# GDPR for event organisers: handling visitor data properly

  [Home](https://mijnevent.nl/en) / [Blog](https://mijnevent.nl/en/blog) / GDPR for event organisers: handling visitor data properly   gdpr privacy legislation 

# GDPR for event organisers: handling visitor data properly

 You collect names, e-mail addresses and payment details. That comes with obligations — here are the ones that matter, in plain language.

 [Jasper Koers](https://mijnevent.nl/en/author/jasper-koers) · 26 August 2026 · 8 min read 

  ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/gdpr-visitor-data-events.webp)  Photo: [Helena Lopes](https://unsplash.com/@helenalopesph?utm_source=MijnEvent&utm_medium=referral) / [Unsplash](https://unsplash.com/?utm_source=MijnEvent&utm_medium=referral)     In short

- The moment you sell a ticket you process personal data, which makes you a controller under the GDPR.
- Five things carry most of the weight: a lawful basis and a purpose, limited retention, a processing agreement with your ticketing platform, respect for data-subject rights, and appropriate security.
- For ticket sales the lawful basis is usually performance of a contract; marketing e-mails need separate consent on top of that.
- A personal data breach must in principle be reported to your national supervisory authority within 72 hours, and fines can reach 4 per cent of annual worldwide turnover.
- A European proposal (the Digital Omnibus package) would stretch that deadline to 96 hours and limit the duty to high-risk breaches, but it has not been adopted — plan for 72 hours.

        Not legal advice

This article explains the rules as we read them, on the date of publication. It is general information, not legal advice — your situation may differ.

  **Short answer:** as soon as you sell tickets you process personal data — names, e-mail addresses, sometimes phone numbers and payment details — and you become a controller under the [General Data Protection Regulation](https://eur-lex.europa.eu/eli/reg/2016/679/oj). In practice your obligations come down to five things: you need a lawful basis (for ticket sales that is normally performance of a contract, with separate consent on top for marketing mail), you keep the data no longer than necessary, you sign a processing agreement with your ticketing platform, you secure the data appropriately, and you honour visitors' rights to access, rectification and erasure. Your national supervisory authority enforces this and can impose fines of up to 4 per cent of annual worldwide turnover — but an organiser who has those five points in order meets the large majority of the requirements. Below we walk through them one by one, from the perspective of someone running events rather than a legal department.

# Every ticket sale is a data processing operation

The GDPR does not care whether you run a stadium tour or a village quiz night. The moment a name and an e-mail address land in your system so you can deliver a ticket, you are processing personal data, and you are the **controller**: the party that decides why and how it happens. Your ticketing platform is normally the **processor**, acting on your instructions.

One thing worth knowing before you assume you are out of scope: the GDPR follows the people, not the venue. If you sell tickets to visitors in the EU, the regulation applies to you even if your organisation is based elsewhere. And if you sell into the United Kingdom, the near-identical UK GDPR applies alongside it, enforced by the [Information Commissioner's Office](https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/).

# 1. Have a lawful basis and a purpose

You may only process personal data on one of the six lawful bases in Article 6. For ticket sales that is almost always **performance of a contract**: you cannot deliver a ticket or admit someone to the venue without knowing who they are.

Marketing is a different purpose and needs its own footing. If you want to mail last year's visitors about this year's line-up, you generally need **separate consent** — freely given, specific and as easy to withdraw as it was to give. The practical rule is to keep those two streams apart: a ticket buyer is not automatically a newsletter subscriber, and a checkbox that is pre-ticked is not consent.

Alongside the basis sits the purpose. Collect the data you need for the event and stop there. If you ask for a date of birth because there is an age limit at the door, that is a purpose; if you ask for it because it might be handy someday, it is not.

# 2. Do not keep data longer than you need it

Personal data is not supposed to sit around indefinitely. Set a sensible retention period per data type and stick to it — invoices are bound by tax law and typically have to be kept for years, whereas marketing data should be cleaned up much sooner. In practice this is the point most organisers quietly skip, because nothing forces the issue: nobody complains about a mailing list from 2019 until it leaks.

The workable approach is to make deletion automatic rather than a task somebody has to remember.

# 3. Sign a processing agreement

If you use a ticketing platform, that platform processes personal data on your behalf. Article 28 GDPR then requires a **processing agreement** (a DPA) setting out what the processor may do with the data, how it secures it, which sub-processors it uses and what happens when the contract ends.

Ask for it — it is a legal requirement, not a formality, and a platform that cannot produce one on request is telling you something. Ours is a public page: [the data processing agreement](/en/data-processing-agreement), alongside a [data protection impact assessment](/en/dpia) for the parts of the platform where that is warranted.

# 4. Respect visitors' rights

Visitors have the right to access the data you hold on them, to have it corrected, and to have it erased — the "right to be forgotten". They can also ask for it in a portable, machine-readable form. You have to be able to actually carry that out, normally within a month.

Two things make this manageable. The first is knowing where the data lives, which is a lot easier when it lives in one system rather than in a spreadsheet, a mailing tool and somebody's inbox. The second is a platform that can execute the request for you instead of leaving you to reconstruct it by hand.

# 5. Secure the data, and know what to do about a breach

Article 32 asks for security "appropriate to the risk": encryption where it matters, access limited to people who need it, and an audit trail so you can tell afterwards who looked at what.

If it does go wrong and data leaks, you must in principle report it to your national supervisory authority **within 72 hours** of becoming aware of it, and inform the affected visitors when the risk to them is high. The [EDPB keeps a list of the national authorities](https://www.edpb.europa.eu/about-edpb/about-edpb/members_en) so you can find yours before you need it — the middle of an incident is a bad time to start looking.

## Note: that 72-hour rule may change

There is a proposal in Brussels aimed squarely at this rule. In the **Digital Omnibus package** presented by the European Commission on 19 November 2025, Article 33 GDPR is rewritten so the duty to report only applies to a breach "that is likely to result in a high risk to the rights and freedoms of natural persons", within "not later than 96 hours after having become aware of it" — see the [proposed regulation on EUR-Lex](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0837). Reports would also go through a single European entry point instead of straight to the national authority. The EDPB and the EDPS backed that simplification in their [joint opinion of 11 February 2026](https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en).

Important: this is **not law yet**. Unlike the AI part of the same package, which has been adopted, this proposal is still listed as tabled in the [European Parliament's legislative train](https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package) as of mid-2026. Build your process around 72 hours and the existing duty to report — and expect the regime to shift at some point.

# How MijnEvent helps with this

Privacy is built into the platform rather than bolted on:

- **Visitors handle their own requests.** From their account they can download everything we hold on them as a JSON file and have their account erased. Erasure anonymises the personal data irreversibly; orders stay on file for your accounts and the associated tickets are invalidated. That covers the access, portability and erasure rights without you doing anything.
- **You can handle a request on their behalf.** In your dashboard, under Privacy &amp; GDPR, you look a visitor up by name or e-mail address and choose export or erasure. Every action — including revealing a masked e-mail address — is written to the activity log, so you can show what happened and when. There is a walkthrough in [handling a GDPR request](/en/blog/handling-gdpr-requests).
- **E-mail addresses stay masked** in the visitor overview until someone deliberately reveals one, so day-to-day work does not put full addresses on screen.
- **Retention runs by itself.** A nightly job anonymises visitor data once the person's most recent event finished more than the retention window ago — 24 months by default. Orders and invalidated tickets stay for the legal accounting obligation; only the personal data is stripped. Nobody has to remember to clean up.
- **Sensitive fields are stored encrypted**, including payment-provider tokens, API secrets and two-factor authentication secrets.
- **The paperwork is public**: [processing agreement](/en/data-processing-agreement), [DPIA](/en/dpia) and an overview of how the platform is secured on [privacy and security](/en/privacy-security).

# Where this touches the rest of your event

Three neighbouring topics come up constantly and each has its own rules:

- **Extra details after the sale.** Dietary requirements, T-shirt sizes, a licence plate for the car park — useful, and all personal data. Collect them for a stated purpose and drop them afterwards. See [collecting attendee details after the ticket sale](/en/blog/collecting-attendee-details-after-the-ticket-sale).
- **Photos and video.** Filming your own event brings in both the GDPR and image rights, which is a separate conversation: [photos and video at your event](/en/blog/photos-video-events-portrait-rights-gdpr).
- **Access to your own dashboard.** The strongest retention policy in the world does not help if four people share one login. [Magic login and two-factor authentication](/en/blog/magic-login-and-2fa) covers how access to visitor data is protected on the organiser side.

# In short

The GDPR asks for a lawful basis, limited retention, a processing agreement, respect for visitor rights and appropriate security. None of that requires you to become a privacy lawyer — it requires a handful of deliberate choices and a platform that does the mechanical parts for you.

Want to see how it works with your own event? [Create your organiser account](/registreer) — no setup costs, no subscription and no contract, and you only pay once you actually sell a ticket: €0.50 per paid ticket, or €0.25 with the [Organiser plan](/en/pricing) at €14.95 once per published event. Free tickets are always fee-free.

*This article is general information, not legal advice. Consult a privacy specialist if you are in any doubt.*

 Legislation changes and tariffs are revised annually. We do our best to keep this article current and link to the source where we can, but we cannot guarantee everything still holds at the moment you read it. If a decision carries financial or legal consequences, check with the authority itself or put it to a lawyer or adviser. See also our [general disclaimer](https://mijnevent.nl/en/disclaimer).

   Frequently asked questions

## Frequently asked questions

## Which lawful basis do I need to process visitor data?

  For ticket sales it is usually performance of a contract: you need the data to deliver the ticket and admit the buyer. If you want to send marketing e-mails afterwards, that needs separate consent.

## Do I need a processing agreement with my ticketing platform?

  Yes. If a platform processes personal data on your behalf, Article 28 GDPR requires a written processing agreement setting out what it may do with the data and how it secures it.

## Does the GDPR apply if my event is outside the EU?

  It can. The GDPR follows the people, not the venue: if you offer tickets to visitors in the EU, you fall within its scope even when your organisation sits elsewhere.

## What do I do when there is a data breach?

  Report it to your national supervisory authority within 72 hours of becoming aware of it, and inform the visitors themselves when the risk to them is high. Work out how you would do that before you need it.

  [    Back to blog ](https://mijnevent.nl/en/blog) 

  MijnEvent

## Read more

 [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/verloting-bingo-op-je-evenement-wat-mag.webp) legislation 

 MijnEvent · 24 August 2026 · 11 min read

## Raffles and bingo at your event: when Dutch gambling law kicks in

A tombola at the parade, a bingo night at the community hall, raffle tickets sold alongside your entry tickets — it all looks harmless, but the Dutch Gambling Act is unambiguous. What is allowed without a licence, what you apply for at the town hall, and where gambling tax comes in.

 ](https://mijnevent.nl/en/blog/raffles-and-bingo-at-your-event-dutch-rules) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/what-does-a-ticketing-platform-cost.webp) pricing 

 MijnEvent · 24 August 2026 · 5 min read

## What does a ticketing platform cost?

Commissions, service fees, payment costs and subscriptions: how to work out what selling tickets really costs you — with worked examples for 100 and 500 tickets.

 ](https://mijnevent.nl/en/blog/what-does-a-ticketing-platform-cost) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/stadsbon-winkels-uitbetalen-van-kassa-tot-bank.webp) modules 

 Jasper Koers · 19 August 2026 · 5 min read

## Paying out shops on your city voucher: from till to bank, with four eyes

A customer pays, the shop deducts the amount — then what? Follow the money: the € 0.05 per redemption, the 'to be paid out' list, payout batches with a SEPA file, and the four-eyes principle.

 ](https://mijnevent.nl/en/blog/paying-out-shops-city-voucher-from-till-to-bank) 

   MijnEvent

## Ready to get started?

Create a free account and sell your first tickets today.

 [Start free](https://mijnevent.nl/registreer) [Pricing](https://mijnevent.nl/en/pricing)
