Skip to content
EventConsultant.com.my

A delegate requests deletion after data was shared with suppliers

After the event, a delegate writes asking you to delete their personal data, and you know their details were sent to several suppliers.

Discuss data request recoveryOpens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.

The short answer

Acknowledge the request, pass it straight to your organisation's data protection contact, and map where the delegate's data went. What must be deleted, kept or answered, and by when, is for that contact and your legal adviser to decide.

Your job as organiser is to make the facts available quickly: what was collected, why, who received it and who holds the records.

What is known and what is not

Fictional scenario: a delegate of the Persatuan Fiktif Pengurus Kemudahan writes: "Please delete all my data." The registration list went to a badge printer, a caterer and a mobile app supplier before the event.

  • Known: the request wording, the date received, the delegate's registration details.
  • Known: which suppliers were sent a list, if the send records exist.
  • Unknown: what each supplier still holds, in which form, and under what agreement.
  • Unknown: whether any of the data is needed for other purposes, such as accounts or a continuing membership. That is a question for your data protection contact, not a call for the events team.

Who has authority to decide

The decision does not sit with the events team. It sits with the person your organisation has named for data protection, advised by legal where needed.

If your organisation has no named contact, escalating that gap to a senior officer is the first action.

  • Data protection contact: whether and how to act on the request, the answer to the delegate and the timing.
  • Legal adviser: any legal or contractual question, including supplier agreements.
  • Event owner: gathers the facts, holds the supplier contacts and keeps the delegate informed as the contact directs.
  • Suppliers: tell you what they hold, when your organisation asks in writing.

Realistic steps and what each involves

These are coordination steps to prepare. The data protection contact chooses which responses apply.

StepWhat it involvesConsequence to weigh
Acknowledge receiptShort, neutral reply that the request is with the responsible person.Reassures the delegate; promises nothing on outcome or timing.
Map the dataList every system and supplier that received the delegate's data, with date, purpose and format.Takes effort now; gives the contact what they need to decide.
Ask suppliers what they holdWritten request to each supplier to confirm what they hold and under what terms.Clarifies the picture; supplier answers may vary in speed and completeness.
Hold changes until advisedAvoid deleting or editing records before the contact says what to do.Prevents accidental loss of records that may be needed; the request stays open longer.
Escalate if unclearTake unclear points to the contact or legal adviser in writing.Keeps decisions with the right party; adds time.

Communications

Use short, polite and neutral wording. Do not state what will or will not happen until the data protection contact has confirmed it.

  • To the delegate: "Thank you for your message. We have passed your request to the person responsible for data protection at [organisation], who will be in touch about next steps."
  • To the data protection contact: "Request received on [date] from [delegate]. Data was sent to [suppliers] on [dates] for [purposes]. Please advise how you want us to respond and what to ask the suppliers."
  • To each supplier: "Please confirm in writing what personal data about delegates you hold from the [event], in what form, and the terms under which you hold it. Please do not delete or change anything until we confirm."
  • Internal: "Please do not delete or amend delegate records related to this request until we hear from [contact]."

Follow-up and prevention

  • Keep a register of every supplier that receives delegate data, with purpose, fields and handover date.
  • Share only the fields each supplier needs. The field minimiser helps your team challenge each field before it is collected or shared.
  • Ask suppliers, in the agreement, how they handle and return or delete event data. Check wording with your legal adviser.
  • Put the data protection contact's name into the run sheet and the handover pack.
  • Record the request, the route and the answer in a decision log. Look also at the sibling pages on an email exposing contact details and sponsor data requests.

Worked example · Fictional example

One request, three suppliers

Fictional organisation and figures, illustrative only.

The secretariat head acknowledges the request the same day and sends the data protection contact a one-page map: badge printer, caterer and app supplier, with dates, purposes and fields.

The contact decides what to tell the delegate and what to ask each supplier. The events team sends the supplier request as instructed and records each reply.

Use this yourself

Question pack for your data protection contact

Send this with your data map. These are questions for the competent party to answer, not conclusions.

  1. What exactly has the delegate asked for, and does the request cover more than event data?
  2. Which of our records about this delegate are needed for other purposes, and who decides that?
  3. What should we tell the delegate now, and who sends it?
  4. What do we need from each supplier, and how should we word the request?
  5. Do our supplier agreements say anything about deletion, return or retention?
  6. Is anything about this case a matter for legal review?
  7. Who records the final answer and where is it kept?
  8. What should change in registration and supplier handover before the next event?

Open the tool: Event registration form field minimiser

Handle it in-house, or bring in help?

Your team can usually handle this when

  • You have a named data protection contact who answers quickly.
  • The data went to one or two suppliers with clear agreements.
  • The request is simple and the contact has handled similar ones.

Outside planning help earns its fee when

  • Nobody owns data protection decisions and the request is sitting unanswered.
  • Many suppliers and systems hold copies and nobody has a map.
  • The organiser wants supplier handovers and registration reviewed before the next event.

Need the data trail mapped and the tasks coordinated?

A conference project lead can coordinate the agreed recovery tasks: building the supplier and data map with your team, issuing your written supplier requests as your contact directs, and keeping the log. A planning diagnostic can review registration and supplier handovers before the next event. Decisions on deletion and retention stay with your data protection contact and legal adviser.

Discuss data request recoveryOpens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.Conference project lead

Questions organisers ask

Do we have to delete the data straight away?

That is a question for your data protection contact and legal adviser. Do not delete or alter records before they advise, and do not promise an outcome to the delegate.

Which regulator or guidance applies?

Ask your data protection contact which requirements apply to your organisation. The official Malaysian authority's website is the place they would normally check, and they can tell you what it says.

What if a supplier will not respond?

Record the date and wording of each request and pass the gap to your data protection contact and legal adviser.

Related resources

Content record: Draft. Written from the cited sources and checked by automated rules; not yet independently reviewed.