Skip to main content

🔐 The 6 Principles of GDPR

Understanding the six key principles of GDPR and how they apply when handling customer data.

When handling personal information, such as your customers' contact details, you need to ensure that you remain compliant with the General Data Protection Regulation (GDPR).

Failure to comply with GDPR can result in significant fines. As customer data is jointly owned by Skiddle, we may also terminate your data-sharing agreement if you are found to be in breach of GDPR.

The six principles are outlined below, along with how they may apply to you as a promoter.


1. ⚖️ Processed Lawfully, Fairly and Transparently

Customers provide their contact information when purchasing tickets or registering for an event.

Once you have access to this information, you must ensure it is used lawfully, fairly and transparently.

For example, you should not share customer data with third parties without an appropriate legal basis or the customer's consent where required.


2. 🎯 Collected for Specified, Explicit and Legitimate Purposes

Customer data should only be used for the specific purpose for which it was collected.

For example, if you collect customer information to promote and run your events, you should not sell the data or use it for an unrelated business purpose.


3. 📋 Adequate, Relevant and Limited to What Is Necessary

You should only collect information that is necessary and relevant to the purpose for which you are collecting it.

Skiddle collects basic contact information that is relevant to processing a customer's order.


4. ✅ Accurate and, Where Necessary, Kept Up to Date

Customer information should be accurate and kept up to date where necessary.

Customers enter their own information when purchasing tickets, helping to ensure it is accurate at the time of purchase.

If you download customer data into your own systems, such as a mailing list, you should have a process that allows customers to update their information where appropriate.


5. 🗑️ Retained Only for as Long as Necessary

Personal data should not be kept for longer than is necessary for the purpose for which it was collected.

If you stop running events or no longer require the data, you should consider whether it needs to be deleted.

If a customer makes a valid request for their data to be deleted, you should handle this in accordance with applicable data protection requirements.


6. 🔒 Processed Securely

You must take appropriate steps to keep customer data secure, including when it is being transferred or stored.

For example:

  • 🔐 Do not allow unauthorised third parties to access customer data.

  • 📧 Avoid sending customer data by email unless it is appropriately encrypted and protected.

  • 🌐 Do not upload customer data to third-party websites without ensuring the connection is secure.

  • 💻 Keep laptops, phones and other devices containing customer data protected by a password or other appropriate security measures.

  • ☁️ Take care when choosing where customer data is stored, including cloud services. Check where your mailing-list or other service providers are based and whether appropriate data protection safeguards are in place.


⚠️ Need Legal Advice?

This article is intended as a general guide and Skiddle is not a legal adviser.

If you are unsure about your legal obligations or how GDPR applies to your business, please seek advice from a solicitor or qualified data protection professional.

Did this answer your question?