They can't track phones that have WiFi turned off or are turned off altogether. I don't leave everything running when it's not in use e.g. WiFi, mobile data, Bluetooth, NFC, hotpsot etc. as it means the battery lasts much longer. In fact my phone has a setting that automatically turns off some of those if they aren't in use to preserve battery life. I'm also skeptical about what you say. While a lot of people accept T&Cs that permit data sharing without reading them, TfL can't just track people without consent - that would be illegal. And if they can legally track say 40% of passengers, then they're making presumptions about the other 60% based on having data for 4 out of 10 passengers. That may work for the example I gave when I was making the exact same journey as work colleagues, but wouldn't work for other journeys.
What law do you say TfL is breaking?
Signs have been put up at stations explaining the Wi-Fi data collection that is taking place and how to opt-out.
In summary, we are collecting the location of devices on our network, identifying them by a pseudonymised version of their MAC address.
We are trying to understand patterns of movement across our network and how customers as a whole use it, not how specific individuals use it.
We are not collecting data on browsing activity, cookies, phone numbers or whether the Wi-Fi service is used.
However, if you would like to opt-out, you can do this by turning off Wi-Fi on your device, turning your device off or putting your device into airplane mode while at our stations.
If the device finds a Wi-Fi network that is known to the device, it will automatically connect to that network. If the device finds unknown networks, it will list these in your device settings so you can decide whether to connect to one of them.
When you are near one of our station Wi-Fi access points (installed on TfL privately-owned property) and you have Wi-Fi enabled, your device will send a probing request to connect. This will be received by our Wi-Fi network, even if your device does not subsequently connect.
This data collection is carried out independently by TfL, not via Virgin Media.
We will not be able to identify any individuals from the data collected. We have designed the process to identify patterns and to avoid identifying individuals. We are trying to understand how customers as a whole use the network, not how specific individuals use it.
All data collected is automatically depersonalised, using a one-way pseudonymisation process to ensure TfL is unable to identify any individual. This happens immediately after the data is first collected.
TfL has no plans to match the Wi-Fi connection data to any other data held about individuals (eg Oyster and Contactless data). There is no way to systematically do this if we wanted to.
If the device has been signed up for free Wi-Fi on the London Underground network and the Elizabeth line stations noted above, the device will disclose its genuine MAC address. This is known as an authenticated device.
The following processing only relates to authenticated devices.
We process authenticated device MAC address connections (along with the date and time the device authenticated with the Wi-Fi network and the location of each router the device connected to). This helps us to better understand how customers move through and between stations - we look at how long it took for a device to travel between stations, the routes the device took and waiting times at busy periods.
As a customer enters a station (if their device has Wi-Fi enabled), the device will attempt to connect to the Wi-Fi network. This is recorded in our Wi-Fi data control system. We carry out a process of hashing once a MAC address is collected. Hashing is the process of generating a new value from a string of text (in this instance the MAC address).
We carry out two rounds of hashing to make sure we never hold the original MAC address. One hash is with a single value (pepper), and the second is with another unique random value (salt) for each MAC address. This pseudonymisation process provides continuity to the data without needing to record the MAC address which could identify an individual device. This means that we have to preserve our hashing key to maintain continuity of the pseudonymised data.
We do not collect any other data generated by your device. This includes web browsing data and data from website cookies.
How and why TfL collects Wi-Fi connection data from devices signed up to use the Wi-Fi available at London Underground stations
tfl.gov.uk
Further interesting information:
https://www.ianvisits.co.uk/article...helping-tfl-update-its-journey-planner-34051/