Guest WiFi marketing laws by country: UK, EU, US, Canada and more
A captive portal that asks for a name, an email address or a mobile number turns every WiFi sign-in into personal data, and every marketing email or text sent afterwards falls under the electronic marketing law of the country the guest is in. Groups with venues in more than one country face different rules at each.
This guide compares the six markets CaptiFi prices in: the United Kingdom, Ireland and the wider EU, the United States, Canada, Australia and New Zealand. Every rule below was checked on 3 October 2026 against the regulator's guidance or the legislation itself, and each section links to the source. It is general information, written for venue owners, and it is not legal advice. Where a decision matters, check it with a solicitor or the regulator.
The rules at a glance
| Country | Marketing email | Marketing texts | Unsubscribe deadline | Regulators |
|---|---|---|---|---|
| United Kingdom | Consent, or the soft opt-in after a sale or negotiation | Same as email | Promptly; no fixed number of days | ICO |
| Ireland | Consent, or existing customers within 12 months of a sale or the last marketing email | Same as email | No fixed number of days | Data Protection Commission |
| United States | Opt-out under CAN-SPAM | Prior express written consent for autodialled texts (TCPA) | 10 business days | FTC (email), FCC (texts) |
| Canada | Express or implied consent under CASL | Same as email | 10 business days | CRTC, Office of the Privacy Commissioner |
| Australia | Express or inferred consent under the Spam Act | Same as email | 5 working days | ACMA, OAIC |
| New Zealand | Express, inferred or deemed consent under the UEMA | Same as email | 5 working days | Department of Internal Affairs, Privacy Commissioner |
The UK soft opt-in and Canada's implied consent from a business relationship are built around a purchase or an enquiry, and Australia's inferred consent needs an ongoing relationship. None of the regulators has said that signing in to free WiFi counts, and the UK regulator, in its guidance on the charity soft opt-in, gives a free guest WiFi sign-in at a charity's community cafe as bad practice, because it shows no interest in the charity's purposes. A marketing opt-in on the sign-in page is therefore the safe basis everywhere.
Making marketing consent a condition of the WiFi
Several regulators have addressed one pattern directly: putting marketing consent inside the terms that guests must accept to get online.
- The UK's ICO, in its guidance on when consent is appropriate, describes a cafe whose WiFi terms say that providing contact details is consent to marketing, and concludes: "This is not therefore valid consent."
- The GDPR, in Article 7(4), says that when assessing whether consent is freely given, "utmost account" is taken of whether a service "is conditional on consent to the processing of personal data that is not necessary" for it. The same text applies in the UK GDPR.
- Canada's PIPEDA says an organisation shall not, "as a condition of the supply of a product or service, require an individual to consent" to collection beyond what the service needs, and the CRTC says CASL consent requests "must not be subsumed in, or bundled with" general terms and conditions.
- In the United States, the TCPA's written consent for marketing texts must tell the person they are "not required to sign the agreement" as a condition of buying anything (47 CFR 64.1200).
- Australia's OAIC warns in its privacy principles guidelines that bundled consent "has the potential to undermine the voluntary nature of the consent".
The fix is the same in every country: give WiFi access on one decision and marketing on another, with a separate box that is not ticked in advance and is not required to get online.
United Kingdom
Personal data is governed by the UK GDPR and the Data Protection Act 2018, and electronic marketing by the Privacy and Electronic Communications Regulations (PECR). The ICO regulates both; on 30 September 2026 the Information Commissioner's Office became the Information Commission, still known as the ICO.
The ICO's position on email and text marketing is direct: "You must not send marketing emails or texts to individuals without specific consent." The exception for businesses, the soft opt-in in PECR regulation 22(3), needs the details to have been collected "in the course of the sale or negotiations for the sale of a product or service", the marketing to cover "similar products and services only", and a simple way to refuse both at collection and in every message. The ICO's test for negotiations is that people "must actively express an interest in buying", and in its guidance on the charity soft opt-in it gives a free guest WiFi sign-in at a community cafe as an example of bad practice. Every message must identify the sender and give a valid address for opting out, under regulation 23.
Guests must be told what is collected and why at the point of collection, under Article 13 of the UK GDPR, and an objection to direct marketing must be acted on: once someone objects, their data "shall no longer be processed" for that purpose. For online services relying on consent, children under 13 need a parent's consent.
The Data (Use and Access) Act 2025 changed two things that matter here. Since 5 February 2026 the ICO can fine up to £17.5 million or 4% of global turnover under PECR as well as the UK GDPR, against a previous PECR maximum of £500,000. And the UK GDPR now lists direct marketing as processing that may be carried out for a legitimate interest, which does not remove the PECR consent rule for emails and texts. The ICO notes that its consent guidance is under review following the Act. Our guest WiFi GDPR compliance checklist and the guide to importing a customer list under PECR cover the UK rules in more depth.
Ireland and the EU
Across the EU, personal data falls under the GDPR, and electronic marketing under each member state's implementation of Article 13 of the ePrivacy Directive. In Ireland that is S.I. No. 336 of 2011, regulation 13, alongside the Data Protection Act 2018, regulated by the Data Protection Commission. The DPC says electronic direct marketing "requires the clear, affirmative consent of the recipient (such as by specifically opting-in)".
Ireland's existing-customer exception is narrower than the UK's. It needs details obtained "in the context of the sale of a product or service", an objection offered at collection and in every message, and a sale "not more than 12 months prior", a window that restarts each time the details are used for a marketing email. The DPC says it applies only to existing customers, and a free WiFi sign-in is not a sale. Every message must identify the sender and give a valid address to stop further messages, and objections fall under GDPR Article 21, with rights requests answered "without undue delay and in any event within one month".
Ireland sets the age for a child's own consent to online services at 16. Breaching regulation 13 is a criminal offence for each message sent, with fines of up to €5,000 on summary conviction and up to €250,000 for a company on indictment, and GDPR fines reach €20 million or 4% of worldwide turnover. Other member states implement the ePrivacy rules in their own way, so a group with venues across the EU should check each country.
United States
Marketing email in the US is opt-out. CAN-SPAM needs no prior consent, according to the FTC's compliance guide, but every message must have accurate header information and an honest subject line, disclose "clearly and conspicuously" that it is an advertisement unless the recipient opted in beforehand, include "your valid physical postal address", and explain how to opt out. The opt-out must keep working for at least 30 days after sending, and "You must honor a recipient's opt-out request within 10 business days." Each email in breach can cost up to $53,088, a figure the FTC confirmed on 15 September 2026 would stay unchanged for 2026.
Marketing texts are stricter. Under the TCPA, autodialled marketing calls and texts to mobiles need "the prior express written consent of the called party", which can be an electronic signature but must say it is not a condition of purchase. A reply such as STOP, QUIT, END, CANCEL or UNSUBSCRIBE revokes it and must be honoured "within a reasonable time not to exceed ten business days". People can sue for $500 per violation, up to three times that for wilful breaches.
There is no general federal privacy law, but state laws apply on top. The largest is California's CCPA, as amended by the CPRA, which covers for-profit businesses with annual gross revenue over $26,625,000 (the adjusted figure since 1 January 2025), businesses that buy, sell or share the personal information of 100,000 or more consumers or households a year, or those earning half their revenue from selling or sharing it. A single restaurant collecting WiFi emails for its own marketing would normally fall below all three, although a venue controlled by a covered business and sharing its branding can be covered. Covered businesses must give notice at or before collection and, if they sell or share personal information, offer a "Do Not Sell or Share My Personal Information" link. COPPA applies to collecting data from children under 13 online.
Canada
Canada's Anti-Spam Legislation (CASL) is consent-based for email and texts alike: a commercial electronic message may be sent only if the recipient "has consented to receiving it, whether the consent is express or implied". Implied consent from an existing business relationship covers a purchase within the previous two years, or an enquiry or application within the previous six months. The CRTC has not said whether a free WiFi login counts.
An express consent request must be sought separately and name the business, give a mailing address and a phone number, email or web address, and say that consent can be withdrawn. Every message must identify the sender, give the same contact details, and carry a free unsubscribe mechanism that stays valid for at least 60 days and takes effect "without delay, and in any event no later than 10 business days". Penalties reach CA$10 million per violation for a business.
Privacy falls under PIPEDA, overseen by the Office of the Privacy Commissioner, which says purposes should be identified at or before collection and that children under 13 generally need a parent's consent. Alberta, British Columbia and Quebec have their own private-sector privacy laws that apply within those provinces, and in Quebec the Commission d'accès à l'information enforces Law 25.
Australia
The Spam Act 2003, enforced by ACMA, requires consent for marketing email and texts: express consent, or consent that can reasonably be inferred from the person's conduct and their relationship with the business. ACMA describes inferred consent as "usually when a person has a provable, ongoing relationship with your business" and says it does not cover messages sent after someone has just bought something, so there is no equivalent of the UK soft opt-in for a one-off purchase. Every message must identify the sender, give accurate contact details and include a free unsubscribe that works for at least 30 days, does not need a login, and is honoured within 5 working days.
The Privacy Act 1988 and the Australian Privacy Principles, overseen by the OAIC, require a collection notice "at or before the time of collection, or as soon as practicable afterwards". Businesses with annual turnover of A$3 million or less are generally exempt from the Privacy Act, but not if they trade in personal information, provide a health service or fall into the other categories the OAIC lists. The Spam Act has no size exemption. Where assessing each person's capacity is not practicable, the OAIC lets organisations presume that someone aged 15 or over can consent for themselves.
New Zealand
The Unsolicited Electronic Messages Act 2007, enforced by the Department of Internal Affairs, allows commercial messages "only when you have express consent, inferred consent, or deemed consent". DIA says inferred consent "tends to take place when an address-holder provides their electronic address during the process of purchasing goods and services" and is limited in its application; deemed consent covers addresses published in a business capacity and does not apply to WiFi guests. Every message must identify the business and how to contact it, include a free unsubscribe, and "You must honour a request to unsubscribe within five working days." DIA puts the maximum fine at NZ$500,000.
The Privacy Act 2020 sets the collection rules. Collect only what you need for a lawful purpose, collect it from the person, and take reasonable steps so they know why it is being collected, who will receive it and whether giving it is voluntary. The Privacy Commissioner asks for particular care when collecting from children and young people.
One setup that works in every country
One sign-in page can meet all six sets of rules if it follows these steps.
- Give WiFi access on its own, with no marketing condition attached.
- Ask for marketing consent with a separate box per channel, one for email and one for texts, neither ticked in advance.
- Word the consent request with the venue's name, postal address and contact details and a line saying consent can be withdrawn, as CASL requires; for marketing texts in the US, add that the guest agrees to receive automated marketing texts and that agreeing is not a condition of buying anything.
- Show a short privacy notice on the page saying what you collect, why, and how to opt out.
- Record when each guest agreed, and to which channel.
- Identify the venue in every message, with a postal address and contact details, which CAN-SPAM and CASL both require.
- Put an unsubscribe link in every message and apply it straight away, inside the 5 working days Australia and New Zealand allow.
- Where the venue serves young people, ask for a date of birth and set a minimum age.
On CaptiFi, marketing consent is asked separately from getting online: on the standard sign-in page it is its own question after the guest taps Connect, with Accept and Reject buttons, and email and SMS consent are recorded separately for each guest, with a timestamp. Only guests who opted in are emailed. Marketing emails carry one-click unsubscribe headers and a footer link, and an unsubscribe is applied at the click across every venue, as the guide to Gmail and Yahoo unsubscribe rules describes. The splash page can ask for a date of birth with a minimum age. The GDPR compliance page covers the rest.
This guide is general information, not legal advice, checked on 3 October 2026 against the sources linked in each section: the ICO and legislation.gov.uk; EUR-Lex, the Irish Statute Book and the Data Protection Commission; the FTC, eCFR and the California Privacy Protection Agency; the Justice Laws website, the CRTC and the Office of the Privacy Commissioner of Canada; legislation.gov.au, ACMA and the OAIC; legislation.govt.nz, the Department of Internal Affairs and the New Zealand Privacy Commissioner. Laws and guidance change, and the ICO's consent guidance is under review; check the current position before relying on it.
Frequently asked questions
Quick answers to the most common questions about this topic.
Which countries need consent before emailing WiFi guests?
Do other countries have an equivalent of the UK soft opt-in?
Which countries rule out bundling marketing consent into WiFi terms?
How quickly do I have to process an unsubscribe?
Does California's CCPA apply to my restaurant's guest WiFi?
What must every marketing email to WiFi guests include?
Does a WiFi login give implied consent under Canada's CASL?
The CaptiFi Editorial Team writes about guest WiFi marketing, captive portals, GDPR-compliant data capture, and local SEO for venue operators. We base our recommendations on real customer outcomes and verified third-party reviews from G2.com.
Ready to turn your guest WiFi into a marketing engine?
CaptiFi captures customer data from every WiFi login, automates Google reviews and email follow-ups, and plugs into the tools you already use. Hardware included (refundable deposit), transparent pricing, 30-day free trial.