Guest Wi-Fi and GDPR: How to Collect Customer Data the Right Way

Guest Wi-Fi is one of the cleanest ways for a hospitality business to collect customer data, provided it's set up properly. Done well, it gives you a consented, first-party list you can market to with confidence. Done badly, it creates compliance risk and a list full of people who never wanted to hear from you.

This guide covers the essentials for UK venues. It's general information rather than legal advice, so check your own setup with a qualified adviser.

Which rules apply?

In the UK, two sets of rules matter most:

  • UK GDPR and the Data Protection Act 2018 govern how you collect, store and use personal data.

  • PECR (Privacy and Electronic Communications Regulations) governs electronic marketing such as email and SMS.

The Information Commissioner's Office (ICO) is the regulator for both. Venues in the EU follow the EU GDPR and their national equivalent of PECR.

Separate Wi-Fi access from marketing consent

The most important principle: access to Wi-Fi and consent to marketing are two different things. Guests can be asked for details to use the Wi-Fi, but agreeing to receive marketing must be a separate, freely given choice.

In practice, that means:

  • A marketing opt-in checkbox that is not pre-ticked

  • Clear wording about what guests will receive (for example, "news, events and offers by email")

  • Guests can still connect if they don't opt in

What a compliant login page includes

  1. Who you are. Your business name, so guests know who is collecting their data.

  2. What you collect. Typically email, and optionally name, birthday or phone number.

  3. Why you collect it. Providing Wi-Fi, understanding visits, and, if they opt in, marketing.

  4. A link to your privacy notice. Explaining retention, rights and how to contact you.

  5. Separate, unticked marketing consent. Per channel if you'll use more than one, such as email and SMS.

  6. Acceptance of terms of use for the network itself.

Data minimisation

Only ask for what you'll actually use. If you won't send SMS, don't collect phone numbers. Shorter forms are also better for sign-up rates, so compliance and performance point the same way.

After collection: keep it clean

  • Honour unsubscribes immediately, and include an unsubscribe link in every message.

  • Keep records of consent: when and how each guest opted in.

  • Set a retention policy, and remove or anonymise data you no longer need.

  • Secure the data with access controls and a reputable platform.

  • Respond to rights requests, such as access or deletion, promptly.

Why consent improves results

Compliance isn't just a box to tick. Guests who actively choose to hear from you open more, click more and unsubscribe less. Lists built on genuine consent also protect your email deliverability, because there are fewer complaints. For more on this, see our article on why consent-based marketing performs better on the resources page.

Wi-Fi data is first-party data

Collected properly, guest Wi-Fi data is:

  • First-party: collected directly by you

  • Accurate: entered by the guest themselves

  • Lawfully collected: with clear consent

  • Owned by your business, not a third-party platform

Getting it right from day one

B-Connect guest Wi-Fi lets you design a branded login page with your own consent wording, so you control exactly what guests agree to. Book a demo to see the login flow and talk through your setup.

Your

customers

are

ready.

Is

your

business

ready?

Join our newsletter to stay upto date on features and realeases.

Stay up to date

By subscribing you agree to our Privacy Policy

Your

customers

are

ready.

Is

your

business

ready?

Join our newsletter to stay upto date on features and realeases.

Stay up to date

By subscribing you agree to our Privacy Policy

Your

customers

are

ready.

Is

your

business

ready?

Join our newsletter to stay upto date on features and realeases.

Stay up to date

By subscribing you agree to our Privacy Policy