Skip to main content

CCPA/CPRA data retention for shared WiFi operators: how long you can keep guest login data and network logs

A practical US compliance guide for DPOs, network architects and venue operators running shared WiFi. It separates CCPA/CPRA storage-limitation decisions from conditional retention obligations, then turns controller-processor analysis into a retention schedule, CCPA service provider agreement checklist and erasure workflow.

Published Updated
📖 12 min read2,808 words3 worked examples10 key definitions

Listen to this guide

View podcast transcript
CCPA/CPRA data retention for shared WiFi operators Welcome. This briefing is for the people who have to make retention decisions work across hotels, shopping destinations, co-working estates, stadiums and public venues. Here is the headline. The CCPA/CPRA does not give guest WiFi operators a fixed number of days for login data or network logs. Storage limitation requires you to keep identifiable data no longer than necessary for the purpose you documented. That means one blanket setting for every record is usually the wrong design. Start with the estate model. A hotel operating a guest network for its own access, service assurance and security purposes will usually make controller decisions for those purposes. A co-working operator may do the same for its member network. But where the operator provides a staff SSID for a tenant business, the tenant may decide why employee identity data is collected, how long it is retained and how staff requests are handled. In that processing, the operator may be a processor. The same data can be handled in different capacities for different purposes. Map the purpose before you argue about the label. Next, separate your data. Connection metadata may include the address assigned to a device, a device identifier, the session start and end time, DHCP leases, RADIUS accounting and traffic totals. On a named-login network, those records will commonly be personal data because you can connect them to a person. For a stated security and incident-response purpose, a 30 to 90 day operational period may be a proportionate starting point. It is not a legal safe harbor. Validate it against how quickly your incidents are found, the systems you can query, the intrusion risk and the controls you use. Authentication data needs its own rule. An email address, name, cell phone number and social-login identifier should not follow the same timer as a firewall event. If the only purpose is access to a guest network, erase or irreversibly de-identify it once access has ended and any short, documented dispute window has passed. If you use it for marketing, you need to respect the marketing lawful basis and electronic-marketing rules. Withdrawal of consent ends marketing use. Keep only the minimum suppression record needed to make sure the person does not receive marketing again. Location and presence data needs a more disciplined design. Aggregated information that has been genuinely anonymized so people cannot be identified is not personal data. But replacing a person’s name with a token does not make the information anonymous if you can relink the token. For identifiable trails, set a short operational window, then aggregate or erase. A 30 day trace period may be workable for a venue that investigates operational issues within that time. Document the reason. Do not store detailed movement trails because they might become useful later.For abuse and security logs, legitimate interests can be appropriate but it is not automatic. The FTC and state attorneys general's three-part test asks: is the security purpose legitimate, is this retention necessary, and do the individual’s interests override yours? Document reasonable expectations, the sensitivity of the fields, the access controls, and the harm that could follow from long retention. If your shared public address means you need historical attribution for an abuse complaint, a 365 day rule could be defensible in a particular environment. It is not a universal CCPA/CPRA floor. Make it a documented policy choice, review it, and minimize the retained fields. Now the UK Investigatory Powers Act, often abbreviated to IPA. This is where a lot of shared WiFi guidance goes wrong. The legal definition of telecommunications operator is broad. The government’s current code says it can include providers giving guests or members of the public access to communications services in places such as hotels, airport lounges and public transport. That makes the question relevant to shared WiFi operators. It does not mean every venue has an automatic twelve-month duty. The default position in the official notices code is that no operator has to retain data under the Act until it receives a data retention notice. Under section 87, a notice must be necessary and proportionate, it must identify the operator, data and retention period, and it cannot require retention for more than twelve months. If you have not received a notice, do not write an internal policy that says IPA requires you to keep every network record for a year. That is not what the Act says. If you do receive a notice, involve specialist legal counsel immediately. Preserve only the relevant communications data and the period actually specified. Keep it separate in your schedule. The government code identifies data that may assist with identifying the who, when, where and how of communication. Examples include source and destination addresses, ports, internet access session times, access-point identities and access-point locations. The IPA does not turn every content log into a retention target. Content is a separate category. For CCPA/CPRA purposes, an applicable legal duty may supply the legal-obligation basis. But your schedule needs the exact statutory reference and the scope of the notice. You should also explain that limited retention in your privacy information where appropriate and observe confidentiality obligations attached to the notice. The legal basis does not justify collecting extra data or using retained records for unrelated marketing. What happens if a person asks for erasure? Receive the request, verify identity proportionately, locate records by data category and purpose, and decide each category rather than making a blanket response. The FTC and state attorneys general say the usual response time is one month. Erase data that is no longer necessary. Stop using marketing data when consent has been withdrawn or the person objects. Where a legal obligation applies, or where data is necessary to establish, exercise or defend a legal claim, explain the limited exemption and keep only the data justified by it. Backups need thought too. Delete from live systems, prevent backup data from being used, and make the overwrite timetable clear. Turn this into a system, not a policy PDF. Your retention schedule should name the data category, purpose, controller or processor role, lawful basis, default period, deletion event, legal-hold override and owner. Configure automated purge jobs. Keep a separate legal-hold collection. Test the deletion logs. Give the DPO a quarterly exception report showing items held beyond the normal period and why. Purple can support that operating model with configurable retention periods, automated purge schedules and workflows for access and erasure requests. For tenant estates, use a purpose and role matrix before onboarding a staff SSID. Then put Article 28 terms in place where you are processing on a tenant’s instructions. The contract should cover documented instructions, security, confidential staff access, sub-processors, rights assistance, breach and DPIA support, return or deletion at the end of the service, and audit rights. Before the rapid questions, avoid four common failures. First, do not use the backup retention period as the live-data period. A backup is a resilience control, not a reason to keep an active profile. Second, do not copy a 12-month figure into every vendor configuration. The IPA notice, if there is one, determines the lawful scope. Third, do not combine guest consent, tenant staff authentication and security evidence in one undifferentiated export. Separate purpose changes how you respond to a subject request, how you contract with the tenant and who can search the records. Fourth, do not make the retention schedule a manual task. If the security lead must remember to delete a folder at the end of each quarter, it is not an effective control. Use automated purge jobs, exception holds with expiry dates and an audit report that shows when the system removed or aggregated data. When a retention period changes, update the privacy information, the LIA and the technical timer together. Three rapid answers. First, can you keep guest login data for a fixed period? Yes, if you can justify the exact period against a stated purpose. Second, must you retain connection logs for twelve months under the IPA? Only if an applicable retention notice requires it, not just because you operate shared WiFi. Third, does every tenant need a data processing agreement? You need an Article 28 contract wherever you are a processor processing tenant employee data on its documented instructions. If you jointly determine the purposes and means, assess an Article 26 joint-controller arrangement instead. The next practical step is to bring your DPO, network lead, commercial owner and each relevant tenant representative into one working session. Inventory the data. Confirm the role. Set the period. Build the purge control. Test an erasure request. And escalate any IPA notice promptly. That is how you keep a necessary network record without building an indefinite archive of visitor behavior. This briefing is technical information, not legal advice. Ask qualified counsel to validate the facts of your property portfolio, tenant agreements and any statutory notice before relying on the policy.

Part of our core series: WiFi Marketing Guide

CCPA/CPRA data retention for shared WiFi operators: how long you can keep guest login data and network logs

Under the CCPA/CPRA, keep identifiable guest WiFi login data and network logs only for the documented purpose and no longer. Most operational security logs may justify a short, tested period, not a universal rule. A 12-month period applies only where an applicable data retention notice requires specified data to be kept.1 7 9

What is a defensible WiFi data-retention policy?

A defensible policy links each data category to one purpose, one accountable party, one lawful basis, one retention period and one deletion event. That is the operational expression of data minimization principles: personal data must not remain identifiable for longer than necessary. The FTC and state attorneys general do not prescribe fixed periods. You must justify the period, document it, review it and erase or anonymize the data when it is no longer needed.1

Legal note. This is technical compliance guidance, not formal legal advice. Ask qualified counsel to validate your estate model, tenant contracts and any regulatory notice before relying on a retention schedule.

Why is shared WiFi a different compliance problem?

Multi-Tenant WiFi creates layers that a single-site guest network does not. You may operate a shared access layer for residents, members, guests and visitors, while providing a Staff WiFi service to a tenant employer. For your own purposes, such as network security, service assurance and billing dispute management, you may be a controller. For employee authentication processed only on the tenant’s documented instructions, you may be a processor. The label in a commercial agreement does not decide the issue.

The FTC and state attorneys general say role follows the specific processing activity. The party deciding why data is collected, the lawful basis, the data categories, recipients, privacy information, rights handling or retention is likely to be controller. A processor can choose technical methods, security controls and deletion mechanics without becoming controller, so long as it does not make the overarching decisions. The same dataset may therefore be separated by purpose and role. If both parties jointly determine purposes and means, use a joint-controller arrangement rather than treating the relationship as a simple processor service.4

Shared WiFi activity Likely role question Practical control
Guest splash-page authentication for the operator’s own network Does the operator decide collection, notice and retention? Record the operator as controller for that purpose.
Tenant employee Staff WiFi authentication Does the tenant decide the population, access purpose and retention? Use service provider terms if the operator follows tenant instructions.
Security investigation across the shared estate Does the operator need evidence to protect its own system? Keep a separate controller-purpose log with restricted access.
Tenant-led engagement campaign Does the tenant select audience and message purpose? Prevent reuse for operator marketing without a separate basis.

This analysis is particularly important for Hospitality, Retail, Healthcare and Transport estates, where a shared network can serve several independent businesses in the same building.

How should you classify the 5 WiFi data categories?

Connection metadata includes the IP address assigned, source MAC address, session start and end times, bytes transferred, DHCP lease records and RADIUS accounting. On a named-login service, these fields will commonly be personal data because they can be linked to an individual. Keep the fields required for the defined security and troubleshooting purpose. A suggested 30 to 90 day operational window is a starting policy, not a statutory safe harbor. Your incident-detection time, threat model and ability to investigate should determine the approved period.1 6

Guest authentication data includes email address, name, phone number and authentication identifier. If you collect it solely to admit a person to Guest WiFi, the access purpose ends with the session. Retain a short, documented dispute or fraud tail only where you can explain it. If you also collect a conscious-choice marketing opt-in, separate the marketing record from access data. Consent can be withdrawn, while electronic marketing also has its own rules. On withdrawal or objection, stop marketing and retain only the minimal suppression information needed to honor the choice.2 6

Location and presence data needs a hard distinction between raw identifiable trails and aggregate outputs. A token is not anonymous if you can relink it to a login. The FTC and state attorneys general say pseudonymized data will usually remain personal data, while data that no longer permits identification can be retained outside the storage-limitation rule. A 30-day raw-trace period followed by irreversible aggregation is a sensible policy pattern where you need short-term operational analysis. Document the aggregation method and test whether re-identification remains possible.1

Marketing communications history includes sends, opens, clicks, and preference changes. Do not inherit the security log timer. Retain it only for the stated marketing purpose, on the lawful basis that applies, with a documented review date. The 24-month review point below is a suggested operating limit, not an FTC and state attorneys general deadline. Never retain an engagement profile just because the person has not withdrawn consent. If consent is withdrawn, erase or de-identify the marketing history unless a separate, documented need applies. An opt-out suppression entry is different: it prevents further messages.2 6

Abuse and security logs may include firewall denials, DNS security events, and RADIUS accounting. Network and information security can support legitimate interests, but it does not do so automatically. Complete the purpose, necessity, and balancing tests before starting the retention period. A 365-day schedule can be defensible where a shared public IP address means you need attribution evidence for delayed incident, claim, or subpoena handling. It is not a CCPA/CPRA floor. Reduce fields, restrict access, log searches, and review the legitimate interests assessment when architecture or risk changes.1 6

CCPA/CPRA data retention for shared WiFi operators: how long you can keep guest login data and network logs - retention deci…

Decision flow: determine identifiability, role, lawful basis, and any statutory notice before setting the automated purge rule.

What retention schedule can you adopt?

The schedule below is a ready-to-tailor baseline for a US shared WiFi estate. It is deliberately split by purpose. Adopt it only after the controller has documented the purpose, lawful basis, and risk assessment for the estate. A legal hold or active claim can override a normal purge date, but only for the specific records and duration that the exception justifies.1 7 9

Data category Purpose and lawful basis Suggested default retention Deletion or change event
Connection metadata and DHCP or RADIUS session data Network security and fault investigation - Article 6(1)(f), subject to an LIA 90 days Purge at day 90 unless an approved incident or legal hold applies.
Guest access authentication data Deliver guest access and resolve short disputes - Article 6(1)(b) or 6(1)(f), according to design Session end plus 30 days Erase identifying access data at day 30.
Raw identifiable location traces Short-term operational analysis - Article 6(1)(f), subject to LIA 30 days Irreversibly aggregate or erase at day 30.
Marketing contact and engagement history Consent or another documented marketing basis Withdrawal, objection, or 24-month review, whichever occurs first Erase or de-identify the profile. Retain only a minimal suppression record where needed.
Security and abuse evidence Network security, defense of claims or an applicable legal duty 365 days only where the LIA documents the shared-address attribution need Purge at day 365 unless a specific hold or legal obligation applies.
Data specified in a valid IPA retention notice Compliance with the notice - Article 6(1)(c) Exact notice period, capped at 12 months Purge when notice-specific period ends, unless another documented basis applies.

The 90-day connection period and 365-day abuse period are policy choices, not mandatory figures. They are useful only when your written LIA, privacy notice, systems evidence and automated deletion design all match. A public authority must also check whether it is performing a public task, because it cannot rely on legitimate interests for that task.6

Does the IPA require a shared WiFi operator to retain logs for 12 months?

No, not by default. The IPA definition of telecommunications operator is broad. The government’s 2025 notices code says it may include a person who provides guests or members of the public access to communications services that are ancillary to another service, including commercial premises such as hotels. This makes the issue relevant for a Multi-Family, co-working or managed WiFi operator.8 9

But the same code is clear that the default position is no retention duty under the Act until a data retention notice is given. Under IPA section 87, the Secretary of State may issue a notice only where the requirement is necessary and proportionate and a Judicial Commissioner has approved it. The notice must identify the operator, data and period. It cannot require retention for more than 12 months. Do not build a generic "keep everything for 12 months" policy merely because the service might satisfy a broad definition of telecommunications operator.7 9

Where a valid notice creates a legal obligation, Article 6(1)(c) can provide the CCPA/CPRA lawful basis for processing necessary to comply. That is not a contractual basis. The FTC and state attorneys general say you must identify the specific legal provision, document the decision and explain the purpose and lawful basis in privacy information. The notice does not authorize secondary marketing use or open-ended collection.3

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.

What must an Article 28 tenant agreement contain?

If you process tenant employee data only on the tenant’s documented instructions, an Article 28 data processing agreement must be in place before that processing begins. The agreement should describe the subject matter and duration, nature and purpose, data types, data-subject categories, and the controller’s rights and obligations. It must then contain the operational commitments below.5

Article 28 obligation What to make operational on Staff WiFi
Documented instructions Store the tenant’s approved authentication, retention and disclosure instructions.
Confidentiality and security Limit privileged access, encrypt administrative access and maintain role-based audit logs.
Sub-processors Notify the tenant of relevant sub-processor changes and flow down equivalent protections.
Rights assistance Define the hand-off for access, rectification, erasure and objection requests.
Breach and DPIA support Set incident notification routes and security-assessment assistance.
End-of-contract return or deletion Choose return or secure deletion, except where state or federal law requires a defined record to remain.
Audit and evidence Provide the information and audit access needed to demonstrate compliance.

Do not use a data processing agreement to hide a joint-controller arrangement. If operator and tenant jointly decide why employee analytics will be used, which fields are collected and how long they remain available, assess joint-controller terms instead.4

How should you handle an erasure request?

CCPA/CPRA deletion is not a one-click delete function. Start with a proportional identity check. Then look up data by purpose and role: guest access, marketing, security, tenant instruction and any notice-specific retention. The FTC and state attorneys general say you should respond without undue delay and, at the latest, within 45 days. Where data is no longer necessary, or consent has been withdrawn, erase it from live records and notify relevant recipients where required.2

Where a legal obligation applies, or data is necessary for the establishment, exercise or defense of legal claims, the right to deletion does not apply to that extent. Explain the limited reason clearly. Keep the retained data segregated, prevent unrelated use and apply the relevant end date. Backups need an explicit answer: deletion should also cover backups where practicable. If an immediate overwrite is impossible, put the backup record beyond use and disclose the overwrite schedule.2

CCPA/CPRA data retention for shared WiFi operators: how long you can keep guest login data and network logs - data erasure r…

An erasure workflow should separate data to be deleted from the narrow records retained under a documented exception.

How does this work in real venues?

Hospitality scenario: a hotel with guest access and tenant staff access

A 200-room hotel operates Guest WiFi for visitors and supplies a Staff WiFi SSID to its restaurant tenant. The hotel writes two separate records of processing. It acts as controller for guest authentication, 90-day connection data and security investigations. The restaurant decides employee population, access conditions and retention for its staff SSID, so the hotel applies data processor terms to that processing. The measurable control is a monthly report showing every guest session older than 90 days has purged, while any exception has an incident or notice reference.

Retail scenario: a shopping destination on one public address

A retail destination uses one public egress address across several units. Its security LIA records why delayed abuse allegations may require attribution to a specific connection. It sets a 365-day security-evidence schedule, but keeps raw identifiable location trails for 30 days before aggregation. The measurable control is a quarterly LIA review plus a test that a security analyst can reconstruct a permitted incident without accessing expired raw location data.

Events scenario: a conference venue with sponsor-owned audiences

A conference center provides attendee access while sponsors collect opt-ins through separately branded journeys. The venue remains controller for service and security data. Each sponsor controls its own marketing purpose and must receive only the opt-ins it is entitled to use. The measurable control is a pre-event test proving withdrawal on one sponsor journey suppresses that sponsor’s communications without deleting the venue’s narrowly retained security evidence.

What should you do next?

Start with a 60-minute retention workshop, not a policy template. Bring your DPO, network architect, venue operations lead and each relevant tenant representative. Build a table of fields flowing from splash page, DHCP, RADIUS, firewall, DNS and analytics components. For each field, decide the purpose, controller or processor role, lawful basis, retention timer, deletion action, audit owner and legal-hold process.

Then configure the system to do the work. Purple provides configurable retention periods, automated purge schedules, access-request tooling and erasure workflows that support this operating model. Keep your Guest WiFi environment distinct from any tenant Staff WiFi purposes. Where you use WiFi Analytics, aggregate or de-identify before the identifiable retention window ends. A cloud overlay should make it easier to apply policy consistently across a distributed estate, not extend the life of records by default.

For related controls, compare the data-retention design with Hardening RADIUS against MD5 collision attacks (BlastRADIUS), Privacy by design: anonymising WiFi data for GDPR compliance and MDU WiFi tenant session tracking and abuse attribution. For broader context, see The definitive timeline of WiFi: from ALOHAnet to WiFi 7 and beyond, Guest WiFi Management: Smart Authentication & Segmentation, Cloud Wifi Management: Secure Enterprise Connectivity 2026 and Purple appoints Imani Butler as Growth Director, North America.

Frequently asked questions

How long can I keep guest WiFi login data under CCPA/CPRA?

Keep it only while the access, dispute, security or other stated purpose remains necessary. A practical starting point for access-only authentication is session end plus a short documented dispute period, such as 30 days. That is a policy choice, not a CCPA/CPRA rule. Record the purpose, lawful basis and deletion event, then test the purge.

Does the UK Investigatory Powers Act require 12 months of WiFi connection records?

No. The IPA does not create an automatic 12-month duty for every shared WiFi operator. A retention duty begins only when an applicable data retention notice is given. The notice defines the relevant communications data and retention period, which cannot exceed 12 months. Get specialist advice immediately if you receive one.7 9

Am I controller or processor for a tenant’s employees on Staff WiFi?

It depends on the processing activity. If the tenant decides the employee population, purpose, notice, rights handling and retention while you operate the service on documented instructions, you are likely processor for that activity. If you make those decisions for your own purpose, you are controller. Where both parties jointly decide essential purposes and means, assess joint controllership.4

What is the right retention period for IP-address logs on a shared WiFi network?

There is no prescribed CCPA/CPRA period. Set a proportionate period tied to the stated security and troubleshooting need. This guide uses 90 days as a suggested default for connection metadata. Extend to 365 days only where a documented LIA supports a genuine shared-address attribution or claims need, with field minimization and access controls.1 6

Erase records that are no longer necessary, but retain only the narrow data and period required by the legal obligation. Respond within one month, explain the applicable exemption and prevent retained data from being used for unrelated purposes. Apply the same decision to backups by deleting them or putting them beyond use until scheduled overwrite.2 3

Do I need a DPA with every tenant organization?

You need an Article 28 data processing agreement whenever you process a tenant’s employee data on that tenant’s documented instructions. You do not need one merely because you share a building. If both parties determine the purposes and essential means together, an Article 26 joint-controller arrangement may be required instead.4 5

No. Active consent does not remove the storage limitation obligation under CCPA/CPRA. Set and document a review period for marketing history, such as a 24-month review, and remove or de-identify data that no longer serves the stated purpose. On withdrawal or objection, stop marketing and retain only minimal suppression data needed to respect the choice. 1 2

References

Key Definitions

Storage limitation

The CCPA/CPRA principle requiring identifiable personal data to be kept no longer than necessary for its processing purpose.

Use it to justify an approved timer for each WiFi record type, rather than a blanket log-retention rule.

Connection metadata

Data about a network access session, such as IP address, device identifier, session times, DHCP lease and RADIUS accounting record.

It can become personal data when you can link the session to a named person.

DHCP lease

A time-bound record assigning an IP address to a device on a network.

It supports fault investigation and attribution, but should have its own retention analysis.

RADIUS accounting

Authentication, authorization and accounting records generated when a device accesses a network.

It is often central to the identity-to-session evidence needed in a shared WiFi investigation.

Pseudonymization

A technique that reduces direct identification by replacing data with a token or code while a re-identification link remains possible.

It is a safeguard, not an automatic escape from CCPA/CPRA retention duties.

Anonymization

A transformation that makes identification no longer possible in practice.

Use it after the raw operational period when you only need aggregate WiFi analytics.

Legitimate interests assessment

A documented purpose, necessity and balancing analysis for a processing purpose.

Complete it before retaining security logs beyond the minimum operational need.

Data retention notice

A legal notice requiring a specified telecommunications operator to retain specified relevant communications data for a stated period.

It can create a legal-obligation basis, but it is not an automatic duty for every guest WiFi operator.

Service provider agreement

A contract governing processing carried out by a service provider on a controller’s documented instructions.

Use it for tenant Staff WiFi processing where the tenant controls the why and the essential how.

Legal hold

A documented, time-limited exception preventing deletion of records needed for a specific investigation, claim, or legal obligation.

It should suspend only the relevant purge rule, not preserve all historical WiFi data.

Worked Examples

A 200-room hotel operates Guest WiFi and a Staff WiFi SSID for its restaurant tenant. How should it separate retention decisions?

Create two processing records. The hotel acts as controller for guest authentication, 90-day connection data and its own security investigations. The restaurant sets employee purpose, population and retention, so the hotel operates under service provider terms. Evidence compliance with a monthly purge report and a recorded reason for each exception.

A retail destination uses one public egress address across several units. How can it preserve abuse evidence without retaining location trails indefinitely?

Document the attribution need in an LIA, restrict security evidence to necessary fields and set a 365-day reviewable abuse-log policy only where the shared-address context supports it. Keep raw identifiable location trails for 30 days, then irreversibly aggregate or erase them. Test the process quarterly against a permitted incident scenario.

A conference center provides access while sponsors collect separately branded opt-ins. Which records should remain with the venue?

Treat service and network-security records as the venue’s controller-purpose data. Give sponsors only opt-ins they are entitled to use for their own stated marketing purpose. Before each event, test that a sponsor withdrawal suppresses sponsor communications while preserving only the venue’s narrowly justified security evidence.

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.