
Event Brew · 2023-06-15 · 46 min
Key moments - from our scoring
Substance score
42 / 100
Five dimensions, 20 points each
The episode examines the Mobile World Congress facial recognition fine through the lens of event industry practices and data privacy obligations. Nick Borelli breaks down the GDPR violation - specifically the lack of a Data Protection Impact Assessment before deploying facial recognition check-in - and notes the precedent it sets for both European and international events with EU attendees. The hosts debate the reality that most B2B event attendees tacitly accept data collection as part of the show experience (visible name badges, QR codes, badging systems), yet remain largely unaware of the actual vulnerabilities they create. Will Kerr suggests attending conferences like DEF CON or Black Hat to understand hacking and social engineering risks in event environments. The discussion covers how technology adoption (facial recognition, marketing automation, badge scanning) has outpaced industry policy-making, and questions whether events need third-party data audits, stricter vendor agreements, and exhibitor policies around lead generation and scanning. The hosts acknowledge that unlike virtual events, in-person events expose attendees to multiple layers of data collection and physical security risks, yet data insights remain valuable for event operations. The core tension: how can events collect meaningful attendee data while respecting privacy and complying with increasingly strict regulations like GDPR, CCPA, and emerging laws in Canada and Australia?
Mobile World Congress was fined €224,000 under GDPR for deploying facial recognition technology for check-in without conducting a required Data Protection Impact Assessment, which violated attendees' privacy rights and data protection regulations.
No - while GDPR enforcement is strongest in Europe, any international event with EU citizens attending faces potential liability, and PR backlash and data breach risks apply regardless of location; California, Canada, and Australia also have increasingly strict privacy laws.
Name badges displaying attendee names, companies, and locations enable social engineering attacks (like conning front desk agents to access hotel rooms) and allow one Google search to reveal additional personal information about attendees.
Organizers should conduct third-party data audits, include explicit data handling clauses in vendor and exhibitor agreements, restrict unauthorized scanning, and ensure QR codes and systems only transmit attendee IDs rather than personal information.
Yes - as facial recognition becomes cheaper and easier to deploy, exhibitors and other non-official parties will likely use it without authorization, shifting the data collection problem outside event producers' control and requiring stricter exhibitor policies and enforcement.
Our reviewer’s read on each dimension, with quotes from the episode.
There are occasional genuine observations buried in the episode - the CSV leak discovery trick, QR code data stripping risk, fake email canary technique - but roughly a third of the runtime is occupied by beverage banter, a Burger King anecdote, and WiFi hotspot tangents that contribute nothing actionable to a B2B operator.
The QR codes are usually super data rich too. Like you can if, unless they're really smart. And the QR code is one that is only information, uh, to an uh, attendee id. There's usually information baked into that that you could just take a camera and strip away from people, just any phone, any person.
We didn't fix that problem. We didn't sit back and go how can we be more ethical about the way we do this? We capitalized on it, we overused it, we abused it and then we got it taken away.
The observation that B2B attendees operate under a different social contract around data visibility (they already wear name badges with PII) is a mildly interesting reframe, and the cycle-of-abuse analogy connecting email marketing to facial recognition has some teeth, but the broader takeaways - be transparent, vet your vendors, get legal advice - are entirely standard issue.
the social contract of attending a B2B event is based around visibility
all these people that are like, oh, I hate being tracked and the government's always following me...but they're the same people that live on Google Maps because it gives them the fastest route to where they're going
The guests are genuine mid-level event industry practitioners - Nick has hands-on experience at a data/analytics event tech company and shares a credible canary email anecdote; Will produces event tech content - but none are C-suite operators who have deployed these systems at real scale, and the conversation stays at the practitioner level rather than producing hard-won strategic insight.
the company I work for, Zenith, is the kind of cure to this...we don't collect any personal information. We, uh, we don't record pictures, we don't record videos. Uh, instantly the camera is a lens that translates your face into numbers.
I worked for, uh, a trade show where we would insert an email address. Every fake, uh, email address, uh, with every one of the exhibitors, uh, and if anything was emailed, uh, to that.
The Mobile World Congress GDPR case is a real and named example with a rough fine figure, and the canary-email technique is concrete and verifiable; however, the fine amount is fumbled and approximate, the TechCrunch article is never cited properly, and most prescriptive recommendations ('ask tough questions,' 'third-party audit') remain unanchored to any specific process, vendor, or metric.
they're looking at what looks like a fine of uh, $200,000. 224American cover the four divided by. It's a quarter million dollars.
We had 50, you know, 50 email addresses, 50 exhibitors. Uh, you know, insert one of them into that list. Uh, if anything, you know, if they sold that list or moved that list wherever, we could say who it came from.
The host asks a couple of structurally useful questions - specifically the EU-versus-US jurisdiction split and whether attendee litigation is becoming a systemic risk - but almost every claim goes unchallenged, the conversation drifts repeatedly into unrelated banter, and there is no genuine pushback or productive disagreement across the episode.
How much of this is like an issue just for the fact that it's taking place in the EU which has like the strict like GDPR rules. Like do you think that this same ex potentially would happen in America with our lack of there for data privacy laws?
do you think that we're at risk that more and more events should be concerned about their attendees potentially taking legal action for potentially even a mistake they're not 100% aware even happened?
Computed from the transcript - who did the talking, and the words that came up most.
Navigating event attendee data requires the right balance between collecting valuable information and respecting event attendee privacy. But with rapid advancements in technology and law that struggles to keep up, finding that balance can be tricky, especially as tech becomes cheaper and easier to access. Catalyzed by a recent Tech Crunch headline about a General Data Protection Regulation (GDPR) violation at Mobile World Congress (MWC), Will, Nick, and Dustin tackle attendee data in today’s episode. But before diving into this pressing issue, Nick provides some background information on MWC’s fine.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to the Eventbrew, where event professionals from different backgrounds talk about the latest, most controversial and interesting topics dominating the minds of the industry right now. This is a candid conversation the likes of which can only otherwise be found late at night in host hotel lobby bars during industry conferences. So relax and drop in on what Event pros really say when no one else is around. This show is brought to you by Endless Events, the event management company that tells you how it really is. Now let's brew something up.
Speaker B: Hello, hello, hello. Welcome back to Eventbrew. Is this thing ever going to end?
Speaker C: That's the outro.
Speaker D: Music never ends.
Speaker B: Why don't you point at me if you didn't need me to talk?
Speaker D: All right, because I want you to talk over the intro music that for
Speaker C: that sound like a dj.
Speaker D: I mean.
Speaker B: Oh my God.
Speaker D: I mean you can extend the. Hello everybody.
Speaker B: God. Think like a DJ with you some days.
Speaker D: Yeah, think like a dj.
Speaker B: Listen, I have spent my entire life ensuring that I never think about. So we're not uh, like you only
Speaker D: play Spotify on like completely random. You don't ever pick like a playlist or anything?
Speaker B: Never. I won't even go that far.
Speaker D: I think Dustin, official title anti dj,
Speaker B: that's my preference is dead silence.
Speaker C: Always.
Speaker B: Yeah.
Speaker C: Music problem.
Speaker B: Welcome back to Eventbre. That was a hot mess of an intro. But in true Eventer style, um, we like to make it as difficult as possible to bring this to you. I'm joined by two of my favorite people on the planet. Will Ker and Nick Borelli. How the hell are you boys?
Speaker D: Amazing.
Speaker C: Uh, hydrated.
Speaker B: Hydrated. That is great. I think you're setting me up for, for uh, a great segue to say. What, uh, what are you gentlemen drinking today?
Speaker D: Oh, what's got you hydrated, Nick?
Speaker C: Just water, man. Uh, I'm like, I've only. This is, uh, three weeks. I've only drank straight up water, nothing, but.
Speaker D: Oh, you haven't drink any liquids other than water?
Speaker C: No, I take that back. Uh, I have one coffee a day. I always have. I guess I just take that as a gift.
Speaker D: Yeah. Okay, cool.
Speaker C: Uh, yeah, and then after that I had just, uh, three weeks of water.
Speaker D: I just like to bookmark today as May 9, 2023. Doesn't really matter what day this gets released or anything, but today Nick announced that he is three weeks sober on water.
Speaker C: Yeah, I don't know what that.
Speaker D: None of. Not he, uh. You gotta pay attention to the last episode. Okay, that was a terrible idea.
Speaker B: Okay, we got it. Yeah, we don't need an excellent whatever.
Speaker D: If you're a true listener of the podcast, you know what I'm talking about.
Speaker B: And if you're not, you've already left.
Speaker C: Ah, I'm in the wrong place. This is supposed to be do something with events, and yet this is going to be 15 minutes of talking about water.
Speaker B: Well, what kind of organic tea are you drinking today?
Speaker D: I'm just drinking my normal Javid Rio chai from San Francisco with some oatly oat milk. So a little chai latte in my little ember mug. It is very delicious.
Speaker B: How's the oat milk industry doing?
Speaker D: Um, well, my stock in oatly went. Didn't go too well when I bought. Like I told you guys a couple years ago I bought it. It, like, went. It just continues to go down the slope. Um, but it seems that, uh, oat milk is more popular than ever, so I don't understand how stocks work at all, apparently.
Speaker B: Well, maybe don't buy stock in milk.
Speaker C: Yeah, that's true. It's, uh, it's really a weird choice. But, hey, you're like, you're really into tech. If you love tech.
Speaker B: It's a very, well, current choice to make though, I think. Yeah.
Speaker D: Uh, for the record, we're doing a series right now on, uh, event tech podcast of tech that you don't think is tech. And it's like we talked about shoes for a whole episode. So I guess oat milk is tech that you don't consider tech.
Speaker B: I think you may be right. You might be onto something. Well, I think you should research that a bit further and see if you can confirm that. Well, I'm here. Uh, my name's Dustin, by the way, and I'm from the beautiful, beautiful Calgary, Alberta, on Trudy 7 land in Alberta, Canada, where it is finally feeling a bit like spring. Um, I'm drinking a nice cold diet Pepsi, which I have now decided that I am an absolute addict and I need to seek help to get off of this. I don't know when it started. I don't know why it started, but it's the drink of choice now.
Speaker D: So we'll start by. We'll make fun of you on this show for about three years.
Speaker C: Yeah.
Speaker D: And then we'll get you to three weeks of no Diet Coke.
Speaker B: Sure.
Speaker C: Yeah.
Speaker B: Has that worked for any of us yet?
Speaker D: Yeah, worked for Nick.
Speaker C: We made fun of him, like, every
Speaker D: episode for, like, three years.
Speaker C: It's a long journey.
Speaker B: Yeah. I have a feeling that Nick's change had nothing to do with us.
Speaker C: Oh, no, no. It was very much the pressure of this show. That makes me do a lot of things. No, I take it as a given. I'm being made fun of here.
Speaker B: Uh, so, yeah, that's why we come here. Right?
Speaker C: Yeah, I would imagine we need something
Speaker D: to make fun of Dustin for anyways. Because he dishes it out.
Speaker B: You make fun of the beer I drink. So you've really been making fun of what I've been drinking.
Speaker D: I got you away from the crappy beer, now I gotta get you off Diet Coke.
Speaker B: No, I still drink the crappy beer. I just don't tell you about it. Well, that's great.
Speaker D: Like me and my oat milk.
Speaker B: Just like you and your oat. Just things that you should keep to yourself. That's your problem, Will, is that you just. You walk into it every single time. It's true. Yeah. Great. Okay, gentlemen, um, today we're talking about that fine line or that thick line, that line we walk between attendee data and privacy, um, which I think is like, definitely like on people's minds lately. And um, there's some things that have popped up lately that I think are worth paying attention to. And um, yeah, I think let's crack this open and talk about attendee data and what we're doing with it, what we should be doing with it, what we shouldn't be doing with it. And um, yeah. Who wants to kick it off? I think We've got a TechCrunch article that we want to use as a bit of a kickoff here.
Speaker D: Yeah. Nick, can you tell explain what happened with Mobile World Congress?
Speaker C: Yeah. Uh, so Mobile Congress is a pretty influential consumer, uh, electronics show that takes place in Barcelona, Spain. Um, there is a, uh, an appeal, um, that is against the show from their 2021, uh, iteration, uh, that says that it has violated, uh, gdpr, which is the General Data Protection Regulation, uh, that covers Europe, uh, that um, they didn't meet the Data Protection Impact Assessment and therefore, um, show attendees had their
Speaker B: personal, uh,
Speaker C: identifiable, uh, information, um, violated based on their facial recognition check in, uh, uh, technology that they deployed, I believe a new technology at the newer company, uh, at that show. Uh, now the upshot of this uh, was, uh, technically it gives them some data collection for sure, uh, less so, uh, about insights and more so on, uh, ease of use. So the idea is this, uh, the check in process is something that the event tech has been probably from the very beginning of the origins of event tech, uh, trying to figure out ways to streamline and if you've opened your phone lately. Uh, the process of using um, your face as a key is pretty ambiguous. It's something that's built into all the iPhones, uh, and it's a technology that's out there. Uh, so I believe the deployment of this was uh, for expediency. You know, you, you register ahead of time, you use your face, um, and uh, that's uh, all you need to get in the door. Um, the problem is, is that that creates a database uh, of uh, personal identified information and that database has uh, you know, potential uh, volatility. Uh, uh, and it's uh, you know, another level beyond other data, uh, collection that uh, could be cross referenced with other banks, um, of information and then you're off to the races as far as a bad actor taking advantage of it. So uh, it's one of those things where um, the most aggressive uh, privacy protection in the world is in Europe in and uh, they're the most likely to have an issue with this. Uh, I mean second place might go to Canada, uh, uh, California and Australia are all kind of vying for that. But in the EU that's a big deal. So uh, I think Mobile World Congress as it is a place where people learn about new technologies, I uh, think they moved quickly, uh, and they used a company that might not have been um, mature enough to know that there's opportunities for data assessment uh, that you can uh, use. Uh and there's also lots of uh, legalities to consider. Um, I think they went for both novelty and I think they wanted to be uh, kind of like first to deploy. And with that comes risk. And they're looking at what looks like a fine of uh, $200,000. 224American cover the four divided by. It's a quarter million dollars. Uh, so you know, you don't want to do that, um, if you can help it. Uh, yes. I mean I don't know like what they've done different.
Speaker D: A couple deep questions.
Speaker C: Sure.
Speaker D: Um, uh, let's maybe go to the first more high level one. How much of this is like an issue just for the fact that it's taking place in the EU which has like the strict like GDPR rules. Like do you think that this same ex potentially would happen in America with our lack of there for data privacy laws?
Speaker C: Except for in California, I mean certainly California, there's more uh, risk for this. I uh, think that if you're having EU citizens at your event, there's uh, an opportunity.
Speaker D: Yeah, that's the thing. Yeah, yeah, that's true.
Speaker C: So international events, I mean, you know, in the world where we live in, that's you know, I mean, could happen any day for anything. Um, and then there's just ah, uh, let's call it PR blowback that could happen anywhere where uh, this is something where there's an increased amount of ah, data collection that's taking place. Uh, and then there's the worst case scenario of uh, this facilitating a bad actor's ability to um, do something malicious with this data. So then you're in a completely different place of uh, vulnerability. So yeah, I mean while this one to one thing might not necessarily be the uh, the given outcome in the United States, it's very easy for lots of other things to be triggered, uh, in addition to that.
Speaker B: And it sets precedents, right, where it's like, it also, it also sends a message to, in our case, it sends a message to attendees and says, and say when you're not happy about, you know, things like this and the way your data is collected that you should go to court. And that's, that's really, that's really dangerous for us. And I think, and I think the point about this is like, you know, there's sometimes this rush to get to market with things is a lot of what the problem is. And you know, I, I'm probably the more free with my data. I think less about it and I worry less about it. And I'm not of the mindset where it's like, oh, if you don't do anything wrong in life, you have nothing to worry about. I think that, you know, people accessing your data can be really, really dangerous. And I also look at it as, you know, there's, you know, in this case, there is a problem that needs to be solved and we want that experience to be better. We want it to be better as producers and we want it to be better as consumers. And there's like, these are the things that are going to make that better. And we have to find a way to do this in a way that is number one lawful. And we have to find a way to do it in a way that respects people's privacy. And you know, it's, it's, you know, I wonder how many people have really thought about where the facial recognition for their phone goes. Like, I wonder if anybody's really thought about where's that store? Does anybody actually know? So I think it's funny that, you know, we can harp on, we can harp on certain things and say, well, I don't want that. And it's like. But you do accept that all the time and you don't fully understand where it goes. And I'm not saying that, you know that your data with Apple is not safe. I'm just saying that like, we don't fully understand how these things work. And there's, there's. As the event industry continues to move forward and advance in tech, I think we're gonna see a lot of this, we're gonna see a lot of this sort of pushback. And I also think a lot of attendees don't really care as much. I think that it's uh, if you really, if you really care about this, you really, really care about this and if you don't, you don't.
Speaker C: I'm gonna put something out there that is, uh, maybe controversial, uh, and maybe doesn't do me any favors but, but I believe it to be true. Uh, the B2B attendee, uh, has, uh. The only outliers have a real strong feeling about where their information goes, uh, when attending an event and the vast majority don't. And the reason for it is the social contract of attending a B2B event is based around visibility. It's about, I mean like. And I do this example a lot. So I'm in, I'm in right now. An analogous conversations to this, but not the same. In fact, like, full disclosure, like what the company I work for, Zenith, is the kind of cure to this and not like the same thing. And some people conflate them. So I immediately have to be like, we're not facial recognition. We don't collect any personal information. We, uh, we don't record pictures, we don't record videos. Uh, instantly the camera is a lens that translates your face into numbers. So right off the bat, like, I don't do facial recognition. Um, that said, the case for increased data collection at specifically and I'm making The case for B2B events is that no one even bats an eye about the idea that you put your name and where you live and hanging around your neck. Now would you do that at the mall?
Speaker B: Yeah, yeah.
Speaker C: Like if you went to the mall. No. You'd be like, ew, that's weird.
Speaker B: Granted, like, uh, maybe I take my badge off the second I even see the door for the exit. Oh, I do. Because I do too.
Speaker C: Because I feel like, well, for me,
Speaker B: I take the badge off Vegas with my name on my.
Speaker D: I take the badge off because I don't want to look like a tourist and you know, no, I don't want
Speaker C: to be look like somebody who, you know, it gives you a lot of information about you, right? Like, hey, I'm from, you know, it gives people an opportunity to, to network with me. Uh, and I'm doing limited networking with homeless people these days.
Speaker B: Uh, so, uh, but really break that down from like a, uh, you know. And I know it's funny and most of us don't wear our badges around. So you're wearing your badge that has your name on it where you live, in the hotel that you're staying. You are opening yourself up to problems. You are opening yourself up to, you know, somebody conning a front desk agent to get into your room. There's like, they've got enough information about you, somebody that's really sleeping like it is. It's very true. It's not.
Speaker C: They know what industry in the show you're in, what company you work for, where you live, and that's that.
Speaker B: Now get this one Google search to find out more about you. So I think it is, it's very easy to say.
Speaker C: And the QR codes are usually super data rich too. Like you can if, unless they're really smart. And the QR code is one that is only information, uh, to an uh, attendee id. There's usually information baked into that that you could just take a camera and strip away from people, just any phone, any person. Uh, so that's an issue too.
Speaker D: I was going to suggest something, this is just a radical idea that I think that I had that might be helpful for a lot of people. We always talk about what conferences should you attend that teach you about an area that you're not 100% as an event professional. It's something kind of adjacent, but not necessarily, um, so this week there was ah, a ton of news about uh, how the White House, or I think it was today, the White House is basically paying to have people try to hack Google and ChatGPT and all these things like that to prove what are the vulnerabilities. Um, and it was funny, one of my, my, my buddies who's really AI is like, I'm definitely going to go. It's called defcon. And I think like Black Hats, uh, Black Hat and White Hat are uh, similar conferences too. But he was like, yeah, I'm gonna go defcon. And I was like, dude, don't go with your phone, don't go with your laptop like that. People there, literally just for fun, just go hack stuff. I don't think a lot of ways it's extremely malicious but like it could get. And I Think that's potentially an event that if I talked about an event that's completely outside the events industry ironically, um, go to that DEF CON conference and like I think like this stuff that we're talking about like, like the idea that like the social engineering stuff that Dustin's talking about, the fact that like hey, how does facial recognition databases get hacked? Like all this stuff could be in there. So that's just a random tidbit idea that I had around that topic. But these, that's area they're talking so much about this. And like in the events industry I put you know, private data privacy agreements with all my contracts and now it's like I'm in 5 to 20 hour long legal conversation with lawyers now for every agreement I do because like we need to make sure that we're protected in all the right ways. But it's funny how like as soon as like virtual events kind of disappeared, no one cares about the data privacy agreements anymore. It's like literally like they just disappeared. Like. But this stuff is still 100% relevant.
Speaker B: Mhm.
Speaker C: Yeah.
Speaker B: I mean more so and in a lot of ways even more so because you're, when you're in person you're exposing all of that data and then more and then there's actually more access to you. You may be actually safer in a virtual event than when you start adding in all these other layers that come to being in person. Yeah.
Speaker C: The flip side is that the data is valuable, you know and like I
Speaker B: don't want to so valuable.
Speaker C: Yeah, like I don't want to have like anyone listening to this coming away with okay. Like I need to you know, go back to uh, an antiquated Luddite way of, of doing events.
Speaker D: We need to print our agendas out again.
Speaker C: Yeah. You know, but like being aware of this and you know, maybe even working with you know a third party to be able to audit your, your event might is definitely the ticket but like without the insights that you could gather from data, uh then you're really in the stone age of where things are going. So it's a tricky tightrope and I guess that's mostly what we're talking about today is that uh, ah, either it's illegal um eyes that you need to have on your event. I mean I would say it's on either it's for sure that and then also uh, uh some sort of third party audit. Uh, unless um, you have someone in your team who is just like an expert. But I would imagine the scale of most organizations don't have that.
Speaker B: Mhm. I think it'll be interesting once we get into. So we're, you know, we're talking about this in the lens of a producer making decisions about how they're going to collect data and facial recognition. What happens once this starts moving into like you know, the, you know the B2B when the, the guy in the trade show brings some sketchy ass technology that's tracking and doing facial recognition that's outside of your, you know, outside of what you're doing. So it's eventually it's going to be eventually especially facial recognition, it's going to become so cheap, so easy to access that it's going to be deployed by other people other than the show producers. And then we have the challenge of figuring out how do we regulate that, what are the rules around that? Or will we allow it, will we not allow it? What's our liability when somebody within our show is doing it? Wait till facial recognition becomes a button on somebody's shirt that's just, that's, that's picking up information and tracking. So uh, we're at the, we're at the beginning.
Speaker C: Yeah.
Speaker D: AR glasses. You know what it reminds me of is like the mobile hotspot like issues that we've run into with like trade shows that like no one wants to pay for the hotel WI fi so that everyone brings a hotspot. So then therefore the costs of the, or the speeds of the tower go down and congested with tons of different WI FI networks and creates all these issues. It's like it's a thing like, I
Speaker C: mean and similar to that, like I'll
Speaker B: stop, I'll stop bringing my mobile hotspot when wireless connections.
Speaker D: Yeah.
Speaker B: 100 fucking dollars. Okay.
Speaker D: Yeah, yeah, yeah. I think uh, we're all in the camp of like down with Monopoly Internet inside of 100%.
Speaker C: Yeah. But the other problem with the hotspot,
Speaker B: I just deploy it to piss people off. I don't even have anybody on it. I just have it. So the venue sees that I have it.
Speaker C: Yeah, I mean I'm just gonna get
Speaker D: you a WI FI jammer instead at defcon Justin. So you could just jam the WI fi.
Speaker C: So I can't even imagine how many, you know, uh, people are spoofing and whatever there. But like the amount of uh, you know, opportunities when that happens for people to uh, put similar named WI fi, uh, you know, into spaces.
Speaker B: So easy.
Speaker C: Yeah. Super easy. And it's like I could do it
Speaker B: and I don't know, wait real quick
Speaker D: circling Back to the topic of the accessibility of like once this technology becomes everywhere. You know what this reminds me of is like when marketing automation tools started hitting their popularity and everybody was like oh, I'm going to ask for a CSV export of the entire attendee list. And then you got marketed to just like drip campaigns like crazy. Um, and then like the person who when like badge scanning became popular would just like go around chat for just scan, scan, scan, scan, scan, scan, scan and like no permission scan people. It reminds me a little bit of the second one less but like reminds me a little bit of that like when people technology evolved, how do us as organizers then design our policies to have that source system? And I think it's a great topic because we need to be start putting this in our like our vendor, our uh, exhibitor agreements. You can't just scan people. You can't bring a uh, lead gen system. Maybe that's outside of our lead gen system. I mean I don't, I don't know.
Speaker B: It's going to be interesting. And I m mean we didn't solve that problem. I think that like the government's decided how we were going to use attendee data. It wasn't something that the industry was like hey, let's get together and find a responsible way to use this data.
Speaker C: It didn't come from us.
Speaker B: It's going to make sure we make less money and has less contact with our attendees. It did not come from us. And so that same thing is going to happen with all these new technologies is they're going to be deployed fast and furious. There's going to be a race to the bottom when it comes to their efficiency and their price. And then eventually the laws and the rules are going to catch up and there's going to be carnage in the middle. It's the exact same thing.
Speaker C: Exact same thing.
Speaker B: We didn't fix that problem. We didn't sit back and go how can we be more ethical about the way we do this? We capitalized on it, we overused it, we abused it and then we got it taken away.
Speaker C: Yep. Yeah. And that's the case.
Speaker B: Nobody gets to play with the email addresses anymore.
Speaker C: And to be fair, there's lots of
Speaker B: shady people that still do I, yeah. Do any of you use like unique email addresses when you sign up for things?
Speaker D: Uh, I've done like the plus thing and then I auto block it out but now I basically have like a throwaway email.
Speaker B: I think now when I, when I know, when I'm a bit suspicious about Something or something I'm attending. I'll use, I'll use a.
Speaker D: Do you use Apple's like hide my email thing?
Speaker B: Yeah.
Speaker D: Where like, it, like there's a couple of these, like fast emails, burner email side things. It makes a fake email account that just go straight to your email. And then if you don't like the email coming in, you can just like destroy the email forwarding system basically.
Speaker B: And you know where it came from.
Speaker D: Yeah. And you know where it came from? Yeah, yeah.
Speaker B: You know who sold your data or
Speaker C: I think which, by the way, I used to do that in the trade shows.
Speaker D: Yeah, you put a plus at the end of your name.
Speaker C: Uh, yeah, no, no. Uh, I worked for, uh, a trade show where we would insert an email address. Every fake, uh, email address, uh, with every one of the exhibitors, uh, and if anything was emailed, uh, to that. So we give you, here's your lead list. If anything.
Speaker B: That's how you monitor. That's how you monitor the exhibitors. That's good.
Speaker D: Like that's, that's smart. I feel like that super low tech. That could be like a company for sure. It's like a, like, yeah, like accountability. Exhibitor accountability, corporate.
Speaker B: It's a secret. It's a secret shopper. Right. Like that's, that's what it should be.
Speaker C: We had 50, you know, 50 email addresses, 50 exhibitors. Uh, you know, insert one of them into that list. Uh, if anything, you know, if they sold that list or moved that list wherever, we could say who it came from. Uh, you know, it was in the wedding industry too. So it was like, you know, small
Speaker B: businesses fast and loose with the rules over there.
Speaker C: Fast. Yeah. Don't know the rules. Unaware of the rules. Uh, willfully.
Speaker B: That's great. I love that.
Speaker D: I got another crazy story. I don't think I've ever shared it on this podcast before. We've talked about like, I think on some other podcasts. But, uh, Thorbin from, uh, EventMobi told a story once, I think it was on like event icons or something like that, that he was like, what, what happens is people accidentally publish the entire attendee list CSV onto like, you know, whatever it is. And apparently if you just go on Google and you search like attendee list dot and then say file type, colon CSV.
Speaker C: Oh, no, it literally will pull up
Speaker D: Google results of just huge conferences that have accidentally like leaked their.
Speaker C: That that stuff somewhere indexed like on a WordPress page or you know, you know.
Speaker D: Yeah, yeah, because someone decided to upload it. It was like, oh, this is the easiest way to share this with exhibitors. Let's like not put it in a Google Drive or something like that.
Speaker B: It's a great, it's a great point though. Like when you think about, you know, we're talking about basic registration information, which is dangerous and shouldn't be, shouldn't be out in the world. But when you think about a lot of the producers, like people we know that produce events, like they don't have complex IT systems, they don't have like, uh, and it's, and that's just, that's the nature of the business. I don't have a complex IT system. Like I don't, I use something. I'm not going to say it now because we're talking about how people get hacked but like I don't, I don't have an overly complex system and you know there's, there's probably vulnerable information within, within mine. We try and be very, very careful especially with like exporting lists and we try not to export them if we ever, ever don't have to. But, but when you think about who are the people that are actually handling this data, like they're not in these big multi billion dollar organizations that have a corporate security division that's watching over their it. They're, and they're, they're smaller businesses that are using, you know, Google business apps or you know, they're stored on their whatever cloud that, so it's, it's. I can, I can see how we should be concerned about how the data is being stored and who has it by nature of the companies that are actually holding onto it. Um, I would think that the tech companies that are supporting people like us in registration and whatever, like they should have their shit together and maybe we should be asking more questions of them as to how the data's stored, where is it backed up, is it ever exported? Like how safe is my data? Um, definitely we should be asking more of those questions and we probably should look for, look within a little bit too to say, do you really need to keep this data in your Google Drive? Is it important that it's there?
Speaker D: I think we're probably going to see a uh, decline now that we're getting away from virtual events being the primary factor of events. I think we're going to see a decline. Companies giving a shit about security and privacy. I think for a little while. Like, like I said, like people are always asking me FOR uh, the DPAs, the data protection addendums, um, to contracts like now I don't ever get asked for one. I feel like that's going to happen.
Speaker B: But it's now it's less, it's less like even this conversation is less about an organization in their data and more about an attendee in their data. Because this, like how we started this with the TechCrunch is about an attendee. Am I correct, Nick?
Speaker D: Yeah, yeah.
Speaker B: Attendee is the one that started this. So that is, that's more of my, like, that's more of my concern. I think that the, you know, do you think there's more risk, privacy rights between you and an organization that gets dealt out in contracting and legal. And my legal and their legal. We figure that out. But when it comes down to how does an attendee feel about the way their data is being captured and used, that's the stuff that we're going to have to face. Um, and figure. And figure that out.
Speaker D: So to bring it back to that topic then, uh, specifically the article is like, do you think that we're at risk that more and more events should be concerned about their attendees potentially taking legal action for potentially even a mistake they're not 100% aware even happened? So like, you know, one of my other big questions I was asked was how much of this was the fact that it was the vendor's fault, One vendor who made a big mistake versus like a, a larger trend of just someone's not happy with facial facial recognition or whatever. Um, or is it that, you know, everything was. Ducks were lined up and then this person found like one single vulnerability with it. But like, how much do we have to be worried that like this is now going to be the new equivalent of tripping on the crack at the venue?
Speaker B: Mhm. Well, I think if you're, if you're putting a program together, whatever that is, trade show, conference event, whatever in your role, if you're putting something together and you know you're using tools that are new, you know you're using tools that are not commonly seen, then you better do your due diligence to figure out how do you ensure that you're deploying that safely. And I think this is where transparency is the most important. This is where telling your attendees what they will expect and not when they uh, walk past it, not when they
Speaker D: see the sign for strobes and lasers are gonna be present at this event.
Speaker B: Yeah. Prior to their arrival, like they should know that this is a part of it. You have the right, I think as a, as a show producer, you know, an organization that's putting on to decide how you want to capture data. And every attendee should have the right to say I don't want to be a part of that. If they don't want to be a part of that, then that's okay.
Speaker C: Well, so here's the thing with this event. Uh, they, they decided or uh, they got them on GDPR is pretty, pretty far. So in North America maybe, but us for sure. If you tell somebody if you don't like something, you don't have to come. That generally works. But in Europe this was not the case. So they, they didn't have an alternative to attend this event. Which you're like, well what right is it your years to attend an event but in their laws you have to be able to collect data. That doesn't exclude anyone.
Speaker B: Yeah.
Speaker C: So they had no other way to attend this event other than giving up their biometric, uh, information. Uh, that's a violation of gdpr. So that's an interesting element of it
Speaker B: that the, and I can, I can see that Nick. Like I, I, I take, I, it's valid, I think it's, I think it is valid as. And that this, you should have that in the person choice. This is coming from the person that doesn't care. Right?
Speaker C: Yeah, I would scan my face, take it. Yeah, I, I take, I use Instagram.
Speaker B: And I think, and I think that you should have, especially when we're talking about biometrics, I think you should have a non biometric option. You should have a way to enter the event without which by the way
Speaker C: if they would have done.
Speaker D: But, but, but, but that's, that's, this is hard though because let's say you've invested to put cameras everywhere. Right. Like, so this is where like Nick knows the technology way better than me obviously. Is that like you, obviously you can't just like make the camera turn itself off. Oh hey, Will's walking up like turn the camera off automatically turn it back on wheels here. You know, but you know the, the question is like that's where you almost need technology is that it depends how you're deploying. Right. Like I just thinking like it's so hard if it's kind of like having like the RFIDs, it's if you made it where literally it's going to scan RFID every time someone walks through a door. If it's scanning like go in another door.
Speaker C: Yeah, it would be that. So it depends on the use case. In this instance it was used for registration. So as far as I can see. And again this is Not a use case that we do because we don't do facial recognition. Uh, as much as, uh, Uh, I guess as much as I understand this, all they would have to do would have been to create another line similar to like tsa, where you can say, I opt out. I go through this. Uh, so if you, if you're like Dustin and myself, you're like, scan my face, you know, take two pictures.
Speaker D: Uh, yeah, there's the pre check line.
Speaker C: And if you take me shave three minutes of my life, I'll give you, you know, my Social Security number. So, um, please take my.
Speaker B: Take my temperature at the same time,
Speaker D: I will take your. I will shave three minutes of your life. I'll end this podcast three minutes so I can get your Social Security number. Nick.
Speaker C: Yes, it's fine. I mean, first off, I'm fairly certain, actually, that you do have it, uh, based on paperwork I filled out for you.
Speaker B: This is also very true. Yeah, I didn't fill out that paperwork. Nick, come on. Now.
Speaker C: See, I'm worse than you.
Speaker D: If you freely give it to me, then I can use it for nefarious reasons. But if I'm an employer and I take your Social Security number off our employee data space and then do it.
Speaker C: I respect other people.
Speaker D: I probably get it.
Speaker C: I respect other people's privacy much more than I respect my own.
Speaker B: I, uh, couldn't agree with you more there.
Speaker C: I'm so cynical on data collection in the same way as I'm cynical about food prep. So, like, in working in fnb, I've seen everything, and I'm like, I. Either I'm never going to eat or I'm just gonna go, I don't care.
Speaker B: I'm the same way.
Speaker C: Yeah.
Speaker D: I'm so ignorantly blissful that I don't want to.
Speaker C: I've spent so much time learning about social media and, like, I just assume I'm, you know, I have no privacy. It's fine.
Speaker B: Yeah. Don't tell me you haven't had a suspiciously old sandwich in a crew room at some point in your life and you live to tell about it.
Speaker D: I've once. Yeah, there's. Everyone's had that sandwich where you bite into it and you're like, this bread's a little hard and the meat's a little weird.
Speaker B: I don't care. I'm eating it.
Speaker C: The Burger King, where I used to, uh, where I used to live in Ohio, the Burger King, that was, like, right by my house. Uh, it went Viral, uh, in 2012, uh, because, uh, there was, uh, a Guy who took photos that was working there of his feet in the uh, lettuce bin. So he had like one lettuce bin in each shoe. And you can like Google it if you're like lettuce feet, Burger King, you'll find the photos. And like, I saw that and I was like, oh, that's crazy. Anyways, and I continue to eat there for a decade.
Speaker B: Great. And we're probably gonna get sued by Burger King now, I'm sure.
Speaker C: Well, I mean that's very much out there.
Speaker D: So it's like the opposite of sponsorship. You get sued by somebody, they take money away from you for brand mentions.
Speaker C: But all that's all that said is it depends on the deployment. I mean, I think that the biggest part of like this deployment was like risk reward, right? So like, you know, if they would have like, look, first off, if they would have given people an option, I think they would have uh, got out of this. So like, that's something that a good tech provider should be able to tell you is like, hey, you know, like legally we can absolutely deploy our technology, but there's limits, right? So like a big part of like what we do at Zenith is like saying like, we don't collect all that. We could give you, quote unquote, more data, uh, but we choose not to because we, we are, we're prioritizing the, the safety of uh, the attendees information over all the stuff we could grab from you with, with you know, the tweaks of the technology. Uh, and, and this company could have said like, we could make this process faster for the 99% of people who don't care in B2B events to go, you know, right through and, and offer an opportunity for the 1 per, you know, percent of people who do that. That's the right thing to do. Um, and that's the good supplier thing to do is to say like, yeah, um, we're going to give you an option. We're not perfect, it's not a cure all. But we, you know, we're a 99% solution. We're an 85% solution. I mean even some of the data sets that we give to people, they're not 100% accurate.
Speaker B: Of course.
Speaker C: Uh, yes. And we, we, we tell people that up front, like we're up against, you know, zero. So like 85 is a big jump. But like the, you know, like, you have to be open to people and say that in this organization with Mobile World Congress, I don't know the ins and the outs of it, but I assume they didn't say there's a way for you to, you know, pretty much, you know, do make this faster for the majority, but they wanted to be, you know, everything.
Speaker B: And what that makes me think, Nick, is that I believe that the onus is on the tech totally to be the expert in this. And I think far too often we ask your, your average hard working event. Prof. To know too much about everything. And I think this is, this, this is a world where we should be relying on tech to be, be giving us the right advice and deploying products that are legal in the space that we're working and are ethical and that we fully understand what we can turn up and turn down and understand, you know, ultimately understand the risks of what that looks like. And I think that this is like, you know, I think the, the whole tech industry should just start a fund, a uh, fucked up fund where they all can, they can all just like go play and take all the risks they want and they can bail themselves out because that, that ultimately is, you know, in this. And as much as it's shitty for this organization to have this quarter million dollar mistake, it's like somebody had to make it and now it's been done, now we can figure out the road forward. And I mean it sucks for them, but that may be the only way that we start to figure our way through this and start to push the boundaries. Because data is always going to be about pushing a boundary. It's always going to be about finding that line and walking it as close as we can. And I think there's, it's, this is, this is just the way it is. And I think, you know, I like, I use this analogy all the time where it's like all these people that are like, oh, I hate being tracked and the government's always following me and they're following me on my phone and this and that, but they're the same people that live on Google Maps because it gives them the fastest route to where they're going, shows them where the construction is. Like, how the fuck do you think that happens? Like, do you think Google's just got a person on every street corner? Like that is the benefit of allowing your data to be put in there. And I think that in our world we can make better events, we can make better experiences for attendees, for everybody that's there. And it's going to take some data and it's going to take some trust from the attendee, from the consumer to allow us to do that. And we then have to trust the tech companies to make sure they're leading us down a path that is ethical and legal. And when shit hits the fan, they should be the ones standing in front of it.
Speaker C: Yeah, I mean, uh, I am m with you on the good partner part of it being like the crux of it. Uh, I really don't think that it's, um, valid or, uh, the right thing for me to say that. Event planners need to become experts in, you know, privacy law as well as, you know, experts in the other hundred things they have to be experts in. Uh, and, uh, I think about it in the same way I would from, like, like, say production, uh, like so, like, will, like, you know, if someone said to you, I need this M. I don't know, uh, this, this piece hung from the ceiling and it has to spin in like, you know, 30 miles an hour, you know, to have our logo on it right above where
Speaker D: the speakers are, the rigging and all the safety compliance.
Speaker C: And if, if it wasn't. And. Yeah, and if it wasn't safe. Yeah. You wouldn't say, look, I was just doing what I was asked to do. Right. Like you.
Speaker B: Would you imagine?
Speaker C: Yeah. Could you imagine that? Right, like, uh, oh, this tent, you know, like it's on. You know, I think that still happens for the wreck.
Speaker D: That's for the record. It still does happen, but it's completely false.
Speaker C: It's a low barrier.
Speaker B: But I think, But I think it's a. I think it's. I think it's an excellent example when you're working with a reputable production team. They're not going to. And it's not about not letting you. They're just not going to. They're not going to put themselves at risk. Their team at risk.
Speaker C: They'd walk out.
Speaker B: At risk. They'd walk out. They'd just be like, I'm not doing it.
Speaker C: And tech needs to walk out too.
Speaker B: That's. And yes, they're like, there are certain parts and I think it's maybe more geographical. There's certain locations that aren't as stringent on safety as we are here in North America and much of Europe. So take all of, take all of that aside, like, you would never in a million years find a, uh, production. A reputable production company in Canada flying truss over somebody's head that isn't done properly. And if you said, hey, I just, you know, all those chain falls are driving me crazy. Cut them in half, they'd be like, go fly a fucking kite. Like there's no.
Speaker C: Yeah, yeah, I'm not doing it.
Speaker B: I don't really care. And I think, and I think that's the kind of attitude we need towards this is when we're asked, you know, when tech companies are asked to do something that crosses the line, they say no.
Speaker C: Yeah. And it's their job to inform you, you know, uh, for alternatives that you know, get you, get you 85% of the way there, you know, and, and, and find that acceptable. Right. Like, and so like I'm, I'm frequently in these conversations where people are like asking if we could do a certain thing and we're just like, uh, like unfortunately no, because if we do, if anything was like this, it would be a personal identifiable, uh, information that we're gathering. So it's just not possible. Like, it's just not something we do. Uh, and tech generally is trying to be like, oh well, whatever, we can just sort of change the scope or ah, be a product that just delivers on whatever anyone wants. Um, we have to. I mean, I think that that's probably the scary part is that the planners are generally with whether they know it or not, reliant on all of the, like, reliant on a caterer to say, yeah, we can't serve that in the summer. Like, we can't, you know, we can't uh, you know, have this out there and if it rains, we can't like all these things, uh, that are just yes and no things. And you know, we, I think, I think it's taken for granted when it comes to tech and data. It's the same idea. Like planners are not food temp, uh, you know, like geniuses and they're not tated like they, they know to a limit, but after that they have a level of trust on the professionalism of who they hire.
Speaker B: Yeah, let's treat, let's treat data and tech like we treat personal safety. Let's make it just as important. And we don't, you know, we're not all experts in it, but we know when to ask the right question. We know when we need an expert at the table. We know when we need a consultant to come and support us on it. And we figured like, I think we figured that out really well. Like I think yes, of course there's exceptions to the rule, but when we're talking about, you know, the, the more reputable parts of our industry, which I think is a big part of our industry, we've figured that out. We have figured this out.
Speaker C: We know certifications when exactly like you know, ask for, ask Tough questions, uh, and see if they flinch. You know, like, the vetting process is one of the most important things a planner can do is to be able to, uh, you know, uh, they put the safety of their attendees, uh, the. The goals of their event, oftentimes third party, uh, their clients needs in the hands of other people that don't work for them directly. A big part of the job as you, you know, as, you know, Dustin, is to be able to have an external team of people that you trust
Speaker B: with your whole entire job.
Speaker C: It's the whole job. Right, so it's the whole job.
Speaker B: Yeah.
Speaker C: Yeah. Tech is just as liable to make mistakes to be, uh, you know, to potentially, you know, disrupt these things. It's not. It's not outside of that, like bad chicken can. Can make people go to the hospital. Uh, and bad tech with. When it comes to data can, you know, uh, create a huge problem for everyone.
Speaker B: Uh, so, yeah, yeah, I think. I think something that would be really helpful for our industry is some sort of certification that will tell us, uh,
Speaker C: there are data certifications.
Speaker B: Like, that is specific to. Like, is there data certifications in our world, in the companies that we would see or. Yeah, yeah.
Speaker D: I mean, that's where like, SOC2 comes in and everything like that too. Right?
Speaker B: Well, that's something that we need to, like, we need to, like, pump those tires and get.
Speaker C: There's data security world, like, exactly that. There's data security, which is broader than the events industry. Uh, and, uh, you know, and frankly, you want that broadness. You know, like, it's depending on how it's used you, uh, want it to be. I don't think an event one would be good.
Speaker D: Or we should probably wrap this one up.
Speaker B: Yeah, maybe we'll wrap. He could still be talking. So if we're talking over Nick, we're sorry you froze. But the good news is, Nick, you made it to the end of the podcast. So whatever's going on, whatever you've got going on on your wifi over there, uh, you need to clean it up for next week. Well, that was a great chat, Will. I always love talking tech and data. It's my favorite thing to talk about, um, especially with you, because you are my resident nerd.
Speaker D: I love being the resident nerd.
Speaker B: I know you do. I know you do. It's just me always curious to hear, um, from the folks that listen to this. Um, I think in this I'd love to hear. What are you coming across? Where's the appetite for data from your clients? And where are you most concerned what concerns you the most about this? Because I think that even after this conversation, I'm starting to like, think about some things that I want to do better, um, within my organization. And I think let's treat data like personal safety and um, give it the respect that it deserves. So you can always, always email us at eventbrew. Eventbrewellowndless.com Damn. I just about nailed it. Damn. Um, and yeah, any of the socials hit us up? We always love hitting hearing from you all. And when you fill our inbox, usually we like it when you send us nice notes and where you're not mad at us. So if we could do that, that would be great.
Speaker D: Yes, please, no mean notes.
Speaker B: We're very sensitive. I know you wouldn't believe it, but you know Will takes this stuff very seriously and he has to vet them all. So, um, thanks everybody for listening. Uh, we hope you're having a great week. Weekend, day, night, whenever you're listening to this and we will see you next time on a Vamper.
Speaker D: Bye.
Speaker A: Thanks again for listening to Eventbrew. Be sure to rate and review us on your favorite podcasting app. Also, be sure to head over to eventbrew.com and leave us a comment about this week's episode. Ask a follow up question or tell us what topics you want to hear covered. See you next time on Eventbrew.
Speaker B: Mhm. It.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.