Menu

Guides

Guest Wi-Fi and GDPR, in plain English.

Written for the people who run venues, not for their lawyers. When guests hand over a name and an email for the Wi-Fi, two laws take an interest — this guide walks through what they actually ask of you. It's general guidance, not legal advice: for your venue's specifics, ask your solicitor.

You're the data controller

Marketing consent: separate, unticked, optional

No fixed retention period — set one and honour it

No blanket 12-month Wi-Fi-log rule

Checked against the legislation: July 2026

Version 1.0 · 13 July 2026 · Checked against the legislation: July 2026

No. 01

Why this lands on you

When a guest types their name and email into your sign-in page, somebody decided why that information was being collected — and it was you. You want a list of people to tell about quiz night. Under UK GDPR, deciding the why makes your venue the data controller: the one who answers for the data being handled properly.

A Wi-Fi platform that holds the data and acts only on your instructions — storing it, syncing it, deleting it when you say — is the data processor. That split settles a common hope early: outsourcing the kit never outsources the responsibility. The lawful basis, the notices, the opt-outs, the retention — the controller answers for all of it, whoever built the sign-in page.

It also hands you your first practical job. UK GDPR (Article 28) requires a written contract between you and any provider that processes guest data on your behalf, setting out what they may do with it and on whose instructions. A provider that won't put that in writing has answered a question you hadn't asked yet.

No. 02

The two laws, briefly

Two laws cover guest Wi-Fi marketing, and they split the work neatly.

UK GDPR governs the personal data itself: what you may collect, why, how long you keep it, and what guests may ask of you. PECR — in full, the Privacy and Electronic Communications Regulations 2003; in practice, the UK rules on marketing messages — governs the sending: when a marketing email or text may go out at all.

The comforting part is that they share one consent standard, not two. When PECR asks for consent, it means consent as UK GDPR defines it — so get the consent right once and it's right for both. PECR's other duties attach to the messages themselves; No. 05 covers those.

One housekeeping note: both laws were amended by the Data (Use and Access) Act 2025, with the key changes in force from 5 February 2026, and this guide reflects the amended text. Nothing in those changes alters the plain advice that follows — get a real opt-in, keep the evidence, honour the "stop".

No. 03

What guest Wi-Fi actually collects

A sign-in page usually asks for a name and an email address, sometimes a mobile number. All of it is personal data: Article 4 of UK GDPR defines personal data as any information relating to an identified or identifiable person, and expressly lists a name and an online identifier among its examples.

The system can also see more than the form shows. Wi-Fi kit handles device identifiers — the sort of thing that ties a particular phone to a particular guest — and once tied to a person, those can be personal data on the same definition. Worth knowing before you assume "we only took an email" covers everything that was collected.

One boundary to draw early: PECR treats a text message as electronic mail, the same as an email. If a message would need consent to send by email, it needs the same consent by text. There is no side door through the phone number.

No. 05

The soft opt-in — exact conditions

You may have heard there's an exception to the consent rule: the "soft opt-in", from regulation 22 of PECR. There is — and it's narrower than the name suggests. It applies only when all three of these hold together:

  • You obtained the person's details in the course of a sale, or negotiations for one.
  • You market only your own similar products and services.
  • You offered a free, simple way to refuse when you collected the details — and you offer it again in every message.

The catch for venues sits in the first condition: a free Wi-Fi sign-in, on its own, is unlikely to count as a sale or sale negotiations. So don't build a guest list on the soft opt-in — get real consent, with the tick-box from No. 04. (A second soft opt-in arrived in February 2026; it applies to charities only, so it won't help a commercial venue.)

And whichever route a message relies on, regulation 23 holds throughout: every marketing email or text must say plainly who it's from, and must carry a valid address the guest can use to say stop.

No. 06

Keeping the receipts

Consent you can't prove is consent you don't have — that's how the law weighs it. UK GDPR places the burden of demonstrating consent on you, the controller: you must be able to show that each person on your list agreed. Not "guests generally tick the box" — this guest, on this date, shown this wording, ticking this box.

In practice that means four things per guest: who they are, when they signed in, the exact consent wording they were shown, and what they ticked. Sign-in wording changes over time, so the record has to keep the version each guest actually saw, not the version on the page today.

This is also where bought lists quietly fail. A list with no consent evidence behind it — however warmly the seller describes it — is a list you can't lawfully email. The receipts aren't bureaucracy; they're what makes the list usable at all.

No. 07

How long to keep it

How long may you keep a guest's details? The honest answer is that UK GDPR doesn't say: there is no fixed statutory retention period for marketing lists anywhere in it. What it does have, in Article 5, is the storage-limitation principle — keep personal data no longer than you need it for the purpose you collected it for.

So the duty isn't "keep it for X years". It's this: set a window you can justify (or the criteria you'll use, where a single number won't fit), state it in your privacy notice, and honour it — deletions included.

What's justifiable follows the rhythm of the venue. Picture two imaginary ones. The Copper Kettle, a café, writes to its regulars every month — it knows quickly when someone has lapsed, so a shorter window is easy to defend. The Bay Hotel sees its guests return by the season, and can reason its way to a longer one. Neither window is "the correct answer" — the test is whether you can say why yours fits your venue, and whether it actually runs.

No. 08

When a guest asks

Sooner or later a guest asks what you hold on them. That's the right of access — Article 15 of UK GDPR — and it has a defined shape: the guest is entitled to know whether you hold their data, to a copy of it, and to the story around it — what it's used for, how long it's kept. Free of charge, in normal cases.

On timing, for an access request: a month is the baseline, extendable by up to two further months where requests are complex or numerous. Keep your records in order and you're unlikely to need the extension — the answer becomes a lookup, not a project.

The other request to get right is shorter: "stop emailing me." An unsubscribe click, a reply that says stop, a word at the bar — each is an objection to direct marketing, and that right is absolute. No balancing test, no judgement call. Stop promptly, and make it permanent.

No. 09

Three myths, retired

Guest Wi-Fi attracts folklore. Three pieces of it, checked against the law:

"We must keep Wi-Fi logs for 12 months." As a general duty on a venue, this is false. Under the Investigatory Powers Act 2016, a duty to retain communications data arises only where the Secretary of State serves a retention notice on an operator — and even under a notice, twelve months is the most that can be required, not a floor for every venue with a router. Ordinary pubs, cafés and hotels are not, as a matter of course, served retention notices. And hoarding logs you have no purpose for sits badly with the storage-limitation principle from No. 07.

"It's public Wi-Fi, so GDPR doesn't apply." There is no such exemption. UK GDPR has no carve-out for guest networks, public Wi-Fi or small businesses — if you collect guests' details, you're processing personal data, and everything above applies.

"The Wi-Fi provider is responsible, not us." You decide why guest details are collected, so your venue is the data controller and the responsibility sits with you. A good provider makes the duties light work; it cannot take them off you.

No. 10

The checklist

The whole guide, as ten lines you could walk round the bar with:

  • The marketing box is its own tick — separate, optional, starting unticked.
  • The Wi-Fi works whether or not that box is ticked.
  • The sign-in wording names your venue and says what you'll send.
  • A privacy notice sits on the sign-in page itself.
  • Every guest has a consent record: who, when, and the wording they saw.
  • A retention window is set, stated — and actually runs.
  • Every message carries a working unsubscribe.
  • Opt-outs take effect promptly, and permanently.
  • You could answer "what do you hold on me?" without a scramble.
  • Your Wi-Fi provider's role is set out in a written contract — and texts are treated exactly like email.

If all ten hold at your venue, you're in good shape on the ground this guide covers. If a few don't, the fixes are specific — and none of them needs a lawyer on retainer so much as a system that does these things as a matter of course.

No. 11

Where Zest fits

Zest Wi-Fi is guest Wi-Fi built to help you stay compliant. The marketing opt-in is always separate. Every sign-in becomes a record of what each guest agreed to, and exactly when — and the history can't be quietly edited, by your team or by ours: versioned, timestamped, tamper-evident. Set a retention window per venue and older records delete themselves on schedule, with every deletion noted in the log. Acting on a deletion request takes two clicks — including connected marketing tools, and erased guests can't creep back onto the list. And when a guest asks what you hold, the subject-access export gives you a copy of everything you hold in one click — the data half of the answer.

If you run a pub, the pubs page shows all of this in your setting; cafés have their own page, and hotels theirs. This guide — and any that join it — lives on the guides page. To see how this website treats your data, read the privacy notice — it's short on purpose. And if a question is still nagging, write to us. We reply within one working day.

End of guide · Version 1.0 · 13 July 2026

General guidance, not legal advice — for your venue's specifics, ask your solicitor. Checked against the legislation: July 2026. Spotted something out of date? Email hello@netmo.it and we'll put it right.