Skip to content
EventConsultant

Privacy and information handling

Event retention schedule review

The event ended months ago and the registration list, photos and feedback forms are still sitting in several inboxes.

Opens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.

The short answer

A retention schedule lists each type of event data, the reason you hold it, the person who decides how long, and the date it is reviewed. Review it before the event, not after.

The periods themselves depend on your own purposes and on rules your reviewer must confirm. This page gives the structure and the questions, not the periods.

List the data before you list the periods

Retention reviews fail when they start with a number. Start by listing every place event data sits: registration platform, spreadsheets, email, printed lists, photo folders, supplier systems and shared drives.

If you have not done this yet, use the personal data inventory first.

What the schedule needs for each row

  • The data type, for example attendee list, dietary needs, feedback forms, photos.
  • The reason you hold it, written as a purpose, not as 'in case'.
  • The owner who decides, by name or role.
  • The proposed review date, and what happens at that date: keep with a stated reason, anonymise, or delete.
  • Which copies exist, including suppliers' copies.
  • Any rule that may require a minimum or maximum period, marked as 'to be confirmed by reviewer'.

Questions your reviewer will want answered

  • Are any periods set by a contract, a funder, an accreditation body or a finance rule? Who confirmed it, and in what document?
  • Which data is kept only because no one has had time to delete it?
  • Is any data reused for the next event? Was that reason stated when it was collected?
  • How will deletion be recorded? See the deletion handover.

Common gaps

  • Backups and email attachments are missed.
  • The schedule exists but no one has a calendar reminder to review it.
  • A supplier keeps a copy after the contract ends.
  • Different teams hold different versions of the same list.

Worked example · Fictional example

A fictional association reviews its schedule before registration opens

Fictional organisation and figures, for illustration only.

Persatuan Fiktif Pengamal Pemasaran has six data types for its 220-delegate forum: registration list, dietary needs, badge print file, photographs, feedback forms and speaker travel details. It finds that dietary needs sit in four places.

For each type the secretariat names an owner and a review date eight weeks after the event, and marks two rows 'confirm with reviewer' because a speaker contract and an accreditation request may affect the period. The photographer's copy is added as its own row.

Use this yourself

Retention schedule review table

Copy one row per data type. Leave the period blank where it is to be confirmed, and send the table to your reviewer.

Data typePurposeWhere copies sitOwnerReview date and actionPeriod confirmed by (name, date)
Attendee list
Dietary needs
Badge print file
Photographs
Feedback forms
Supplier-held copies

Open the tool: Event registration form field minimiser

Handle it in-house, or bring in help?

Your team can usually handle this when

  • Few data types and one team holds them all.
  • Your organisation already has a records policy to follow.
  • A reviewer is available to confirm periods.

Outside planning help earns its fee when

  • Data is spread across committees, suppliers and personal inboxes.
  • No one owns the decision and reviews keep slipping.
  • You need the schedule written into supplier requirements and the event handover.

Need the schedule built into your event plan?

An Event Blueprint can include a retention schedule as a handover document, with owners, review dates and supplier requirements written in. Your reviewer confirms the periods; the plan makes sure the review actually happens.

Discuss event data retentionOpens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.Event Blueprint (planning pack)

Questions organisers ask

How long should we keep event data?

This page does not set periods. The right period depends on your purpose and on rules your reviewer must confirm. The sheet helps you bring the question to them in a complete form.

Should the schedule be written before the event?

Yes. Writing it after the event usually means the data has already spread to more places.

Who owns the schedule?

A named person in your organisation, usually the event owner or secretariat head, with the reviewer advising.

Related resources

Sources and check dates

  1. Personal Data Protection Department Malaysia (JPDP) website, Jabatan Perlindungan Data Peribadi (checked 2026-10-07). The site names the Personal Data Protection Act 2010 (Act 709) and lists data protection principles and data breach notification among its topics. It does not decide whether a particular event's practice is compliant; that needs a qualified review.

Content record: Draft. Written from the cited sources and checked by automated rules; not yet independently reviewed.