Skip to main content
Organiser Resources

Guide to GDPR Compliance for Event Organisers

How event organisers can comply with UK GDPR when collecting attendee data, managing mailing lists, and working with third-party platforms.

165
THE TICKTS JOURNALORGANISER RESOURCES

Guide to GDPR Compliance for Event Organisers

6 min read

As an event organiser, you collect personal data at multiple touchpoints: ticket purchases, registration forms, mailing list sign-ups, photography, CCTV, and attendee surveys. The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 set out strict rules about how you collect, use, store, and share this data. Non-compliance can result in enforcement action by the Information Commissioner's Office (ICO), including fines of up to £17.5 million or 4% of annual worldwide turnover, whichever is higher.

Disclaimer: This article provides general guidance on UK GDPR compliance for event organisers. Data protection law is complex and fact-specific. Always seek professional legal advice for your circumstances. The ICO website (ico.org.uk) provides authoritative guidance and templates.

Understanding your role

Under UK GDPR, you need to understand whether you are a data controller, a data processor, or both:

  • Data controller -- you determine the purposes and means of processing personal data. As an event organiser collecting attendee details to manage your event, you are almost certainly a data controller.
  • Data processor -- processes personal data on behalf of a controller. Your ticketing platform, your email marketing service, and your payment processor are typically data processors acting on your instructions.
  • Joint controllers -- if you and another organisation jointly determine the purposes and means of processing, you are joint controllers and must have an arrangement defining your respective responsibilities.

Lawful bases for processing

Every piece of personal data you process must have a lawful basis. The six lawful bases under UK GDPR are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. For event organisers, the most relevant are:

  • Contract -- processing attendee data to fulfil a ticket purchase is necessary for the performance of a contract. You do not need separate consent to process someone's name and email address in order to send them their ticket.
  • Legitimate interests -- you may have a legitimate interest in processing data for purposes such as event security, fraud prevention, or improving your events based on feedback. You must carry out a Legitimate Interests Assessment (LIA) to balance your interests against the individual's rights.
  • Consent -- required for optional processing, such as adding someone to your marketing mailing list, sharing their data with sponsors, or taking and publishing photographs where consent is the appropriate lawful basis.

Under UK GDPR, consent must be freely given, specific, informed, and unambiguous. For event organisers, this means:

  • Pre-ticked boxes are not valid consent. The attendee must take a positive action, such as ticking an unticked box.
  • Bundling consent with terms and conditions is not valid. You cannot make ticket purchase conditional on agreeing to receive marketing emails.
  • You must keep records of consent: who consented, when, what they were told, and how they consented.
  • Individuals must be able to withdraw consent as easily as they gave it. If they signed up via a checkbox at checkout, they must be able to unsubscribe via a simple link in your emails.

When setting up your online ticket sales, make sure your checkout flow includes a clear, separate opt-in for marketing communications, distinct from the purchase itself.

Privacy notices

You must provide a privacy notice to individuals at the point you collect their data. The notice must explain: who you are (the data controller), what data you collect, why you collect it (the lawful basis), who you share it with, how long you keep it, and the individual's rights. The notice must be written in clear, plain language.

For events, you should have a privacy notice on your website, a shortened version or link to it on your ticket purchase page, and consideration of notices at the event itself (for example, signs informing attendees about CCTV or photography).

Data sharing with third parties

Event organisers commonly share attendee data with:

  • Ticketing platforms -- these are usually data processors. You should have a data processing agreement in place that sets out what data they process, for what purpose, and the security measures they implement.
  • Venue operators -- if the venue needs attendee data for security or capacity management, you need a lawful basis for sharing it and should inform attendees in your privacy notice.
  • Sponsors and partners -- sharing attendee data with sponsors requires explicit consent from the attendee unless you have another lawful basis. Never share attendee contact lists with sponsors without clear, informed consent.
  • Payment processors -- payment card data is processed by your payment gateway (such as Stripe) under their own data processing obligations, including PCI DSS compliance.

Data retention

You must not keep personal data for longer than necessary. Define retention periods for different categories of data and stick to them. For example, you might keep transaction records for seven years (to comply with HMRC requirements), attendee contact details for two years after their last purchase, and marketing preferences until consent is withdrawn.

Document your retention periods in a data retention policy and implement automated or manual processes to delete data when the retention period expires.

Data security

UK GDPR requires you to implement appropriate technical and organisational measures to protect personal data. For event organisers, this includes:

  • Using encrypted connections (HTTPS) for all web forms and payment pages.
  • Securing access to your event management systems with strong passwords and two-factor authentication.
  • Limiting access to attendee data to people who need it for their role.
  • Ensuring that portable devices (laptops, tablets, phones) containing personal data are encrypted.
  • Having a process for responding to data breaches: under UK GDPR, you must report certain personal data breaches to the ICO within 72 hours of becoming aware of them.

Photography and CCTV at events

Photographing attendees and operating CCTV at events involves processing personal data (images of identifiable individuals). Your lawful basis may be legitimate interests (for security purposes) or consent (for promotional photography). Whichever basis you use, inform attendees in advance through your privacy notice and signage at the event.

Be particularly careful with photographs of children. If you photograph children at your event for promotional purposes, you should obtain consent from a parent or guardian. Consider having designated photography zones and offering event areas where photography is not permitted for those who prefer not to be photographed.

Practical checklist

  • Write a privacy notice and display it on your website and ticket purchase pages.
  • Ensure marketing consent is collected via a clear, unticked opt-in checkbox.
  • Put data processing agreements in place with your ticketing platform, email service, and other processors.
  • Define and document your data retention periods.
  • Implement appropriate security measures for all systems holding personal data.
  • Train your team on data protection basics.
  • Have a data breach response plan.

Data protection compliance is not a one-off task. It requires ongoing attention as your events grow and your data processing activities evolve. The ICO provides a wealth of free guidance and tools, including a self-assessment toolkit for small organisations, that can help you build and maintain compliance.

Share this article

Find something worth going to

Browse what's on near you. Every ticket at face value, no booking fees, ever.

Browse events Run events? Sell with zero fees