Collecting Event Data in a Post-GDPR and Cambridge Analytica Era

May 8, 2018

Tamar Beck

Tamar Beck is a 15-year veteran of Reed Exhibitions. She is currently CEO of Gleanin, an attendee acquisition software platform. 

Savvy event organizers have been keeping their eyes and ears glued to the news lately. 

In addition to the European General Data Protection Regulation (GDPR) coming right around the corner and now with the Cambridge Analytica and Facebook controversy, event organizers are facing their own challenges when it comes to collecting and protecting event data. 

Because they collect so much data from and about their attendees, organizers now face pressure to protect that information, while making sure everyone understands what data is collected and why.

Collecting any kind of event data today means making changes. Here’s what organizers should be thinking about data collection, protection and privacy in a post-GDPR and Cambridge Analytica era. 

Be Totally Transparent

Name. Company name. Email. Phone. Address. Dietary preferences. Special accommodations. Social media handles. 

Think about all of the information requested from attendees when registering for an event. 

While it’s all necessary from an organizer’s perspective, it’s quite a bit – especially since much of it is now defined as personal data and falls under the new GDPR guidelines.

But beyond GDPR, because of Cambridge Analytica and Facebook, attendees are likely to be even more sensitive about sharing any kind of personal data, wondering how and why it will be used. 

Obviously, organizers need to be very careful about the kinds of information they request from attendees and use it sparingly. 

But even more important, organizers need to be totally transparent not only about why they’re collecting the data in the first place but also how it will be used. 

In other words, organizers shouldn’t be asking for any unnecessary information. And it’s just as important that they don’t use collected information in ways that are unintended, unethical or don’t follow the agreement they have with attendees.

For example, it should be very clear that data collected during the registration process is being provided to a third-party registration company for the purpose of creating an attendee list, sending attendees ongoing communications about the event and in order to provide guests with event credentials on-site.

Being totally transparent about this kind of data collection is relatively straightforward and simple.

But the waters get a little muddier when it comes to newer data collection strategies used by organizers like social media referrals, beacons, RFID-tracking or visits to a landing page since those often are provided by third-party providers.

Creating Explicit Opt-In

As highlighted by the Cambridge Analytica and Facebook situation, it wasn’t crystal clear that when people long-ago accessed a specific app, that not only their data but their friends’ data was being collected, activity at the time that Facebook permitted but has since been banned (the bigger issue with this controversy is that this data was then sold – something Facebook expressly prohibits).

Many Facebook users weren’t aware that Facebook routinely allows researchers to have access to user data – and users consent to this access when they create a Facebook account. 

Unfortunately, details of these kinds of data sharing permissions being granted are often buried in a long list of terms and conditions, or revealed so briefly and quickly before a user clicks acceptance to move on to the next registration step. 

That’s why we at Gleanin take an explicitly transparent and clear process for obtaining opt-in to share data on social media platforms. For example, when we register an event app through Facebook, as a developer we have to go through an approval process. We have to tell Facebook what we’re going to request from a user. And more importantly, we have to explain why we’re collecting the data.

Since we allow event registrants to see other friends who are attending an event and to make it easy to invite others, we ask specific permission for information related to that request. That’s it. We don’t collect any other information or use the data for any other purpose. 

Just as important, it’s very clear what we’re asking for and exactly what it’s being used for. Unlike the app scenario in the Cambridge Analytica situation, there’s no lengthy permissions or hidden details about how data will be used. 

Questions to Ask About Third-Party Data Collection 

Despite an organizer’s best attempts to be clear and compliant with the data they collect, today much just as much attendee data is collected through third-party event technology or software companies. And that means understanding how these providers communicate what they collect and why it’s being collected falls squarely on an organizer’s shoulders. 

When working with third-party providers, to fully understand how data is being obtained, organizers should ask detailed questions such as:

  • How do you collect data? Is it through a transparent opt-in process?
  • How do you communicate to users what is being collected and why?
  • What are the exact ways this collected data will be used?
  • How is collected data protected? Is it kept for a certain amount of time (if at all)? Is it stored in a secure location?
  • Is any data collected shared, transferred or sold to other third-parties?

Of course, it’s important to note that event technology companies aren’t the same as Facebook or Google. The data they collect on behalf of the organizer isn’t a product. The event or show is the product and the data event tech companies collected is used to improve the experience for the attendee and grow the show.

But the situation brought to light by Cambridge Analytica and Facebook sends a crystal-clear message to exhibition organizers that they too have a responsibility to protect their attendee/customer’s information. Asking tough questions like these to any event technology provider is the best way understand what data is collected and why, and to ensure attendee data is kept safe and secure.

With so much event technology today, there are a lot of moving parts where data is concerned. 

But no organizer wants to be the poster child for a data breach, an unauthorized use of data or not being transparent about how they manage the data they collect and the data their event tech partners collect.

As the news headlines continue to highlight GDPR and Cambridge Analytica, organizers have a responsibility to understand and take control how and where data flows within the attendee ecosystem. 

Add new comment

Image CAPTCHA

Partner Voices

Mohegan Sun is one of the largest and most unique meeting and entertainment venues in the United States.  Situated on 185 acres along the Thames River in scenic southeastern, New England, Mohegan Sun is home to 1,600 deluxe hotel rooms, two Mandara Spa locations, a golf course, over 90 shops, restaurants and bars as well as three award – winning entertainment venues including a 10,000 – seat Arena.