DES DES Event Accessibility & Compliance 2 — Questions and Answers
Question 1: What does GDPR require of US-based event organizers when collecting data from European Union attendees?
- A lawful basis for data processing, explicit consent where required, and the right for attendees to access or delete their data (Correct answer)
- Only a privacy policy link on the registration page
- Automatic deletion of all EU attendee data within 24 hours of the event
- Storing EU attendee data only on US-based servers
Correct answer: A lawful basis for data processing, explicit consent where required, and the right for attendees to access or delete their data
GDPR applies to any organization processing EU residents' personal data, regardless of the organization's location, requiring lawful basis, transparency, and data rights.
Question 2: What is a 'data processing agreement' (DPA) in the context of digital events?
- A contract between the event organizer and third-party vendors that defines how attendee data is handled and protected (Correct answer)
- An agreement between the event host and speakers about content ownership
- A document outlining how event recordings will be distributed
- A registration form addendum for high-security government events
Correct answer: A contract between the event organizer and third-party vendors that defines how attendee data is handled and protected
A DPA ensures that vendors processing attendee personal data on behalf of the organizer comply with applicable data protection regulations.
Question 3: What is the CAN-SPAM Act's primary requirement for event marketing emails sent to US recipients?
- Each commercial email must include a clear unsubscribe mechanism and the sender's physical mailing address (Correct answer)
- All event emails must be sent only to previously registered attendees
- Marketing emails cannot include promotional pricing information
- Event organizers must obtain written consent before sending any email
Correct answer: Each commercial email must include a clear unsubscribe mechanism and the sender's physical mailing address
CAN-SPAM mandates an opt-out mechanism and sender identification in every commercial email, though it does not require prior consent like GDPR does.
Question 4: Under COPPA, what must event organizers verify before collecting registration data from online attendees in the United States?
- Whether the attendee is under 13 years old, requiring verifiable parental consent if so (Correct answer)
- Whether the attendee has a valid credit card for payment processing
- Whether the attendee lives in a state with specific privacy laws
- Whether the event topic is appropriate for all age groups
Correct answer: Whether the attendee is under 13 years old, requiring verifiable parental consent if so
COPPA (Children's Online Privacy Protection Act) prohibits collecting personal data from children under 13 without verified parental consent.
Question 5: What is 'purpose limitation' in data privacy compliance for digital events?
- Using collected attendee data only for the specific purposes disclosed at the time of collection (Correct answer)
- Limiting the number of data fields on the event registration form
- Restricting data access to only the lead organizer
- Deleting all attendee data immediately after the event ends
Correct answer: Using collected attendee data only for the specific purposes disclosed at the time of collection
Purpose limitation requires that personal data collected for event registration not be repurposed for unrelated activities like third-party marketing without new consent.
Question 6: Which accessibility practice benefits both attendees with cognitive disabilities and all attendees in general during digital events?
- Using plain language, clear navigation, and consistent visual design across the event platform (Correct answer)
- Providing printed agendas to in-person attendees only
- Offering a dedicated help desk exclusively for attendees with disabilities
- Requiring all session titles to be under five words
Correct answer: Using plain language, clear navigation, and consistent visual design across the event platform
Plain language and consistent design reduce cognitive load for everyone, making the event more usable across all ability levels — a principle known as universal design.
What does GDPR require of US-based event organizers when collecting data from European Union attendees?