At a café in Seoul you pick the Wi-Fi, tap a box that says you agree, and you are online in seconds — no account, no name, no email. It feels like you handed over nothing. Except you did hand something over: the box you tapped is a consent form. You just agreed to let the network keep a record of your device for the next three months.

What checking the box actually agrees to
That "I agree" is not only the terms of service. On Starbucks Korea's Wi-Fi — run by the carrier KT — the box is a 개인정보 수집·이용 동의 (a consent to collect and use personal information).
The form is specific about what. KT's own consent notice lists three items: your device's MAC address, its type, and cookies. The stated purpose is providing the Wi-Fi. The stated retention is three months.
No account doesn't mean no record
You felt good about not having to create an account and enjoy free Wi-Fi. But a MAC address is a unique identifier built into your device's Wi-Fi hardware. The network does not need your name to tell your device apart from everyone else's in the room — or to recognize it the next time you walk in.
The three-month log is keyed to your device. You never made an account, but your device was the identifier that mattered anyway.

Why a checkbox is all they need
Korean privacy law requires consent before a company collects and uses personal information, and the operator treats this as exactly that: the form calls itself a 개인정보 수집·이용 동의 (a personal-information collection-and-use consent). You grant the consent when you tap that checkbox and submit.
So the "free" Wi-Fi is actually a small exchange. You get free internet connectivity, they get to log your device.
What the log is for
None of this needs your name, and it likely never singles you out. Aggregated across every customer, the log answers the questions a coffee chain actually cares about:
- How long people sit on average
- How busy each hour gets
- What share of a store's visitors come back over three months
- Which branches draw the steadiest crowd
All of it is measured per store, across everyone at once.

This is why they bother to collect anything at all. Under Korea's PIPA (Personal Information Protection Act), aggregate statistics like these can run without any extra consent; using the log to profile one person would need one. Either way, the record you agreed to is the raw material.
Should you avoid café Wi-Fi?
This is not surveillance, and it is not a reason to avoid café Wi-Fi. The collection is small and tied to running the network. A modern iPhone or Android phone already uses a randomized MAC address by default, so the log points at a throwaway ID.
The point is that you should know what you are trading for free Wi-Fi. "I didn't sign up, so I gave nothing" is the wrong instinct — you gave a consented, three-month record of your device.
When did you last tap "agree" on a café network without reading a word of it?
References
- KT GiGA WiFi / Starbucks Korea Wi-Fi — 개인정보 수집·이용 동의 (personal-information collection & use consent) — collection items: device MAC address, device type, cookies; retained 3 months. https://first.wifi.olleh.com/starbucks/privacy_new.html
- Apple — Wi-Fi privacy (a randomized "Private Wi-Fi Address" per network, on by default). https://support.apple.com/guide/security/wi-fi-privacy-secb9cb3140c/web
