Data privacy at events: badges, apps, and attendee consent
Every badge scan and every event app is a data collection point, and in healthcare and finance rooms that turns into a liability fast. Here is what I collect, what I refuse to, and how I get consent that holds up.
A compliance officer at a finance client of mine asked one question in the kickoff call that changed how I run registration. “When your badge scanner reads my attendee at a session door, where does that record go, and who owns it?” I did not have a clean answer. The lead-retrieval vendor owned the data, stored it who-knows-where, and my client’s name was on the event. That was three years ago. Now I can answer it before anyone asks.
Events are data operations wearing a lanyard. You collect names, titles, employers, dietary restrictions, sometimes health accommodations, session attendance, badge-scan movement, and app behavior. In healthcare and finance, half of that is regulated the moment you write it down. The venue does not carry this for you. You do.
The three data streams nobody maps
Registration. Name, email, company, title, and the quiet extras: dietary needs, accessibility requests, emergency contact. A gluten allergy is arguably health data. A request for a sign-language interpreter is close to it. If you are running a hospital-system client, treat that field like it is protected, because a regulator might.
Badge scanning. Two kinds, and people confuse them. Access scanning at a session door tells you who attended what. Lead-retrieval scanning at a sponsor booth hands an attendee’s full contact record to a third-party company. Those are not the same consent. An attendee who registered did not agree to have their profile handed to twelve exhibitors because they walked past a booth.
The event app. This is the leakiest stream. Apps collect location signals from in-room sensors, in-app messages, session bookmarks, and sometimes contact-sync permissions that scrape a phone’s address book. I stopped defaulting to a full app years ago for exactly this reason, and I laid out the operational case in why I stopped using event apps. The privacy case is just as strong.
What I collect, and what I refuse
My rule is collect the minimum the event actually needs to run. Name and company for the badge. Email for logistics. Dietary and accessibility only where catering and setup require it, and stored separately from the marketing list. I do not collect a phone number unless there is a same-day operational reason, because a phone number is a marketing asset a sponsor will ask for and I will have to say no.
The line I hold hardest: session-attendance data does not go to sponsors. Ever. If a sponsor paid for a lead list, they get the people who opted in at their booth, not a heat map of who sat in which breakout. That distinction has killed exactly one sponsorship upsell for me, and it was worth it.
Consent that actually holds
Consent buried in a registration checkbox that also agrees to the terms of service is not real consent, and a finance-client legal team will tell you so. Split it.
Separate the operational agreement from the marketing agreement. One checkbox to register and receive event logistics. A second, unchecked by default, to share contact information with sponsors and partners. If lead retrieval is in play, the booth scan itself is the consent moment, so the attendee should see a clear “scanning shares your info with this exhibitor” notice, not a silent beep.
Write down what you promised. The privacy notice attendees saw at registration is the contract you are bound to. If it said data is used for event administration only, you cannot hand it to a sponsor later, no matter how good the offer. I keep a dated snapshot of the exact registration language, the same way I keep everything else in writing, and it saves the argument every time.
Set a deletion date. Tell attendees you will purge registration data 90 days after the event unless they opted into ongoing contact. Then actually do it. A data set you deleted is a data set that cannot leak.
The vendor contract is where it lives or dies
The badge vendor, the app vendor, and the registration platform each hold your attendees’ data on their servers, and your client’s name is the one exposed if they lose it. Read those contracts the way you would read a venue contract before signing. I look for four things: where the data is stored, who else it is shared with, how long the vendor retains it, and whether you can force deletion after the event. If the app vendor’s contract says it may use aggregated attendee data to improve its product, that is your attendees’ behavior training someone else’s model, and a finance compliance team will not sign off.
Networking apps sell themselves on engagement features that are mostly theater anyway, a point I made in why networking-app launches are cope. The privacy cost is real even when the engagement value is not.
The breach nobody plans for
Ask yourself what happens if the registration laptop is stolen from the check-in desk, or the badge vendor’s server is compromised, or a staffer emails the full attendee list to the wrong address. In healthcare and finance that is a reportable event, and the timeline to notify affected people is short, sometimes 30 days or less depending on the data and the state. I keep the attendee data set encrypted, I limit who has access to two named people, and I know before the event which vendor carries breach-notification responsibility in its contract. A finance client asked me once who would send the notice if a laptop walked off. I could name the person and the vendor clause. That answer is the difference between a controlled incident and a client learning about the exposure from a regulator.
The venue’s role, and its limit
The venue provides the wifi, and that matters more than planners think. An open, unsegmented conference wifi network at a conference center means attendee devices and your registration laptop share a broadcast domain with strangers. Ask for a segmented event VLAN and a private SSID for staff devices handling data. Most purpose-built convention centers can provide it. Many smaller event venues cannot, and then you run registration on a cellular hotspot instead of house wifi.
The venue does not own your consent obligation, your vendor contracts, or your deletion promise. Those follow the event, and the event is yours.
The pre-event privacy pass
A week out, I run one checklist. What data fields am I collecting, and is each one operationally necessary. Is marketing consent separate and unchecked by default. Does every scanning point have a visible consent notice. Where does each vendor store the data, and can I force deletion. What is my purge date, and who executes it. Did I keep the exact registration-notice language on file.
Six questions, fifteen minutes. They are the difference between a compliance officer nodding and a compliance officer opening a file with your client’s name on it.
Tell me your attendee count, your industry, and whether sponsors are scanning leads, and I will tell you which of these three streams is your biggest exposure and what to lock down first.
Need quotes for your event?
Tell us where, when, and how many. Up to 3 venues will respond — usually inside a day.