Nearly every event software website now carries a GDPR badge. The label is not protected: no authority awards it, no auditor takes it away when it stops being true. Any vendor can print it, and most do.
The responsibility it implies, however, never moves. Under the General Data Protection Regulation (GDPR), you as the organiser are the controller of your attendees’ data. Your software vendor is only your processor. If the setup fails an audit, the fine lands on your desk, not theirs. Which is why the person who really decides your software shortlist is not in your event team at all: it is your data protection officer, and at some point before the contract signature they will ask what exactly you have checked.
This checklist gives you the answer. GDPR compliance is not a badge you trust; it is an audit you can run yourself: five criteria, the exact documents they hide in, and about 30 minutes of work per vendor. We also cover the layer most checklists skip, matchmaking data, and the 2026 legal situation around US vendors that your legal team will want priced into any multi-year contract.
What Makes Event Software GDPR-Compliant?
GDPR-compliant event software is software that puts you, as the controller, in a position to meet your obligations: lawful processing, documented consent, deletion on schedule, traceable data flows. You can recognise it by five verifiable criteria:
- Data processing agreement (DPA): a contract under Article 28 GDPR that binds the vendor as your processor, available as a standard document rather than on special request.
- Server location: data held in Germany or the EU removes the entire third-country transfer question from your audit.
- Consent management: double opt-in, documented consent records, and working opt-outs in every mail.
- Deletion concept: configurable retention periods and automated deletion of attendee data after the event.
- Subprocessor transparency: a published list of every company that touches your attendee data, with notice when it changes.
A badge proves none of these. Documents do.
The stakes are not theoretical. European supervisory authorities have now issued cumulative GDPR fines beyond the six billion euro mark, and enforcement has shifted noticeably towards mid-sized organisations. For a typical organiser, that changes the question from “could we be fined?” to “would our setup survive a routine complaint?”
What enforcement looks like in 2026
GDPR fines have crossed six billion euros
The Five Criteria in Detail: Question, Source, Red Flag
Badges live on landing pages; the truth lives in legal documents. For each criterion, here is what to ask, where the answer is verifiable, and what should make you cautious.
1. Data processing agreement under Article 28
The DPA is the contract that makes the vendor legally your processor: it defines what they may do with attendee data, which subprocessors they use, and what happens after termination. Ask whether the DPA is part of the standard contract set. Verify it in the vendor’s terms or legal centre, where mature vendors publish the current version. The red flag: a DPA that exists only “on request”, or a vendor who cannot say which contract version applies to you. Your data protection officer will read this document first, so vendors who make it hard to find are creating your first audit finding for you.
2. Server location and third-country transfers
Where attendee data physically sits decides how much legal machinery your setup needs. Hosting in Germany or the EU keeps processing inside GDPR territory. Hosting in the US is not forbidden, but it requires a valid transfer mechanism, and we cover below why 2026 is a bad year to take that mechanism for granted. Verify the location in the vendor’s privacy policy: serious vendors name the provider and the region, for example a data centre in Frankfurt, not just “secure cloud hosting”. The red flag: no named country at all. Vagueness here is almost always load-bearing.
3. Consent management
Every registration form is a consent machine: newsletter opt-ins, photo permissions, data sharing with partners. The software must support double opt-in, record who consented to what and when, and honour withdrawals without manual work. Verify it by building a test registration page and trying to configure a pre-ticked checkbox. If the tool lets you, it will let your busiest colleague too, three days before the event, and a pre-ticked box is invalid consent under GDPR. Good software makes the compliant path the default path.
4. Deletion concept and storage limitation
Attendee data may not live forever; storage limitation is a core GDPR principle, and it is enforced. Deutsche Wohnen SE was fined 14.5 million euros in Germany essentially for keeping personal data without a deletion concept, and a Croatian real estate case in June 2026 followed the same pattern. For you this means one question: can the software delete or anonymise attendee data automatically after a configurable period? Verify it in the product documentation. The red flag: deletion only via support ticket. If cleaning up after your event depends on someone remembering, your retention policy exists on paper only.
5. Subprocessor transparency
Your vendor rarely works alone: hosting providers, mail services, video infrastructure all touch attendee data as subprocessors. Article 28 makes the vendor responsible for them, but your audit needs to know who they are. Verify that a current subprocessor list is published, with locations, and that the contract promises notice before new subprocessors are added. The red flag: no list anywhere. You cannot assess a data flow you are not allowed to see.
The Matchmaking Layer: What Standard Checklists Miss
The five criteria above appear, in some form, in most software checklists. What almost none of them covers is the data layer that makes B2B event software valuable in the first place. Matchmaking platforms process more than registration records: they hold interest profiles, stated business goals, meeting requests, accepted and declined invitations, and full meeting histories. That is behavioural data about identifiable professionals, and it deserves three extra checks:
- Profile visibility: who can see attendee profiles, and is visibility an attendee choice rather than a system default? A participant list pushed to all exhibitors without consent is one of the most common GDPR mistakes at B2B events.
- Lead sharing with exhibitors: on what legal basis do contact details move from your platform to a sponsor’s CRM (customer relationship management system)? “It was in the terms and conditions” is not consent; a scanned badge with a documented opt-in is.
- Matching accountability: can you explain why the system suggested a meeting? Article 5(2) GDPR makes you accountable for processing you cannot explain. A transparent matching logic with an audit trail answers that question; a black box does not.
Solution: Converve approaches this layer from the governance side. The platform is developed by a German company based in Barmstedt near Hamburg, certified to ISO 27001:2022, hosts in Germany, and ships the DPA as a standard contract document. Matching runs on a meeting matrix with traceable rules, so every suggested meeting has an explanation your data protection officer can read. Details on the security setup are on our IT security page, and our article on why ISO 27001:2022 should matter to event organisers explains what the certification does and does not prove.
US Vendors in 2026: Allowed, but Price In the Risk
None of this means US software is off limits. It means the legal ground under it is moving again, and your data protection officer knows it.
The current mechanism, the EU-US Data Privacy Framework (DPF), is the third attempt at a transatlantic transfer agreement. Safe Harbor fell in court in 2015, Privacy Shield in 2020. The DPF survived its first challenge when the EU General Court dismissed the Latombe case in September 2025, but the appeal is now pending before the European Court of Justice as case C-703/25 P. In July 2026, a US Supreme Court ruling on the independence of federal oversight bodies prompted the privacy organisation noyb to demand that the European Commission withdraw the DPF adequacy decision altogether. Two of three frameworks have already been struck down; the third is back in court.
For a running event, none of this changes anything overnight. For a procurement decision, it changes the maths: a multi-year contract with a US-hosted platform carries a scenario in which the transfer basis disappears mid-term and your team migrates attendee data under time pressure. Standard contractual clauses (SCCs) exist as a fallback, but they bring transfer impact assessments and extra paperwork with them. EU or German hosting is the one choice that removes this entire risk class from your file. Not because US software is worse, but because your audit gets one chapter shorter.
One fairness note, because a large vendor makes this argument prominently: server location alone does not make software compliant, and that is true. Processes, contracts and your own data handling matter just as much. The reverse conclusion does not hold either, though. Among vendors that are otherwise equal, the one whose data never leaves Germany is the one that spares you the third-country chapter, the monitoring of case C-703/25 P, and the migration scenario. Shorter audits are a feature.
From badge to documented decision
The 30-minute vendor check
- Step 1 Identify the company Open the imprint or legal notice. Note the legal entity, registry number and headquarters. No imprint, no shortlist.
- Step 2 Locate the data Read the privacy policy for named hosting providers and countries. Vague cloud language counts as a finding, not an answer.
- Step 3 Request the DPA Ask for the standard data processing agreement before any demo. The response time tells you how often they are asked.
- Step 4 Check lists and deletion Find the published subprocessor list and confirm automated deletion or anonymisation is configurable in the product.
- Step 5 Document the result Write the five answers down with sources and hand them to your data protection officer. That document is your accountability proof.
Vendor Self-Disclosures at a Glance (August 2026)
The table below summarises what six vendors publicly state about themselves in their own legal and security pages. These are self-disclosures, not audit results: treat each entry as a starting point for step 3 of the check above, not as a verdict.
| Vendor | Headquarters | Server location (self-disclosed) | Certifications (self-disclosed) | Third-country setup |
|---|---|---|---|---|
| Converve | Barmstedt near Hamburg, Germany | Germany | ISO 27001:2022 | Processing in Germany, DPA standard |
| Sweap (MATE Development GmbH) | Berlin, Germany | IBM Cloud Frankfurt, Hetzner Germany | Certified data centres | EU processing |
| Evenito | Zurich, Switzerland | Switzerland | ISO 27001, ISO 27701 | Swiss adequacy decision |
| Swapcard | Paris, France | EEA (AWS Ireland) | ISO 27001:2022, SOC 2 Type II | Group companies in 9 countries incl. USA |
| Grip | London, UK | AWS, region not specified | Cyber Essentials; ISO via AWS centres | UK adequacy decision |
| EventMobi | Toronto, Canada (GmbH in Berlin) | AWS, USA | SOC 2, external German DPO | SCCs plus DPF |
How you weight these columns depends on your format. If you run hosted buyer programmes, where qualification data and travel details raise the stakes further, our comparison of hosted buyer software platforms applies the same privacy lens to that category in depth.
FAQ: GDPR and Event Software
What makes event software GDPR-compliant?
Software is GDPR-compliant in practice when it lets you meet your controller obligations: a standard data processing agreement under Article 28, hosting in Germany or the EU (or a valid transfer mechanism), documented consent management, automated deletion of attendee data, and a published subprocessor list. The vendor badge alone proves none of this; the documents do.
Is US event software allowed for European organisers?
Yes. Transfers to certified US vendors currently run under the EU-US Data Privacy Framework, with standard contractual clauses as a fallback. The framework is under appeal before the European Court of Justice (case C-703/25 P) and under political pressure since July 2026, so organisers signing multi-year contracts should plan for the scenario in which it falls, as its two predecessors did.
Do I need a data processing agreement with my event software vendor?
Yes, without exception. The vendor processes attendee data on your behalf, which makes a DPA under Article 28 GDPR mandatory, for a 100-person seminar as much as for a trade show. This also applies to small side tools such as survey or badge printing services.
How long may I keep attendee data after an event?
Only as long as the purpose requires. Invoice-related data follows statutory retention periods; marketing data needs ongoing consent; everything else should be deleted or anonymised on a defined schedule. The 14.5 million euro Deutsche Wohnen fine was, at its core, about the absence of exactly this deletion concept.
What extra GDPR questions does matchmaking software raise?
Three: who controls the visibility of attendee profiles, on what legal basis contact data flows to exhibitors and sponsors, and whether matching decisions are explainable with an audit trail. Interest profiles and meeting histories are behavioural data about identifiable people, so they deserve stricter checks than a plain registration list.
Conclusion: Check Documents, Not Badges
GDPR compliance is not a property you buy; it is a result you verify. Five criteria, five documents, 30 minutes per vendor: after that you know more about a platform’s data practices than its landing page will ever tell you. Run the check before the demo call, not after the contract, and give the written result to your data protection officer. The vendors with nothing to hide will make it easy for you, and how easy a vendor makes this check is itself a signal.
For the broader duties around your event, from photo consent to privacy notices, our GDPR guide for event managers covers the organiser side of the same coin. And if you want to see how a German-hosted, ISO 27001:2022 certified matchmaking platform answers all five criteria in one conversation: get in touch with Converve, we will bring the DPA to the first call.