All stories
August 18, 2026·23 min read

Attendee Data GDPR: A DPO-Reviewed Compliance Guide for Event Organisers

A practical DPO-reviewed guide to attendee data GDPR compliance for event organisers. Learn how to define lawful bases, minimise registration data, handle consent, manage processors, set retention periods, protect networking privacy and document attendee rights across the event lifecycle.

Y
Yağız GürbüzFounder, MeetWho
Published August 18, 2026 · Updated August 18, 2026
TL;DR
  • Attendee data under GDPR is personal information relating to an identifiable event participant.
  • A company name on its own may not identify an individual, while an email address such as firstname.lastname@company.com generally can.
  • In many event workflows, the organiser determines why attendee information is collected and how it will be used.
  • GDPR's core data-processing principles provide a useful framework for almost every event-data decision.
  • A useful GDPR event registration review starts with every individual form field.
Read as markdown (.md) — built for AI assistants
Key questions
  • Attendee data under GDPR is personal information relating to an identifiable event participant. It can include obvious identifiers such as a person's name and email address, but the scope is much broader.

  • A company name on its own may not identify an individual, while an email address such as firstname.lastname@company.com generally can. The practical principle is straightforward: do not assume information is outside GDPR simply because an event takes place in a professional or business setting.

  • In many event workflows, the organiser determines why attendee information is collected and how it will be used. That commonly places the organiser in the role of data controller for those purposes.

  • GDPR's core data-processing principles provide a useful framework for almost every event-data decision. For an organiser, they translate into practical questions about necessity, transparency, access and retention.

  • GDPR does not require consent for every use of attendee information. Instead, organisations need an appropriate lawful basis for each processing purpose under Article 6, and different activities within the same event can rely on different bases .

  • A strong attendee privacy process begins at the point where information is collected. Attendees should not have to search through several unrelated pages to understand who is collecting their information, why it is needed and what will happen to it.

Attendee Data GDPR: A DPO-Reviewed Compliance Guide for Event Organisers

Title: "Attendee Data GDPR: DPO-Reviewed Compliance Guide"

Description: "Learn how attendee data GDPR rules apply to events, from registration and consent to networking, retention, processors and attendee rights. A practical guide."

Attendee data GDPR compliance affects far more than a privacy checkbox on an event registration form. Organisers need to consider why attendee information is collected, which lawful basis applies, who can access it, whether networking or sponsor sharing is appropriate, how long records are retained and how attendee rights are handled. This practical guide turns those requirements into decisions across the full event lifecycle.

Attendee Data GDPR: A Practical Compliance Guide for Event Organisers

Running an event can involve collecting considerably more personal data than an attendee's name and email address. Registration forms may contain job titles, company details, dietary requirements or accessibility information. Check-in systems create attendance records. Networking tools may process professional profiles, interests and information about whom participants want to meet. Event teams may also communicate with attendees before and after the event or work with sponsors and technology providers that need access to certain data.

Under the General Data Protection Regulation (GDPR), these activities should not be treated as one undifferentiated use of personal information. An organiser needs to understand what data is being processed, for which purpose, on what lawful basis, by whom and for how long. The appropriate answer can vary from one activity to another. This guide provides practical information for event organisers; it is not a substitute for legal advice tailored to a particular organisation, jurisdiction or processing activity.

What Does GDPR Mean for Attendee Data?

Attendee data under GDPR is personal information relating to an identifiable event participant. It can include obvious identifiers such as a person's name and email address, but the scope is much broader. Professional information, registration records, check-in activity, networking preferences and other information connected with an identifiable person may also constitute personal data.

Whether GDPR applies also depends on its material and territorial scope. For organisations within scope, the important operational point is that event attendee data should be mapped throughout its lifecycle rather than considered only at the moment a registration form is submitted. Collection is only the beginning: organisers also need to consider access, use, disclosure, security, retention and eventual deletion or anonymisation.

What Counts as Personal Data at an Event?

Common examples can include:

  • Name and contact details
  • Company and job title
  • Registration and attendance status
  • Check-in records
  • Professional profile information
  • Networking interests and preferences
  • Photographs linked to identifiable attendees
  • IP addresses or relevant device information
  • Messages or connection information where a networking service provides those functions

Context matters. A company name on its own may not identify an individual, while an email address such as firstname.lastname@company.com generally can. Similarly, information about dietary requirements or accessibility needs may reveal health-related information in some circumstances and therefore require additional consideration under GDPR rules concerning special categories of personal data.

The practical principle is straightforward: do not assume information is outside GDPR simply because an event takes place in a professional or business setting.

Who Is the Controller and Who Is the Processor?

In many event workflows, the organiser determines why attendee information is collected and how it will be used. That commonly places the organiser in the role of data controller for those purposes. A registration or event technology provider processing information on the organiser's instructions may act as a data processor.

Those labels cannot be assigned purely by contract language or by calling a company a “vendor”. GDPR roles depend on the actual purposes and means of processing. A supplier might be a processor for one activity while acting differently for another processing purpose.

This distinction matters because controllers and processors have different responsibilities. Before introducing an event platform, CRM, badge provider, email service or other supplier into an attendee-data workflow, organisers should understand what that provider receives, why it needs the information and what role each party plays.

Which GDPR Principles Apply to Event Attendee Data?

GDPR's core data-processing principles provide a useful framework for almost every event-data decision. For an organiser, they translate into practical questions about necessity, transparency, access and retention.

GDPR principlePractical implication for event organisers
Lawfulness, fairness and transparencyExplain what attendee information is collected, why it is used and who may receive it
Purpose limitationDo not automatically reuse registration information for unrelated purposes
Data minimisationCollect only information reasonably needed for the defined purpose
AccuracyProvide a practical way to correct relevant attendee information
Storage limitationEstablish retention criteria instead of keeping attendee databases indefinitely
Integrity and confidentialityRestrict access and apply appropriate safeguards
AccountabilityDocument important privacy decisions, vendors and processes

Data Minimisation Starts With the Registration Form

A useful GDPR event registration review starts with every individual form field. For each question, the organiser should be able to answer: What specific event purpose requires us to collect this information?

A name and contact method may be necessary to administer many registrations. A job title might be relevant to a professional networking programme. Asking for a telephone number, home address, date of birth or extensive demographic information merely because it “might be useful later” is much harder to reconcile with data minimisation if there is no defined need.

Reducing unnecessary fields has benefits beyond compliance. Shorter forms can also make registration clearer and reduce the amount of sensitive information an organisation must secure, govern and eventually delete.

Purpose Limitation Continues After the Event

The reason data was originally collected remains important after registration closes. Signing up for a conference does not automatically mean an attendee expects their email address to be added indefinitely to unrelated marketing databases or transferred to sponsors for prospecting.

Organisers should therefore distinguish event administration from subsequent uses. Sending an essential venue update, managing check-in, enabling an attendee-requested networking experience and delivering unrelated promotional communications are different processing activities and may require different lawful-basis and transparency assessments.

What Lawful Basis Should You Use for Attendee Data Under GDPR?

GDPR does not require consent for every use of attendee information. Instead, organisations need an appropriate lawful basis for each processing purpose under Article 6, and different activities within the same event can rely on different bases.

For example, processing genuinely necessary to provide an event service requested by an attendee may raise contractual-necessity considerations. Certain operational activities may be assessed under legitimate interests where the relevant conditions are met. Optional promotional or networking activities may require a separate analysis, and consent may be appropriate in particular contexts.

The key mistake to avoid is choosing one lawful basis for an entire attendee database and assuming it automatically covers every future use of the information.

Contractual Necessity

Contractual necessity can apply where processing is objectively necessary to deliver a service that the attendee has requested. For an event organiser, this may include using registration details to confirm a booking, communicate essential event information or provide access to an event where those activities are genuinely required to perform the relevant agreement.

The test should be applied narrowly. Simply mentioning a processing activity in terms and conditions does not automatically make it contractually necessary. If an event can be delivered without a particular use of attendee data, another lawful basis may need to be considered.

Legitimate Interests

Legitimate interests may be relevant to some event operations, but it is not a blanket justification for processing attendee information. An organiser should identify the specific interest being pursued, assess whether the processing is necessary for that purpose and consider the impact on attendees' rights and reasonable expectations.

A documented Legitimate Interests Assessment can help structure that analysis. The assessment should consider alternatives that use less personal data, the nature of the information involved, what attendees would reasonably expect and whether additional safeguards could reduce privacy risks. The outcome may differ depending on the activity.

Consent

Consent can be an appropriate lawful basis when participation in a particular processing activity is genuinely optional. Under GDPR, valid consent must be freely given, specific, informed and unambiguous, and the organisation should be able to demonstrate that it was obtained. Withdrawing consent should also be possible without unnecessary friction.

This means consent should not be treated as a universal checkbox attached to every registration form. If an attendee must agree to optional marketing in order to access an event they have already paid for, for example, questions can arise about whether that choice was truly freely given.

When Separate Consent May Be Appropriate

Separate choices can be useful where an activity is distinct from the core event experience. Depending on the circumstances and applicable rules, this may include optional marketing subscriptions, particular forms of promotional communication or optional participation in attendee networking visibility.

The interface should make those choices understandable. Combining event administration, sponsor communications, newsletter subscriptions and networking permissions into one broad statement makes it harder for attendees to understand what they are agreeing to and harder for organisers to demonstrate that each purpose was handled appropriately.

Why Pre-Ticked Boxes Are a Bad Pattern

Consent requires an affirmative action. Pre-selected boxes, inactivity or silence should not be relied upon as valid GDPR consent.

Registration interfaces should instead make optional choices clear and deliberate. Where consent is used, organisers should also retain an appropriate record of what the attendee agreed to, when the choice was made and which information was presented at that time.

How Should GDPR-Compliant Event Registration Work?

A strong attendee privacy process begins at the point where information is collected. Attendees should not have to search through several unrelated pages to understand who is collecting their information, why it is needed and what will happen to it.

The registration experience should therefore combine data minimisation with clear privacy information. Organisers should also distinguish between information required to administer the event and optional uses such as marketing or networking. This helps reduce ambiguity while creating a more understandable registration journey.

What Your Registration Privacy Notice Should Explain

A privacy notice should describe the processing in clear language and include the information required by the applicable GDPR transparency provisions. Depending on the circumstances, attendees may need to be told:

  • The identity and contact details of the controller
  • The purposes for which their data will be processed
  • The relevant lawful basis or bases
  • Who may receive the information
  • How long the information will be retained, or how that period is determined
  • Whether international transfers are involved and which safeguards apply
  • Which data subject rights may apply
  • How to raise a complaint with the relevant supervisory authority
  • Whether requested information is required and what happens if it is not provided
  • Relevant information about automated decision-making where applicable

The notice should accurately reflect the real event workflow. Copying a generic privacy notice from another organisation can create gaps if the actual registration, sponsor-sharing, networking or retention practices differ.

Separate Event Operations From Marketing Choices

Operational event communication and marketing should not automatically be treated as the same purpose. An organiser may need to send information that is necessary to administer the event, such as schedule changes, access instructions or venue updates. That does not automatically justify enrolling the attendee in an unrelated promotional mailing programme.

Where optional marketing preferences are offered, the interface should make the distinction explicit. Electronic direct marketing can also be governed by rules beyond GDPR, including national legislation implementing or supplementing ePrivacy requirements, so organisers should assess the relevant jurisdiction rather than relying on GDPR alone.

Can You Share an Attendee List Under GDPR?

Event registration does not automatically authorise an organiser to publish or distribute an attendee's personal information. Before sharing an attendee list, the organiser should identify the purpose, determine the appropriate lawful basis, consider what attendees were told and decide whether the proposed visibility is proportionate.

This is especially important where a list contains names, companies, job titles, email addresses, photographs or professional profiles. A participant may reasonably expect an organiser to use those details to administer a conference without expecting the same information to become available to every attendee, sponsor or external party.

Public Attendee Lists vs Permission-Based Networking

Traditional event networking often relies on broad attendee directories that require participants to search through long lists of people. A more privacy-conscious model can instead control visibility and use attendee preferences to help surface relevant connections.

DimensionBroad attendee directoryPermission-based approach
VisibilityPotentially wideControlled through settings and permissions
DiscoveryAttendees search manuallyRelevant participants can be recommended
Data exposureMay reveal many profilesCan limit unnecessary profile exposure
Networking goalBrowse many peopleFind people with stronger mutual relevance

Neither model is automatically compliant or non-compliant solely because of its design. The organiser still needs an appropriate lawful basis, transparency, safeguards and configuration that match the actual processing.

How MeetWho Approaches Networking Privacy

MeetWho is designed around permission-based, relevance-focused networking rather than treating the attendee list as a commodity. Organisers can determine networking privacy settings, while participants can create professional profiles describing what they are working on, what they are looking for, whom they want to meet and where they can help others.

Among users who have permitted the networking experience, MeetWho can analyse those signals together with event goals and shared interests to recommend relevant people. Recommendations can explain why two participants may benefit from meeting, how they could help one another and how a conversation might begin.

MeetWho does not sell attendee lists, and paid membership does not unlock hidden profiles or private contact information. These product choices can support a more deliberate networking experience, but they do not by themselves determine an organiser's GDPR compliance.

Can Sponsors Receive Attendee Data?

Sponsors do not automatically gain a right to receive attendee information simply because they support an event. If an organiser plans to disclose personal data to a sponsor, that transfer should be assessed as a separate processing activity with its own purpose, lawful basis, transparency requirements and role allocation.

There is also an important difference between showing sponsor content to attendees and handing sponsors identifiable attendee data. A logo on an event page, a sponsored session or an attendee voluntarily approaching a sponsor stand is not the same as transferring a registration database containing names, email addresses or professional profiles.

Questions to Answer Before Sharing Data With a Sponsor

Before any disclosure takes place, organisers should be able to answer:

  • What exact attendee data will be shared?
  • Why does the sponsor need that information?
  • What lawful basis applies to the disclosure?
  • Were attendees clearly informed about the sharing?
  • Is separate consent required in this particular context?
  • Is the sponsor acting as an independent controller, joint controller or processor?
  • How long will the sponsor retain the information?
  • Will the sponsor use it for its own marketing purposes?

These questions help prevent vague arrangements such as “sponsors receive attendee details” from becoming an undocumented default. Where sponsor marketing is involved, organisers should also consider applicable direct-marketing and ePrivacy rules in addition to GDPR.

How Long Should You Keep Event Attendee Data?

GDPR does not establish a universal rule requiring organisers to delete all event records after a fixed number of days or months. Instead, the storage-limitation principle requires personal data to be kept no longer than necessary for the purposes for which it is processed, subject to any applicable legal or regulatory obligations.

That means different categories of attendee information may have different retention periods. A registration record, a marketing preference, a support request and a networking profile do not necessarily serve the same purpose and should not automatically be retained on the same schedule.

Build an Attendee Data Retention Schedule

A documented retention schedule helps turn a broad privacy principle into an operational process.

Data categoryExample purposeRetention decision
Registration recordEvent administrationRetain only while justified by operational or legal needs
Check-in recordAttendance managementReview once the attendance purpose has ended
Marketing preferenceMarketing complianceRetain appropriate consent or objection records as needed
Networking profileNetworking experienceRetain according to the stated account or service purpose
Support recordCustomer supportFollow the organisation's documented support-retention policy

The key is not to invent arbitrary dates but to define and document why each category is kept. Once the relevant purpose expires, organisers should consider deletion or, where appropriate, effective anonymisation.

Exported spreadsheets deserve particular attention. Event teams frequently download attendee lists for check-in, speaker coordination or temporary operational tasks. Those files can persist on personal devices, shared drives or email inboxes long after the event platform itself has been cleaned up.

What GDPR Rights Do Event Attendees Have?

Depending on the circumstances and lawful basis involved, attendees may have rights including access, rectification, erasure, restriction, objection and data portability. Not every right applies identically to every processing activity, but organisers should have a process for recognising and responding to requests.

A strong event data protection workflow therefore includes more than publishing a privacy notice. The organisation should know where attendee information is held, who is responsible for handling a request and which suppliers may need to assist.

Access, Correction and Erasure

An attendee may ask what personal information an organiser holds about them or request correction of inaccurate details. In some situations, they may also request erasure.

The organiser needs to be able to locate relevant information across systems rather than treating the main registration database as the only source. Personal data may also exist in email tools, check-in systems, CRM records, exported spreadsheets or networking platforms.

Erasure is not absolute. There may be situations in which data must or may lawfully be retained despite a request, so the response should be based on the actual circumstances rather than an automatic delete-or-refuse rule.

Objection, Restriction and Portability

The right to object can be particularly relevant where processing relies on legitimate interests or involves direct marketing. Restriction may apply in specific situations, while data portability is conditional on factors including the lawful basis and whether processing is carried out by automated means.

Organisers do not need to turn every event into a legal workflow, but they should establish a clear internal route for receiving, verifying and handling requests within the applicable GDPR timeframes.

What If the Data Is Held by an Event Platform?

Where an event technology provider acts as a processor, the organiser may still remain responsible as controller for handling the attendee's request. The processor should be able to assist the controller where required under the applicable agreement and GDPR obligations.

This is one reason vendor selection should include privacy operations, not only feature comparisons. A platform should fit into the organiser's ability to locate, correct, export or delete relevant information where legally required.

Event Vendors, DPAs and International Data Transfers

Most modern events depend on several technology providers. Registration systems, email services, video platforms, badge tools, analytics products and networking software can all become part of the attendee-data chain.

Organisers should therefore maintain a clear view of which vendors process personal data, for what purpose and under which contractual arrangement. This helps prevent a common problem: knowing which platform collected the data but not knowing which additional services received copies of it.

What to Review in an Event Technology Provider

A practical supplier review should consider:

  • The provider's role in the processing
  • The purposes for which data is processed
  • Confidentiality obligations
  • Appropriate security measures
  • Use of subprocessors
  • Assistance with data subject requests
  • Deletion or return of data
  • Personal data breach support
  • International transfer arrangements
  • Applicable contractual documentation

Organisers should verify these points from current provider documentation rather than relying on marketing claims.

When Do You Need a Data Processing Agreement?

Where a service provider processes personal data on behalf of an organiser as a processor, Article 28 GDPR requires an appropriate data processing agreement or equivalent contractual terms containing specified safeguards and obligations.

A DPA is important, but it is not a compliance shortcut. The organiser still needs to understand the actual processing, assess the supplier and configure the service appropriately. Equally, not every supplier relationship is automatically controller-to-processor; the correct role depends on what each party actually does with the data.

What About International Transfers?

If personal data is transferred outside the relevant protected jurisdiction, the organiser may need to assess the applicable international transfer mechanism. Depending on the situation, this can involve adequacy decisions, Standard Contractual Clauses or other recognised safeguards.

For UK-related processing, separate UK GDPR transfer mechanisms may also be relevant. Because transfer requirements depend heavily on jurisdiction, destination and contractual arrangements, organisers should use current guidance from the European Data Protection Board, European Commission, Information Commissioner's Office or other relevant supervisory authority rather than relying on generic assumptions.

How to Protect Attendee Data Before, During and After an Event

Effective attendee data GDPR practices should follow the entire event lifecycle. Privacy decisions made during registration can lose their value if attendee spreadsheets are later copied to uncontrolled devices, networking settings expose more information than expected or post-event records are retained without a defined purpose.

A lifecycle approach gives organisers a practical way to apply GDPR principles at each stage. Rather than treating privacy as a one-time legal exercise, teams can build data minimisation, access controls and retention decisions into normal event operations.

Before the Event

Before registration opens, map the information the event genuinely needs. Review each registration field, identify its purpose and lawful basis, and make the relevant privacy information available when the data is collected.

Organisers should also:

  • Review registration fields for necessity
  • Identify relevant lawful bases
  • Configure attendee and networking visibility
  • Review processors and other recipients
  • Put required contractual arrangements in place
  • Restrict administrative access
  • Establish a retention approach
  • Prepare a process for attendee rights requests

This is also the right time to examine sponsor arrangements. If attendee information could be disclosed to sponsors or partners, the purpose, roles and transparency requirements should be established before data collection begins—not after a sponsor requests a spreadsheet.

During the Event

Live events create practical privacy risks that may not be visible during registration. Check-in devices can display attendee records, staff accounts may have broader permissions than necessary, and downloaded lists can circulate quickly among temporary event teams.

Access should therefore be limited to people who genuinely need it. Devices used for check-in should be appropriately protected, and organisers should avoid unnecessarily displaying attendee information in public-facing environments. Networking preferences and organiser-defined visibility settings should also continue to be respected throughout the event.

After the Event

Once an event ends, attendee data should not simply become a permanent archive. Review which records still serve a documented purpose and which temporary exports, duplicates or operational files can be removed.

Post-event communications also deserve a separate assessment. An operational message about an event is not automatically equivalent to permission for indefinite marketing. Organisers should continue to respect applicable preferences, objections and direct-marketing requirements while applying their documented retention schedule.

Attendee Data GDPR Checklist for Event Organisers

No checklist can guarantee GDPR compliance because the appropriate measures depend on the organisation, jurisdiction and processing involved. However, this operational checklist can help identify common gaps across the attendee lifecycle.

  • Map attendee data: Identify the personal data collected across registration, check-in, communications and networking.
  • Define each purpose: Document why every category of attendee information is needed.
  • Minimise registration fields: Remove questions that do not serve a defined purpose.
  • Identify lawful bases: Assess the appropriate basis for each distinct processing activity.
  • Provide privacy information: Give attendees clear information at the appropriate point of collection.
  • Separate optional choices: Do not bundle unrelated marketing or other optional activities into event administration.
  • Control networking visibility: Define what participants can see and how networking permissions operate.
  • Review sponsor sharing: Assess purpose, lawful basis, transparency and roles before disclosure.
  • Map controllers and processors: Understand what each organisation actually does with attendee data.
  • Put required DPAs in place: Address Article 28 requirements where a provider acts as a processor.
  • Review international transfers: Identify relevant destinations and applicable transfer safeguards.
  • Restrict staff access: Give attendee-data access only to people who need it.
  • Prepare for attendee rights: Establish a process for locating data and handling requests.
  • Set retention criteria: Define when different categories of information should be reviewed or deleted.
  • Remove unnecessary copies: Include exported spreadsheets, inbox attachments and temporary files.
  • Document decisions: Maintain evidence of important privacy, vendor and security assessments.

Privacy-Conscious Attendee Management and Networking With MeetWho

Privacy-conscious event management is not about preventing people from connecting. It is about creating a clear framework for collecting and using attendee information while avoiding unnecessary exposure. This becomes particularly important at professional events, where participants may want valuable introductions without wanting their profile or contact details broadly distributed.

MeetWho combines event creation, registration and networking within one platform. Organisers can create an event page for free, collect registrations, approve applications, manage a waitlist, send announcements and reminders, restrict online event links to registered attendees, use QR check-in and determine networking privacy settings.

From “Everyone Can See Everyone” to “Know Who to Meet”

MeetWho approaches professional networking around the principle “Know who to meet.” Instead of making the objective simply to browse as many attendees as possible, participants can describe what they are working on, what they need, whom they want to meet and where they can help other people.

For users who have permitted networking, MeetWho can analyse these signals alongside shared interests and event goals to rank relevant people. Recommendations can explain why meeting may be useful, how the participants could help each other and how they might start the conversation. A participant can send an introduction request, and messaging becomes available after a mutual connection.

This approach is designed to support meaningful networking while respecting organiser settings and participant permissions. It does not, however, replace the organiser's responsibility to assess its own purposes, lawful bases, notices, vendors and other GDPR obligations.

Planning an event? Create your event for free with MeetWho and manage registrations, approvals, waitlists and attendee communications in one place.

What MeetWho Does Not Do

Privacy positioning is most useful when its limits are explicit. MeetWho does not sell attendee lists. A paid membership does not provide access to hidden profiles or unlock participants' private contact information.

Organiser settings and attendee permission remain fundamental to networking visibility. MeetWho's product design can therefore support a more deliberate approach to attendee networking, but using any event platform should never be presented as automatically making an event GDPR compliant.

Frequently Asked Questions About Attendee Data and GDPR

Does GDPR Apply to Event Attendee Data?

Yes, attendee information can fall within GDPR when the regulation's material and territorial scope applies and the information relates to an identified or identifiable natural person. Names and email addresses are common examples, but registration records, professional profiles, check-in information and networking preferences can also constitute personal data.

An organiser should therefore consider the complete processing lifecycle rather than limiting its assessment to the registration form.

Do Attendees Need to Consent to Event Registration?

Not necessarily. Consent is one of the lawful bases available under GDPR, not a universal requirement for processing attendee information. An organiser should identify the appropriate lawful basis for each purpose.

Processing objectively necessary to provide a requested event service may involve contractual-necessity considerations, while other activities may require a different analysis. Optional marketing should not automatically be bundled into the basis used for event administration.

Can I Email Attendees After an Event?

Potentially, but the purpose matters. A necessary operational communication and a promotional campaign are different activities. Organisers should assess the relevant lawful basis, what attendees were told and any applicable electronic direct-marketing rules.

National ePrivacy or direct-marketing legislation may apply alongside GDPR, so event registration alone should not be treated as unlimited permission for future promotional emails.

Can I Give Attendee Email Addresses to Sponsors?

You should not assume that event registration authorises sponsor disclosure. Sharing attendee email addresses requires an assessment of the purpose, lawful basis, transparency provided to attendees and the respective roles of the parties.

If the sponsor intends to use those addresses for its own marketing, additional direct-marketing requirements may also be relevant.

Can Event Attendees See Each Other's Details?

They can where the event's processing model, lawful basis, transparency and privacy settings appropriately support that visibility. It should not be assumed that registering automatically makes an attendee's profile public.

A permission-based networking design can provide greater control by enabling relevant connections without relying on unrestricted exposure of an entire attendee directory.

How Long Can I Keep Attendee Information?

GDPR does not set one universal retention period for event attendee data. Information should be retained only for as long as its purpose and any applicable legal obligations justify.

Different records can therefore require different retention decisions. Organisers should document those criteria and periodically remove or appropriately anonymise information that is no longer needed.

Is a Business Email Address Personal Data Under GDPR?

A professional email address can be personal data when it identifies or relates to an individual. An address containing an employee's name is a common example.

The fact that information is used in a business or conference context does not automatically place it outside GDPR.

Do Event Platforms Need a Data Processing Agreement?

Where an event platform processes personal data on behalf of an organiser as a processor, the requirements of Article 28 GDPR are relevant, including the need for appropriate contractual terms.

The actual roles must still be assessed. Calling every technology supplier a processor without examining how and why it handles the information can lead to an inaccurate controller–processor analysis.

Does Using a GDPR-Friendly Event Platform Automatically Make an Event Compliant?

No. An event's compliance depends on the organiser's purposes, lawful bases, transparency, platform configuration, security practices, recipients, retention decisions and other processing circumstances.

Technology can support good privacy practices, but it cannot independently determine whether every activity carried out by an organiser complies with GDPR.

Final Takeaway: Treat Attendee Privacy as Part of Event Design

Good attendee data governance can be reduced to a useful operating principle: collect less, explain why, control access, respect preferences, share deliberately and delete information when its purpose no longer justifies keeping it. Applying those decisions before, during and after an event makes privacy part of event design rather than an administrative task added at the end.

For authoritative interpretation, organisers should consult the text of the General Data Protection Regulation on EUR-Lex, guidance from the European Data Protection Board and the European Commission's data protection resources. UK organisers should additionally consult current Information Commissioner's Office guidance. Requirements should be assessed against the organisation's actual processing and jurisdiction.

MeetWho gives organisers a way to create events, manage attendee registration and enable more intentional professional networking without treating attendee lists as something to sell or indiscriminately expose. The goal is not to help attendees meet everyone—it is to help them identify the right people for meaningful, mutually useful conversations.

Create your event for free with MeetWho and help attendees know who to meet.

More stories

Browse all
August 17, 2026·19 min

The Complete Guide to Recurring Event Series

A practical guide to planning, launching, managing, and improving a recurring event series. Learn how to choose the right cadence, structure registration, manage attendees, build community, measure performance, and create better networking experiences across every event in the series.

August 17, 2026·20 min

The Complete Guide to Event Data and Privacy

A practical event data privacy guide for organisers covering attendee data, consent, registration, networking, vendors, retention, security, and post-event handling. Learn how to design privacy-conscious event workflows while still enabling useful attendee experiences and meaningful professional networking.

August 6, 2026·20 min

Attendee Data Retention Policy Template for Event Organizers

Create a defensible attendee data retention policy with an editable template, data inventory, retention schedule, deletion workflow, lifecycle checklist, and source-backed guidance for event organizers. Includes privacy-conscious registration and networking guidance for MeetWho users.

August 6, 2026·18 min

How to Turn One Event Into a Repeating Community

Learn how to turn a successful event into a repeating community with a practical system for follow-up, member engagement, recurring programming, meaningful networking, and sustainable growth. This guide covers the full journey from event registration to post-event connection, community rituals, retention metrics, and the next event.

August 6, 2026·20 min

How to Build a Public Community Calendar That Ranks on Google

Learn how to build a public community calendar that people can discover, trust, and use. This practical guide covers calendar structure, event page SEO, schema markup, moderation, internal linking, local visibility, measurement, and conversion—plus how MeetWho can support registration, attendee management, and meaningful event networking.

July 30, 2026·17 min

How to Increase Event Attendee Retention: A Practical Playbook

Learn how to increase event attendee retention before, during, and after an event. This practical guide covers attendee journey design, personalized communication, meaningful networking, engagement measurement, feedback loops, and repeat-registration strategies for conferences, workshops, communities, and professional events.

July 27, 2026·18 min

Most Important Event KPIs for Organizers: Metrics That Actually Matter

A practical guide to the most important event KPIs for organizers, covering registration, attendance, engagement, networking, satisfaction, financial performance, retention, and post-event outcomes. Learn which metrics matter, how to calculate them, and how to build a KPI framework around real event goals.

July 27, 2026·18 min

How to Create an Event Calendar for Your Community: A Practical Guide

Learn how to create an event calendar for your community that keeps events organised, improves attendance, simplifies registrations, and helps members discover relevant opportunities. This practical guide covers calendar structure, event information, publishing workflows, promotion, management, accessibility, measurement, and meaningful networking.