The phone in a visitor's pocket isn't quiet. While Wi-Fi is on, it keeps sending small requests looking for networks it has known before, even when connected to nothing. Each request carries the phone's hardware address, known as its MAC address.
Some business routers and access points can record those signals. The result is sold as analytics: how many people walk past the shop, how many come in, how long they stay, and how many return next week. It sounds like ordinary statistics. The important question is when those statistics become personal data.
Two ways businesses count through Wi-Fi
Passive detection. Access points record probe signals from every phone nearby, including those that never connect. Visitors press nothing and usually don't know they're being counted. This is the form that most needs thinking through from a rules perspective.
Through guest Wi-Fi connections. Visitors connect, often through a login page, and the system records when they arrive and leave. Here there's a moment to inform and ask for consent, which makes this form much easier to do properly.
When it becomes personal data
A MAC address alone is just a string of numbers. But it's tied to one device, and that device almost always belongs to one person. Once the system is used to recognise the same device from visit to visit, what's being counted is no longer "people" but "this person, who comes every Tuesday afternoon".
The line gets sharper when that data is combined with other things: a phone number from the login page, camera footage, or till transactions. Combinations like that produce a profile of someone's habits. In Indonesia, processing of this kind falls under the personal data protection law, outlined in personal data security and the PDP law.
A safe way to think about it: if your system can answer "has this device been here before", treat the data as personal data.
Randomised MACs change the count
Phone makers noticed this problem long ago. Modern phones use randomised MAC addresses: when searching for networks they use a changing fake address, and for each network they join they often use a separate one.
For businesses this has two consequences:
- Passive detection figures become rough. One person can be counted several times, and repeat visitors are hard to recognise. The figures are still useful for busy hours and weekly trends, not for exact headcounts.
- Recognition shifts to the login page. Because passive signals are hard to follow, analytics vendors tend to push visitors to log in with a phone number or social account. That makes the data more clearly personal, not less.
Randomised MACs don't free a business from its obligations. They only make the passive form less accurate. When a business chooses another way to recognise people, the rules follow.
The principles that apply
Without going into article numbers, the personal data protection law rests on a few principles that translate easily into practice:
- A clear purpose. Decide first what the data is for: staffing busy hours, judging a promotion, or sending offers. Data collected for one purpose must not quietly be used for another.
- Notice. Visitors have a right to know their device is being counted, who processes it, and why. Small print in terms nobody reads isn't the same as telling them.
- A lawful basis. For rough counting that's summarised quickly, a clear notice is often a reasonable basis. For recognising repeat visitors, building profiles, or sending marketing, ask for explicit consent, not a pre-ticked box.
- Only what's needed. If all you need is people per hour, there's no reason to keep MAC addresses for months.
- Retention limits and deletion. Set how long raw data is kept, then delete or summarise it. Visitors who ask for their data to be deleted must be able to get that.
The same principles applied to customer data generally are covered in rules for collecting customer data.
A tidy setup for small businesses
Most shops, cafés, and minimarkets only need simple answers: when is it busy, and did this week's promotion bring people in. This setup answers that without keeping more than necessary:
- Turn MAC addresses into summary counts from the start. Many systems can store only counts per hour rather than a list of devices. If that option exists, use it.
- If you must keep an identifier, obscure it and limit its life. A re-scrambled identifier deleted within days carries far less risk than a list of real MACs piling up for a year.
- Put up a notice where people see it, at the entrance and on the Wi-Fi login page, in plain language: what's counted, why, how long it's kept, and who to contact.
- Separate marketing consent. Joining the Wi-Fi isn't agreeing to receive promotions. The right approach is covered in Wi-Fi marketing for small businesses, and the page wording in guest Wi-Fi terms and conditions.
If you use an analytics vendor
Many businesses don't process the data themselves. Analytics comes bundled with equipment or a cloud service from a vendor. Responsibility towards visitors stays with the business owner, so ask a few things before switching it on:
- Where the data is stored, and for how long.
- Whether the vendor uses data from your shop for its own purposes, such as combining it with data from elsewhere to sell as market reports.
- Whether there's a setting to keep summaries only and delete raw data.
- What happens in a breach, and who notifies whom. The reporting steps are in reporting a personal data breach.
If the answers are vague, switch the feature off. Losing a busy-hours chart is far cheaper than dealing with a leak of visitor data.
Don't combine quietly
The biggest temptation comes when Wi-Fi data sits in one place and camera footage in another. Linking them, such as matching devices to faces at the till, turns a counting tool into a surveillance tool. The rules for cameras themselves are in CCTV rules and privacy, and a combination like that demands far more serious thought than a sticker on the door.
A good question to ask whenever you want to add something: would visitors, if told honestly, find this reasonable? If the answer is uncertain, don't do it.
Frequently asked questions
Is a MAC address personal data?
It can be. On its own it's just a string of numbers, but once it's used to recognise the same device day after day, or combined with a phone number from a login page, it points to one person. From that point, treat it as personal data.
Why do Wi-Fi visitor counts often not match reality?
Because modern phones use randomised MAC addresses that keep changing, one person can be counted several times. Phones with Wi-Fi switched off aren't counted at all. The figures suit trends, not headcounts.
Is a notice at the entrance enough?
For rough counting where the data is summarised and discarded quickly, a clear notice is often a reasonable basis. For recognising repeat visitors or combining with other data, ask for explicit consent, for example through the Wi-Fi login page.