MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Wi-Fi or Bluetooth tracking to measure visitor numbers is privacy-sensitive: as soon as you link unique codes to smartphones over an extended period, you move from counting people to tracking people. The municipality of Enschede was fined 600,000 euros for this. It is only permitted under strict conditions — with a valid legal basis, clear information, a short retention period, and minimal processing.
The Dutch Data Protection Authority (AP) imposed a fine of 600,000 euros on the municipality of Enschede. The municipality used a Wi-Fi tracking system to measure crowds in the city center — but such a system can also track people, and that is not allowed.
When counting turns into tracking
Enschede hired a company to measure crowd levels (since 2017, stopped in May 2020). Wi-Fi signals were used to count people moving criss-cross: a unique code was linked to each smartphone, and by counting the unique smartphones, the crowd level could be determined.
The problem: such a system does more than count. In a quiet moment, you can see which person belongs to which code and recognize patterns — for example, someone who arrives every day at 8:00 AM and leaves at 5:00 PM (likely an employee). By linking codes to smartphones over a longer period, you move from counting people to tracking them. A municipality is allowed to count people, but not simply track and spy on them.
A fine of 600,000 euros
Although the municipality did not intend to monitor citizens and there were no indications to that effect, the AP intervened nonetheless. Citizens have the right to walk the streets freely and unobserved. Following intervention by the AP, the municipality ceased the practice on May 1, 2020, and was ultimately fined 600,000 euros.
Privacy-friendly tracking: difficult, but not impossible
Wi-Fi or Bluetooth tracking is difficult to set up in a privacy-friendly way, and is only possible under strict conditions:
- there must be a valid basis (for a municipality, for example, safety in the city);
- citizens and visitors must be clearly informed about it;
- the data may only be stored for a short period;
- Processing must remain limited, for example by activating the system only at specific locations and times, or by anonymizing MAC addresses. Please note: hashing is pseudonymization, not anonymization — in that case, you are still processing personal data.
Frequently Asked Questions
Am I allowed to use Wi-Fi tracking to count visitors?
Only under strict conditions. As soon as you link unique codes to individuals over an extended period, you are processing personal data and must, among other things, have a legal basis and provide transparent information.
Is anonymizing MAC addresses sufficient?
True anonymization can be a solution, because you then no longer process personal data. Hashing is not sufficient: that is pseudonymization, and that data remains personal data.
Why did the municipality receive a fine without proof of following?
Because the system *could* track people and thereby violated privacy. The AP deemed the infringement serious, even without indications that actual tracking was taking place.
Have Wi-Fi tracking legally reviewed
Prevent a privacy breach and hefty fines: have tracking reviewed in advance. The privacy experts at MKB Juristen help you set this up in a privacy-friendly way. View our expertise in privacy and data protection or schedule a no-obligation intake meeting .