Data and privacy
Published
Event Tech Notes Data and privacy
An event is a data-collection operation with catering. Most organizers collect far more personal data than they realize and keep it far longer than they can justify.
Walk through your own event as a record rather than a person. Registration captured your name, email, employer, title, dietary requirements, maybe accessibility needs. Check-in logged your arrival time. Session scans logged which rooms you entered and when. The app logged what you tapped. Exhibitors scanned your badge and now hold a copy of your record. Photography captured your face. That is the actual inventory, and it is what the law regulates, not the subset you remember collecting.
The regulatory floor
If any attendees are in the EU, or you target the EU market, the General Data Protection Regulation applies regardless of where your organization sits. Reading a summary is no substitute for the source; the full text of the GDPR is organized by article and more readable than its reputation. US organizers without EU exposure still face state privacy laws that borrow the same skeleton: a lawful basis for processing, disclosure, access and deletion rights.
The concepts that do the work:
- Lawful basis. You need a defensible reason for each processing activity. Running the event the attendee registered for covers a lot (contract, or legitimate interest). Marketing to them afterward, or handing their record to sponsors, does not ride along automatically.
- Consent must be real. Freely given, specific, informed, and as easy to withdraw as to give. A pre-ticked box is not consent. "By attending you agree to everything" is not consent.
- Purpose limitation. Data collected to run the event cannot be silently repurposed. This is the clause your sponsorship team will dislike, which is exactly why it needs deciding in advance.
Badge scans are personal data
A badge scan is not a neutral logistics ping. It is a timestamped record that an identifiable person was in a particular place, and a day of session scans is a movement profile. Two consequences follow.
First, session scanning needs a disclosed purpose. Scanning for capacity and continuing-education credit is easy to justify and easy to explain. Passive tracking (RFID portals reading badges without a deliberate tap, as covered under check-in and badging) is harder on both counts, because the attendee performs no intentional act.
Second, exhibitor scans are a disclosure of personal data to a third party, and the attendee is entitled to know that presenting a badge means handing over their record. Who becomes responsible for that data afterward is messy enough to have its own page; the short version is that "scanning implies consent" is an assumption, not a legal position.
Retention: decide, write it down, do it
Data kept "in case it is useful" is pure liability: breach exposure grows, subject-access requests get harder, and no one can explain why a dietary requirement from three events ago still exists. Dietary and accessibility data can reveal health information and deserves the shortest life of all, days after the event, not years.
Set a schedule per category (registration record, financial record, scan logs, special-category data), and then verify deletion actually happens in each vendor's system, not just your spreadsheet. Vendor retention defaults are a contract question, and "we keep it indefinitely" is a common, negotiable default.
What goes in the privacy notice
The notice is shown at registration, linked from the confirmation email, and written in plain language. It should state: who the controller is (you, not your platform vendor); what is collected; the purpose and lawful basis for each use; who receives it, named by category, including registration vendor, app vendor, and exhibitors via badge scans; transfers out of the attendee's region; how long each category is kept; and how to exercise access, correction, and deletion rights, with a working contact.
Then make the operational reality match the document. The gap between a privacy notice and actual data flows is where regulators and journalists both start digging, and at an event the flows are unusually easy to observe: they are printed on a badge and standing in a booth.