A European municipal visitor center will collect guest email addresses through the Wi-Fi captive portal for marketing. Which requirement should WLAN security policy work incorporate under GDPR?
Select an answer to reveal the explanation.
Short Explanation
Free Wi-Fi isn't a GDPR hall pass. If the portal grabs emails for marketing, policy has to spell out consent, why you need the data, and how little you'll keep—before the splash page goes live.
Full Explanation
GDPR applies when personal data such as email addresses are collected through a guest WLAN portal. Requirements should address lawful basis (often consent for marketing), purpose limitation, and data minimization before the collection feature is enabled. Indefinite retention, skipping consent, or insecure logging of personal data conflict with those obligations.