Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What do security teams get wrong about privacy…
Governance, Ownership & Risk

What do security teams get wrong about privacy at in-person events?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Governance, Ownership & Risk

A common mistake is assuming that a relaxed setting means informal data handling is acceptable. In practice, event photos, attendee lists, and contact details can become lasting records. Teams should set expectations in advance, train staff on opt-out handling, and make sure any promotional use of images is tied to clear consent and removal pathways.

Why This Matters for Security Teams

In-person events often create a false sense of informality, but privacy risk does not disappear when people are face to face. Attendee badges, sign-in sheets, QR scans, photo walls, and sponsor lead capture all become durable records that can be copied, repurposed, or retained long after the event ends. Under EU General Data Protection Regulation (GDPR), that means collection, purpose limitation, retention, and consent expectations still apply.

Security teams also underestimate how quickly event data spreads across marketing, venue staff, volunteers, and third-party tools. The practical issue is not only whether data was collected, but who can see it, where it is stored, and how it is deleted. NHIMG research on the Ultimate Guide to NHIs shows that 92% of organisations expose NHIs to third parties, which is a useful reminder that event privacy often fails at the handoff points, not just at the point of capture. In practice, many security teams encounter privacy complaints only after attendee data has already been shared with sponsors or reused in post-event campaigns, rather than through intentional privacy review.

How It Works in Practice

Good event privacy starts before registration opens. Security and privacy teams should define what data is necessary, who receives it, how long it is retained, and whether image capture or attendee networking features require opt-in rather than opt-out. That review should cover the physical event as well as the supporting systems, because badge printers, mobile apps, lead retrieval tools, and Wi-Fi portals often collect more data than the core registration form.

Operationally, the controls are straightforward:

  • Use data minimisation for registration fields and badge content.
  • Separate operational attendance records from promotional or sponsorship lists.
  • Limit access to attendee data on a need-to-know basis, including temporary event staff.
  • Set retention windows for photos, scans, and lead captures, then delete them automatically.
  • Make opt-out and removal requests easy to execute after the event.

For teams looking for a control baseline, NIST SP 800-53 Rev 5 Security and Privacy Controls gives useful guidance on access control, media protection, and information retention. NHIMG’s IOS app secrets leakage report is also relevant because it illustrates how seemingly routine tooling can expose sensitive data when teams assume convenience tools are safe by default. These controls tend to break down when event vendors operate as independent processors with inconsistent deletion practices and no shared retention workflow.

Common Variations and Edge Cases

Tighter privacy controls often increase event operations overhead, requiring organisations to balance attendee experience against compliance and data minimisation. That tradeoff becomes most visible in high-touch events where networking is a feature, not a side effect, and where photo sharing or sponsor follow-up is part of the business model.

Best practice is evolving for hybrid events, multi-venue conferences, and events that use AI-powered transcription or facial recognition. There is no universal standard for this yet, but current guidance suggests treating these as higher-risk processing activities because they expand collection beyond what attendees may reasonably expect. A badge scan to confirm entry is not the same as persistent location tracking, and a consent banner at registration does not automatically justify all downstream uses.

Security teams should also watch for edge cases such as VIP lists, minors, health-related accommodations, and media access zones. In those settings, the privacy question is not only “was consent obtained?” but also “was the collection necessary at all?” If the event uses third-party photo platforms or sponsor apps, the review should extend to deletion SLAs and data-sharing contracts so that attendee expectations match actual practice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Event privacy depends on limiting who can access attendee data and images.
NIST SP 800-63Registration and badge workflows still need assurance about identity collection and verification.
OWASP Non-Human Identity Top 10NHI-05Third-party event tools often expose sensitive data through weak secret and access hygiene.
NIST AI RMFGOVERNAI photo and transcription features create privacy risks that need governance and oversight.

Collect only the identity attributes needed for event access and avoid unnecessary verification data.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org