
Public WiFi: Legal Obligations for Businesses on the French Riviera
Who is concerned — and who legally counts as an "access provider"?
Your ISP remains responsible for the line; you are responsible for the access you redistribute. The size of the establishment is irrelevant: a twenty-seat tea room is covered just like a palace hotel.

The legal framework in three texts
The LCEN (2004 law on confidence in the digital economy) completes the framework on the liability of technical intermediaries.
GDPR and the French Data Protection Act govern the processing: connection data is personal data. You must inform users, limit collection to what's necessary, secure storage and honour access and erasure rights (the latter doesn't apply to data whose retention is a legal obligation). The CNIL publishes practical guidance dedicated to publicly open WiFi — a useful reference in case of doubt.
Which data to keep, and for how long?
- User's civil identity (if you collect it: first and last name): 5 years after the end of the relationship.
- Information provided at registration (email, account ID, payment data where applicable): 1 year.
- Technical connection data (assigned IP address, technical identifier such as MAC address, date, time and duration of each connection): 1 year — the minimum baseline every establishment must be able to produce.
And crucially, what you must not keep: the content of communications and detailed browsing history (sites visited). The law requires knowing who connected, when, with which address — not what they did. Keeping more than necessary isn't prudence: it's a GDPR violation.
In practice, this logging is handled by a professional router or WiFi controller, with timestamped export and secure backup. Consumer hardware is rarely capable of it.
What it means for your line of business
Café / restaurant. One-click access with displayed terms is enough — named identification is not mandatory. What matters: technical logging genuinely running, and the public network isolated from the till and payment terminal.
Coworking. The most demanding case: users are recurring, often identified (member account), and usage is heavy. The "identity 5 years / account 1 year / technical 1 year" periods fully apply, and separation between the members' network and the visitors' network must be strict. The recommended architecture matches that of business guest WiFi: VLANs, captive portal, client isolation.
Template text for your captive portal
"By connecting to this WiFi network, you accept these terms of use. In accordance with article L34-1 of the French Post and Electronic Communications Code, [Establishment name] retains technical connection data (IP addresses and technical identifiers, connection dates, times and durations) for 12 months. This data may be disclosed to legally authorised authorities upon requisition. It is not used for any commercial purpose and does not cover the content of your communications. Data controller: [Name, address]. To exercise your access and rectification rights: [contact email]. Access is provided for [X hours] and may be suspended in case of abusive or unlawful use."
If you additionally collect an email for marketing, add a separate, un-ticked consent box: GDPR consent is never inferred from accepting the terms of use.
Public WiFi compliance checklist
- ☐ Logging active: IP, technical identifier, date/time/duration of each session, reliable timestamps (NTP).
- ☐ 12-month retention of technical data, backed up off-site or on secure storage.
- ☐ Requisition procedure tested: you can extract the logs for a given period within a day, and you know who is authorised to do it.
- ☐ Public network isolated from the internal network (VLAN, firewall) — legal compliance doesn't cover the damage of an intrusion.
- ☐ User information displayed on the captive portal (template above) and reflected in your privacy policy.
- ☐ Minimal collection: no browsing history, no content, no marketing data without separate consent.
- ☐ Log access restricted to authorised persons, with an audit trail of consultations.
- ☐ GDPR register up to date: the "public WiFi" processing is listed with its purposes and retention periods.
If you're missing one point, it's most often compliant logging or the extraction procedure — both solved with suitable equipment and an hour of configuration.
Risks and getting compliant
Getting compliant is rarely heavy: an audit of the existing setup, the right equipment (controller with logging and captive portal), the information texts, and a written procedure. That's exactly the scope of our public WiFi compliance audit, performed on site for establishments in the Alpes-Maritimes and Monaco, together with our professional WiFi installation service.
FAQ on public WiFi obligations
Am I considered an internet service provider (ISP)?
Partially, yes. Your ISP (Orange, SFR...) remains responsible for the line, but as soon as you redistribute access to the public, article L34-1 of the CPCE applies connection-data retention obligations to you. It's the point establishments most often miss.
Must I identify my customers by name?
No, named identification is optional. However, technical logging (IP, date, time, duration) is mandatory. If you choose to collect identities, their retention extends to 5 years and GDPR fully applies.
How long must I keep the data?
Technical connection data: 1 year. Account information provided at registration: 1 year. Civil identity if collected: 5 years. Never the content of communications or browsing history.
Is a captive portal mandatory?
No, no text requires it. But it's the simplest way to fulfil three obligations at once: informing users, recording acceptance of the terms, and structuring per-session logging. In practice, it's the standard.
What are the penalties for non-compliance?
Failure to retain connection data is criminally sanctioned (article L39-3 of the CPCE), and GDPR breaches fall under the CNIL. The most concrete risk remains a judicial requisition the establishment cannot answer.
Can I outsource the management of my public WiFi?
Yes, and it's often the right call for the technical side (logging, portal, security). But legally you remain the data controller: the provider acts as a processor, which must be reflected in the contract.
Ready to transform your connectivity?
Free Quote