The most common question we get from exhibitors and organizers is not "how accurate is it?" but "are we even allowed to do this?" The short answer is yes, if the data collection is designed in tiers from the start. Here is the longer answer.
Most event teams treat visitor measurement as a binary: either it is personal and legally fraught, or it is anonymous and commercially useless. That framing is wrong, and it quietly kills good projects before they begin.
Between "we know nothing" and "we know everyone's name" sits the tier where most commercially useful questions are already answered, without a single personal record.
The visitor hands back the tag or deactivates the app. Nothing is stored. This option has to be genuinely available and genuinely easy, not merely mentioned in a policy document nobody reads.
Movement data with no link to a person. For an organizer that still delivers hall occupancy, visitor flow, zone comparison and bottleneck detection. For running an event operationally, this is already most of the practical value.
Visitors are analysed by ticket category: trade visitor, buyer, press, exhibitor, investor. The group is measured, never the individual. No personal profiles are created, and in the EU this tier can typically rest on legitimate interest under Art. 6(1)(f) GDPR, provided there is proper transparency and a real ability to object.
This is the decisive point in practice: the tier works on an opt-out basis, not opt-in. Coverage therefore does not collapse to the minority who actively consent, which is exactly where app-based approaches fail.
Only here is behavior linked to an identifiable person: name, company, role. This requires explicit, informed and documented consent under Art. 6(1)(a), and withdrawing it must be as easy as giving it.
Build only for Tier 3 and you have a system that produces nothing without consent. In practice some visitors agree and the rest stay invisible, and the remaining data is systematically skewed, because people who opt in are more engaged to begin with. Every metric derived from them reads better than reality.
The tiered model inverts this: complete coverage at category level, personal depth only where the visitor actively wants it.
Consent is a trade. Offer nothing back and the opt-in rate will be low, and correctly so.
What works at events: routing across an unfamiliar venue, prompts about relevant exhibitors and sessions, suggestions about who is nearby and worth meeting, and afterwards a summary of their own visit. At our first live deployment, visitors approached us unprompted asking whether they could see their own path through the event.
Usually less than expected, and mostly organisational rather than structural. Sensing is mounted during the normal build days, zones are defined on the floor plan in advance, and ticket categories need to be mapped cleanly before doors open. The effort sits in coordination between organizer, stand builder and data protection, not in the installation itself.
Event success can be measured lawfully in Europe. The failure is almost never technical. It comes from treating data collection as a single decision instead of a tiered model with its own lawful basis at each level.
This article is a practical orientation, not legal advice. The correct assessment depends on your specific setup. Talk to your data protection officer.
Yes, when it is designed in tiers with a documented lawful basis for each level. Anonymous movement data identifies nobody. Category-level analysis grouped by ticket type can typically rest on legitimate interest under Art. 6(1)(f) GDPR with transparency and a genuine right to object. Linking behavior to a named individual requires explicit consent under Art. 6(1)(a).
Not for every tier. Anonymous and category-level measurement generally operate on an opt-out basis, which is why coverage stays close to complete. Explicit opt-in is required only where behavior is linked to an identifiable individual, which is also the tier that unlocks named lead data and personalised visitor features.
Data becomes personal as soon as it can be attributed to an identifiable individual, directly or indirectly. Movement data grouped by ticket category, with no identifier tying it back to a person, is not personal data. The moment a record can be joined to a name, email or profile, full GDPR obligations apply.
It depends on who determines the purpose of the processing, and at events this is frequently shared. The organizer usually controls venue-level measurement, while an exhibitor receiving named leads becomes a controller for that data. The arrangement should be settled in writing before the event, together with the processing agreement covering the vendor.
Only as long as necessary for the stated purpose, which must be defined in advance and enforced technically rather than only contractually. Anonymous and aggregated data can generally be retained longer for benchmarking, because it no longer relates to identifiable people.