
Every guest list is personal data, and most corporate events also collect dietary and access needs. Here's a plain-English overview of what UK GDPR means for event organisers. It isn't legal advice: your data protection lead should decide what's right for your events.
Controller and processor
The organisation that decides why and how guest data is used is the controller, usually the company hosting the event. Suppliers that handle the data on its behalf, such as an event agency or registration software provider, are processors. Processors should only use the data on the controller's instructions, under a written data processing agreement.
Collect only what you need
Ask only for information you'll use for this event. If you don't need a guest's phone number, don't ask for it. Every extra field is more data to protect and more for guests to fill in.
Dietary and access needs can be health data
Allergies and many dietary or access needs can reveal information about someone's health, which is special category data under UK GDPR and needs extra protection. Common approaches are asking for explicit consent on the reply form, storing these details separately from the main guest list, and limiting who can see them. Your caterer needs dietary needs and allergies, but not accessibility details.
Limit access
Give each person the access their role needs. Door staff need names and arrival status, not email addresses or medical information. Colleagues following progress may only need totals. Use strong sign-in, such as two-step verification, for anyone who can see personal details.
Keep a record
Being able to show who exported a list or viewed someone's requirements helps you answer questions from guests and demonstrate accountability.
Don't keep data longer than you need
Decide in advance how long you'll keep guest data after the event, and stick to it. Duplicate an event's setup for next year rather than keeping old guest lists.
Choosing suppliers
Ask suppliers who their own sub-processors are, how data is separated between customers, how access is controlled and whether they'll sign a data processing agreement. Our buyer's guide to event registration software has a full list of questions.
How DelegateFlow helps
DelegateFlow acts as a processor on your instructions. Requirements are stored separately, stay hidden until opened, and every viewing is recorded; you can require explicit consent before they're stored. Door staff using the check-in app see names, organisations and arrival status only. Read how DelegateFlow protects guest data.


