Knowledge Hub

Guest WiFi GDPR & PECR Compliance UK

Published August 2026 · Telexico Connect

Collecting customer data through guest WiFi is both legal and commercially powerful — but it must be done correctly. This guide explains what UK GDPR and PECR require for guest WiFi data capture and marketing.

The two regulations that apply

UK GDPR (Data Protection Act 2018)

Governs the collection, processing and storage of personal data. Applies when you collect name, mobile, email or any other data that can identify an individual through your guest WiFi.

PECR (Privacy and Electronic Communications Regulations)

Governs electronic marketing — SMS and email communications sent to individuals. If you want to send marketing messages to WiFi-captured contacts, PECR requires explicit prior consent (or a valid "soft opt-in" exception).

The correct consent architecture

The most common mistake in guest WiFi data capture is making marketing consent a condition of WiFi access. This is a GDPR violation. The correct approach separates two distinct consent actions:

Step 1 — WiFi Terms (required for access): The guest accepts your acceptable use policy to access the network. This is legitimate — you can require guests to agree to terms.

Step 2 — Marketing consent (optional, never pre-ticked): Separate, unticked checkboxes for SMS marketing and email marketing. The guest chooses whether to opt in. WiFi access is available regardless.

What data you can legally capture

  • Name, mobile, email — standard and straightforward with consent
  • Date of birth — for birthday clubs; specify the purpose clearly
  • Vehicle registration — for automotive venues; DVLA data retrieval is permitted for legitimate business purposes
  • Dietary preference, fitness goal, visit reason — industry-specific optional fields with clear explanation

You should not collect sensitive personal data (health, ethnicity, religion etc.) through a guest WiFi portal without a clear, proportionate legal basis.

Google review requests and PECR

Inviting customers to leave a Google review is not electronic marketing under PECR — it is a service communication. You can send a review invitation without a specific marketing opt-in, provided it is a genuine invitation to share their experience and not conditional on giving a positive rating.

Review gating is prohibited by Google policy — selectively sending review invitations only to customers who first gave you a high private rating. Every customer should receive the same genuine invitation.

Data retention

UK GDPR requires you to keep data only as long as necessary for the purpose for which it was collected. For WiFi marketing data, common approaches are:

  • Marketing contact data: retained until the customer withdraws consent or you have not communicated in 24+ months
  • Consent audit trail: retained for 7 years (recommended for legal compliance demonstration)
  • Visit logs: typically 12 months for analytics purposes

Customer rights you must support

  • Right to access — customers can request a copy of their data
  • Right to erasure — customers can request deletion of their data
  • Right to withdraw consent — SMS must include unsubscribe; email must include unsubscribe link
  • Right to data portability — customers can request their data in a portable format

How Telexico Connect handles compliance

Telexico Connect is built with UK GDPR and PECR compliance by design. WiFi access and marketing consent are always separated. Checkboxes are never pre-ticked. Every capture includes a timestamp, consent wording version and venue record. Customers can request deletion through our standard process.

FAQ

Related questions

Do I need a Privacy Policy to capture WiFi data?+
Yes. You must have a Privacy Policy that explains what data you collect, why, how it is used, how long it is kept and how customers can exercise their rights. Telexico Connect portals link to your Privacy Policy — you must create and maintain this document.
Can I send marketing to WiFi contacts who didn't tick the SMS box?+
No. UK PECR requires explicit prior consent for SMS marketing. You can only send SMS to customers who specifically opted in at the WiFi login screen. The "soft opt-in" exception (for existing customers) may apply in limited circumstances — check with your legal adviser.
Is date of birth sensitive data under GDPR?+
Date of birth alone is not classified as special category sensitive data under UK GDPR. However, it must be collected with a clear stated purpose (birthday club automation), stored securely and deleted on request.

Ready to own your customers?

Build your portal in 30 seconds. Free trial. No card.

✨ Start FreeFrom £5/month →