Guest WiFi and privacy rules in plain language
What the GDPR, California's privacy law and the Dutch Caribbean ordinances mean for the moment a guest types an email address into your WiFi login. This is a plain language summary of public sources, not legal advice: check anything you rely on with a qualified adviser where you operate.
The one idea every set of rules shares
Picture the table of four at a beach bar who join the WiFi to split the bill on their phones. They want the connection. Some of them might want your Friday news; most will not. Every law on this page, in its own words, protects that difference: getting online is one thing, agreeing to hear from you is another.
The rest of this page shows where each rule comes from, so you can check it rather than take our word for it. Sources were read on 7 October 2026.
Europe and the UK: the GDPR
The GDPR applies to businesses established in the EU, and to some outside it when they offer goods or services to people who are in the EU (Article 3). The UK keeps its own copy, the UK GDPR, with the same core consent rules, supervised by the ICO.
Article 3(2) is the part that reaches beyond Europe, and the one a Caribbean venue should know. It brings a business outside the EU under the GDPR when it offers goods or services to people who are in the EU, or monitors their behaviour while they are there. A guest on your WiFi in Willemstad or Philipsburg is not in the EU at that moment; emailing offers to European guests once they are home is the kind of activity to check with an adviser.
A lawful basis for each use
Every use of personal data needs one of six lawful bases listed in Article 6(1), among them consent, a contract with the person, and legitimate interests. Running the network and sending offers are different purposes, and each needs its own basis. For marketing email, consent is the usual one.
What valid consent looks like
Article 4(11) defines consent as a freely given, specific, informed and unambiguous indication of the person’s wishes, by a statement or a clear affirmative action. The ICO’s guidance adds that silence, pre ticked boxes or inactivity should not count as consent. A box the guest has to tick themselves is the clear affirmative action.
Not bundled with the WiFi
When deciding whether consent was freely given, Article 7(4) says utmost account is taken of whether a service is made conditional on consent to processing that the service does not need. Sending offers is not needed to provide WiFi, and Article 7(2) says a consent request must be clearly distinguishable from other matters, so the marketing box should not hide inside the terms.
Withdrawal as easy as giving it
Article 7(3) gives the guest the right to withdraw consent at any time and says it must be as easy to withdraw as to give. Article 7(1) puts the burden of proof on the business: you must be able to demonstrate that the person consented. Separately, Article 21(2) lets anyone object at any time to their data being used for direct marketing.
Collect less, and say what you collect
Article 5(1) requires data to be processed in a transparent manner and to be limited to what is necessary for the purpose, which the law calls data minimisation. Article 13 lists what to tell people at the moment you collect from them, including who you are, your purposes and legal basis, and who receives the data. That is the job of a privacy notice linked from the login.
California: the CCPA, as amended by the CPRA
California’s law works differently: rather than consent before collection, it gives residents rights and sets duties for larger businesses. According to the California Attorney General, it applies to for profit businesses that meet any one of three tests: gross annual revenue over 25 million dollars, buying, selling or sharing the personal information of 100,000 or more California residents or households, or earning 50 percent or more of annual revenue from selling or sharing California residents’ personal information. The revenue figure is adjusted for inflation; the California Privacy Protection Agency lists $26,625,000 at the time of writing.
Where it applies, a business must give a notice at collection listing the categories of personal information it collects and what it uses them for. Residents can ask to know what was collected, ask for it to be deleted, ask the business to stop selling or sharing it, ask for corrections, limit the use of sensitive information, and exercise these rights without being treated worse for it.
For a large hotel in Los Angeles, the WiFi login is a collection point, so the notice belongs there.
The Dutch Caribbean: four places, four regimes
The GDPR does not apply in the Caribbean part of the Kingdom of the Netherlands. A paper by the Dutch parliamentary delegation for the interparliamentary Kingdom consultations says so directly, adds that each Caribbean country has its own ordinances, and describes work on a shared Kingdom act to harmonise them. Until that happens, a venue in Willemstad and one in Philipsburg follow different texts.
Curaçao
Curaçao has the Landsverordening bescherming persoonsgegevens, its national ordinance on the protection of personal data. The Staten van Curaçao describe it as the general framework for processing personal data, which also creates an independent supervisor, and say that supervisor is still being prepared.
Sint Maarten
Sint Maarten has its own Landsverordening bescherming persoonsgegevens. In a memo to the Parliament of Sint Maarten, the Minister of Justice says it covers the public and private sectors, gives people rights of access, rectification and objection, and provides for a supervisory committee that is established by law but has not yet been constituted.
Aruba
Aruba has its own legislation too, separate from both the GDPR and its neighbours. We could not read an official text of it, so we state no specifics here. Check with the Government of Aruba or a local adviser before you rely on any summary, including ours.
Bonaire, Sint Eustatius and Saba
The Caribbean Netherlands follow the Wet bescherming persoonsgegevens BES. It defines consent as a free, specific and informed expression of will (Article 1), lists unambiguous consent among the grounds for processing (Article 8), lets anyone object free of charge, at any time, to their data being used for commercial approaches (Article 33), and is supervised by the Commissie toezicht bescherming persoonsgegevens BES (Article 44).
Marketing email has its own rules
Data protection law decides whether you may hold and use the email address. Separate rules decide what a marketing email must look like and who may receive one.
- United States. The federal law on commercial email, explained in the FTC’s compliance guide, requires accurate headers and subject lines, a clear statement that the message is an advertisement, a valid physical postal address, and a clear way to opt out, honoured within 10 business days.
- United Kingdom. Under PECR, the ICO says you must not send marketing email to individuals unless they specifically consented, or they are existing customers who bought or negotiated to buy something similar and were given a chance to opt out.
- European Union. Marketing messages also fall under national rules based on the ePrivacy Directive, which sits alongside the GDPR.
The rules side by side
| Rule | Who it covers | What it means for a WiFi login | Source |
|---|---|---|---|
| GDPR (EU) | Businesses in the EU, and some outside it serving people in the EU | A lawful basis per use; marketing consent freely given, specific, informed, unambiguous; not a condition of the WiFi; easy to withdraw | Regulation 2016/679 |
| UK GDPR and PECR | Businesses in the UK | Same consent standard; no pre ticked boxes; marketing email needs consent or the existing customer exception | ICO |
| CCPA as amended by the CPRA | For profit businesses over any of three thresholds, for California residents | Notice at collection on the login; honour requests to know, delete, correct and opt out of sale or sharing | California AG |
| US federal commercial email law | Anyone sending commercial email | Postal address, honest subject, clear opt out honoured within 10 business days | FTC |
| Landsverordening bescherming persoonsgegevens (Curaçao) | Processing of personal data in Curaçao | General rules for processing; supervisor in preparation | Staten van Curaçao |
| Landsverordening bescherming persoonsgegevens (Sint Maarten) | Public and private sectors in Sint Maarten | Rights of access, rectification and objection; supervisor not yet constituted | Parliament of Sint Maarten |
| Aruba | Processing in Aruba | Check with the Government of Aruba or a local adviser | No official text read |
| Wet bescherming persoonsgegevens BES | Bonaire, Sint Eustatius and Saba | Unambiguous consent as a ground; free objection to commercial use at any time | wetten.overheid.nl |
How the VoqadoWiFi login lines up
The guest login was built around the separation these rules describe. What it does by default:
- The WiFi terms checkbox, “I accept the WiFi terms of use”, is separate from marketing consent, and accepting the terms is never treated as marketing consent.
- The marketing box starts unticked on the explicit consent form, the default for venues created from now on and switched on by the owner for an existing venue, with wording like “Email me offers and news from” your venue.
- Every consent choice is stored with the exact wording shown, a wording version, the time and the source, in an append only log.
- Every email links to a preference centre where the guest can stop messages from one venue with one tap, unsubscribe from every venue of that business, or ask for their data to be deleted. One click unsubscribe headers are set.
- Returning guests see a welcome back card instead of the form, and that card never records consent again.
Your legal basis, retention period and notice wording stay your decisions. Start from the privacy notice template and the WiFi terms template, then have an adviser fill the gaps.
Questions
Can I make guests agree to marketing emails before they get WiFi?
Does the GDPR apply to a venue in Curaçao, Sint Maarten, Aruba or Bonaire?
Does the California law apply to a small cafe?
What should I keep as proof that a guest agreed?
Is this page legal advice?
Keep reading
Not legal advice. Sources were read on 7 October 2026 and laws change; follow the links and confirm with an adviser where you operate.
Start a guest list with consent built in
Separate WiFi terms and an unticked marketing box by default for new venues. One location and 500 guest logins a month free on the Starter plan, no card.