Data Privacy at Trade Fairs: How to Handle Contact Information

Last updated:
09.03.2023
The exhibition halls stood empty for a long time, but the current situation has encouraged exhibitors and entrepreneurs to meet in person once again. When doing so, it is essential to keep trade fair data protection in mind during customer acquisition. We show you what to look out for and how to easily implement these requirements.
Data Privacy at Trade Fairs: How to Handle Contact Information
Key Takeaways
  • Observe data minimization: Only collect necessary data (Art. 5 (1) (c) GDPR).
  • Purpose limitation principle: Only process data for as long as the purpose for collection exists.
  • Obtain consent: Get prior consent for further marketing (newsletters, offers, etc.).
  • Transparent information: Provide information about data processing at the trade fair booth in accordance with Art. 13 GDPR.
  • Data protection training: Train trade fair staff on data protection in advance.

Following the pandemic-related standstill, the trade fair season is back in full swing. With all the new contacts being made, data protection should be a priority from the very beginning. This not only ensures security but also reflects a professional approach. 

Trade fair halls were empty for a long time – now, the COVID-19 situation allows exhibitors and entrepreneurs to meet in person once again. When acquiring new customers, data protection at trade fairs should be considered right from the start. We show you what to look out for and how to easily implement the requirements.

What data may be collected at a trade fair?

Exhibitors at trade fairs want to do more than just provide information about their innovative products; they naturally want to sell them or, at the very least, make new contacts. Data protection must be considered in all these aspects. As soon as contact details are exchanged, compliance with the General Data Protection Regulation (GDPR) is essential. 

The most important principle to observe when collecting data at a trade fair is data minimization, as per Art. 5 (1) (c) of the GDPR. This means you may only collect the personal data of prospects or customers that you actually need. For specific product information via email, this is the email address and, if applicable, the name; for shipping an order, it is both the name and the address. 
As a rule of thumb: only data that is actually necessary for providing contractual services may be collected. Incidentally, it does not matter whether you collect the data digitally or via a paper form/contract. 

Furthermore, please note the so-called purpose limitation principle: this states that personal data may only be processed as long as the purpose for collection exists. Subsequently, the personal data must generally be deleted. In a trade fair environment, the following scenarios are conceivable:

  • You acquire a customer who purchases a product. To conclude the sales contract and deliver the goods, you need their name, address, and payment information. Once the goods are paid for and the product has been delivered, the purpose for collecting the personal data has expired. Further promotional contact with the customer is not permitted without their express consent.
  • You have a prospect who is interested in a product but cannot decide. They request an information brochure by mail. For this purpose, you collect their name and postal address. As soon as you have sent the information, the purpose for collecting the personal data has expired. Further promotional contact with the customer is not permitted without their express consent.

If you wish to send further promotional material (newsletters, offers, etc.) via email to prospects who visited your booth after the trade fair, you must generally have them complete a declaration of consent in advance. 

To what extent must information be provided regarding the collection or processing of data?

Information about data processing must also be provided directly at the trade fair booth: Art. 13 of the GDPR states that individuals whose data is being collected must be transparently informed at the time of collection. This includes, among other things, the following questions:

  • Who is responsible for the data processing? (You or your company)
  • What are the purposes of the data collection? (Sales, information offers, etc.)
  • Is the data shared with third parties?
  • How long is the data stored?
  • How can the customer / prospect object to data processing?
  • What other rights do customers / prospects have?

It is advisable to display this information clearly on a small sign at your trade fair booth and to provide it to all customers and prospects as a printed statement when they fill out a contact form. However, the customer / prospect does not need to confirm this statement (via signature or by checking a box). 

Handling customer data correctly

Customer data is collected and processed in more places than just trade fairs. Companies must ensure they process customer data in compliance with data protection regulations, especially in everyday situations.

Data protection at trade fairs: Key points to keep in mind

In addition to the points already mentioned, you should also ensure that you train all trade fair staff on data protectionbeforehand. Once at the trade fair, there are further data protection points that should not be overlooked:

  • Regarding contact forms and data protection: Do not leave lists of contact details lying around in plain sight! Furthermore, prospects filling out a paper contact form should not be able to see the information previously provided by others.
  • Do not post photos of individual trade fair visitors at your booth on social media without having obtained their consent!
  • Please note that prospect data may only be used for the purpose for which it was collected (e.g., to send a requested quote). If you wish to use this data beyond the initial contact, such as for promotional emails or newsletters, you require a new legal basis: in this case, additional consent (e.g., double opt-in for marketing emails). Alternatively, you can, of course, encourage prospects to sign up for a newsletter right from the start.  

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in