跳至主要內容

22,000 人同意以社區服務換取免費 WiFi

作者:Richard Ellor
10 July 2017
閱讀時間 1 分鐘
22,000 人同意以社區服務換取免費 WiFi
Interactive Compliance Auditor

Guest WiFi terms & GDPR compliance advisor

Audit your captive portal terms length, consent structure, and user transparency against global privacy standards.

1,600 words (~8 min read)
260 (Purple micro-policy)1,600 (Legacy average)3,500+ (High friction)
35,000
2,00075,000150,000+

Enables guests to review collected data, update marketing preferences, or invoke GDPR Article 17 (Right to Erasure) without manual DPO tickets.

Privacy Compliance Score

35%/ 100

Audit Risk Detected

Blind Consent Risk

99.8%

Community service trap risk

Onboarding Completion

82%

~28,700 successful logins/mo

Annual DPO Workload

252h/ year

+218h saved with Profile Portal

Retail Malls & Shopping Centers – Compliance & Architecture Profile

GDPR / CCPA Marketing Opt-in & Footfall Analytics

Recommended Onboarding Architecture: Granular marketing opt-in with self-serve Profile Portal.

Key Audit Vulnerabilities to Address

  • 1Pre-ticked marketing boxes violate GDPR Article 7.
  • 2Terms exceeding 1,000 words cause 99.9% blind consent rates.
  • 3Lack of clear data controller identification on splash screens.
The Purple Benchmark: In Purple's landmark 2-week experiment, 22,000 users agreed to 1,000 hours of community service (including cleaning festival loos) because legacy terms averaged 1,600 words. Purple replaced legacy terms with a 260-word micro-policy, granular opt-in checkboxes, and a self-serve Profile Portal, establishing the gold standard for transparent guest WiFi onboarding.

Deploy 100% GDPR-compliant guest WiFi today

Simplify terms to 260 words, automate subject access requests, and give visitors complete transparency over marketing preferences with Purple.

清理音樂祭的流動廁所、擁抱流浪貓狗,以及刮除街道上的口香糖,這些只是人們為了換取免費 WiFi 而同意的部分不討喜任務。而且我們不只是在談論幾百個不幸的人。在我們於兩週期間將惡搞條款加入服務條款與細則後,有超過 22000 人公開同意進行 1000 小時的社區服務。

我們在一般的條款中加入了「社區服務條款」,內容指出:根據 Purple 的自行決定,用戶可能需要履行 1,000 小時的社區服務。這可能包括以下內容:

  • 清理當地公園的動物排泄物
  • 給予流浪貓狗擁抱
  • 手動疏通下水道堵塞
  • 清理當地節慶與活動的流動廁所
  • 為蝸牛殼著色以美化牠們的生活
  • 刮除街道上的口香糖

不用擔心,我們不會召集這些人,要求他們戴上橡膠手套來償還這筆社區債務。我們進行這項實驗的真正原因,是為了突顯消費者在註冊使用 免費訪客 WiFi 時缺乏安全意識。所有使用者都有機會指出這項可疑的條款以換取獎品,但令人驚訝的是,在整個兩週期間,只有一個人發現了這點,這僅佔所有 WiFi 使用者的 0.000045%。

Purple 的執行長 Gavin Wheeldon 在對此結果發表評論時表示:「WiFi 使用者在註冊存取網路時需要閱讀條款。他們同意了什麼?分享了多少資料?以及給予了提供商什麼授權?我們的實驗表明,勾選一個方框並同意某些不公平的條款是多麼容易的事。」

我們在今天宣佈成為 第一家符合一般資料保護規範 (GDPR) 的 WiFi 提供商 的同時,也公佈了這項實驗的結果。這項將於 2018 年 5 月 25 日生效的歐洲法規,將重塑企業組織處理資料隱私的方式,並讓終端使用者能更進一步存取所收集的個人資料。GDPR 的一項核心規定是在將使用者的個人或行為資料用於行銷目的之前,必須取得「明確同意」。我們的實驗結果顯然支持在 GDPR 規範中納入「明確同意」。

為了回應 GDPR 以及我們在實驗中獲得的結果,我們已經修改了隱私權政策,使其更清晰、更簡單、更簡短。事實上,我們的隱私權政策現在只有 260 個字,而不是原來的 1600 個字,這意味著人們在點擊「接受」之前,應該會更願意閱讀這些條款。我們的接入流程也進行了調整,讓使用者對於他們的資料將如何被使用、用於何種目的以及由誰使用有更高的透明度。

Gavin Wheeldon 表示:「我們歡迎 GDPR 即將為整個歐洲帶來的資料保護法強化。這不僅能讓 WiFi 終端用戶更清楚掌控企業如何使用其個人資料,還能提升對數位經濟的信任度。」

今天宣布的另一項新功能是我們全新的 Profile Portal,它為終端用戶提供了其所有被收集資料的完整透明度,同時也允許他們修改其行銷偏好。」

Gavin 補充說明:「Purple 的 Profile Portal 意味著全球所有終端用戶都能安心,因為他們知道自己可以控制個人資料的使用方式。如果他們同時也樂意擁抱幾隻流浪狗,那更是雙贏的局面。」

延伸閱讀:GDPR 的十大實用建議

常見問題

What was Purple's 22,000-user community service WiFi experiment?

In a landmark two-week experiment to highlight blind consent on public networks, Purple added a humorous 'Community Service Clause' to its guest WiFi terms and conditions. Over 22,000 users consented to perform 1,000 hours of community service (such as cleaning festival toilets, hugging stray animals, and scraping chewing gum from streets) to access free WiFi, with only a single person spotting the clause.

Why do users blindly accept guest WiFi terms and conditions?

Traditional captive portal terms and conditions average between 1,600 and 3,000 words of complex legalese, taking an average of 8 to 15 minutes to read. Because users desire immediate internet access, over 99.9% accept terms without reading them, exposing themselves to unknown data sharing and tracking permissions.

What does GDPR require for guest WiFi captive portal consent?

Under GDPR (Article 7), consent for personal data processing and marketing must be freely given, specific, informed, and unambiguous. Captive portals cannot bundle marketing opt-ins into the basic terms required for internet access, cannot use pre-ticked checkboxes, and must clearly identify the data controller and data usage purposes.

How did Purple redesign its privacy policy for GDPR compliance?

Following the experiment and the introduction of GDPR, Purple reduced its guest WiFi privacy policy from 1,600 words down to a concise, plain-English 260-word micro-policy. This concise format allows visitors to understand data collection practices in under 70 seconds before connecting.

What is Purple's self-serve Profile Portal?

The Purple Profile Portal is a dedicated privacy management dashboard that gives WiFi end users complete visibility over the personal and behavioural data collected during venue visits. Users can view their stored profile, modify marketing opt-in preferences, or invoke their GDPR Article 17 right to erasure at any time.

How can venue operators ensure their captive portals remain privacy-compliant?

Venue operators must unbundle marketing consent from network access terms, replace multi-page legalese with concise transparent summaries, maintain timestamped consent audit logs, and provide self-service preference management to eliminate manual Subject Access Request (SAR) overhead.

準備好開始了嗎?

預約專家演示,了解 Purple 如何協助您達成業務目標。

諮詢專家