Skip to content
EventConsultant.com.my

Event incident privacy controls

An incident report contains names, descriptions and sometimes health or conduct details, and it is sitting in a shared chat.

Discuss incident recordsOpens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.

The short answer

Treat every incident record as sensitive. Collect only what is needed, keep it in one place with a named owner, limit who can read it, and ask your data-protection contact and legal adviser how long it may be kept and who it may be shared with.

The organiser sets the working controls. What the law requires, what may be disclosed to insurers or authorities and how long records are held are questions for your data-protection contact, legal adviser and the competent authority.

Where incident data leaks

  • Photos and messages about an incident in a volunteer group chat.
  • Forms on several phones, emailed to personal accounts or printed and left on a desk.
  • Names of complainants or people involved shared more widely than needed.
  • Health or conduct details copied into the general event log.
  • Records kept indefinitely because nobody decided when to delete them.

Access table to complete

RecordWho may read itWho may copy or share itStored where
Incident report formIncident lead and event owner.Only the incident lead, to venue or adviser as agreed.One restricted folder.
Complaint routing recordIntake person and independent officer.Intake person, to adviser as needed.Separate restricted folder.
Medical-provider notesThe provider, who holds them.The provider.Provider's own system.
Statement logSpokesperson and approver.Spokesperson.Communications folder.
Photos and messagesDelete from group chats once the form is complete, unless an adviser says to keep them.No onward sharing.Only where an adviser directs.
Summary for the boardBoard members.Chair.Anonymised, no names or details that identify people.

Steps to set up controls

  1. Decide the one place where incident forms are stored and name its owner.
  2. Limit access to the people in the access table, and switch off link sharing.
  3. Brief volunteers: report through the form and the intake route, and never in group chats.
  4. Ask your data-protection contact or adviser what notice, if any, is needed for the information you collect, and record the answer.
  5. Ask the adviser and insurer how long records should be kept, who may receive them and how they should be deleted.
  6. Agree a short anonymised summary format for the board, with no names.

Question pack for your data-protection contact or legal adviser

  • What incident information may the organiser collect, and does a notice or consent apply?
  • Who may receive it, including the venue, insurer, medical provider, police or an authority?
  • How long should it be kept and how should it be deleted?
  • Can we keep an anonymised log of incidents for planning future events?
  • What should happen if a record is lost, sent to the wrong person or seen by someone not authorised?
  • If a volunteer or supplier holds copies, what must they do with them?

Worked example · Fictional example

Cleaning up after a minor incident

Fictional organisation and figures, for illustration only.

At a fictional pharmacists' association seminar, a volunteer posts a photo of an incident in the volunteer group chat. The incident lead completes the form, asks the volunteer to delete the photo and message, and stores the form in a restricted folder visible to two named people.

After the event the secretariat asks its adviser how long to keep the record, and writes the answer on the form's storage line. For the board, the secretariat prepares a one-paragraph summary with no names.

Use this yourself

Incident record privacy checklist

Use this before the event and again at close-out.

  • One storage location for incident records, with a named owner:
  • Access limited to named people, link sharing off:
  • Volunteers briefed: no photos or details in group chats:
  • Notice or consent question put to data-protection contact, answer recorded:
  • Recipients agreed: venue, insurer, provider, authority:
  • Retention period and deletion method confirmed by adviser:
  • Copies held by volunteers or suppliers collected and deleted:
  • Anonymised board summary format agreed:
  • Process for a lost or misdirected record, agreed with adviser:

Open the tool: Event responsibility matrix builder

Handle it in-house, or bring in help?

Your team can usually handle this when

  • The organisation has a data-protection contact who can answer the question pack.
  • Incidents are expected to be few and routed through one person.

Outside planning help earns its fee when

  • Several partners, venues and suppliers each collect and hold incident information.
  • Complaints or health details are involved and nobody has settled who may see them.
  • The committee wants the controls designed and briefed before the event.

Want the controls set up and briefed?

A conference project lead can set up the single storage point and access table with your team, brief volunteers and suppliers, and prepare the question pack for your data-protection contact. What is lawful to collect, share or keep stays with your adviser and the competent authority. Share the incident forms and tools you plan to use.

Discuss incident recordsOpens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.Conference project lead

Questions organisers ask

Can volunteers photograph an incident?

Set the rule in advance: no photos or details in group chats. Ask your adviser whether any photo is ever appropriate and who may hold it.

Can we share the report with the venue?

Only as your adviser and the venue's procedure allow. Share what is needed, and record what was shared and why.

Who decides what the board sees?

The chair, based on an anonymised summary. Names and identifying details stay with the incident lead and adviser.

How long do we keep records?

Ask your data-protection contact, legal adviser and insurer, and record the answer in the access table.

Related resources

Content record: Draft. Written from the cited sources and checked by automated rules; not yet independently reviewed.