GDPR & security

Full control over attendees, data and payments

As an organizer of major events with a large number of paying attendees, you know exactly how important it is to have full control over security, privacy and payments.

With Checkin, you can be assured that everything from registration to settlement is taken care of securely, simply and efficiently.

We take security seriously and are fully GDPR-compliant, and as an approved payment service provider, we ensure that your ticket revenues are processed quickly and securely.

Checkinday 2025 audience

GDPR

Full control over your data

Checkin is GDPR-compatible, and we make it easy for you to comply with privacy regulations:

  • Consent-based registration: Attendees provide explicit consent when registering.

  • No sharing with third parties: We never sell or share attendee information.

  • Secure backup and recovery: Regular backups ensure that data is never lost.

  • Delete data automatically on a pre-set date

Checkin is GDPR-compatible

Security

World-class security

Your attendees’ data and your earnings are valuable.

That’s why Checkin was built in accordance with the highest security standards.

Checkin provides
  • End-to-end encryption: All data is encrypted using SSL/TLS during transfer and storage.

  • Secure, EU-based servers: All storage and backup occur in the AWS EU Ireland Region (eu-west-1) and on-premise in Norway.

  • Regular security audits: We conduct penetration tests and vulnerability analyses to ensure optimal protection.

  • Two-factor authentication (2FA): Additional security for you and your team.

  • Logging of access and changes: All user actions are logged to increase traceability and security.

A chart with numbers moves past our mascotte Algebra, who isn't stressed at all

Testimonials

WHAT OUR
CUSTOMERS
SAY ABOUT US

Read our success stories

Approved payment provider

Checkinpay - secure and efficient transactions

CheckinPay, our payment solution, is approved as a payment service provider by the Financial Supervisory Authority of Norway, which means that we operate in compliance with strict requirements defined for payment handling.

  • Checkin operates in accordance with Norwegian and EU financial directives.

  • PCI DSS-certified: We comply with strict requirements for payment card transactions.

  • Weekly or fortnightly payouts: Have your ticket revenues paid out quickly and securely.

  • Flexible payment methods: Support for Vipps, card payments and invoices.

  • We monitor transactions to reduce the risk of chargebacks and to prevent fraud.

  • Automated accounting: Full overview of transactions and reporting in real time.

CheckinPay, our payment solution, is approved as a payment service provider by the Financial Supervisory Authority of Norway

Common questions about event GDPR and data security

The questions below are among the most common from event organisers evaluating data privacy, security protocols, and GDPR compliance. Each answer is self-contained.

Is Checkin fully GDPR compliant?

Yes. Checkin is built with European data privacy standards at its core. We ensure all attendee data is processed securely within the EU/EEA, and we provide tools for data portability and the right to be forgotten.

Where is my event data stored?

All data is stored on secure servers within the EU/EEA, ensuring full compliance with European privacy regulations and protecting your organization from the complexities of international data transfers.

How does Checkin ensure payment security?

Unlike many other providers who rely solely on third-party integrations, Checkin is an authorized payment institution approved by the Financial Supervisory Authority of Norway. This means we are held to the same high security and capital standards as banks, ensuring your revenue is handled with maximum professional oversight.

Can I sign a Data Processing Agreement (DPA) with Checkin?

Absolutely. We provide a standard Data Processing Agreement that clearly outlines how we handle data on your behalf, ensuring your organization meets its legal obligations under GDPR.