Pre-conference day (27th April, 2023) activity of the 'WikiConference India 2023' or WCI2023. It was held at the Hyatt hotel at Gachibowli, Hyderabad, from 28th to 30th April 2023. About 150 Wikipedians from India, Bangladesh, Sri Lanka, Italy and the USA participated at the three day event.
Photo by Biswarup Ganguly on wikimedia

Rights Agreements

Part of Conference and business event sponsorship

Reviewing attendee data access in a sponsor package

“Attendee data included” is not a complete sponsor right. Ask which fields are shared, which attendees are covered, when the data arrives, whether people can …

Treat “attendee data included” as incomplete. Get the fields, attendee group, supply timing, consent, permitted use, access arrangements and end of access and retention set out in writing.

AuSAE’s Linc Conference sponsorship offer specifies email addresses for participants who opt in, for one post-conference communication. It does not specify additional fields or further attendee categories.

The offer says participants opt in, but does not state how that consent is worded or recorded. Check that the opt-in covers the message you plan to send, and check the Spam Act 2003 (Cth) and ACMA guidance on avoiding spam before sending email.

The stated use is one post-conference communication. Do not treat that as permission for recurring sales messages; a list collected to run a hosted meeting does not by itself establish permission for general sales follow-up, and a badge scan is not proof of agreement to every later message.

The offer does not state when the list will be supplied, how it will be handed over or who may access it. Agree those details in writing, and limit access to people responsible for the permitted follow-up.

No retention period, access end point or deletion step is specified in the offer. Agree when access ends, when the data must be deleted and who is responsible for deletion and for passing on correction, opt-out or deletion requests.

Check whether the organiser and sponsor are covered by the Privacy Act 1988 (Cth), which regulates Australian Government agencies and organisations with annual turnover of more than $3 million, plus some other organisations. The Act includes 13 Australian Privacy Principles (APPs), which apply to some private sector organisations and most Australian Government agencies.

For an APP entity, compare its privacy policy with the proposed transfer. APP 1.4 covers the kinds of personal information collected and held; the purposes for which it is collected, held, used and disclosed; how a person can seek access or correction; and how complaints are handled.

The OAIC is the independent national privacy regulator; consult its direct-marketing guidance when assessing a marketing use. If the organiser cannot explain the notice and opt-in route, do not assume the list can be used for the proposed follow-up.

AuSAE offer: what is specified vs what is left open

  • Fields sharedSpecified: email addresses of participants who opt in. No other fields stated.
  • Attendee group coveredSpecified: opted-in participants. No further attendee categories stated.
  • Permitted useSpecified: one post-conference communication. Not permission for recurring sales messages.
  • Consent wording and recordLeft open: opt-in is stated, but not how the consent is worded or recorded.
  • Supply timing and handoverLeft open: the offer does not state when the list is supplied or how it is handed over.
  • Access arrangementsLeft open: no statement of who may access the list, or how access is limited.
  • Retention, access end and deletionLeft open: no retention period, access end point or deletion step, and no owner for correction, opt-out or deletion requests.

Reviewing attendee data access: six steps

  1. Read the offer and list the silencesTreat 'attendee data included' as incomplete. Set out the fields, attendee group, supply timing, consent, permitted use, access arrangements, and end of access and retention.
  2. Test the consent against your messageCheck that the opt-in wording and record actually cover the message you plan to send.
  3. Agree supply, handover and access in writingFix the supply date, the handover method and who may access the list, limited to those running the permitted follow-up.
  4. Set the end pointAgree when access ends, when the data must be deleted, and who is responsible for deletion and for passing on correction, opt-out or deletion requests.

Attendee data rights: key thresholds and limits

Privacy Act coverage threshold
$3 million annual turnover, plus some other organisations
Permitted email use in the AuSAE offer
One post-conference communication

More from Rights Agreements

Outcome Measurement

Measuring qualified interactions at a sponsored conference

A badge scan records contact, not qualification. Decide before the event what a useful interaction means: the person fits the intended audience, has a relevant …

Rights Agreements

Agreeing on approval rights and brand usage

Set sponsorship brand permissions, proof approvals, accurate relationship wording and the end of each permitted use.