Since 2018, the GDPR (General Data Protection Regulation) has governed the handling of personal data across the EU. For events, this covers the entire attendee journey: registration, payments, photo and video recordings, data sharing with sponsors, and collaboration with service providers such as hotels and IT vendors.
Scope: EU-wide, plus EU citizens worldwide
Potential fines: Up to €20 million or 4% of annual turnover
Supervisory authority: State Data Protection Commissioners (DE)
Why the GDPR is critical for event organizers
By nature, a conference collects large amounts of personal data: registration details, payment information, photographic recordings, behavioral data within the event app, and lead handovers to sponsors. The GDPR requires that there is a legal basis for each of these processing activities, that the individuals concerned are informed, and that they can exercise their rights (access, erasure, withdrawal) at any time.
Violations can not only lead to significant fines but—perhaps even worse—reputational damage within the community and a loss of trust among speakers, sponsors, and attendees.
Data flows at the conference
The GDPR covers every stage of the attendee lifecycle at the conference:
- Registration: Collection of master data, tickets, payment information
- Communication: Sending confirmations, reminders, newsletters (consent required!)
- Payment: Transmission to payment service providers, storage of billing data
- On-site: Check-in scans, photo and video recordings, Wi-Fi logins if applicable
- Event app and platform: Profiles, networking contacts, behavioral data
- Exhibitor contacts: Lead retrieval, business card exchange
- Follow-up: Certificates of attendance, surveys, evaluations
- Archiving: Retention for accounting, future events, legal obligations
Obligations in detail
Legal bases
Every data processing activity requires a legal basis. Typical for events:
- Performance of a contract (Art. 6 para. 1 lit. b) for ticketing, check-in, certificates
- Legal obligation (lit. c) for accounting, retention periods
- Legitimate interest (Art. 6(1)(f) GDPR) with balancing of interests – e.g., for event photos
- Consent (Art. 6(1)(a) GDPR) for newsletters, photo publication, lead transfer
Information obligations
At the latest upon registration, a privacy policy must provide information on all processing activities – who processes what, for what purpose, for how long, with whom it is shared, and what rights exist.
Data Processing Agreement (DPA)
With every service provider that processes personal data (conference software, email distribution, hotel, printing services, lead retrieval), a data processing agreement must be concluded – in writing, before the first data transfer. Converia provides a template for this, developed in collaboration with data protection officers from universities and PCOs. It works for almost all cases but can be adapted if necessary.
Data minimization
Only collect data that is necessary for the specific purpose. Example: Only ask for a date of birth if it is truly required (e.g., for CME reports) – otherwise, omit it.
Deletion policy
Clear deadlines for when specific data will be deleted. Accounting data for 10 years, marketing data usually 2–3 years, participant data without a follow-up event typically 1–2 years. Converia supports this with its own data cleanup tools.
Special topic: Photo and video recordings
Event recordings are a classic source of GDPR violations. To be safe:
- Signs at the entrance notifying attendees of recordings are legally insufficient if individuals are clearly identifiable
- Active consent (e.g., via registration form or a different colored lanyard for "no photos") is best practice
- Speakers and panelists require separate image rights agreements
- Publication on social media is a separate processing activity and requires its own consent
- Live streaming has additional rules (viewer data, recording rights)
Sponsorship and lead handover
The transfer of attendee data to sponsors is only possible with active, granular consent from the participants – blanket "you consent to data transfer" clauses are invalid. In practice, this means:
- At the booth, the badge is only scanned after a conscious action scanned
- Separate opt-in in the registration form for "data may be shared with exhibitors"
- Lead retrieval devices document the time and location of the scan (burden of proof)
Practical checklist
- Current privacy policy linked in the registration form and on the website
- DPA signed and archived with all service providers
- Record of processing activities maintained
- Data protection officer appointed (required for 20+ people regularly processing data)
- Consent documented by version (which version was agreed to and when)
- Deletion and retention periods technically implemented
- Employees and volunteers committed to data privacy
- Emergency plan for data breaches (mandatory reporting within 72 hours!)
GDPR compliance in Converia
Converia is designed to be GDPR-compliant from the ground up: hosting in EU data centers, data processing agreement included.
Data protection as a standard, not a hurdle
With Converia, you fulfill your event's GDPR obligations without extra effort – because the platform meets the requirements out-of-the-box.
- Payment management – Ticketing & registration
- Attendee management – Ticketing & registration
- Event registration – Ticketing & registration
EU hosting, granular consent, data processing agreement included – GDPR is a standard, not an add-on.