IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Your annual conference is running on a data stack IT never reviewed

Your annual conference is running on a data stack IT never reviewed

Fri, 4th Sep 2026 (Today)
The Conference Group
THE CONFERENCE GROUP

Somewhere in most large Australian organisations there is a registration platform holding several thousand records: names, job titles, employers, mobile numbers, dietary requirements, accessibility needs, and in some cases passport details for interstate travel. It was chosen by the marketing or events team. It syncs to the CRM through an integration nobody documented. It is almost certainly hosted overseas.

And in a great many cases, IT has never seen the contract.

Corporate events have quietly become one of the larger uncontrolled data collection exercises inside the enterprise. The annual user conference, the partner summit, the roadshow series: each one spins up a temporary technology stack, gathers personal information at volume, distributes it to third parties, and then goes dormant until next year without anyone formally decommissioning it. For a function that reports to the CMO, it carries a surprising amount of the CIO's risk.

The stack nobody put through vendor review

A mid-sized corporate conference typically runs on more moving parts than the events team realises. There is a registration and ticketing platform. A badge printing and scanning system, often supplied by the venue or the AV contractor. A delegate mobile app. A lead retrieval tool that sponsors use to scan attendees at their stands. A streaming platform if the event is hybrid. Increasingly, a matchmaking feature that recommends sessions or introduces delegates to each other algorithmically.

That is six or seven vendors, each with their own subprocessors, each with a different retention default, and each typically signed off against a marketing budget line rather than a procurement gate.

The organiser holds most of those contracts. This is why the smarter organisations appointing a Professional Conference Organiser (PCO) in Melbourne, where a substantial share of the country's business events activity is concentrated, are now writing data handling requirements into the initial brief rather than discovering them at the post-event debrief. The appointment is the point of maximum leverage. Once the platform is chosen and registration is open, the architecture is fixed for the year.

What the registration form actually collects

The contact fields are the least interesting part. What matters is further down the form.

Dietary requirements can constitute sensitive information under the Privacy Act. A note about coeliac disease or a severe nut allergy is health information. A halal or kosher meal request can reveal religious belief. Accessibility requirements are health information almost by definition. Sensitive information attracts a higher threshold for collection than ordinary personal information, and it cannot be collected simply because it is convenient to have.

Most event registration forms treat these as free text boxes with no consent language attached, no retention rule, and no restriction on who downloads the resulting spreadsheet. That spreadsheet is then emailed to a caterer.

Where the data goes after the event

Three exposures are worth mapping.

Sponsor lead lists. Every exhibitor who scanned a badge now holds a copy of a subset of your attendee data, under their own privacy practices, in their own CRM. Whether attendees understood that scanning a badge constituted disclosure to a third party is a question that rarely gets tested until someone complains.

Cross-border storage. A large proportion of event technology is hosted in the United States or Europe. Disclosing personal information to an overseas recipient does not transfer accountability. The Australian entity remains on the hook for how that recipient handles it.

Retention. Nobody deletes the 2019 delegate list. It sits in the platform, or in a shared drive, or in the inbox of an events coordinator who left two years ago. It has no business purpose and it is pure breach surface.

Why the legal exposure has shifted

The Privacy and Other Legislation Amendment Act 2024 was the first tranche of a multi-stage reform program, and most of it commenced in December 2024. Two elements matter here.

The statutory tort for serious invasions of privacy commenced on 10 June 2025. For the first time, an individual can sue directly rather than lodging a complaint with the OAIC and waiting for enforcement action. Courts can award damages and grant injunctions, and the door to class actions is now open. A leaked delegate list stops being a reputational irritation and becomes a claim.

Automated decision-making transparency obligations commence on 10 December 2026. If your event platform uses an algorithm to match delegates or recommend sessions, that is worth checking against the new disclosure requirements well before the deadline.

Beyond that, the Government has released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, containing roughly 40 proposals and signalling a material lift in obligations around data minimisation, data security and breach response across the full information lifecycle. The direction of travel is clear even though the timetable is not.

The questions worth asking before the contract is signed

None of this requires IT to take over the events function. It requires five questions, asked early:

  • Where is attendee data stored, and which subprocessors touch it?
  • What is the retention period, and who can trigger deletion?
  • What consent language sits against dietary and accessibility fields?
  • What exactly do sponsors receive when they scan a badge, and what are they contractually permitted to do with it?
  • Does the platform make automated decisions about attendees, and can it explain them?

Every one of these is answerable by a competent organiser. The ones who cannot answer them are telling you something useful.

Make the events team an ally, not a workaround

The failure mode here is predictable. IT discovers the gap, imposes a review process, and the events team routes around it next year because the platform has to be live in three weeks and procurement takes six.

The better move is to hand the events function something they can actually use: a short list of pre-cleared platforms, a standard data protection addendum to attach to organiser contracts, and a named contact who will turn around a review inside a week. Meet them at the briefing stage, when the decision is still open, rather than at the point where cancellation costs are already sunk.

Conferences are not going away, and the data they generate is only becoming more valuable and more regulated. The organisations that get ahead of this will be the ones who stopped treating the annual conference as a marketing expense and started treating it as a data processing activity that happens to involve catering.