Data Protection at Events – What You Need to Know
Since the GDPR came into effect in May 2018, event organizers must also take data protection seriously. This guide helps you plan in a legally compliant way.
Guest Lists and Registrations
Clear rules apply when collecting guest data:
Only necessary data : Name, email, and possibly company are usually sufficient Purpose limitation : Guest data may only be used for the event Consent : For newsletters or marketing, you need separate consent Deletion deadlines : After the event, data must be deleted unless legal retention periods apply
Photography and Image Rights
Photography at events is a sensitive topic:
Advance notice : Inform guests in advance that photos will be taken Consent : For publishing photos of individuals, you generally need consent Exceptions : At large events, overview shots may fall under freedom of panorama Opt out : Offer guests the option to be excluded from photography (e.g., colored wristbands)
Digital Event Tools
When using online tools for planning:
Data processing agreement : Conclude DPA with tool providers Server location : Prefer providers with EU servers Data security : Encryption and secure passwords are mandatory Participant lists : Don't share openly
Video Surveillance and Livestreaming
Notice obligation : Visible notice signs for camera surveillance Livestreaming : Participants must be informed and able to consent Recordings : Define storage duration and access rights in advance
Ticketing and Payment Data
For paid events:
PCI DSS compliant : Payment service providers must be certified Invoice data : Subject to tax retention obligation (10 years) Ticket data : Delete after the event unless tax relevant
Checklist for GDPR-Compliant Events
1. Create privacy policy for the event 2. Maintain processing records 3. Prepare consent forms (photos, newsletter) 4. Conclude DPAs with service providers 5. Brief employees and helpers on data protection 6. Plan deletion concept for after the event
At Zeitgeist Taunus, we take data protection seriously. Our booking processes and systems are GDPR compliant – so you can focus on your event.
Checklist before confirming the booking
Assign responsibility for guest data and photos. Check the purpose, legal basis, recipients and retention period for each processing activity. Seek individual professional advice when uncertain; a blanket photo consent does not resolve every situation.