6 min read
Event check-in and GDPR: concrete obligations
Which data can you collect at check-in? How long should you keep it? What notices should you display? A clear, actionable guide to stay GDPR-compliant.
Why GDPR directly affects your welcome desk
Event check-in looks simple: verify a list, mark arrivals, handle latecomers. Yet at every step you process personal data: name, first name, email, company, sometimes job title or phone number.
As soon as you collect, store or update that data, GDPR applies.
Good news: you do not need a heavy legal setup. In most cases, a few well-applied rules are enough to stay compliant.
1. Only collect useful data
The minimization principle is central: only ask for what is necessary for the purpose.
Data generally legitimate for check-in
- First and last name
- Email address
- Registration status (confirmed, waiting, present, absent)
- Company (for B2B events)
Data to avoid without a strong justification
- Date of birth
- Full postal address
- Phone number (if you do not use it)
- Sensitive data (health, opinions, etc.)
In practice: if you cannot clearly explain why a field is useful on the day or for immediate follow-up, do not collect it.
2. Inform attendees clearly
Before or at registration, you must provide understandable information about data processing.
A simple GDPR notice should include:
- Who is the data controller (your company/association)
- Why you collect the data (registration and check-in management)
- Legal basis (legitimate interest or contract performance, depending on context)
- Retention period
- Individual rights (access, rectification, erasure, objection)
- Contact point (email)
The simplest approach: show this notice under the registration form and repeat it in your privacy policy.
3. Define a realistic retention period
Keeping lists forever is an unnecessary risk.
For a typical event, a pragmatic policy is to:
- Keep operational data for the event duration + immediate follow-up
- Archive only what is needed for invoicing or legal obligations
- Delete or anonymize the rest after a defined delay
What matters is having a written rule that is actually applied — not a perfect universal duration.
4. Secure access on the day
GDPR compliance is also decided on site.
Simple good practices:
- One account per team member (avoid shared credentials)
- Manual or automatic deactivation of team access after the event
- Lock devices when they are not in use
- No list exports sent to personal email addresses
- Delete temporary files after the event
These measures strongly reduce the risk of accidental leaks.
5. Prepare a GDPR rights procedure
An attendee may request:
- Access to their data
- Correction of an error
- Erasure (within legal limits)
You do not need a dedicated legal team. Prepare a short process:
- Receive the request on a predefined email address
- Verify the requester’s identity
- Reply within legal deadlines
- Keep an internal record of the request and response
A one-page written process is often enough to be operational.
Quick checklist before your next event
- [ ] Form fields are limited to what is strictly necessary
- [ ] A clear GDPR notice is visible at registration
- [ ] A retention period is defined and documented
- [ ] Day-of access is secured (accounts, devices, exports)
- [ ] A GDPR rights response procedure is ready
In practice with Gatesly: apply these principles every day during check-in, with time-limited data retention, controlled data exports and expiring access links. See plans →
Ready to simplify your check-in?
Import your list and manage entries in real time.