New Resource: "The Internal Comms Bible"

Guide

Compliance Questions to Ask Before Running a Regulated Industry Event

03 August 2026

Corporate event with a producer at mixing desk. Example of compliant, regulated event.

 SHARING  

Regulated events have a unique set of requirements. Asking the right questions is key to making your event compliant.

Quick answer: Before running an event in a regulated industry, you need clear answers on data protection, financial promotions and marketing rules, anti-bribery and hospitality limits, gifts and inducements, record-keeping and audit trails, accessibility, sector-specific codes (such as financial services or pharmaceutical rules), supplier and sponsor due diligence, and cross-border requirements if the event is international. The safest approach is to agree these answers in writing with your compliance, legal and data protection teams early, and to design the event around them rather than retrofitting compliance at the end. 

Events in regulated sectors carry risks that ordinary events do not. Financial services, pharmaceutical, legal, healthcare, government and other regulated industries operate under rules that govern how you can market, who you can host, what you can offer them, and how you must handle their data and your records. Getting it wrong can mean regulatory action, reputational damage and personal liability for individuals, not just a disappointing event. 

This guide sets out the questions to ask before you commit. It is a framework for the conversations you should have with your own compliance, legal and data protection advisers, not a substitute for their advice. Rules differ by sector and jurisdiction and they change, so treat what follows as the structure for due diligence rather than a definitive ruling. 

The Guide Every Internal Comms Professional Needs

The Internal Comms Bible 2026

Why regulated events need a different approach

An ordinary event is judged on experience and outcome. A regulated event is judged on those things and on whether every element stayed within the rules that govern the sector. The difference is that compliance cannot be an afterthought bolted on at the end, because by then the risky decisions, who to invite, what to offer, how to capture data, have already been made. 

The organisations that handle this well treat compliance as a design input from the first planning session. They know the constraints before they build, so the event is compliant by design rather than by correction. That is faster, cheaper and far less stressful than discovering a problem in week eight. 

1. Data protection: how will you handle delegate data? 

Every event collects personal data, and regulated industries tend to attract closer scrutiny of how that data is handled. The core questions: 

  • What is your lawful basis for collecting and processing delegate data under UK GDPR and the Data Protection Act 2018, and is it documented? 
  • Have you minimised what you collect to what you genuinely need, rather than gathering data by default? 
  • How is consent captured and recorded, particularly for marketing follow-up and for any special category data such as dietary or accessibility requirements that may reveal health information? 
  • Who are your processors, including your event technology platforms, and do you have appropriate data processing agreements in place? 
  • Where is the data stored and processed, and does any of it leave the UK in a way that requires additional safeguards? 
  • How and when will data be deleted after the event, and is that retention period defensible? 

If your event is international, this gets more complex. A UK event with Singapore delegates, for example, engages both UK GDPR and Singapore’s PDPA, and the two regimes have to be reconciled rather than treated as one. Map the data flows before you choose your technology. 

This is an area where your event platforms matter. At Live Group, AudienceDNA and Envoku are built to handle delegate and audience data responsibly, with data protection considered as part of the design rather than an afterthought, which is exactly the standard a regulated event demands of any system touching its data. 

2. Financial promotions and marketing: what are you allowed to say?

In financial services and other regulated sectors, how you promote an event and what is said during it can both fall under regulatory rules. Ask: 

  • Does any event content constitute a financial promotion or regulated communication, and if so, has it been approved through the correct internal process? 
  • Are speakers and presenters briefed on what they can and cannot say, particularly around products, performance and advice? 
  • Is promotional material for the event itself compliant with the relevant marketing and advertising rules for the sector? 
  • Are appropriate disclaimers and risk warnings included where required? 

The key point is that regulated communication rules can apply to what happens on stage, not just to formal marketing. Content quality assurance for a regulated event therefore includes a compliance review, not only an editorial one. 

3. Anti-bribery, hospitality and inducements: where are the limits?

Hospitality is central to many events and tightly constrained in regulated sectors. The relevant questions: 

  • What are the hospitality limits under your own policy, the Bribery Act 2010 and any sector-specific code, and does every element of the event stay within them? 
  • Is the hospitality proportionate and defensible, or could it be seen as intended to influence a decision? 
  • Are public officials or government representatives attending, and do stricter rules apply to hosting them? 
  • How will hospitality be recorded so that it can be evidenced if questioned? 

The test regulators tend to apply is whether hospitality is reasonable and transparent, or whether it could reasonably be seen as an inducement. Design the guest experience with that test in mind from the start. 

4. Gifts and inducements: what can you offer attendees? 

Closely related, and worth separating out, is anything of value given to attendees. In sectors such as pharmaceutical and healthcare, the rules here are especially strict. 

  • Are any gifts, prizes or giveaways within the limits set by your policy and the relevant sector code? 
  • In pharmaceutical or medical contexts, does the event comply with the applicable code, such as the ABPI Code of Practice in the UK, on hospitality, meetings and materials? 
  • Are speaker fees and expenses set at defensible, fair-market levels and properly documented? 

When in doubt, the safe assumption in a regulated sector is that anything of value must be justifiable, proportionate and recorded. 

5. Record-keeping and audit trails: can you evidence compliance?

Regulated industries run on evidence. If you cannot show that you complied, you may be treated as though you did not. Ask: 

  • What records must you keep, covering attendees, hospitality provided, content delivered, approvals given and data handled? 
  • How long must those records be retained, and where? 
  • Is there a clear audit trail for the key compliance decisions, showing who approved what and when? 
  • Could you reconstruct the event’s compliance position months later if a regulator asked? 

Build the record-keeping into the process as you go. Reconstructing it after the event is painful, unreliable and exactly what regulators are unimpressed by. 

6. Sector-specific codes: which rules apply to you?

Beyond the cross-cutting rules, most regulated industries have their own codes that shape what an event can and cannot do. A non-exhaustive prompt list: 

  • Financial services: FCA rules on communications, promotions and inducements. 
  • Pharmaceutical and healthcare: the ABPI Code and equivalent codes governing meetings, hospitality and materials. 
  • Legal and professional services: professional conduct and marketing rules from the relevant regulator. 
  • Government and public sector: procurement, transparency, propriety and hospitality rules, which are often stricter than the private sector equivalent. 

Identify every code that applies to your sector and your attendees at the outset, and get a named person to confirm the event has been checked against each. 

7. Supplier, sponsor and partner due diligence: who are you working with?

In a regulated event, your compliance exposure extends to the parties you work with and platform alongside. Ask: 

  • Have sponsors and partners been checked for conflicts of interest or reputational risk? 
  • Are suppliers, particularly those handling data, contractually bound to appropriate standards? 
  • Does sponsorship of the event create any perception of endorsement or inducement that needs managing? 
  • Are sponsor messages and materials subject to the same compliance review as your own? 

The relationships are part of the event’s compliance picture, and a regulator or the public will not neatly separate your conduct from that of the partners you chose to stand beside. 

8. Accessibility and inclusion: are your obligations met?

Accessibility is both a legal obligation and a quality standard. Ask whether the event meets the requirements of the Equality Act 2010 and good-practice accessibility standards: venue access, content and communication accessibility, provision for a range of needs, and a clear route for delegates to request adjustments. Handle any health-related information disclosed in that process under the heightened data protection standard for special category data. 

9. Cross-border requirements: does the event cross jurisdictions? 

If your event is international, or your audience is, every question above may need answering in more than one regime at once. Consider: 

  • Which jurisdictions’ rules apply, based on where the event is held and where attendees are based? 
  • How do the data protection regimes interact, and which sets the higher standard you should design to? 
  • Do local marketing, hospitality or anti-bribery rules differ from your home market? 
  • Are there visa, tax or import considerations for speakers, staff or materials crossing borders? 

The safe default for a cross-border event is to design to the highest applicable standard across all relevant jurisdictions, rather than the lowest.

A pre-event compliance checklist

Area Key question Who owns the answer 
Data protection Lawful basis, minimisation, retention, processors Data protection officer or legal 
Financial promotions Does content need regulatory approval Compliance 
Anti-bribery and hospitality Are limits respected and recorded Compliance 
Gifts and inducements Is anything of value within code limits Compliance 
Record-keeping Can compliance be evidenced later Compliance and events 
Sector codes Which codes apply and are they met Compliance 
Supplier and sponsor Have partners been checked Procurement and legal 
Accessibility Are obligations and standards met Events and legal 
Cross-border Which jurisdictions and which standard Legal 

Use this as the agenda for an early conversation with your compliance, legal and data protection colleagues. The point is to assign each answer to a named owner before planning goes far, not to leave any of them assumed. 

The bottom line

Compliance for a regulated event is not a hurdle to clear at the end; it is a set of design constraints to build around from the beginning. Ask the questions early, assign a named owner to each answer, keep the records as you go, and design to the highest applicable standard where jurisdictions or codes overlap. Do that and compliance becomes something the event quietly satisfies rather than something that threatens it. 

This guide is a framework for the conversations to have with your own compliance, legal and data protection advisers. It is not legal advice, and the specific rules for your sector and jurisdiction should always be confirmed with a qualified professional. 

If you are planning an event in a regulated sector and want a partner who understands that compliance and data protection are design requirements, not afterthoughts, we are happy to talk it through. 

Planning your next compliant event? Share your brief with Live Group.

Get in touch with the Live Group team to discuss how we can support your next event, whatever the timeline. 

Get the latest guide on virtual town hall meetings.

Financial services events typically engage FCA rules on communications and financial promotions, anti-bribery and inducement rules under the Bribery Act 2010, data protection under UK GDPR and the Data Protection Act 2018, and internal firm policies that are often stricter than the regulatory baseline. Content delivered at the event, not just the marketing, can fall within these rules, so it should be reviewed for compliance as well as quality.

Data protection rules govern how you collect, store, use and delete delegate personal data. You need a documented lawful basis, data minimisation, proper consent for marketing and special category data, appropriate agreements with any processors including your event platforms, and a defensible retention and deletion plan. International events may engage more than one data protection regime at once.

Yes. Pharmaceutical and healthcare events in the UK are governed by codes such as the ABPI Code of Practice, which set strict limits on hospitality, meetings, materials and anything of value provided to healthcare professionals. These codes are typically stricter than general anti-bribery rules and require careful design and record-keeping.

Responsibility is shared but should be clearly assigned. Compliance, legal and data protection teams own the rules; the events team owns building the event within them and keeping the records. The most important step is agreeing at the outset who owns the answer to each compliance question, so nothing is assumed.

From the very first planning session. The decisions that create compliance risk, who to invite, what to offer, how to capture data, how to promote the event, are made early. Treating compliance as a design input from the start is far safer and cheaper than trying to correct problems late in the process.


Ready to take the stress out of event planning?

Live Group helps organisations design and deliver personalised event experiences that engage audiences and achieve results. Contact us to discuss your next event.

 SHARING  

TALK TO OUR EVENT EXPERTS TODAY

You may also be
interested in.

check out more articles…

GET IN
TOUCH

Contact us today to discuss your upcoming event.

Whether you need support with full event management or you’re looking for a team of experts to handle only one element of your project, we’d love to hear from you.