CCPA/CPRA data retention for shared WiFi operators: how long you can keep guest login data and network logs
A practical US compliance guide for DPOs, network architects and venue operators running shared WiFi. It separates CCPA/CPRA storage-limitation decisions from conditional retention obligations, then turns controller-processor analysis into a retention schedule, CCPA service provider agreement checklist and erasure workflow.
Listen to this guide
View podcast transcript
Part of our core series: WiFi Marketing Guide →
- What is a defensible WiFi data-retention policy?
- Why is shared WiFi a different compliance problem?
- How should you classify the 5 WiFi data categories?
- What retention schedule can you adopt?
- Does the IPA require a shared WiFi operator to retain logs for 12 months?
- What must an Article 28 tenant agreement contain?
- How should you handle an erasure request?
- How does this work in real venues?
- Hospitality scenario: a hotel with guest access and tenant staff access
- Retail scenario: a shopping destination on one public address
- Events scenario: a conference venue with sponsor-owned audiences
- What should you do next?
- Frequently asked questions
- How long can I keep guest WiFi login data under CCPA/CPRA?
- Does the UK Investigatory Powers Act require 12 months of WiFi connection records?
- Am I controller or processor for a tenant’s employees on Staff WiFi?
- What is the right retention period for IP-address logs on a shared WiFi network?
- What should I do with an erasure request when I have a legal duty to retain traffic data?
- Do I need a DPA with every tenant organization?
- Can I keep marketing history until a guest withdraws consent?
- References

Under the CCPA/CPRA, keep identifiable guest WiFi login data and network logs only for the documented purpose and no longer. Most operational security logs may justify a short, tested period, not a universal rule. A 12-month period applies only where an applicable data retention notice requires specified data to be kept.1 7 9
What is a defensible WiFi data-retention policy?
A defensible policy links each data category to one purpose, one accountable party, one lawful basis, one retention period and one deletion event. That is the operational expression of data minimization principles: personal data must not remain identifiable for longer than necessary. The FTC and state attorneys general do not prescribe fixed periods. You must justify the period, document it, review it and erase or anonymize the data when it is no longer needed.1
Legal note. This is technical compliance guidance, not formal legal advice. Ask qualified counsel to validate your estate model, tenant contracts and any regulatory notice before relying on a retention schedule.
Why is shared WiFi a different compliance problem?
Multi-Tenant WiFi creates layers that a single-site guest network does not. You may operate a shared access layer for residents, members, guests and visitors, while providing a Staff WiFi service to a tenant employer. For your own purposes, such as network security, service assurance and billing dispute management, you may be a controller. For employee authentication processed only on the tenant’s documented instructions, you may be a processor. The label in a commercial agreement does not decide the issue.
The FTC and state attorneys general say role follows the specific processing activity. The party deciding why data is collected, the lawful basis, the data categories, recipients, privacy information, rights handling or retention is likely to be controller. A processor can choose technical methods, security controls and deletion mechanics without becoming controller, so long as it does not make the overarching decisions. The same dataset may therefore be separated by purpose and role. If both parties jointly determine purposes and means, use a joint-controller arrangement rather than treating the relationship as a simple processor service.4
| Shared WiFi activity | Likely role question | Practical control |
|---|---|---|
| Guest splash-page authentication for the operator’s own network | Does the operator decide collection, notice and retention? | Record the operator as controller for that purpose. |
| Tenant employee Staff WiFi authentication | Does the tenant decide the population, access purpose and retention? | Use service provider terms if the operator follows tenant instructions. |
| Security investigation across the shared estate | Does the operator need evidence to protect its own system? | Keep a separate controller-purpose log with restricted access. |
| Tenant-led engagement campaign | Does the tenant select audience and message purpose? | Prevent reuse for operator marketing without a separate basis. |
This analysis is particularly important for Hospitality, Retail, Healthcare and Transport estates, where a shared network can serve several independent businesses in the same building.
How should you classify the 5 WiFi data categories?
Connection metadata includes the IP address assigned, source MAC address, session start and end times, bytes transferred, DHCP lease records and RADIUS accounting. On a named-login service, these fields will commonly be personal data because they can be linked to an individual. Keep the fields required for the defined security and troubleshooting purpose. A suggested 30 to 90 day operational window is a starting policy, not a statutory safe harbor. Your incident-detection time, threat model and ability to investigate should determine the approved period.1 6
Guest authentication data includes email address, name, phone number and authentication identifier. If you collect it solely to admit a person to Guest WiFi, the access purpose ends with the session. Retain a short, documented dispute or fraud tail only where you can explain it. If you also collect a conscious-choice marketing opt-in, separate the marketing record from access data. Consent can be withdrawn, while electronic marketing also has its own rules. On withdrawal or objection, stop marketing and retain only the minimal suppression information needed to honor the choice.2 6
Location and presence data needs a hard distinction between raw identifiable trails and aggregate outputs. A token is not anonymous if you can relink it to a login. The FTC and state attorneys general say pseudonymized data will usually remain personal data, while data that no longer permits identification can be retained outside the storage-limitation rule. A 30-day raw-trace period followed by irreversible aggregation is a sensible policy pattern where you need short-term operational analysis. Document the aggregation method and test whether re-identification remains possible.1
Marketing communications history includes sends, opens, clicks, and preference changes. Do not inherit the security log timer. Retain it only for the stated marketing purpose, on the lawful basis that applies, with a documented review date. The 24-month review point below is a suggested operating limit, not an FTC and state attorneys general deadline. Never retain an engagement profile just because the person has not withdrawn consent. If consent is withdrawn, erase or de-identify the marketing history unless a separate, documented need applies. An opt-out suppression entry is different: it prevents further messages.2 6
Abuse and security logs may include firewall denials, DNS security events, and RADIUS accounting. Network and information security can support legitimate interests, but it does not do so automatically. Complete the purpose, necessity, and balancing tests before starting the retention period. A 365-day schedule can be defensible where a shared public IP address means you need attribution evidence for delayed incident, claim, or subpoena handling. It is not a CCPA/CPRA floor. Reduce fields, restrict access, log searches, and review the legitimate interests assessment when architecture or risk changes.1 6

Decision flow: determine identifiability, role, lawful basis, and any statutory notice before setting the automated purge rule.
What retention schedule can you adopt?
The schedule below is a ready-to-tailor baseline for a US shared WiFi estate. It is deliberately split by purpose. Adopt it only after the controller has documented the purpose, lawful basis, and risk assessment for the estate. A legal hold or active claim can override a normal purge date, but only for the specific records and duration that the exception justifies.1 7 9
| Data category | Purpose and lawful basis | Suggested default retention | Deletion or change event |
|---|---|---|---|
| Connection metadata and DHCP or RADIUS session data | Network security and fault investigation - Article 6(1)(f), subject to an LIA | 90 days | Purge at day 90 unless an approved incident or legal hold applies. |
| Guest access authentication data | Deliver guest access and resolve short disputes - Article 6(1)(b) or 6(1)(f), according to design | Session end plus 30 days | Erase identifying access data at day 30. |
| Raw identifiable location traces | Short-term operational analysis - Article 6(1)(f), subject to LIA | 30 days | Irreversibly aggregate or erase at day 30. |
| Marketing contact and engagement history | Consent or another documented marketing basis | Withdrawal, objection, or 24-month review, whichever occurs first | Erase or de-identify the profile. Retain only a minimal suppression record where needed. |
| Security and abuse evidence | Network security, defense of claims or an applicable legal duty | 365 days only where the LIA documents the shared-address attribution need | Purge at day 365 unless a specific hold or legal obligation applies. |
| Data specified in a valid IPA retention notice | Compliance with the notice - Article 6(1)(c) | Exact notice period, capped at 12 months | Purge when notice-specific period ends, unless another documented basis applies. |
The 90-day connection period and 365-day abuse period are policy choices, not mandatory figures. They are useful only when your written LIA, privacy notice, systems evidence and automated deletion design all match. A public authority must also check whether it is performing a public task, because it cannot rely on legitimate interests for that task.6
Does the IPA require a shared WiFi operator to retain logs for 12 months?
No, not by default. The IPA definition of telecommunications operator is broad. The government’s 2025 notices code says it may include a person who provides guests or members of the public access to communications services that are ancillary to another service, including commercial premises such as hotels. This makes the issue relevant for a Multi-Family, co-working or managed WiFi operator.8 9
But the same code is clear that the default position is no retention duty under the Act until a data retention notice is given. Under IPA section 87, the Secretary of State may issue a notice only where the requirement is necessary and proportionate and a Judicial Commissioner has approved it. The notice must identify the operator, data and period. It cannot require retention for more than 12 months. Do not build a generic "keep everything for 12 months" policy merely because the service might satisfy a broad definition of telecommunications operator.7 9
Where a valid notice creates a legal obligation, Article 6(1)(c) can provide the CCPA/CPRA lawful basis for processing necessary to comply. That is not a contractual basis. The FTC and state attorneys general say you must identify the specific legal provision, document the decision and explain the purpose and lawful basis in privacy information. The notice does not authorize secondary marketing use or open-ended collection.3
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.
What must an Article 28 tenant agreement contain?
If you process tenant employee data only on the tenant’s documented instructions, an Article 28 data processing agreement must be in place before that processing begins. The agreement should describe the subject matter and duration, nature and purpose, data types, data-subject categories, and the controller’s rights and obligations. It must then contain the operational commitments below.5
| Article 28 obligation | What to make operational on Staff WiFi |
|---|---|
| Documented instructions | Store the tenant’s approved authentication, retention and disclosure instructions. |
| Confidentiality and security | Limit privileged access, encrypt administrative access and maintain role-based audit logs. |
| Sub-processors | Notify the tenant of relevant sub-processor changes and flow down equivalent protections. |
| Rights assistance | Define the hand-off for access, rectification, erasure and objection requests. |
| Breach and DPIA support | Set incident notification routes and security-assessment assistance. |
| End-of-contract return or deletion | Choose return or secure deletion, except where state or federal law requires a defined record to remain. |
| Audit and evidence | Provide the information and audit access needed to demonstrate compliance. |
Do not use a data processing agreement to hide a joint-controller arrangement. If operator and tenant jointly decide why employee analytics will be used, which fields are collected and how long they remain available, assess joint-controller terms instead.4
How should you handle an erasure request?
CCPA/CPRA deletion is not a one-click delete function. Start with a proportional identity check. Then look up data by purpose and role: guest access, marketing, security, tenant instruction and any notice-specific retention. The FTC and state attorneys general say you should respond without undue delay and, at the latest, within 45 days. Where data is no longer necessary, or consent has been withdrawn, erase it from live records and notify relevant recipients where required.2
Where a legal obligation applies, or data is necessary for the establishment, exercise or defense of legal claims, the right to deletion does not apply to that extent. Explain the limited reason clearly. Keep the retained data segregated, prevent unrelated use and apply the relevant end date. Backups need an explicit answer: deletion should also cover backups where practicable. If an immediate overwrite is impossible, put the backup record beyond use and disclose the overwrite schedule.2

An erasure workflow should separate data to be deleted from the narrow records retained under a documented exception.
How does this work in real venues?
Hospitality scenario: a hotel with guest access and tenant staff access
A 200-room hotel operates Guest WiFi for visitors and supplies a Staff WiFi SSID to its restaurant tenant. The hotel writes two separate records of processing. It acts as controller for guest authentication, 90-day connection data and security investigations. The restaurant decides employee population, access conditions and retention for its staff SSID, so the hotel applies data processor terms to that processing. The measurable control is a monthly report showing every guest session older than 90 days has purged, while any exception has an incident or notice reference.
Retail scenario: a shopping destination on one public address
A retail destination uses one public egress address across several units. Its security LIA records why delayed abuse allegations may require attribution to a specific connection. It sets a 365-day security-evidence schedule, but keeps raw identifiable location trails for 30 days before aggregation. The measurable control is a quarterly LIA review plus a test that a security analyst can reconstruct a permitted incident without accessing expired raw location data.
Events scenario: a conference venue with sponsor-owned audiences
A conference center provides attendee access while sponsors collect opt-ins through separately branded journeys. The venue remains controller for service and security data. Each sponsor controls its own marketing purpose and must receive only the opt-ins it is entitled to use. The measurable control is a pre-event test proving withdrawal on one sponsor journey suppresses that sponsor’s communications without deleting the venue’s narrowly retained security evidence.
What should you do next?
Start with a 60-minute retention workshop, not a policy template. Bring your DPO, network architect, venue operations lead and each relevant tenant representative. Build a table of fields flowing from splash page, DHCP, RADIUS, firewall, DNS and analytics components. For each field, decide the purpose, controller or processor role, lawful basis, retention timer, deletion action, audit owner and legal-hold process.
Then configure the system to do the work. Purple provides configurable retention periods, automated purge schedules, access-request tooling and erasure workflows that support this operating model. Keep your Guest WiFi environment distinct from any tenant Staff WiFi purposes. Where you use WiFi Analytics, aggregate or de-identify before the identifiable retention window ends. A cloud overlay should make it easier to apply policy consistently across a distributed estate, not extend the life of records by default.
For related controls, compare the data-retention design with Hardening RADIUS against MD5 collision attacks (BlastRADIUS), Privacy by design: anonymising WiFi data for GDPR compliance and MDU WiFi tenant session tracking and abuse attribution. For broader context, see The definitive timeline of WiFi: from ALOHAnet to WiFi 7 and beyond, Guest WiFi Management: Smart Authentication & Segmentation, Cloud Wifi Management: Secure Enterprise Connectivity 2026 and Purple appoints Imani Butler as Growth Director, North America.
Frequently asked questions
How long can I keep guest WiFi login data under CCPA/CPRA?
Keep it only while the access, dispute, security or other stated purpose remains necessary. A practical starting point for access-only authentication is session end plus a short documented dispute period, such as 30 days. That is a policy choice, not a CCPA/CPRA rule. Record the purpose, lawful basis and deletion event, then test the purge.
Does the UK Investigatory Powers Act require 12 months of WiFi connection records?
No. The IPA does not create an automatic 12-month duty for every shared WiFi operator. A retention duty begins only when an applicable data retention notice is given. The notice defines the relevant communications data and retention period, which cannot exceed 12 months. Get specialist advice immediately if you receive one.7 9
Am I controller or processor for a tenant’s employees on Staff WiFi?
It depends on the processing activity. If the tenant decides the employee population, purpose, notice, rights handling and retention while you operate the service on documented instructions, you are likely processor for that activity. If you make those decisions for your own purpose, you are controller. Where both parties jointly decide essential purposes and means, assess joint controllership.4
What is the right retention period for IP-address logs on a shared WiFi network?
There is no prescribed CCPA/CPRA period. Set a proportionate period tied to the stated security and troubleshooting need. This guide uses 90 days as a suggested default for connection metadata. Extend to 365 days only where a documented LIA supports a genuine shared-address attribution or claims need, with field minimization and access controls.1 6
What should I do with an erasure request when I have a legal duty to retain traffic data?
Erase records that are no longer necessary, but retain only the narrow data and period required by the legal obligation. Respond within one month, explain the applicable exemption and prevent retained data from being used for unrelated purposes. Apply the same decision to backups by deleting them or putting them beyond use until scheduled overwrite.2 3
Do I need a DPA with every tenant organization?
You need an Article 28 data processing agreement whenever you process a tenant’s employee data on that tenant’s documented instructions. You do not need one merely because you share a building. If both parties determine the purposes and essential means together, an Article 26 joint-controller arrangement may be required instead.4 5
Can I keep marketing history until a guest withdraws consent?
No. Active consent does not remove the storage limitation obligation under CCPA/CPRA. Set and document a review period for marketing history, such as a 24-month review, and remove or de-identify data that no longer serves the stated purpose. On withdrawal or objection, stop marketing and retain only minimal suppression data needed to respect the choice. 1 2
References
Key Definitions
Storage limitation
The CCPA/CPRA principle requiring identifiable personal data to be kept no longer than necessary for its processing purpose.
Use it to justify an approved timer for each WiFi record type, rather than a blanket log-retention rule.
Connection metadata
Data about a network access session, such as IP address, device identifier, session times, DHCP lease and RADIUS accounting record.
It can become personal data when you can link the session to a named person.
DHCP lease
A time-bound record assigning an IP address to a device on a network.
It supports fault investigation and attribution, but should have its own retention analysis.
RADIUS accounting
Authentication, authorization and accounting records generated when a device accesses a network.
It is often central to the identity-to-session evidence needed in a shared WiFi investigation.
Pseudonymization
A technique that reduces direct identification by replacing data with a token or code while a re-identification link remains possible.
It is a safeguard, not an automatic escape from CCPA/CPRA retention duties.
Anonymization
A transformation that makes identification no longer possible in practice.
Use it after the raw operational period when you only need aggregate WiFi analytics.
Legitimate interests assessment
A documented purpose, necessity and balancing analysis for a processing purpose.
Complete it before retaining security logs beyond the minimum operational need.
Data retention notice
A legal notice requiring a specified telecommunications operator to retain specified relevant communications data for a stated period.
It can create a legal-obligation basis, but it is not an automatic duty for every guest WiFi operator.
Service provider agreement
A contract governing processing carried out by a service provider on a controller’s documented instructions.
Use it for tenant Staff WiFi processing where the tenant controls the why and the essential how.
Legal hold
A documented, time-limited exception preventing deletion of records needed for a specific investigation, claim, or legal obligation.
It should suspend only the relevant purge rule, not preserve all historical WiFi data.
Worked Examples
A 200-room hotel operates Guest WiFi and a Staff WiFi SSID for its restaurant tenant. How should it separate retention decisions?
Create two processing records. The hotel acts as controller for guest authentication, 90-day connection data and its own security investigations. The restaurant sets employee purpose, population and retention, so the hotel operates under service provider terms. Evidence compliance with a monthly purge report and a recorded reason for each exception.
A retail destination uses one public egress address across several units. How can it preserve abuse evidence without retaining location trails indefinitely?
Document the attribution need in an LIA, restrict security evidence to necessary fields and set a 365-day reviewable abuse-log policy only where the shared-address context supports it. Keep raw identifiable location trails for 30 days, then irreversibly aggregate or erase them. Test the process quarterly against a permitted incident scenario.
A conference center provides access while sponsors collect separately branded opt-ins. Which records should remain with the venue?
Treat service and network-security records as the venue’s controller-purpose data. Give sponsors only opt-ins they are entitled to use for their own stated marketing purpose. Before each event, test that a sponsor withdrawal suppresses sponsor communications while preserving only the venue’s narrowly justified security evidence.
Continue reading in this series
How to leverage SMS in marketing to increase return visits
This technical reference guide outlines how enterprise venues can integrate WiFi analytics with SMS marketing engines to drive repeat visits. It details the architecture required to capture real-time presence data, trigger automated SMS campaigns based on physical behavior, and measure the direct impact on return rates. By aligning network infrastructure with marketing automation, IT and operations teams can establish a high-yield channel for customer retention.
First-party data marketing: a comprehensive guide for businesses
This guide explains how to build a robust first-party data marketing strategy using enterprise Guest WiFi networks. It covers the technical architecture for secure data capture via captive portals, CCPA/CPRA-compliant consent workflows, CRM integration patterns, and automated campaign deployment. Venue operators across hospitality, retail, events, and public-sector environments will find actionable guidance for turning passive visitors into a high-quality, owned marketing audience.
Customer data management platform: a comprehensive guide for businesses
This guide explains how venue operators can deploy a customer data management platform to unify fragmented visitor data. It covers technical architecture, integration strategies, and the critical role of Guest WiFi in building first-party data profiles.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.