--- name: govern-event-data-and-consent category: data description: Govern event data across collection, access, sharing, recording, retention, rights, and deletion. Use when registration, access needs, payments, sponsors, apps, photography, analytics, or follow-up create material privacy and consent risk. --- # govern-event-data-and-consent ## When to use - Use when several event systems, vendors, audiences, sensitive fields, recordings, jurisdictions, or secondary uses interact. - Use a simple registration privacy notice for one low-risk form with no complex sharing or media. ## Preconditions - Confirm event scope, jurisdictions, data controller or accountable owner, privacy and security reviewers, systems and vendors, participant groups, sensitive-data boundary, incident route, records needs, and rights-handling capacity. ## Procedure 1. Build a data lifecycle map from invitation, registration, payment, access request, credentialing, app, Wi-Fi, attendance, recording, photography, survey, sponsor activity, support, incident, and follow-up. 2. Create an event data register with field, person, source, purpose and authority, necessity, system, owner, access, sharing, location, retention, rights, and risk. 3. Minimize identity, disability, dietary, safeguarding, payment, travel, demographic, behavioral, and incident data at the point of collection. 4. Establish consent separation so optional marketing, sponsor sharing, photography, recording, research, and profile publication are distinct from attendance and service delivery. 5. Design plain notices and usable choices for adults, children, speakers, staff, remote participants, photographers, and people who cannot or do not consent. 6. Control vendors and sponsors through scope, instructions, access, security, subprocessors, location, incident, return, deletion, and audit evidence. 7. Test data flows against actual integrations, exports, badges, spreadsheets, inboxes, dashboards, pixels, recordings, backups, and manual workarounds. 8. Provide access, correction, withdrawal, objection, deletion, alternative participation, and urgent privacy support routes. 9. Monitor breach, misdirected badge, exposed attendee list, unauthorized image, sponsor misuse, credential loss, and sensitive accommodation disclosure scenarios. 10. Perform retention and deletion across primary systems, exports, vendors, media, devices, backups, and archives, preserving only authorized records and exceptions. ## Failure plan - Stop collection or sharing when purpose, authority, necessity, notice, protection, recipient, or deletion route is unresolved. - Do not treat event terms, prechecked boxes, entry, badges, or camera notices as universal consent for unrelated uses. - Escalate child, biometric, health, safeguarding, cross-border, direct-marketing, incident, and legal-retention questions to qualified owners. ## Done - An event data register and data lifecycle map reconcile collected fields, systems, purpose and authority, access, sharing, location, and risk - A consent and sharing record proves consent separation, notices, choices, vendor instructions, participant rights, and nonconsent alternatives - Flow tests and incident rehearsals verify actual integrations, exports, manual copies, media, support, and containment - A retention and deletion report proves deletion verification across systems, vendors, exports, devices, media, backups, and approved exceptions