UK legal note: This article is planning guidance, not legal advice. The Data (Use and Access) Act 2025 has amended parts of the UK data-protection framework, and ICO guidance continues to be updated. Check the current guidance and the actual data flow before launch.

No single “proximity technology law” applies to every installation. The applicable duties depend on whether the system processes personal information, sends direct marketing, uses communications-network location data, changes a public service journey, modifies a building or introduces installation work.

A gallery visitor using contactless technology to explore cultural content
Illustrative example of NFC or QR access to gallery information.

Data (Use and Access) Act 2025 changes

The Act amended parts of the UK data-protection framework. By 19 June 2026 organisations were required to have a process for data-protection complaints, including acknowledgement and response duties described by the ICO. Existing UK GDPR, Data Protection Act 2018 and PECR analysis still depends on the facts of the processing, so use current ICO guidance rather than a frozen checklist.

Deploying beacons, NFC tags, QR codes and indoor navigation systems in UK physical spaces brings the project into contact with data protection law, accessibility duties, British Standards and health and safety obligations. Understanding which rules apply at each stage, from procurement through to ongoing operation, prevents costly remediation work and reputational damage later. This guide sets out the regulatory landscape as it stands, with practical pointers on what to check and where.

UK data protection: start with the actual data flow

UK GDPR applies to any processing of personal data within the deployment of proximity technology. The critical question for most projects is whether the data collected amounts to personal data at all. A MAC address received from a smartphone that has not been randomised can, in many cases, identify an individual device and therefore falls within the definition. Even when addresses are randomised, a sequence of location observations over time can be linked to a device profile, which the ICO has acknowledged may still constitute personal data in certain contexts.

For proximity marketing notifications triggered by beacons, the lawful basis most organisations rely on is consent. Under UK GDPR, consent must be freely given, specific, informed and unambiguous. A blanket notification permission granted when downloading a venue app does not, by itself, cover location-triggered messages. The user needs a clear explanation that their location will be used to send them targeted content, and they must be able to refuse without losing access to core app functions.

NFC and QR interactions sit slightly differently. When a visitor physically taps an NFC tag or scans a QR code, they are taking a deliberate action to access content. The act of scanning itself can demonstrate a degree of informed engagement, but it does not automatically satisfy all transparency requirements. The landing page should still make clear what data, if any, is being collected and why.

Practical steps to address UK GDPR in a proximity deployment include documenting the lawful basis for each data flow before going live, building privacy notices into the onboarding sequence rather than burying them in terms and conditions, and ensuring the backend can honour data subject access and deletion requests within the statutory timeframes. If an integrator or platform provider processes data on your behalf, a written data processing agreement is required regardless of contract size.

PECR location-data rules are narrower than the everyday phrase

The Information Commissioner's Office has published specific guidance on the use of location data and technologies that track devices in physical spaces. While the guidance does not create new law, it sets out the ICO's regulatory expectations and is the reference point against which enforcement decisions are made.

Key points from the ICO's position include an expectation that organisations will conduct a data protection impact assessment before deploying any system that tracks device locations within a venue. The DPIA should cover what data is collected, how long it is retained, whether it is aggregated or linked to individuals, and what controls exist to prevent function creep, such as using footfall data originally collected for capacity management to build individual visitor profiles for marketing.

The ICO distinguishes between anonymised data, which falls outside the scope of UK GDPR entirely, and pseudonymised data, which does not. Genuine anonymisation of location data is difficult to achieve in practice because re-identification risks persist when datasets can be combined with other sources. Organisations claiming anonymisation should be prepared to evidence the methodology and the residual risk assessment.

For analytics use cases, such as dwell time measurement or heatmapping, the ICO expects data minimisation. Collecting raw RSSI values from every beacon encounter when the business question only requires zone-level presence data is difficult to justify. The guidance encourages aggregation at the earliest possible stage and retention periods tied to a demonstrated need rather than a default setting in the analytics platform.

When reviewing a proximity platform, ask the supplier for a summary of how their data architecture supports UK GDPR principles, what aggregation options exist at the point of collection, and whether their default retention periods can be configured to match your own policy. If the supplier cannot provide clear answers, that is a meaningful risk signal regardless of how capable the technology appears.

Standards, guidance and contractual requirements

There is no single British Standard that governs indoor navigation systems in the way that BS 5266 governs emergency lighting. Instead, relevant requirements are spread across several standards, some of which address the built environment and others the digital systems layered on top of it.

BS 8300 and its accompanying BS 8300-2 address the design of an accessible and inclusive built environment. While these standards do not prescribe indoor navigation software, they set requirements for wayfinding provision in physical spaces, including signage, tactile surfaces and the logical sequencing of routes. Any indoor navigation system deployed in a public building should be checked against BS 8300 to confirm that the digital wayfinding does not conflict with or undermine the physical wayfinding provisions.

BS EN ISO 21542 covers accessibility and usability of the built environment and includes provisions relevant to wayfinding for people with visual impairments. Where an indoor navigation app is intended as an aid for visually impaired visitors, the design should be informed by the principles in this standard, even though the standard itself does not mandate digital solutions.

For the digital components, PAS 1880, published by BSI, provides guidance on the use of connected and autonomous vehicles in public spaces, which includes some provisions for infrastructure communication. While not directly about indoor navigation, it illustrates the direction of standards development for location-aware systems in shared spaces.

The practical implication is that specifiers should not expect a single standard to tick the compliance box. Instead, review the relevant built environment standards for the venue type, check whether any sector-specific guidance exists, such as that produced by the Museums Association or retail industry bodies, and document how the indoor navigation system aligns with each. When tendering the project, requiring the supplier to map their proposed solution against the applicable standards is a reasonable and useful requirement.

Accessibility duties must shape the full journey

Two main regulatory frameworks impose accessibility obligations on indoor wayfinding systems in the UK: the Equality Act 2010 and the Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018.

The Equality Act 2010 requires service providers to make reasonable adjustments to avoid putting disabled people at a substantial disadvantage. Applied to indoor navigation, this means considering whether the wayfinding system is usable by people with visual impairments, mobility impairments, cognitive disabilities or hearing impairments. A system that relies solely on visual map cues without voice guidance or large-text options may fail to meet this obligation for certain user groups. The duty is not to achieve perfection but to take proportionate steps, and what is reasonable depends on the size and resources of the organisation.

The 2018 Accessibility Regulations apply directly to public sector bodies and require their websites and mobile applications to meet WCAG 2.1 AA standards. If a local authority museum or an NHS trust deploys an indoor navigation app, that app falls within scope. Private sector organisations are not directly bound by these regulations, but WCAG 2.1 AA has become the de facto benchmark for digital accessibility in the UK, and meeting it reduces the risk of Equality Act claims.

For indoor wayfinding specifically, accessibility considerations extend beyond screen-reader compatibility. They include whether the system provides step-free route options, whether it accounts for temporary obstacles like closed lifts or stairs, whether the timing of turn-by-turn instructions is appropriate for users who move at different speeds, and whether the interface remains usable in environments with poor lighting or high ambient noise.

When evaluating a wayfinding platform, request the supplier's accessibility statement and any WCAG conformance documentation. Ask specifically how the system handles step-free routing, how it behaves when a user's preferred accessibility settings are enabled at the operating system level, and whether they have involved disabled users in testing. A supplier who cannot describe their accessibility testing process is unlikely to have taken the obligation seriously.

Installation remains ordinary workplace risk management

Physical installation of beacons introduces health and safety obligations that are easy to overlook during the procurement and planning stages. The Management of Health and Safety at Work Regulations 1999 require a suitable and sufficient risk assessment before any installation work begins.

The most immediate concern is working at height. Beacons mounted on ceilings or high walls require the use of step ladders, tower scaffolds or mobile elevated work platforms, depending on the height and the duration of the work. The Work at Height Regulations 2005 apply, and the hierarchy of controls, avoiding work at height where possible, then preventing falls, then mitigating the consequences of a fall, must be followed. In a retail environment, installation during trading hours introduces additional risks from members of the public, so scheduling work outside opening hours is usually the safer approach.

Battery safety deserves specific attention. Most beacons use lithium coin cells or lithium-polymer packs. While the energy content of a single coin cell is low, damaged or improperly disposed-of lithium cells present a fire risk, particularly if large numbers of spent batteries accumulate in a store room. The installer should have a procedure for safe battery removal and disposal that complies with the Waste Batteries and Accumulators Regulations 2009. If beacons with replaceable batteries are specified, the maintenance schedule should include safe handling instructions for operational staff who will be swapping cells.

Fixing methods also require consideration. Adhesive-backed beacons are convenient but can fail over time, particularly in environments with temperature fluctuations or high humidity. A beacon falling from a ceiling onto a visitor is a foreseeable hazard that should be addressed in the risk assessment. Mechanical fixings, such as cable ties to ceiling grids or screws into structural elements, are more secure but take longer to install and may require permission from the building owner or landlord. The chosen fixing method should be documented for each beacon location, and periodic inspections should check for deterioration.

Fire safety regulations may be relevant depending on the venue. In premises subject to the Regulatory Reform (Fire Safety) Order 2005, any physical alteration to the building, including the addition of ceiling-mounted devices, should be considered in the fire risk assessment. While a small beacon is unlikely to materially affect fire safety, the cumulative effect of cabling, if powered beacons are used, or the potential for devices to fall and obstruct escape routes, should be evaluated.

For venues with specific regulatory regimes, such as healthcare settings under NHS estate management rules or listed buildings under heritage protection, additional consents or procedures may apply. The installation plan should identify these requirements early, as obtaining listed building consent or NHS estates approval can add weeks to a project timeline.

Project compliance register

Maintain one register linking each requirement to the project feature, evidence owner and review date. Separate legal duties, published standards, good-practice guidance, contractual requirements and internal policy; they do not carry the same status.