Back to resources
Legal & practical

6 min read

Event check-in and GDPR: concrete obligations

Which data can you collect at check-in? How long should you keep it? What notices should you display? A clear, actionable guide to stay GDPR-compliant.

Why GDPR directly affects your welcome desk

Event check-in looks simple: verify a list, mark arrivals, handle latecomers. Yet at every step you process personal data: name, first name, email, company, sometimes job title or phone number.

As soon as you collect, store or update that data, GDPR applies.

Good news: you do not need a heavy legal setup. In most cases, a few well-applied rules are enough to stay compliant.

1. Only collect useful data

The minimization principle is central: only ask for what is necessary for the purpose.

Data generally legitimate for check-in

  • First and last name
  • Email address
  • Registration status (confirmed, waiting, present, absent)
  • Company (for B2B events)

Data to avoid without a strong justification

  • Date of birth
  • Full postal address
  • Phone number (if you do not use it)
  • Sensitive data (health, opinions, etc.)

In practice: if you cannot clearly explain why a field is useful on the day or for immediate follow-up, do not collect it.

2. Inform attendees clearly

Before or at registration, you must provide understandable information about data processing.

A simple GDPR notice should include:

  • Who is the data controller (your company/association)
  • Why you collect the data (registration and check-in management)
  • Legal basis (legitimate interest or contract performance, depending on context)
  • Retention period
  • Individual rights (access, rectification, erasure, objection)
  • Contact point (email)

The simplest approach: show this notice under the registration form and repeat it in your privacy policy.

3. Define a realistic retention period

Keeping lists forever is an unnecessary risk.

For a typical event, a pragmatic policy is to:

  • Keep operational data for the event duration + immediate follow-up
  • Archive only what is needed for invoicing or legal obligations
  • Delete or anonymize the rest after a defined delay

What matters is having a written rule that is actually applied — not a perfect universal duration.

4. Secure access on the day

GDPR compliance is also decided on site.

Simple good practices:

  • One account per team member (avoid shared credentials)
  • Manual or automatic deactivation of team access after the event
  • Lock devices when they are not in use
  • No list exports sent to personal email addresses
  • Delete temporary files after the event

These measures strongly reduce the risk of accidental leaks.

5. Prepare a GDPR rights procedure

An attendee may request:

  • Access to their data
  • Correction of an error
  • Erasure (within legal limits)

You do not need a dedicated legal team. Prepare a short process:

  1. Receive the request on a predefined email address
  2. Verify the requester’s identity
  3. Reply within legal deadlines
  4. Keep an internal record of the request and response

A one-page written process is often enough to be operational.

Quick checklist before your next event

  • [ ] Form fields are limited to what is strictly necessary
  • [ ] A clear GDPR notice is visible at registration
  • [ ] A retention period is defined and documented
  • [ ] Day-of access is secured (accounts, devices, exports)
  • [ ] A GDPR rights response procedure is ready

In practice with Gatesly: apply these principles every day during check-in, with time-limited data retention, controlled data exports and expiring access links. See plans →

Ready to simplify your check-in?

Import your list and manage entries in real time.

Gatesly - logo

Gatesly

The check-in platform for all your professional events.

© 2026 Gatesly. All rights reserved.

Made with ❤️ in France