GDPR for event organisers: handling guest data

A plain-English guide to UK GDPR for corporate event organisers: controllers and processors, dietary data, consent, access, retention and choosing suppliers.

9 October 2026 · 8 min read

The delegate list with requirements kept separately

Every guest list is personal data, and most corporate events also collect dietary and access needs. Here's a plain-English overview of what UK GDPR means for event organisers. It isn't legal advice: your data protection lead should decide what's right for your events.

Controller and processor

The organisation that decides why and how guest data is used is the controller, usually the company hosting the event. Suppliers that handle the data on its behalf, such as an event agency or registration software provider, are processors. Processors should only use the data on the controller's instructions, under a written data processing agreement.

Collect only what you need

Ask only for information you'll use for this event. If you don't need a guest's phone number, don't ask for it. Every extra field is more data to protect and more for guests to fill in.

Dietary and access needs can be health data

Allergies and many dietary or access needs can reveal information about someone's health, which is special category data under UK GDPR and needs extra protection. Common approaches are asking for explicit consent on the reply form, storing these details separately from the main guest list, and limiting who can see them. Your caterer needs dietary needs and allergies, but not accessibility details.

Limit access

Give each person the access their role needs. Door staff need names and arrival status, not email addresses or medical information. Colleagues following progress may only need totals. Use strong sign-in, such as two-step verification, for anyone who can see personal details.

Keep a record

Being able to show who exported a list or viewed someone's requirements helps you answer questions from guests and demonstrate accountability.

Don't keep data longer than you need

Decide in advance how long you'll keep guest data after the event, and stick to it. Duplicate an event's setup for next year rather than keeping old guest lists.

Choosing suppliers

Ask suppliers who their own sub-processors are, how data is separated between customers, how access is controlled and whether they'll sign a data processing agreement. Our buyer's guide to event registration software has a full list of questions.

How DelegateFlow helps

DelegateFlow acts as a processor on your instructions. Requirements are stored separately, stay hidden until opened, and every viewing is recorded; you can require explicit consent before they're stored. Door staff using the check-in app see names, organisations and arrival status only. Read how DelegateFlow protects guest data.

See it with your next event.

We’ll walk you through an event from invitation to arrival, and show you how it would work for yours.

We’ll only use these details to reply to you. See our privacy notice.