Identify which users are Data Administrators
Tasks
|
Background information:
You can assign any EventsAir user at any level the additional authority to serve as a Data Administrator. This authorization lets the user search for Anonymized records using encrypted name, email or phone numbers from within the Attendee Panel. Data Administrators can also search for encrypted contact details in the Contact Locator.
Archive old events
Tasks
|
Background information:
When an event is archived, all attendees are Anonymized and all personal data in the event will be permanently deleted. The attendee’s name, email and phone number is permanently encrypted, allowing for a record search only by an authorized Data Administrator.
Identify Fields containing Personal Data
Tasks
|
Background information:
It is important for event managers to review any fields - especially additional fields you have created - so you can mark them as containing personal data if needed. These can be User Defined Contact Fields, Note Types, Marketing Tags and Custom Fields. Identifying any that contain personal data is used by EventsAir for reporting to attendees and when anonymizing or deleting a contact record for data privacy reasons.
Set up default Data Consent policies
Tasks
|
Background information:
Data Processing Consent policies are statements shown to a contact prior to them submitting their personal information to you during event registration or using the Attendee App. These statements describe how you plan to use a contact’s personal data, including the reasons for collecting their personal data, how long you plan to store their personal data and details of third-party processors accessing their personal data. There are additional policies that need to be defined and these are detailed in the EventsAir and the Data Protection Toolkit White Paper.
Set up Data Consent policies for all active events
Tasks
|
Background information:
Even if you have events already in progress, you should add Data Consent Policies in Event Preferences and update all Interactive Sites to display these policies and to capture Consent from new attendees.
Add the Data Protection widget to all user dashboards
Tasks
|
Background information:
The Data Protection Widget provides event planners with a snapshot of their Data Protection status across Data Processing Consent, Attendee App Visibility and Compliance. For each category, statistics are displayed, with most of the items having a link that lets you view attendee details or links to Interactive Sites, Apps, Reports and Exports for easy follow up and checking.
Send a Merge Doc to those who haven't given Data Consent
Tasks
|
Background information:
If you add Data Consent to an existing event, you may have attendees who have previously registered without indicating consent. This process is important to assure that all contacts in your database have provided consent to using their personal data.
Set (or convert) Quick Reports and Quick Exports to Private
Tasks
|
Background information:
It is a requirement to know and manage which third-party processors or individuals are accessing personal data contained in EventsAir, such hotel partners, clients and other service providers. When you create a Quick Report or Export in EventsAir and enable Web Publishing, you can mark these as Private or Public as defined in your organization’s policies. This process lets the Data Protection Toolkit track and log every time an authorized third party accesses a Private Quick Report or Export.
Advise third-party data processors of all requests to 'forget' (remove Personal Data)
Tasks
|
Add Attendee App Visibility option to all Attendee Apps
Tasks
|
Background information:
Separate from providing Consent to providing personal data for event registrations, attendees also able to Opt In or Opt Out of having their contact details visible in the Attendee App. This allows attendees to attend an event by providing Consent to provide personal data, but Opt Out of having their contact details visible in Attendee Searches, function table allocation and in the EventStream Private Social Network.
Provide a Data Processing Statement to attendees if requested
Tasks
|
Background information:
It is a requirement in GDPR to allow attendees and contacts to request information about what personal data you have as well as how long you plan to use their personal data and what third parties are accessing their information. The Contact Locator Tool that allows you to search for attendee records across multiple events and generate a detailed Data Processing Statement to send to the requesting party.
It is important to have policies in place for:
- identifying person(s) requesting and approving requests for personal data;
- making sure your team knows how to properly review and select searched contact records in order to generate an accurate Data Processing Statement.
Remove or Anonymize contact records if requested
Tasks
|
Background information:
In terms of protecting the personal data of our attendees you are required to honor a request from an attendee to delete, remove, or "forget" their personal data. However, you also have the right to retain the non-private aspects of the record for reporting and tracking reasons. These could include taxes collected, payments made, registration details, housing reservations and more.
While removing a contact will permanently delete it, EventsAir will not allow you to do so if there are any outstanding financial transactions. It is a common practice for many meeting planners NEVER to delete any record that has financial transactions present, whether they are fully paid or not.
So, when you Anonymize a contact record, you will delete all personal data, encrypt the name, email and phone number, and retain all historical data for reporting reasons.