UNIVERSAL EVENT LEAD CAPTUREREADS THE PRINT · WORKS OFFLINE

Blog

Scanning Badges at a German Trade Show Under GDPR: What Your Booth App Vendor Must Provide (2026)

Ali Varinlioglu11 min read

You can scan badges at a German show with a phone app. What you cannot do is treat the scan as permission for a marketing email sequence, and that is the mistake this page exists to prevent.

I build Tendro, so read the vendor section with that in mind; this is not legal advice and your DPO gets the last word. The page comes from a real review: a German buyer asked us this month what they needed from us before scanning badges at an October show with no organizer lead retrieval, and their security team put 99 controls in front of us before anyone installed anything.

Can you scan attendee badges at a German trade show with a phone app under GDPR?

Yes, with a lawful basis you have logged, a notice the attendee can see, and a vendor bound as a processor. The scan is easy. The paperwork decides.

For either device, four things have to be written down: the purpose, the lawful basis, the security measures and the data flow. A rented organizer scanner moves part of that onto the organizer's terms, which you did not write and usually have not read. A phone app moves it onto your own vendor contract, which you can read. The rest of this page is that contract, question by question. The scan exists to avoid retyping the printed badge fields at the booth; the processing chain below is the price of that, and with enrichment off your staff still collect the work email by hand. A tablet form with no OCR and no enrichment is the alternative, and the two complete workflows are worth comparing before you choose.

The German difference we have seen is sequence. The buyer's data protection officer asked for the documents before the show, not after, and some German association shows run no organizer lead retrieval at all, so the exhibitor's own tool is the only capture there is. The general booth privacy questions apply everywhere; this page is the version for a German procurement review.

Who is the controller when booth staff scan a badge?

The exhibitor. You decide why the data is collected and what happens next. The app vendor is your processor under an Article 28 contract.

The split assigns the work. The controller owes the attendee the notice, the lawful basis, the retention decision and the answer to an access or erasure request. The processor owes the controller a contract with the Article 28(3) terms: process only on documented instructions, confidentiality, security measures, sub-processor approval, assistance with data-subject requests, deletion or return at the end, and audit rights. If a vendor cannot produce that contract, the vendor is not ready for a German show, whatever the app does.

The organizer is a separate controller for the registration data on the badge. Scanning the badge does not make you a party to their processing, and it does not grant access to their registration data; that takes authorized access, the organizer's lead-retrieval service or an approved API connection. That is why most organizer badges encode an ID rather than the contact record; the badge code types guide covers what a scanner can and cannot read off the print.

Which lawful basis covers a booth scan?

Legitimate interest under Article 6(1)(f) or consent. Choose one before the show, write it down, and never read a scan as consent to marketing email.

Legitimate interest is the practical choice for following up on a booth conversation: a business visitor walked to a commercial stand at a commercial fair. It still needs the assessment written down, necessity and the balancing test, once per event program rather than per scan. Consent is the cleaner story when the attendee agrees to the scan after hearing what it is for, and it has to be informed, specific and recorded; a lanyard held out at a booth is not consent on its own.

The line that trips German programs is the follow-up, which carries an additional requirement alongside GDPR. Under UWG section 7, advertising by email needs prior express consent, B2B recipients included, with a narrow existing-customer exception that has its own conditions. A badge scan does not authorize a marketing sequence. Record what follow-up the visitor asked for, send that, and treat anything wider as a separate consent.

What breaks either basis is scope creep. A scan taken to follow up on a booth conversation does not cover adding the person to a newsletter, enriching the record with a home address, or handing it to a partner. Decide the purpose before the show, write it into the notice, and configure the app so that the data cannot quietly travel further than the purpose.

What must you tell the attendee at the booth?

Who you are, why you scan, where the data goes, how long you keep it, how to object. A counter notice linked to the full notice is the booth format.

Article 13 wants the information at the time of collection. Nobody reads a privacy policy at a booth, so the working pattern is two layers: a one-paragraph notice on the counter or the scan confirmation ("we scan your badge to follow up on this conversation; details and your rights at this link"), and the complete notice on your site, available the moment the scan happens. The complete notice names the lawful basis, the recipients, the countries the data goes to, the retention period, the rights to object, to withdraw consent and to complain to a supervisory authority, and the contact for requests. Enriched fields come from a source other than the attendee, which brings in Article 14: the notice names the data categories and their sources, and unless the attendee already has that information you provide it within a reasonable period after obtaining the data, no later than one month, and earlier if the first communication with them or the first disclosure to another recipient comes sooner.

The staff briefing is the other half. If you rely on consent, the rep gives the required information, including how to withdraw, and records agreement to a specific purpose. "May I scan your badge so we can email you the spec sheet you asked for?" is consent to that email and nothing wider. The rep who scans a lanyard without a word has collected nothing you can rely on, and the program's legitimate-interest assessment has to cover that case explicitly or it does not happen. Brief the booth on one script and keep it the same on every stand.

Why is data location the first question for the vendor?

A scan in Hannover stored on a US server is an international transfer. Every overseas recipient needs a documented transfer basis, the host included.

Most event lead capture apps are US companies on US infrastructure. That is workable under Standard Contractual Clauses with the transfer assessment behind them, or under an adequacy decision where one applies, and the vendor should be able to name the mechanism for every provider that touches the data. What a German reviewer will not accept is "our data stays in the cloud" or a vendor who cannot say which country the badge image is stored in. EU hosting narrows the question without closing it: if the OCR model or the enrichment provider sits in the US, badge images or contact fields still travel, whatever the database's postcode. Tendro's own EU deployment is an example, in the last section.

The second-order question is the processing chain. A badge image read by an OCR model, a contact enriched by a data provider, an email sent through a transactional mail service: each is a recipient with its own role, location and transfer basis, and some enrichment providers act as independent controllers rather than processors. A vendor with a public sub-processor page has started this work; ask for the terms and assessments behind the list. A vendor without one is asking you to do it for them.

What do you need from the vendor before the show?

A data processing agreement, a sub-processor list, the hosting location, a deletion procedure, a breach deadline, and access controls.

The list, in the order a reviewer usually asks:

  1. Data processing agreement under Article 28, with the transfer mechanism documented for every recipient outside the EEA, usually the EU Standard Contractual Clauses. Signed before the first scan, not after.
  2. Sub-processor list with purpose, data categories, location and transfer basis for each provider, plus a notice period for changes and a right to object.
  3. Hosting location, stated as a city and a provider, and whether an EU deployment is available.
  4. Deletion procedure: who requests, who executes, how long it takes, what confirmation you receive, and what happens to backups.
  5. Breach notification commitment: the vendor tells you without undue delay so that you can meet your own 72-hour clock under Article 33.
  6. Access controls: who at the vendor can enter your workspace, whether that entry is logged, and whether your own team can require two-step sign-in.

A seventh item is optional and cheap: a completed security questionnaire. Vendors that have been through a German review will have one. Read every zero and every not-applicable explanation, then ask for the evidence behind the controls that matter to your deployment.

Does lead enrichment change the GDPR picture?

Yes. It adds a processing step and a third-party source, and some providers act as controllers of their own databases. Be able to switch it off.

Enrichment is the feature that turns a name and a company on a badge into a work email, a title and a LinkedIn URL. It is also the step a DPO looks at longest, for two reasons. The data now comes from somewhere the attendee did not hand you, so the notice has to say so. And several enrichment providers state in their own terms that they are independent controllers of the contributor databases they match against, which means data submitted for a lookup may be used to verify or extend that database.

The workable position is a switch plus a plan. Approve enrichment by provider, purpose and data flow, decide it per workspace, and record the decision. If it is off for the German program, the badge gives you a name and a company and often no email, so the rep collects the work email at the booth and notes the follow-up the visitor asked for. If a vendor cannot turn enrichment off, the vendor's enrichment terms become your problem to explain.

How do you delete attendee data after the campaign?

Set a deletion date before the show. Afterwards, request deletion and get written confirmation with counts and timestamps for your records.

Retention is a controller decision, so make it before the show and write it into the notice: for example, deletion 30 days after the follow-up campaign closes. The vendor's part is the mechanism. The pattern that survives a review is semi-automatic: your admin requests deletion from the dashboard, the vendor executes it as one transaction with an audit-log entry, and you receive a generated confirmation stating what was deleted, when, and when residual copies in provider backups expire.

Be suspicious of "we delete it immediately" as a promise about backups. Backups rotate on a schedule; a vendor who understands their own system will tell you the schedule rather than promise instant erasure everywhere.

What happens if a booth phone is lost?

Treat it as a possible breach. Cut the device's access, tell the vendor, assess at once, and notify the authority without undue delay if required.

Article 33 puts the controller's notification to the supervisory authority at without undue delay and, where feasible, within 72 hours of becoming aware; the 72 hours is the outer limit for notifying, not a window for finishing the investigation. The processor's duty is to tell you without undue delay and keep adding facts as they emerge. Two design facts decide how bad this is. First, whether leads live in the account or only on the phone: an app that syncs each capture to the workspace means the lost phone holds a copy, not the only copy. Ask the vendor how a lost device's access is cut off, and how fast. Second, offline mode: captures taken without signal sit on the device until they sync, so a lost phone with an offline queue holds unsynced data. Short sync windows and a lock screen are the controls. The offline behaviour of your tool is worth testing at your desk before you find out at the venue.

How does Tendro handle GDPR at German shows?

As a processor: DPA on EU Standard Contractual Clauses, a public sub-processor list, EU hosting on request, deletion with written confirmation.

The specifics, stated the way we state them in a questionnaire:

  • Role. Tendro (a product of Veton, Inc.) processes personal data under GDPR as a processor. The data processing agreement uses the EU Standard Contractual Clauses and is available on request from privacy@tendro.com.
  • Sub-processors. Every provider that touches customer data is listed at tendro.com/subprocessors with purpose, data categories, location and transfer basis. DPA customers get 30 days' notice of changes and a right to object.
  • Hosting. Production runs on DigitalOcean in New York, covered by DigitalOcean's SOC 2 Type II report for the infrastructure, under Standard Contractual Clauses. A dedicated EU deployment, its own application, database and image storage on DigitalOcean Frankfurt or Amsterdam, is available on annual agreements.
  • Badge reading. Badge text recognition runs through Google's Gemini API on the paid tier, in the United States under Standard Contractual Clauses; prompts and responses are not used to train Google's models. That stays true on the EU deployment: the application, database and images sit in Frankfurt or Amsterdam, and the badge image still goes to Gemini in the US for reading. The sub-processor page says so rather than a feature list hiding it.
  • Enrichment. Switchable per workspace by your admin. Off means no contact data leaves for any enrichment provider.
  • Deletion. Your workspace admin requests deletion of all captured data from the dashboard; Tendro executes it from an internal console in one transaction with an audit-log entry and confirms in writing with counts and timestamps.
  • Breach notification. Tendro notifies the customer without undue delay after becoming aware of a personal-data breach and no later than 72 hours after confirming one, as written into the DPA, and supplements the first notice as facts emerge.
  • Access. Every entry by Tendro staff into a customer workspace is logged and emailed to the founder. Two-step sign-in for the dashboard is a workspace setting you can require.
  • Evidence. A completed 99-control security questionnaire, the information security policy and the supplier procedure are available on request, and a reviewer can ask for any control's evidence line.

Commercially, the German program is priced the same as every other one: $499 per event, unlimited team members and scans, no per-device fees, and no annual contract unless you want the EU deployment. The per-event versus annual comparison covers why that matters at a show with no organizer scanner, and the organizer scanner cost breakdown covers what you are comparing against where one exists. If your DPO wants the documents first, ask for them and we send the packet before anyone downloads the app. The free trial itself is a desk test, 25 scans of your own old badges with no card and no CRM connection, so the review can run on real output before a single attendee is scanned.

Frequently asked questions

Can you scan attendee badges at a German trade show with a phone app under GDPR?

Yes, with a lawful basis you have logged, a notice the attendee can see, and a vendor bound as a processor. The scan is easy. The paperwork decides.

Who is the controller when booth staff scan a badge?

The exhibitor. You decide why the data is collected and what happens next. The app vendor is your processor under an Article 28 contract.

Which lawful basis covers a booth scan?

Legitimate interest under Article 6(1)(f) or consent. Choose one before the show, write it down, and never read a scan as consent to marketing email.

What must you tell the attendee at the booth?

Who you are, why you scan, where the data goes, how long you keep it, how to object. A counter notice linked to the full notice is the booth format.

Why is data location the first question for the vendor?

A scan in Hannover stored on a US server is an international transfer. Every overseas recipient needs a documented transfer basis, the host included.

What do you need from the vendor before the show?

A data processing agreement, a sub-processor list, the hosting location, a deletion procedure, a breach deadline, and access controls.

Does lead enrichment change the GDPR picture?

Yes. It adds a processing step and a third-party source, and some providers act as controllers of their own databases. Be able to switch it off.

How do you delete attendee data after the campaign?

Set a deletion date before the show. Afterwards, request deletion and get written confirmation with counts and timestamps for your records.

What happens if a booth phone is lost?

Treat it as a possible breach. Cut the device's access, tell the vendor, assess at once, and notify the authority without undue delay if required.

How does Tendro handle GDPR at German shows?

As a processor: DPA on EU Standard Contractual Clauses, a public sub-processor list, EU hosting on request, deletion with written confirmation.

Stop losing deals at your next event

Book a Demo