Understanding GDPR for Events
As an event organiser in the UK, you collect personal data every time someone buys a ticket: names, email addresses, sometimes phone numbers. Under the UK GDPR, you are responsible for handling this data lawfully, transparently, and securely.
The good news is that compliance does not have to be complicated. By choosing a platform that handles data securely and being transparent with your attendees, you can meet your obligations without legal expertise.
Key Requirements
- Lawful basis — you need a legal reason to collect data (contract fulfilment for ticket delivery, or consent for marketing)
- Privacy notice — tell attendees what data you collect and why
- Data minimisation — only collect what you genuinely need
- Right to erasure — fans can request their data be deleted
- Data security — use secure platforms and protect stored data
Tickts and GDPR
Tickts is built with GDPR compliance in mind. Cookie consent is handled with logged consent records, attendee data is stored securely, and data export tools let fans exercise their rights. As an organiser, you should still maintain your own privacy policy and be transparent about how you use attendee data for marketing.
GDPR Basics for Event Organisers
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 govern how you collect, store, and use personal data. As an event organiser, you collect personal data every time someone buys a ticket — names, email addresses, payment details, and potentially more.
GDPR compliance is not optional, and the fines for non-compliance can be substantial. But for most grassroots organisers, compliance is straightforward if you follow basic principles.
What Data You Collect
Through Tickts, you collect:
- Contact details: Name, email address (required for ticket delivery)
- Payment data: Handled by Stripe — you never see or store card numbers
- Attendance data: QR code scan records showing who attended and when
- Communication preferences: Whether the attendee has opted in to marketing emails
Your Responsibilities
- Lawful basis: You need a legal reason to process data. For ticket purchases, this is "contractual necessity" — you need their data to provide the ticket. For marketing emails, you need consent.
- Transparency: Tell people what data you collect and why. Your event page and privacy policy should explain this clearly.
- Data minimisation: Only collect data you actually need. Do not ask for phone numbers, dates of birth, or addresses unless there is a genuine reason.
- Security: Keep data secure. Tickts handles platform security, but you are responsible for how you use exported data (attendee lists, email exports).
- Rights: Respond to data subject requests — if someone asks to see their data, correct it, or delete it, you must comply within 30 days.
Practical Steps
- Add a privacy policy link to your organiser profile explaining your data practices
- Only use attendee email addresses for legitimate purposes (event updates, marketing with consent)
- Do not share attendee lists with third parties without consent
- Securely delete exported data files when they are no longer needed
- Include an unsubscribe mechanism in all marketing emails
Frequently Asked Questions
Do I need a privacy policy?
Yes. Any organisation collecting personal data should have a privacy policy. It does not need to be a lengthy legal document — a clear, plain-English explanation of what you collect, why, and how you use it is sufficient for most grassroots organisations.
Can I email ticket buyers about future events?
You can send transactional emails related to their purchase (confirmation, event updates, cancellation notices) without additional consent. For marketing emails about future events, you should obtain consent. A checkbox at checkout asking "Would you like to hear about future events?" is the standard approach.