Skip to content
Resource guide

Guest WiFi and privacy rules in plain language

What the GDPR, California's privacy law and the Dutch Caribbean ordinances mean for the moment a guest types an email address into your WiFi login. This is a plain language summary of public sources, not legal advice: check anything you rely on with a qualified adviser where you operate.

What do privacy rules require from a guest WiFi login?
Keep two decisions apart. Guests accept the WiFi terms to get online; marketing is a separate, unticked choice they can skip. Say plainly who you are, what you collect and why, keep proof of what each guest agreed to, and make it easy to stop messages or ask for their data to be deleted.

The one idea every set of rules shares

Picture the table of four at a beach bar who join the WiFi to split the bill on their phones. They want the connection. Some of them might want your Friday news; most will not. Every law on this page, in its own words, protects that difference: getting online is one thing, agreeing to hear from you is another.

The rest of this page shows where each rule comes from, so you can check it rather than take our word for it. Sources were read on 7 October 2026.

Europe and the UK: the GDPR

The GDPR applies to businesses established in the EU, and to some outside it when they offer goods or services to people who are in the EU (Article 3). The UK keeps its own copy, the UK GDPR, with the same core consent rules, supervised by the ICO.

Article 3(2) is the part that reaches beyond Europe, and the one a Caribbean venue should know. It brings a business outside the EU under the GDPR when it offers goods or services to people who are in the EU, or monitors their behaviour while they are there. A guest on your WiFi in Willemstad or Philipsburg is not in the EU at that moment; emailing offers to European guests once they are home is the kind of activity to check with an adviser.

A lawful basis for each use

Every use of personal data needs one of six lawful bases listed in Article 6(1), among them consent, a contract with the person, and legitimate interests. Running the network and sending offers are different purposes, and each needs its own basis. For marketing email, consent is the usual one.

What valid consent looks like

Article 4(11) defines consent as a freely given, specific, informed and unambiguous indication of the person’s wishes, by a statement or a clear affirmative action. The ICO’s guidance adds that silence, pre ticked boxes or inactivity should not count as consent. A box the guest has to tick themselves is the clear affirmative action.

Not bundled with the WiFi

When deciding whether consent was freely given, Article 7(4) says utmost account is taken of whether a service is made conditional on consent to processing that the service does not need. Sending offers is not needed to provide WiFi, and Article 7(2) says a consent request must be clearly distinguishable from other matters, so the marketing box should not hide inside the terms.

Withdrawal as easy as giving it

Article 7(3) gives the guest the right to withdraw consent at any time and says it must be as easy to withdraw as to give. Article 7(1) puts the burden of proof on the business: you must be able to demonstrate that the person consented. Separately, Article 21(2) lets anyone object at any time to their data being used for direct marketing.

Collect less, and say what you collect

Article 5(1) requires data to be processed in a transparent manner and to be limited to what is necessary for the purpose, which the law calls data minimisation. Article 13 lists what to tell people at the moment you collect from them, including who you are, your purposes and legal basis, and who receives the data. That is the job of a privacy notice linked from the login.

California: the CCPA, as amended by the CPRA

California’s law works differently: rather than consent before collection, it gives residents rights and sets duties for larger businesses. According to the California Attorney General, it applies to for profit businesses that meet any one of three tests: gross annual revenue over 25 million dollars, buying, selling or sharing the personal information of 100,000 or more California residents or households, or earning 50 percent or more of annual revenue from selling or sharing California residents’ personal information. The revenue figure is adjusted for inflation; the California Privacy Protection Agency lists $26,625,000 at the time of writing.

Where it applies, a business must give a notice at collection listing the categories of personal information it collects and what it uses them for. Residents can ask to know what was collected, ask for it to be deleted, ask the business to stop selling or sharing it, ask for corrections, limit the use of sensitive information, and exercise these rights without being treated worse for it.

For a large hotel in Los Angeles, the WiFi login is a collection point, so the notice belongs there.

The Dutch Caribbean: four places, four regimes

The GDPR does not apply in the Caribbean part of the Kingdom of the Netherlands. A paper by the Dutch parliamentary delegation for the interparliamentary Kingdom consultations says so directly, adds that each Caribbean country has its own ordinances, and describes work on a shared Kingdom act to harmonise them. Until that happens, a venue in Willemstad and one in Philipsburg follow different texts.

Curaçao

Curaçao has the Landsverordening bescherming persoonsgegevens, its national ordinance on the protection of personal data. The Staten van Curaçao describe it as the general framework for processing personal data, which also creates an independent supervisor, and say that supervisor is still being prepared.

Sint Maarten

Sint Maarten has its own Landsverordening bescherming persoonsgegevens. In a memo to the Parliament of Sint Maarten, the Minister of Justice says it covers the public and private sectors, gives people rights of access, rectification and objection, and provides for a supervisory committee that is established by law but has not yet been constituted.

Aruba

Aruba has its own legislation too, separate from both the GDPR and its neighbours. We could not read an official text of it, so we state no specifics here. Check with the Government of Aruba or a local adviser before you rely on any summary, including ours.

Bonaire, Sint Eustatius and Saba

The Caribbean Netherlands follow the Wet bescherming persoonsgegevens BES. It defines consent as a free, specific and informed expression of will (Article 1), lists unambiguous consent among the grounds for processing (Article 8), lets anyone object free of charge, at any time, to their data being used for commercial approaches (Article 33), and is supervised by the Commissie toezicht bescherming persoonsgegevens BES (Article 44).

Marketing email has its own rules

Data protection law decides whether you may hold and use the email address. Separate rules decide what a marketing email must look like and who may receive one.

  • United States. The federal law on commercial email, explained in the FTC’s compliance guide, requires accurate headers and subject lines, a clear statement that the message is an advertisement, a valid physical postal address, and a clear way to opt out, honoured within 10 business days.
  • United Kingdom. Under PECR, the ICO says you must not send marketing email to individuals unless they specifically consented, or they are existing customers who bought or negotiated to buy something similar and were given a chance to opt out.
  • European Union. Marketing messages also fall under national rules based on the ePrivacy Directive, which sits alongside the GDPR.

The rules side by side

Privacy rules for a guest WiFi login, sources read on 7 October 2026. Not legal advice.
RuleWho it coversWhat it means for a WiFi loginSource
GDPR (EU)Businesses in the EU, and some outside it serving people in the EUA lawful basis per use; marketing consent freely given, specific, informed, unambiguous; not a condition of the WiFi; easy to withdrawRegulation 2016/679
UK GDPR and PECRBusinesses in the UKSame consent standard; no pre ticked boxes; marketing email needs consent or the existing customer exceptionICO
CCPA as amended by the CPRAFor profit businesses over any of three thresholds, for California residentsNotice at collection on the login; honour requests to know, delete, correct and opt out of sale or sharingCalifornia AG
US federal commercial email lawAnyone sending commercial emailPostal address, honest subject, clear opt out honoured within 10 business daysFTC
Landsverordening bescherming persoonsgegevens (Curaçao)Processing of personal data in CuraçaoGeneral rules for processing; supervisor in preparationStaten van Curaçao
Landsverordening bescherming persoonsgegevens (Sint Maarten)Public and private sectors in Sint MaartenRights of access, rectification and objection; supervisor not yet constitutedParliament of Sint Maarten
ArubaProcessing in ArubaCheck with the Government of Aruba or a local adviserNo official text read
Wet bescherming persoonsgegevens BESBonaire, Sint Eustatius and SabaUnambiguous consent as a ground; free objection to commercial use at any timewetten.overheid.nl

How the VoqadoWiFi login lines up

The guest login was built around the separation these rules describe. What it does by default:

  • The WiFi terms checkbox, “I accept the WiFi terms of use”, is separate from marketing consent, and accepting the terms is never treated as marketing consent.
  • The marketing box starts unticked on the explicit consent form, the default for venues created from now on and switched on by the owner for an existing venue, with wording like “Email me offers and news from” your venue.
  • Every consent choice is stored with the exact wording shown, a wording version, the time and the source, in an append only log.
  • Every email links to a preference centre where the guest can stop messages from one venue with one tap, unsubscribe from every venue of that business, or ask for their data to be deleted. One click unsubscribe headers are set.
  • Returning guests see a welcome back card instead of the form, and that card never records consent again.

Your legal basis, retention period and notice wording stay your decisions. Start from the privacy notice template and the WiFi terms template, then have an adviser fill the gaps.

Questions

Can I make guests agree to marketing emails before they get WiFi?
Under the GDPR and UK GDPR that is the bundling Article 7(4) warns against. Give the WiFi on its own terms and ask about marketing separately, with an unticked box.
Does the GDPR apply to a venue in Curaçao, Sint Maarten, Aruba or Bonaire?
An official Dutch parliamentary paper states that the GDPR does not apply in the Caribbean part of the Kingdom and that each country has its own ordinances. If you also target people who are in the EU, ask an adviser.
Does the California law apply to a small cafe?
Only if it meets one of the three thresholds the California Attorney General lists, covered above. Most small single site venues do not, but check.
What should I keep as proof that a guest agreed?
The wording the guest saw, when they agreed, and how. Article 7 of the GDPR says the business must be able to demonstrate consent. VoqadoWiFi stores each choice with the exact wording, a wording version, the time and the source.
Is this page legal advice?
No. It is a plain language summary of public sources, checked on the date shown. Ask a qualified adviser where you operate before you rely on it.

Keep reading

Guest WiFi privacy notice templateGuest WiFi terms of use templateWhat makes a good WiFi landing pageHow post visit campaigns workCompliance and data handling

Not legal advice. Sources were read on 7 October 2026 and laws change; follow the links and confirm with an adviser where you operate.

Start a guest list with consent built in

Separate WiFi terms and an unticked marketing box by default for new venues. One location and 500 guest logins a month free on the Starter plan, no card.

Free forever plan. No credit card and no sales call.