Published August 2026 · Telexico Connect
Collecting customer data through guest WiFi is both legal and commercially powerful — but it must be done correctly. This guide explains what UK GDPR and PECR require for guest WiFi data capture and marketing.
Governs the collection, processing and storage of personal data. Applies when you collect name, mobile, email or any other data that can identify an individual through your guest WiFi.
Governs electronic marketing — SMS and email communications sent to individuals. If you want to send marketing messages to WiFi-captured contacts, PECR requires explicit prior consent (or a valid "soft opt-in" exception).
The most common mistake in guest WiFi data capture is making marketing consent a condition of WiFi access. This is a GDPR violation. The correct approach separates two distinct consent actions:
Step 1 — WiFi Terms (required for access): The guest accepts your acceptable use policy to access the network. This is legitimate — you can require guests to agree to terms.
Step 2 — Marketing consent (optional, never pre-ticked): Separate, unticked checkboxes for SMS marketing and email marketing. The guest chooses whether to opt in. WiFi access is available regardless.
You should not collect sensitive personal data (health, ethnicity, religion etc.) through a guest WiFi portal without a clear, proportionate legal basis.
Inviting customers to leave a Google review is not electronic marketing under PECR — it is a service communication. You can send a review invitation without a specific marketing opt-in, provided it is a genuine invitation to share their experience and not conditional on giving a positive rating.
Review gating is prohibited by Google policy — selectively sending review invitations only to customers who first gave you a high private rating. Every customer should receive the same genuine invitation.
UK GDPR requires you to keep data only as long as necessary for the purpose for which it was collected. For WiFi marketing data, common approaches are:
Telexico Connect is built with UK GDPR and PECR compliance by design. WiFi access and marketing consent are always separated. Checkboxes are never pre-ticked. Every capture includes a timestamp, consent wording version and venue record. Customers can request deletion through our standard process.
Build your portal in 30 seconds. Free trial. No card.
✨ Start FreeFrom £5/month →