Skip to main content

22,000 people agreed to community service for free WiFi

By Richard Ellor
10 July 2017
3 min read
22,000 people agreed to community service for free WiFi
Interactive Compliance Auditor

Guest WiFi terms & GDPR compliance advisor

Audit your captive portal terms length, consent structure, and user transparency against global privacy standards.

1,600 words (~8 min read)
260 (Purple micro-policy)1,600 (Legacy average)3,500+ (High friction)
35,000
2,00075,000150,000+

Enables guests to review collected data, update marketing preferences, or invoke GDPR Article 17 (Right to Erasure) without manual DPO tickets.

Privacy Compliance Score

35%/ 100

Audit Risk Detected

Blind Consent Risk

99.8%

Community service trap risk

Onboarding Completion

82%

~28,700 successful logins/mo

Annual DPO Workload

252h/ year

+218h saved with Profile Portal

Retail Malls & Shopping Centers – Compliance & Architecture Profile

GDPR / CCPA Marketing Opt-in & Footfall Analytics

Recommended Onboarding Architecture: Granular marketing opt-in with self-serve Profile Portal.

Key Audit Vulnerabilities to Address

  • 1Pre-ticked marketing boxes violate GDPR Article 7.
  • 2Terms exceeding 1,000 words cause 99.9% blind consent rates.
  • 3Lack of clear data controller identification on splash screens.
The Purple Benchmark: In Purple's landmark 2-week experiment, 22,000 users agreed to 1,000 hours of community service (including cleaning festival loos) because legacy terms averaged 1,600 words. Purple replaced legacy terms with a 260-word micro-policy, granular opt-in checkboxes, and a self-serve Profile Portal, establishing the gold standard for transparent guest WiFi onboarding.

Deploy 100% GDPR-compliant guest WiFi today

Simplify terms to 260 words, automate subject access requests, and give visitors complete transparency over marketing preferences with Purple.

Cleaning festival bathrooms, hugging stray cats and dogs, and scraping chewing gum off the streets are just some of the uninviting tasks people have agreed to in exchange for free WiFi. And we aren't just talking about a few hundred unfortunate individuals. Over 22,000 people have openly agreed to carry out 1,000 hours of community service after we added the spoof clause into our terms and conditions over a two-week period.

A "Community Service Clause" was added to our usual terms and stated: The user may be required, at Purple's discretion, to carry out 1,000 hours of community service. This may include the following:

  • Cleansing local parks of animal waste
  • Providing hugs to stray cats and dogs
  • Manually relieving sewer blockages
  • Cleaning portable restrooms at local festivals and events
  • Painting snail shells to brighten up their existence
  • Scraping chewing gum off the streets

Don't worry, we aren't going to round up these individuals and ask them to don their rubber gloves and repay the community debt. The real reason behind our experiment is to highlight the lack of consumer awareness when signing up to use free guest WiFi. All users were given the chance to flag up the questionable clause in return for a prize, but remarkably only one individual, which is 0.000045% of all WiFi users throughout the whole two weeks, managed to spot it.

Commenting on the results, Gavin Wheeldon, CEO of Purple, said: “WiFi users need to read terms when they sign up to access a network. What are they agreeing to, how much data are they sharing, and what license are they giving to providers? Our experiment shows it's all too easy to tick a box and consent to something unfair.”

We've unveiled the findings of our experiment to coincide with today's announcement that we are the first CCPA/CPRA compliant WiFi provider. The legislation will reshape the way organizations approach data privacy and allow end users to gain more access to the data collected about them. One of the headline rulings is the introduction of 'unambiguous consent' before users' personal or behavioral data can be used for marketing purposes. The results from our experiment clearly support the inclusion of 'unambiguous consent' in modern privacy regulations.

In response to CCPA/CPRA and the results we obtained in our experiment, we have modified our privacy policy so it is clearer, simpler and shorter. In fact, our privacy policy is now only 260 words long rather than 1600, which means people should be more open to reviewing the terms before clicking 'accept'. Our access journey has also been tweaked so that users have more clarity around how their data will be used, for what purposes, and by whom.

Gavin Wheeldon says: "We welcome the strengthening of data protection laws across Europe that CCPA/CPRA will bring. Not only will it give WiFi end users more control over how their personal data is being used by companies, it will also raise the level of trust in the digital economy."

Another new feature which has been announced today is our brand-new Profile Portal, which gives end users complete transparency of all the data collected about them and also allows them to modify their marketing preferences.

Gavin adds: "Purple's Profile Portal means that all end users worldwide have the comfort of knowing they can control how their data is being used. And if they're happy to hug a few stray dogs at the same time it's a win-win."

Read next: Top 10 Tips for CCPA/CPRA

Frequently asked questions

What was Purple's 22,000-user community service WiFi experiment?

In a landmark two-week experiment to highlight blind consent on public networks, Purple added a humorous 'Community Service Clause' to its guest WiFi terms and conditions. Over 22,000 users consented to perform 1,000 hours of community service (such as cleaning festival toilets, hugging stray animals, and scraping chewing gum from streets) to access free WiFi, with only a single person spotting the clause.

Why do users blindly accept guest WiFi terms and conditions?

Traditional captive portal terms and conditions average between 1,600 and 3,000 words of complex legalese, taking an average of 8 to 15 minutes to read. Because users desire immediate internet access, over 99.9% accept terms without reading them, exposing themselves to unknown data sharing and tracking permissions.

What does GDPR require for guest WiFi captive portal consent?

Under GDPR (Article 7), consent for personal data processing and marketing must be freely given, specific, informed, and unambiguous. Captive portals cannot bundle marketing opt-ins into the basic terms required for internet access, cannot use pre-ticked checkboxes, and must clearly identify the data controller and data usage purposes.

How did Purple redesign its privacy policy for GDPR compliance?

Following the experiment and the introduction of GDPR, Purple reduced its guest WiFi privacy policy from 1,600 words down to a concise, plain-English 260-word micro-policy. This concise format allows visitors to understand data collection practices in under 70 seconds before connecting.

What is Purple's self-serve Profile Portal?

The Purple Profile Portal is a dedicated privacy management dashboard that gives WiFi end users complete visibility over the personal and behavioural data collected during venue visits. Users can view their stored profile, modify marketing opt-in preferences, or invoke their GDPR Article 17 right to erasure at any time.

How can venue operators ensure their captive portals remain privacy-compliant?

Venue operators must unbundle marketing consent from network access terms, replace multi-page legalese with concise transparent summaries, maintain timestamped consent audit logs, and provide self-service preference management to eliminate manual Subject Access Request (SAR) overhead.

Ready to get started?

Book a demo with one of our experts to see how Purple can help you achieve your business goals.

Speak to an expert