs protecting, nothing needs deleting.

The downside is obvious: you lose a channel for communicating with customers. For some businesses that trade is worth it. For those genuinely building a customer base, well-organised data collection makes more sense, discussed in the guide to Wi-Fi marketing.

Ringkasnya

What you doObligations that arise
Open Wi-Fi with no portalPractically no data obligations
Portal with no data collectionTerms of use are enough
Portal collecting an emailPrivacy policy, consent, retention, data subject rights
Portal plus sending promotionsAll of the above, plus separate marketing consent and an opt-out
Keeping session recordsRetention period, restricted access, mentioned in the policy

The more you collect, the more there is to manage. That is not a reason to collect nothing, but a reason to collect deliberately.