Compliance & GDPR

Last updated: September 2026

Our commitment to data protection laws, European Union General Data Protection Regulation (GDPR), and attendee privacy.

1. Regulatory Commitment

Eventzone operates in adherence to international data protection principles, including the European Union General Data Protection Regulation (GDPR - Regulation EU 2016/679) and regional privacy frameworks. We ensure all personal data collected during event registration and attendance is processed lawfully, transparently, and securely.

2. Controller & Processor Roles

Under the GDPR data protection framework:

  • Event Organizers as Data Controllers: The organizer determines what attendee fields are collected (e.g. registration questions, dietary preferences, passport numbers for foreign delegates) and is responsible for establishing a lawful basis for that collection.
  • Eventzone as Data Processor: Eventzone processes attendee registration data solely on behalf of, and according to the instructions of, the event organizer.

3. Lawful Basis for Processing

Data processed through Eventzone relies on the following lawful bases:

  • Contractual Performance: Processing required to issue event passes, process ticket transactions, and grant venue admission.
  • Consent: Where attendees explicitly opt-in to receive organizer marketing updates, summit bulletins, or sponsor contact requests.
  • Legitimate Interests: Preventing fraud, ensuring physical event gate safety, and maintaining system availability.

4. Attendee & Delegate Rights

Under GDPR, attendees whose data is processed through Eventzone enjoy clear enforceable rights:

  • Right of Access: Request a copy of all personal records stored in connection with your event registrations.
  • Right to Rectification: Request correction of inaccurate contact details, spelling errors, or company affiliations.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your registration profile once an event has concluded, subject to statutory legal record-keeping obligations.
  • Right to Restrict Processing: Request temporary restriction of data processing during verification disputes.
  • Right to Data Portability: Obtain your registration history in a structured, machine-readable format (e.g., CSV or JSON export).

5. International Data Transfers

When data is transferred across international borders, Eventzone relies on Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring equivalent levels of data protection regardless of where cloud compute and storage clusters reside.

6. Data Processing Agreement (DPA)

We offer a standard Data Processing Agreement (DPA) incorporating European Standard Contractual Clauses for institutional and enterprise event organizers requiring formal compliance documentation.

7. Data Protection Office Contact

To submit a data subject access request (DSAR), request a signed DPA, or reach our compliance office:

Eventzone Data Protection Officer
Email: compliance@eventzone.pro
General: contact@eventzone.pro

Subscribe to our newsletter

to stay up to date on all the latest news and offers from us