Purpose, people and data flows
Under UK GDPR, any organisation processing personal data must choose a lawful basis before it begins. For location data collected through Bluetooth beacons, Wi-Fi tracking, or indoor positioning systems, the two bases most often discussed are opt-in consent and legitimate interest. They sit at opposite ends of the risk spectrum, and choosing the wrong one is one of the most common compliance errors in proximity deployments.

Opt-in consent means the individual has given clear, affirmative agreement to their location data being collected for a stated purpose. The standard is high: consent must be freely given, specific, informed, and unambiguous. Withdrawing it must be as easy as giving it. For proximity systems, this typically means a permission prompt in an app, a toggle in a venue's web experience, or a deliberate action such as scanning a QR code that leads to an explicit consent screen.
Legitimate interest (Article 6(1)(f) of UK GDPR) allows processing without explicit consent where the organisation has a genuine business reason, the processing is necessary to achieve it, and the individual's rights and freedoms do not override that interest. Crucially, a documented Legitimate Interest Assessment (LIA) must be completed before processing starts. The Information Commissioner's Office (ICO) expects to see a three-part test: identify the legitimate interest, show necessity, and conduct a balancing test weighing the impact on the individual.
The practical difficulty with location data is that it can reveal sensitive details about a person's movements, habits, health conditions, or religious practices. The ICO has repeatedly signalled that location tracking, particularly when it is continuous or not immediately obvious to the individual, carries a high privacy impact. That does not automatically rule out legitimate interest, but it makes the balancing test considerably harder to pass. In many real-world proximity deployments, relying on consent is the more defensible path.
This article focuses on the decision between these two bases. It does not cover the mechanics of building consent flows or app-specific permission prompts, which are addressed separately in the neighbouring guides on obtaining valid consent and consent for app-based proximity.
Consent, lawful basis and user choice
Aggregated footfall counting
Some beacon and Wi-Fi systems count device pings in a zone without storing identifiers. If the data is genuinely aggregated in real time and no individual device can be identified or re-identified later, it may fall outside the scope of personal data entirely. In that scenario, neither consent nor legitimate interest is required because UK GDPR does not apply. However, the threshold for genuine anonymisation is strict. If a MAC address, advertising identifier, or hashed device fingerprint is logged even briefly before aggregation, the data is likely still personal data, and a lawful basis is needed.
Zone-level analytics with pseudonymised identifiers
A museum or retail venue might track which zones a device visits and for how long, using a pseudonymised identifier rather than a name or email. The data reveals movement patterns but not identity. Here, some organisations attempt to rely on legitimate interest, arguing that understanding visitor flow is a core operational need. The LIA would need to address whether the same insight could be achieved with a less intrusive method, whether individuals would reasonably expect this tracking, and whether signage adequately informs them. Even with a strong LIA, many venues opt for consent because the public expectation of privacy in indoor spaces has shifted, and the reputational risk of a complaint is significant.
Individual-level location triggers and notifications
When a system sends a push notification to a specific user because they entered a defined zone, the processing is clearly individual-level. Legitimate interest is extremely difficult to justify here. The user receives a targeted message based on their precise physical location, and the purpose is commercial rather than necessary for security or safety. Consent is the appropriate basis in nearly all cases.
Staff and workforce tracking
Employers sometimes use beacons or indoor positioning to monitor staff locations in warehouses, hospitals, or large venues. The power imbalance between employer and employee makes "freely given" consent almost impossible to demonstrate. Legitimate interest may be arguable where there is a genuine health and safety justification, but the LIA must be rigorous and the processing proportionate. The ICO's Employment Practices Code provides additional guidance specific to this context.
Temporary event deployments
At a conference or exhibition, a short-term beacon network might be used for wayfinding or session check-in. The limited duration does not, by itself, lower the privacy bar. If individual devices are identified and their movements logged, a lawful basis is still required. Some event organisers use a hybrid approach: aggregated counting for operational analytics with no personal data stored, and consent-based features such as personalised schedules or networking prompts for users who opt in.
Rights, retention and accountability
Assuming legitimate interest is the default
A frequent error is treating legitimate interest as a lighter, easier alternative to consent. In practice, a properly conducted LIA requires documented evidence, legal input, and a genuine balancing exercise. If the LIA exists only as a tick-box exercise filed after deployment, it will not withstand scrutiny. The ICO can request to see it, and an absent or superficial assessment is itself a compliance failure.
Confusing notice with consent
Putting up a sign at a venue entrance stating "this premises uses beacon technology for analytics" provides transparency but does not constitute consent. Transparency is a separate GDPR requirement. Notice without a clear opt-in mechanism supports a legitimate interest argument only if the LIA balancing test holds, which, as noted above, is difficult for location tracking.
Treating pseudonymisation as a free pass
Replacing a device MAC address with a hashed or randomised identifier reduces risk but does not remove the data from the scope of UK GDPR. If the organisation holds the key to re-identify the device, or if the pseudonymised identifier can be linked back to an individual through another system, the data remains personal. The lawful basis must still apply.
Ignoring purpose limitation
Data collected under one lawful basis for one purpose cannot simply be repurposed. If zone-level analytics were initially justified under legitimate interest, the same dataset cannot later be used to send targeted proximity notifications without revisiting the lawful basis, which in most cases would mean obtaining consent.
Key checks before choosing a basis
- Is the data genuinely anonymised? If no identifier is stored at any point, GDPR may not apply. Verify this with technical assurance, not assumption.
- Is the processing individual-level? If a specific device can be singled out and its movements profiled, consent is almost certainly the safer basis.
- Would the individual reasonably expect this? Consider whether a typical visitor to your type of venue would anticipate being tracked indoors. The answer has shifted noticeably towards "no" in recent years.
- Can the same result be achieved less intrusively? If aggregated counting or manual observation would suffice, the necessity test for legitimate interest is harder to meet.
- Is there a documented LIA? If you are relying on legitimate interest, the assessment must exist before processing begins and should be reviewable.
- Can people easily withdraw? If you choose consent, the withdrawal mechanism must be as accessible as the original opt-in.
This guidance is practical rather than legal. For deployments involving individual-level location data, complex LIA arguments, or data sharing with third parties, seek proper legal advice and refer to the ICO's current guidance on lawful bases and location data. The regulatory landscape continues to evolve, and internal policies should be reviewed against the latest published guidance rather than relying on assumptions from past projects.

