Search Events
Legal & Policies

GDPR Compliant


About General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR), effective since May 2018, replaces the Data Protection Act 1998 and sets updated standards for managing personal data. These regulations affect anyone selling tickets for events and collecting customer information. Under GDPR, protecting attendee data is not limited to marketing permissions or third-party sharing, it encompasses all aspects of how you collect, store, and process personal data.

As an organiser using TicketKart, you act as the Data Controller, retaining full responsibility for your customers’ personal data. Personal data includes any information that identifies an individual, such as their name, address, email, or phone number. TicketKart operates as a Data Processor, handling ticket sales and bookings on your behalf.

While many GDPR requirements align with the previous Data Protection Act, several enhancements demand attention:

  • Understand what personal data you hold and document how it is stored, used, and shared.
  • Ensure compliance with GDPR by safeguarding data and detailing your processes in a privacy policy.
  • Be prepared to demonstrate compliance, as non-compliance and data breaches can result in significant fines.



TicketKart’s Role in GDPR Compliance

When attendees purchase tickets via TicketKart, our Privacy Policy governs how their data is collected, stored, and used. This ensures transparency and compliance with GDPR.

If you, as an organiser, export attendee data from TicketKart, the responsibility for handling this data transfers to you. In such cases, your organisation’s privacy policy will apply. It is essential to clearly state this policy in your Organiser Profile to maintain GDPR compliance and build trust with your attendees.



TicketKart's Commitment to GDPR

TicketKart is dedicated to helping organisers meet GDPR requirements while providing a secure and reliable platform for managing events.

We have implemented measures to ensure GDPR compliance in our operations. For detailed information on how we protect personal data, refer to our:


You Own All Your Ticket Buyer and Attendee Data

When you use TicketKart to sell tickets and collect data from attendees, you are the "data controller" of that information. TicketKart acts as a "data processor," meaning we only handle attendee data as needed to provide our service to you. While we do retain your attendees' data to send them marketing emails about other events, we do not sell this data to third parties. Your data privacy and security are our top priorities.



Data Security Measures

TicketKart ensures that your data is protected by hosting our servers and databases in secure facilities. While some of our essential service providers may operate outside the EU, we have contractual agreements in place with all third-party vendors to ensure GDPR compliance. You can view the list of third-party services we use, along with their data roles, here.



Easily Upload Your Privacy Policy for Attendees

Under GDPR, organisers must inform attendees about why their personal data is being collected and how it will be used. Typically, this information is detailed in a privacy policy that attendees can review when sharing their data.

If you already have a privacy policy, you can easily upload it to your Organiser Profile on TicketKart. This ensures your attendees can access the information when registering for tickets, keeping your process transparent and compliant with GDPR.



Don’t Have a Privacy Policy? Create One for Free

If you don’t have a privacy policy yet, you can quickly generate one online or draft your own. For example, you can use TermsFeed Privacy Policy Generator to create one in just a few minutes.



Streamlined Marketing Consent Collection

Data protection laws may require you to collect consent before sending marketing emails. TicketKart simplifies this by offering a checkbox at the checkout page, allowing attendees to opt out of receiving marketing emails from the organiser.

By default, anyone who purchases a ticket is automatically opted in as a follower of your organisation and will receive marketing emails unless they choose to uncheck the opt-out box during checkout. This ensures compliance while giving attendees control over their communication preferences.


For any questions regarding GDPR compliance, please reach out to us at legal@ticketkart.com