Define the processing before choosing controls
Under UK GDPR and the Data Protection Act 2018, transparency is a fundamental data protection principle. For organisations deploying proximity technology—Bluetooth beacons, NFC tags, QR codes, and indoor navigation systems—this means providing clear, accessible information to visitors about what happens when their device interacts with your physical infrastructure.

A generic corporate privacy policy published on a website is rarely sufficient on its own. The Information Commissioner’s Office (ICO) expects information to be provided at the point of interaction. Transparency notices in this context are the specific, often localised, explanations given to people before or as they enter a tracked zone, scan a code, or tap a tag. They bridge the gap between a full legal privacy policy and the physical moment a signal is broadcast or received.
These notices must explain the identity of the data controller, the purpose of the processing, the specific technology in use, and what data is actually collected. In proximity deployments, this often means clarifying whether you are collecting a device’s MAC address (even if hashed), logging a QR scan timestamp, or simply detecting a anonymous Bluetooth ping for footfall counting.
Consent, lawful basis and user choice
Retail environments
If a shop uses beacons to detect footfall near a till point or to trigger push notifications via a proprietary app, a notice at the entrance or within the app’s onboarding flow must state this. The notice should explain that Bluetooth signals are used to estimate proximity, what the data is used for (such as queue management or personalised offers), and who is responsible for that data. Physical signage works alongside digital app permissions to build a complete picture for the visitor.
Museums and exhibitions
Visitors interacting with NFC tags or QR codes on exhibits need immediate context. A small physical label beside the tag stating that scanning the code logs an interaction with that specific exhibit for visitor analytics provides necessary transparency at the precise point of engagement. If the venue uses indoor navigation beacons to power a wayfinding app, corridor signage should indicate that the space uses location-sensing technology and direct visitors to the full privacy information.
Events and temporary venues
Pop-up events using temporary beacon grids or QR-based ticketing face specific logistical challenges. Physical A-boards, lanyard inserts, or notices on the reverse of event badges act as transparency notices. The operational priority here is ensuring the notice is deployed alongside the technology and remains legible throughout the event, rather than being left in a box with the unused lanyards.
The layered approach
Given the physical space constraints on signs and labels, a layered approach is the most practical solution. A short, clear statement on-site—such as "This venue uses Bluetooth beacons for wayfinding. Find out more at [URL]"—paired with a comprehensive digital privacy policy satisfies the requirement for both conciseness and completeness. The physical notice catches attention; the digital document provides the legal detail.
Retention limits and ongoing governance
Common mistakes
- Burying the information: Linking to a lengthy privacy policy from a tiny QR code on the back of a door does not meet the standard for clear, accessible information. The core message must be visible without requiring a scan.
- Vague language: Stating "we use your location data" without specifying that the location is derived from Bluetooth signal strength (RSSI) or QR scan logs is misleading. The mechanism must match the notice.
- Stale notices: Changing a beacon configuration, adding a new NFC campaign, or switching analytics providers without updating the corresponding physical or digital notices is a frequent oversight. The notice must reflect the current system, not the system as it was deployed two years ago.
Limitations
Banner blindness is a genuine problem in busy retail or event spaces; people simply do not read signs. While you must provide the notice to meet your legal obligations, you cannot assume it has been read or understood. This reinforces the need for robust, separate consent mechanisms within your app or web interface, rather than relying on a physical sign alone to imply permission.
In multi-tenant buildings, such as shopping centres or shared exhibition halls, determining who is responsible for the notice requires clear contractual alignment. The data controller for a beacon network might be the centre management, while the data controller for an NFC tap at a specific pop-up stand is the individual retailer. A single, generic venue notice may not accurately reflect these divided responsibilities.
Key checks
- Is the notice positioned exactly where the interaction happens, rather than at a generic building entrance?
- Does it identify the data controller by name or clearly distinguish between joint controllers?
- Does it specify the exact technology being used (e.g., Bluetooth Low Energy, NFC, dynamic QR code)?
- Does it state the purpose clearly in plain language (e.g., "to count visitors to this zone", "to display exhibit information")?
- Is there a direct, working link to the full privacy policy for those who want more detail?
- Has the notice been reviewed and updated to match any recent changes to the beacon inventory, NFC tag URLs, or analytics platform?