Skip to content
EventConsultant

Privacy and information handling

Building an event personal data inventory

Registration, the badge printer, the caterer, the photographer and the sponsor portal all hold delegate details, and nobody has a list of who has what.

Opens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.

The short answer

An event personal data inventory is a table with one row per item of personal information: what it is, where it is collected, why, who holds a copy, who can see it, where it goes next and who deletes it.

Build it from the actual data flow, not from the registration form alone. Then give it to your organisation's data protection contact, who decides what the answers mean.

What an inventory is and is not

It is a factual map of information handling for one event. It is not a compliance statement and it does not say whether any practice is acceptable.

The PDP Malaysia website identifies the Personal Data Protection Act 2010 (Act 709) as the law it administers and says it concerns persons processing personal data in commercial transactions. Whether and how that applies to your organisation and event is for your data protection contact or legal adviser to say.

Find the data by following the delegate

  1. Before: invitations, mailing lists, speaker and VIP lists, member records brought in from elsewhere.
  2. During registration: the form, payment, invoices, dietary and access notes, group registrations made by an employer.
  3. Before the event: badge and certificate files, supplier lists, transport or accommodation lists.
  4. On the day: check-in lists, photography, recordings, feedback forms, lead scans.
  5. After: exports, post-event surveys, sponsor lists, archived files on shared drives and personal laptops.

Columns that make the inventory useful

ColumnQuestion it answers
ItemWhat exactly is held, for example name, email, dietary note, photograph?
Source and purposeWhere did it come from and what is it used for?
Holder and locationWhich person, supplier or system holds it, and where?
AccessWho can see or download it?
SharingDoes it go to a supplier, sponsor, speaker or venue, and under what written terms?
Retention ownerWho decides when it is deleted, and who confirms it was?
Question for the data protection contactWhat needs a decision from them?

Where the unexpected copies hide

  • Exports emailed to a supplier and left in inboxes.
  • Spreadsheets on a staff member's laptop for the badge mail merge.
  • A venue or caterer asked for names and allergies by message app.
  • The registration platform's own backups and a previous event's data.
  • Photos taken by delegates, sponsors or a volunteer, outside the official photographer's brief.

Hand it on

Ask the data protection contact to review the finished inventory and mark each question. Use the field minimiser tool to review what the form collects, and record supplier handovers in the handover pack builder.

The inventory feeds the privacy notice drafting questions and the data minimisation checklist.

Worked example · Fictional example

Inventory for a 400-person industry forum

Fictional organisation and figures, for illustration only.

A fictional industry body lists 14 items. The form holds names, emails, job titles, company and dietary notes. The inventory also finds the badge file with phone numbers, a sponsor lead scan list, and a photographer's raw files.

Three questions go to the data protection contact: whether the phone number is needed on the badge file, what the sponsor list may contain, and how long the photographer keeps raw files. The secretariat does not answer them itself.

Use this yourself

Personal data inventory worksheet

Copy one row per data item. Leave the final column for your data protection contact.

Data itemSource and purposeHolder and locationWho can accessShared with (written terms?)Retention ownerQuestion for data protection contact
Name, email, titleRegistration form; confirmation and badgeRegistration platform; badge fileSecretariat, two volunteersBadge printerSecretariat head
Dietary noteForm; cateringPlatform exportSecretariatCatererSecretariat head
PhotographsPhotographer on the dayPhotographer's drivePhotographer, communicationsWebsite, social postsCommunications lead

Open the tool: Event registration form field minimiser

Handle it in-house, or bring in help?

Your team can usually handle this when

  • One event, one registration platform and a handful of suppliers.
  • Someone in your team can follow the data through each supplier by asking questions.
  • You have a data protection contact who will review the result.

Outside planning help earns its fee when

  • Data moves between several committees, agencies and platforms.
  • Nobody knows which suppliers hold copies.
  • A previous event's files and lists are mixed with the current one.

Want the data flow mapped and written up?

An Event Blueprint can include a clear map of who collects, holds and receives delegate information for your event, together with the supplier handover steps and the question list for your data protection contact. The contact, not the planner, decides what the answers mean.

Ask about an Event BlueprintOpens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.Event Blueprint (planning pack)

Questions organisers ask

Who should own the inventory?

The event owner or secretariat head keeps it current, with your data protection contact as reviewer. Suppliers confirm their own rows in writing.

Does a small event need one?

A short version is still useful. Even a single table lists who holds delegate details and prevents surprise copies after the event.

Does this show that we comply with the law?

No. It is a map that makes review possible. Compliance questions go to your data protection contact or legal adviser.

Related resources

Sources and check dates

  1. Jabatan Perlindungan Data Peribadi (PDP Malaysia), homepage, Personal Data Protection Department, Malaysia (checked 2026-10-07). Identifies the Personal Data Protection Act 2010 (Act 709), says it concerns persons processing personal data in commercial transactions, and lists a data protection officer registration guide. Nothing here is a statement about any event.

Content record: Draft. Written from the cited sources and checked by automated rules; not yet independently reviewed.