GDPR award entries: who is actually the controller?
It starts as a question about roles. Whoever launches the award and determines the purposes and essential means of its core processing is normally the controller under the GDPR. A supplier is a processor only to the extent that it processes personal data on the organiser's documented instructions. A provider that pursues its own purposes or determines essential means may be an independent controller; some designs can create joint controllership. The label in a contract does not decide the role on its own.
In German-speaking Europe that contract has a well-worn name of its own, the Auftragsverarbeitungsvertrag or AVV, and vendors are expected to hand it over unprompted. Supervision is national in Austria and devolved to the individual states in Germany; Swiss organisers sit outside the EU under their own federal law. The five traps below appear regardless, and whether you receive 40 entries or 400.
Trap 1: there is no processor agreement
The most common finding by some distance: the entry form runs on a tool somebody put on a company card, and no agreement under Art. 28 GDPR was ever signed — often never even requested.
The risk: Art. 28 requires a written contract with a defined minimum content for every processing arrangement. Without it the processing is exposed no matter how carefully the vendor operates technically. You also have no documented right to co-operation when an erasure request lands or a breach must be reported.
The fix: before launch, list every tool that touches entry data, determine and document its role, and execute an Art. 28 agreement for each processing arrangement. For independent controllers, document the recipient, legal basis and information duties. If an actual processor offers no agreement, treat that as a selection criterion rather than paperwork.
Trap 2: the legal basis has never been decided
“We collect consent” is the most widespread misconception. Not every data flow needs consent, and using it in the wrong place creates obligations you never meant to assume.
The risk: if the entry itself rests on consent, entrants hold a right to withdraw at any moment, including in the middle of judging. If your newsletter rests on the entry contract instead, you are mailing without a workable basis at all.
The fix: separate the data flows and assign each one a basis. Handling the entry rests on contract, meaning your terms of entry; promoting next year's award by email rests on separate consent. Write this down before the call for entries goes live, because after that the forms are already circulating. Our piece on launching a call for entries covers how to draft the terms alongside the deadlines.
Trap 3: consent exists but is not documented
Consent you cannot evidence is, in a dispute, no consent. The exposed points are almost always photography and video at the ceremony, plus publication of the winners' project material.
The risk: with no record, you cannot show who agreed to what, or when. If a ceremony photograph is challenged six months later, it is one recollection against another. A blanket line in the ticket shop rarely covers publishing an entrant's dossier.
The fix: store the timestamp, the exact wording version and the action taken for each consent — an actively ticked box, never a pre-ticked one. Keep the purposes apart: entering, image rights and marketing are three decisions, not one. At the ceremony, pair visible signage at the entrance with documented agreement from the winners themselves.
Trap 4: the data sits in the United States
Rarely a decision, usually an inheritance. The form tool stores in a US region, the uploads land in a US cloud folder, the ceremony video goes onto a US platform.
The risk: transfers to third countries are not forbidden, but they must be justified and documented. You need a defensible transfer mechanism and must be able to name it. An organiser who cannot say which region a service stores in has plainly not run that assessment.
The fix: settle storage and processing locations in writing before you sign. EU hosting or your own infrastructure reduces transfer risk for the core platform, but does not automatically remove third-country exposure from ancillary or AI services. Each third-country recipient needs a valid adequacy decision or appropriate safeguards and any required documented transfer assessment. What running the platform on your own machines involves is set out on our self-hosting page.
Trap 5: the jury pack goes out by email
Operationally the easiest shortcut and legally the worst: every entry as a ZIP archive or spreadsheet, sent to every juror, once per round.
The risk: complete records leave the centrally controlled system. Copies then live in inboxes, on endpoints and inside backups, making access control, rectification and timely erasure materially harder and dependent on additional procedures. There is a substantive problem on top: jurors see entries they were never assigned, which is the opposite of data minimisation and an open flank on conflicts of interest.
The fix: judge where the data already lives. Jurors should see only their allocation, access should be logged, and it should be withdrawn once the season closes. If files genuinely must leave the system, send only the relevant subset. Our article on the jury process covers allocation, rounds and conflict handling in more detail.
The five traps at a glance
| Trap | Risk | Fix | Deadline |
|---|---|---|---|
| Role/agreement unclear | Processing without an Art. 28 contract or incorrect recipient information | Assess each tool's role; execute an agreement where Art. 28 applies | Before the first test run |
| Undecided legal basis | Withdrawal mid-process, or marketing with no basis | Record contract or consent per data flow | Before the call for entries goes live |
| Undocumented consent | No evidence when a photo, video or publication is challenged | Store timestamp, wording version and action; split purposes | With the form draft |
| US storage location | Third-country transfer with no documented assessment | Confirm location in writing; EU hosting or your own server | At vendor selection |
| Jury pack by email | Uncontrolled copies; rights and erasure materially harder | Judge in-system, allocate instead of broadcasting | Before the jury kick-off |
What software settles — and what it does not
Some of the five are structurally solvable, some are not. Tooling helps where the question is access, storage location and logging. Laureo operates the core platform in the EU, supplies a standard Art. 28 agreement and shows jurors only the entries assigned to them; the Sovereign tier can run on infrastructure you own. Optional mail, payment and AI services must be documented before activation. This reduces the risks behind traps 1, 4 and 5 but does not replace the organiser's specific assessment.
Traps 2 and 3 stay with you. Which legal basis covers which data flow is a controller's decision, and no product can make it for you. Documented consent is only as good as the wording in your terms of entry and your form.
The honest caveat runs wider. A platform covers the core of the process, not your whole ecosystem: newsletter tool, ticketing, photographer and video platform remain separate processing operations whose roles must be assessed. Depending on that role, they need an Art. 28 agreement or other recipient and legal-basis documentation. Self-hosting moves the technical and organisational measures back into your own building — more control, but also more work, and for a small team without in-house IT, EU hosting with the vendor is usually the more realistic call.
One last point if you are rebuilding anyway: data minimisation starts in the form. Any field you do not ask for is a field you never have to secure, export or delete — more on that in our piece on the entry form. The access and allocation tools named above are listed in the feature overview.
This article is orientation for award organisers and is not legal advice. For a binding assessment of your own process, consult your data protection officer or a qualified lawyer. Laureo is a product of State of Innovation GmbH, Mahlerstraße 7/25, 1010 Vienna, Austria.
Frequently asked questions
Do you need a data processing agreement for an award entry form?
If the external provider processes entry data on your documented instructions, Art. 28 GDPR requires a processing agreement. A provider that pursues its own purposes or determines essential means may instead be an independent controller. Determine and document the role and contract for every tool before launch.
What is the legal basis for processing award entries under GDPR?
Handling the entry itself normally rests on contract, meaning your published terms of entry. Marketing to entrants afterwards normally needs separate consent. Decide and document the basis for each data flow before the call for entries opens.
Can award entries be stored on US servers?
Not banned outright. A third-country transfer needs a valid adequacy decision or appropriate safeguards and any required documented transfer assessment. Confirm storage and processing locations in writing before signing, including for ancillary and AI services.
Can jurors receive award entries by email?
Technically possible, practically risky. Copies in inboxes, endpoints and backups make access control and timely erasure materially harder. Judging inside a system, where each juror sees only their allocation and access ends with the season, reduces that risk.
Related reading
Planning an award right now?
In 20 minutes we walk through your process: entry, jury round, invoice.
Book a demo