Consent and Data Protection in Event Matchmaking Under Kenya's Data Protection Act
What organisers must get right when delegates' business profiles and contact details are shared for networking purposes.
Matchmaking involves publishing personal data to other delegates. That is a processing activity with obligations attached under the Data Protection Act, and organisers are the data controller.
These are the controls we build into every matchmaking deployment.
Explicit, separate opt-in
Registering for an event is not consent to appear in a networking directory. The opt-in is a distinct, unticked choice at registration, with plain wording about who will see the profile.
A delegate can withdraw and disappear from the directory at any time, including during the event.
Publish less than you collect
The directory shows name, organisation, role and interests. Email addresses and phone numbers are not published; they are exchanged only after both parties accept a meeting.
Field-level visibility is configurable, so a closed convening can restrict the directory to registered participants only.
Sponsors are not given the list
Sponsors see the profiles of people who accepted their meeting requests, not a downloadable delegate database. Bulk export of personal data to third parties is not part of the product.
Badge scanning at a stand, where the delegate presents their code, is a separate and clearly consented exchange.
Retention and deletion
Networking data is retained for an agreed period after the event, then deleted. Organisers set the window and receive confirmation.
Questions about compliance for your event: info@cara.co.ke.
Work with our team
Matchmaking runs inside every programme we deliver. See our event management services service, or explore the platform at events.cara.co.ke.
Plan your event with Cara
Need corporate event planners in Nairobi?
We deliver full-service corporate event management in Kenya, planning, production and coverage.