[{"data":1,"prerenderedAt":1989},["ShallowReactive",2],{"top-banner-en":3,"blog-article-event-data-security-european-sovereignty-en":4},{"prismicDocument":-1},{"prismicDocument":5,"relatedArticles":467,"relatedPages":1988},{"id":6,"uid":7,"url":8,"type":9,"tags":10,"first_publication_date":13,"slugs":14,"linked_documents":16,"lang":17,"data":18,"_source":463},"en_blog_article_securite-souverainete-plateforme-europeenne","event-data-security-european-sovereignty",null,"blog_article",[11,12],"conseil","global","2026-08-24T10:01:46+0000",[15],"securite-des-donnees-evenementielles--latout-europeen",[],"en-us",{"distribution":12,"article_title":19,"author_name":25,"publication_date":26,"banner_image":27,"article_content":38,"main_tag":449,"body":450},[20],{"type":21,"text":22,"spans":23,"direction":24},"heading1","Event data security: the European advantage",[],"ltr","Joy GRAND","2026-08-24T10:00:00+0000",{"dimensions":28,"alt":31,"copyright":8,"url":32,"id":33,"edit":34},{"width":29,"height":30},900,600,"Illustration of a shield protecting event data, symbolizing security, privacy, and attendee protection.","https://images.prismic.io/digi-www/A5joQZmYgMoOgxli_S%C3%A9curit%C3%A9-des-donn%C3%A9es-%C3%A9v%C3%A9nementielles.webp?auto=format,compress&rect=0,0,900,600&w=900&h=600","A5joQZmYgMoOgxli",{"x":35,"y":35,"zoom":36,"background":37},0,1,"transparent",[39,43,46,49,52,54,57,59,62,64,71,74,77,79,82,84,87,89,92,98,100,106,108,122,124,127,129,141,143,146,148,151,154,156,159,161,166,169,172,174,177,179,185,188,191,193,198,201,204,207,209,214,217,220,223,226,229,232,235,237,242,245,248,250,253,255,259,262,265,268,270,274,277,282,285,288,294,296,300,303,306,309,312,314,318,321,323,326,330,333,336,339,341,343,346,352,355,357,363,365,370,373,375,378,381,384,387,389,391,394,396,399,402,404,409,412,415,417,420,423,425,428,430,433,435,442],{"type":40,"text":41,"spans":42,"direction":24},"paragraph","How do you protect your attendees' data?",[],{"type":40,"text":44,"spans":45,"direction":24},"Event data security is no longer a formality tucked away at the end of a contract. It has become a selection criterion, on par with price or features.",[],{"type":40,"text":47,"spans":48,"direction":24},"",[],{"type":40,"text":50,"spans":51,"direction":24},"Why now? Because your internal clients, procurement teams, and IT departments ask the question before signing. Because an event brings together sensitive data: contact details, job titles, sometimes profiles of executives or VIP guests.",[],{"type":40,"text":47,"spans":53,"direction":24},[],{"type":40,"text":55,"spans":56,"direction":24},"At Digitevent, we support more than 3,000 organizers. The reflex of \"my data is in Europe, so all is well\" is no longer enough to reassure a demanding buyer.",[],{"type":40,"text":47,"spans":58,"direction":24},[],{"type":40,"text":60,"spans":61,"direction":24},"This article gives you a clear framework. You'll see why the topic concerns you directly, what risks you often carry without knowing it, and what a European vendor concretely brings you.",[],{"type":40,"text":47,"spans":63,"direction":24},[],{"type":65,"text":66,"spans":67,"direction":24},"heading2","The topic has moved from the legal department to your desk",[68],{"start":35,"end":69,"type":70},58,"strong",{"type":40,"text":72,"spans":73,"direction":24},"Compliance is no longer a problem reserved for lawyers.",[],{"type":40,"text":75,"spans":76,"direction":24},"For a long time, data protection was seen as a matter for specialists, a technical topic handled far from the organizer. That time is over.",[],{"type":40,"text":47,"spans":78,"direction":24},[],{"type":40,"text":80,"spans":81,"direction":24},"Today, \"where and how is your attendees' data processed?\" appears in vendor approval questionnaires, right alongside certifications or financial guarantees.",[],{"type":40,"text":47,"spans":83,"direction":24},[],{"type":40,"text":85,"spans":86,"direction":24},"Take a common case. You're organizing a corporate convention for a large group. The procurement department sends you a thirty-line questionnaire. Half of it is about security. Where is the data hosted? Who has access to it? What certifications do you hold? If your platform can't answer, you're the one stuck.",[],{"type":40,"text":47,"spans":88,"direction":24},[],{"type":40,"text":90,"spans":91,"direction":24},"Several factors explain this shift.",[],{"type":40,"text":93,"spans":94,"direction":24},"First, the nature of events. An executive seminar, a strategy committee, an internal convention: these formats bring together sensitive data. Executive names, confidential topics, information on VIP guests. The slightest leak can turn into an internal crisis.",[95],{"start":96,"end":97,"type":70},7,27,{"type":40,"text":47,"spans":99,"direction":24},[],{"type":40,"text":101,"spans":102,"direction":24},"Next, regulatory pressure. In 2025, the CNIL issued €486.8 million in fines, and data security is among its main grounds for sanction. The message is clear.",[103],{"start":104,"end":105,"type":70},6,25,{"type":40,"text":47,"spans":107,"direction":24},[],{"type":40,"text":109,"spans":110,"direction":24},"Finally, the cost of an incident. According to the IBM Cost of a Data Breach report, a data breach costs a French company an average of €3.59 million. A figure that speaks to finance departments.",[111,114],{"start":112,"end":113,"type":70},9,33,{"start":115,"end":116,"type":117,"data":118},51,83,"hyperlink",{"link_type":119,"url":120,"target":121},"Web","https://www.ibm.com/reports/data-breach","_blank",{"type":40,"text":47,"spans":123,"direction":24},[],{"type":40,"text":125,"spans":126,"direction":24},"These amounts are no longer trivial. They turn event data security into a board-level topic.",[],{"type":40,"text":47,"spans":128,"direction":24},[],{"type":40,"text":130,"spans":131,"direction":24},"\"A few years ago, the question of hosting came up at the end of the discussion. Today, our clients ask us about it from the very first meeting,\" - Rémi Fontaine, Head of Customer Success at Digitevent.",[132,135,140],{"start":36,"end":133,"type":134},142,"em",{"start":136,"end":137,"type":117,"data":138},147,201,{"link_type":119,"url":139,"target":121},"https://www.linkedin.com/in/r%C3%A9mifontaine/",{"start":136,"end":137,"type":70},{"type":40,"text":47,"spans":142,"direction":24},[],{"type":40,"text":144,"spans":145,"direction":24},"The result? Security moves up the decision chain. It's no longer raised as an afterthought. It determines the choice of platform.",[],{"type":40,"text":47,"spans":147,"direction":24},[],{"type":40,"text":149,"spans":150,"direction":24},"There's also a generational effect. Attendees themselves are more attentive. They read the data collection notices. They question how their contact details will be used. An opaque form drives them away, and drags down your registration rates.",[],{"type":40,"text":152,"spans":153,"direction":24},"In short: compliance is no longer just defensive. It becomes a signal of credibility, perceived by your guests as much as by your clients.",[],{"type":40,"text":47,"spans":155,"direction":24},[],{"type":40,"text":157,"spans":158,"direction":24},"For you, this changes everything. You can no longer delegate this responsibility without understanding it.",[],{"type":40,"text":47,"spans":160,"direction":24},[],{"type":65,"text":162,"spans":163,"direction":24},"Three risks you carry over attendee data",[164],{"start":35,"end":165,"type":70},40,{"type":40,"text":167,"spans":168,"direction":24},"You remain responsible, even when you delegate to a vendor.",[],{"type":40,"text":170,"spans":171,"direction":24},"GDPR is crystal clear on this point. The organizer is the data controller. The platform is only its processor. In other words: legal responsibility falls on you, even if a third party handles the data.",[],{"type":40,"text":47,"spans":173,"direction":24},[],{"type":40,"text":175,"spans":176,"direction":24},"Three concrete risks follow from this: ",[],{"type":40,"text":47,"spans":178,"direction":24},[],{"type":180,"text":181,"spans":182,"direction":24},"heading3","The risk of non-compliance",[183],{"start":35,"end":184,"type":70},26,{"type":40,"text":186,"spans":187,"direction":24},"Consent, purpose, retention period: these obligations fall on you. Collecting data \"just in case,\" or keeping files indefinitely, exposes you directly. Event GDPR compliance starts with a simple discipline: collect only what's necessary.",[],{"type":40,"text":189,"spans":190,"direction":24},"An example? You ask an attendee about their dietary requirements for a dinner. That's legitimate. But do you keep that information three years after the event? That's where you're at fault. The data should have been deleted.",[],{"type":40,"text":47,"spans":192,"direction":24},[],{"type":180,"text":194,"spans":195,"direction":24},"The pure security risk",[196],{"start":35,"end":197,"type":70},22,{"type":40,"text":199,"spans":200,"direction":24},"A leak, poorly controlled access, a password that's too weak. In 2025, the CNIL sanctioned fourteen organizations for insufficient data security, often over basic oversights, like accounts shared between users.",[],{"type":40,"text":202,"spans":203,"direction":24},"This risk is technical, but its causes are human. An Excel file circulating by email. An administrator access left open. A former vendor who keeps their credentials. Every link matters.",[],{"type":40,"text":205,"spans":206,"direction":24},"The good news? These gaps close with simple rules and a tool that enforces them by default. Security isn't a matter of technical genius. It's a matter of method and rigor.",[],{"type":40,"text":47,"spans":208,"direction":24},[],{"type":180,"text":210,"spans":211,"direction":24},"The reputational risk",[212],{"start":35,"end":213,"type":70},21,{"type":40,"text":215,"spans":216,"direction":24},"Losing a vendor approval because the tool doesn't inspire confidence. Or exposing the data of a sensitive event. Your attendees' trust isn't easily repaired.",[],{"type":40,"text":218,"spans":219,"direction":24},"Picture the scene. You announce to five hundred guests that their contact details have leaked. The event was a success. Only the leak will be remembered.",[],{"type":40,"text":221,"spans":222,"direction":24},"Should you give in to fear because of this? No. The right instinct isn't to lock everything down, but to know what you're entrusting, and to whom.",[],{"type":40,"text":224,"spans":225,"direction":24},"Attendee data protection is built first on this judgment. A serious platform helps you minimize the data you collect, document your processing activities, and secure access.",[],{"type":40,"text":227,"spans":228,"direction":24},"A fragile platform leaves you alone to face your obligations.",[],{"type":40,"text":230,"spans":231,"direction":24},"The nuance matters. Not all solutions on the market offer the same level of assurance, and the gaps rarely show up on a sales sheet. They show up in the certifications, the contracts, and the governance of access.",[],{"type":40,"text":233,"spans":234,"direction":24},"This is where a defining choice comes into play.",[],{"type":40,"text":47,"spans":236,"direction":24},[],{"type":65,"text":238,"spans":239,"direction":24},"What a European event software really changes",[240],{"start":35,"end":241,"type":70},45,{"type":40,"text":243,"spans":244,"direction":24},"Sovereignty starts with who you're dealing with, not with a slogan.",[],{"type":40,"text":246,"spans":247,"direction":24},"Choosing European event software isn't about ticking a marketing box. It's about choosing a vendor that contracts under European law, and that builds data protection in by design.",[],{"type":40,"text":47,"spans":249,"direction":24},[],{"type":40,"text":251,"spans":252,"direction":24},"The difference plays out on three levels:",[],{"type":40,"text":47,"spans":254,"direction":24},[],{"type":180,"text":256,"spans":257,"direction":24},"An aligned legal framework",[258],{"start":35,"end":184,"type":70},{"type":40,"text":260,"spans":261,"direction":24},"A European vendor builds its product with GDPR as the starting point. Compliance is native, not bolted on afterward. Your obligations and your vendor's fall under the same framework.",[],{"type":40,"text":263,"spans":264,"direction":24},"This simplifies your contractual relationship. You speak the same regulatory language. If in doubt, you refer to the same text, without translation or risky interpretation.",[],{"type":40,"text":266,"spans":267,"direction":24},"The principle that matters here has a name: privacy by design. In practice, data minimization, retention period settings, and consent management are built into the tool. You don't have to cobble together workarounds. The right settings are offered by default, and you keep control to adapt them for each event.",[],{"type":40,"text":47,"spans":269,"direction":24},[],{"type":180,"text":271,"spans":272,"direction":24},"Verifiable certifications",[273],{"start":35,"end":105,"type":70},{"type":40,"text":275,"spans":276,"direction":24},"A sales promise is worthless without proof. Certifications, on the other hand, are audited. They hold the vendor accountable to a third-party body, not just to you.",[],{"type":40,"text":278,"spans":279,"direction":24},"ISO 27001 certification, a concrete benchmark.",[280],{"start":35,"end":281,"type":70},46,{"type":40,"text":283,"spans":284,"direction":24},"ISO 27001 certification governs information security management. It can't be self-declared. It's earned at the end of a demanding audit, then maintained over time through regular checks.",[],{"type":40,"text":286,"spans":287,"direction":24},"For you, it's a solid benchmark. You're not relying on an intention, but on an internationally recognized standard. ISO 27001 certification covers risk management, access control, and incident response.",[],{"type":40,"text":289,"spans":290,"direction":24},"Digitevent is ISO 27001 certified and documents its commitments in its trust center. There, you'll find proof, not just promises.",[291],{"start":35,"end":113,"type":117,"data":292},{"link_type":119,"url":293,"target":121},"https://www.digitevent.com/en/gdpr-data-protection-security",{"type":40,"text":47,"spans":295,"direction":24},[],{"type":180,"text":297,"spans":298,"direction":24},"Governance and control",[299],{"start":35,"end":197,"type":70},{"type":40,"text":301,"spans":302,"direction":24},"Who has access to what? A good platform gives you fine-grained management of roles and permissions. Each member of your team sees what they need to see, and nothing more.",[],{"type":40,"text":304,"spans":305,"direction":24},"It also guarantees reversibility. Your data remains yours, retrievable the day you leave. No forced retention, no unreadable proprietary format.",[],{"type":40,"text":307,"spans":308,"direction":24},"A European vendor doesn't make you invulnerable. No tool does. But it reduces your exposure, and it speaks the same regulatory language as your clients.",[],{"type":40,"text":310,"spans":311,"direction":24},"In practice, this makes your life easier in tenders. You tick the expected boxes without contortions. You turn a constraint into an argument.",[],{"type":40,"text":47,"spans":313,"direction":24},[],{"type":65,"text":315,"spans":316,"direction":24},"Event GDPR compliance: the right questions before you sign",[317],{"start":35,"end":69,"type":70},{"type":40,"text":319,"spans":320,"direction":24},"A few simple questions reveal how solid a platform really is.",[],{"type":40,"text":47,"spans":322,"direction":24},[],{"type":40,"text":324,"spans":325,"direction":24},"Ask them before entrusting your data. They quickly separate the serious players from the rest.",[],{"type":327,"text":328,"spans":329,"direction":24},"list-item","Where is the vendor based, and under which law are you signing your contract? ",[],{"type":327,"text":331,"spans":332,"direction":24},"Is the platform ISO 27001 certified, and can it prove it? ",[],{"type":327,"text":334,"spans":335,"direction":24},"Who are its subprocessors, and how does it oversee them? ",[],{"type":327,"text":337,"spans":338,"direction":24},"What happens to your database the day you decide to leave?",[],{"type":40,"text":47,"spans":340,"direction":24},[],{"type":40,"text":47,"spans":342,"direction":24},[],{"type":40,"text":344,"spans":345,"direction":24},"These questions aren't paranoid. They reflect what your own clients are already asking you.",[],{"type":40,"text":347,"spans":348,"direction":24},"One point deserves particular attention: reversibility. Many organizers discover too late that they can't cleanly export their history. It's a classic trap.",[349],{"start":350,"end":351,"type":70},41,54,{"type":40,"text":353,"spans":354,"direction":24},"Test it before you commit. Request a full export of your data during the trial phase. If the process is cumbersome, or if the resulting file is unusable, you know what to expect.",[],{"type":40,"text":47,"spans":356,"direction":24},[],{"type":40,"text":358,"spans":359,"direction":24},"Also check the clarity of the data processing agreement. It should specify the security measures, processing instructions, and what happens to the data at the end of the relationship. The CNIL actually reiterated these obligations in 2025, by sanctioning negligent processors.",[360],{"start":361,"end":362,"type":70},11,55,{"type":40,"text":47,"spans":364,"direction":24},[],{"type":40,"text":366,"spans":367,"direction":24},"Also think about the entire chain. Your platform relies on other vendors: messaging, payment, analytics. Each one potentially handles your attendees' data. A serious vendor documents this chain and governs it by contract.",[368],{"start":369,"end":113,"type":70},17,{"type":40,"text":371,"spans":372,"direction":24},"Here's a second useful habit to add to your evaluation checklist.",[],{"type":40,"text":47,"spans":374,"direction":24},[],{"type":327,"text":376,"spans":377,"direction":24},"Demand the security documentation, not just a sales brochure. ",[],{"type":327,"text":379,"spans":380,"direction":24},"Ask how attendee rights are handled, such as access or erasure. ",[],{"type":327,"text":382,"spans":383,"direction":24},"Check the traceability of access to your database. ",[],{"type":327,"text":385,"spans":386,"direction":24},"Clarify the default retention period.",[],{"type":40,"text":47,"spans":388,"direction":24},[],{"type":40,"text":47,"spans":390,"direction":24},[],{"type":40,"text":392,"spans":393,"direction":24},"One last piece of advice. Don't stop at the sales pitch. Ask for the documents. A platform that truly protects your attendees has no reason to hide behind vague statements.",[],{"type":40,"text":47,"spans":395,"direction":24},[],{"type":40,"text":397,"spans":398,"direction":24},"In practice, a half-hour conversation will tell you more than a long product pitch. You'll immediately see who really knows their subject.",[],{"type":40,"text":400,"spans":401,"direction":24},"And if your contact dodges the question? You have your answer.",[],{"type":40,"text":47,"spans":403,"direction":24},[],{"type":65,"text":405,"spans":406,"direction":24},"Event data security: make the right choice",[407],{"start":35,"end":408,"type":70},42,{"type":40,"text":410,"spans":411,"direction":24},"Security and compliance are no longer expert topics. They are selection criteria, on equal footing with features.",[],{"type":40,"text":413,"spans":414,"direction":24},"Remember the essential point. You are the data controller, and that responsibility can't be delegated by handing your data to a third party. Event GDPR compliance binds you, whatever tool you use.",[],{"type":40,"text":47,"spans":416,"direction":24},[],{"type":40,"text":418,"spans":419,"direction":24},"Choosing a European vendor that's compliant and certified means aligning your platform with your own obligations. It also means taking care of the data protection that your attendees' trust depends on.",[],{"type":40,"text":421,"spans":422,"direction":24},"An incident spreads fast. A reputation rebuilds slowly.",[],{"type":40,"text":47,"spans":424,"direction":24},[],{"type":40,"text":426,"spans":427,"direction":24},"Also involve your IT department early on. They know your internal requirements and will speak to the vendor as an equal. This way, you'll avoid unpleasant surprises late in the process, when the contract is almost signed.",[],{"type":40,"text":47,"spans":429,"direction":24},[],{"type":40,"text":431,"spans":432,"direction":24},"So ask the right questions, demand proof, and be wary of promises without certification.",[],{"type":40,"text":47,"spans":434,"direction":24},[],{"type":40,"text":436,"spans":437,"direction":24},"To learn more, discover how we protect and secure your data.",[438],{"start":439,"end":440,"type":117,"data":441},24,59,{"link_type":119,"url":293,"target":121},{"type":40,"text":443,"spans":444,"direction":24},"Want to assess your level of security and compliance? Talk to a Digitevent expert.",[445],{"start":351,"end":446,"type":117,"data":447},81,{"link_type":119,"url":448,"target":121},"https://www.digitevent.com/fr?contact","advice",[451],{"primary":452,"items":460,"id":461,"slice_type":462,"slice_label":8},{"seo_title":453,"seo_meta_descriptions":456},[454],{"type":40,"text":22,"spans":455,"direction":24},[],[457],{"type":40,"text":458,"spans":459,"direction":24},"Event data security: why a GDPR-compliant, ISO 27001-certified European vendor genuinely protects your attendee data.",[],[],"seo$ccd0ccf0-8b01-49c5-96d9-5490000960d2","seo",{"id":464,"lang":465,"type":9,"uid":466},"aowS8BEAACcA0Kc1","fr-fr","securite-souverainete-plateforme-europeenne",[468,1077,1497],{"id":469,"uid":470,"url":8,"type":9,"tags":471,"first_publication_date":472,"slugs":473,"linked_documents":475,"lang":17,"data":476,"_source":1074},"en_blog_article_rgpd-evenementiel-le-top-5-des-astuces","gdpr-events-the-top-5-tips-not-to-be-missed",[12],"2026-07-02T10:07:54+0000",[474],"rgpd-et-evenementiel--le-guide-complet-pour-rester-en-conformite",[],{"distribution":12,"article_title":477,"author_name":25,"publication_date":481,"banner_image":482,"article_content":488,"main_tag":449,"body":1061},[478],{"type":21,"text":479,"spans":480,"direction":24},"GDPR and events: the complete guide to staying compliant",[],"2026-06-02T08:30:00+0000",{"dimensions":483,"alt":484,"copyright":8,"url":485,"id":486,"edit":487},{"width":29,"height":30},"Enterprise-grade security for event management platforms, covering consent, access control, and breach detection to keep your attendee data fully GDPR compliant.","https://images.prismic.io/digi-www/afyG-cBOoF08xt72_Gemini_Generated_Image_s8cudds8cudds8cu-1.webp?auto=format,compress","afyG-cBOoF08xt72",{"x":35,"y":35,"zoom":36,"background":37},[489,492,494,497,499,505,507,511,514,517,519,528,531,535,539,544,549,554,558,560,562,565,567,570,573,575,578,582,587,594,601,606,608,610,622,624,627,630,632,635,640,645,649,654,656,658,661,663,666,671,676,681,685,689,693,698,702,707,712,714,716,719,723,726,728,731,734,736,740,742,745,748,751,753,756,762,764,769,772,774,779,783,787,791,795,800,804,806,808,811,813,819,821,824,826,829,832,834,839,843,847,853,855,857,860,862,865,867,871,873,876,892,895,897,900,904,908,912,916,918,920,923,925,928,931,936,938,941,944,947,950,953,955,957,960,962,967,969,972,975,977,980,984,988,990,992,995,998,1000,1003,1006,1008,1012,1014,1017,1022,1026,1030,1034,1036,1038,1041,1043,1046,1048,1055,1057],{"type":40,"text":490,"spans":491,"direction":24},"You collect data at every event. Registration, badge, networking, post-event follow-up: every interaction involves the processing of personal data.",[],{"type":40,"text":47,"spans":493,"direction":24},[],{"type":40,"text":495,"spans":496,"direction":24},"But how can you be sure you're complying with the General Data Protection Regulation (GDPR)?",[],{"type":40,"text":47,"spans":498,"direction":24},[],{"type":40,"text":500,"spans":501,"direction":24},"Good news: you don't need to be a lawyer to ensure your GDPR compliance for events. You do, however, need to understand the fundamentals, and especially their concrete impact on your organization, and that's what this short practical guide will help you do.",[502],{"start":503,"end":504,"type":70},56,82,{"type":40,"text":47,"spans":506,"direction":24},[],{"type":65,"text":508,"spans":509,"direction":24},"What is GDPR for events?",[510],{"start":35,"end":439,"type":70},{"type":180,"text":512,"spans":513,"direction":24},"What you need to know about GDPR",[],{"type":40,"text":515,"spans":516,"direction":24},"GDPR is a European regulation that governs the collection and processing of personal data within the European Union.",[],{"type":40,"text":47,"spans":518,"direction":24},[],{"type":40,"text":520,"spans":521,"direction":24},"In practice, as an event organizer, you are considered a data controller. Your role? Guarantee the protection of personal data for every attendee.\n",[522,525],{"start":523,"end":524,"type":70},57,72,{"start":526,"end":527,"type":70},99,126,{"type":40,"text":529,"spans":530,"direction":24},"GDPR is built on several key principles. Here are the ones you absolutely need to master:",[],{"type":327,"text":532,"spans":533,"direction":24},"Explicit consent. You must obtain clear agreement from the person concerned before collecting any data. This means informing them about how the data will be used, in a transparent and understandable way.",[534],{"start":35,"end":369,"type":70},{"type":327,"text":536,"spans":537,"direction":24},"Purpose of processing. Every piece of data collected must serve a specific purpose (registration, communication, networking, etc.). You can't collect data \"just in case.\"",[538],{"start":35,"end":197,"type":70},{"type":327,"text":540,"spans":541,"direction":24},"Data minimization. You must only collect the data strictly necessary for your event activity.",[542],{"start":35,"end":543,"type":70},18,{"type":327,"text":545,"spans":546,"direction":24},"The right to access and erasure. Every attendee can exercise their rights: access, modification, the right to be forgotten. You must respond within a maximum of 30 days.",[547],{"start":35,"end":548,"type":70},32,{"type":327,"text":550,"spans":551,"direction":24},"Data security. GDPR requires appropriate data security measures to be put in place. In the event of a breach, notifying the supervisory authority (CNIL) is mandatory within 72 hours.",[552],{"start":35,"end":553,"type":70},14,{"type":327,"text":555,"spans":556,"direction":24},"Data portability. A person can request to retrieve their data in a usable format.",[557],{"start":35,"end":369,"type":70},{"type":40,"text":47,"spans":559,"direction":24},[],{"type":40,"text":47,"spans":561,"direction":24},[],{"type":40,"text":563,"spans":564,"direction":24},"In other words: GDPR requires data management that is structured, secure, and transparent.",[],{"type":40,"text":47,"spans":566,"direction":24},[],{"type":180,"text":568,"spans":569,"direction":24},"Types of data collected at events",[],{"type":40,"text":571,"spans":572,"direction":24},"In practice, the events industry handles a wide variety of personal data.",[],{"type":40,"text":47,"spans":574,"direction":24},[],{"type":40,"text":576,"spans":577,"direction":24},"Here are the main types of data collected:",[],{"type":327,"text":579,"spans":580,"direction":24},"Registration data: last name, first name, email, phone number, company, job title, etc. ",[581],{"start":35,"end":543,"type":70},{"type":327,"text":583,"spans":584,"direction":24},"Behavioral data: session attendance, interactions, networking, etc. ",[585],{"start":35,"end":586,"type":70},16,{"type":327,"text":588,"spans":589,"direction":24},"Attendance data: badge scans, check-in, QR code, etc. ",[590,591],{"start":35,"end":586,"type":70},{"start":369,"end":197,"type":117,"data":592},{"link_type":119,"url":593,"target":121},"https://www.digitevent.com/fr/blog/badge-evenementiel",{"type":327,"text":595,"spans":596,"direction":24},"Data from digital tools: CRM, event platform, mobile app, etc. ",[597,598],{"start":35,"end":439,"type":70},{"start":281,"end":503,"type":117,"data":599},{"link_type":119,"url":600,"target":121},"https://www.digitevent.com/en/blog/why-adopt-event-app",{"type":327,"text":602,"spans":603,"direction":24},"Marketing data: preferences, interests, post-event engagement, etc. ",[604],{"start":35,"end":605,"type":70},15,{"type":40,"text":47,"spans":607,"direction":24},[],{"type":40,"text":47,"spans":609,"direction":24},[],{"type":40,"text":611,"spans":612,"direction":24},"For example, in practice, at a trade show or a corporate seminar, scanning a badge through an app constitutes the collection of personal data. This data can then be used by an exhibitor or a sales rep as part of a customer relationship. And that's precisely where GDPR compliance becomes strategic.",[613,617],{"start":614,"end":350,"type":117,"data":615},31,{"link_type":119,"url":616,"target":121},"https://www.digitevent.com/en/blog/how-to-organize-a-trade-show",{"start":618,"end":619,"type":117,"data":620},47,64,{"link_type":119,"url":621,"target":121},"https://www.digitevent.com/en/blog/organize-corporate-seminar-guide",{"type":40,"text":47,"spans":623,"direction":24},[],{"type":180,"text":625,"spans":626,"direction":24},"What impact does GDPR have on events?",[],{"type":40,"text":628,"spans":629,"direction":24},"GDPR isn't just a legal constraint: it's also a performance lever for your event strategy.",[],{"type":40,"text":47,"spans":631,"direction":24},[],{"type":40,"text":633,"spans":634,"direction":24},"In practice, what does this change for you?",[],{"type":327,"text":636,"spans":637,"direction":24},"Better data quality. You collect less, but better. The data is more reliable and more usable.",[638],{"start":35,"end":639,"type":70},20,{"type":327,"text":641,"spans":642,"direction":24},"More qualified contact lists. No more massive, low-engagement lists. Instead, contacts who are genuinely interested.",[643],{"start":35,"end":644,"type":70},29,{"type":327,"text":646,"spans":647,"direction":24},"Stronger trust. Transparency, respect for privacy, clarity: all factors that improve the user experience.",[648],{"start":35,"end":605,"type":70},{"type":327,"text":650,"spans":651,"direction":24},"More structured internal processes. GDPR pushes you to formalize your practices: consent management, retention, security, data governance.",[652],{"start":35,"end":653,"type":70},35,{"type":40,"text":47,"spans":655,"direction":24},[],{"type":40,"text":47,"spans":657,"direction":24},[],{"type":40,"text":659,"spans":660,"direction":24},"GDPR thus transforms the way you design your events.",[],{"type":40,"text":47,"spans":662,"direction":24},[],{"type":65,"text":664,"spans":665,"direction":24},"Cheat sheet: what are the GDPR obligations for an event?",[],{"type":40,"text":667,"spans":668,"direction":24},"Here are the essential legal obligations to meet to ensure your GDPR compliance for events:",[669],{"start":670,"end":165,"type":70},13,{"type":327,"text":672,"spans":673,"direction":24},"Obtain explicit consent from attendees. Before collecting any personal data, you must obtain clear, freely given, and informed agreement.",[674],{"start":35,"end":675,"type":70},39,{"type":327,"text":677,"spans":678,"direction":24},"Define a legal basis for each processing activity. Consent, contract performance, legitimate interest: every data processing activity must rest on a legal basis.",[679],{"start":35,"end":680,"type":70},50,{"type":327,"text":682,"spans":683,"direction":24},"Inform transparently. You must provide clear information on the purpose, retention period, and use of the data collected.",[684],{"start":35,"end":213,"type":70},{"type":327,"text":686,"spans":687,"direction":24},"Limit collection to what's strictly necessary. Only collect the data that's useful for organizing your event.",[688],{"start":35,"end":281,"type":70},{"type":327,"text":690,"spans":691,"direction":24},"Guarantee data security. You must implement protection and security measures suited to the risks.",[692],{"start":35,"end":439,"type":70},{"type":327,"text":694,"spans":695,"direction":24},"Enable the exercise of rights. Access, rectification, erasure, the right to object: every person concerned must be able to exercise their rights easily.",[696],{"start":35,"end":697,"type":70},30,{"type":327,"text":699,"spans":700,"direction":24},"Keep a record of processing activities. You must document all processing operations carried out as part of your events.",[701],{"start":35,"end":675,"type":70},{"type":327,"text":703,"spans":704,"direction":24},"Report any data breach. In the event of a leak or incident, notifying the CNIL is mandatory within 72 hours.",[705],{"start":35,"end":706,"type":70},23,{"type":327,"text":708,"spans":709,"direction":24},"Govern vendors and partners. Your event vendors must also comply with GDPR (contract, liability, security).",[710],{"start":35,"end":711,"type":70},28,{"type":40,"text":47,"spans":713,"direction":24},[],{"type":40,"text":47,"spans":715,"direction":24},[],{"type":40,"text":717,"spans":718,"direction":24},"Want to dig deeper into the topic? Here are the tips to help you stay fully compliant with GDPR when organizing your events.\n",[],{"type":65,"text":720,"spans":721,"direction":24},"6 keys to ensuring your events comply with GDPR",[722],{"start":35,"end":618,"type":70},{"type":40,"text":724,"spans":725,"direction":24},"Complying with GDPR shouldn't slow down your events. Quite the opposite: it's a lever to make them more effective, more reliable, and more professional. Here are the keys to doing that.",[],{"type":40,"text":47,"spans":727,"direction":24},[],{"type":180,"text":729,"spans":730,"direction":24},"Obtain clear and transparent consent",[],{"type":40,"text":732,"spans":733,"direction":24},"Without explicit consent, no processing of personal data is compliant.",[],{"type":40,"text":47,"spans":735,"direction":24},[],{"type":40,"text":737,"spans":738,"direction":24},"In practice, you must clearly inform every attendee: why their data is being collected, how it will be used, and for how long. In other words: no gray areas, no ambiguity.",[739],{"start":197,"end":115,"type":70},{"type":40,"text":47,"spans":741,"direction":24},[],{"type":40,"text":743,"spans":744,"direction":24},"Your data collection must rest on a legal basis that is transparent and understandable.",[],{"type":40,"text":746,"spans":747,"direction":24},"In fact, if you're not compliant, the risks are very real. The CNIL provides for penalties of up to €20 million, or 4% of global annual revenue. ",[],{"type":40,"text":749,"spans":750,"direction":24},"Protecting personal data is therefore not an option, but a genuine responsibility.",[],{"type":40,"text":47,"spans":752,"direction":24},[],{"type":180,"text":754,"spans":755,"direction":24},"Make sure the data you collect is GDPR-compliant",[],{"type":40,"text":757,"spans":758,"direction":24},"As you'll have gathered: to be GDPR-compliant, your collection of personal data must rest on one key principle: the explicit consent of the individual.",[759],{"start":760,"end":761,"type":70},116,150,{"type":40,"text":47,"spans":763,"direction":24},[],{"type":40,"text":765,"spans":766,"direction":24},"In practice, this comes down to one essential point: opt-in. Opt-in means the attendee voluntarily chooses to share their data with you and agrees to its use.\n",[767],{"start":768,"end":440,"type":70},53,{"type":40,"text":770,"spans":771,"direction":24},"But be careful: this consent must be freely given, informed, and above all unbiased.",[],{"type":40,"text":47,"spans":773,"direction":24},[],{"type":40,"text":775,"spans":776,"direction":24},"Here are the best practices to apply:",[777],{"start":670,"end":778,"type":70},36,{"type":327,"text":780,"spans":781,"direction":24},"A mandatory, clear opt-in. The attendee must check a box themselves to give their consent.",[782],{"start":35,"end":184,"type":70},{"type":327,"text":784,"spans":785,"direction":24},"No pre-checked boxes. No consent should ever be assumed.",[786],{"start":35,"end":213,"type":70},{"type":327,"text":788,"spans":789,"direction":24},"A recommended double opt-in. An email confirmation strengthens proof of consent.",[790],{"start":35,"end":711,"type":70},{"type":327,"text":792,"spans":793,"direction":24},"Proof of consent kept on record. You must be able to demonstrate at any time that the person agreed.",[794],{"start":35,"end":548,"type":70},{"type":327,"text":796,"spans":797,"direction":24},"A clear distinction between customers and prospects. Communication rules differ depending on status.",[798],{"start":35,"end":799,"type":70},52,{"type":327,"text":801,"spans":802,"direction":24},"Granular choices. Newsletter, invitations, partners: each use must be covered by its own specific agreement.",[803],{"start":35,"end":369,"type":70},{"type":40,"text":47,"spans":805,"direction":24},[],{"type":40,"text":47,"spans":807,"direction":24},[],{"type":40,"text":809,"spans":810,"direction":24},"Here's an example of compliant wording for a registration form: \"I agree that my data may be used for commercial communications.\" ",[],{"type":40,"text":47,"spans":812,"direction":24},[],{"type":40,"text":814,"spans":815,"direction":24},"Once consent is obtained, you can use the data within the defined scope. But as soon as the use changes, new agreement becomes necessary.",[816],{"start":817,"end":818,"type":70},77,136,{"type":40,"text":47,"spans":820,"direction":24},[],{"type":40,"text":822,"spans":823,"direction":24},"And above all: you must always let attendees easily unsubscribe from your communications.",[],{"type":40,"text":47,"spans":825,"direction":24},[],{"type":180,"text":827,"spans":828,"direction":24},"Properly inform your attendees about their data",[],{"type":40,"text":830,"spans":831,"direction":24},"Informing your attendees is crucial to complying with GDPR for events. But you may be wondering exactly what you need to communicate? ",[],{"type":40,"text":47,"spans":833,"direction":24},[],{"type":40,"text":835,"spans":836,"direction":24},"Here are the mandatory disclosures to include in your forms, registration pages, or emails:",[837],{"start":670,"end":838,"type":70},34,{"type":327,"text":840,"spans":841,"direction":24},"The purpose of processing. Why are you collecting this data (registration, event management, communication, etc.)?",[842],{"start":35,"end":184,"type":70},{"type":327,"text":844,"spans":845,"direction":24},"The retention period. How long will the data be kept?",[846],{"start":35,"end":213,"type":70},{"type":327,"text":848,"spans":849,"direction":24},"Attendees' rights. Access, rectification, erasure, the right to object: every person concerned must be able to act on their data.",[850,851],{"start":35,"end":543,"type":70},{"start":115,"end":852,"type":70},70,{"type":40,"text":47,"spans":854,"direction":24},[],{"type":40,"text":47,"spans":856,"direction":24},[],{"type":40,"text":858,"spans":859,"direction":24},"In practice, your message must be simple, accessible, and understandable within a few seconds.",[],{"type":40,"text":47,"spans":861,"direction":24},[],{"type":40,"text":863,"spans":864,"direction":24},"For example: \"Your data is used to manage your registration for this event and to send you related information. You can access, modify, or request the deletion of your data at any time.\"",[],{"type":40,"text":47,"spans":866,"direction":24},[],{"type":40,"text":868,"spans":869,"direction":24},"And don't forget to include a link to your privacy policy either. This document or web page must detail all of your practices regarding the protection of personal data: data processing, security, sharing with vendors, user rights, etc. ",[870],{"start":697,"end":523,"type":70},{"type":40,"text":47,"spans":872,"direction":24},[],{"type":180,"text":874,"spans":875,"direction":24},"Manage and control all attendee data in one place",[],{"type":40,"text":877,"spans":878,"direction":24},"To ensure compliant data management, one rule applies: centralize. In other words, gather all the data collected (registration, attendance, interactions, networking) within a single event platform. This way, you stay in control of data processing at every stage.\n",[879,881,884,889],{"start":116,"end":880,"type":70},97,{"start":882,"end":883,"type":70},98,112,{"start":885,"end":886,"type":117,"data":887},182,196,{"link_type":119,"url":888,"target":121},"https://www.digitevent.com/en/blog/event-management-platform",{"start":890,"end":891,"type":70},166,197,{"type":40,"text":893,"spans":894,"direction":24},"But be careful: you can't freely share your attendees' data. Even in an event context, the rule is clear: no data sharing without the explicit consent of the person concerned. Sharing with an exhibitor, passing data to a partner, post-event commercial use: everything must be approved in advance, through a specific opt-in. ",[],{"type":40,"text":47,"spans":896,"direction":24},[],{"type":40,"text":898,"spans":899,"direction":24},"And that's where technology becomes useful. A centralized solution lets you, among other things:",[],{"type":327,"text":901,"spans":902,"direction":24},"Ensure consent traceability: who agreed to what, when, and in what context.",[903],{"start":35,"end":711,"type":70},{"type":327,"text":905,"spans":906,"direction":24},"Easily manage attendees' rights: access, modification, deletion of data, etc.",[907],{"start":35,"end":548,"type":70},{"type":327,"text":909,"spans":910,"direction":24},"Automate data deletion based on the defined retention period",[911],{"start":35,"end":197,"type":70},{"type":327,"text":913,"spans":914,"direction":24},"Secure access and usage to limit the risk of leaks or non-compliant use.",[915],{"start":35,"end":706,"type":70},{"type":40,"text":47,"spans":917,"direction":24},[],{"type":40,"text":47,"spans":919,"direction":24},[],{"type":40,"text":921,"spans":922,"direction":24},"This way, you move from scattered management to management that's secure, controlled, and compliant.",[],{"type":40,"text":47,"spans":924,"direction":24},[],{"type":180,"text":926,"spans":927,"direction":24},"Structure your data governance (with or without a DPO)",[],{"type":40,"text":929,"spans":930,"direction":24},"You process personal data at every event. But who's actually responsible internally, within your company or your event agency?\n",[],{"type":40,"text":932,"spans":933,"direction":24},"That's precisely the role of the Data Protection Officer (DPO). Their mission is simple: oversee data collection and processing, guarantee its protection, and ensure compliance with the General Data Protection Regulation.",[934],{"start":113,"end":935,"type":70},62,{"type":40,"text":47,"spans":937,"direction":24},[],{"type":40,"text":939,"spans":940,"direction":24},"In practice, the DPO handles several key areas:",[],{"type":327,"text":942,"spans":943,"direction":24},"Validating collection processes",[],{"type":327,"text":945,"spans":946,"direction":24},"Monitoring data usage",[],{"type":327,"text":948,"spans":949,"direction":24},"Managing risks and incidents",[],{"type":327,"text":951,"spans":952,"direction":24},"Supporting teams on best practices",[],{"type":40,"text":47,"spans":954,"direction":24},[],{"type":40,"text":47,"spans":956,"direction":24},[],{"type":40,"text":958,"spans":959,"direction":24},"Note that appointing a DPO isn't systematically mandatory. It's required in certain specific cases: for public bodies, companies carrying out large-scale data processing, or organizations handling sensitive or high-risk data.",[],{"type":40,"text":47,"spans":961,"direction":24},[],{"type":40,"text":963,"spans":964,"direction":24},"If none of these cases apply to you, you can simply designate an internal GDPR point of contact. This role can be filled by a marketing manager, an event project manager, or an IT manager. Their goal remains the same as a DPO's: structure your organization and ensure compliant data management.",[965],{"start":799,"end":966,"type":70},95,{"type":40,"text":47,"spans":968,"direction":24},[],{"type":180,"text":970,"spans":971,"direction":24},"Optimize your existing data",[],{"type":40,"text":973,"spans":974,"direction":24},"Already have a database? Good news: you can keep using it. But on one condition: that it's GDPR-compliant. In other words, you can't use your existing data without being able to justify how it's used.",[],{"type":40,"text":47,"spans":976,"direction":24},[],{"type":40,"text":978,"spans":979,"direction":24},"Two elements are essential:",[],{"type":327,"text":981,"spans":982,"direction":24},"The purpose of the database. Why was this data collected? In what context can it be used today?",[983],{"start":35,"end":711,"type":70},{"type":327,"text":985,"spans":986,"direction":24},"Proof of consent. You must be able to state when consent was obtained, in what context, and for what type of use.",[987],{"start":35,"end":369,"type":70},{"type":40,"text":47,"spans":989,"direction":24},[],{"type":40,"text":47,"spans":991,"direction":24},[],{"type":40,"text":993,"spans":994,"direction":24},"In practice, this means doing a sorting and qualification exercise. Clean out outdated data, remove contacts without clear consent, check the retention period, and segment your lists according to authorized uses.",[],{"type":40,"text":996,"spans":997,"direction":24},"You may end up with a smaller list, but one you can use in full compliance.",[],{"type":40,"text":47,"spans":999,"direction":24},[],{"type":65,"text":1001,"spans":1002,"direction":24},"How do you guarantee the security of your event data?",[],{"type":40,"text":1004,"spans":1005,"direction":24},"Collecting data is one thing. Protecting it is another. And on this point, GDPR sets a high bar for data security. This is where the choice of your event management tool becomes strategic.",[],{"type":40,"text":47,"spans":1007,"direction":24},[],{"type":40,"text":1009,"spans":1010,"direction":24},"To guarantee GDPR-compliant protection of personal data, your platform must include several essential standards.",[1011],{"start":670,"end":362,"type":70},{"type":40,"text":47,"spans":1013,"direction":24},[],{"type":40,"text":1015,"spans":1016,"direction":24},"Here are the elements to check first:",[],{"type":327,"text":1018,"spans":1019,"direction":24},"Data hosting within the European Union, for example through infrastructure such as AWS Europe. This guarantees a level of protection consistent with European regulations.",[1020],{"start":35,"end":1021,"type":70},38,{"type":327,"text":1023,"spans":1024,"direction":24},"Data encryption (HTTPS / TLS). This way, data is protected during exchanges and connections.",[1025],{"start":35,"end":697,"type":70},{"type":327,"text":1027,"spans":1028,"direction":24},"Fine-grained access management (roles and permissions). Each user only accesses the data they need, limiting the risk of internal errors or leaks.",[1029],{"start":35,"end":362,"type":70},{"type":327,"text":1031,"spans":1032,"direction":24},"Logs and an activity history. You know who accessed what, when, and how. This is a key point in the event of an audit or incident.",[1033],{"start":35,"end":644,"type":70},{"type":40,"text":47,"spans":1035,"direction":24},[],{"type":40,"text":47,"spans":1037,"direction":24},[],{"type":40,"text":1039,"spans":1040,"direction":24},"Also keep in mind that a truly GDPR-compliant platform should let you govern data sharing with your vendors, and automate certain secure data management rules (handling modification or deletion requests, for example).",[],{"type":40,"text":47,"spans":1042,"direction":24},[],{"type":40,"text":1044,"spans":1045,"direction":24},"And don't forget that the regulations and laws enforced by the CNIL are often updated. So remember to regularly check that the guidance issued by the CNIL matches your practices and your privacy policy.",[],{"type":40,"text":47,"spans":1047,"direction":24},[],{"type":40,"text":1049,"spans":1050,"direction":24},"Need an event platform that's 100% GDPR-compliant, intuitive, and powerful? Discover all of Digitevent's commitments to data protection and security.",[1051],{"start":1052,"end":1053,"type":117,"data":1054},76,148,{"link_type":119,"url":293,"target":121},{"type":40,"text":47,"spans":1056,"direction":24},[],{"type":40,"text":1058,"spans":1059,"direction":24},"V2 - 07/05/2026",[1060],{"start":35,"end":605,"type":70},[1062],{"primary":1063,"items":1072,"id":1073,"slice_type":462,"slice_label":8},{"seo_title":1064,"seo_meta_descriptions":1068},[1065],{"type":40,"text":1066,"spans":1067,"direction":24},"GDPR for events: obligations and best practices to follow",[],[1069],{"type":40,"text":1070,"spans":1071,"direction":24},"How do you make your events GDPR-compliant? Invitations, data security, obligations: a complete, practical guide to help you",[],[],"seo$3babe631-12ae-458a-a900-6eed66510c8e",{"id":1075,"lang":465,"type":9,"uid":1076},"akYmuBIAACwAyuDK","rgpd-evenementiel-le-top-5-des-astuces",{"id":1078,"uid":1079,"url":8,"type":9,"tags":1080,"first_publication_date":1081,"slugs":1082,"linked_documents":1084,"lang":17,"data":1085,"_source":1494},"en_blog_article_plateforme-evenementielle-appel-offres","event-management-platform-rfp",[12],"2026-07-02T10:08:00+0000",[1083],"plateforme-evenementielle-les-10-cles-de-votre-appel-doffres",[],{"distribution":12,"article_title":1086,"author_name":25,"publication_date":1090,"banner_image":1091,"article_content":1098,"main_tag":449,"body":1481},[1087],{"type":21,"text":1088,"spans":1089,"direction":24},"Event platform: the 10 keys to your RFP",[],"2026-06-16T09:00:00+0000",{"dimensions":1092,"alt":1094,"copyright":8,"url":1095,"id":1096,"edit":1097},{"width":29,"height":1093},604,"Three colleagues analyzing an event RFP in a modern open space, with RFP documents, tablets, and data screens in the background.","https://images.prismic.io/digi-www/ajETmY1P9HI4Ujwl_Gemini_Generated_Image_ivkyiuivkyiuivky-1.webp?auto=format,compress","ajETmY1P9HI4Ujwl",{"x":35,"y":35,"zoom":36,"background":37},[1099,1104,1106,1109,1111,1114,1116,1119,1121,1124,1128,1131,1133,1137,1139,1143,1146,1148,1151,1153,1156,1158,1162,1169,1171,1174,1176,1179,1181,1185,1188,1190,1195,1197,1200,1202,1205,1209,1212,1214,1217,1219,1223,1230,1232,1235,1237,1241,1243,1249,1251,1255,1258,1260,1265,1267,1270,1272,1275,1277,1281,1284,1286,1292,1294,1297,1299,1302,1304,1308,1311,1313,1316,1318,1321,1323,1326,1330,1333,1336,1338,1342,1345,1347,1350,1352,1355,1357,1368,1370,1373,1375,1378,1380,1385,1388,1390,1393,1395,1398,1400,1403,1405,1409,1412,1414,1417,1419,1422,1424,1432,1434,1437,1439,1444,1447,1449,1452,1454,1457,1459,1474,1476,1479],{"type":40,"text":1100,"spans":1101,"direction":24},"Choosing an event platform is rarely decided on signing day. The verdict is prepared well before, in a document that's often underestimated: your event RFP. Poorly framed, it leads you to the wrong event platform. Well built, it becomes the most powerful lever to align your teams, compare vendors on objective criteria, and secure a strategic investment.",[1102],{"start":1103,"end":184,"type":70},12,{"type":40,"text":47,"spans":1105,"direction":24},[],{"type":40,"text":1107,"spans":1108,"direction":24},"At Digitevent, we support more than 3,000 organizers of professional events and respond to hundreds of RFPs every year. Some are excellent: short, prioritized, driven by business objectives. Others are completely unusable: 400 flat lines of features, no mention of security, not a word about support.",[],{"type":40,"text":47,"spans":1110,"direction":24},[],{"type":40,"text":1112,"spans":1113,"direction":24},"The gap between the two isn't a question of resources. It's a question of method.",[],{"type":40,"text":47,"spans":1115,"direction":24},[],{"type":40,"text":1117,"spans":1118,"direction":24},"This article gives you the 10 concrete keys to choosing your next event platform through a workable RFP. Three steps: frame your need before writing a single specification, write clear functional and technical requirements, and evaluate vendors with the rigor such a strategic investment deserves.",[],{"type":40,"text":47,"spans":1120,"direction":24},[],{"type":40,"text":1122,"spans":1123,"direction":24},"By the end, you'll have a repeatable method for your next consultation.\n",[],{"type":65,"text":1125,"spans":1126,"direction":24},"Framing your event platform choice first",[1127],{"start":35,"end":165,"type":70},{"type":40,"text":1129,"spans":1130,"direction":24},"A good RFP doesn't start with a feature.",[],{"type":40,"text":47,"spans":1132,"direction":24},[],{"type":40,"text":1134,"spans":1135,"direction":24},"It starts with a question: why are we changing platforms? This question seems obvious. Yet it's missing from one RFP out of two. The result? A consultation run without direction, vendors answering off the mark, and a final choice dictated by price for lack of a better compass.",[1136],{"start":97,"end":523,"type":134},{"type":40,"text":47,"spans":1138,"direction":24},[],{"type":180,"text":1140,"spans":1141,"direction":24},"Key 1 - Define your business objectives first",[1142],{"start":35,"end":241,"type":70},{"type":40,"text":1144,"spans":1145,"direction":24},"An RFP for an event platform serves a project, not a specifications document. Before drafting a single requirement, define what you expect from the future event platform: qualified lead generation, customer loyalty, post-event sales performance, improved attendee experience, measurable ROI.",[],{"type":40,"text":47,"spans":1147,"direction":24},[],{"type":40,"text":1149,"spans":1150,"direction":24},"Pick out one or two primary objectives. Everything else becomes secondary.",[],{"type":40,"text":47,"spans":1152,"direction":24},[],{"type":40,"text":1154,"spans":1155,"direction":24},"Then quantify these objectives with concrete indicators: registration rate, attendance rate, post-event NPS, sales leads generated. And document what happens if you keep your current stack. The cost of inaction is often higher than the cost of change.",[],{"type":40,"text":47,"spans":1157,"direction":24},[],{"type":180,"text":1159,"spans":1160,"direction":24},"Key 2 - Map your internal stakeholders",[1161],{"start":35,"end":1021,"type":70},{"type":40,"text":1163,"spans":1164,"direction":24},"An event platform RFP is never a single team's job. According to Forrester's 2026 study on the state of B2B buying, a B2B software decision involves an average of 13 internal stakeholders and 9 external ones. Better to anticipate them.",[1165],{"start":619,"end":1166,"type":117,"data":1167},114,{"link_type":119,"url":1168,"target":121},"https://www.forrester.com/press-newsroom/forrester-2026-the-state-of-business-buying/",{"type":40,"text":47,"spans":1170,"direction":24},[],{"type":40,"text":1172,"spans":1173,"direction":24},"Identify every stakeholder upfront: marketing, communications, IT, procurement, legal, DPO, HR for internal events, finance for the budget. Each has their own \"must haves\". IT will require SSO SAML and data localization. Marketing will want deep customization. Legal will ask for a DPA ready to sign.",[],{"type":40,"text":47,"spans":1175,"direction":24},[],{"type":40,"text":1177,"spans":1178,"direction":24},"Name a single sponsor. Only they decide in case of disagreement. Without this arbiter, your RFP risks lacking coherence.",[],{"type":40,"text":47,"spans":1180,"direction":24},[],{"type":180,"text":1182,"spans":1183,"direction":24},"Key 3 - Define your real event scope",[1184],{"start":35,"end":778,"type":70},{"type":40,"text":1186,"spans":1187,"direction":24},"How many events do you organize per year? What sizes? In-person, hybrid, remote? Single-site or multi-country? What's the peak concurrent usage?",[],{"type":40,"text":47,"spans":1189,"direction":24},[],{"type":40,"text":1191,"spans":1192,"direction":24},"This data determines the fit of an event platform. A vendor built for 50 internal seminars a year won't properly handle a 5,000-attendee convention. Conversely, oversizing your platform will cost you dearly for nothing.",[1193],{"start":653,"end":1194,"type":70},49,{"type":40,"text":47,"spans":1196,"direction":24},[],{"type":40,"text":1198,"spans":1199,"direction":24},"The French event industry is worth €5.5 billion in investment in 2024-2025, up 17.6% according to Unimev's 2025 Event Data Book. Volumes are rising, and so are requirements. Plan for growth over at least 24 months. A tool sized for today will be too narrow tomorrow.",[],{"type":40,"text":47,"spans":1201,"direction":24},[],{"type":40,"text":1203,"spans":1204,"direction":24},"Now you're ready to write. This is where everything can still go wrong.\n",[],{"type":65,"text":1206,"spans":1207,"direction":24},"Specifying without turning into a shopping list",[1208],{"start":35,"end":618,"type":70},{"type":40,"text":1210,"spans":1211,"direction":24},"This is the phase that derails most RFPs.",[],{"type":40,"text":47,"spans":1213,"direction":24},[],{"type":40,"text":1215,"spans":1216,"direction":24},"The natural reflex is to stack up expected features. 300 lines weighted equally, ambiguous questions, checkboxes. Serious vendors give up. The others answer \"Yes\" to everything. You end up drowning in unusable responses.",[],{"type":40,"text":47,"spans":1218,"direction":24},[],{"type":180,"text":1220,"spans":1221,"direction":24},"Key 4 - Prioritize requirements as Must / Should / Nice",[1222],{"start":35,"end":362,"type":70},{"type":40,"text":1224,"spans":1225,"direction":24},"A workable event specifications document ranks needs into three levels: Must, Should, Nice. And it standardizes the expected responses, for example Yes, Configuration, Customization, Roadmap, Not supported.",[1226,1228],{"start":524,"end":1227,"type":134},90,{"start":1053,"end":1229,"type":134},205,{"type":40,"text":47,"spans":1231,"direction":24},[],{"type":40,"text":1233,"spans":1234,"direction":24},"This hierarchy changes everything. It forces your team to decide internally before asking the question. It stops vendors from answering \"Yes\" across the board. It gives you a scoring grid you can use right away.",[],{"type":40,"text":47,"spans":1236,"direction":24},[],{"type":40,"text":1238,"spans":1239,"direction":24},"Cover the essential building blocks of professional event management software: registration, ticketing, event website, attendee app, check-in, badges, networking, communication, reporting. For every Must requirement, ask for a screenshot or a targeted demonstration. That's what separates promises from actual delivery.",[1240],{"start":799,"end":817,"type":70},{"type":40,"text":47,"spans":1242,"direction":24},[],{"type":40,"text":1244,"spans":1245,"direction":24},"A concrete example: for the registration block, don't just ask \"does the platform handle registrations?\". Ask whether it handles your specific cases. Named invitations, access codes, conditional forms, multiple pricing tiers, multi-stage validation, payments in several currencies. It's the depth of the answer that will separate serious vendors from the rest. Every ambiguous line in your event specifications will be exploited commercially. Be precise.",[1246],{"start":1247,"end":1248,"type":134},63,104,{"type":40,"text":47,"spans":1250,"direction":24},[],{"type":180,"text":1252,"spans":1253,"direction":24},"Key 5 - Address security and GDPR in the first section",[1254],{"start":35,"end":351,"type":70},{"type":40,"text":1256,"spans":1257,"direction":24},"Security isn't an appendix item. It opens your RFP.",[],{"type":40,"text":47,"spans":1259,"direction":24},[],{"type":40,"text":1261,"spans":1262,"direction":24},"Data localization within the European Union, encryption at rest and in transit, authentication (SSO SAML, MFA), fine-grained role management, audit logs, identified subprocessors, certifications (ISO 27001, SOC 2, HDS if sensitive data). These elements belong at the start of the document, not the end.",[1263],{"start":886,"end":1229,"type":117,"data":1264},{"link_type":119,"url":293,"target":121},{"type":40,"text":47,"spans":1266,"direction":24},[],{"type":40,"text":1268,"spans":1269,"direction":24},"Require a DPA ready to sign as early as the response phase. Ask for the full list of subprocessors. Check the terms for data reversibility in case the contract ends.",[],{"type":40,"text":47,"spans":1271,"direction":24},[],{"type":40,"text":1273,"spans":1274,"direction":24},"An event platform processes thousands of pieces of personal data. You are the data controller. Not the vendor.",[],{"type":40,"text":47,"spans":1276,"direction":24},[],{"type":180,"text":1278,"spans":1279,"direction":24},"Key 6 - Measure the depth of integrations",[1280],{"start":35,"end":350,"type":70},{"type":40,"text":1282,"spans":1283,"direction":24},"A platform isolated from your information system doesn't create value. It destroys it.",[],{"type":40,"text":47,"spans":1285,"direction":24},[],{"type":40,"text":1287,"spans":1288,"direction":24},"List the expected integrations precisely: Salesforce, HubSpot, Marketo, Pardot, Workday, Slack, Teams, enterprise SSO. Ask for the technical documentation of the public API. Check webhook availability. Ask about custom field governance and two-way data synchronization.",[1289],{"start":543,"end":697,"type":117,"data":1290},{"link_type":119,"url":1291,"target":121},"https://www.digitevent.com/en/integrations",{"type":40,"text":47,"spans":1293,"direction":24},[],{"type":40,"text":1295,"spans":1296,"direction":24},"Ask for customer integration cases on a stack comparable to yours. A vendor that can't name a reference close to your context has probably never handled this in production.",[],{"type":40,"text":47,"spans":1298,"direction":24},[],{"type":40,"text":1300,"spans":1301,"direction":24},"A company uses dozens of SaaS applications on average. Your future platform is just one piece of that whole. It has to talk to the others without friction.",[],{"type":40,"text":47,"spans":1303,"direction":24},[],{"type":180,"text":1305,"spans":1306,"direction":24},"Key 7 - Demand a clear framework for data and KPIs",[1307],{"start":35,"end":680,"type":70},{"type":40,"text":1309,"spans":1310,"direction":24},"Many vendors promise \"powerful reporting\". Few say what they actually measure.",[],{"type":40,"text":47,"spans":1312,"direction":24},[],{"type":40,"text":1314,"spans":1315,"direction":24},"List the expected indicators: registration rate, conversion rate, no-show rate, attendee app engagement, post-event satisfaction, qualified lead generation. Ask for dashboard examples. Specify the expected export frequency and accepted formats (CSV, API data, BI).",[],{"type":40,"text":47,"spans":1317,"direction":24},[],{"type":40,"text":1319,"spans":1320,"direction":24},"Also ask about outcomes, not just outputs. How many qualified leads were produced for their previous clients? What change in attendance rate? What reduction in cost per attendee? A platform that can't answer these questions doesn't have enough usable track record.",[],{"type":40,"text":47,"spans":1322,"direction":24},[],{"type":40,"text":1324,"spans":1325,"direction":24},"You now have a solid specifications document. What's left is choosing the right vendor behind it.\n",[],{"type":65,"text":1327,"spans":1328,"direction":24},"Evaluating vendors without getting swept away",[1329],{"start":35,"end":241,"type":70},{"type":40,"text":1331,"spans":1332,"direction":24},"This is where the decision is won or lost.",[],{"type":40,"text":1334,"spans":1335,"direction":24},"Too many organizations spend 80% of their energy writing the RFP and only 20% on evaluation. This balance is backwards. A well-rehearsed demo can easily hide a product's weaknesses. Three keys help you dig beneath the surface.",[],{"type":40,"text":47,"spans":1337,"direction":24},[],{"type":180,"text":1339,"spans":1340,"direction":24},"Key 8 - Weight support and human accompaniment heavily",[1341],{"start":35,"end":351,"type":70},{"type":40,"text":1343,"spans":1344,"direction":24},"An event tolerates neither downtime nor a ticket sitting unanswered for 24 hours.",[],{"type":40,"text":47,"spans":1346,"direction":24},[],{"type":40,"text":1348,"spans":1349,"direction":24},"Ask precisely about support terms: days and hours covered, available channels (chat, phone, email), response SLA, on-call coverage for strategic events (evenings and weekends included), a named Customer Success Manager, a detailed onboarding plan.",[],{"type":40,"text":47,"spans":1351,"direction":24},[],{"type":40,"text":1353,"spans":1354,"direction":24},"Require a name, a language, a time zone. Ask for a quantified use case on average response time. Call two or three references to verify the CSM's operational maturity.",[],{"type":40,"text":47,"spans":1356,"direction":24},[],{"type":40,"text":1358,"spans":1359,"direction":24},"\"For major accounts, the platform + Customer Success pairing makes 80% of the difference on the day. A perfect tool without a human behind it always fails. The reverse is true too.\", Lucas Boheme, Head of Major Accounts at Digitevent",[1360,1362,1367],{"start":35,"end":1361,"type":134},181,{"start":1363,"end":1364,"type":117,"data":1365},183,233,{"link_type":119,"url":1366,"target":121},"https://www.linkedin.com/in/lucas-boheme/",{"start":1363,"end":1364,"type":70},{"type":40,"text":47,"spans":1369,"direction":24},[],{"type":40,"text":1371,"spans":1372,"direction":24},"The weight given to support in your scoring grid should reflect this real importance. 20 to 25% minimum isn't excessive.",[],{"type":40,"text":47,"spans":1374,"direction":24},[],{"type":40,"text":1376,"spans":1377,"direction":24},"Also ask about escalation. What happens if a blocking incident occurs an hour before doors open? What's the emergency number? Which team responds? Within how many minutes? Those answers are worth ten pages of marketing documentation.",[],{"type":40,"text":47,"spans":1379,"direction":24},[],{"type":180,"text":1381,"spans":1382,"direction":24},"Key 9 - Break down the TCO over three years",[1383],{"start":35,"end":1384,"type":70},43,{"type":40,"text":1386,"spans":1387,"direction":24},"The sticker price isn't the total cost.",[],{"type":40,"text":47,"spans":1389,"direction":24},[],{"type":40,"text":1391,"spans":1392,"direction":24},"Ask for the Total Cost of Ownership over three years: base license, optional modules, cost per attendee, initial setup fees, team training, premium support, custom integrations, professional services.",[],{"type":40,"text":47,"spans":1394,"direction":24},[],{"type":40,"text":1396,"spans":1397,"direction":24},"Demand a detailed pricing grid. Not a marketing PDF. A quantified document that simulates your real volumes. Ask about the terms for annual increases. Clarify the terms for renewal, scope reduction, and exit. A contract that doesn't plan for exit is a contract that traps you.",[],{"type":40,"text":47,"spans":1399,"direction":24},[],{"type":40,"text":1401,"spans":1402,"direction":24},"Then compare at a comparable cost. If a vendor looks 30% cheaper, identify what's missing from their scope. Often it's support, integrations, or advanced modules. The gap shows up on the first extension invoice.",[],{"type":40,"text":47,"spans":1404,"direction":24},[],{"type":180,"text":1406,"spans":1407,"direction":24},"Key 10 - Ask for a demo built around your real cases",[1408],{"start":35,"end":799,"type":70},{"type":40,"text":1410,"spans":1411,"direction":24},"A generic demonstration proves nothing.",[],{"type":40,"text":47,"spans":1413,"direction":24},[],{"type":40,"text":1415,"spans":1416,"direction":24},"Prepare an identical demo brief for every candidate. This brief should describe one of your real scenarios: a specific event type, a quantified volume, an expected integration, a complete attendee journey. Require the same format from every vendor: 60 minutes, 80% live hands-on, 20% Q&A.",[],{"type":40,"text":47,"spans":1418,"direction":24},[],{"type":40,"text":1420,"spans":1421,"direction":24},"You'll see the gaps immediately. Some vendors show you a tool. Others perform a well-rehearsed routine on a fictional case. A single imposed scenario is enough to reveal the platform's real depth.",[],{"type":40,"text":47,"spans":1423,"direction":24},[],{"type":40,"text":1425,"spans":1426,"direction":24},"Then ask for three customer references comparable to your context. Call them without a script. Ask two simple questions: what would you do differently with hindsight? and how does support hold up when something goes wrong? Unprepared answers are worth every demo in the world.",[1427,1429],{"start":1428,"end":890,"type":134},121,{"start":1430,"end":1431,"type":134},171,222,{"type":40,"text":47,"spans":1433,"direction":24},[],{"type":40,"text":1435,"spans":1436,"direction":24},"If possible, finish with a short proof of concept (POC) on a test event. That's the moment of truth.",[],{"type":40,"text":47,"spans":1438,"direction":24},[],{"type":65,"text":1440,"spans":1441,"direction":24},"Conclusion",[1442],{"start":35,"end":1443,"type":70},10,{"type":40,"text":1445,"spans":1446,"direction":24},"A well-written event RFP isn't the longest one. It's the most structured one.",[],{"type":40,"text":47,"spans":1448,"direction":24},[],{"type":40,"text":1450,"spans":1451,"direction":24},"Business framing upfront, aligned stakeholders, a quantified event scope, requirements ranked as Must / Should / Nice, security front and center, thoroughly tested integrations, explicit KPIs, support weighted at its true value, TCO broken down over three years, a demonstration built around your real cases. These ten keys cover the essentials.",[],{"type":40,"text":47,"spans":1453,"direction":24},[],{"type":40,"text":1455,"spans":1456,"direction":24},"They don't guarantee the right choice. No method does. But they eliminate 80% of the classic mistakes and create the conditions for a well-argued decision, defensible in committee, and sustainable over time.",[],{"type":40,"text":47,"spans":1458,"direction":24},[],{"type":40,"text":1460,"spans":1461,"direction":24},"To go further, check out our complete guide on how to choose an event platform as well as our comparison of the best event management tools. And if you'd like to include Digitevent in your consultation, request a Digitevent demo: we'll build a custom demonstration based on your real use cases.",[1462,1465,1470],{"start":439,"end":1463,"type":117,"data":1464},78,{"link_type":119,"url":888,"target":121},{"start":1466,"end":1467,"type":117,"data":1468},89,139,{"link_type":119,"url":1469,"target":121},"https://www.digitevent.com/en/blog/event-management-software",{"start":1471,"end":1472,"type":117,"data":1473},202,228,{"link_type":119,"url":448,"target":121},{"type":40,"text":47,"spans":1475,"direction":24},[],{"type":40,"text":1477,"spans":1478,"direction":24},"Your next RFP will be better than the last one. That's what matters.",[],{"type":40,"text":47,"spans":1480,"direction":24},[],[1482],{"primary":1483,"items":1491,"id":1493,"slice_type":462,"slice_label":8},{"seo_title":1484,"seo_meta_descriptions":1487},[1485],{"type":40,"text":1088,"spans":1486,"direction":24},[],[1488],{"type":40,"text":1489,"spans":1490,"direction":24},"Choosing an event platform requires a good RFP. Here are the 10 keys to structuring your specifications and making the best choice.",[],[1492],{},"seo$077b66fc-08fb-4ec9-a8a5-5255659a50a5",{"id":1495,"lang":465,"type":9,"uid":1496},"akYm7xIAACcAyuGp","plateforme-evenementielle-appel-offres",{"id":1498,"uid":1499,"url":8,"type":9,"tags":1500,"first_publication_date":1502,"slugs":1503,"linked_documents":1505,"lang":17,"data":1506},"ao2XPxEAACoA00An","martyns-law-event-organisers",[1501],"en-only","2026-08-25T14:55:20+0000",[1504],"martyns-law-what-event-organisers-must-prepare",[],{"distribution":1501,"article_title":1507,"author_name":25,"publication_date":1511,"banner_image":1512,"article_content":1518,"main_tag":449,"body":1976},[1508],{"type":21,"text":1509,"spans":1510,"direction":24},"Martyn's Law: what event organisers must prepare",[],"2026-08-25T14:45:00+0000",{"dimensions":1513,"alt":1514,"copyright":8,"url":1515,"id":1516,"edit":1517},{"width":29,"height":30},"Business event registration and check-in illustrating real-time attendance tracking and event security preparedness under Martyn’s Law.","https://images.prismic.io/digi-www/oyBiPRY-hF8BGKrA_Martyn%E2%80%99s-Law-and-Event-Security-1.webp?auto=format,compress&rect=0,0,900,600&w=900&h=600","oyBiPRY-hF8BGKrA",{"x":35,"y":35,"zoom":36,"background":37},[1519,1522,1524,1527,1529,1534,1536,1539,1541,1545,1547,1550,1552,1557,1563,1569,1571,1574,1576,1579,1581,1584,1586,1593,1595,1600,1602,1609,1611,1616,1621,1623,1626,1630,1632,1635,1637,1642,1644,1647,1649,1653,1656,1659,1661,1665,1667,1670,1673,1676,1678,1680,1687,1689,1693,1696,1698,1704,1706,1709,1711,1717,1719,1722,1724,1727,1729,1734,1736,1739,1741,1745,1748,1751,1753,1758,1760,1763,1768,1770,1773,1775,1781,1783,1786,1788,1794,1796,1799,1801,1807,1809,1812,1815,1817,1821,1824,1826,1829,1831,1834,1836,1840,1842,1845,1847,1850,1852,1855,1857,1865,1867,1873,1875,1878,1880,1889,1891,1894,1897,1900,1903,1905,1907,1911,1913,1916,1918,1922,1924,1928,1932,1934,1937,1939,1942,1944,1948,1950,1955,1957,1960,1962,1968,1970],{"type":40,"text":1520,"spans":1521,"direction":24},"On 3 April 2025, a new law reshaped the rules for event organisers across the UK. The Terrorism (Protection of Premises) Act 2025, known as Martyn's Law, creates for the first time a legal duty for public venues and events to prepare and plan for public safety.",[],{"type":40,"text":47,"spans":1523,"direction":24},[],{"type":40,"text":1525,"spans":1526,"direction":24},"It is expected to take effect in spring 2027. That may sound far off. It isn't.",[],{"type":40,"text":47,"spans":1528,"direction":24},[],{"type":40,"text":1530,"spans":1531,"direction":24},"From 200 people present at the same time, your event falls within the scope of the law. Above 800, the requirements step up considerably.",[1532],{"start":35,"end":1533,"type":70},88,{"type":40,"text":47,"spans":1535,"direction":24},[],{"type":40,"text":1537,"spans":1538,"direction":24},"Many organisers still believe this only concerns stadiums and large arenas. That's a misreading. Conferences, exhibitions, corporate seminars: most B2B formats are affected.",[],{"type":40,"text":47,"spans":1540,"direction":24},[],{"type":40,"text":1542,"spans":1543,"direction":24},"The good news? The law rests on a principle of proportionality. You don't have to turn your event into a fortress. You have to show that you have taken reasonable steps.",[1544],{"start":605,"end":1247,"type":70},{"type":40,"text":47,"spans":1546,"direction":24},[],{"type":40,"text":1548,"spans":1549,"direction":24},"This article breaks it down. What Martyn's Law actually says, which tier you fall into, and above all how to prove that you control the number of people present. Because that is where it all comes together.",[],{"type":40,"text":47,"spans":1551,"direction":24},[],{"type":65,"text":1553,"spans":1554,"direction":24},"Understanding Martyn's Law and why it exists",[1555],{"start":35,"end":1556,"type":70},44,{"type":40,"text":1558,"spans":1559,"direction":24},"Behind this law lies a personal story.",[1560],{"start":35,"end":1021,"type":117,"data":1561},{"link_type":119,"url":1562,"target":121},"https://www.gov.uk/guidance/understanding-martyns-law-and-the-sias-role-as-regulator",{"type":40,"text":1564,"spans":1565,"direction":24},"In May 2017, a serious incident took place at a concert venue in Manchester. Among those affected was a young man named Martyn Hett. The law now carries his first name.",[1566],{"start":1567,"end":1568,"type":70},133,168,{"type":40,"text":47,"spans":1570,"direction":24},[],{"type":40,"text":1572,"spans":1573,"direction":24},"His mother, Figen Murray, turned that experience into a campaign. For years, she pushed for a law that would require public venues to prepare better.",[],{"type":40,"text":47,"spans":1575,"direction":24},[],{"type":40,"text":1577,"spans":1578,"direction":24},"So Martyn's Law is not just another piece of red tape. It is a direct response to a gap in preparedness identified through the official review that followed the incident.",[],{"type":40,"text":47,"spans":1580,"direction":24},[],{"type":40,"text":1582,"spans":1583,"direction":24},"This law also reflects a broader context: public safety planning for large gatherings has become a growing area of focus in the UK, with authorities encouraging venues to plan ahead rather than react after the fact.",[],{"type":40,"text":47,"spans":1585,"direction":24},[],{"type":40,"text":1587,"spans":1588,"direction":24},"So what does the law actually change? It places a duty to prepare on venues and events open to the public. The Security Industry Authority (SIA) is the designated regulator.",[1589],{"start":1590,"end":1591,"type":117,"data":1592},107,144,{"link_type":119,"url":1562,"target":121},{"type":40,"text":47,"spans":1594,"direction":24},[],{"type":40,"text":1596,"spans":1597,"direction":24},"The Act introduces a new logic for many players. Until now, this kind of preparedness rested mostly on goodwill. It becomes a regulated duty, with a regulator, thresholds and penalties attached.",[1598],{"start":133,"end":1599,"type":70},194,{"type":40,"text":47,"spans":1601,"direction":24},[],{"type":40,"text":1603,"spans":1604,"direction":24},"And the penalties are not symbolic. For the enhanced tier (the stricter tier, above 800 people), fines can reach £18 million or 5% of worldwide revenue, with daily penalties for persistent breaches. Senior individuals can also be held personally liable in certain cases.",[1605],{"start":880,"end":1606,"type":117,"data":1607},151,{"link_type":119,"url":1608,"target":121},"https://www.burges-salmon.com/articles/102mqoj/martyns-law-counting-down-to-live-implementation/",{"type":40,"text":47,"spans":1610,"direction":24},[],{"type":40,"text":1612,"spans":1613,"direction":24},"For organisers, event security compliance moves from good practice to legal obligation.",[1614],{"start":586,"end":1615,"type":70},87,{"type":40,"text":1617,"spans":1618,"direction":24},"One principle guides the whole framework: \"reasonably practicable.\" In other words, your duties are proportionate to your size and your means. A 250-person seminar will never face the same requirements as a 5,000-strong convention.",[1619],{"start":1384,"end":1620,"type":70},65,{"type":40,"text":47,"spans":1622,"direction":24},[],{"type":40,"text":1624,"spans":1625,"direction":24},"The aim is not to multiply security gates. It is to reduce risk in a reasonable, documented way.",[],{"type":40,"text":1627,"spans":1628,"direction":24},"Then there's the timeline. Royal Assent dates from April 2025. The government has set an implementation period of roughly 24 months. The law is expected to take effect in spring 2027, though the exact date has not yet been confirmed.",[1629],{"start":1567,"end":885,"type":70},{"type":40,"text":47,"spans":1631,"direction":24},[],{"type":40,"text":1633,"spans":1634,"direction":24},"Put simply: you have time to prepare. You don't have time to ignore it. The statutory guidance is being firmed up throughout 2026, and serious organisers are already building their approach.",[],{"type":40,"text":47,"spans":1636,"direction":24},[],{"type":40,"text":1638,"spans":1639,"direction":24},"Why get ahead rather than scramble? Because a proper compliance effort touches your organisation, your teams and your tools. These are jobs that take months, not days. Recurring events have every reason to build Martyn's Law thinking into their next editions.",[1640],{"start":1568,"end":1641,"type":70},259,{"type":40,"text":47,"spans":1643,"direction":24},[],{"type":40,"text":1645,"spans":1646,"direction":24},"First concrete step: work out which category you fall into.",[],{"type":40,"text":47,"spans":1648,"direction":24},[],{"type":65,"text":1650,"spans":1651,"direction":24},"Standard tier (200-799): the baseline duties",[1652],{"start":35,"end":1556,"type":70},{"type":40,"text":1654,"spans":1655,"direction":24},"This is the category that covers the majority of B2B events.",[],{"type":40,"text":1657,"spans":1658,"direction":24},"The trigger threshold is worth pausing on. It covers venues and events where 200 to 799 people may be present at the same time, at peak times.",[],{"type":40,"text":47,"spans":1660,"direction":24},[],{"type":40,"text":1662,"spans":1663,"direction":24},"The phrase \"at the same time\" is decisive. It's not the daily total. It's the peak footfall at any given moment. An exhibition that sees 1,500 visitors across eight hours, but never more than 600 at once, sits in the standard tier.",[1664],{"start":35,"end":1384,"type":70},{"type":40,"text":47,"spans":1666,"direction":24},[],{"type":40,"text":1668,"spans":1669,"direction":24},"At this level, the duties remain manageable. They come down to two strands:",[],{"type":327,"text":1671,"spans":1672,"direction":24},"Notify the SIA as the person responsible for the venue or event.",[],{"type":327,"text":1674,"spans":1675,"direction":24},"Put in place reasonable public protection procedures: evacuation, invacuation, lockdown, communication in the event of an incident.",[],{"type":40,"text":47,"spans":1677,"direction":24},[],{"type":40,"text":47,"spans":1679,"direction":24},[],{"type":40,"text":1681,"spans":1682,"direction":24},"One point reassures from the outset. No costly physical measures are required at the standard tier. No mandatory security gates, no heavy equipment to fund.",[1683],{"start":1684,"end":526,"type":117,"data":1685},37,{"link_type":119,"url":1686,"target":121},"https://www.protectuk.police.uk/martyns-law/martyns-law-overview-and-what-you-need-know",{"type":40,"text":47,"spans":1688,"direction":24},[],{"type":40,"text":1690,"spans":1691,"direction":24},"The spirit of the law lies elsewhere. It's about preparedness, not fortifying the site.",[1692],{"start":35,"end":1615,"type":70},{"type":40,"text":1694,"spans":1695,"direction":24},"What does \"preparing\" mean in practice? Training your teams in the right reflexes. Knowing who raises the alarm, who evacuates, who coordinates. Documenting your procedures so you can present them.",[],{"type":40,"text":47,"spans":1697,"direction":24},[],{"type":40,"text":1699,"spans":1700,"direction":24},"Take a simple example. In an alert, do your front-of-house teams know where to direct attendees? Does your production desk know how to cut the music and broadcast a clear instruction? These reflexes are built in advance.",[1701],{"start":1702,"end":1703,"type":70},184,220,{"type":40,"text":47,"spans":1705,"direction":24},[],{"type":40,"text":1707,"spans":1708,"direction":24},"Picture a 400-person annual staff seminar in a conference centre. You sit in the standard tier. In practice, you'll need to have identified your exits, appointed zone leads, and briefed your suppliers on what to do. Nothing insurmountable, but nothing improvised either.",[],{"type":40,"text":47,"spans":1710,"direction":24},[],{"type":40,"text":1712,"spans":1713,"direction":24},"It's also a matter of operational common sense. Many of these reflexes overlap with what you already do for crisis management or fire evacuation.",[1714],{"start":1715,"end":1716,"type":70},48,145,{"type":40,"text":47,"spans":1718,"direction":24},[],{"type":40,"text":1720,"spans":1721,"direction":24},"So the difficulty isn't technical. It's organisational. You have to appoint owners, write the procedures, drill the teams.",[],{"type":40,"text":47,"spans":1723,"direction":24},[],{"type":40,"text":1725,"spans":1726,"direction":24},"A tip from the field: don't start from scratch. Most organisers already have evacuation plans and safety instructions. Martyn's Law asks you to formalise them, extend them to cover this specific type of risk, and check that everyone knows them.",[],{"type":40,"text":47,"spans":1728,"direction":24},[],{"type":40,"text":1730,"spans":1731,"direction":24},"Think about traceability too. A procedure that exists but that no one can evidence counts for little in front of a regulator. Date your documents, keep a record of your training, archive your team briefings.",[1732],{"start":697,"end":1733,"type":70},125,{"type":40,"text":47,"spans":1735,"direction":24},[],{"type":40,"text":1737,"spans":1738,"direction":24},"Above 800 people, however, the bar rises sharply.",[],{"type":40,"text":47,"spans":1740,"direction":24},[],{"type":65,"text":1742,"spans":1743,"direction":24},"Enhanced tier (800+): the stricter duties",[1744],{"start":35,"end":350,"type":70},{"type":40,"text":1746,"spans":1747,"direction":24},"At this level, the requirements change in nature.",[],{"type":40,"text":1749,"spans":1750,"direction":24},"The enhanced tier covers large events: major congresses, large-scale exhibitions, conventions gathering several thousand attendees.",[],{"type":40,"text":47,"spans":1752,"direction":24},[],{"type":40,"text":1754,"spans":1755,"direction":24},"First difference, and a significant one. Documentation becomes mandatory. You must document your procedures and measures, then submit them to the SIA. The burden of proof becomes formal.",[1756],{"start":350,"end":1757,"type":70},73,{"type":40,"text":47,"spans":1759,"direction":24},[],{"type":40,"text":1761,"spans":1762,"direction":24},"Second difference: measures to reduce vulnerability. It's no longer only about knowing how to react. You also have to reduce the site's exposure to safety and security risks.",[],{"type":40,"text":1764,"spans":1765,"direction":24},"That can include surveillance, access control, or protective measures where they are practicable. Always under the principle of proportionality: what's expected of a large convention centre differs from what's asked of an outdoor event.",[1766],{"start":1591,"end":1767,"type":70},236,{"type":40,"text":47,"spans":1769,"direction":24},[],{"type":40,"text":1771,"spans":1772,"direction":24},"Third difference, often underestimated: governance. Someone has to own compliance. A named lead, with a clear mandate and follow-through over time.",[],{"type":40,"text":47,"spans":1774,"direction":24},[],{"type":40,"text":1776,"spans":1777,"direction":24},"Picture a trade show of 2,000 visitors over three days. You sit in the enhanced tier. You'll need to assess the site's vulnerabilities, define suitable measures, appoint a lead, then submit the whole package to the SIA. All of this is prepared months ahead, in coordination with the venue and your security suppliers.",[1778],{"start":1779,"end":1780,"type":70},219,257,{"type":40,"text":47,"spans":1782,"direction":24},[],{"type":40,"text":1784,"spans":1785,"direction":24},"The venue and the organiser share the responsibility, incidentally. Clarify who does what at the contract stage, not the night before doors open.",[],{"type":40,"text":47,"spans":1787,"direction":24},[],{"type":40,"text":1789,"spans":1790,"direction":24},"In practice, the enhanced tier calls for a genuine project approach. You don't tick a box the day before. You build a framework, document it, and keep it up to date.",[1791],{"start":1792,"end":1793,"type":70},106,165,{"type":40,"text":47,"spans":1795,"direction":24},[],{"type":40,"text":1797,"spans":1798,"direction":24},"Watch out for a common trap. An event that grows year on year can shift from the standard to the enhanced tier without the organiser having anticipated it. Going from 750 to 900 attendees changes your category, and therefore your duties.",[],{"type":40,"text":47,"spans":1800,"direction":24},[],{"type":40,"text":1802,"spans":1803,"direction":24},"Hence the importance of tracking your real footfall over time. Not just on the day, but from edition to edition. Your registration and attendance figures become a regulatory management indicator.",[1804],{"start":1805,"end":1806,"type":70},113,195,{"type":40,"text":47,"spans":1808,"direction":24},[],{"type":40,"text":1810,"spans":1811,"direction":24},"This documentary requirement has a direct consequence. You must be able to demonstrate, with evidence, that you control your event. Including the number of people present.",[],{"type":40,"text":1813,"spans":1814,"direction":24},"And this is precisely where many organisers discover a blind spot.",[],{"type":40,"text":47,"spans":1816,"direction":24},[],{"type":65,"text":1818,"spans":1819,"direction":24},"The real challenge: proving how many people are present",[1820],{"start":35,"end":362,"type":70},{"type":40,"text":1822,"spans":1823,"direction":24},"It all starts with a number. You still have to know it.",[],{"type":40,"text":47,"spans":1825,"direction":24},[],{"type":40,"text":1827,"spans":1828,"direction":24},"Look closely at how the law works. Your tier depends on the number of people present at the same time. Your duties flow from it. So does your ability to prove your compliance.",[],{"type":40,"text":47,"spans":1830,"direction":24},[],{"type":40,"text":1832,"spans":1833,"direction":24},"Yet many only know that number approximately. A rough estimate. A manual count at the end of the day. A paper register quickly overtaken when the crowd builds.",[],{"type":40,"text":47,"spans":1835,"direction":24},[],{"type":40,"text":1837,"spans":1838,"direction":24},"The problem is obvious. If you underestimate your footfall, you think you're in the standard tier when you actually fall under the enhanced tier. You're non-compliant without even knowing it.",[1839],{"start":35,"end":706,"type":70},{"type":40,"text":47,"spans":1841,"direction":24},[],{"type":40,"text":1843,"spans":1844,"direction":24},"The reverse is costly too. Overestimating means imposing disproportionate duties on yourself, and therefore wasting time and money.",[],{"type":40,"text":47,"spans":1846,"direction":24},[],{"type":40,"text":1848,"spans":1849,"direction":24},"Manual counting quickly shows its limits. At peak times the flow accelerates, the queues stretch, and no one keeps a reliable tally with a handheld counter. The result? A rough figure, impossible to defend in front of a regulator.",[],{"type":40,"text":47,"spans":1851,"direction":24},[],{"type":40,"text":1853,"spans":1854,"direction":24},"In the event of an inspection, the stakes become even more concrete. How do you show you controlled your headcount at a given moment? A handwritten notebook won't cut it. Nor will a verbal estimate.",[],{"type":40,"text":47,"spans":1856,"direction":24},[],{"type":40,"text":1858,"spans":1859,"direction":24},"This is where a real-time registration and check-in solution changes everything. Each entry is scanned, timestamped, counted. You know, to the minute, how many people are inside your venue.",[1860,1864],{"start":553,"end":1861,"type":117,"data":1862},61,{"link_type":119,"url":1863,"target":121},"https://www.digitevent.com/en/feature/checkin-guestlist-event-app-control-register-participants",{"start":446,"end":527,"type":70},{"type":40,"text":47,"spans":1866,"direction":24},[],{"type":40,"text":1868,"spans":1869,"direction":24},"At Digitevent, we support more than 3,000 organisers, and this live visibility on who's present is increasingly high on their list. Registration data stops being a mere logistics tool. It becomes a piece of compliance evidence.",[1870],{"start":1871,"end":1872,"type":70},132,227,{"type":40,"text":47,"spans":1874,"direction":24},[],{"type":40,"text":1876,"spans":1877,"direction":24},"Since Martyn's Law was passed, we've seen a shift in what UK teams ask for. Check-in is no longer seen only as a way to speed up the door. It becomes a way to secure a legal duty.",[],{"type":40,"text":47,"spans":1879,"direction":24},[],{"type":40,"text":1881,"spans":1882,"direction":24},"\"With Martyn's Law, counting who's present is no longer a nice-to-have, it's evidence. Knowing exactly how many people are in the room, and being able to document it, is what will make the difference during an inspection\" says Jonathan Astruc, Co-founder at Digitevent.",[1883,1884,1888],{"start":36,"end":1703,"type":134},{"start":1431,"end":1885,"type":117,"data":1886},269,{"link_type":119,"url":1887,"target":121},"https://www.linkedin.com/in/jonathan-astruc/",{"start":1431,"end":1885,"type":70},{"type":40,"text":47,"spans":1890,"direction":24},[],{"type":40,"text":1892,"spans":1893,"direction":24},"A real-time check-in delivers three simple things:",[],{"type":327,"text":1895,"spans":1896,"direction":24},"A precise, timestamped count of every entry and exit.",[],{"type":327,"text":1898,"spans":1899,"direction":24},"Live visibility on the exact number of people present at any moment.",[],{"type":327,"text":1901,"spans":1902,"direction":24},"An exploitable history, ready to be presented to the SIA if needed.",[],{"type":40,"text":47,"spans":1904,"direction":24},[],{"type":40,"text":47,"spans":1906,"direction":24},[],{"type":40,"text":1908,"spans":1909,"direction":24},"This data serves far beyond compliance. It helps you decide in real time. Should you stagger entries? Open an extra room? Trigger a crowd management plan? You steer on figures, not on a hunch.",[1910],{"start":165,"end":1757,"type":70},{"type":40,"text":47,"spans":1912,"direction":24},[],{"type":40,"text":1914,"spans":1915,"direction":24},"A word on personal data, since the question often comes up. Tracking a headcount doesn't mean collecting more information than necessary. What matters is the number and the timestamp, in line with the UK GDPR.",[],{"type":40,"text":47,"spans":1917,"direction":24},[],{"type":40,"text":1919,"spans":1920,"direction":24},"In short: you turn a regulatory constraint into reliable data. And you stop steering your headcount blind.",[1921],{"start":35,"end":935,"type":70},{"type":40,"text":47,"spans":1923,"direction":24},[],{"type":65,"text":1925,"spans":1926,"direction":24},"Spring 2027 is prepared now",[1927],{"start":35,"end":97,"type":70},{"type":40,"text":1929,"spans":1930,"direction":24},"Let's recap. Martyn's Law imposes a duty to prepare from 200 people present at the same time, stepped up above 800. The regulator is the SIA. The law is expected to take effect in spring 2027.",[1931],{"start":670,"end":760,"type":70},{"type":40,"text":47,"spans":1933,"direction":24},[],{"type":40,"text":1935,"spans":1936,"direction":24},"Under the Terrorism (Protection of Premises) Act 2025, event security compliance is now something you can plan for, not a surprise to absorb.",[],{"type":40,"text":47,"spans":1938,"direction":24},[],{"type":40,"text":1940,"spans":1941,"direction":24},"Your next steps are clear. Identify your tier based on your real peak footfall. Notify the SIA when the time comes. Document your procedures. Train your teams. And equip yourself with the tools that prove, with figures, that you control the flow of your attendees.",[],{"type":40,"text":47,"spans":1943,"direction":24},[],{"type":40,"text":1945,"spans":1946,"direction":24},"That last point often makes the difference. Organisers who build their check-in and attendance tracking now will approach the deadline a step ahead. The rest will meet the requirement in a rush.",[1947],{"start":35,"end":1384,"type":70},{"type":40,"text":47,"spans":1949,"direction":24},[],{"type":40,"text":1951,"spans":1952,"direction":24},"One final piece of advice, whatever your tier. Don't treat Martyn's Law as an isolated box to tick. Tie it to what you already do: registration, on-site welcome, evacuation plans, post-event reporting. Compliance then becomes an extension of your operation, not an extra layer of admin.",[1953],{"start":137,"end":1954,"type":70},286,{"type":40,"text":47,"spans":1956,"direction":24},[],{"type":40,"text":1958,"spans":1959,"direction":24},"Spring 2027 feels far off. It's prepared in 2026.",[],{"type":40,"text":47,"spans":1961,"direction":24},[],{"type":40,"text":1963,"spans":1964,"direction":24},"Want to know exactly how many people are at your event, at every moment, and be able to prove it? Request a demo of Digitevent and see how real-time check-in secures your compliance.",[1965],{"start":882,"end":527,"type":117,"data":1966},{"link_type":119,"url":1967,"target":121},"https://www.digitevent.com/en?contact",{"type":40,"text":47,"spans":1969,"direction":24},[],{"type":40,"text":1971,"spans":1972,"direction":24},"For more insights, explore our event registration and check-in resources on the blog.",[1973],{"start":614,"end":524,"type":117,"data":1974},{"link_type":119,"url":1975,"target":121},"https://www.digitevent.com/en/blog",[1977],{"primary":1978,"items":1986,"id":1987,"slice_type":462,"slice_label":8},{"seo_title":1979,"seo_meta_descriptions":1982},[1980],{"type":40,"text":1509,"spans":1981,"direction":24},[],[1983],{"type":40,"text":1984,"spans":1985,"direction":24},"Martyn's Law takes effect in spring 2027. Here's what UK event organisers must put in place from 200 attendees to prove their event security compliance.",[],[],"seo$bd3a5a19-4866-4263-ab5a-f90310337e61",[],1789021292634]