The processing decision behind the project
Museums occupy an unusual position in privacy law. Visitors enter a public building, often without buying a ticket or creating an account, and may not expect their movements to be recorded. When a museum introduces Bluetooth beacons, Wi-Fi tracking, or camera-based analytics, the legal and ethical baseline shifts. Understanding where consent is required—and where it is not—depends entirely on what the technology actually does with the data it collects.

The UK GDPR draws a clear line between anonymous, aggregated footfall measurement and individual-level tracking. If a system detects device signals but immediately discards identifiers and only stores counts per zone, many organisations treat this as not involving personal data at all. The moment a device identifier is logged, linked to a profile, or used to trigger a personalised notification, personal data is in scope and a lawful basis must apply.
Consent is one of six lawful bases under UK GDPR, but it is not always the right choice. For a museum app that sends exhibit-related notifications, consent is the natural fit because the visitor is actively opting into a service. For back-of-house operations like queue monitoring or cleaning schedules based on zone occupancy, legitimate interests may be more appropriate—provided a proper balancing test is documented and visitors are informed via signage.
Transparency as a Non-Negotiable
Regardless of the lawful basis chosen, transparency is required. The Information Commissioner's Office (ICO) expects organisations to tell people what is happening in a way they can reasonably understand. In a museum, this typically means clear signage at entrances and at the point where tracking begins. A small notice buried in a terms-and-conditions page does not meet this standard when the visitor never opened an account.
Children present a further complication. Museums attract school groups and families with younger children who cannot validly consent. If a system can identify or profile individual visitors, the museum needs a strategy for handling under-18s—whether that means excluding them from personalised features, relying on parental consent, or designing the system so it never processes individual child data in the first place.
Design controls around the real data flow
Different museum use cases demand different consent approaches. Mapping these out before procuring any hardware prevents costly redesigns later.
Exhibit-Triggered Content via App
A visitor downloads the museum's app, enables Bluetooth, and receives information about nearby exhibits. Here, consent is collected within the app at the point the visitor enables location services or pushes a specific "allow nearby alerts" toggle. The consent record should capture what the visitor agreed to, when, and which version of the privacy notice was in force. If the museum later wants to add dwell-time analytics or personalised recommendations based on visit history, fresh consent is generally required because the purpose has expanded.
Web-Based or QR-Triggered Experiences
Some museums avoid apps entirely and use QR codes or NFC tags that open a web page when tapped. If the web page simply displays static exhibit text, no consent is needed for location processing because no location data was collected—the visitor chose to scan a specific tag. If the same web page requests background location access to offer wayfinding, the browser's own permission dialogue acts as a consent mechanism, but the museum must still provide a privacy notice explaining why location is needed and what will happen with it.
Anonymous Footfall Analytics
Beacons or Wi-Fi access points that count devices per zone without storing MAC addresses or other identifiers sit in a grey area. Many organisations argue this falls outside personal data entirely. The safer approach is to document the data flow, confirm with your data protection officer or legal adviser that identifiers are genuinely irreversibly discarded, and still put up signage explaining that anonymised footfall data is collected to improve the visitor experience. This pre-empts complaints and demonstrates accountability.
Signage Placement and Wording
Effective signage is specific, visible, and written in plain language. A notice at the main entrance that reads "We use Bluetooth beacons to understand how visitors move through the museum. No personal data is stored. Speak to staff or visit [URL] for details" achieves more than a legalistic paragraph. Signs should also appear at transition points where a new type of detection begins—for example, at the entrance to a temporary exhibition that uses a different tracking system from the permanent galleries.
Group Visits and Shared Devices
Families often share a single phone for the museum app. If the app logs visit history to a device identifier, it is effectively building a profile that represents multiple people without any of them having explicitly agreed. Designing the app to allow guest mode, or to clear session data on exit, reduces this risk. For school groups using shared devices provided by the museum, the consent model needs to account for the fact that dozens of children may use the same hardware in a single day.
Exceptions, incidents and reassessment
Assuming Public Space Removes the Obligation
A frequent error is the belief that because a museum is open to the public, visitors have no reasonable expectation of privacy regarding their movements. UK case law and ICO guidance do not support this assumption. The nature of the space, the type of tracking, and what a reasonable person would expect all factor into the assessment. A security camera at an exit is one thing; continuous Bluetooth tracking that builds a timeline of every gallery visited is another.
Bundling Consent with Other Agreements
Presenting location consent as a non-negotiable part of app terms and conditions, or making it a condition of free Wi-Fi access without a genuine alternative, invalidates consent under UK GDPR. Consent must be freely given, specific, and uninfluenced by bundling. If a museum wants to offer Wi-Fi contingent on analytics tracking, legitimate interests may be the more defensible basis—but the balancing test must genuinely consider the visitor's reasonable expectations.
Collecting More Than the Use Case Requires
Data minimisation is a core principle. If the only purpose is triggering an exhibit description when a visitor is within three metres, there is no lawful reason to log the timestamp of every beacon sighting for later analytics. Over-collection increases risk and makes the consent explanation more complicated, which in turn makes it harder to argue that consent was informed. Before deployment, map every data field to a specific, documented purpose.
No Clear Path to Withdraw Consent
Withdrawing consent must be as easy as giving it. If a visitor enabled location alerts with a single tap in the app, they should be able to disable them with a single tap—not by navigating to a settings menu four levels deep, and not by emailing a support address that takes five working days to respond. The withdrawal mechanism should also confirm what happens to historical data: is it deleted immediately, retained in anonymised form, or kept for a defined period?
Key Checks Before Deployment
- Lawful basis documented: For each data processing activity, is the lawful basis recorded, and has a legitimate interests assessment been completed where applicable?
- Privacy notice current: Does the notice accurately describe what data is collected, why, how long it is kept, and the visitor's rights?
- Signage in place: Are notices visible at all entry points and at locations where a new type of detection begins?
- Consent granularity: Can visitors opt into exhibit alerts without also opting into marketing emails or third-party data sharing?
- Withdrawal tested: Has someone unfamiliar with the system tried to find and use the opt-out mechanism?
- Children addressed: Is there a documented approach for visitors under 18, and does the system design reflect it?
- Retention defined: Is there a clear, justified retention period for each data type, and an automated or manual process for deletion?
- Supplier due diligence: If a third-party platform processes the data, is there a data processing agreement in place, and has the supplier's privacy practices been reviewed?
Consent in a museum environment is not a one-time compliance checkbox. Exhibitions change, technology is updated, and visitor expectations shift. Building a review cycle into the operational calendar—revisiting privacy notices, signage, and consent flows at least annually or whenever a new use case is introduced—keeps the museum's position defensible and its relationship with visitors grounded in transparency.




