GDPR

GDPR-compliant visitor tracking at events: what's actually allowed

The most common question we get from exhibitors and organizers is not "how accurate is it?" but "are we even allowed to do this?" The short answer is yes, if the data collection is designed in tiers from the start. Here is the longer answer.

The mistake that starts everything

Most event teams treat visitor measurement as a binary: either it is personal and legally fraught, or it is anonymous and commercially useless. That framing is wrong, and it quietly kills good projects before they begin.

Between "we know nothing" and "we know everyone's name" sits the tier where most commercially useful questions are already answered, without a single personal record.

Four tiers of collection

Tier 0: no collection

The visitor hands back the tag or deactivates the app. Nothing is stored. This option has to be genuinely available and genuinely easy, not merely mentioned in a policy document nobody reads.

Tier 1: anonymous

Movement data with no link to a person. For an organizer that still delivers hall occupancy, visitor flow, zone comparison and bottleneck detection. For running an event operationally, this is already most of the practical value.

Tier 2: category (the recommended baseline)

Visitors are analysed by ticket category: trade visitor, buyer, press, exhibitor, investor. The group is measured, never the individual. No personal profiles are created, and in the EU this tier can typically rest on legitimate interest under Art. 6(1)(f) GDPR, provided there is proper transparency and a real ability to object.

This is the decisive point in practice: the tier works on an opt-out basis, not opt-in. Coverage therefore does not collapse to the minority who actively consent, which is exactly where app-based approaches fail.

Tier 3: personal

Only here is behavior linked to an identifiable person: name, company, role. This requires explicit, informed and documented consent under Art. 6(1)(a), and withdrawing it must be as easy as giving it.

Why the tier logic is the real lever

Build only for Tier 3 and you have a system that produces nothing without consent. In practice some visitors agree and the rest stay invisible, and the remaining data is systematically skewed, because people who opt in are more engaged to begin with. Every metric derived from them reads better than reality.

The tiered model inverts this: complete coverage at category level, personal depth only where the visitor actively wants it.

What visitors must get in return

Consent is a trade. Offer nothing back and the opt-in rate will be low, and correctly so.

What works at events: routing across an unfamiliar venue, prompts about relevant exhibitors and sessions, suggestions about who is nearby and worth meeting, and afterwards a summary of their own visit. At our first live deployment, visitors approached us unprompted asking whether they could see their own path through the event.

A practical checklist

  1. Document a lawful basis per tier: not one blanket justification for "the tracking".
  2. Be transparent at the door: a clear notice where the tag is issued, not only in the privacy policy.
  3. Make objection real: handing back a tag must work without an argument.
  4. Minimise data: no personal storage at Tiers 1 and 2, by architecture rather than by promise.
  5. Settle the processing agreements: between organizer, exhibitor and vendor, including where data is stored.
  6. Set deletion periods: and enforce them technically, not just contractually.
  7. Separate the roles cleanly: who is controller, who is processor? At events this is rarely obvious.

What the build team needs to prepare

Usually less than expected, and mostly organisational rather than structural. Sensing is mounted during the normal build days, zones are defined on the floor plan in advance, and ticket categories need to be mapped cleanly before doors open. The effort sits in coordination between organizer, stand builder and data protection, not in the installation itself.

The bottom line

Event success can be measured lawfully in Europe. The failure is almost never technical. It comes from treating data collection as a single decision instead of a tiered model with its own lawful basis at each level.

This article is a practical orientation, not legal advice. The correct assessment depends on your specific setup. Talk to your data protection officer.

Common questions

Is visitor tracking at trade shows legal under GDPR?

Yes, when it is designed in tiers with a documented lawful basis for each level. Anonymous movement data identifies nobody. Category-level analysis grouped by ticket type can typically rest on legitimate interest under Art. 6(1)(f) GDPR with transparency and a genuine right to object. Linking behavior to a named individual requires explicit consent under Art. 6(1)(a).

Do we need opt-in consent from every attendee?

Not for every tier. Anonymous and category-level measurement generally operate on an opt-out basis, which is why coverage stays close to complete. Explicit opt-in is required only where behavior is linked to an identifiable individual, which is also the tier that unlocks named lead data and personalised visitor features.

What counts as personal data in event tracking?

Data becomes personal as soon as it can be attributed to an identifiable individual, directly or indirectly. Movement data grouped by ticket category, with no identifier tying it back to a person, is not personal data. The moment a record can be joined to a name, email or profile, full GDPR obligations apply.

Who is the controller: the organizer or the exhibitor?

It depends on who determines the purpose of the processing, and at events this is frequently shared. The organizer usually controls venue-level measurement, while an exhibitor receiving named leads becomes a controller for that data. The arrangement should be settled in writing before the event, together with the processing agreement covering the vendor.

How long can event behavioral data be stored?

Only as long as necessary for the stated purpose, which must be defined in advance and enforced technically rather than only contractually. Anonymous and aggregated data can generally be retained longer for benchmarking, because it no longer relates to identifiable people.

TRAKKER runs at category level by default, with personal identity strictly on opt-in. Book a demo →