Short answer
Compliance is shared. The Purple platform behind FirstNet Managed Guest Wi-Fi provides consent controls aligned to POPIA and GDPR, but your login method, consent wording, retention and data use determine the outcome. FirstNet helps you set this up correctly.
In detail
POPIA (the Protection of Personal Information Act) governs how you collect and use guests' personal information, so a platform can enable compliance but cannot guarantee it on your behalf. How responsibilities divide:
- Platform: consent-based login and data capture aligned to POPIA and GDPR, ISO 9001 and ISO 27001 certification, annual third-party audits and ongoing vulnerability and penetration testing.
- FirstNet: portal and login configuration, hosting region confirmed per deployment through its compliance process, change control and support.
- Your organisation: you remain the data controller, approve the terms and privacy wording, and decide on login method, retention and downstream use.
Good practice is to keep consent wording clear and specific, collect only the data you need, set a retention period, and keep marketing journeys in the Engage tier opt-in. If you need in-country hosting, a named certification or a completed security questionnaire, raise it early so it can be confirmed before rollout.
Source: FirstNet Managed Guest Wi-Fi service page →
Didn’t answer your question?
