Privacy and information handling
Event confidential spreadsheet sharing
The master attendee spreadsheet has been emailed to the venue, the caterer, two volunteers and a sponsor, each as a new attachment.
Opens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.
The short answer
Share a spreadsheet by giving each recipient only the columns and rows their task needs, through one controlled location, with named access and a date to remove it. Attachments that get forwarded are the weak point.
Decide who may see the master file first, then make purpose-built extracts for everyone else. Your IT or privacy reviewer confirms what controls are suitable.
One master, many extracts
Keep one master file with a named owner. Never send it. For each recipient make an extract with only the columns their task needs: the caterer needs dietary categories and counts, a volunteer on the desk needs names and session tickets, a sponsor may need nothing at all unless a separate decision has been made.
The sponsor data-sharing review covers sponsors. Do not use this page to decide that question.
Choose the channel before the file
| Option | Works well when | Watch for |
|---|---|---|
| Emailed attachment | A one-off, low-sensitivity extract to one person. | Forwarding, copies in several inboxes, no way to withdraw access. |
| Shared drive link, named people | Several people need the same extract for a period. | Links that anyone can open; people who change roles. |
| Registration platform export or role | Desk staff need live lookup. | Roles left active after the event. |
| Printed list | Desk or venue security need a paper copy. | Collection and shredding must be assigned to a person. |
Controls to ask your IT or privacy reviewer about
- Password or access settings on the file, and how the password is shared separately.
- Whether downloads and printing can be restricted for the extract.
- Whether file names or email subjects carry personal details.
- How access is removed after the event, and who checks it.
After sharing
- Record each share in a log: who, which extract, when, why.
- Ask recipients to confirm in writing when they have deleted or returned their copy.
- Remove access on the date set, and record that you did.
- Pass open items to the deletion handover.
Worked example · Fictional example
A fictional secretariat replaces five attachments with three extracts
Fictional organisation and figures, for illustration only.
Persatuan Fiktif Jurulatih Korporat holds a master list of 190 registrants with 14 columns. It plans to send the whole file to five parties.
It instead makes three extracts: a desk list with name, organisation and ticket type (4 columns) for three volunteers, a catering sheet with dietary category counts and no names, and a speaker sheet with speaker names only. The venue receives the catering counts. Access for the three volunteers is set to expire the day after the event, and the owner notes the date in the log.
Use this yourself
Spreadsheet sharing checklist
Work through this before each share and keep the completed copy with the log.
- Master file owner named:
- Recipient and their task:
- Columns needed for that task only:
- Rows needed (all attendees, one session, one day):
- Channel chosen and why:
- Access set to named people, not 'anyone with the link':
- Password or access detail sent through a separate route:
- File name and email subject carry no personal details:
- Access end date set and diarised:
- Recipient asked to confirm deletion or return in writing:
- Entry made in the sharing log:
Handle it in-house, or bring in help?
Your team can usually handle this when
- A small number of recipients and a stable team.
- Your organisation has an approved shared drive and a way to restrict access.
- One person can keep the log.
Outside planning help earns its fee when
- Many volunteers, suppliers and committees need data at different times.
- No agreed channel exists and extracts are made ad hoc.
- You want the sharing rules written into supplier requirements and the event handover.
Want the sharing rules set up before registration opens?
An Event Blueprint can set out who receives which extract, through which channel, with owners and end dates, and write those rules into supplier requirements. Controls themselves are for your IT or privacy reviewer to confirm.
Questions organisers ask
Is a password on the spreadsheet enough?
A password is one control. Ask your IT or privacy reviewer whether it is enough for your data, and how the password itself is shared and changed.
Can volunteers use their own phones or laptops?
That is a question for your reviewer. If it is allowed, say so in the volunteer briefing and record it in the log.
What if a recipient already forwarded the file?
Record it, ask the recipient who has it, and take it to your reviewer and the incident contact tree if you are unsure.
Related resources
Content record: Draft. Written from the cited sources and checked by automated rules; not yet independently reviewed.