“Access control” at an event sounds like a door problem: badges, scanners, and a queue that moves quickly. It is, but only half of it. The other half is invisible and higher-risk: the moment you scan a badge, you are processing personal data, and in Europe that puts you squarely under the GDPR. A smooth check-in that mishandles that data is not a success; it is a liability waiting for a complaint.
This guide separates the two levels of event access control, sets out the GDPR requirements that apply to registration and check-in, and gives you a compliance checklist plus the exact data-security questions to ask any vendor.
This article is general information, not legal advice. For your specific event, confirm requirements with your Data Protection Officer or legal counsel.
The two levels of event access control
Access control at an event means two different things, and most guides only cover the first:
- Physical access control: deciding who may enter, and admitting them quickly and securely. This is the badge, the QR or NFC scan, the check-in desk, the zones a pass unlocks.
- Data access control: protecting the personal data that registration and check-in generate, and controlling who inside your organisation and your suppliers can see it.
You need both. A venue that lets the wrong person in has a physical problem; a platform that lets the wrong person see attendee data has a legal one. Treating access control as only the door is how well-run events end up with badly-run data.
Level 1: physical access control
The operational layer is well understood: QR- or NFC-based badges, fast on-site check-in that validates entry automatically, and access rights that open only the zones a given pass allows. Done well, it removes queues and stops unauthorised entry. This is the part the existing guidance already covers — and the part that, on its own, is not enough.
Level 2: data access control
The moment a visitor registers, you hold their name, contact details, company, and often more. Every scan adds a timestamp and a location. That is personal data under the GDPR, and it must be protected in transit and at rest, visible only to those who genuinely need it. This is the level that turns a check-in from “fast” into “compliant”.
GDPR requirements for registration and check-in
If your event involves anyone in the EU, these principles apply to the data you collect at registration and the door.
- Lawful basis and consent. You need a valid legal basis to process each piece of data. Where you rely on consent (for example, sharing a lead with an exhibitor or sending marketing), it must be freely given, specific, and recorded — not a pre-ticked box buried in a form.
- Data minimisation. Collect only what the event genuinely needs. If a field does not serve a clear purpose, do not ask for it.
- Purpose limitation. Use the data only for the purpose you stated at collection. Registration data repurposed for something the attendee never agreed to is a breach.
- Storage limitation and retention. Keep personal data only as long as necessary, then delete it on a defined retention schedule rather than holding it indefinitely.
- Security of processing. Protect the data with appropriate measures — encryption in transit and at rest, access restricted to those who need it, and monitoring.
- Data processing agreements. Your event platform is a data processor acting on your instructions. You need a Data Processing Agreement (DPA) with it, and clarity on any sub-processors.
- International transfers and hosting. Know where the data is hosted. Data kept in EU data centres avoids the extra safeguards required for transfers outside the EEA.
- Data subject rights. Attendees can request access to, correction of, or deletion of their data. You must be able to honour that — which means knowing exactly where their data sits.
A GDPR compliance checklist for event check-in
Before your next event, confirm you can tick each of these:
- Every data field collected at registration has a clear, stated purpose (data minimisation).
- Consent, where used, is explicit, specific, and logged — not assumed.
- You have a privacy notice that tells attendees what you collect, why, and for how long.
- A retention schedule defines when attendee data is deleted after the event.
- Personal data is encrypted in transit and at rest.
- Access to attendee data is restricted by role, not open to the whole team.
- You have a signed DPA with your platform and know its sub-processors.
- You know which country hosts the data, ideally within the EU.
- You can fulfil access, correction, and deletion requests.
- There is an audit trail of who accessed or changed what.
Data-security questions to ask your vendor
The check-in demo will look slick. The compliance answers are what protect you. Ask each vendor:
- “Is data encrypted in transit and at rest, and with what standard?” (AES-256 and SSL/TLS are the expected baseline.)
- “Where are your data centres located?” EU hosting simplifies GDPR compliance considerably.
- “Will you sign a DPA, and who are your sub-processors?”
- “How do you control internal access to attendee data?” Look for role-based permissions and multi-factor authentication.
- “Do you keep an audit trail of data access and changes?”
- “What is your retention and backup policy?” Confirm data is not kept longer than needed.
- “How do you support data subject access and deletion requests?”
- “Are you monitoring for security threats, and how do you handle a breach?”
Common mistakes to avoid
- Treating access control as only the door. Fast check-in with sloppy data handling is a compliance risk, not a win.
- Collecting data “just in case”. Every extra field is extra liability and a minimisation failure.
- Assuming consent. Pre-ticked boxes and vague notices do not meet the GDPR standard.
- Ignoring where data lives. Non-EU hosting can trigger transfer obligations you did not plan for.
- No retention plan. Holding attendee data indefinitely is a breach waiting to happen.
Where LetzFair fits
For the data-protection layer, LetzFair is built to the baseline this guide describes: AES-256 encryption for data at rest, SSL/TLS for data in transit, hosting in certified EU data centres, full GDPR compliance, role-based access control with multi-factor authentication and granular permissions, a complete audit trail of activity, 24/7 monitoring, and automatic daily backups with a 30-day retention policy. On the physical layer, QR and digital badges handle fast, validated on-site check-in.
The result is a check-in that is quick at the door and defensible in the data — the reassurance an organiser needs when the person asking the hard questions is a DPO, not a delegate. To review how LetzFair handles event data and access, see the data security and legal overview or request a demo.
Frequently asked questions
What is event access control? It has two levels: physical access control — admitting the right people quickly and securely via badges, QR/NFC scans, and check-in — and data access control, protecting the personal data that registration and check-in generate and restricting who can see it. A compliant event needs both.
Is event check-in subject to the GDPR? Yes. As soon as you collect a name, contact details, or scan a badge for anyone in the EU, you are processing personal data under the GDPR, with obligations around lawful basis, minimisation, security, retention, and data subject rights.
What does a GDPR-compliant check-in require? Collect only necessary data, obtain and record valid consent where needed, provide a clear privacy notice, encrypt the data, restrict access by role, set a retention schedule, sign a DPA with your platform, and be able to honour access and deletion requests.
Where should event attendee data be hosted? Ideally in EU data centres. Hosting data within the EU avoids the additional safeguards the GDPR requires for transfers outside the EEA and simplifies compliance.
What security should event access control software have? Encryption in transit and at rest (SSL/TLS and AES-256), role-based access with multi-factor authentication, an audit trail, active monitoring, defined backups and retention, and a signed Data Processing Agreement.
What is the difference between access control and accreditation at events? Access control governs entry and the zones a pass unlocks; accreditation is the process of verifying and assigning those rights to each person beforehand. Both depend on handling personal data securely and in line with the GDPR.









