Skip to main content

Data protection laws and how Purple helps you comply

By Claudia Hill
13 December 2022
6 min read
Data protection laws and how Purple helps you comply
Interactive advisorGDPR, CCPA & LGPD guest WiFi compliance

Data privacy compliance and fine exposure advisor

Calculate statutory fine exposure, evaluate captive portal consent workflows, and estimate DSAR automation cost savings across global privacy regulations.

Organisation size & visitor parameters

50M
5M250M500M+
100,000 visitors
25%

Results in ~25,000 guest logins per month needing compliant consent.

Statutory framework enforcement rule:

Up to €20 million or 4% of global annual turnover, whichever is higher.

Maximum statutory penalty exposure
€20.0 million
Tier 2 major violation ceiling
Annual visitor consents managed
300,000
Records requiring verifiable audit trail

Mandatory GDPR (European Union & UK) compliance requirements

  • Unbundled, opt-in consent for marketing communications
  • 72-hour statutory data breach reporting to supervisory authorities
  • Automated Right to Erasure (Article 17) and Subject Access (Article 15)
  • Strict data minimisation on captive portal login forms
ISO 27001
ISO 27701
SOC 2 Type II
Certified B Corp

Ensure complete data privacy compliance across your venue WiFi

Speak with Purple's data compliance specialists to audit your captive portal workflows and automate DSAR requests.

Interactive Compliance EvaluatorISO 27001 & GDPR Ready

Guest WiFi Data Privacy & Regulatory Compliance Evaluator

Select your primary operating region and network scale to inspect mandatory captive portal consent rules, maximum non-compliance penalties, and how Purple automates lawful data collection.

Governing Legal Framework
EU GDPR & UK Data Protection Act 2018
Statutory Non-Compliance Exposure
Up to €20M / £17.5M or 4% of global annual turnover (whichever is higher)
Consent Mechanism Mandate
Explicit, unbundled opt-in with freely given consent

⚖️ Mandatory Captive Portal Requirements

  • Unambiguous, active opt-in consent for marketing (no pre-ticked boxes)
  • Granular consent unbundled from basic network terms and conditions
  • Mandatory 72-hour notification timeframe for personal data breaches
  • Designated Data Protection Officer (DPO) for large-scale systematic monitoring
Enforceable Visitor (Data Subject) Rights:
  • Right to access personal records within 30 days
  • Right to rectification and erasure (Right to be Forgotten)
  • Right to data portability in machine-readable format
  • Right to withdraw consent at any time without network denial

🛡️ How Purple Enforces Compliance

  • Granular splash page checkboxes separated from network access acceptance
  • Automated MyData self-service portal for instant subject access and erasure requests
  • Real-time CRM webhook synchronization to halt marketing upon consent withdrawal
  • ISO 27001 certified AWS infrastructure with full EU data residency guarantees
Multi-Site Commercial (6 - 50 Locations)
High: Aggregated visitor records require automated DSAR handling and CRM sync.
Privacy FeatureLegacy Captive PortalsPurple Cloud Compliance Engine
Consent CaptureBundled T&Cs, pre-ticked opt-in boxes (non-compliant)Unbundled, freely-given consent checkboxes
Right to Erasure (DSAR)Manual database queries taking weeksAutomated MyData self-service portal (instant)
CRM SynchronizationStatic CSV exports with orphaned opt-outsReal-time two-way webhooks & consent suppression
Security CertificationsUnverified local server storageISO 27001, ISO 9001 & SOC 2 Type II certified

Ensure 100% Guest WiFi Data Privacy Compliance

Deploy Purple's ISO 27001 certified captive portal with native GDPR, CCPA, and LGPD consent management across your venues.

What is data protection and data privacy?

The concept of the right to privacy emerged in 1948 when the Universal Declaration of Human Rights was adopted by the UN. This states that “no one shall be subjected to arbitrary interference with his privacy, family, home or correspondence”. By 1978, the first marketing email had been sent out to 400 recipients and in 1994, the first banner ad appeared on the internet. By the year 2000, many banks started offering online banking services. In 2006, Facebook was created and social media took off exponentially, becoming an integral part of our everyday lives. 

Currently, 137 out of 197 countries have put some level of legislation in place to secure the protection of data and privacy. Some of the biggest names on the planet have been subject to fines as a result of violations such as Google, Whatsapp, and Facebook, with one of the biggest ever data protection fines being awarded to Amazon for $877 million in 2021. 

In this blog, we'll examine three of the major data privacy laws in the world, the GDPR, CCPA, and LGPD. We'll give you a short summary of the law, what happens if you don't comply and how the Purple Platform can enable you to collect data from visitors to your venue compliantly. 

Europe: General Data Protection Regulation (GDPR)

What is GDPR?

Perhaps the most well-known data protection law in the world, the GDPR was created by the European Union and came into effect on the 25th of May 2018. The legislation imposes legal obligations on any organisation that gathers and holds data related to people in the EU and EU citizens, even if the organisation itself is not EU-based. 

The GDPR provides a framework for data controllers (and processors), through, seven principles, which include minimising how much data is collected and timeframes for storing data. It also imposes specific rules, such as the 72-hour reporting requirement for data breaches. 

The GDPR also clearly imposes rights on data subjects (individuals) with regard to the information an organisation collects about them, for example, the right to be informed about the data being processed. In some circumstances, the data subject may need to give unambiguous consent to process the data, such as opting into your marketing email list whereas there are other situations where data can be processed without consent (such as life-threatening situations or on public interest grounds).

What happens if you don't comply with the GDPR?

Fines for non-compliance are substantial. Less severe infringements could result in a fine of up to €10 million ($9.8m) or 2% of the firm's worldwide annual revenue from the preceding financial year. For more serious infringements, including going against the principles of the right to privacy and right to be forgotten, fines can be up to €20 million ($19.7) or 4% of the firm's worldwide annual revenue from the preceding financial year, whichever amount is higher. 

North America: California's California Consumer Privacy Act (CCPA)

What is the CCPA? 

The California Consumer Privacy Act of 2018 (CCPA) aims to give consumers more control over the data that businesses collect about them and includes new privacy rights for California consumers. These rights include the right to know what data is being collected about them, the right to delete it, the right to opt-out of the sale of their personal information, and the right to non-discrimination for exercising their CCPA rights

In order to comply with the CCPA, websites need to inform their users at the point of data collection about the personal information it collects and for what purposes. Websites should feature a “do not sell my personal information” link to opt-out of third-party data sales and should the consumer request the data you hold about them, this should be provided free of charge. 

What happens if you don't comply with the CCPA?

If your business is non-compliant with the CCPA, consumers can file a private right of action giving the business 30 days to put the violation right. The business then has to show that the “violation has been cured and no further violations will occur”. If the business fails this, the consumer has the right to file the right of action with the Attorney General. The Attorney General can take civil action and impose an injunction and a penalty of $2500 per violation. If the violation was deemed intentional then this could rise to $7500 per violation. This is considered to be per consumer, therefore if 1000 of your customers were affected, your business would be fined $ 7.5 million!

South America: Brazil's Lei Geral de Proteção de Dados (LGPD)

What is the LGPD?

The Lei Geral de Proteção de Dados (LGPD) came into effect in 2020 and affects any business or organisation that processes the personal data of people in Brazil, regardless of whether that is where the business or organisation is located. 

The LGPD specifies that you can only process personal data for legitimate, specific, and clearly communicated purposes. Similar to GDPR, the LGPD principles include transparency and data minimisation, in other words, tell your customers what data you are collecting, and what you will use it for, and only collect the data you need. Businesses are required to appoint a DPO (Data Protection Officer) in order to comply with the law. 

What happens if you don't comply with the LGPD?

If you fail to comply with the LGPD, you may face fines of up to 2% of your company's annual turnover, up to a maximum of 50 million Brazilian Reais, about €8 million or $ 9 million. There are other corrective actions for violators, including publicising the infringement and blocking or deleting the processing activities or personal data that caused the issue. This means the offending data controller could lose the entire associated email list and the database related to the incident could be suspended for up to 6 months. 

How the Purple Platform can help businesses collect and manage data compliantly with major data protection laws

Captive portal for visitor consent

Purple's customisable splash pages allow for links to terms and conditions at login as well as optional opt-in checkboxes for marketing materials and communications or an opt-out box for personal data sales for those that need to be compliant with CCPA.

As well as this, Purple's captive portal can ensure that customers who log in have agreed to the terms and conditions as well as the privacy policy.

Data Compliant Purple T&C's

MyData portal for complete data transparency

Through Purple's My Data Portal which can be found on the Purple website, data subjects can view the data that the business has collected about them through the Purple Portal completely free of charge and withdraw consent should they wish.

mydata portal on desktop 1

Automated WiFi marketing

If you're collecting customer contact data through the Purple Platform and a customer opts out of marketing communications then this would prevent you from emailing them through our automated WiFi marketing tools. Even if you've got an integration on the Purple Platform to an external CRM system, you can map the data there using Purple's built-in software in order to update your database with this information which keeps your database compliant.

logic flow 1

Frequently asked questions

How does the GDPR apply to guest WiFi networks?

The GDPR applies to any organization offering guest WiFi to EU or UK residents. Venues must obtain freely given, specific, informed, and unambiguous opt-in consent before collecting personal data such as names or emails for marketing. Pre-ticked boxes are prohibited, and terms must be separate from marketing consent.

What are the penalties for non-compliance with GDPR, CCPA, and LGPD?

GDPR fines reach up to €20 million or 4% of annual global turnover for major violations. The CCPA imposes statutory civil penalties up to ,500 per intentional violation per affected consumer. Brazil's LGPD penalizes up to 2% of Brazilian revenue (capped at RM) and allows regulatory suspension of customer databases.

How do captive portals ensure compliance with data protection regulations?

Compliant captive portals present unbundled terms and conditions at login, feature clear opt-in checkboxes for marketing, provide 'Do Not Sell' opt-outs for CCPA, and record verifiable digital consent timestamps. They also enforce data minimisation by only collecting necessary visitor credentials.

How does Purple automate Data Subject Access Requests (DSARs)?

Purple provides guests with the self-service MyData portal where visitors can view, export, or permanently erase their personal data without manual IT intervention. This satisfies the statutory 30-day fulfillment requirement under GDPR Article 15 and 17, and CCPA consumer deletion rights.

What is the difference between GDPR, CCPA, and LGPD requirements?

GDPR operates on an opt-in consent model requiring a lawful basis prior to data processing. CCPA operates primarily on an opt-out framework focusing on the right to prevent the sale of personal information. LGPD mirrors GDPR principles but uniquely requires a Data Protection Officer (DPO) regardless of company size.

How does Purple handle MAC address anonymisation and WiFi tracking data?

Purple anonymises and hashes raw hardware MAC addresses to protect visitor privacy while calculating footfall analytics. Personal identifiable information is only associated when a visitor explicitly authenticates and opts in through the captive portal.

What security certifications validate Purple's data protection architecture?

Purple is ISO 27001, ISO 27701 (Privacy Information Management), and SOC 2 Type II certified, and is a certified B Corporation. All visitor data is encrypted in transit and at rest using enterprise-grade AES-256 protocols.

Ready to get started?

Book a demo with one of our experts to see how Purple can help you achieve your business goals.

Speak to an expert
Data protection laws: global guide to guest WiFi compliance | Purple