{"id":16689,"date":"2024-09-26T06:00:29","date_gmt":"2024-09-26T06:00:29","guid":{"rendered":"https:\/\/letslaw.es\/?p=16689"},"modified":"2024-09-09T10:33:11","modified_gmt":"2024-09-09T10:33:11","slug":"fines-wifi-tracking","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/fines-wifi-tracking\/","title":{"rendered":"First fines of over 40,000\u20ac by the AEPD for exploiting customer data through business Wi-Fi"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">The Spanish Data Protection Agency (AEPD) has focused on the handling of personal data collected by companies through Wi-Fi in their establishments, warning of potential hefty fines for those who jeopardize their customers&#8217; privacy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These fines can range from \u20ac40,000 to \u20ac20 million, potentially even threatening the survival of small businesses.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Use of Wi-Fi tracking<\/span><\/h2>\n<p><a href=\"https:\/\/letslaw.es\/en\/data-controllers-wifi-tracking\/\"><span style=\"font-weight: 400;\">Wi-Fi tracking<\/span><\/a><span style=\"font-weight: 400;\">, also known as Wi-Fi tracking technology, is a tool that allows the identification and tracking of mobile devices through the Wi-Fi signals they emit. <\/span><b>Its main purpose is to detect the presence of devices in specific areas and analyze movement patterns<\/b><span style=\"font-weight: 400;\">. It is used, among other things, to estimate the number of people in a location, analyze movement flows, and measure dwell times.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This technology has applications in a wide variety of contexts, such as shopping centers, museums, workplaces, public spaces, public transportation, and large events. However, it is crucial to note that this practice presents significant privacy risks, as it could enable tracking of people&#8217;s movements without their consent or knowledge, and therefore without an appropriate legal basis.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The AEPD has focused on businesses that, without adequate preventive measures, allow the identification and tracking of electronic devices that have connected to the establishment&#8217;s network.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Violation of explicit consent<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">It is important to remember that any processing of personal data must comply with the principles established in Article 5 of the GDPR and meet at least one of the legal bases listed in Article 6 of the GDPR. This also applies to Wi-Fi tracking when the data controller chooses a technology that enables such processing.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It is important to note that Article 4.11 of the GDPR defines the data subject&#8217;s consent as any freely given, specific, informed, and unambiguous indication of the data subject&#8217;s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Wi-Fi tracking technology allows businesses to track devices comprehensively, so it must be ensured that the processing is conducted fairly and transparently, with individuals clearly understanding what data is being handled and how through Wi-Fi tracking. <\/span><b>This information must be provided in an accessible and easy-to-understand manner, regardless of the technical or practical difficulties that Wi-Fi tracking may present<\/b><span style=\"font-weight: 400;\"> to the data controller in complying with these principles.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Another possibility that businesses might argue is that the legitimate interest of the data controller, as outlined in Article 6.1.f) of the GDPR, takes precedence. However, the data controller must ensure that this processing is necessary to satisfy those interests and that the interests or rights and freedoms of the data subjects do not override them, considering their reasonable expectations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This requires a meticulous assessment of whether the processing can be carried out and whether it takes precedence over others\u2014a balancing test\u2014even if a data subject could reasonably foresee it at the time and in the context of the collection of personal data. This balancing test must be conducted by the data controller.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Preventive measures<\/span><\/h2>\n<p><b>The data protection authorities in Spain have developed specific guidelines for those responsible who use Wi-Fi tracking technology<\/b><span style=\"font-weight: 400;\">. These guidelines examine both the technical and legal implications of Wi-Fi tracking, identify the main risks, and offer recommendations for proper use in compliance with <\/span><a href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\"><span style=\"font-weight: 400;\">data protection<\/span><\/a><span style=\"font-weight: 400;\"> regulations. Beyond clearly informing users, these recommendations include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymizing data immediately after collection.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restricting the scope of Wi-Fi tracking.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Not cross-referencing geolocation data with information from other sources.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoiding assigning the same identifier to a mobile device on different visits to the same location.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Providing an effective opt-out option for users.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establishing data processing agreements that limit the use of data to the controller&#8217;s instructions.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoiding international data transfers without adequate safeguards.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conducting independent audits.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implementing security measures adapted to the level of risk and subject to continuous reviews.<\/span><\/li>\n<\/ul>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/16689#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>First fines of over 40,000\u20ac by the AEPD for exploiting customer data through business Wi-Fi.<\/p>\n","protected":false},"author":60,"featured_media":16686,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-16689","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16689","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/60"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=16689"}],"version-history":[{"count":4,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16689\/revisions"}],"predecessor-version":[{"id":16693,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16689\/revisions\/16693"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/16686"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=16689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=16689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=16689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}