Lead-scanning privacy rules
Before every capture, identify your company and explain: “May we save your name, company, job title and email so that our team can follow up about this conversation? It is optional.” Show the attendee your company’s privacy notice and explain how they can withdraw.
Only confirm permission when the attendee has agreed. Do not scan badges at a distance, use photographs or attendee lists to collect leads, or infer permission from event attendance. Entry checks are not lead capture.
Use notes only for the requested business follow-up. Do not record health information, personal opinions or other sensitive details. A badge scan does not subscribe someone to marketing: obtain a separate lawful permission if needed.
Limit lead access and CSV exports to authorised colleagues. Protect exports, set a documented retention period and action objections, withdrawals and deletion requests across your systems. Do not sell leads or share them with unrelated companies.
Offline scans contain personal data on this device. Lock it, sync promptly and discard unnecessary pending records. Signing out retains pending scans for recovery. Never hand over a device with unsynced attendee data.