Guest WiFi terms and consent checker
Test your captive portal terms length and consent design against UK GDPR and PECR, and get the fixes to make.
- Marketing consent is separate from the access terms (0/25)UK GDPR Art. 7(2) and 7(4)
- Consent is a clear affirmative act (20/20)UK GDPR Art. 4(11), Recital 32
- Terms short enough to read at the portal (0/15)UK GDPR Art. 12(1): concise, intelligible, plain language
- Privacy notice names controller, purposes, lawful basis, retention and rights (15/15)UK GDPR Art. 13
- Guests can withdraw consent and see or delete their data themselves (0/15)UK GDPR Art. 7(3), 15, 17
- A retention period is set and enforced (0/10)UK GDPR Art. 5(1)(e)
- Give marketing its own checkbox so guests can get online without agreeing to it.
- Put a summary of 300 words or fewer on the splash page and link to the full terms (a layered notice).
- Offer a self-serve preference and data portal; withdrawing must be as easy as giving consent.
- Set a retention period for profiles and session logs and delete automatically when it ends.
Retail and shopping centres: what auditors look for
Marketing consent and footfall analyticsRecommended flow: Short access terms, a separate unticked marketing box, and a link to a preference centre.
- 1Pre-ticked marketing boxes are not valid consent (UK GDPR Recital 32; CJEU Planet49, 2019).
- 2Footfall and location analytics need to be disclosed in the privacy notice, with the lawful basis stated.
- 3The splash page must name the data controller, not just the WiFi provider.
In 2017 Purple added a joke clause to its WiFi terms for two weeks, committing anyone who connected to 1,000 hours of community service, including cleaning portable toilets at festivals. 22,000 people accepted it. One person, about 0.0045%, spotted it. Long terms are accepted, not read.
Assumptions and method
- ·Reading time = words ÷ 238 words per minute, the average adult silent reading rate for non-fiction (Brysbaert, 2019).
- ·Score = sum of the six checks (25 + 20 + 15 + 15 + 15 + 10). Terms of 300 words or fewer earn the full length points, up to 800 earn half. The score is a design check, not a legal opinion.
- ·Requests = logins × 12 ÷ 10,000 × 1, handled in 1 h each by hand or 0.1 h with self-service. Replace the rate with your own request log. Access requests must be answered within one month (UK GDPR Art. 12(3)).
Make your portal short, clear and consent-safe
Purple portals separate access terms from marketing consent and give guests a self-serve preference page.
清理音樂祭的流動廁所、擁抱流浪貓狗,以及刮除街道上的口香糖,這些只是人們為了換取免費 WiFi 而同意的部分不討喜任務。而且我們不只是在談論幾百個不幸的人。在我們於兩週期間將惡搞條款加入服務條款與細則後,有超過 22000 人公開同意進行 1000 小時的社區服務。
我們在一般的條款中加入了「社區服務條款」,內容指出:根據 Purple 的自行決定,用戶可能需要履行 1,000 小時的社區服務。這可能包括以下內容:
- 清理當地公園的動物排泄物
- 給予流浪貓狗擁抱
- 手動疏通下水道堵塞
- 清理當地節慶與活動的流動廁所
- 為蝸牛殼著色以美化牠們的生活
- 刮除街道上的口香糖
不用擔心,我們不會召集這些人,要求他們戴上橡膠手套來償還這筆社區債務。我們進行這項實驗的真正原因,是為了突顯消費者在註冊使用 免費訪客 WiFi 時缺乏安全意識。所有使用者都有機會指出這項可疑的條款以換取獎品,但令人驚訝的是,在整個兩週期間,只有一個人發現了這點,這僅佔所有 WiFi 使用者的 0.000045%。
Purple 的執行長 Gavin Wheeldon 在對此結果發表評論時表示:「WiFi 使用者在註冊存取網路時需要閱讀條款。他們同意了什麼?分享了多少資料?以及給予了提供商什麼授權?我們的實驗表明,勾選一個方框並同意某些不公平的條款是多麼容易的事。」
我們在今天宣佈成為 第一家符合一般資料保護規範 (GDPR) 的 WiFi 提供商 的同時,也公佈了這項實驗的結果。這項將於 2018 年 5 月 25 日生效的歐洲法規,將重塑企業組織處理資料隱私的方式,並讓終端使用者能更進一步存取所收集的個人資料。GDPR 的一項核心規定是在將使用者的個人或行為資料用於行銷目的之前,必須取得「明確同意」。我們的實驗結果顯然支持在 GDPR 規範中納入「明確同意」。
為了回應 GDPR 以及我們在實驗中獲得的結果,我們已經修改了隱私權政策,使其更清晰、更簡單、更簡短。事實上,我們的隱私權政策現在只有 260 個字,而不是原來的 1600 個字,這意味著人們在點擊「接受」之前,應該會更願意閱讀這些條款。我們的接入流程也進行了調整,讓使用者對於他們的資料將如何被使用、用於何種目的以及由誰使用有更高的透明度。
Gavin Wheeldon 表示:「我們歡迎 GDPR 即將為整個歐洲帶來的資料保護法強化。這不僅能讓 WiFi 終端用戶更清楚掌控企業如何使用其個人資料,還能提升對數位經濟的信任度。」
今天宣布的另一項新功能是我們全新的 Profile Portal,它為終端用戶提供了其所有被收集資料的完整透明度,同時也允許他們修改其行銷偏好。」
Gavin 補充說明:「Purple 的 Profile Portal 意味著全球所有終端用戶都能安心,因為他們知道自己可以控制個人資料的使用方式。如果他們同時也樂意擁抱幾隻流浪狗,那更是雙贏的局面。」
延伸閱讀:GDPR 的十大實用建議



