Skip to main content

What is GDPR?

Definition

GDPR, the EU General Data Protection Regulation, governs how organisations collect and use personal data about people in the EU. It requires a lawful basis for processing, transparent privacy notices, data minimisation, breach notification and respect for rights such as access and erasure. Guest WiFi sign-ins fall squarely within it.

GDPR explained

GDPR has applied since May 2018. It treats more than names and emails as personal data: device identifiers such as MAC addresses and behavioural data such as visit history count too. So a captive portal that collects an email address, and an analytics platform that records device movements, are both processing personal data.

For guest WiFi, compliance comes down to a few practical rules. Separate network access from marketing consent, so a guest can get online without opting in. Capture explicit, specific consent per sign-up and store the consent log for audit. Collect only what you use, set a retention period and honour requests to access or delete data.

Accuracy is part of the law as well. Article 5(1)(d) requires personal data to be accurate and kept up to date, which is the regulatory case for verifying email addresses at sign-in. Outside the EU, similar rules apply under laws such as the UK GDPR, CCPA in California and PIPEDA in Canada, so multi-country venues need a portal that adapts to each.

Need more than a definition?

Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.