Ailance Alt TM Logo
Ailance Alt TM Logo

Sharing of Participant Data with Partners in Connection with Webinars and Joint Events

Sharing of participant data at a joint event.

The sharing of participant data with event partners is common practice. However, there are several data protection considerations to keep in mind. This article analyzes the relevant legal grounds for such sharing and examines the distinction between joint controllership (Art. 26 GDPR) and controller-to-controller-Transmission and develops concrete design models for two typical real-world scenarios.

Share participant data with partners?

Webinars and joint events with partner companies are part of B2B-Marketing is a common occurrence. This regularly leads to situations in which participant data—such as name, email address, and company affiliation—is to be shared with the participating partners. The external speaker needs the participant list to follow up with participants afterward, while the organizer uses the list to identify competitors in advance and exclude them. Both scenarios require a solid legal foundation for data protection.

Because, as a general rule: Every Transmission The transfer of personal data to a third party is a separate Processing pursuant to Art. 4, No. 2 GDPR and requires its own legal basis under Article 6(1) GDPR.

The law provides for a „group privilege“ that permits data flows between companies within a group per se, GDPR not provided for. In Recital 48 GDPR Intra-group transfers are cited merely as a possible example of a legitimate interest. However, a case-by-case assessment is always required.

Intra-group data sharing following the customer seminar

Here is a real-life example: An event organizer is hosting a customer seminar. During the seminar, a partner GmbH from the corporate group serves as a speaker and subsequently requests the list of participants so it can contact them directly.

However, since Partner-GmbH pursues its own marketing objectives, a data processing agreement (DPA) under Art. 28 is not applicable GDPR ... There is no obligation to follow instructions. To rely on the legitimate interest under Art. 6(1)(f) GDPR In its judgment of October 4, 2024 (Case C-621/22), the European Court of Justice clarified the requirements. What is required is a Processing to protect legitimate interests only if it is absolutely necessary to achieve the interest in question and does not override the interests or fundamental rights of the data subjects.

Whether follow-up marketing contact can be based on legitimate interest depends largely on the circumstances of the individual case. This legal basis is generally ruled out, since participants do not have to expect, when registering for an event, that their data will be used for marketing purposes by Third be disclosed. The situation may be different if the participating group companies present a unified image to the outside world under a common brand: In this case, the reasonable expectations of the data subjects may influence the balancing of interests in favor of the controller. However, it remains a prerequisite that this circumstance be transparently communicated at the time of data collection (Art. 13(1)(d) GDPR) and a documented Legitimate Interest Assessment (LIA) is available.

For the organizer’s own communication with its webinar participants, however, current case law provides greater leeway: In its judgment of November 13, 2025 (Case C-654/23 – Inteligo Media), the European Court of Justice broadly interpreted the term „sale” as defined in Article 13(2) of the ePrivacy Directive. Accordingly, even registration for a free service can be considered a „sale,” meaning that the organizer may contact participants without a separate Consent can contact them via email with similar offers of their own (Section 7(3) of the UWG).

Reading tip: ECJ Allows Newsletters Without Consent Under These Conditions

With regard to data sharing with the partner, however, the following applies: The most legally sound solution remains obtaining explicit, voluntary Consent in the registration, in which the partner is named (Art. 4, No. 11; Art. 7, para. 1 GDPR) and which may be revoked at any time (Art. 7, para. 3 GDPR).

In the case of group-wide data sharing, it must also be ensured that a uniform opt-out register is maintained, which must be observed throughout the group. A declared Contradiction Contacting Partner-GmbH must not be used to circumvent the organizer.

Data Sharing During Joint Webinars and Customer Events

The next scenario: An event organizer hosts webinars and in-person events in collaboration with external partner companies. The partner wants to know in advance who will be attending. The organizing event organizer, on the other hand, needs the registration list to exclude competitors.

In principle, a legitimate interest under Art. 6(1)(f) may serve as a basis for excluding competitors GDPR may be considered. However, it is essential to observe the principle of Data minimization (Art. 5 para. 1 lit. c GDPR): As a rule, the Transmission company affiliation or email domain. Disclosing a person’s name is only proportionate if the purpose cannot be achieved without it. This purpose of processing must be described transparently in the privacy policy. The right to object under Art. 21 GDPR must be actively communicated.

As a rule, the partner does not have a legitimate interest in using the data for follow-up marketing purposes, since participants cannot reasonably be expected, when registering for an event, to anticipate that their data will be used for marketing purposes by Third be passed on. Therefore, a Consent.

Role Definition: JCA or Delegation Among Independent Parties?

Correctly determining roles under data protection law is of considerable practical importance, as failure to do so is subject to fines. The decisive factor is whether there is genuine joint decision-making regarding the purposes and means of the Processing exists. In that case, a Joint Controller Agreement (JCA) pursuant to Art. 26 GDPR required.

If, on the other hand, there is no joint decision regarding the purposes and means, but rather each party processes the data independently for its own purposes, there is no joint responsibility.

The model that is often easier to implement in practice is that of separate accountability with transparent C2C-Transmission: The organizer collects the data, indicates in its privacy policy that the data may be shared with specifically named partners, and transfers the data based on an appropriate legal basis. Each party then processes the data independently. A prerequisite is that, following the Transmission there is no longer any joint decision-making authority. 

Recommendations for Action in Practice

For companies that regularly host partner events, we recommend the following measures:  

  • Clarify the purpose in advance:Clarify in writing the purpose for which the partner intends to use the data. Marketing purposes require Consent. Organizational purposes may, where applicable, be based on legitimate interests.   
  • Customize the Privacy Policy:Include a separate section on partner events that specifies the disclosure of data, recipient categories, and the legal basis.   
  • Document role assignments:For each partner event, note whether it is JCA or C2C-Transmission is in effect. Incorrect use of the AVV carries the risk of a fine.   
  • Group-wide opt-out system:Maintain a centralized register of objections and ensure compliance across the entire group.   
  • Section 7(3) of the Unfair Competition Act (UWG), applicable only to self-promotion: The existing customer privilege under Section 7(3) of the German Unfair Competition Act (UWG) allows the organizer to communicate directly with participants—without requiring their consent—regarding its own similar offers; however, it applies exclusively to this type of self-promotion. Sharing this information with Third Their use for advertising purposes is not permitted. 
  • Legitimate Interest Assessment (LIA):When relying on a legitimate interest, conduct a documented LIA (interest, Necessity, balancing of interests). 

Frequently Asked Questions

Can participant data be shared with partners after a webinar?

Participant data may not be automatically shared with partners after a webinar. Each instance of sharing personal data with another company constitutes a separate Processing and requires a solid legal basis. Especially in the case of follow-up contact for advertising purposes by partners, explicit, voluntary consent is generally required Consent required.

Is a legitimate interest sufficient grounds for sharing webinar participant data?

A legitimate interest may play a role in certain organizational situations, such as when an event organizer wishes to exclude competitors from an event. However, this is generally not sufficient for promotional use by partners, because participants do not normally expect, when registering, that their data will be shared with Third be passed on.

When is a Joint Controller Agreement required for joint webinars?

A Joint Controller Agreement pursuant to Article 26 GDPR is required when several companies jointly determine the purposes and means of the Processing decide. This may be the case for jointly planned webinars or events, where both parties have a say in registration, data use, communication with participants, or follow-up contact. If each party decides independently on its Processing, a controller-to-controller—Transmission are available.

What is the difference between joint responsibility and controller-to-controller transfer?

In cases of joint responsibility, several parties involved jointly decide on the purpose and means of data processing. In such cases, an agreement is required under Art. 26 GDPR. In the case of a controller-to-controller—Transmission One data controller transfers data to another independent data controller. Each party then processes the data for its own purposes and on its own legal basis.

What must be included in the privacy policy for partner webinars?

The privacy policy should clearly explain what participant data is processed, for what purposes the data is used, whether and to which partners the data is disclosed, on what legal basis this occurs, and what rights participants have. If partners use the data for their own Advertising If they are to be used, they should be identified by name, and the Consent must be clear, voluntary, and revocable.

Who helps companies design webinars and partner events in compliance with the GDPR?

2B Advice helps companies ensure that their webinars, events, and partner events comply with data protection laws. This includes reviewing the legal basis and distinguishing between joint controllership and controller-to-controller—Transmission, drafting transparent privacy notices, designing consent forms, and the Documentation the distribution of roles.

Do you have any questions about your specific event planning practices?

The classification of partner events under data protection law depends heavily on the specific details: It is rarely possible to provide a general answer as to whether joint or separate responsibility applies, what the legal basis is, and how the privacy policy must be adapted. 

At 2B Advice, we help you ensure your webinars and events are legally compliant—from analyzing your objectives and defining roles to drafting the specific language for your privacy policy and registration processes. 

Please feel free to contact us; we look forward to hearing from you. 

Phone: +1 (954) 852-1633  
Mail: info@2b-advice.com 

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

Sharing of Participant Data with Partners in Connection with Webinars and Joint Events