Registration is the first thing your audience experiences and the last thing most organisers design. It's also where personal data enters the system, which makes it the point where privacy obligations start. This guide covers both — the conversion and the compliance — in practical terms. It's general information from a production team, not legal advice.
Registration that converts
Every extra field loses registrants. Ask for what you'll actually use: name, email, organisation, and one or two questions that shape the event (role, topic of interest). Put the rest in a post-event survey. Confirm instantly by email with a calendar file, the join link, and what to expect. Send reminders the day before and an hour before; the hour-before email is the single biggest driver of attendance.
Data you'll want afterwards
Registered vs attended (the no-show rate tells you about your reminders); session-level attendance and watch time; questions asked and polls answered (with names, if consented); on-demand views in the following weeks. Make sure the platform can export all of it, per attendee, before you sign — see the feature checklist.
The GDPR basics for an event
Lawful basis. Running the event someone registered for is usually covered by contract or legitimate interests; using their details for marketing afterwards generally needs consent (a clearly labelled, unticked box) or a documented legitimate-interests assessment for existing customers. Don't bury marketing consent in the registration terms.
Privacy notice. Link to it at registration. It should say what you collect, why, who processes it (the platform, the production company, the CRM), how long you keep it and how to opt out.
Processors. The platform and any production partner handling attendee data are processors; you need a data-processing agreement with each. Ask where they store data and whether it leaves the UK/EEA — many platforms are US-hosted and rely on transfer mechanisms you should at least know the name of.
Recordings. Recording attendees (their video, their questions with names, their chat) is processing personal data. Tell people the session is recorded before they join, and decide whether Q&A on the on-demand version shows names.
Retention. Decide when registration data is deleted from the platform — after the follow-up campaign, say — and actually delete it. Export what you need to your own systems first.
Internal events
Employee events are still personal data, and the attendance report your leadership wants ("who didn't watch the all-hands?") has implications. Be transparent with staff about what's tracked and why.
A short pre-launch checklist
- Registration form: minimum fields, clear marketing consent, privacy notice linked.
- Processing agreements with platform and production partners in place.
- Data location and transfers understood.
- Recording notice on the join page and at the top of the show.
- Export and deletion plan written down with dates.
The organisations that handle this well aren't the ones with the longest terms and conditions — they're the ones who collect less and can explain every field.
