Around a decade ago, phone makers changed one of the quietest defaults in computing: the MAC address, the permanent hardware identifier a phone broadcast with every Wi-Fi transmission, became randomised. It was a genuine privacy improvement, aimed at a real abuse, the silent logging of permanent identifiers as people moved through cities. It also created two myths that still shape how people think about Wi-Fi analytics: that randomisation made tracking impossible, and that randomisation is what protects visitors from counting systems. Both are wrong, in instructive ways.

What randomisation actually does

A randomising phone presents different MAC addresses in different contexts: one while scanning, typically another per network it joins, rotating on schedules that vary by manufacturer and operating system. Platform documentation describes the design goal plainly: the address a network sees should not be a stable, universal identifier that follows the device everywhere. Against the crude tracker that randomisation targeted, an address logger matching one permanent ID across locations, it works.

What the research keeps finding

Against more determined analysis, the picture is different, and the security literature has been consistent about it. Studies of randomisation implementations have demonstrated practical ways to defeat it, and analyses of probe-request traffic show that the timing, sequence and content patterns of a device’s transmissions form a fingerprint that survives address changes. Later work combining temporal and content-based fingerprints reports de-randomisation at rates that should end any illusion of anonymity-by-address. The honest conclusion: MAC randomisation reduced casual tracking, and a capable adversary with raw signal access can often work around it.

That conclusion matters for how you evaluate any system that hears Wi-Fi signals, including counting systems. If a vendor’s privacy story amounts to “addresses are randomised anyway”, they are resting your compliance on the phone-maker’s imperfect defence rather than on their own design.

Privacy by architecture, not by address

The right lesson is architectural. A measurement system designed for privacy does not depend on what the phone does, because it removes the attack surface on its own side: personal data is irrevocably deleted at the start of the pipeline, never hashed and kept, never stored, and only anonymous, aggregated statistics remain. There is no address log to de-randomise, no raw signal archive to fingerprint, nothing to breach and nothing to subpoena. This is the design behind our Wi-Fi method, the only footfall method in Europe approved by a data protection authority, and it is the standard the DPIA questions are really probing for.

And yes, it made counting harder, honestly

There is an accuracy side to this story. A counter that trusts addresses double-counts every randomising phone, so serious measurement detects randomisation patterns, filters spoofing and stationary devices, and calibrates the statistical model against manual control counts. That correction layer, not the sensor, is where counting quality is decided. Randomisation forced the industry to grow up twice: on privacy and on method. How the signals become statistics in the first place is covered in what is a probe request, this article’s natural companion.

Frequently asked questions

What is MAC randomisation?

Instead of broadcasting its permanent hardware address, a modern phone presents randomised MAC addresses that change over time and differ per network. Introduced across major mobile platforms over the last decade, it was designed to stop the crudest form of Wi-Fi tracking: logging one permanent identifier as it reappears.

Does MAC randomisation make Wi-Fi tracking impossible?

No, and this is well documented. Academic work has shown that devices can be fingerprinted despite randomisation, through timing, sequence and content patterns in their transmissions, and platform documentation itself describes randomisation that persists per network rather than changing constantly. Randomisation raised the bar; it did not build a wall.

If randomisation is imperfect, what actually protects visitors?

The architecture of the receiving system. A system designed for privacy deletes personal data irrevocably at the start of its pipeline, never hashed and kept, never stored, leaving only anonymous, aggregated statistics. Then it does not matter what a clever adversary could in principle do with raw signals, because the raw material does not exist to attack.

How does randomisation affect counting accuracy?

A naive counter that trusts addresses counts the same phone several times. Serious measurement detects and corrects for randomisation, spoofing, stationary devices and staff patterns, then calibrates against manual control counts. The correction layer is where counting quality is decided, which is why method maturity matters more than sensor choice.

Privacy that doesn't depend on the phone's behaviour

Book a walkthrough and see measurement whose privacy case rests on architecture, reviewed and approved where it matters most.

Book a demo