Summary

  • The AIS 2026 registration form requires a passport or government-issued ID upload.
  • The reviewed current pages do not state the document-specific purpose, access roles, retention period or deletion route.

The AIS 2026 registration form marks the upload of a passport or other government-issued identity document as mandatory. It also collects a registrant's name, address, location, email, account credentials, organisation, event choices and participation mode.

Sources

The form gives one narrow explanation for some information: gender, country and category may be used for statistics, excluding personal data. The terms add a wider framework. They say registrant data is processed under Mauritian data-protection law, incorporate the AFRINIC Privacy Policy, authorize publication of a registrant's name and organisation, and contemplate third-party service providers.

Those statements do not answer the document-specific questions raised by the required upload. On the two reviewed pages, the organisers do not state why the identity file is needed, which role may open it, whether a processor receives it, how long it is kept, when it is deleted or where a registrant can ask about the file. The form also offers both onsite and online participation, but does not explain whether the same document rule is necessary for each.

This is not evidence that a document has been misused, disclosed or lost. It does not establish a breach of law, and it does not show that no internal procedure exists. Identity verification may serve a legitimate operational or security purpose. The governance problem is visibility: a person must transfer a sensitive document before the public collection interface explains the authority and lifecycle attached to it.

A government-issued ID is not an ordinary conference preference. Its collection concentrates power in whoever defines the requirement and whoever can retrieve the file. Registrants bear the exposure if access is broader or retention longer than necessary, while the organisers bear the cost of specifying and enforcing a narrow process.

The smallest remedy is a notice beside the upload field. It should name the purpose and responsible organisation, distinguish onsite from remote needs, list authorized access roles and processors, state retention and deletion periods, describe security at an appropriate level, and give a contact for access, correction or erasure questions. If the document is required only in particular cases, the form should say so before collection.