Public WiFi: Legal Obligations for Businesses on the French Riviera
Back to news
Législation

Public WiFi: Legal Obligations for Businesses on the French Riviera

Fabricio — Riviera Connect
July 4, 2025
Offering public WiFi has become essential for hotels, cafés, restaurants and coworking spaces. But few establishments realise: as soon as you open internet access to third parties, French law treats you as an electronic communications operator, with precise data-retention and user-information obligations. This guide covers the legal framework that actually applies — the relevant articles of the CPCE, retention periods, GDPR — and gives you two directly usable tools: a template text for your captive portal and a compliance checklist.

Who is concerned — and who legally counts as an "access provider"?

This is the most misunderstood point. Article L34-1 of the French Post and Electronic Communications Code (CPCE) covers not only telecom operators but also "persons who, as a main or ancillary professional activity, offer the public a connection enabling online communication via network access". In other words: the hotel that gives guests the WiFi code, the café advertising "free WiFi", the coworking space, the media library, the campsite — all take on part of an access provider's obligations, even though the internet subscription is with Orange or SFR.

Your ISP remains responsible for the line; you are responsible for the access you redistribute. The size of the establishment is irrelevant: a twenty-seat tea room is covered just like a palace hotel.

Legal obligations of public WiFi for premises open to the public

The legal framework in three texts

The CPCE (article L34-1) sets the principle: connection data must be retained and be producible to authorised authorities (courts, investigators) upon requisition. The regime was clarified by decree no. 2021-1362 of 20 October 2021, which distinguishes data categories and their retention periods.

The LCEN (2004 law on confidence in the digital economy) completes the framework on the liability of technical intermediaries.

GDPR and the French Data Protection Act govern the processing: connection data is personal data. You must inform users, limit collection to what's necessary, secure storage and honour access and erasure rights (the latter doesn't apply to data whose retention is a legal obligation). The CNIL publishes practical guidance dedicated to publicly open WiFi — a useful reference in case of doubt.

Which data to keep, and for how long?

The retention periods applicable in practice, per the CPCE and its implementing decree:

  • User's civil identity (if you collect it: first and last name): 5 years after the end of the relationship.
  • Information provided at registration (email, account ID, payment data where applicable): 1 year.
  • Technical connection data (assigned IP address, technical identifier such as MAC address, date, time and duration of each connection): 1 year — the minimum baseline every establishment must be able to produce.


And crucially, what you must not keep: the content of communications and detailed browsing history (sites visited). The law requires knowing who connected, when, with which address — not what they did. Keeping more than necessary isn't prudence: it's a GDPR violation.

In practice, this logging is handled by a professional router or WiFi controller, with timestamped export and secure backup. Consumer hardware is rarely capable of it.

What it means for your line of business

Hotel. A captive portal with per-room vouchers naturally ticks the boxes: each session is tied to a stay, logs are clean, and the legal notice shows at connection. Watch out: PMS guest data and WiFi logs must remain in separate systems.

Café / restaurant. One-click access with displayed terms is enough — named identification is not mandatory. What matters: technical logging genuinely running, and the public network isolated from the till and payment terminal.

Coworking. The most demanding case: users are recurring, often identified (member account), and usage is heavy. The "identity 5 years / account 1 year / technical 1 year" periods fully apply, and separation between the members' network and the visitors' network must be strict. The recommended architecture matches that of business guest WiFi: VLANs, captive portal, client isolation.

Template text for your captive portal

Here is a base text to adapt (company name, contact details, session durations) and have validated for your situation:

"By connecting to this WiFi network, you accept these terms of use. In accordance with article L34-1 of the French Post and Electronic Communications Code, [Establishment name] retains technical connection data (IP addresses and technical identifiers, connection dates, times and durations) for 12 months. This data may be disclosed to legally authorised authorities upon requisition. It is not used for any commercial purpose and does not cover the content of your communications. Data controller: [Name, address]. To exercise your access and rectification rights: [contact email]. Access is provided for [X hours] and may be suspended in case of abusive or unlawful use."


If you additionally collect an email for marketing, add a separate, un-ticked consent box: GDPR consent is never inferred from accepting the terms of use.

Public WiFi compliance checklist

  • Logging active: IP, technical identifier, date/time/duration of each session, reliable timestamps (NTP).
  • 12-month retention of technical data, backed up off-site or on secure storage.
  • Requisition procedure tested: you can extract the logs for a given period within a day, and you know who is authorised to do it.
  • Public network isolated from the internal network (VLAN, firewall) — legal compliance doesn't cover the damage of an intrusion.
  • User information displayed on the captive portal (template above) and reflected in your privacy policy.
  • Minimal collection: no browsing history, no content, no marketing data without separate consent.
  • Log access restricted to authorised persons, with an audit trail of consultations.
  • GDPR register up to date: the "public WiFi" processing is listed with its purposes and retention periods.


If you're missing one point, it's most often compliant logging or the extraction procedure — both solved with suitable equipment and an hour of configuration.

Risks and getting compliant

Failure to retain connection data carries criminal penalties for the responsible party (up to one year's imprisonment and a €75,000 fine for individuals under article L39-3 of the CPCE), and GDPR breaches fall under CNIL sanctions. Beyond the texts, the concrete risk is operational: a judicial requisition you cannot answer, or a security incident originating from your open WiFi.

Getting compliant is rarely heavy: an audit of the existing setup, the right equipment (controller with logging and captive portal), the information texts, and a written procedure. That's exactly the scope of our public WiFi compliance audit, performed on site for establishments in the Alpes-Maritimes and Monaco, together with our professional WiFi installation service.

FAQ on public WiFi obligations

Am I considered an internet service provider (ISP)?

Partially, yes. Your ISP (Orange, SFR...) remains responsible for the line, but as soon as you redistribute access to the public, article L34-1 of the CPCE applies connection-data retention obligations to you. It's the point establishments most often miss.

Must I identify my customers by name?

No, named identification is optional. However, technical logging (IP, date, time, duration) is mandatory. If you choose to collect identities, their retention extends to 5 years and GDPR fully applies.

How long must I keep the data?

Technical connection data: 1 year. Account information provided at registration: 1 year. Civil identity if collected: 5 years. Never the content of communications or browsing history.

Is a captive portal mandatory?

No, no text requires it. But it's the simplest way to fulfil three obligations at once: informing users, recording acceptance of the terms, and structuring per-session logging. In practice, it's the standard.

What are the penalties for non-compliance?

Failure to retain connection data is criminally sanctioned (article L39-3 of the CPCE), and GDPR breaches fall under the CNIL. The most concrete risk remains a judicial requisition the establishment cannot answer.

Can I outsource the management of my public WiFi?

Yes, and it's often the right call for the technical side (logging, portal, security). But legally you remain the data controller: the provider acts as a processor, which must be reflected in the contract.

Ready to transform your connectivity?

Free Quote

Contact us
Tags: Législation

Is your public WiFi compliant? Have it checked

Riviera Connect performs public WiFi compliance audits for hotels, restaurants, shops and coworking spaces in the Alpes-Maritimes and Monaco: logging, captive portal, network isolation and GDPR documentation.

Contact us today for a compliance audit: