• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

What do TOCs do with personal information you enter for WiFi?

Status
Not open for further replies.

tornado

Member
Joined
6 Apr 2010
Messages
439
some TOCs such as Avanti require you to enter your full name, post code, email, and phone number, to access wifi.

Given that other train companies just let you press a button to accept their terms and conditions, why the need for such personal information and what do they do with it?
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Western 52

Established Member
Joined
19 Jun 2020
Messages
1,672
Location
Burry Port
There should be a notice telling you what they do with any personal data you have to provide on or linked to their data collection form.
 

Peter0124

Established Member
Joined
20 Nov 2016
Messages
2,751
Location
Glasgow
Scotrail wifi at Glasgow Central Low Level wants you to fill a very quick survey out everytime you log in. I think that defeats the purpose of it as you'd just press random buttons to get on the wifi. It should really be made optional or unreliable data will be sent
 

JamesT

Established Member
Joined
25 Feb 2015
Messages
4,868
some TOCs such as Avanti require you to enter your full name, post code, email, and phone number, to access wifi.

Given that other train companies just let you press a button to accept their terms and conditions, why the need for such personal information and what do they do with it?
Does the registration page say it’s Avanti retaining your data or the provider of the service?

The most likely answer is that their marketing team reckon they can use those details to drive more business. Whereas those that don’t presumably don’t think it’s worth that much.

Another option may be that they have or believe they have an obligation to record this data for law enforcement purposes.
 

Lemmy99uk

Member
Joined
5 May 2015
Messages
562
Another option may be that they have or believe they have an obligation to record this data for law enforcement purposes.
I think if that was the case they would need a more robust system.

I used Avanti Wi-Fi this morning with a made up email address and postcode. There is no validation check.
 

DarloRich

Veteran Member
Joined
12 Oct 2010
Messages
32,916
Location
Fenny Stratford
some TOCs such as Avanti require you to enter your full name, post code, email, and phone number, to access wifi.

Given that other train companies just let you press a button to accept their terms and conditions, why the need for such personal information and what do they do with it?
There will be a data handling statement somewhere on the website
 

yorkie

Forum Staff
Staff Member
Administrator
Joined
6 Jun 2005
Messages
78,364
Location
Yorkshire
It's not uncommon to have a grace period (perhaps 15 minutes) to validate the email address; it's surprising that more systems do not have this!

However, there can't be any validation of real name, or your address (other than it may require a valid address, but it could be anyone's address).

I suspect most people have an email address that they use to sign up for stuff, which doesn't give them push notifications, and I also suspect most people don't provide their real name either, so it's fairly pointless!
 

Ziggiesden

On Moderation
Joined
4 Jun 2024
Messages
107
Location
Edrom
Scotrail wifi at Glasgow Central Low Level wants you to fill a very quick survey out everytime you log in. I think that defeats the purpose of it as you'd just press random buttons to get on the wifi. It should really be made optional or unreliable data will be sent
Absolutely correct. When I can be bothered I fill it in as “not travelling” even though I’m already on a train to show how nonsensical it actually is.
 

185

On Moderation
Joined
29 Aug 2010
Messages
5,709
I've found that for most railway WiFi logins a fake, nonexistent email will suffice. Only one or two require validation.

Currently, I'm dealing with one TOC in a rather serious case regarding the retention and (a director) subsequently misusing someone's personal data which they retained for 15 years (ie 9 years too long). The data which wasn't divulged during a subject access request (ie they'd denied having it), but was only released when the ICO and parent company got involved, claiming it was an 'oversight'..
 

OscarH

Established Member
Joined
15 Sep 2020
Messages
1,284
Location
Crawley
Several of the TOCs use it to send strike information (SWR and Northern I know of - I think they're both the standard Icomera email only?). This is when you don't click the marketing checkbox, presumably if you do then you get mountains of junk trying to persuade you to buy from them.
 

chesterred16

Member
Joined
31 Aug 2021
Messages
60
Location
Chester
I've often wondered this - the (non-rail) company I work for takes GDPR incredibly seriously, and we try not to take any more personal information than we absolutely have to. Having TOCs and their wifi providers collecting personal info just feels like an ICO fine waiting to happen - and those fines are set at levels designed to be crippling to the business.
 

MikeWM

Established Member
Joined
26 Mar 2010
Messages
4,956
Location
Ely
It's not uncommon to have a grace period (perhaps 15 minutes) to validate the email address; it's surprising that more systems do not have this!

That seems to be becoming less common, fortunately - I don't want to be accessing my personal email on public wifi, for security reasons.

(Yes, you can use a disposable email address, though they are somewhat harder to get than they used to be. Or you can use a VPN to access your mail - arguably you ought to be using a VPN on public wifi anyway, but I don't see it matters that much if I'm just web browsing without logging into accounts. But it's all unnecessary hassle).
 

OscarH

Established Member
Joined
15 Sep 2020
Messages
1,284
Location
Crawley
I've often wondered this - the (non-rail) company I work for takes GDPR incredibly seriously, and we try not to take any more personal information than we absolutely have to. Having TOCs and their wifi providers collecting personal info just feels like an ICO fine waiting to happen - and those fines are set at levels designed to be crippling to the business.
Basically every free WiFi network does this, rail or not. I agree it's awful, but if it's this widespread then a lot of different lawyers must have independently signed off on it
 

alistairlees

Established Member
Joined
29 Dec 2016
Messages
4,406
The real question is: why do some TOCs need intrusive information, and others do not? For example, Southeastern did not previously collect personal info to access wifi, but now it does. It changed a couple of years ago.

== Doublepost prevention - post automatically merged: ==

Several of the TOCs use it to send strike information (SWR and Northern I know of - I think they're both the standard Icomera email only?). This is when you don't click the marketing checkbox, presumably if you do then you get mountains of junk trying to persuade you to buy from them.
SWR always send me "how was your journey" emails after I use their wifi.
 

TUC

Established Member
Joined
11 Nov 2010
Messages
5,073
If this means TOCs will send targeted rather than random offers to me, my response is yes please, here's my email address and location.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,850
Location
Gwynedd
I've often wondered this - the (non-rail) company I work for takes GDPR incredibly seriously, and we try not to take any more personal information than we absolutely have to. Having TOCs and their wifi providers collecting personal info just feels like an ICO fine waiting to happen - and those fines are set at levels designed to be crippling to the business.
Being fined is somewhat dependent upon a complaint (or breach notification) actually being logged though.

The vast majority of people just accept the wifi terms without reading them and just 'accept' that they have to provide an email address then forget about it.

Such a complaint also requires some sort of basis. I haven't read anything in this thread yet which points to any specific DPA offence or GDPR principle being breached. It's more a feeling of, "I resent this.", than, "This is unlawful and here's why." I also suspect most operators contract out the wifi provision, e.g. LNER and Northern pay icomera to operate their on-board wifi and I expect icomera may advise what sort of things need collecting and what may be needed in a privacy notice. Fundamentally I expect the operators have adequate legal basis for their wifi data collection and retention. I imagine it is mostly aggregate information or wifi session metadata used for statistical purposes.
 

yorkie

Forum Staff
Staff Member
Administrator
Joined
6 Jun 2005
Messages
78,364
Location
Yorkshire
If this means TOCs will send targeted rather than random offers to me, my response is yes please, here's my email address and location.
I doubt anyone has recieved a worthwhile offer from a TOC based on providing information to access their WiFi.
 

island

Veteran Member
Joined
30 Dec 2010
Messages
17,910
Location
0036
I just use a random name, Mailinator email address, and a postcode of whatever city I'm in at the time. Very few wifi portals require verifying the email address, but it's easy to do so on Mailinator if needed.
 

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,576
Location
Warks
I have heard of WiFi sign-up data being used to market "booking direct" [from the TOC] to customers who have purchased their tickets from a TPR.
 

yorkie

Forum Staff
Staff Member
Administrator
Joined
6 Jun 2005
Messages
78,364
Location
Yorkshire
I have heard of WiFi sign-up data being used to market "booking direct" [from the TOC] to customers who have purchased their tickets from a TPR.
Ah; they must be desperate for those people to pay more than they might otherwise pay if they book through us :lol:
 

BeijingDave

Member
Joined
26 Jul 2019
Messages
804
Scotrail wifi at Glasgow Central Low Level wants you to fill a very quick survey out everytime you log in. I think that defeats the purpose of it as you'd just press random buttons to get on the wifi. It should really be made optional or unreliable data will be sent
Yes, and for the forms that require a postcode (possibly Northern or Arriva Trains Wales) I just end up entering CH1 1AA all the time.
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,560
Location
Isle of Man
I use president@whitehouse.gov and I work my way through the list of serial killers for my name. Although one TOC, I forget which, did refuse to accept “Pol Pot” as a name.
Basically every free WiFi network does this, rail or not. I agree it's awful, but if it's this widespread then a lot of different lawyers must have independently signed off on it
I’m no GDPR expert, but I can’t see how it is unlawful if the data is proportionate and consent is freely given.

I hate it too, but the TOCs can very easily argue that agreeing to promotional emails is the consideration you pay for getting the otherwise free WiFi.
 

DynamicSpirit

Established Member
Joined
12 Apr 2012
Messages
9,213
Location
SE London
but I don't see it matters that much if I'm just web browsing without logging into accounts. But it's all unnecessary hassle).

I suspect the risk there is that you might think you're just browsing without logging in, but if it's a website you regularly use, you may well be auto-logged in via cookies, without even thinking about it.

On the other hand, I'd expect the risk of an attack by taking details off an insecure train Wifi would be very low - not least because the attacker would presumably need to be on the train as well. It's not the kind of thing that I'd expect an attacker to consider worth while doing (although to be safe, personally I'm still very cautious if I'm using a public wifi - especially if it's one that doesn't require a password to connect).
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,095
Location
Redcar
As I'm currently on an LNER service thought I'd have a little look and the Privacy Policy on the wi-fi page says the following:

Welcome to the LNER Wi-Fi service: Your guide to data protection on the move
Embark on a journey with London North Eastern Railway, where your personal data's security is our priority as you connect to our onboard Wi-Fi service. Let's keep you on the right track with a concise guide to our data safeguarding practices as you travel with us. This is partnered with Icomera to keep you connected. Should you wish to delve deeper into the specifics of our approach to data protection across all areas, please signal your interest by clicking through to our comprehensive policy.
Who We Are
At London North Eastern Railway (LNER), we're not just about the destination; we're about making the journey memorable. Teaming up with Icomera, we aim to keep you connected with Wi-Fi services as you travel with us. We're constantly working on the lines of communication to improve your experience, so while you take in the views and relax, we're managing the signals — both on the tracks and for your online access.
Our Data Protection Officer
Steering the way for data protection at LNER, our Data Protection Officer is on board to ensure your information stays on the right track. If you have any questions or need to send a signal about your data, please dispatch an email to data.safe@lner.co.uk or post your inquiries to our headquarters at West Offices, Station Rise, York, YO1 6GA. We're here to assist with any data protection requests or concerns you may have - consider us your go-to station for privacy matters.
Data Processing for Wi-Fi Service
Just as we navigate the complexities of rail travel, we apply the same attention to detail when it comes to our Wi-Fi service. We collect essential data from your device, like the MAC address, IP address, session timestamps, and session ID, along with the GPS position of the train.
In our efforts to keep you connected aboard our trains, we collect just enough data to maintain your Wi-Fi account smoothly. When you log in, we'll ask for your name and email address - think of it as your digital ticket to onboard internet access. We securely store this information to streamline your future sign-ins, making it as straightforward as hopping on a train.
If you're already part of the LNER family and purchase tickets with us, this information becomes a part of your existing customer profile, helping us deliver a more cohesive and integrated experience. For those who are guests on our service, we create a more concise profile, focused on enhancing your Wi-Fi experience without any unnecessary baggage.
Legal Grounds for Processing
When you use our Wi-Fi service on LNER trains, we take our responsibility for your personal data seriously. The collection and processing of your data are fully aligned with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We base our data processing on our legitimate interests, which are as follows:
  • Facilitating Network Access: We process certain data, like your device's MAC address and IP address, because it's vital for us to give you access to our Wi-Fi network. This information helps us to identify your device reliably, allowing for a consistent connection as you travel.
  • Enhancing Our Services: We're always on a mission to better our Wi-Fi service for you. By analysing how you use our Wi-Fi, including session times and data consumption, we gain insights that help us tweak and enhance our network.
  • Service Quality and Support: We also process the technical data from your Wi-Fi sessions. This means we can quickly sort out any issues that might interrupt your online activities and support you effectively, ensuring high-quality service every time you log on.
Sharing Your Information
In the quest to offer you an effective Wi-Fi service on our trains, we've joined forces with Icomera, the leading light in providing cutting-edge Wi-Fi solutions. To keep our service running smoothly, we may share certain technical details with Icomera that are key to your online experience, such as your device's unique identifiers and session info. Rest assured, this is all about keeping you connected and ensuring a robust internet service while you're aboard.
Communication and Information Updates
Occasionally, we may send you emails that are considered part of our service provision. These include necessary updates about our Wi-Fi service, maintenance notifications, or changes to our privacy policy. Please note that these communications are an integral part of the service we provide and are not marketing messages, so the option to opt-out is not available for these types of emails. They are sent to ensure you have all the essential information for a seamless travel experience with LNER.
Safeguarding Your Data
At LNER, we recognise the importance of your privacy and the need to protect your personal data. We are dedicated to safeguarding your information with a comprehensive suite of technical and organisational measures designed to ensure the highest levels of security and confidentiality.
Use of Cookies
To enhance your experience with our Wi-Fi service, we utilise cookies—small text files stored on your device. These cookies play a crucial role in facilitating a smoother connectivity experience by:
  • Device Recognition: Cookies enable us to recognise your device, allowing for quicker connection times and reducing the need for you to repeatedly log in or authenticate your device.
  • Service Improvement: By analysing how our Wi-Fi service is used, we can identify areas for improvement, making the service more efficient and user-friendly.
  • User Preferences: Cookies help us remember your preferences and settings, personalising your Wi-Fi experience according to your usage patterns and choices.
Your Data Protection Rights
At LNER, we are committed to ensuring that your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 are fully respected and facilitated. You have the following rights regarding your personal data:
  • Right to Access: You have the right to request access to your personal data that we hold.
  • Right to Rectification: If you believe that any personal data we hold about you is inaccurate or incomplete, you have the right to request its correction.
  • Right to Erasure: In certain circumstances, you have the right to request the deletion of your personal data from our systems.
  • Right to Restrict Processing: You have the right to request a restriction on the processing of your personal data under specific conditions.
  • Right to Data Portability: You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit those data to another controller.
To exercise any of these rights, please contact our Data Protection Officer via email at data.safe@lner.co.uk. We are here to assist you with any queries or requests related to your personal data.
Automated Decision Making and Profiling
We want to clarify that our Wi-Fi service does not involve any form of automated decision making or profiling using your personal data. Our processes are designed to ensure that all decisions affecting our users are made with human intervention and consideration.
Making a Data Protection Complaint
If you have any concerns or complaints about how we handle your personal data, please do not hesitate to reach out to our Data Protection Officer at data.safe@lner.co.uk. While we are dedicated to resolving any issues related to your data protection rights, please note that we may not be able to assist with issues unrelated to data protection, such as Wi-Fi connectivity problems.
Policy Updates
This privacy policy was last updated in March 2024. We regularly review and, where necessary, update our privacy information. Should any significant changes be made to our data protection practices, we will communicate these changes through our usual channels.

Which, occasional LNER corporate flowery language aside, all seems fairly boilerplate to be honest! Not sure there's anything in there that's particularly concerning from a data protection point of view and whilst I'm no expert the grounds for processing all seem to be fairly reasonable on their face. Personally I think email should be sufficient to register with name being optional but it's not too onerous I feel.
 

Egg Centric

Established Member
Joined
6 Oct 2018
Messages
2,876
Location
Land of the Prince Bishops
some TOCs such as Avanti require you to enter your full name, post code, email, and phone number, to access wifi.

Given that other train companies just let you press a button to accept their terms and conditions, why the need for such personal information and what do they do with it?

To focus on the "need" bit of this - it's commonly considered that public wifi needs to record its users, although in reality the position is a bit more wooly. This is why most of them are rubbish in terms of validation - they're doing it because they legally have to (or perceive they have to) not because they necessarily want to. So they don't care that everyone gives fake details as long as they can tick that legal checkbox and make it not their problem(tm).

To quote from https://www.draytek.co.uk/support/guides/kb-guest-internet-logging:


Legal Obligations for logging Guest Internet Access​



If you provide guest access to the Internet, for example WiFi in your coffee shop, the question of whether you are required to register, log or retain user data (identity or usage) is a complex area, not least because there is conflicting and continuously changing information.

Many organisations log the information, believing it to be required, others do not log it at all, or log only some of it (for example usage, but not identity). There are other commercial benefits to logging such information - for example, asking for people's email addresses also enabled you to ask if they wish to opt-in to email lists. We note that some providers make the receiving of marketing emails a mandatory requirement if you wish to use a facility's "free" WiFi service.

This area of logging users is an ever-evolving landscape, so what is valid at the time of writing might not be at the time of reading. Secondly, laws can be unclear, ambiguous or conflicting and so it's necessary to clearly state that this article represents our understanding but you should obtain professional legal advice before relying on anything here.

It's really difficult to give you a definitive answer on whether you are or are not required to log public Internet access, and one that even if valid today, is valid tomorrow or when you read this. For example, this article was first written in 2015, since when the European GDPR regulations came into force, which changed obligations, and arguably made them more complex.


Effectiveness and Purpose

The justification for these laws has been to combat terrorism and the most serious crime (the public would never have accepted this level of tracking/intrusion if it was just for trolls or mischief makers). A technically capable perpertrator does have many options available to them to circumvent tracking or mask their activities (VPNs, dark nets, one-time email, SSL/TLS, untracked providers, PAYG cellular SIMs, unauthorised use of other's connectivity etc.) but presumably some are less sophisticated or don't care about being tracked after the event. People guilty of lower level crimes (piracy, trolling etc.) or whistleblowers are less likely to make the same effort to cover their tracks.



Relevant Legislation

Following is a list of the most common or relevant legislation we're aware of affecting this subject. As an ever changing landscape though, this is not to be taken as legal advice or comprehensive:



European General Data Protection Regulation (GDPR)

GDPR came into force in June 2018. This attempts to regularise many of the previous regulations and to increase data controllers' responsibility to look after, protect and use data subject's data accordingly. In respect of guest internet access, your obligations will include being clear to your users about what data you will collect, what its used for, how long its kept for, keeping it securely, notifying of breaches, allowing for corrections and providing user's own data recorded on demand. Where data is anonymised and not logged to a known person, this may not be required though our (non legal view) is that this is a minefield yet to be tested, as well as the crossover between previous and new legislation.


European Directive (2006/24/EC)

A European Directive (2006/24/EC) in 2006 mandated providers throughout Europe to retain customer data relating to electronic communication services. Data was required to be retained for between 6 and 24 months. Police and security agencies could then request that data from the service provider. The directive specifically cited combatting terrorism as a justification but journalists, medical professionals, IT security experts, scientists and various other groups objected to the legislation.

"Service Provider" itself is a very broad term and whilst it was assumed to include telcos and ISPs, could also include coffee shops, schools or anyone providing WiFi access. The data retained would include users' IP addresses, time of access and the time of every email, call and text message sent or received. In April 2014, the European Court of Justice annulled the directive, citing that it was undue interference with citizens privacy.

The Data Retention (EC Directive) Regulations 2009

This UK law was the UK passing into law the requirements of the European Directive, but as the directive was annulled, when asked, the UK government said that the law still applies, despite the European court ruling that such retention "breaches citizens' fundamental right to privacy" .

Digital Economy Act 2010 (DEA2010)

Part of this legislation relates to unlawful activity on your Internet connection and that you, as the owner/operator of the service may be considered the most likely or possible culprit of any unlawful activity. For that reason, in order to protect yourself if you do allow others or the public to use your systems, you may wish to keep records which could help show that you were not responsible. It is our opinion that simply showing that (for example) a pirate movie was downloaded via your IP address would be insufficient to convict you, especially if you can reasonably show that other people may use your connection. Even if the DEA doesn't catch you, this doesn't mean, as has happened in the past that copyright holders won't directly demand penalties directly under threat of legal proceedings, sometimes against entirely innocent people who, faced with being publicly accused of downloading (say) pornography, pay up. Certainly never leave a WiFi connection without a password, for many reasons, but in particular relation to this topic, to stop people using it without permission and if you offer guest access, consider blocking protocols which are mostly used for piracy or unlawful activities (torrents, Tor etc.).

Ofcom's "DEA Initial Obligations Code"

Augmenting the DEA2010 further, Ofcom have their own set of rules and warn consumers about the risks of letting other people use their connections. Ofcom's "three strikes" rule could cause suspension of your service if you repeatedly allow pirated materials to be downloaded through your connection, and ISPs are obligated to identify you to the copyright holders.

i.e. the copyright holder would normally only know your IP address; the ISP is required to identify you fully. The rules and obligations are different for businesses who are providing Internet access (or WiFi) as a service (for example a coffee shop) and such businesses would not be assumed to be the responsible party.

January 2004 Code of Practice (Voluntary Retention of Data)

This code of practice was a result of Part 11 of the Anti-terrorism, Crime & Security Act 2001. It is voluntary, not mandatory (at the time of writing).

Data Protection Act 1984

Under the DPA, the users who you actually store or retain the data, where they are identifiable, have a right to request that data from you (you may charge a reasonable fee).

So, that's a summary. Like we said, we can't give you a definitive answer which will stay valid as things evolve but you may be able to make a value judgement on what you should do or at least know where to look further. If in doubt, take formal qualified legal advice in your country. This is a UK article, so if you are reading this elsewhere, you laws and requirements will be different.
 

chesterred16

Member
Joined
31 Aug 2021
Messages
60
Location
Chester
Being fined is somewhat dependent upon a complaint (or breach notification) actually being logged though.

The vast majority of people just accept the wifi terms without reading them and just 'accept' that they have to provide an email address then forget about it.

Such a complaint also requires some sort of basis. I haven't read anything in this thread yet which points to any specific DPA offence or GDPR principle being breached. It's more a feeling of, "I resent this.", than, "This is unlawful and here's why." I also suspect most operators contract out the wifi provision, e.g. LNER and Northern pay icomera to operate their on-board wifi and I expect icomera may advise what sort of things need collecting and what may be needed in a privacy notice. Fundamentally I expect the operators have adequate legal basis for their wifi data collection and retention. I imagine it is mostly aggregate information or wifi session metadata used for statistical purposes.
The fear isn't complaints as such (at least with our company), it's hackers getting the personal data via some weakness. That's where the fines really kick in. Who's holding the data, how secure is it really, and are the TOCs insured against the risk of unauthorised data loss? As I said, the best defence is not holding the data in the first place.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,850
Location
Gwynedd
The fear isn't complaints as such (at least with our company), it's hackers getting the personal data via some weakness. That's where the fines really kick in. Who's holding the data, how secure is it really, and are the TOCs insured against the risk of unauthorised data loss? As I said, the best defence is not holding the data in the first place.
I don't disagree that the best defence is not holding the data, and that's my preference as a consumer also.

I was merely responding to the surprise at no ICO fines having been levied. I'm not convinced the TOCs are doing anything unlawful in collecting and processing the data, so I don't think there's anything to take to the ICO really.

I also suspect that, while say LNER may be the data controller, the data collector and processor is going to be icomera, and given it's their entire business, I imagine they're reasonably DPA/GDPR-compliant.
 
Status
Not open for further replies.

Top