Under Article 15 of the UK GDPR, every individual has the right to obtain confirmation of whether you are processing their personal data and, if so, to receive a copy of that data along with supplementary information. This is known as a Data Subject Access Request (DSAR). As an event organiser, you may receive DSARs from attendees, former attendees, or anyone whose data you hold. You must respond within one calendar month, and getting it wrong can result in complaints to the Information Commissioner's Office (ICO) and potential enforcement action.
Disclaimer: This article provides general guidance on handling DSARs under UK GDPR and the Data Protection Act 2018. Data protection law is complex, and DSARs can raise difficult questions about exemptions and third-party data. Always seek professional legal advice for complex requests and consult the ICO's guidance on the right of access.
What triggers a DSAR?
A DSAR can be made verbally or in writing, by email, letter, social media message, or even in person. The individual does not need to use the words "data subject access request" or cite Article 15. If someone asks you "what data do you hold about me?" or "can I see the information you have on me?", that is a DSAR.
There is no requirement for the individual to explain why they want the data or what they intend to do with it. You cannot refuse a DSAR simply because you disagree with the requester's motives.
Step 1: Recognise the request
Ensure that all staff who may receive a DSAR know how to recognise one. This includes your customer service team, your box office staff, your social media managers, and anyone who handles attendee communications. A request does not need to be formal or use specific terminology. Train your team to escalate anything that looks like a data access request to the person responsible for data protection.
Step 2: Verify the requester's identity
Before disclosing any personal data, you must be satisfied that the person making the request is who they claim to be. If the request comes from an email address you already have on file for that person, this may be sufficient. If you have any doubt, you can ask for reasonable proof of identity, such as a copy of a passport or driving licence.
Do not ask for excessive identification. The ICO's guidance is clear that you should only request additional proof if you have reasonable grounds for doubt. Asking for multiple forms of ID when the request clearly comes from the person's known email address would be considered disproportionate.
Step 3: Locate all personal data
You must provide all personal data you hold about the individual, not just what is in a single system. For event organisers, this may include:
- Ticket purchase records and transaction history from your ticketing platform.
- Email marketing records (subscription status, emails sent, open and click data).
- Customer service correspondence (emails, chat logs, phone call notes).
- CCTV footage where the individual is identifiable.
- Photographs taken at events where the individual is identifiable.
- Survey responses and feedback forms.
- Internal notes, comments, or files mentioning the individual.
- Financial records related to the individual (invoices, refunds, payment details).
Search all systems, databases, email accounts, and paper files where personal data may be held. Do not limit your search to a single system.
Step 4: Apply exemptions
The Data Protection Act 2018 sets out a number of exemptions that may allow you to withhold certain data from a DSAR response. The most commonly relevant exemptions for event organisers are:
- Third-party data -- if providing the requested data would involve disclosing personal data about another identifiable individual, you can redact the third party's data unless that person has consented to the disclosure or it is reasonable to disclose without consent.
- Legal privilege -- data subject to legal professional privilege (for example, legal advice about a dispute with the requester) is exempt.
- Management planning -- in limited circumstances, data relating to management forecasting or planning may be exempt if disclosure would prejudice those activities.
Exemptions must be applied on a case-by-case basis. You cannot refuse an entire DSAR because one exemption applies to one piece of data.
Step 5: Prepare the response
Your response must include:
- Confirmation that you are processing the individual's personal data (or confirmation that you are not, if applicable).
- A copy of the personal data in a commonly used electronic format (such as PDF, CSV, or a structured document).
- The purposes of the processing.
- The categories of personal data concerned.
- The recipients or categories of recipients to whom the data has been or will be disclosed.
- The retention period or criteria used to determine it.
- Information about the individual's rights (to rectification, erasure, restriction, objection, and to lodge a complaint with the ICO).
- The source of the data if it was not collected directly from the individual.
- Whether automated decision-making (including profiling) is applied and, if so, the logic involved.
Step 6: Respond within the deadline
You must respond within one calendar month of receiving the request (or within one calendar month of receiving verification of identity, if you requested it). If the request is complex or you have received a large number of requests, you can extend the deadline by a further two months, but you must inform the individual within the first month, explaining why the extension is needed.
The response must be provided free of charge. You can charge a "reasonable fee" only if the request is manifestly unfounded or excessive, or if the individual requests further copies of the same data. In practice, charging a fee is rare and should only be done after careful consideration.
What if you cannot find any data?
If after a thorough search you do not hold any personal data about the requester, you must still respond within the one-month deadline, confirming that you do not process their personal data.
Practical tips for event organisers
- Have a DSAR response process documented before you receive your first request. Knowing where data is stored and who is responsible for each system saves significant time when a request arrives.
- Keep records of all DSARs received and your responses, including the timeline of each request.
- Use your event management software to maintain organised attendee records. Well-structured data is much easier to locate and extract when a DSAR is received.
- If you use third-party platforms (ticketing, email marketing, CRM), know how to export data from each one and include these in your search.
- Consider the DSAR implications of your event data collection practices. The more data you collect, the more complex DSARs become. Only collect data you actually need.
DSARs can feel burdensome, but they are a fundamental right under UK GDPR. A well-prepared event organiser can handle them efficiently and use the process as an opportunity to audit and improve their data management practices. The ICO provides detailed guidance on the right of access, including worked examples and template response letters, which are invaluable resources.