Skip to content

Data Privacy in Event Registrations: What’s Changed Since GDPR

Eight years after the introduction of the GDPR, the landscape of data protection in event registrations continues to evolve, requiring organizers to closely monitor regulatory developments and reduce compliance risks.

From a legal perspective, an event registration form is a point of personal data collection with significant obligations. Names, email addresses, company details, dietary requirements, and accessibility information may all be collected, with some falling into special categories of personal data. The principle of data minimization remains fundamental: every field requested must serve a clear, documented purpose rather than simply being ‘nice to have.’

Cross-border data transfers have become an increasingly important issue for international event organizers. When attendees come from multiple countries and data is stored in cloud infrastructure outside the European Economic Area, additional contractual safeguards are required. Choosing providers with transparent data residency policies is now a key platform selection criterion rather than merely a technical detail.

Consent management has also evolved beyond a simple terms and conditions checkbox. Modern requirements call for separate consent for each processing purpose: event participation, marketing communications, and the use of photography or video should each be handled independently. Combining them into a single blanket consent is now considered a clear compliance risk.

The right to erasure after an event also deserves particular attention. Many organizers retain attendee lists indefinitely ‘for future use,’ despite this conflicting with the storage limitation principle. Establishing a clear retention policy, including automatic deletion or anonymization after a defined period, is increasingly regarded as best practice by partners and sponsors alike.

Finally, the growing overlap between AI regulations and registration data is becoming increasingly important. As more platforms use algorithms for attendee matchmaking, attendance forecasting, and personalized content recommendations, organizers must be able to explain how personal data is used within these automated processes in line with emerging AI regulatory frameworks.

Compliance should not be viewed as a bureaucratic burden but as a foundation of trust. Attendees are far more willing to share their data with organizers who demonstrate transparency and genuine respect for privacy.

Back To Top