What does GDPR require of US-based event organizers when collecting data from European Union attendees?
-
A
A lawful basis for data processing, explicit consent where required, and the right for attendees to access or delete their data
-
B
Only a privacy policy link on the registration page
-
C
Automatic deletion of all EU attendee data within 24 hours of the event
-
D
Storing EU attendee data only on US-based servers