- Purple
- Enterprise WiFi security and authentication: a complete guide
- CIPA compliance: compliance checklist for venue operators
CIPA compliance: compliance checklist for venue operators
You will be able to decide whether CIPA binds your WiFi, then segment networks, route DNS through Purple Shield and close bypass routes. You will also know what evidence to keep for Form 486 or Form 479 certification. The checklist assigns every requirement an owner, so your next funding year certification has nothing missing.
Video overview
Part of our core series: Enterprise WiFi Security Guide →
- What does CIPA compliance actually require of your network?
- Who is in scope
- The three obligations
- What CIPA does not require
- What do you need in place before you start a CIPA compliance project?
- How do you set up CIPA filtering on public and student WiFi?
- Step 1: Segment networks by audience
- Step 2: Route DNS through Purple Shield
- Step 3: Close the bypass routes
- Step 4: Configure the captive portal
- Step 5: Write the override and unblock process
- Step 6: Document and certify
- Which filtering approach fits your network?
- How do you check your CIPA controls work?
- What do CIPA deployments look like in practice?
- Scenario 1: A county library system with 12 branches
- Scenario 2: A shopping mall with a public library tenant
- Scenario 3: A hotel group running family-friendly guest WiFi
- What goes wrong with CIPA filtering, and how do you fix it?
- Over-blocking is a compliance problem too
- Collecting too much data from minors
- What is the CIPA compliance checklist?
- What does CIPA compliance cost, and what do you get back?
- The cost side
- The return side
- Frequently asked questions
- Does CIPA apply to hotel, retail or stadium WiFi?
- Does Purple Shield work with the access points we already own?
- Is DNS filtering enough to meet CIPA on its own?
- Can adults ask for filtering to be switched off?
- Does CIPA require us to log what students and patrons browse?
- How does Purple handle personal data collected at WiFi login?
- What does CIPA filtering cost, and can E-Rate fund it?
- How long does it take to move from our current filter to Purple Shield?
To achieve CIPA compliance, US schools and libraries must meet three core obligations: implement a technology protection measure like Purple Shield, adopt an internet safety policy, and hold a public hearing. Operators must also retain compliance records for 10 years to secure their E-rate discounts.
What does CIPA compliance actually require of your network?
The Children's Internet Protection Act (CIPA) became US federal law in 2000. The Federal Communications Commission (FCC) enforces it through the E-rate program, and the Universal Service Administrative Company (USAC) administers E-rate funding. The Institute of Museum and Library Services (IMLS) applies parallel rules to Library Services and Technology Act (LSTA) grants.
Who is in scope
CIPA binds K-12 schools and public libraries that take E-rate discounts for internet access or internal connections. It also binds libraries that use LSTA funds to buy computers or pay for internet access. Hotels, retailers, stadiums, and conference centers are not covered directly.
Venue operators still meet CIPA in three common ways:
- You run WiFi for a library or school, as a contractor, managed service provider, or landlord.
- You share a building or network with a library branch, such as a shopping center or civic hub.
- You adopt CIPA as a public benchmark for family-friendly WiFi, because it is the best-known filtering standard in the US.
The three obligations
- A technology protection measure. This means a filter that blocks or filters visual depictions that are obscene or show child sexual abuse. On devices that minors use, it must also block content that is harmful to minors.
- An internet safety policy. The policy must address minors' access to inappropriate material and the safety of minors using email, chat rooms, and other direct communications. It must also cover hacking and other unlawful activity, plus unauthorized disclosure of minors' personal information.
- Public notice and a hearing. You must give reasonable public notice and hold at least one public hearing or meeting on the proposed policy.
Schools carry two further duties under the Protecting Children in the 21st Century Act of 2008. Their policy must cover monitoring minors' online activities. It must also cover educating minors about appropriate online behavior, including social networking, chat rooms, and cyberbullying awareness.
Applicants certify compliance on FCC Form 486 each funding year. Members of a consortium certify to their lead on FCC Form 479.
What CIPA does not require
CIPA does not require you to log the browsing of named individuals. The FCC has confirmed that the monitoring duty does not mean recording internet activity against identifiable minors or adults. CIPA lets an authorized person disable the filter for an adult who needs access for bona fide research or another lawful purpose. Your filter design must make that override possible.
What do you need in place before you start a CIPA compliance project?
Gather six things before you change a single SSID. Missing any one of them is the usual reason a project stalls at certification.
- Funding confirmation. Confirm which buildings and services draw E-Rate or LSTA money. That defines your compliance boundary.
- A draft internet safety policy. Legal or governance staff should own the text. IT supplies the technical description of the filter.
- A network inventory. List every SSID, VLAN (virtual LAN, a logically separated network segment), wired port, and internet breakout in scope.
- Your access point and controller vendor. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, and Fortinet.
- A named owner for unblock and override requests. Staff need a fast route to reclassify a wrongly blocked site and to disable filtering for an adult.
- A data handling plan. Decide what personal data your WiFi login collects, especially from minors, and how you will answer access and deletion requests.
Purple's Connect plan is free to start and gives you a secure captive portal with branded splash pages in 25 languages. A captive portal is the login page a device sees before it reaches the internet. The Connect onboarding article walks through venue and hardware setup.
How do you set up CIPA filtering on public and student WiFi?
The architecture has three layers: separate networks per audience, filtered DNS on every network, and controls that stop devices bypassing the filter.
Step 1: Segment networks by audience
Create a separate SSID and VLAN for each audience that needs a different policy. A typical public library runs three:
- Patron WiFi for the public, including minors, with full CIPA filtering.
- Staff WiFi for employees, with the adult filtering baseline and an override process.
- Device network for catalog terminals, printers, and building systems, with no public access.
Segmentation keeps a filtering exception on one network from leaking into another. It also gives you a clean boundary when you show an auditor which traffic the filter covers.
Step 2: Route DNS through Purple Shield
Purple Shield blocks malware, botnets, and inappropriate content at the DNS level. DNS (Domain Name System) turns a site name into an address. Filtering at that point stops a blocked site before any connection opens.
DNS filtering covers every device on the network, including patron-owned phones and laptops. No software is installed on those devices. That matters because most library and school WiFi traffic now comes from devices the institution does not own.
Step 3: Close the bypass routes
A DNS filter only works if devices use your DNS. Add three controls at your firewall or gateway:
- Block outbound DNS to external resolvers, so devices cannot query a public resolver directly.
- Use the Firefox canary domain. Mozilla documents that Firefox turns off automatic DNS over HTTPS (DoH) when the network's resolver blocks use-application-dns.net.
- Restrict VPN and proxy services on patron and student networks, in line with your internet safety policy.
Step 4: Configure the captive portal
Purple splash pages come in three types, each useful for CIPA:
- Offline page. This is the login page. It sits inside the walled garden, so it shows limited content and no external links. Put a plain-English summary of your internet safety policy here.
- Online page. This optional page appears after login and can carry external links. Link the full policy and the unblock request route from it.
- Out of hours page. This prevents logins outside opening hours. It suits libraries and schools that do not want unsupervised access overnight.
Step 5: Write the override and unblock process
Document who can disable filtering for an adult, how they verify the request and how quickly they act. Set a target, such as one business day, for reviewing wrongly blocked sites. Record each decision with a date and reason, not the requester's browsing history.
Step 6: Document and certify
Keep the adopted policy, the public notice, the meeting minutes and a description of your filter configuration. FCC rules require E-Rate applicants to retain program records for at least 10 years after the last date of service. Then certify on Form 486, or Form 479 if you are a consortium member.
Which filtering approach fits your network?
| Approach | Hardware needed | Covers patron-owned devices | Typical deployment time | Main bypass risk | Best suited to |
|---|---|---|---|---|---|
| Cloud DNS filtering (Purple Shield) | None beyond existing access points and gateway | Yes, all devices on the network | Hours per site once DNS is redirected | DoH, VPNs, hard-coded resolvers | Libraries, multi-site estates, shared buildings |
| Firewall web filtering (UTM) | Licensed firewall at each breakout | Yes, all traffic through the firewall | Days to weeks per site | Encrypted traffic without TLS inspection | Single large campuses with an on-site security team |
| Endpoint agent | None on network, agent per device | No, institution-owned devices only | Weeks, tied to device rollout | Agent removal, unmanaged devices | 1:1 school laptop programs |
| Forward proxy with TLS inspection | Proxy appliance or cloud proxy, certificates on devices | Only devices that trust your certificate | Weeks to months | Certificate pinning, unmanaged devices | Staff networks with managed devices |
Many schools combine two layers: DNS filtering on every network and an endpoint agent on school-issued laptops. Libraries usually rely on DNS filtering because patrons bring their own devices.
How do you check your CIPA controls work?
Test the controls as an auditor would. Run each check on every SSID in scope, from an unmanaged cell phone and an unmanaged laptop.
- Category test. Request a test site from each blocked category. Confirm the block page appears on every network.
- Resolver bypass test. Point a device at a public DNS resolver manually. The query should fail or time out.
- DoH test. Open Firefox with default settings. Confirm the canary domain blocks automatic DoH and filtered sites stay blocked.
- Segmentation test. From patron WiFi, try to reach a staff printer or the catalog terminals. The connection should fail.
- Override test. Ask an authorized staff member to process an adult override. Time it from request to access.
- Out of hours test. Try to log in after closing time. The out of hours page should appear and access should not open.
- Data request test. Submit a test access request and a test erasure request, then time the response.
Repeat the full test after any firmware upgrade, controller change or new SSID. Keep the results with your CIPA records.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.
What do CIPA deployments look like in practice?
The three scenarios below are illustrative. They show the decisions and the measures to report, not results from named Purple deployments.
Scenario 1: A county library system with 12 branches
Situation. Each branch runs its own consumer-grade router with a different filter. The library cannot describe its technology protection measure consistently for the Form 486 certification. Patron complaints about blocked research sites go to whoever is on the desk.
What was done. The library segments patron and staff WiFi on its existing access points. It routes both networks through Purple Shield and blocks external DNS at each branch gateway. It moves the policy summary onto the offline splash page and adds an out of hours page timed to branch closing.
Measurable outcome. One filter policy now applies across all 12 branches. The library reports two numbers to its board each quarter: unblock requests resolved within one business day, and branches passing the bypass test. Both feed straight into the next year's certification file.
Scenario 2: A shopping mall with a public library tenant
Situation. A shopping mall operator runs one guest WiFi network across the mall. A county library opens a branch inside the mall and needs CIPA-filtered access. The library cannot certify filtering on a network it does not control.
What was done. The operator adds a library SSID on a dedicated VLAN, broadcast only from the library's access points. That network resolves through Purple Shield. Mall shopper WiFi keeps its own settings, so the operator changes nothing for shoppers or retail tenants.
Measurable outcome. The library receives a written description of its filtered network for its records. The operator adds the tenant with no new hardware, using access points it already owns. The same pattern suits Retail estates with civic or education tenants.
Scenario 3: A hotel group running family-friendly guest WiFi
Situation. A 200-room resort hotel hosts school residential trips each term. Schools ask whether the WiFi filters content for their pupils. CIPA does not bind the hotel, but the hotel wants a clear answer for every booking inquiry.
What was done. The hotel adds a filtered guest network for groups and families, using CIPA's content categories as its benchmark. Adult guests keep the standard network. The group sales team sends schools a one-page description of the filter and the opening hours of the filtered network.
Measurable outcome. The hotel answers filtering questions with a written policy rather than a phone call to IT. It measures school group rebookings year over year. Operators of Hotels and Trains can apply the same benchmark to family and group travel.
What goes wrong with CIPA filtering, and how do you fix it?
| Problem | Likely cause | Fix |
|---|---|---|
| Blocked sites load on some devices | Devices use DoH or a hard-coded public resolver | Block external DNS at the gateway and block the Firefox canary domain |
| Students reach blocked content via an app | VPN or proxy app tunnels around DNS | Restrict known VPN and proxy services on student networks |
| Research or health sites blocked | Category too broad for the audience | Review the category, allow the site and record the decision |
| Captive portal does not appear | Device cached DNS or walled garden misconfigured | Check walled garden entries against your hardware vendor guide |
| Staff network inherits patron rules | Shared VLAN or shared DNS policy | Separate the SSIDs onto their own VLANs and policies |
| Certification evidence incomplete | Policy, notice or minutes not filed | Build the records file before the Form 486 deadline |
Over-blocking is a compliance problem too
CIPA requires you to block specific visual content, not every borderline category. Overly broad filtering blocks health, sexual education and LGBTQ+ resources that patrons and students have good reason to reach. Keep a short, published route to request a review. In healthcare settings, apply the same discipline to patient and visitor WiFi; the Healthcare page covers that audience.
Collecting too much data from minors
A login form that captures email addresses from children creates a data protection exposure. The US Children's Online Privacy Protection Act (COPPA) restricts collecting personal information from children under 13. CIPA's own safety policy must address unauthorized disclosure of minors' personal information. On student and patron networks, use the lightest login you can justify.
Where you do hold personal data, Purple gives you two routes. Visitors can view, update and request deletion of their data through the Profile Portal. Administrators can search for a visitor, download their profile to meet a right of access request, or anonymize it. Anonymizing permanently and irreversibly removes personally identifiable information. Purple's support article on managing and deleting visitor personal data gives the steps.
What is the CIPA compliance checklist?
| CIPA requirement | Evidence to keep | Owner |
|---|---|---|
| Technology protection measure in place | Filter configuration, network diagram, test results | IT or network manager |
| Harmful - to - minors filtering on devices minors use | SSID and VLAN map showing filtered networks | IT or network manager |
| Adult override available | Written override procedure and decision log | Library director or school administrator |
| Internet safety policy adopted | Signed policy with adoption date | Governing board |
| Policy covers the five required topics | Policy text mapped to each topic | Compliance or legal lead |
| Public notice and hearing held | Notice copy and meeting minutes | Board secretary |
| Schools: monitoring and online safety education | Curriculum plan and monitoring statement | Head of school or district |
| Annual certification | Filed Form 486 or Form 479 | E-Rate coordinator |
| Records retained | Archive of all items above for 10 years | E-Rate coordinator |
What does CIPA compliance cost, and what do you get back?
The cost side
E-Rate discounts range from 20% to 90% of eligible costs, depending on poverty level and rural status. Category Two internal connections are capped at an 85% discount. Content filtering is not on the FCC's Eligible Services List. Budget for the filter from your own funds.
Purple's Connect plan is free and covers the captive portal and splash pages. Shield is a security add - on, priced with your Purple plan. Because Purple runs as a cloud overlay, you keep your existing access points and controllers. You avoid a hardware refresh to add filtering.
The return side
The main return is protected funding. A school or library that fails to certify loses E-Rate discounts for that funding year. If USAC finds a violation after funds are paid, it can recover them.
The second return is lower operating effort. One DNS policy across every site replaces a filter configuration on each router. One test plan produces evidence for every branch.
The third return is assurance on data. Purple holds ISO 27001 and Cyber Essentials certification and supports CCPA/CPRA compliance. Purple runs across 80,000+ live venues and logged 440 million logins in 2024, according to Purple's own data. That scale is relevant when a board asks whether the platform will hold up.
Frequently asked questions
Does CIPA apply to hotel, retail or stadium WiFi?
No, CIPA binds only US schools and libraries that receive E-Rate discounts or LSTA grants. Hotels, retailers and stadiums are not covered unless they operate WiFi for a library or school, share a network with one, or deliver it under contract. Many venue operators still use CIPA's content categories as a benchmark for family friendly guest WiFi, because it is the standard schools and parents recognize.
Does Purple Shield work with the access points we already own?
Yes, Purple Shield works with the access points you already run. Purple is hardware agnostic and operates as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Because Shield filters at the DNS level, it covers every device on the network without installing software on patron or student devices. You keep your existing controllers and avoid a hardware refresh.
Is DNS filtering enough to meet CIPA on its own?
DNS filtering can serve as your technology protection measure, but the filter alone does not make you compliant. You also need an adopted internet safety policy, public notice, a hearing and annual certification. On the technical side, block external DNS resolvers and automatic DNS over HTTPS. Schools with 1:1 laptop programs often add an endpoint agent for school-issued devices used off site.
Can adults ask for filtering to be switched off?
Yes, CIPA allows an authorized person to disable the filter for an adult with a bona fide research or other lawful purpose. Your internet safety policy should name who can grant the override, how they verify the request and how fast they act. Separate staff and patron networks make overrides easier to administer. Log the decision and its reason, not the adult's browsing history.
Does CIPA require us to log what students and patrons browse?
No, CIPA does not require you to log browsing against identifiable individuals. Schools must have a policy covering monitoring of minors' online activities, but the FCC has said this does not mean recording internet use by named students. Keep filter logs at the network level for security and troubleshooting. Collect as little personal data from minors as your purpose allows, especially under COPPA.
How does Purple handle personal data collected at WiFi login?
Purple supports CCPA/CPRA and GDPR compliance and holds ISO 27001 certification. Visitors can view, update, and request deletion of their data through the Profile Portal. Administrators can search for a visitor, download a full profile to answer an access request, or anonymize the profile. Anonymizing permanently and irreversibly removes personally identifiable information from the platform. On networks used by minors, use the lightest login you can justify.
What does CIPA filtering cost, and can E-Rate fund it?
E-Rate does not fund content filtering, so you pay for the filter from your own budget. E-Rate does discount eligible internet access and internal connections by 20% to 90%. Purple's Connect plan is free and covers the captive portal and splash pages. Shield is a security add-on priced with your Purple plan. Because Purple runs on existing hardware, filtering adds no access point costs.
How long does it take to move from our current filter to Purple Shield?
Most of the effort sits in policy and testing, not configuration. Redirecting DNS to Shield and blocking external resolvers takes hours per site once your network inventory is complete. Allow time to run the full test plan on every SSID, update your splash pages and refresh your certification records. Run the old and new filters in parallel on one pilot site before switching the property portfolio.
Key Definitions
Children's Internet Protection Act (CIPA)
US federal law enacted in 2000 and codified at 47 U.S.C. 254(h). It conditions E-rate discounts and LSTA grants on a technology protection measure, an internet safety policy, and public notice with at least one hearing on that policy.
IT teams meet CIPA when a school or library network draws E-rate or LSTA money. It sets the compliance boundary that decides which SSIDs need filtering and evidence.
E-rate
The FCC Schools and Libraries Universal Service program, administered by the Universal Service Administrative Company (USAC). It discounts eligible internet access and internal connections by 20% to 90%, with Category Two internal connections capped at 85%.
E-rate funding is what triggers CIPA for schools and libraries. Content filtering is not on the Eligible Services List, so the filter is budgeted from your own funds.
Library Services and Technology Act (LSTA)
Federal grant program run by the Institute of Museum and Library Services (IMLS). IMLS applies CIPA rules to libraries that use LSTA funds to buy computers or pay for internet access.
Libraries funded through LSTA rather than E-rate still fall in scope, so the funding confirmation step must check both programs.
Technology protection measure
The CIPA term for a filter that blocks or filters visual depictions that are obscene or show child sexual abuse, and on devices used by minors, content harmful to minors. CIPA allows an authorized person to disable it for an adult with a bona fide research or other lawful purpose.
This is the technical layer IT owns. DNS filtering through Purple Shield can serve as the measure, but the design must also support an adult override.
Internet safety policy
The CIPA-required policy covering minors' access to inappropriate material, safety in email, chat and direct communications, hacking and unlawful activity, and unauthorized disclosure of minors' personal information. The Protecting Children in the 21st Century Act of 2008 adds monitoring and online safety education for schools.
Legal or governance staff own the text and IT supplies the filter description. A summary belongs on the offline splash page and the full policy on the online page.
FCC Form 486 and Form 479
FCC certification forms. Form 486 is where E-Rate applicants certify CIPA compliance each funding year; Form 479 is where consortium members certify compliance to their consortium lead.
A missed or unsupported certification costs that year's E-Rate discounts, and USAC can recover funds already paid if it later finds a violation.
DNS filtering
Filtering applied at the Domain Name System, defined in IETF RFC 1034 and RFC 1035, which resolves site names to addresses. A filtering resolver refuses to resolve blocked domains, so no connection to the site opens.
DNS filtering covers every device on the network, including patron-owned phones and laptops, with no software installed. It is the approach Purple Shield uses.
DNS over HTTPS (DoH)
Encrypted DNS resolution over HTTPS, specified in IETF RFC 8484. Browsers can use it to send queries to a public resolver and bypass the network's own DNS.
DoH is a main bypass risk for DNS filtering. Mozilla documents that Firefox turns off automatic DoH when the network resolver blocks the canary domain use-application-dns.net.
VLAN
A virtual LAN, a logically separated network segment defined by IEEE 802.1Q tagging, which lets one physical network carry isolated traffic for different audiences.
Each audience SSID maps to its own VLAN, so patron rules, staff rules and device networks stay separate and an auditor sees a clean filtering boundary.
Captive portal
The login page a device sees before it reaches the internet, served from inside a walled garden that limits reachable content until login completes.
Purple's offline, online and out of hours splash pages carry the policy summary, link the full policy and unblock route, and stop unsupervised overnight access.
Children's Online Privacy Protection Act (COPPA)
US federal law, implemented by the Federal Trade Commission's COPPA Rule at 16 CFR Part 312, that restricts collecting personal information from children under 13.
A WiFi login that captures email addresses from children creates data protection exposure, so student and patron networks should use the lightest login you can justify.
Worked Examples
A county library system with 12 branches runs a consumer-grade router with a different filter at each site. It cannot describe its technology protection measure consistently for Form 486, and unblock complaints go to whoever is on the desk.
The library segments patron and staff WiFi on its existing access points and routes both networks through Purple Shield. It blocks external DNS at each branch gateway, so devices cannot query a public resolver. It moves the policy summary onto the offline splash page and adds an out of hours page timed to branch closing. One filter policy now applies across all 12 branches. The library reports two numbers to its board each quarter: unblock requests resolved within one business day, and branches passing the bypass test. Both feed straight into the next year's certification file.
A shopping center operator runs one guest WiFi network across the mall. A county library opens a branch inside the center and needs CIPA-filtered access, but cannot certify filtering on a network it does not control.
The operator adds a library SSID on a dedicated VLAN, broadcast only from the library's access points. That network resolves through Purple Shield, while shopper WiFi keeps its own settings, so nothing changes for shoppers or retail tenants. Segmentation gives the library a clean boundary it can describe to an auditor. The library receives a written description of its filtered network for its records. The operator adds the tenant with no new hardware, using access points it already owns, and can reuse the pattern across retail estates with civic or education tenants.
A 200-room resort hotel hosts school field trips each term. Schools ask whether the WiFi filters content for their pupils. CIPA does not bind the hotel, but it wants a clear answer for every booking inquiry.
The hotel adds a filtered guest network for groups and families, using CIPA's content categories as its benchmark, because it is the standard schools and parents recognize. Adult guests keep the standard network, so their experience does not change. The group sales team sends schools a one-page description of the filter and the opening hours of the filtered network. The hotel now answers filtering questions with a written policy rather than a phone call to IT, and measures school group rebookings year over year to track the return.
Frequently asked questions
Does CIPA apply to hotel, retail or stadium WiFi?
No, CIPA binds only US schools and libraries that receive E-Rate discounts or LSTA grants. Hotels, retailers and stadiums are not covered unless they operate WiFi for a library or school, share a network with one, or deliver it under contract. Many venue operators still use CIPA's content categories as a benchmark for family-friendly guest WiFi, because it is the standard schools and parents recognize.
Does Purple Shield work with the access points we already own?
Yes, Purple Shield works with the access points you already run. Purple is hardware-agnostic and operates as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Because Shield filters at the DNS level, it covers every device on the network without installing software on patron or student devices. You keep your existing controllers and avoid a hardware refresh.
Is DNS filtering enough to meet CIPA on its own?
DNS filtering can serve as your technology protection measure, but the filter alone does not make you compliant. You also need an adopted internet safety policy, public notice, a hearing and annual certification. On the technical side, block external DNS resolvers and automatic DNS over HTTPS. Schools with 1:1 laptop programs often add an endpoint agent for school-issued devices used off site.
Can adults ask for filtering to be switched off?
Yes, CIPA allows an authorized person to disable the filter for an adult with a bona fide research or other lawful purpose. Your internet safety policy should name who can grant the override, how they verify the request and how fast they act. Separate staff and patron networks make overrides easier to administer. Log the decision and its reason, not the adult's browsing history.
Does CIPA require us to log what students and patrons browse?
No, CIPA does not require you to log browsing against identifiable individuals. Schools must have a policy covering monitoring of minors' online activities, but the FCC has said this does not mean recording internet use by named students. Keep filter logs at network level for security and troubleshooting. Collect as little personal data from minors as your purpose allows, especially under COPPA.
How does Purple handle personal data collected at WiFi login?
Purple supports GDPR and CCPA compliance and holds ISO 27001 certification. Visitors can view, update and request deletion of their data through the Profile Portal. Administrators can search for a visitor, download a full profile to answer an access request, or anonymize the profile. Anonymizing permanently and irreversibly removes personally identifiable information from the platform. On networks used by minors, use the lightest login you can justify.
What does CIPA filtering cost, and can E-Rate fund it?
E-Rate does not fund content filtering, so you pay for the filter from your own budget. E-Rate does discount eligible internet access and internal connections by 20% to 90%. Purple's Connect plan is free and covers the captive portal and splash pages. Shield is a security add-on priced with your Purple plan. Because Purple runs on existing hardware, filtering adds no access point costs.
How long does it take to move from our current filter to Purple Shield?
Most of the effort sits in policy and testing, not configuration. Redirecting DNS to Shield and blocking external resolvers takes hours per site once your network inventory is complete. Allow time to run the full test plan on every SSID, update your splash pages and refresh your certification records. Run the old and new filters in parallel on one pilot site before switching the estate.
Continue reading in this series
WPA3 transition mode connection failures: a deployment checklist for Cisco Meraki, HPE Aruba and Ruckus
Use this checklist to diagnose why devices fail on a WPA3 SAE transition mode SSID and fix it on Cisco Meraki, HPE Aruba or Ruckus. You will match 802.11 status codes to causes, isolate PMF, 802.11r and 6GHz issues, and decide when to move to a WPA3-only SSID.
Best DNS filtering: a comprehensive guide for businesses
This technical reference guide explains how enterprise DNS filtering secures public networks by blocking malicious domains at the resolution layer - before a connection is ever established. It gives IT directors, network architects, and venue operations teams the deployment architecture, firewall configuration, and compliance context they need to protect Guest WiFi across hospitality, retail, and public-sector environments. Purple Shield blocks malware, botnets, and inappropriate content at the DNS level across 80,000+ live venues.
The Enterprise Guide to SCEP: Deploying Simple Certificate Enrollment Protocol for Automated Campus WiFi Security
This technical reference guide provides a definitive architectural blueprint and step-by-step implementation strategy for enterprise WiFi certificate deployment using SCEP. It covers the critical differences between SCEP and PKCS, the exact deployment sequence required for success, and real-world risk mitigation strategies for IT leaders.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.