Guides · Compliance

Guest WiFi and the law. Five foundations for clearer consent.

UK GDPR and PECR can be difficult to untangle. These five practical foundations help a venue build a clearer sign-in and consent process.

6 minute read · Updated September 2026

Why venue owners worry about this

Guest WiFi consent can feel complicated, especially when a supplier describes a portal as if it makes the whole venue compliant. A sign-in page is only one part of the process.

The practical starting point is less dramatic: build the consent choice clearly, document the organisations involved and review how the list is used. This is general guidance rather than legal advice, and the venue should check its own circumstances and current ICO guidance on electronic mail marketing.

The two sets of rules, in one minute

Two pieces of law matter here, and they do different jobs.

UK GDPR governs personal data: collecting it, storing it, and being able to show why you have it. An email address is personal data even without a name attached, so the moment your WiFi keeps one, GDPR applies.

PECR governs electronic marketing: who you are allowed to email or text, and what every message must include. It covers the practical question owners care about: "am I allowed to send offers to this list?"

For many consumer email campaigns, the practical starting point is valid consent that names the sender and the communication method, together with a record of who consented, when and how. PECR also contains limited soft-opt-in rules, so the venue must decide which rule and UK GDPR lawful basis apply to its campaign.

Five foundations for a clear consent workflow

Guest WiFi consent checklist: an unticked box, plain words, a privacy link, a working marketing opt-out, and a timestamped consent record
The five practical parts of a consent-first portal. Swipe across the diagram on a phone.

1. An unticked box. The guest chooses to opt in. A pre-ticked box, or a portal where connecting automatically joins you to the list, is not consent. This failure is straightforward to avoid.

2. Plain words next to the box. "Send me the occasional offer from The Tinker's Arms" beats three paragraphs of legal mist. The guest should know who will email them and roughly how often, in the time it takes to read one line.

3. A link to your privacy notice. One short page saying what you collect, why, where it lives and how to be removed. If you have a website you almost certainly have one already; the portal just needs to point at it.

4. A working way to unsubscribe from every marketing email. Make it easy to opt out, and test the unsubscribe route in your mailing tool before sending. Consented portal contacts can be exported as a CSV today; a direct Mailchimp or Brevo connector can be built and acceptance-tested at customer go-live on request.

5. A timestamped consent record. Our portal records the email, consent outcome and latest matching sign-up time. It is an operational record, not an immutable audit-event ledger, so a venue with formal evidential requirements should raise those during scoping.

Those are five practical foundations, not a claim that a page makes the whole organisation compliant. The venue remains responsible for what it sends, how long it keeps the list and how it handles people’s rights.

Who controls the data (read this before signing anything)

The venue normally decides why opted-in addresses are collected and how they are used, making it the data controller for that activity. A supplier processing those records only on the venue's documented instructions acts as its processor. The roles and responsibilities should be recorded in the contract and data-processing agreement.

Portability is also a commercial question. Before signing, ask what can be exported, in which format, what happens to new collection at cancellation and how individual rights requests will be handled. Do not assume the word “ownership” answers those questions.

Our current portal provides a protected bulk CSV of opted-in records and a two-step erasure tool for an email address. It does not have a one-click single-person export, correction or portability tool, so those requests follow the agreed manual process. See the ICO's controller and processor guidance for the legal distinction.

The common mistakes, so you can spot them

Common failures include pre-ticked boxes, adding every connected guest to a mailing list, using bought addresses as if they were consented, emailing people who only asked for WiFi access, and keeping no record of the choice.

Ask the supplier to correct the consent design and document the controller, processor and export terms before proceeding.

What about the browsing side?

A common question is whether a venue is responsible for what guests do on its WiFi. Sensible practice is family-friendly content filtering on the guest network and keeping guests separated from your tills and business systems. What a portal does not do is watch what people browse. A guest network may record connection events without identifying every guest; it is not a view into anyone's phone.

Questions venue owners ask

Do I need a cookie banner on the portal?

The current Net Intellect portal does not use client-side storage, so that portal does not introduce a cookie-consent banner of its own. The venue must still assess its wider website, analytics, advertising tools and other technologies. Under PECR, non-essential cookies and similar storage or access technologies generally need consent; strictly necessary uses are treated differently.

How long can I keep the list?

UK GDPR does not set one universal retention period. The venue should identify the purpose and lawful basis, choose and document a period it can justify, review it, and erase or anonymise records that are no longer needed. The ICO's storage-limitation guidance explains the principle.

Someone asked to be deleted. What now?

A deletion request goes further than an unsubscribe. The venue should stop marketing, locate the relevant records across the portal and mailing tool, apply any relevant exemption or suppression requirement, and respond within the applicable time limit. Record the request and the action taken rather than assuming one deletion button covers every system.

Is the free WiFi at the big chains doing all this?

Large operators use different systems and legal bases, so their public sign-in flow is not a reliable template for an independent venue. Use the venue's own purposes, suppliers and marketing plans to set the process.

The short version

A sound Guest WiFi consent workflow starts with an unticked box, plain words, a privacy link, an unsubscribe link and a useful consent record. Make sure your agreement says the venue is the controller, the supplier is the processor and the opted-in list stays portable. Then keep reviewing how you use and retain it.

We build Guest WiFi portals with those tools included across Worcester and the Three Counties. A free survey can identify which technical or consent elements need to be added.

From consent to commissioning

Put the guest journey and data terms in writing.

Explain how guests connect now and what the venue wants to do with opted-in addresses. We will set out the technical scope, roles and readiness checks.

Discuss the Guest WiFi route
  1. 01Explain the current guest journeyHow people connect and what the venue wants to do.
  2. 02Set out consent and responsibilitiesOpt-in, privacy, export and processor terms.
  3. 03Review the commissioning scopeTechnical and data checks agreed before go-live.