Importing attendee data into Premagic: what consent you need

Anenth

Anenth

Last updated on Jul 2, 2026

When you import a list into Premagic, you're sharing attendee data with us so we can help you send event notifications, produce personalised posters, and run your marketing. You are the data controller for your event. Premagic is a third-party processor acting on your instructions, and the providers we use are sub-processors.

Most of this is ordinary personal data. One part, facial recognition, is treated differently and needs a stronger form of consent. This article explains both.

The general case: sharing data for communications and marketing

For a standard import (name, email, headshot for posters, and similar fields), attendees need to have agreed that their data can be shared with third-party providers like Premagic for these purposes. As the controller, you collect that agreement, usually by covering it in your registration terms or privacy notice.

So before you import, make sure your privacy notice or terms tell attendees their data will be shared with third-party processors to deliver event communications and marketing materials. Importing a list is your confirmation that you've done this.

A headshot on its own counts as ordinary personal data here. Using it to print a poster or personalise an email doesn't require biometric consent. That threshold is only crossed when a face is run through recognition to identify someone, which is covered next.

When facial recognition applies: the photo consent flag

Photo matching uses facial recognition to identify attendees in event photos. This turns a headshot into biometric data, which privacy laws such as GDPR and India's DPDP Act treat as a special category needing explicit consent.

Premagic only processes a headshot this way when your import includes the photo consent flag for that attendee. Without the flag, the headshot is used only for the general purposes above and is never enrolled for facial recognition.

Set the flag only for attendees who have given explicit biometric consent, agreeing that their selfie and facial data can be collected and processed, including by third-party AI providers, for photo identification and delivery. This is the wording attendees accept:

I consent to the collection and use of my selfie and facial biometric data for the purpose of identifying and delivering my event photos. My data may be processed by third-party AI service providers for this purpose. I have read and accept the Terms of Service and Privacy Policy.

What to do if you don't have consent yet

Sometimes you import attendees who never saw a consent step, such as a list from another system. Don't assume consent.

For the general case, confirm your privacy notice covered third-party sharing before you import. For facial recognition, don't set the photo consent flag unless you hold explicit biometric consent. You can have Premagic send a consent request email to those attendees; once they consent, photo matching is enabled for them.

Quick checklist

  1. Confirm your privacy notice or terms cover sharing attendee data with Premagic and third-party providers for communications and marketing.

  2. Import general fields (name, email, headshot) for those purposes freely once the above is covered.

  3. Set the photo consent flag only for attendees who have given explicit biometric consent.

  4. For attendees with no consent on record, send the consent request email through Premagic before enabling photo matching.

  5. If you're unsure, check with your legal or privacy contact before importing.

Questions? Reach our support team through the chat widget.