How to properly comply with the Data Protection Act at your event

Avoid fines and penalties by protecting the data of those attending your event

If you’re an event organizer, designing and creating an event from scratch is probably your favorite part. Once you receive the client’s brief, it’s time to put your creativity to work and think about all the actions needed to achieve the established objectives. But all that glitters is not gold, and you, as an event planner, know that better than anyone.

Designing and organizing an event involves a lot of planning. You have to consider all aspects, including legal issues such as Occupational Risk Prevention (ORP) and the Organic Law on Data Protection (LOPD).

At any event, we collect and manage a lot of data. In fact, whoever has data has a treasure.

Why? Because information is power. The more data we have about our attendees and the event itself, the more tools we have to measure objectives and, ultimately, the success of our event.

However, personal data is protected by law and must be used and processed appropriately. If we don’t do it right, we could find ourselves in serious trouble, resulting in hefty fines.

Sometimes, due to lack of knowledge or insufficient involvement, we can make mistakes that, at first glance, may seem insignificant but, when push comes to shove, can cause real nightmares. Remember that ignorance of the law is no excuse.

Therefore, and to avoid bigger problems, the best course of action is to hire a Data Protection Law professional (just like for Occupational Risk Prevention) and have peace of mind.

Here are some tips to help you understand, in general terms, how to properly comply with the Data Protection Law at your event.

Basic Premises of Data Protection at an Event

According to Royal Decree-Law 5/2018 and Organic Law 3/2018, further supported by the European General Data Protection Regulation (GDPR) 679/2016, the following must be strictly adhered to:

Personalized accreditation to protect the data of event attendees

  • 1. Comply with the duty to inform.
  • 2. Obtain the express consent of attendees and individuals who will be involved in the event in any capacity (staff, security, others).
  • 3. Prepare and sign contracts between the data processor and those who provide the data (attendees, others).
  • 4. Facilitate the exercise of rights.
  • 5. Notify security breaches.
  • 6. Record processing activities and risk analyses.
  • 7. Make the information available on the event website and app.

We don’t want to bore you too much, since, as we mentioned at the beginning of this article, it’s best to hire a Data Protection Law expert for your event. However, it is important to understand what it entails. We’ll briefly detail each of its sections:

  • Duty to inform: We must inform the people who provide us with their data who will be responsible for collecting and processing it, and for what purpose. We must also inform them where it will be stored and make it very clear that we are complying with current legislation.
  • Explicit consent: It is very important to state with absolute clarity that the person is completely free to provide or not provide this data and that they are being informed of this. There cannot be any pre-ticked boxes.
  • Contracts: If we have to transfer this data to a third party for any reason, they must be expressly informed, and a contract must be drawn up with them. Facilitating the exercise of rights: We must also inform individuals who provide their data where and to whom they can go if they wish to modify or delete it.
  • Reporting security breaches: Nowadays, despite the numerous security and antivirus systems on the devices we use, it is very easy to suffer a cyberattack that compromises the data we must protect so carefully. If a security breach occurs, we must immediately inform the Spanish Data Protection Agency within a maximum of 72 hours from the moment the situation is detected.
  • Risk analysis: It is necessary to carry out a risk analysis, as well as define what protection measures we must adopt to guarantee the proper processing of the personal data we have collected.
  • Website: The event website must have a section with the legal notice, privacy policy, cookie policy, and general terms and conditions, indicating that they are up-to-date and comply with all legal requirements. This information must also be available in the app.

 

Content Index

Share this entry

Basic pillars to avoid queues at the accesses of events

Plan the access and exit control of public to events to avoid long queues