27 May 2026 WeefyBox Team 3 min read
GDPR and captive portals: what UK/EU venues need to know
Guest WiFi collects real personal data — email, phone, device identifiers. Here's what UK GDPR and EU GDPR actually require of a venue running a captive portal.
If your venue's guest WiFi asks for a name, email or phone number before granting access, you are processing personal data under UK GDPR and/or EU GDPR — the same rules that apply to any other customer database. This isn't a reason to avoid guest WiFi marketing; it's a reason to do it properly. Here's what actually matters.
You are (probably) the data controller
For most venues, you — the café, restaurant, hotel or bar — are the data controller for your guests' data, even though a platform like WeefyBox is processing it on your behalf as a data processor. That distinction matters: you're the one who needs a lawful basis for collecting the data, and you're the one guests will contact if they want it deleted.
Consent has to be real, per channel, and never pre-ticked
"Getting online" and "agreeing to marketing" are two different things, and treating them as one is a common — and risky — mistake. A captive portal should:
- Separate access (getting online) from marketing consent (being emailed or texted later).
- Never pre-check a marketing consent box — a guest should have to actively opt in.
- Record consent per channel (email vs SMS) — someone who's happy to get an email might not want texts.
- Keep an auditable record of exactly what was asked and what was answered, not just "some" consent captured at some point.
The right to erasure doesn't mean "delete everything, always"
Article 17(3) GDPR permits retaining data needed for a legal obligation or a legitimate business record even after someone asks to be forgotten. In practice, that usually means: anonymize what identifies the person (name, email, phone), but you can typically keep aggregate records — visit counts, consent history — that don't point back at an identifiable individual, precisely because that consent record is what proves you honoured their original preferences.
Device identifiers are personal data too
A MAC address or a device cookie can be personal data if it can be linked back to an individual — which, on a system tracking repeat visits, it usually can. Any vendor's WiFi marketing platform should treat these with the same care as an email address, including deleting device-linking data (not just the guest's name) when a full erasure request comes in.
Practical checklist for a UK/EU venue
- Have a Privacy Policy that specifically describes what your captive portal collects (not just a generic "we may collect data" clause).
- Have a Data Processing Agreement in place with whichever platform runs your portal — it should name what's processed, for what purpose, and where it's stored.
- Make sure marketing consent is genuinely separable from network access — nobody should be forced to accept marketing texts just to check their email.
- Know how to handle an erasure request end-to-end, including what happens to device identifiers, not just the obvious name/email fields.
None of this is exotic — it's the same discipline any customer database needs. The only thing that's changed is that guest WiFi has quietly become one of the biggest personal-data collection points many hospitality venues run, often without anyone treating it that way.