Personal data is part of almost every event. Names, email addresses, accessibility requirements, dietary information and payment records all need to be handled carefully.
This guide explains the main roles TryBooking and event organisers play under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It is a practical overview, not legal advice.
Who is responsible for personal data?
UK data-protection law distinguishes between a controller and a processor.
A controller decides why and how personal data is used. An event organiser will usually be a controller for the information they choose to collect from ticket buyers, such as contact details, meal choices or accessibility requirements.
A processor handles personal data on a controller’s instructions. When TryBooking provides ticketing and registration services for an organiser, it may act as a processor for parts of that service. TryBooking may also act as a controller where it decides how personal data is used for its own legitimate purposes, such as operating accounts, preventing fraud or meeting legal obligations.
The exact role depends on the activity. TryBooking’s current privacy policy and GDPR information explain these arrangements in more detail.
What event organisers should do
Collect only what the event needs
Before adding a question to a booking form, ask why you need the answer and how long you need to keep it. Avoid collecting sensitive or unnecessary information simply because it might be useful later.
Be clear with ticket buyers
Tell people what you are collecting, why you need it, who it may be shared with and how long it will be retained. Your event terms and privacy information should be easy to find and written in plain language.
Choose an appropriate lawful basis
Consent is one lawful basis, but it is not the only one. Some information may be needed to fulfil a booking, meet a legal obligation or support a legitimate interest. The right basis depends on what you are doing with the information.
Keep access controlled
Only give account and report access to people who need it. Remove access when committee members, volunteers or staff leave their role. Downloaded reports should be stored securely and deleted when they are no longer required.
Treat marketing separately
Buying a ticket does not automatically mean someone has agreed to every future marketing message. If you plan to add ticket buyers to a mailing list, make the choice clear and keep a record of their preference. Every marketing email should provide a straightforward way to unsubscribe.
Be ready for information requests
People have rights over their personal data, including rights to access, correct and in some circumstances erase it. Make sure your organisation knows who will respond if a ticket buyer makes a request.
How TryBooking supports data protection
TryBooking provides account controls and booking tools that help organisers manage event information. Our legal documents describe how personal data is handled, the terms that apply to organisers and ticket buyers, and how people can contact us about privacy.
For the current documents, read:
The Information Commissioner’s Office also publishes detailed UK GDPR guidance for organisations.
A sensible starting checklist
- List the personal information your events collect.
- Record why each item is needed and the lawful basis for using it.
- Remove questions you no longer need.
- Review who can access your account and downloaded reports.
- Check that your privacy information and event terms are current.
- Separate booking communications from optional marketing.
- Decide how your team would handle a data request or suspected breach.
Data protection is easier when it is built into an event from the beginning. Collect less, explain more, restrict access and review your records regularly.
This article provides general information and does not constitute legal advice. Speak to a suitably qualified adviser if you need guidance for your organisation.