You collect data at every event. Registration, badge, networking, post-event follow-up: every interaction involves the processing of personal data.
But how can you be sure you're complying with the General Data Protection Regulation (GDPR)?
Good news: you don't need to be a lawyer to ensure your GDPR compliance for events. You do, however, need to understand the fundamentals, and especially their concrete impact on your organization, and that's what this short practical guide will help you do.
What is GDPR for events?
What you need to know about GDPR
GDPR is a European regulation that governs the collection and processing of personal data within the European Union.
In practice, as an event organizer, you are considered a data controller. Your role? Guarantee the protection of personal data for every attendee.
GDPR is built on several key principles. Here are the ones you absolutely need to master:
- Explicit consent. You must obtain clear agreement from the person concerned before collecting any data. This means informing them about how the data will be used, in a transparent and understandable way.
- Purpose of processing. Every piece of data collected must serve a specific purpose (registration, communication, networking, etc.). You can't collect data "just in case."
- Data minimization. You must only collect the data strictly necessary for your event activity.
- The right to access and erasure. Every attendee can exercise their rights: access, modification, the right to be forgotten. You must respond within a maximum of 30 days.
- Data security. GDPR requires appropriate data security measures to be put in place. In the event of a breach, notifying the supervisory authority (CNIL) is mandatory within 72 hours.
- Data portability. A person can request to retrieve their data in a usable format.
In other words: GDPR requires data management that is structured, secure, and transparent.
Types of data collected at events
In practice, the events industry handles a wide variety of personal data.
Here are the main types of data collected:
- Registration data: last name, first name, email, phone number, company, job title, etc.
- Behavioral data: session attendance, interactions, networking, etc.
- Attendance data: badge scans, check-in, QR code, etc.
- Data from digital tools: CRM, event platform, mobile app, etc.
- Marketing data: preferences, interests, post-event engagement, etc.
For example, in practice, at a trade show or a corporate seminar, scanning a badge through an app constitutes the collection of personal data. This data can then be used by an exhibitor or a sales rep as part of a customer relationship. And that's precisely where GDPR compliance becomes strategic.
What impact does GDPR have on events?
GDPR isn't just a legal constraint: it's also a performance lever for your event strategy.
In practice, what does this change for you?
- Better data quality. You collect less, but better. The data is more reliable and more usable.
- More qualified contact lists. No more massive, low-engagement lists. Instead, contacts who are genuinely interested.
- Stronger trust. Transparency, respect for privacy, clarity: all factors that improve the user experience.
- More structured internal processes. GDPR pushes you to formalize your practices: consent management, retention, security, data governance.
GDPR thus transforms the way you design your events.
Cheat sheet: what are the GDPR obligations for an event?
Here are the essential legal obligations to meet to ensure your GDPR compliance for events:
- Obtain explicit consent from attendees. Before collecting any personal data, you must obtain clear, freely given, and informed agreement.
- Define a legal basis for each processing activity. Consent, contract performance, legitimate interest: every data processing activity must rest on a legal basis.
- Inform transparently. You must provide clear information on the purpose, retention period, and use of the data collected.
- Limit collection to what's strictly necessary. Only collect the data that's useful for organizing your event.
- Guarantee data security. You must implement protection and security measures suited to the risks.
- Enable the exercise of rights. Access, rectification, erasure, the right to object: every person concerned must be able to exercise their rights easily.
- Keep a record of processing activities. You must document all processing operations carried out as part of your events.
- Report any data breach. In the event of a leak or incident, notifying the CNIL is mandatory within 72 hours.
- Govern vendors and partners. Your event vendors must also comply with GDPR (contract, liability, security).
Want to dig deeper into the topic? Here are the tips to help you stay fully compliant with GDPR when organizing your events.
6 keys to ensuring your events comply with GDPR
Complying with GDPR shouldn't slow down your events. Quite the opposite: it's a lever to make them more effective, more reliable, and more professional. Here are the keys to doing that.
Obtain clear and transparent consent
Without explicit consent, no processing of personal data is compliant.
In practice, you must clearly inform every attendee: why their data is being collected, how it will be used, and for how long. In other words: no gray areas, no ambiguity.
Your data collection must rest on a legal basis that is transparent and understandable.
In fact, if you're not compliant, the risks are very real. The CNIL provides for penalties of up to €20 million, or 4% of global annual revenue.
Protecting personal data is therefore not an option, but a genuine responsibility.
Make sure the data you collect is GDPR-compliant
As you'll have gathered: to be GDPR-compliant, your collection of personal data must rest on one key principle: the explicit consent of the individual.
In practice, this comes down to one essential point: opt-in. Opt-in means the attendee voluntarily chooses to share their data with you and agrees to its use.
But be careful: this consent must be freely given, informed, and above all unbiased.
Here are the best practices to apply:
- A mandatory, clear opt-in. The attendee must check a box themselves to give their consent.
- No pre-checked boxes. No consent should ever be assumed.
- A recommended double opt-in. An email confirmation strengthens proof of consent.
- Proof of consent kept on record. You must be able to demonstrate at any time that the person agreed.
- A clear distinction between customers and prospects. Communication rules differ depending on status.
- Granular choices. Newsletter, invitations, partners: each use must be covered by its own specific agreement.
Here's an example of compliant wording for a registration form: "I agree that my data may be used for commercial communications."
Once consent is obtained, you can use the data within the defined scope. But as soon as the use changes, new agreement becomes necessary.
And above all: you must always let attendees easily unsubscribe from your communications.
Properly inform your attendees about their data
Informing your attendees is crucial to complying with GDPR for events. But you may be wondering exactly what you need to communicate?
Here are the mandatory disclosures to include in your forms, registration pages, or emails:
- The purpose of processing. Why are you collecting this data (registration, event management, communication, etc.)?
- The retention period. How long will the data be kept?
- Attendees' rights. Access, rectification, erasure, the right to object: every person concerned must be able to act on their data.
In practice, your message must be simple, accessible, and understandable within a few seconds.
For example: "Your data is used to manage your registration for this event and to send you related information. You can access, modify, or request the deletion of your data at any time."
And don't forget to include a link to your privacy policy either. This document or web page must detail all of your practices regarding the protection of personal data: data processing, security, sharing with vendors, user rights, etc.
Manage and control all attendee data in one place
To ensure compliant data management, one rule applies: centralize. In other words, gather all the data collected (registration, attendance, interactions, networking) within a single event platform. This way, you stay in control of data processing at every stage.
But be careful: you can't freely share your attendees' data. Even in an event context, the rule is clear: no data sharing without the explicit consent of the person concerned. Sharing with an exhibitor, passing data to a partner, post-event commercial use: everything must be approved in advance, through a specific opt-in.
And that's where technology becomes useful. A centralized solution lets you, among other things:
- Ensure consent traceability: who agreed to what, when, and in what context.
- Easily manage attendees' rights: access, modification, deletion of data, etc.
- Automate data deletion based on the defined retention period
- Secure access and usage to limit the risk of leaks or non-compliant use.
This way, you move from scattered management to management that's secure, controlled, and compliant.
Structure your data governance (with or without a DPO)
You process personal data at every event. But who's actually responsible internally, within your company or your event agency?
That's precisely the role of the Data Protection Officer (DPO). Their mission is simple: oversee data collection and processing, guarantee its protection, and ensure compliance with the General Data Protection Regulation.
In practice, the DPO handles several key areas:
- Validating collection processes
- Monitoring data usage
- Managing risks and incidents
- Supporting teams on best practices
Note that appointing a DPO isn't systematically mandatory. It's required in certain specific cases: for public bodies, companies carrying out large-scale data processing, or organizations handling sensitive or high-risk data.
If none of these cases apply to you, you can simply designate an internal GDPR point of contact. This role can be filled by a marketing manager, an event project manager, or an IT manager. Their goal remains the same as a DPO's: structure your organization and ensure compliant data management.
Optimize your existing data
Already have a database? Good news: you can keep using it. But on one condition: that it's GDPR-compliant. In other words, you can't use your existing data without being able to justify how it's used.
Two elements are essential:
- The purpose of the database. Why was this data collected? In what context can it be used today?
- Proof of consent. You must be able to state when consent was obtained, in what context, and for what type of use.
In practice, this means doing a sorting and qualification exercise. Clean out outdated data, remove contacts without clear consent, check the retention period, and segment your lists according to authorized uses.
You may end up with a smaller list, but one you can use in full compliance.
How do you guarantee the security of your event data?
Collecting data is one thing. Protecting it is another. And on this point, GDPR sets a high bar for data security. This is where the choice of your event management tool becomes strategic.
To guarantee GDPR-compliant protection of personal data, your platform must include several essential standards.
Here are the elements to check first:
- Data hosting within the European Union, for example through infrastructure such as AWS Europe. This guarantees a level of protection consistent with European regulations.
- Data encryption (HTTPS / TLS). This way, data is protected during exchanges and connections.
- Fine-grained access management (roles and permissions). Each user only accesses the data they need, limiting the risk of internal errors or leaks.
- Logs and an activity history. You know who accessed what, when, and how. This is a key point in the event of an audit or incident.
Also keep in mind that a truly GDPR-compliant platform should let you govern data sharing with your vendors, and automate certain secure data management rules (handling modification or deletion requests, for example).
And don't forget that the regulations and laws enforced by the CNIL are often updated. So remember to regularly check that the guidance issued by the CNIL matches your practices and your privacy policy.
Need an event platform that's 100% GDPR-compliant, intuitive, and powerful? Discover all of Digitevent's commitments to data protection and security.
V2 - 07/05/2026



