GDPR for Conferences and Congresses

Data protection requirements for event organizers – from registration and photos/videos to lead handovers to sponsors.

Since 2018, the GDPR (General Data Protection Regulation) has governed the handling of personal data across the EU. For events, this covers the entire attendee journey: registration, payments, photo and video recordings, data sharing with sponsors, and collaboration with service providers such as hotels and IT vendors.

Scope: EU-wide, plus EU citizens worldwide

Potential fines: Up to €20 million or 4% of annual turnover

Supervisory authority: State Data Protection Commissioners (DE)

Why the GDPR is critical for event organizers

By nature, a conference collects large amounts of personal data: registration details, payment information, photographic recordings, behavioral data within the event app, and lead handovers to sponsors. The GDPR requires that there is a legal basis for each of these processing activities, that the individuals concerned are informed, and that they can exercise their rights (access, erasure, withdrawal) at any time.

Violations can not only lead to significant fines but—perhaps even worse—reputational damage within the community and a loss of trust among speakers, sponsors, and attendees.

Data flows at the conference

The GDPR covers every stage of the attendee lifecycle at the conference:

  • Registration: Collection of master data, tickets, payment information
  • Communication: Sending confirmations, reminders, newsletters (consent required!)
  • Payment: Transmission to payment service providers, storage of billing data
  • On-site: Check-in scans, photo and video recordings, Wi-Fi logins if applicable
  • Event app and platform: Profiles, networking contacts, behavioral data
  • Exhibitor contacts: Lead retrieval, business card exchange
  • Follow-up: Certificates of attendance, surveys, evaluations
  • Archiving: Retention for accounting, future events, legal obligations

Obligations in detail

Legal bases

Every data processing activity requires a legal basis. Typical for events:

  • Performance of a contract (Art. 6 para. 1 lit. b) for ticketing, check-in, certificates
  • Legal obligation (lit. c) for accounting, retention periods
  • Legitimate interest (Art. 6(1)(f) GDPR) with balancing of interests – e.g., for event photos
  • Consent (Art. 6(1)(a) GDPR) for newsletters, photo publication, lead transfer

Information obligations

At the latest upon registration, a privacy policy must provide information on all processing activities – who processes what, for what purpose, for how long, with whom it is shared, and what rights exist.

Data Processing Agreement (DPA)

With every service provider that processes personal data (conference software, email distribution, hotel, printing services, lead retrieval), a data processing agreement must be concluded – in writing, before the first data transfer. Converia provides a template for this, developed in collaboration with data protection officers from universities and PCOs. It works for almost all cases but can be adapted if necessary.

Data minimization

Only collect data that is necessary for the specific purpose. Example: Only ask for a date of birth if it is truly required (e.g., for CME reports) – otherwise, omit it.

Deletion policy

Clear deadlines for when specific data will be deleted. Accounting data for 10 years, marketing data usually 2–3 years, participant data without a follow-up event typically 1–2 years. Converia supports this with its own data cleanup tools.

Special topic: Photo and video recordings

Event recordings are a classic source of GDPR violations. To be safe:

  • Signs at the entrance notifying attendees of recordings are legally insufficient if individuals are clearly identifiable
  • Active consent (e.g., via registration form or a different colored lanyard for "no photos") is best practice
  • Speakers and panelists require separate image rights agreements
  • Publication on social media is a separate processing activity and requires its own consent
  • Live streaming has additional rules (viewer data, recording rights)

Sponsorship and lead handover

The transfer of attendee data to sponsors is only possible with active, granular consent from the participants – blanket "you consent to data transfer" clauses are invalid. In practice, this means:

  • At the booth, the badge is only scanned after a conscious action scanned
  • Separate opt-in in the registration form for "data may be shared with exhibitors"
  • Lead retrieval devices document the time and location of the scan (burden of proof)

Practical checklist

  • Current privacy policy linked in the registration form and on the website
  • DPA signed and archived with all service providers
  • Record of processing activities maintained
  • Data protection officer appointed (required for 20+ people regularly processing data)
  • Consent documented by version (which version was agreed to and when)
  • Deletion and retention periods technically implemented
  • Employees and volunteers committed to data privacy
  • Emergency plan for data breaches (mandatory reporting within 72 hours!)

GDPR compliance in Converia

Converia is designed to be GDPR-compliant from the ground up: hosting in EU data centers, data processing agreement included.

Data protection as a standard, not a hurdle

With Converia, you fulfill your event's GDPR obligations without extra effort – because the platform meets the requirements out-of-the-box.

EU hosting, granular consent, data processing agreement included – GDPR is a standard, not an add-on.