Business

What To Do With Scanned Contacts: The Privacy Rules

What to Do With Scanned Contacts: The Privacy Rules

Scanning a card is easy. The hard part is handling that data correctly over the next 30 days, and that's where many teams make mistakes.

When you talk to a revenue team about scanned contacts, privacy is rarely their top priority. They care more about routing, follow-ups, and quick responses. But after the event, records get scattered everywhere, and then the big questions appear: Can we email these people? Can we text them? How long can we keep this data? What if someone asks us to delete everything?

However, after you've verified that a badge can scan, compliance doesn't stop. After the event, when the booths close, guests depart, and you have newly acquired contacts to manage, the next set of issues arises.

The First 72 Hours: Kill the Copies

The CRM itself isn't your biggest danger after an incident. Data ends up in all the other locations.

Records in the scanning software, a CSV in someone's downloads, an Excel copy on the shared drive, and even a screenshot in Slack are all examples of the same mess that is created by every event. By Tuesday, it had already occurred even though no one had planned for it.

This is important because every rule that follows assumes you know where your data is. You can't handle a deletion request if you forget about a spreadsheet, and deleting a CRM record doesn't count if copies are still hidden elsewhere.

So the rule for post-event data privacy is simple: use one system of record, fill it within 72 hours, and destroy all other copies. Don't just archive them; destroy them. An archived export is still a copy you are responsible for.

Do two more things while it's still fresh—record where and when you met each person, as this helps explain later why a record exists. Also, keep enrichment data separate from what the person gave you. Inferred firmographics and volunteered details have different risks, and California requires you to disclose retention by category. It's much easier if you never mix the categories.

What to Do With Scanned Contacts: Privacy Rules Before You Hit Send

CAN-SPAM governs the message, not the platform

Consent isn't the main issue when emailing US contacts. CAN-SPAM is an opt-out system, so you don't need permission first. The rules focus on the message content, and they're detailed enough that most post-event emails break at least one rule.

A proper opt-out mechanism, a legitimate physical postal address, a subject line that accurately describes the email content, and accurate header information are all necessary for any business email. After the transmission, that mechanism must be operational for at least 30 days, and opt-outs must be processed within 10 business days.

The postal address is the requirement most event teams miss, often because follow-up emails come from a rep's personal email instead of the marketing platform, which would add the address automatically. If a rep sends forty personalized emails from Outlook, that's forty non-compliant messages. You're also responsible for what agencies send on your behalf. The FTC clearly says you can't pass off legal responsibility to someone else.

The phone number trap

Even competent teams often struggle with this problem because it doesn't seem like a compliance decision. It simply feels like exercising initiative.

When a representative arrives home and notices a mobile number on a scanned card, they send a cordial SMS. However, a business card does not qualify as previous express written authorization required by the Telephone Consumer Protection Act for marketing messages sent using regulated automated technology. Every message carries a risk: recipients can claim $500 for each infraction, which triples if the infraction was deliberate. A representative can make forty claims if they text forty numbers.

On April 11, 2025, the FCC's revised revocation regulations took effect, changing how companies must respond to opt-out requests. Businesses now have a maximum of 10 working days to fulfill requests to stop receiving messages or to withdraw consent, down from the prior 30-day restriction.

The more extensive "revoke-all" requirement has been postponed. This regulation frequently interprets an opt-out from one type of communication as a loss of consent for subsequent unrelated robocalls or robotexts from the same sender. The FCC extended the compliance deadline to January 31, 2027, when it renewed the waiver in January 2026. As a result, businesses have more time to prepare before it takes effect.

The simplest solution is to avoid collecting mobile numbers unless you have a consent-compliant SMS program. If you don't use the phone field, it's just a risk.

Contact Data Retention: How Long You Can Actually Keep It

"Delete old leads eventually" is not a good way to preserve contact details. Vagueness is no longer allowed because California requires businesses to identify how long they retain each type of personal information or the reasons behind that choice. This must be a published schedule, not merely an internal regulation. If you don't mention this in your privacy notice, you will always have a disclosure gap, no matter how carefully you handle the data.

A one-page retention policy

Event leads that were scanned but never used are known as unworked leads. It makes sense to hold onto them for a full year because if you don't follow up after a year, they become a liability with a name attached rather than a prospect.

Anyone who responded, attended a meeting, or advanced in the process is considered an engaged prospect. It makes sense to retain their data for 24 months, but start counting from the last significant interaction rather than the event date. Otherwise, because the trade exhibition occurred two years ago, you might remove an ongoing discussion.

Keep card images for as little time as possible. Delete them as soon as you've verified the data extraction. They only duplicate what's already in your CRM, so there's no reason to keep them and plenty of reasons to delete them.

This policy does not cover customer information. Contract-driven business retention standards govern it and usually require long-term retention. The most common mistake is not keeping data long enough, but instead removing marketing records that finance must maintain.

Strong policies are built on triggers rather than dates. For example, "24 months from last engagement" works better than "delete every January," which many people forget. Put your explanation in writing as well because California requires that collection, use, and retention be necessary and suitable for the intended use. You give that explanation when someone asks.

This also matters for business reasons. Most policies underestimate how quickly contact information becomes outdated. According to the Bureau of Labor Statistics, the median US employee tenure decreased from 4.1 years in 2022 to 3.9 years in January 2024—the lowest since 2002. Within a year, many of the 400 records will have incorrect addresses and titles. Maintaining a large list is not only dangerous, but it also increases your vulnerability to data breaches and hurts deliverability.

Here are three controls to use. Encrypt data both in transit and at rest, treating card images and extracted text as personal information. Delete card images once you've extracted the fields. The photo is just raw material, not a record, and it's more likely to leak since no one planned for it. Also, limit access to what's needed: a rep should see only their own leads, not all four hundred.

Where RoloScan Fits After the Scan

All of the steps above are part of a process, and that process breaks down when it takes too much time. Post-event privacy doesn't fail because people don't know the rules—it fails because the real work happens later, in Excel, under tight deadlines. The right tools move that work back to the few seconds you have at the booth.

Sidecar AI's RoloScan, a business card and badge reader, is built for that. This is how it relates to the four issues mentioned above.

Copy sprawl never begins. RoloScan uses verified OAuth connections to sync captured contacts into HubSpot or Salesforce. Your current duplicate rules, assignment rules, and retention triggers apply because records enter your governed system as native records. You won't have to search for copies to remove every CSV output you avoid.

Make a note of it immediately rather than waiting to obtain provenance. Employees scan a card, make brief notes, classify the lead by type or occurrence, and identify whether the intent is warm, cold, or hot. Who met whom and where is displayed in the team visibility. You can actually enforce a retention time because it creates your provenance layer in seconds instead of requiring hours to rebuild later.

Duplicates are automatically combined. One prospect scanned by three employees results in one record. When it comes time to delete, you need to be sure there isn't a fourth copy in someone's private pile.

There are already retention categories. The division between unworked leads and engaged prospects is directly correlated with the hot, warm, and cold scoring. Your deletion triggers and score in the booth have a legitimate target.

AI OCR and enrichment cut down on manual work. Extraction and company enrichment happen right on the device, so there's no temporary spreadsheet where someone retypes hundreds of records—the point where most hidden copies are created. Offline mode saves data when the convention center Wi-Fi fails and syncs it later. AI follow-up drafts help you send messages while the conversation is still fresh, using a system that remembers what was discussed.

According to its privacy policy, RoloScan protects data with end-to-end encryption during transfer and stores it in encrypted cloud databases. Users can export, correct, and delete their data, and the company does not sell or rent personal information for marketing. Keep two things in mind: deletion is not immediate—data is kept for 30 days for account recovery while marked for deletion. Also, servers are in the United States, which you should consider if data location matters for your policies.

The Checklist for After the Event

  • Within 72 hours, combine all records into a single system; eliminate temporary exports.

  • Verify that the event, date, capture method, and owner provenance fields are filled in.

  • Remove the card pictures once you've extracted and verified the text.

  • Screen the list against your suppression file before any send.

  • Verify follow-up emails carry a valid postal address and live opt-out, including from reps' personal inboxes.

  • Delete any acquired cellphone numbers unless you have an SMS program that complies with consent.

  • In your privacy notice, include a retention term for each category.

  • Hang deletion on an engagement trigger, not a calendar date.

  • Practice a complete deletion request against an actual record.

In conclusion

Although handling scanned contacts is often framed as a privacy issue, it is an operational challenge. Errors occur during the procedure, but the laws are clear. Data is copied into unmonitored locations. Emails are sent without a mailing address. An SMS message is sent without permission. The 45-day period begins when you receive a deletion request, but nobody knows where all the data is.

Consolidate all records within 72 hours. Encrypt all data, since that requirement is tied to statutory damages. Delete card images. Don't use mobile numbers without written consent. Publish a retention period for each category and make sure it's based on a real trigger.

If you follow these steps, then when someone asks if you can delete a person's data by Friday, you can say yes. Three months after an event, that's the only compliance question that really matters.