Suppression lists for registered attendees stop you paying twice for the same person
A suppression list is the registered file pushed back to each ad platform as a hashed audience exclusion, refreshed daily so people leave the targeting within a day of registering. Match rates on hashed uploads sit well below 100 per cent, so the exclusion removes most of the waste and never all of it.
Somebody on your commercial team registered for the show in week three of the campaign. In week eleven she is still seeing the registration banner on a trade site, twice a day, with a call to action she already answered. She mentions it in a meeting, and the polite version of the question is whether the media agency knows she registered.
Suppression lists for registered attendees are the fix, and they are the least glamorous piece of paid media hygiene there is. The registered file goes back to every platform every day as a hashed exclusion, and the audience shrinks by exactly the people who have already done the thing you are paying to make them do.
Why does an exclusion list beat better targeting?
Targeting decides who might see the ad. Exclusion decides who cannot. Only the second one is under your control after the campaign starts, because an ad platform optimising for registrations will keep finding people who look like registrants, and the people who look most like registrants are the ones who already registered.
There is a second effect that matters more than the money. A fixed budget spread across a pool that includes 22,000 people who cannot convert lands as frequency on everyone in the pool. Take those 22,000 out and the same budget buys reach among people who can still act.
The mechanism is a customer list upload used as an exclusion instead of a target. Every major platform supports it. You are giving them a hashed list of people to stop showing your ads to, which is a smaller privacy footprint than the audience targeting most organisers already run.
What goes into a registered attendee suppression file?
Three groups belong in the suppression list, and they need to be kept separate so you can turn each one off.
Confirmed registrations. Everyone with a confirmed registration for the current edition, added within a day of confirming.
Exhibitor and staff records. Booth staff, contractors, your own team. They are already coming, they cannot register as visitors, and they are heavy users of the trade media where you buy.
Hard opt-outs and known bad records. People who asked not to be marketed to. They belong out of every paid audience as well as out of the email, which is a point that gets missed because the two systems are usually run by different people.
What does not belong in the file is anyone you might legitimately want to reach again. Cancelled registrations, for one. A person who registered in April and withdrew in June is a prospect, and if your suppression job reads the registration table without checking status, she is silenced for the rest of the campaign. The same applies to people registered for a different show in the portfolio, who often end up in a shared suppression file because somebody exported at the account level instead of the event level. Both mistakes are invisible, because a person who is not being advertised to generates no data at all.
Cadence is the part that quietly decides the size of the saving. A weekly push leaves everyone who registered since the last upload inside the targeting. On a show taking 300 registrations a day in the middle of its campaign, a weekly refresh means an average of about 1,050 registered people are still being advertised to at any moment, and in the final fortnight, when daily volume can triple, that number is far worse. Daily is the right cadence, and it is a scheduled job that runs before anybody arrives in the morning.
The hashing rules that decide your match rate
Contact records are normalised and hashed before they leave your systems. Google's Customer Match documentation, current in 2026, is explicit about the normalisation: strip leading and trailing whitespace, lowercase the whole address, and for gmail.com and googlemail.com addresses remove periods and any plus suffix from the username before hashing with SHA-256. If the record is not formatted correctly before hashing, the upload is still accepted and the record simply never matches anybody.
That last detail is the one that costs organisers real money. A malformed hash is not an error. It is silence.
Two more rules from the same documentation are worth holding. Google reports a match rate for each upload, so the number is visible rather than inferred. And a customer list needs a minimum of 100 active users in the last 30 days to serve, for lists uploaded or refreshed after 1 February 2024, while older lists still need 1,000 matched users. A suppression list for a show of any size clears that floor comfortably, but a suppression list for a single niche co-located event might not.
Working the waste on 22,000 registered records
Suppose the edition holds 22,000 confirmed registrations with eight weeks to go, and paid social and display are still running to an audience that includes them.
Start with the match. Upload 22,000 records with email only and a 65 per cent match rate gives 14,300 people excluded. The other 7,700 stay in the pool because the address you hold is not the address they used on the platform. Add phone number and name plus country as secondary identifiers and the rate typically improves, which is why the file you push should carry every identifier you legitimately hold rather than only the email.
Now the media. Over a 30 day flight at an average frequency of 18, those 14,300 excluded people would have taken 257,400 impressions. At a 4 dollar CPM that is 1,029.60 of display money, which is not a number that changes anyone's year. Run the same arithmetic on professional network inventory at a 32 dollar CPM and it is 8,236.80, which is a real line.
The frequency effect is larger than either figure. If the total campaign pool is 260,000 people and 22,000 of them are already registered, removing the matched 14,300 frees 5.5 per cent of impressions to land on people who can still register. On a budget of 180,000 that is roughly 9,900 of media redirected to an audience that can act, without asking finance for anything.
There is a version of this arithmetic that gets abused, so it is worth naming. Multiplying excluded people by frequency by CPM and calling the result a saving assumes the budget disappears with them, which it does not. The money stays in the account and buys other impressions. What you have actually measured is the share of the budget that was landing on people who could not convert, and the honest phrasing is that 5.5 per cent of impressions moved from a pool that could not act to one that could.
Report it as two lines: impressions served to registered records before suppression, and after. Both come from joining the platform audience report to your registered file, which needs a rule for who claims a registration when several sources touch it before the join means anything.
Does a suppression list need consent of its own?
Uploading a customer list is a data processing decision before it is a media one. Google's Customer Match guidance for the Google Ads API, published in 2024, requires both consent fields, ad_user_data and ad_personalization, to be set to granted for Customer Match lists used in the European Economic Area, and states plainly that data from unconsented EEA users will not be processed and cannot be used for ad personalisation through Customer Match. The same documentation tells partners to upload users with different consent signals in separate jobs.
Read that carefully and you find an awkward asymmetry. The list you are uploading is being used to stop advertising to people, which is the outcome a privacy-minded registrant would want, and it still needs the same consent as a list used to target them. That is the rule as written, and the practical consequence is that your suppression file in the EEA covers only the consenting subset of your registrants, while the non-consenting ones keep seeing ads you cannot switch off at the platform.
The alternative for that group is to suppress on your side: stop retargeting audiences built from site behaviour once the person has a confirmed registration, which is where the abandoned registration audiences need an exit rule anyway.
Where this stops
Suppression is bounded by identity, and identity in event data is messy in a way that no platform feature fixes.
The person who registers with her work address and browses the trade press signed into a personal account is one human and two records, and no hashed upload will connect them. Your match rate is a measurement of that gap. When a platform reports 65 per cent, the honest reading is that a third of your registered audience is unreachable by exclusion. Your file can be clean and still match at that rate.
The second limit is that suppression removes waste and produces no registrations, so it never shows up as a win in any channel report. The saving appears as a slightly better cost per registration across the whole account, which is easy to attribute to something else. If you want the credit, measure the before and after explicitly and write down the date the suppression job started.
The third is timing at the top of the funnel. A person can register and see an ad the same afternoon because the impression was bought before your daily push ran, and there is no way to be faster than that without real-time integration most organisers do not have. Same-day residual waste is the price of the batch approach, and it is small.
Start this week by exporting confirmed registrations for the current edition, hashing them to the platform specification, and uploading one exclusion list to whichever channel carries your largest budget. Then look at the reported match rate. That single percentage tells you how much of this method is available to you before you plan any of it, and it takes an afternoon to find out. The same file becomes the base for measuring what a mailing to lapsed records actually recovers, and both sit inside the wider acquisition and attribution picture.
Questions people ask about suppression lists for registered attendees
- How often should a registered attendee suppression list be refreshed?
- Daily during the campaign, and more often in the fortnight before doors when registrations arrive fastest. A weekly refresh leaves everyone who registered since the last push inside the paid audience. On a show taking 300 registrations a day, that is an average of about 1,050 people being advertised to after they have already committed.
- Why do suppression lists never match everyone?
- Platforms match hashed contact records against hashed account records, so a person registering with a work address who signed up to the platform with a personal one will not match. Uploading several identifiers, such as email plus phone plus name and country, raises the rate. A match rate around two thirds is common and the unmatched remainder keeps seeing ads.
- Does a suppression list break consent rules?
- Uploading a customer list for audience use requires a lawful basis and, in the European Economic Area, explicit consent signals. Google has required both ad_user_data and ad_personalization to be granted for Customer Match lists used in the EEA since March 2024, and states that data from unconsented users in that region will not be processed for ad personalisation.