A cafe owner asks for customers' WhatsApp numbers to send promotions. A boarding house records residents' names and addresses. A Wi-Fi portal collects an email address before granting access.
All three feel entirely ordinary. All three also make the person doing it a personal data controller under Law No. 27 of 2022, with obligations attaching from the first record collected.
The good news is that the obligations are not heavy. What makes them awkward is that nearly all of them need to be in place before you start collecting, not afterwards.
Note. This is an educational summary, not legal advice. How it applies to a particular situation depends on many things that cannot be assessed from a distance. For business decisions, consult a competent legal adviser.
What counts as personal data
Broader than most people assume. Anything that can identify a person, on its own or combined with other data.
| Commonly collected by small businesses | Counts? |
|---|---|
| Name and phone number | Yes |
| Email address | Yes |
| Photographs or camera footage | Yes |
| Device IP address and MAC address | Yes |
| Visit history linked to a name | Yes |
| Daily visitor counts | No, if not tied to a specific person |
The fourth row often comes as a surprise. A Wi-Fi portal that logs device MAC addresses is already collecting personal data, even if it never asks for a name.
Five basic obligations
Have a lawful ground
Consent is the most common one for small businesses, but not the only one. Performing a contract and meeting a legal obligation are lawful grounds too. What is not allowed is collecting with no ground at all.
Give clear notice
Who you are, what data you take, what for, how long you keep it, and where people can ask. These five fit into one short paragraph.
Take only what you need
Every extra field adds risk and reduces the number of people willing to fill the form in. A cafe has no lawful reason to ask for a national identity number.
Keep it secure
Customer data does not belong in an open file anyone can read. Limit who has access, and revoke it when someone leaves.
Delete it once it is no longer needed
Set a retention period from the start, and actually apply it. A policy stating twenty-four months while never deleting anything becomes evidence against you rather than for you.
Valid consent
This is where things go wrong most often, and the mistake is nearly always the same.
A single checkbox reading "I agree to the terms and conditions" is not enough to send promotions. Consent must be specific to each distinct purpose.
| Purpose | Needs its own box? |
|---|---|
| Granting Wi-Fi access | One is enough, for the service itself |
| Contacting about an order | Attaches to the contract |
| Sending promotions | Yes, separately |
| Sharing with a third party | Yes, separately, naming who |
Three further conditions attach to consent: it must not be pre-ticked, it must be as easy to withdraw as it was to give, and refusing must not make the main service inaccessible.
That last condition means a visitor who declines promotions must still be able to use your Wi-Fi.
For anyone running a Wi-Fi portal
How to structure the terms page itself, which clauses help and which do not, is covered in the guide to guest Wi-Fi terms and conditions.
A portal that collects data is the collection point most often overlooked, because it feels like a purely technical matter.
- Provide a privacy policy link that actually opens from the portal page, not a dead link caused by the portal blocking outbound access.
- Separate the marketing consent box from the terms-of-use box.
- State how long the data is kept.
- Consider collecting nothing at all. A portal that shows terms and a continue button removes every one of these obligations at once.
That last option deserves more serious consideration than it usually gets. Portal design and the alternatives are discussed in the guide to Wi-Fi marketing for small businesses and the guide to setting up Wi-Fi vouchers.
Rights you need an answer ready for
Your customers hold rights they can exercise at any time. Preparing the answer in advance is far easier than doing it when the first request arrives:
- To know what data you hold about them.
- To correct data that is wrong.
- To delete data, so long as no other obligation requires keeping it.
- To withdraw consent, including stopping promotions.
Provide one clear channel for requests of this kind, a contact form or a number that is genuinely monitored. These rights seen from the user's side are covered in the guide to the PDP Law.
If a breach happens
Three steps, in order:
- Stop the cause. Revoke access, change passwords, close the hole.
- Record what happened: when, what data, how many people affected, and what has already been done.
- Notify the people affected and the competent authority in line with applicable rules.
Covering up a breach almost always makes things worse. Beyond adding a further violation, it damages the trust that is a small business's largest asset.
What you can do this week
- List every place you collect data: the Wi-Fi portal, the guest book, the cameras, order forms, messaging groups.
- For each one, write down the purpose and how long it is kept.
- Remove any field you do not actually use.
- Draft one paragraph of notice and put it at the point of collection.
- Decide who has access, and revoke anyone who no longer needs it.
For security cameras, the more specific requirements are covered separately in the guide to CCTV rules and privacy.
Frequently asked questions
Do personal data rules apply to small businesses too?
Yes. The law does not distinguish by business size. What differs is how much data you collect and how sensitive it is, and that determines the level of security effort reasonably expected of you.
Is a single "I agree" checkbox enough?
Not always. Consent must be specific to each purpose. Agreeing to terms of use is not the same as agreeing to receive promotions, and each needs its own box that is not ticked by default.
How long can customer data be kept?
As long as it is still needed for the stated purpose, or as long as another rule such as a bookkeeping obligation requires. After that it should be deleted or anonymised. Keeping it indefinitely adds risk without adding benefit.