All stories
August 7, 2026·14 min read

Interview: A DPO on What Event Organizers Get Wrong About Consent

A data protection officer explains the most common consent mistakes event organizers make, how privacy regulations affect attendee data, and how better consent practices create safer event experiences.

Y
Yağız GürbüzFounder, MeetWho
Published August 7, 2026 · Updated August 11, 2026
TL;DR
  • A data protection officer explains the most common consent mistakes event organizers make, how privacy regulations affect attendee data, and how better consent practices create safer event experiences.
  • Events have become data-rich experiences.
  • Registering for an event naturally requires some information.
  • Q: What is one of the first things a DPO would challenge in an event registration flow?
  • Q: If somebody registers for a professional conference, can the organizer assume they want to be discoverable by other attendees?
Read as markdown (.md) — built for AI assistants
Key questions
  • A strong privacy program does not begin with a legal disclaimer added immediately before registration opens. It begins much earlier, when organizers decide what information the event actually needs, which features participants can opt into, who will receive the data, and what attendees should reasonably expect throughout the event lifecycle.

  • Q: What questions should an event team answer before publishing a registration form? For every field, the organizer should be able to describe why the information is needed and what will happen to it.

  • Privacy controls and networking effectiveness are sometimes presented as opposing goals: reveal more people and networking becomes easier; restrict visibility and connections supposedly decline. That framing overlooks what professional networking is actually for.

Interview: A DPO on What Event Organizers Get Wrong About Consent

Title: "DPO Interview: Event Consent Mistakes Explained"

Description: "A DPO explains what event organizers get wrong about consent, attendee privacy, GDPR compliance, and better data practices for modern events."

Interview: A DPO on What Event Organizers Get Wrong About Consent

Interview: A DPO on What Event Organizers Get Wrong About Consent, starts with a deceptively simple question: when someone registers for an event, what have they actually agreed to? Registration may authorize an organizer to process information needed to deliver the event, but it does not automatically mean an attendee has agreed to appear in a public directory, receive unrelated marketing, have their details shared with sponsors, or become visible to every other participant.

For event teams, that distinction matters because modern events collect far more than a name and email address. Registration forms, professional profiles, networking preferences, QR check-ins, online-event access, announcements, matching tools, and post-event communication can all involve personal data. This interview-format guide distills established data-protection principles and the practical questions a Data Protection Officer would expect organizers to ask. It is educational guidance rather than legal advice; specific obligations should be assessed against the applicable law and circumstances of each event.

Why Consent Matters More Than Ever at Modern Events

Events have become data-rich experiences. A conference organizer may need basic contact information to process a registration, send logistical updates, confirm attendance, or provide access to an online session. A networking platform may additionally ask participants what they are working on, whom they want to meet, or which professional topics interest them.

The problem begins when all of those activities are treated as though they have the same purpose and legal justification. They do not necessarily do so. Under the GDPR, organizations should identify an appropriate lawful basis for each processing activity rather than defaulting to consent for everything. Where consent is relied upon, European data-protection guidance emphasizes that it should be freely given, specific, informed and unambiguous, and that withdrawing it should be possible.

That makes event consent management less about adding another checkbox and more about designing understandable choices around distinct uses of attendee information.

A useful organizer question is:

If an attendee says yes to this action, would they reasonably understand every important way their information will be used afterward?

If the answer is no, the consent experience probably needs more clarity.

Registration Is Not a Blank Cheque for Attendee Data

Registering for an event naturally requires some information. An organizer may need a participant's name, email address, ticket status, accessibility requirements or other information relevant to providing the event. The principle of data minimization, however, encourages organizations to collect personal data that is adequate, relevant and limited to what is necessary for the stated purpose.

This creates a practical test for every registration field: Why do we need this information?

A professional job title may be useful for networking. A phone number may be useful in a particular operational workflow. Neither should be collected merely because a registration form can accommodate another field. Organizers should be able to explain what each material data point is for and how it contributes to the attendee experience.

A DPO Explains the Biggest Consent Mistakes Event Organizers Make

Collecting Attendee Data Without a Clear Purpose

Q: What is one of the first things a DPO would challenge in an event registration flow?

A: A strong starting point is purpose. Before asking whether a form has the right consent wording, the organizer should ask why each category of personal data is being collected and what will happen to it. Consent language cannot compensate for unnecessary collection or an unclear processing purpose.

One common design mistake is creating an extensive attendee profile during registration simply because that information might become useful later. Privacy-conscious event design reverses the process: define the event experience first, identify which data is actually required, and then explain those purposes to attendees in accessible language.

A practical pre-launch review should establish:

  • Purpose clarity: Every meaningful field has a defined reason for collection.
  • Access boundaries: The organizer knows which teams, providers or other parties can access the information.
  • Retention expectations: Personal data is not kept indefinitely simply because storage is available.
  • Participant control: Attendees can understand relevant choices and exercise applicable rights.

This is where attendee privacy becomes a product-design issue as much as a compliance issue. Participants should not need to decode a lengthy privacy notice to understand the basic consequences of completing a form.

Assuming Event Registration Equals Networking Permission

Q: If somebody registers for a professional conference, can the organizer assume they want to be discoverable by other attendees?

A: That assumption should be treated with caution. Attending an event and participating in networking are two different decisions. Someone may want to watch talks, attend a workshop or join an online session without making their professional profile visible to other participants.

The distinction becomes especially important when event technology includes attendee discovery, recommendations or messaging. A traditional public attendee list may expose a large group by default. A privacy-first model instead asks whether a participant wants to take part and then limits discovery according to those permissions.

MeetWho is designed around that distinction. Organizers can determine networking privacy settings, while participant permission remains central to whether people take part in networking. Rather than selling attendee lists or unlocking hidden profiles and private contact information through a paid subscription, MeetWho uses information shared by participating users to recommend relevant people they may benefit from meeting.

That approach supports the broader principle behind privacy-first networking: participation in an event should not automatically mean surrendering control over professional visibility.

Sharing Attendee Lists Without Proper Approval

Q: Why are attendee lists such a recurring privacy concern?

A: Because a list that looks operationally harmless can create uses attendees never expected. Publishing names and companies on an event website, sending a spreadsheet to sponsors, or giving participants unrestricted access to a directory can materially change who can access the information and for what purpose.

Organizers should therefore separate at least three questions: what information is needed to operate the event, what information participants choose to make available for networking, and whether any information will be disclosed to sponsors or other third parties.

The safest default is not to assume these permissions are interchangeable. Transparency should come before visibility, and attendee choice should be meaningful before networking begins.

Interview With a Data Protection Officer: Building Privacy-First Events

A strong privacy program does not begin with a legal disclaimer added immediately before registration opens. It begins much earlier, when organizers decide what information the event actually needs, which features participants can opt into, who will receive the data, and what attendees should reasonably expect throughout the event lifecycle.

From a Data Protection Officer's perspective, the most useful question is often not “Do we have consent?” but “What is our lawful basis, what exactly are we doing with this data, and have we explained it clearly?” Under the GDPR, consent is only one possible lawful basis for processing personal data. Organizers should determine the appropriate basis for each activity rather than treating a checkbox as universal permission.

What Should Organizers Ask Before Collecting Personal Data?

Q: What questions should an event team answer before publishing a registration form?

A: Start with necessity and purpose. For every field, the organizer should be able to describe why the information is needed and what will happen to it. If that explanation is difficult to provide, the field deserves another review.

A practical pre-event assessment should cover:

  1. Why is this data needed? Connect each data category to a specific event function rather than collecting information “just in case.”
  2. Who can access it? Identify internal teams, technology providers, sponsors, partners or other recipients where relevant.
  3. How will attendees be informed? Important uses should be described clearly and at an appropriate point in the attendee journey.
  4. How long is it needed? Establish retention practices appropriate to the purpose and applicable obligations.
  5. Can participants control optional uses? Where participation is optional, avoid designing interfaces that make refusal confusing or unnecessarily difficult.
  6. What happens after the event? Registration data should not silently become an unlimited marketing or networking database.

This approach also makes registration forms easier to use. Data minimization can reduce unnecessary questions, while clearer explanations can help participants understand why the remaining information matters.

How Should Event Platforms Handle Consent?

Q: What should organizers look for when evaluating event technology?

A: The platform should help organizers translate privacy decisions into actual attendee experiences. A privacy notice is important, but the interface itself should reinforce the same expectations. Visibility settings, profile controls, communications and networking features should not contradict what participants were told during registration.

For networking in particular, the design should recognize that different attendees have different expectations. Some actively want introductions. Others may participate only in sessions. A useful system therefore distinguishes attending an event from choosing to be discoverable for networking.

MeetWho reflects this separation through organizer-controlled networking privacy settings and participant permission. Participants can create professional profiles describing what they are working on, what they are looking for, whom they want to meet and how they can help others. MeetWho can then use these signals, alongside event goals and shared interests, to recommend relevant people among users who have permissioned participation, rather than relying on an unrestricted public attendee list.

Recommendations are designed to explain why two people may benefit from meeting, how they could potentially help one another and how a conversation might begin. Users can send connection requests, and messaging becomes available after a mutual connection. Paid membership does not provide access to hidden profiles or private contact information, and MeetWho does not sell attendee lists.

The important lesson extends beyond any single platform: attendee privacy should influence feature design, not just policy wording.

Event Consent Checklist for Organizers

A checklist cannot replace a legal assessment, especially when events operate across jurisdictions or process sensitive categories of information. It can, however, expose common gaps before they become part of the attendee experience.

Use the following framework during registration design, vendor selection and pre-launch testing:

AreaRecommended PracticeQuestion to Ask
RegistrationCollect information for defined purposesDo we know why every important field exists?
Privacy informationExplain material processing clearlyCan an attendee understand what happens to their data?
NetworkingSeparate event attendance from networking participationDoes registration automatically make someone discoverable?
ProfilesProvide appropriate visibility controlsWho can see the information a participant provides?
CommunicationsDistinguish necessary event updates from optional marketing where requiredWhat messages should an attendee reasonably expect?
Sponsors and partnersBe transparent about relevant third-party sharingWould the attendee expect this organization to receive their information?
Check-inLimit access to operational needsWho can view or use check-in information?
RetentionDefine an appropriate retention approachAre we keeping data longer than its purpose requires?
Participant requestsEstablish a process for applicable data rightsCan the team respond when someone asks about their information?
VendorsUnderstand processing responsibilitiesWhat does each provider do with attendee data?

The checklist is deliberately broader than event consent management alone. That is because good privacy governance involves lawful basis, transparency, necessity, security, retention and individual rights alongside consent. Treating every privacy problem as a checkbox problem can create false confidence.

Organizers should also document important decisions. When a team decides that a particular data field is necessary, that networking participation is optional, or that a third-party disclosure has a specific basis, recording the reasoning can make future reviews more consistent.

How Privacy-Friendly Networking Creates Better Events

Privacy controls and networking effectiveness are sometimes presented as opposing goals: reveal more people and networking becomes easier; restrict visibility and connections supposedly decline. That framing overlooks what professional networking is actually for. A directory containing hundreds or thousands of names does not necessarily help someone determine whom they should speak to.

A more useful model focuses on relevance and mutual participation. Instead of making every attendee browseable by default, privacy-first networking can prioritize people who have chosen to participate and use contextual signals to identify potentially valuable introductions.

For organizers, this supports a clearer promise to attendees: participation in the event does not automatically mean unrestricted exposure. For participants, it can also reduce the effort required to search through profiles that have little connection to their objectives.

MeetWho describes this philosophy as “Know who to meet.” The goal is not to maximize the number of contacts collected during an event, but to help people find relevant, mutually beneficial conversations. Its networking experience can surface personalized recommendations and explain the reasoning behind them while respecting organizer settings and participant permission.

That distinction is especially valuable for conferences, community gatherings, workshops, entrepreneurship programs, corporate events and online professional events where trust and networking quality can matter as much as attendance numbers.

Common Questions Event Organizers Ask About Consent

Privacy questions rarely disappear once registration closes. They continue through networking, check-in, sponsor engagement, communications and post-event follow-up. The following answers address several of the issues organizers should resolve before attendees encounter them.

Do Attendees Need to Approve Networking Visibility?

Event attendance should not automatically be treated as agreement to participate in networking or appear in an attendee directory. Organizers should distinguish information needed to provide the event from optional uses that make a participant discoverable to other people.

Where consent is the applicable legal basis, it should meet the relevant requirements for a valid choice. Even where another lawful basis applies to particular processing, organizers still need appropriate transparency. A privacy-conscious networking experience should make it reasonably clear who can see participant information and what happens when networking is enabled.

Can Event Organizers Share Attendee Information Publicly?

Organizers should not assume that registration creates blanket permission to publish attendee information. Posting names, employers, photographs, professional biographies or contact information can represent a separate use of personal data from administering the event itself.

The same caution applies to sponsors and partners. If attendee information will be disclosed to another organization, the organizer should understand the purpose, applicable lawful basis, transparency obligations and respective data-protection responsibilities before the disclosure happens.

What Role Does a DPO Play in Event Privacy?

A Data Protection Officer can help an organization evaluate how personal information moves through the event lifecycle, identify data-protection risks and advise on obligations under applicable privacy law. Depending on the organization and processing involved, appointing a DPO may itself be legally required under the GDPR.

A useful data protection officer interview therefore goes beyond asking whether a registration form contains a consent checkbox. A DPO is more likely to examine purposes, lawful bases, transparency, data minimization, retention, access, third-party relationships, participant rights and whether the actual event experience matches the promises made to attendees.

How Can Event Technology Support Consent Management?

Technology cannot decide an organizer's legal obligations, but it can make privacy decisions easier—or harder—to implement. Useful capabilities include configurable visibility, clear participant controls, controlled access, appropriate communications settings and networking experiences that do not depend on exposing everyone by default.

MeetWho combines event creation, registration, attendee management and smart networking within one platform. Organizers can create an event for free, collect registrations, approve applications, manage waiting lists, send announcements and reminders, use QR check-in, and determine networking privacy settings. For online events, event links can be limited to registered participants.

On the attendee side, networking focuses on relevant introductions among participating users rather than unrestricted access to a public attendee list. This provides a practical example of how product design can support event data privacy while still helping attendees discover worthwhile professional connections.

From Consent Checkbox to Privacy-by-Design Event Planning

The most important shift for organizers is to stop treating privacy as a final compliance step. Consent wording added the day before registrations open cannot correct a workflow that was designed around unnecessary data collection, unclear sharing or default public visibility.

Instead, privacy questions should appear throughout event planning. Before adding a registration field, ask why it is needed. Before enabling a directory, ask whether attendees expect to be visible. Before transferring a list to a sponsor, establish whether that use is appropriate and transparent. Before retaining profiles after an event, determine why continued storage is necessary.

This approach also helps teams distinguish consent from the wider data-protection framework. Under the GDPR, consent is one lawful basis among several. Principles such as purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality remain relevant to how personal data is handled.

For authoritative guidance, organizers working with European personal data should consult sources such as the European Data Protection Board, the official text of the General Data Protection Regulation, and national supervisory authorities such as the UK's Information Commissioner's Office. Legal requirements can vary by jurisdiction and circumstance, so event teams should obtain qualified advice where necessary.

Final Thoughts From a DPO: Consent Builds Better Events

The central lesson from this DPO interview is not that organizers need more checkboxes. It is that people should understand what is happening to their information and retain meaningful control where choices are offered.

Registration, event operations, networking, marketing and third-party sharing are not automatically the same purpose. Treating them as interchangeable can create privacy risks and undermine attendee trust. Separating them encourages organizers to collect less unnecessary data, explain important uses more clearly and choose technology that respects participant expectations.

For networking in particular, privacy does not have to mean less value. A permission-based experience can replace indiscriminate visibility with more relevant discovery. When participants understand how they are being introduced and remain in control of whether they participate, networking can focus on quality rather than exposure.

MeetWho's approach follows that principle: Know who to meet. Organizers can create and manage events for free while setting the conditions for networking, and participants can receive relevant introductions without paid access exposing hidden profiles, private contact details or attendee lists.

If you are planning a conference, workshop, community meetup, startup program, corporate event or online gathering, you can create a free event with MeetWho and build an attendee experience around controlled participation, useful event management and meaningful professional networking.

Sources and Further Reading

More stories

Browse all
August 11, 2026·16 min

Networking Benchmarks 2027: Connection, Follow-Up, and Meeting Rates

Discover 2027 networking benchmarks covering connection rates, follow-up rates, meeting conversion, and practical ways event organizers can improve meaningful professional connections.

August 11, 2026·16 min

The Consent Ladder for Attendee Data: A Complete Consent Framework for Event Organizers

Learn how the Consent Ladder for Attendee Data helps event organizers build transparent consent frameworks, protect attendee privacy, and create trusted networking experiences with better data governance.

August 11, 2026·15 min

The Second Meeting Metric: How Second Meeting Rate Measures Networking Success

Discover the Second Meeting Metric and learn how second meeting rate reveals the real quality of professional networking connections beyond first interactions.

August 10, 2026·17 min

What Is a Good Repeat Attendance Rate? A Benchmark Guide for Events

Discover what a good repeat attendance rate means, how event organizers benchmark returning attendees, which factors influence repeat participation, and how event networking platforms can improve attendee retention.

August 10, 2026·15 min

What Is a Connection Rate at Events? How to Measure Networking Success

Learn what connection rate at events means, how to calculate it, why it matters for networking outcomes, and how event organizers can improve meaningful attendee connections.

August 10, 2026·14 min

What Is Event Intelligence? A Complete Guide to Smarter Event Networking

Discover what event intelligence means, how it helps organizers and attendees create better event experiences, and how data-driven networking platforms like MeetWho enable more meaningful professional connections.

August 10, 2026·16 min

What Is a Relationship Graph? How It Maps Meaningful Connections

Learn what a relationship graph is, how it represents connections between people, data, and entities, and how relationship-based intelligence helps create more meaningful professional networking experiences.

August 10, 2026·15 min

How We Measure Whether MeetWho Actually Worked: Product Success Metrics

Discover how to measure whether an event networking platform actually creates value. Learn the product success metrics, engagement signals, networking outcomes, and evaluation methods that show whether MeetWho helps people build meaningful connections.