Skip to main content
Ticketing Guides

GDPR for Event Organisers: What You Need to Know

A practical guide to GDPR compliance for event organisers, covering consent, data retention, attendee rights, and ICO registration.

Admit One
TICKETING GUIDES · No. 643

GDPR for Event Organisers: What You Need to Know

6 min read

The General Data Protection Regulation has been in force since 2018, but many event organisers are still unsure about what it actually requires. The rules are not as complicated as they sound, but getting them wrong can lead to fines, reputational damage, and loss of trust from your audience.

This guide covers what GDPR means in practice for anyone selling event tickets or collecting attendee data in the UK.

What GDPR actually means for events

GDPR (retained in UK law as the UK GDPR, alongside the Data Protection Act 2018) governs how you collect, store, use, and share personal data. For event organisers, personal data typically includes names, email addresses, phone numbers, and payment information collected during the ticket purchase process.

If you sell tickets online, you are a data controller. That means you are legally responsible for how attendee data is handled, even if a third-party platform processes the transactions on your behalf.

The good news is that compliance for most small-to-medium event organisers is straightforward. You do not need a dedicated data protection officer or a team of lawyers. You need clear processes, honest communication, and basic record-keeping.

Lawful basis for processing data

Under GDPR, you need a lawful basis to process personal data. For event ticketing, two bases are most relevant:

Contract: When someone buys a ticket, you have a contractual relationship. You need their name and email to fulfil the order, send the ticket, and communicate essential event information (venue changes, cancellations, etc.). No additional consent is needed for this.

Consent: If you want to use attendee data for marketing purposes, such as emailing them about future events, you need their explicit, freely given consent. This must be a positive opt-in action, not a pre-ticked box.

This is where most organisers trip up. You cannot automatically add ticket buyers to your mailing list. They must actively choose to receive marketing communications.

Best practice is to include an unticked checkbox during the ticket purchase process with clear wording such as: "I would like to receive emails about future events from [your organisation]." If they tick it, you can email them. If they do not, you cannot.

Every marketing email must also include a clear unsubscribe link. When someone unsubscribes, you must remove them from your mailing list promptly. Most email marketing tools like Mailchimp or MailerLite handle this automatically.

What about soft opt-in?

The Privacy and Electronic Communications Regulations (PECR) allow a "soft opt-in" for existing customers. If someone has bought a ticket from you, you can email them about similar events without explicit consent, provided you gave them an easy way to opt out at the point of purchase and in every subsequent email. This is a useful exception for event organisers but must be applied carefully.

Data retention

GDPR requires that you do not keep personal data for longer than necessary. For event data, sensible retention periods are:

  • Transaction records: Keep for six years (required by HMRC for tax purposes)
  • Attendee contact details: Keep only as long as you have a valid reason. If someone attended one event two years ago and has not engaged since, consider deleting their data
  • Marketing lists: Review regularly. Remove anyone who has not engaged in twelve to eighteen months

Document your retention periods in your privacy policy so attendees know what to expect.

Attendee rights

Under GDPR, your attendees have several rights that you must be prepared to honour:

  • Right of access: They can request a copy of all personal data you hold about them. You must respond within one month
  • Right to rectification: They can ask you to correct inaccurate data
  • Right to erasure: They can ask you to delete their data (with some exceptions, such as data you are legally required to keep for tax purposes)
  • Right to object: They can object to their data being used for marketing at any time

In practice, subject access requests from individual event attendees are rare. But you need a process in place to handle them if they come in.

Writing a privacy policy

Every event organiser who collects personal data needs a privacy policy. It must be written in clear, plain language and cover:

  • What data you collect and why
  • Your lawful basis for processing it
  • Who you share data with (ticketing platforms, payment processors, email marketing tools)
  • How long you keep data
  • How attendees can exercise their rights
  • Your contact details for data protection queries

Link to your privacy policy from your ticket purchase page and your website footer. The ICO provides free templates and guidance on writing a privacy policy that meets the requirements.

ICO registration

If you process personal data as an organisation, you likely need to register with the Information Commissioner's Office (ICO). The registration fee is modest: forty pounds per year for small organisations, sixty pounds for medium, and two thousand eight hundred pounds for large organisations with a turnover above thirty-six million pounds.

You can check whether you need to register using the ICO's self-assessment tool on their website. Most event organisers selling tickets online will need to register.

Using third-party platforms

When you use a ticketing platform like Tickts, the platform acts as a data processor on your behalf. You remain the data controller. This means you should understand what data the platform collects and how it handles it.

Check that your ticketing platform has its own GDPR-compliant privacy policy, uses encryption for data in transit and at rest, and does not use attendee data for its own marketing purposes without consent.

Practical steps to get compliant

For most event organisers, GDPR compliance comes down to a few concrete actions:

  1. Write a clear privacy policy and link to it from your ticketing pages
  2. Use an opt-in checkbox for marketing consent during ticket purchases
  3. Include unsubscribe links in all marketing emails
  4. Document what data you hold and how long you keep it
  5. Register with the ICO
  6. Have a process for handling data requests from attendees

None of this is difficult or expensive. It is about respecting your attendees' data and being transparent about how you use it. That transparency builds trust, and trust sells tickets.

Share this article

Find something worth going to

Browse what's on near you. Every ticket at face value, no booking fees, ever.

Browse events Run events? Sell with zero fees