Skip to content
EventConsultant

Delegate data, communication and access problems

An event email exposes other delegates' contact details

An email to delegates has just gone out with every address visible in the To or Cc line.

Opens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.

The short answer

Stop any further sending, record the facts, and tell your organisation's data protection contact straight away. Whether this is a reportable incident, who must be told and how is a decision for that contact and your legal adviser, not the events team.

The events team's job is to contain the spread, preserve the evidence and give the contact what they need to decide.

What is known and what is not

Fictional scenario: the secretariat of the Persatuan Fiktif Perunding Kejuruteraan sends a reminder to 140 delegates and puts all addresses in the Cc line. The mistake is noticed eleven minutes later.

Write down what is certain and mark guesses as guesses.

  • Known: the email, the time sent, the number of recipients, who sent it and from which account.
  • Known: what is visible: email addresses only, or also names, organisations or other details in the message or addresses.
  • Unknown: whether any recipient replied to all, forwarded the message or saved the list.
  • Unknown: whether the list included anyone for whom exposure carries a particular sensitivity, such as a speaker or a delegate who asked for discretion. Ask the contact how to treat those.

Who has authority to decide

The data protection contact decides how the incident is classified, who is told and when. The legal adviser advises on obligations. Both may need to be reached outside office hours, so check that you have their numbers.

Do not let the sender, or the events team, decide alone whether it is serious.

  • Data protection contact: classification, notification decisions, and the wording of any notice.
  • Legal adviser: obligations, regulator contact and contract questions.
  • IT or email administrator: logs, recall options and account security.
  • Event owner: pausing other messages and coordinating delegate-facing wording once approved.

Immediate steps and options

Do the first two now; the rest need the data protection contact's decision.

Step or optionWhat it involvesConsequence to weigh
Stop further sendingPause all delegate emails, including scheduled ones, until the cause is understood.Prevents repeat; delays other messages.
Preserve the evidenceSave the sent email, headers, recipient list and timeline. Do not delete.Gives the contact what they need; takes a few minutes.
Ask IT about recallIT checks whether the message can be recalled or access reduced.Recall is unreliable, so do not tell delegates it worked unless confirmed.
Send a notice to recipientsA short, plain message, worded and approved by the contact.Transparency; wording matters, so do not send without approval.
Ask recipients to deleteA request to delete the message and not forward the list, if the contact approves.May reduce spread; cannot be enforced.
Tell affected individualsThe contact decides whether and how to tell the people whose details were visible.Honest and respectful; needs correct wording and timing.

Communications

Keep every message factual and short. Do not speculate on cause or impact.

  • To the data protection contact (immediately): "At [time] we sent [subject] to [number] delegates with all addresses visible. Sent from [account]. Evidence saved at [location]. Please advise on classification, who must be told and the notice wording. We have paused other delegate emails."
  • To the team: "Do not send or reply to delegate emails until [owner] confirms. Do not delete the sent message."
  • To IT: "Please check the logs and tell us if recall is possible. Please do not alter the mailbox until the contact confirms."
  • To delegates, only after approval: wording supplied by the data protection contact.

Follow-up and prevention

Worked example · Fictional example

140 addresses in the Cc line

Fictional organisation and figures, illustrative only.

The secretariat head pauses all scheduled emails, saves the sent message and phones the data protection contact within minutes. IT confirms recall is not possible.

The contact decides what to tell recipients and drafts the wording. The secretariat head sends it as approved and keeps a record of times and decisions.

Use this yourself

Incident facts sheet for the data protection contact

Complete as far as you can in the first hour and send it. Unknowns can stay blank.

  1. Date and time sent; date and time noticed:
  2. Sender and account used:
  3. Subject and a saved copy of the message:
  4. Number of recipients; whether Cc, To or visible list:
  5. What is visible: addresses, names, organisations, other details:
  6. Replies to all or forwards seen so far:
  7. Any recipient with particular sensitivity (to ask the contact about):
  8. Steps taken so far (sending paused, IT contacted, evidence saved):
  9. Questions for the contact and legal adviser: classification, who to tell, wording, timing:
  10. Decision log entry: who decided what, and when:

Open the tool: Event registration form field minimiser

Handle it in-house, or bring in help?

Your team can usually handle this when

  • You can reach the data protection contact quickly and they have a procedure.
  • The exposure is limited and the facts are clear.
  • IT can provide logs the same day.

Outside planning help earns its fee when

  • No one is named for data protection decisions and the team is unsure who to call.
  • Several systems or suppliers sent the message, or the list is large.
  • You want mail handling, supplier handover and registration reviewed before the next event.

Need the response coordinated?

A conference project lead can coordinate the agreed recovery tasks: pulling the facts together for your contact, keeping the pause and approvals on track, and managing delegate-facing messages once they are approved. A planning diagnostic can review how delegate communications are controlled. Breach and notification decisions stay with your data protection contact and legal adviser.

Discuss data incident coordinationOpens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.Conference project lead

Questions organisers ask

Do we have to report this?

That is for your data protection contact and legal adviser to decide. Give them the facts quickly, and ask them what applies to your organisation, including anything the official Malaysian data protection authority states.

Should we apologise to delegates?

The contact decides whether and how to notify, and approves the wording. A plain, factual message is usually better than a long one.

Can we ask recipients to delete the email?

Only if the data protection contact agrees. Such a request cannot be enforced, so avoid promising it solves the problem.

Related resources

Content record: Draft. Written from the cited sources and checked by automated rules; not yet independently reviewed.