Privacy and information handling
Event vendor data-processing questions
Your event uses four or five suppliers, and each of them will see some of your attendees' personal details.
Opens WhatsApp with a draft you can edit before sending. Nothing is sent automatically.
The short answer
Before any supplier receives attendee data, list what they will receive, why, who inside the supplier can see it, where it is kept and what happens to it afterwards. Put those questions to each supplier in writing and keep the answers.
The answers are material for a qualified privacy or legal reviewer. They are not a compliance conclusion, and this page does not give one.
Which suppliers actually touch attendee data
Start from the data flow, not from the supplier list. A supplier that only delivers chairs sees nothing. A badge printer, a registration platform or a photographer sees names, organisations and sometimes faces.
Mark each supplier as receiving data, receiving data only on the day, or receiving none. Only the first two need the full question pack.
The questions, grouped by topic
| Topic | Ask the supplier in writing | Why it matters to your reviewer |
|---|---|---|
| What they receive | Which fields do you need, and which could you do without? | Shows whether the supplier asks for more than the task needs. |
| Who sees it | Which roles in your company and any sub-suppliers can open the file? | Sub-suppliers extend the data flow. |
| Where it is kept | In which country or countries are files and backups stored? | Feeds the cross-border questions. |
| How long | When do you delete our files, and how do you confirm it? | Feeds the retention schedule and deletion handover. |
| Instructions | Will you use the data only for our event, and is that stated in the contract or order form? | Separates your instructions from the supplier's own uses. |
| Problems | Whom do you tell, how fast, and what do you tell us if you lose or expose a file? | Feeds the incident contact tree. |
Getting answers you can use
- Send the same questions to every supplier so answers can be compared.
- Ask for answers by a named person, not a general sales mailbox.
- A reply of 'we are compliant' answers nothing. Ask which of your questions it responds to.
- File the replies with the supplier's quotation so they travel with the contract.
Where this sits with the rest of your privacy work
The supplier questions assume you already know what you collect. If not, start with the personal data inventory and the data minimisation checklist. The registration form field minimiser helps you cut fields before they reach any supplier.
Worked example · Fictional example
A fictional association asks four suppliers the same questions
Fictional organisation and figures, for illustration only.
Persatuan Fiktif Perunding Kejuruteraan expects 280 delegates. Four suppliers receive data: an online registration platform (names, emails, company, dietary needs), a badge printer (names, company), a photographer (faces on the day) and a caterer (dietary needs, counts).
The secretariat sends the six question groups to all four. The caterer replies that it needs only counts and dietary categories, not names, so the file is changed. The badge printer cannot say where its design files are stored, so that is marked open and sent to the reviewer before the order is confirmed.
Use this yourself
Vendor data question log
Copy one row per supplier. Fill in the answers, mark gaps as Open, and send the completed log to your privacy reviewer.
- Supplier and role in the event:
- Data fields they will receive (and fields removed after asking):
- When they receive it and by what channel:
- Roles and sub-suppliers who can see it:
- Country or countries where files and backups are held:
- Will it be used only for this event? Where is that written?
- Deletion date and how they confirm it:
- Who we tell and how fast if a file is lost or exposed:
- Answers received on (date), by (name):
- Open points sent to reviewer on (date):
Handle it in-house, or bring in help?
Your team can usually handle this when
- You have a short supplier list and a clear data inventory.
- Suppliers answer plainly and in writing.
- Your organisation already has a reviewer you can send the log to.
Outside planning help earns its fee when
- Several suppliers, sub-suppliers or regions are involved and no one owns the log.
- Suppliers answer vaguely and someone needs to keep asking and recording.
- You need the questions, answers and decisions kept in one handover file for the next event.
Want the supplier questions run to a close?
An Event Blueprint can include the supplier data questions as part of the supplier requirements, so each quotation is compared on the same sheet and open points are dated and owned. The review itself stays with your privacy or legal adviser.
Questions organisers ask
Do I need to ask a supplier that only receives names?
Yes, ask the short version: what they receive, who sees it, where it is kept and when it is deleted. Names are still personal details. Whether anything further is needed is for your reviewer.
Can a supplier's standard terms replace these questions?
Standard terms are one answer to the questions. Read them against the log and mark any question the terms leave open.
Who signs off the answers?
Your organisation decides who approves supplier appointments. The privacy or legal reviewer advises on the answers; this page does not replace that advice.
Related resources
Sources and check dates
- Personal Data Protection Department Malaysia (JPDP) website, Jabatan Perlindungan Data Peribadi (checked 2026-10-07). The site names the Personal Data Protection Act 2010 (Act 709) and lists data protection principles and data breach notification among its topics. It does not decide whether a particular event's practice is compliant; that needs a qualified review.
Content record: Draft. Written from the cited sources and checked by automated rules; not yet independently reviewed.