NewDo you know which regulations apply to you? Find out in under 3 minutes. Our sincere gift:EU scoperKorea scoper
How can we help?

Message us on

KakaoTalkLINE

Response within 48 hours

Send us an email →
The Reason Behind Café Wi-Fi "Consent"
Data Privacy

The Reason Behind Café Wi-Fi "Consent"

July 20, 2026·Alex Holmquist, Panke IT Solutions LLC

At a café in Seoul you pick the Wi-Fi, tap a box that says you agree, and you are online in seconds — no account, no name, no email. It feels like you handed over nothing. Except you did hand something over: the box you tapped is a consent form. You just agreed to let the network keep a record of your device for the next three months.

A café table with a coffee cup and a phone showing an

What checking the box actually agrees to

That "I agree" is not only the terms of service. On Starbucks Korea's Wi-Fi — run by the carrier KT — the box is a 개인정보 수집·이용 동의 (a consent to collect and use personal information).

The form is specific about what. KT's own consent notice lists three items: your device's MAC address, its type, and cookies. The stated purpose is providing the Wi-Fi. The stated retention is three months.

No account doesn't mean no record

You felt good about not having to create an account and enjoy free Wi-Fi. But a MAC address is a unique identifier built into your device's Wi-Fi hardware. The network does not need your name to tell your device apart from everyone else's in the room — or to recognize it the next time you walk in.

The three-month log is keyed to your device. You never made an account, but your device was the identifier that mattered anyway.

A phone lying face-down, its MAC address engraved on the back like a serial number and glowing; beside it a blank paper

Why a checkbox is all they need

Korean privacy law requires consent before a company collects and uses personal information, and the operator treats this as exactly that: the form calls itself a 개인정보 수집·이용 동의 (a personal-information collection-and-use consent). You grant the consent when you tap that checkbox and submit.

So the "free" Wi-Fi is actually a small exchange. You get free internet connectivity, they get to log your device.

What the log is for

None of this needs your name, and it likely never singles you out. Aggregated across every customer, the log answers the questions a coffee chain actually cares about:

  1. How long people sit on average
  2. How busy each hour gets
  3. What share of a store's visitors come back over three months
  4. Which branches draw the steadiest crowd

All of it is measured per store, across everyone at once.

A tablet on a café counter showing the store's aggregate Wi-Fi analytics dashboard — average dwell time, repeat-visitor rate, daily visitors, and an hourly-traffic bar chart — with the café softly out of focus behind it.

This is why they bother to collect anything at all. Under Korea's PIPA (Personal Information Protection Act), aggregate statistics like these can run without any extra consent; using the log to profile one person would need one. Either way, the record you agreed to is the raw material.

Should you avoid café Wi-Fi?

This is not surveillance, and it is not a reason to avoid café Wi-Fi. The collection is small and tied to running the network. A modern iPhone or Android phone already uses a randomized MAC address by default, so the log points at a throwaway ID.

The point is that you should know what you are trading for free Wi-Fi. "I didn't sign up, so I gave nothing" is the wrong instinct — you gave a consented, three-month record of your device.

When did you last tap "agree" on a café network without reading a word of it?

References

  1. KT GiGA WiFi / Starbucks Korea Wi-Fi — 개인정보 수집·이용 동의 (personal-information collection & use consent) — collection items: device MAC address, device type, cookies; retained 3 months. https://first.wifi.olleh.com/starbucks/privacy_new.html
  2. Apple — Wi-Fi privacy (a randomized "Private Wi-Fi Address" per network, on by default). https://support.apple.com/guide/security/wi-fi-privacy-secb9cb3140c/web
Concerned about your attack surface?

If you'd like to know how your infrastructure scores in an attacker's scanning model, reach out at contact@pankeit.com for an external attack surface assessment.

Subscribe to our blog

Stay up to date with the latest security trends

No spam. Unsubscribe anytime.

HomeAboutPrivacyDMCA

©2026 Panke IT Solutions LLC

Austin, TX