·10 min readtrade show GDPR lead capturebusiness card data protectionvisitor data privacyexhibition leads

Can You Market to the Business Cards You Collected at a Trade Show? A GDPR Lead Capture Guide

Handing over a business card is not consent to your newsletter. A practical GDPR guide to collecting, storing, using, and deleting trade show visitor data — with a stage-by-stage checklist.


After every trade show, the same thing happens in marketing departments everywhere: the stack of business cards and scanned badges gets uploaded straight into the newsletter list. Here is the short answer up front — receiving someone's business card is not the same as receiving their consent to marketing. A card signals "you may contact me about what we discussed," not "add me to every campaign you run." Under the GDPR, the contact details on a business card are personal data, and every use of them needs a lawful basis. This guide walks exhibitors and event organizers through what that means in practice — from the moment a lead is captured at the booth to the day the record is deleted.

This article is general information, not legal advice. For decisions about your specific situation, consult a data protection professional or your supervisory authority.

Exchanging a business card at a trade show

Why can't we just use the cards we were handed?

A business card carries a name, employer, job title, phone number, and email address — all personal data, even in a B2B context. The GDPR's core logic is straightforward: you may only process personal data for the purposes you identified, on a lawful basis, and the person must be told what you are doing.

Context matters. When a visitor hands over a card during a booth conversation, the reasonable expectation is follow-up about that conversation — the quote you promised, the meeting you agreed to schedule. Follow-up of that kind can often rest on legitimate interest, provided you have weighed it properly and documented that assessment. Recurring marketing emails are a different matter. The safer and widely recommended basis for newsletters and promotional campaigns is consent — freely given, specific, informed, and recorded. And regardless of which basis you rely on, electronic marketing rules in many jurisdictions add their own opt-in or opt-out requirements on top of the GDPR.

Three risky patterns show up again and again on show floors:

  1. Treating a card as blanket consent. Consent under the GDPR must be specific and demonstrable. A card in a fishbowl demonstrates neither.
  2. Collecting consent but not recording it. If a booth rep asked "may we email you?" and the visitor said yes, but nothing was written down — who consented, when, to what — you cannot demonstrate it later. Undocumented consent is functionally no consent.
  3. Keeping lead lists forever. Spreadsheets from events three editions ago sit in shared drives indefinitely. Storage limitation is a core principle: when the purpose is fulfilled or the retention period ends, the data should go.

What principles should govern trade show lead data?

You do not need to memorize the regulation. You need to build five habits into your event workflow.

First, be transparent at the point of collection. Tell visitors what you collect (contact details, notes from the conversation), why (follow-up, marketing — named separately), and how long you will keep it. A short privacy notice at the booth or on the capture form does the job. If you want marketing consent, ask for it explicitly and separately from conversation follow-up — one unchecked-by-default checkbox, with a timestamp saved alongside the record.

Second, stay within the stated purpose. A lead captured for "follow-up on your inquiry" cannot be quietly merged into the global campaign database. Widening the purpose requires going back for consent or establishing a new lawful basis — and documenting it.

Third, set a retention period and actually delete. "We might need it someday" is not a retention policy. Define how long event leads live — tied to your sales cycle, for instance — communicate it, and when the clock runs out, delete irreversibly: the CRM record, the exported spreadsheets, and the scanned card images.

Fourth, distinguish disclosure to third parties from processing on your behalf. Sharing your lead list with another company that will use it for its own purposes is a third-party disclosure and needs its own basis and transparency. Using a SaaS tool that processes leads solely on your instructions is engaging a processor — a different relationship with different obligations, centered on a data processing agreement (DPA).

Fifth, manage your processors. Every tool that touches visitor data — the lead capture app, the email platform, the cloud drive — is a processor. You need a DPA with each, and you should verify their security posture: access controls, audit trails, data isolation. If a processor leaks your leads, the accountability still runs through you.

Receiving a stack of business cards at a trade show

What should you check at each stage?

Here is the lifecycle as a checklist. It works well as an agenda item in your pre-show planning meeting.

Stage What to verify
At collection Privacy notice available at the booth / marketing consent asked separately from follow-up / consent status and timestamp recorded per lead
While stored Access limited to people who need it / card images and lead files kept in a controlled repository, not on personal phones / a log of who accessed what, and when
When used Purpose and lawful basis confirmed before sending / marketing emails include a working opt-out / any third-party disclosure covered by its own basis
At deletion Retention period reviewed / originals, exports, and scanned images erased irreversibly / the deletion itself documented

The item teams miss most often is the recording. Consent without a record cannot be demonstrated; access without a log cannot be explained; deletion without documentation cannot be proven. Accountability — the GDPR principle that you must be able to show compliance, not just achieve it — runs on records.

What is the event organizer's responsibility?

If you run the event rather than a booth, your view has to be wider. The organizer is the party positioned to design and explain the overall data structure of the show: who collects what, where it lives, and who controls it.

Three things belong on the organizer's list. Map the roles. Pre-registration data, badge scans, and the conversation records exhibitors capture at their booths may each have different controllers. Write down who is responsible for what, so that when a visitor asks "where does my data go," there is a one-sentence answer. Set a floor for exhibitors. Include minimum data protection expectations in the exhibitor manual — provide a privacy notice, separate marketing consent from follow-up, collect only what is needed. It lowers risk for the entire event, including yours. Get the contracts right. Registration platforms and lead capture tools are processors; sign DPAs with them, and make ownership explicit in the paperwork — visitor data collected at the event should belong to the exhibitors and the organizer, not to the vendor.

Following the principles requires tools that keep records

Look back at the checklist and one theme repeats: proof. Proof of consent, proof of who accessed a record, proof of deletion. Business card binders and spreadsheets produce none of it.

TagBooth is a QR and NFC tag-based SaaS for recording trade show conversations, built around exactly this record-keeping problem. Every conversation record carries a consent status field with a timestamp, so the consent collected at the booth survives as data. Business card images are stored in a private repository — never on a public URL — and are viewable only through time-limited links issued to verified, authorized requests. Data is fully isolated between exhibiting companies, and login uses email verification codes with no passwords to leak. Most distinctively, every data access is written to an audit log that is sealed daily in a hash chain and anchored to Bitcoin via OpenTimestamps — meaning you can demonstrate who viewed which record and when, in a form that cannot be altered after the fact. Companies get an access-history screen, remote session revocation for lost phones, and a DPA: data ownership stays with the exhibitors and the organizer, while TagBooth acts strictly as a processor. To be clear, no tool discharges your legal obligations for you — but the right tool generates the records that meeting those obligations depends on. You can try it without installing anything on the demo page, and the full workflow is explained in how it works.

FAQ

Is a business card handed to us at the booth valid consent for marketing?

No. Exchanging cards is reasonably understood as an invitation to follow up on the conversation, not as specific, informed consent to marketing campaigns. For newsletters and promotions, obtain explicit consent — asked separately, unambiguous, and recorded with a timestamp.

Can we rely on legitimate interest instead of consent for trade show leads?

Legitimate interest can support relevant B2B follow-up in some situations, but it requires a documented balancing assessment, and electronic marketing rules often demand opt-in consent regardless of your GDPR basis. Many organizations use consent for ongoing marketing precisely because it is cleaner to demonstrate. When in doubt, ask — a checkbox at the booth costs nothing.

How long can we keep the leads we collected?

The GDPR does not set a fixed number; it requires that retention match the stated purpose. Define a period tied to your follow-up and sales cycle, communicate it in your privacy notice, and when it lapses, delete every copy — including exports and scanned card images — and document that you did.

Does using a lead capture SaaS count as sharing data with a third party?

Generally no — a SaaS that processes leads only on your instructions is a processor, not a third-party recipient, so no separate disclosure consent is needed. What is needed is a data processing agreement and due diligence: confirm the vendor offers access controls, audit logging, and isolation between customers before you trust it with visitor data.

Start capturing booth conversations with a single tag

From event setup to performance reports, see it yourself in the demo.

Try the demo →