Short answer
You do. Your organisation remains the data controller for its guest dataset, and the platform supports consent-based login and data capture aligned to POPIA and GDPR.
In detail
Being the data controller (the responsible party, in POPIA terms) means you decide why and how guest data is used, and you are accountable for it. In practice:
- You approve the terms and privacy wording shown on the portal.
- You choose the login method, such as email, mobile, social, or OTP via SMS or WhatsApp.
- You set retention and decide on downstream use, such as CRM, loyalty or campaigns.
- The Capture tier builds a consented first-party database you can use for analytics and reporting.
Those choices determine the compliance outcome, and FirstNet helps set them up correctly. FirstNet provides portal design, login configuration, site set-up, reporting access, change control and support, and confirms the hosting region per deployment through its compliance process.
The Purple platform that holds the data is ISO 9001 and ISO 27001 certified, with annual third-party audits and ongoing vulnerability and penetration testing.
Source: FirstNet Managed Guest Wi-Fi service page →
Didn’t answer your question?
