Why event data privacy now defines exhibitor lead quality
Event data privacy for UK exhibitors is no longer a compliance side note. The Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, tightens data protection rules around every event, from registration forms to badge scanners on the show floor. For any exhibitor treating personal data as a cheap commodity, the new regime turns that habit into a direct commercial and regulatory risk.
Under the Act, explicit consent is now the default expectation whenever you collect personal data from visitors at UK B2B events, whether through badge scans, QR codes, or lead capture apps. That consent must be separate from general terms, clearly linked to specific products and services, and easy to withdraw, which forces exhibitors to rethink how they present contact options and email marketing choices at every touchpoint. The shift is not just legal; it changes how companies design their tech stack, how they brief sales teams, and how they justify every request for contact details in terms of value to the attendee.
For operations and procurement leaders, this is not abstract regulation but a practical filter on which events deserve budget. When event data privacy for UK exhibitors is handled well, you gain cleaner contact data, clearer legal basis for follow up, and a stronger narrative when procurement challenges the ROI of a stand at ExCeL London or the NEC. When it is handled badly, you inherit opaque data sharing with third parties, weak consent records, and a real chance that a single complaint about how you process personal information will trigger an Information Commissioner’s Office enquiry.
Executive summary for UK exhibitors: the Data (Use and Access) Act 2025 raises the bar on consent, documentation, and accountability for event data. Exhibitors that redesign badge scanning, lead capture, and post event data sharing around explicit consent and clear retention rules will not only reduce ICO enforcement risk but also improve lead quality, sales conversion, and trust with procurement and legal stakeholders.
What the Data Act 2025 changes for event data collection
The Data (Use and Access) Act 2025 sits alongside UK GDPR and the Data Protection Act 2018, but it sharpens expectations around how exhibitors collect and use event data. The government’s own summary of the legislation notes that the Act introduces stricter regulations on personal data processing and that explicit consent is mandatory for processing personal data in many event scenarios. For UK exhibitors, that means every badge scan, lead retrieval form, and hosted buyer meeting now needs a traceable consent trail, not just a verbal nod at a busy stand.
Consent requests must be clear, granular, and separate from other terms, so you can no longer bury marketing consent for multiple products and services inside a generic privacy policy on your website. If your stand team uses tablets or event tech apps to collect contact data, each request for an email address or mobile number must explain why you collect it, how long you will keep it, and whether you will share personal information with any third party such as service providers or event sponsors. The Information Commissioner’s Office guidance on consent underlines that consent requests must be clear and separate from other terms and that individuals have the right to withdraw consent at any time, and it expects organisations to be able to demonstrate how and when consent was obtained.
For exhibitors using organiser-supplied lead retrieval devices, the Act also pushes transparency on data sharing and data controller roles. You need to know whether the organiser or the exhibitor is the primary data controller, which third parties process personal data on your behalf, and how cookies or tracking pixels on third-party websites link back to your own CRM. This is exactly where first-party event data strategies, such as those outlined in analyses of how first-party event data delivers higher ROI for UK exhibitors, become commercially relevant rather than theoretical.
Badge scanning consent in practice on the show floor
Badge scanning has long been treated as a casual exchange at UK trade shows, but under the Data Act 2025 it becomes a formal consent moment. Before you scan a badge, your stand staff must explain what personal data you will collect, how you will use those contact details, and whether you will share personal information with any exhibitor sponsor or other third party. A hurried “we will send you some information” is no longer enough; you need a short, standardised script aligned with your privacy notice and privacy policy.
In practice, that means rewriting badge scanning workflows for events such as London Tech Week, UK Construction Week, or the Pharmacy Show, where exhibitors often process personal data at scale. A simple example script might be: “If I scan your badge, we will collect your name, role, company and contact details so we can follow up about our [product/service]. We will not share your details outside our group companies without your permission. You can opt out at any time using the link in our emails. Are you happy for us to scan your badge on that basis?” Your script should cover the legal basis for processing, the specific products and services you will talk about, and how the visitor can later withdraw consent or request deletion of their contact data. Ideally, the lead retrieval app or device should record that consent in a structured way, linking the scan to the consent text shown on screen, so you can evidence data protection compliance if the ICO asks why you decided to disclose personal information to certain service providers.
Post event, your CRM or marketing automation platform should clearly flag which contacts came via badge scans with explicit consent and which came from other events or websites. This is where a structured post event debrief template, such as frameworks that help teams turn three days of information overload into a ninety day action plan, becomes a compliance tool as well as a commercial one. You can then segment by consent status, avoid unlawful data sharing with third parties, and ensure that only contacts with a valid legal basis receive follow up email campaigns.
Sample consent-recording schema for badge scans: at minimum, each lead record should store: event name and date; device or app identifier; stand staff user ID; timestamp of consent; consent wording version; legal basis (for example, explicit consent for marketing); communication channels authorised (email, phone, SMS); and any notes on restrictions, such as “no third-party sponsors”. This simple structure turns a basic badge scan into an auditable consent log that aligns with ICO expectations on recording consent.
Lead retrieval devices, ownership and retention of personal data
Lead retrieval devices and apps sit at the heart of event data privacy for UK exhibitors, yet many contracts still blur who owns which personal data. Under the Data Act 2025, you must know whether the organiser or the exhibitor is the data controller for each stream of contact details, and which service providers act as processors. If the organiser will share personal data from badge scans with multiple sponsoring exhibitors, that data sharing must be transparent in both the organiser’s privacy notice and your own.
Retention periods are another weak spot that the Act brings into focus. You should define, in writing, how long you will keep personal data collected at specific events, and align that with your CRM rules and any sector specific guidance, rather than leaving old contact data to linger indefinitely. For example, a procurement manager visiting your stand at a manufacturing expo may expect you to keep their email and phone number only as long as there is an active opportunity, not for every future marketing campaign across unrelated products and services.
Contracts with lead retrieval vendors and event tech platforms should now include explicit clauses on data protection, data sharing, and the right to audit how they process personal information. You should also check whether their websites and third-party websites use cookies or tracking tools that automatically collect personal data from visitors who scan QR codes or visit a campaign landing page. If those tools disclose personal information to advertising networks or analytics third parties, you need to ensure that your privacy policy and consent flows reflect that reality, not an idealised diagram that only exists in a slide deck.
Illustrative retention-period table for event leads: for example, you might keep warm opportunities for up to 24 months from last meaningful interaction; general marketing contacts with explicit consent for 18 months from last engagement; event-only enquiries for 12 months from the event end date; and unsuccessful tenders for six to twelve months depending on sector norms. Whatever durations you choose, document them, apply them consistently in your CRM, and explain them in your privacy notice so attendees understand how long their event data will be retained.
Post event data sharing, sponsors and exhibitor accountability
Once the lights go down at the NEC or Olympia, the real test of event data privacy for UK exhibitors begins. Post event data sharing between organisers, sponsoring exhibitors, and individual stands is where most compliance gaps appear, especially when multiple companies expect access to the same pool of personal data. The Data Act 2025 raises the bar on transparency here, demanding that attendees know exactly which organisations will receive their contact details and on what legal basis.
If you act as an exhibitor sponsor for a conference stream or hosted buyer lounge, you must be clear whether you will share personal information with your own partners or third parties, and how that aligns with the organiser’s commitments. Your privacy notice should spell out which categories of companies receive contact data, whether any third party outside the UK is involved, and how attendees can request access or deletion. This is also the moment to align your sponsorship strategy with more strategic event sponsorship guidance that emphasises long term brand visibility over indiscriminate list buying.
Accountability does not stop at paperwork; it shapes how your sales and marketing teams behave after events. If your team receives a spreadsheet of leads from the organiser, they should check that each line has a clear consent status before loading it into your CRM or emailing prospects about new products and services. When in doubt, treat the contact as opted out until you can evidence a valid legal basis, rather than risking a complaint that your company chose to disclose personal information without proper consent.
Audit checklist and ICO enforcement expectations for badge scanning season
With autumn badge scanning season approaching, UK exhibitors need a structured audit rather than a last minute scramble. Start by mapping every event where you will collect personal data, from major trade fairs to smaller sector meetups, and list the tools you use to capture contact details. For each event, identify the data controller, the service providers involved, and any third parties that might receive data through integrations or third-party websites.
Next, review your consent flows and privacy documentation against the ICO’s guidance on obtaining consent, which stresses that consent must be freely given, specific, informed, and unambiguous. Check that your website forms, event apps, and badge scanning scripts all use the same core language about how you process personal information, how long you keep it, and whether you will share personal data with sponsoring exhibitors or other companies. Align your cookies banner and tracking settings with that narrative, so visitors are not told one story on your website and another at the registration desk.
Finally, prepare for enforcement as if an ICO audit were a realistic scenario, because for repeat offenders it will be. Non compliance may result in significant penalties; proactive adaptation to the Act's requirements is essential for exhibitors. A simple internal checklist can help: record the event name and date, confirm the data controller and processors, capture the exact consent wording used, log retention periods, and store evidence of staff training. That means training staff, documenting your legal basis for each processing activity, and being ready to show when and how each attendee gave consent for follow up contact, because in the end what matters is not the badge scan count, but the deal that followed.
Key statistics on event data consent and UK exhibitors
- The Data (Use and Access) Act 2025 received Royal Assent on 19 June, marking the formal start of a staged implementation that will reshape how UK exhibitors handle event data over the following 12 months (source: UK Government legislation collection for the Data (Use and Access) Act 2025).
- New consent requirements under the Act are being implemented from the year after Royal Assent, giving exhibitors a limited window to redesign badge scanning and lead capture processes before enforcement expectations harden (source: UK Government guidance on data protection and privacy changes linked to the Act).
- Regulators highlight enhanced data protection and transparent consent mechanisms as core trends, signalling that exhibitors who cannot evidence explicit consent for personal data processing at events face increased compliance obligations and potential penalties (source: UK Government and ICO commentary on the Data (Use and Access) Act 2025 and UK GDPR).
- ICO guidance on consent emphasises that organisations must be able to demonstrate when and how consent was obtained, which means exhibitors need auditable records for every badge scan and digital form used at UK B2B events (source: ICO guidance on obtaining, recording and managing consent under UK GDPR).
FAQ on event data consent and UK exhibitors
How does the Data Act 2025 change badge scanning at UK events?
The Act makes explicit consent the expected standard for processing personal data collected through badge scanning at UK events. Exhibitors must explain why they collect contact details, how they will use them, and whether they will share personal information with any third party, then record that consent in a way that can be audited later. Casual or implied consent at the stand is no longer defensible if challenged by the ICO.
Who is the data controller for leads captured at a trade show?
The data controller can be the organiser, the exhibitor, or both, depending on how registration and lead retrieval are structured. Exhibitors should clarify this in contracts and privacy notices, because the data controller is responsible for defining the legal basis, managing data sharing with service providers, and responding to attendee requests. Assuming the organiser carries all responsibility is a common and risky mistake.
Can exhibitors share event leads with group companies or partners?
Exhibitors can only share personal data from event leads with group companies or partners if they have a valid legal basis, usually explicit consent that clearly mentioned such data sharing. Any plan to disclose personal information to sponsoring exhibitors, resellers, or other third parties must be transparent in the consent wording and privacy policy. Silent or blanket consent for unspecified partners will not meet the standard set by the Data Act 2025.
What records should exhibitors keep to prove consent?
Exhibitors should keep records showing who consented, when, how, and what they were told at the time, including the specific wording used on forms or devices. For badge scans, that means linking each contact record to the event, the device or app used, and the consent text shown on screen or on paper. These records help demonstrate compliance if an attendee withdraws consent or the ICO investigates a complaint.
What are the risks of non compliance for UK exhibitors?
Non compliance with the Data Act 2025 and wider data protection law can lead to regulatory investigations, financial penalties, and orders to stop processing certain categories of personal data. For exhibitors, that can mean losing access to valuable event leads, damaging relationships with organisers, and facing reputational harm with procurement and legal teams at client companies. The cost of redesigning consent processes is modest compared with the disruption of an enforcement action focused on event data practices.