# Handling a GDPR request: access and erasure in your dashboard — MijnEvent

  [Home](https://mijnevent.nl/en) / [Blog for event organizers](https://mijnevent.nl/en/blog) / Handling a GDPR request: access and erasure in your dashboard   privacy gdpr dashboard visitors 

# Handling a GDPR request: access and erasure in your dashboard

A visitor asks for their data or wants to be erased. In Dashboard → Privacy &amp; GDPR you look them up, download everything you hold on them as JSON, or anonymise their personal data irreversibly.

 [Jasper Koers](https://mijnevent.nl/en/author/jasper-koers) · 6 July 2026 · 5 min read 

       In short

- In Dashboard → Privacy &amp; GDPR you look up a visitor by name or e-mail address and handle their request straight away.
- 'Export data' produces a JSON file with the profile, orders, tickets, listings and gift cards.
- 'Delete data' anonymises the personal data irreversibly; orders are kept for the accounts and tickets are invalidated.
- Every action — including revealing an e-mail address — ends up in 'Recent privacy actions'.

  A visitor sends an e-mail: "I want to know what data you hold on me." Or, a week later: "Delete my data." Those are not favours but statutory rights: the [right of access](https://www.autoriteitpersoonsgegevens.nl/themas/basis-avg/privacyrechten-avg/recht-op-inzage) and the [right to erasure](https://www.autoriteitpersoonsgegevens.nl/themas/basis-avg/privacyrechten-avg/recht-op-gegevens-verwijderen), as the Dutch data protection authority explains them (in Dutch). You handle both requests in MijnEvent on a single screen, without a database export or a support ticket.

# Where to find it

Your dashboard has **Privacy &amp; GDPR** in the navigation. The page is called *Privacy &amp; GDPR requests* in full and says in one sentence what it does: handle access and erasure requests from your visitors, and every action is recorded. Keep an eye on the deadline the Dutch data protection authority sets out in [Voor organisaties: privacyrechten in de praktijk](https://www.autoriteitpersoonsgegevens.nl/themas/basis-avg/privacyrechten-avg/voor-organisaties-privacyrechten-in-de-praktijk) (in Dutch): you have one month from receipt to handle the request, extendable by two months in exceptional cases, provided you say within that first month that you need longer.

# Step 1: look up the visitor

At the top is the **Find visitor** search field, with the hint: search on the e-mail address the visitor gave in their request. You can search by name too — the search looks at both fields. The results appear as cards with the name and e-mail address, and two buttons per visitor.

Do bear in mind that e-mail addresses in your dashboard are normally [masked](/en/blog/privacy-email-masking). That is deliberate: you do not need to see the full address on every order to do your job.

# Step 2: access — exporting the data

For an access request you click **Export data**. Your browser immediately downloads a JSON file (with the visitor id in the filename) containing what is stored about this person in the tenant database:

- **Profile** — name, e-mail address and the date the account was created.
- **Orders** — status, total amount, date, and per line the ticket type, the quantity and the unit price.
- **Tickets** — the ticket token, whether the ticket is still valid, and the creation date.
- **Listings** — resale listings with the asking price and status.
- **Gift cards** — with a masked code, the role (buyer or recipient), the original and remaining amount and the personal message, if there is one.

You get a confirmation on screen ("the data has been downloaded") and you can forward the file to the visitor as it is. JSON is a structured, machine-readable format — exactly what you want to be able to supply for a data portability request.

# Step 3: erasure — anonymising the data

For an erasure request you click **Delete data**. That button is only there for team members who are also allowed to manage users; a colleague who only views orders will not see it.

A confirmation dialogue appears with the heading **"Anonymise data permanently?"** and underneath it exactly what is going to happen: this visitor's personal data is anonymised irreversibly, orders are kept for the accounts, but tickets are invalidated.

More happens behind that button than just overwriting a name and an e-mail address:

- The visitor's name and e-mail address are replaced with a neutral placeholder — on the associated login account as well, so the login identity is decoupled.
- All of this visitor's tickets are set to invalid, and the associated wallet passes are revoked so they turn grey in Apple Wallet and Google Wallet.
- Gift cards refer to the buyer and recipient by e-mail address. That personal data and the personal message are erased, but the code and the balance remain — a gift card is a bearer instrument and so stays spendable.

Rows are never hard-deleted anywhere; anonymisation happens in the place where the data sits.

# Why orders stay

This is the question that comes back most often: if someone wants to be erased, why does their order remain? Because an order is also an accounting fact. You have to be able to account for your administration, and that does not work if transactions vanish without trace from your system.

The solution MijnEvent has chosen: the transaction stays, the person disappears from it. The amount, the ticket type and the date are still there; the name and e-mail address that were attached to them are not. There is more background on what you as an organiser actually hold on to in the way of visitor data in the article on [what your ticket platform does with visitor data](/en/blog/what-does-your-ticket-platform-do-with-visitor-data).

# Every action ends up in the logbook

Below the search section is the **Recent privacy actions** block: a table with the action, who carried it out and the time. *Data exported*, *E-mail address revealed* and *Data anonymised* appear there, among others.

That revealing an e-mail address is on that list too is no accident. Requesting a masked address is a processing of personal data, and so the system records who requested which address and when. The logbook itself is append-only: entries are added, never edited or deleted. More on that in the article on [the activity log](/en/blog/the-activity-log-who-did-what).

# What happens automatically

Besides what you do yourself, MijnEvent also tidies up without a request. A scheduled task anonymises the data of visitors whose last event finished longer ago than the configured retention period — 24 months by default. The same applies there: orders and (invalidated) tickets are kept for the administration, only the personal data goes.

That is the same thinking the whole platform was set up with: keep as little as possible, and no longer than necessary.

   Frequently asked questions

## Frequently asked questions

## Where do I handle a GDPR request?

 In your dashboard under Privacy &amp; GDPR. You look the visitor up by name or e-mail address and then choose 'Export data' or 'Delete data'.

## Are orders deleted as well?

 No. Anonymising erases the personal data, but orders are kept for the accounts. The associated tickets are invalidated.

## Can I undo an anonymisation?

 No. The confirmation dialogue warns about this explicitly: the personal data is anonymised irreversibly. Export first if the visitor also asked for access.

## Who can delete data?

 The delete button only appears for team members who are allowed to manage users. Anyone with access to the dashboard can search and export.

  [    Back to blog ](https://mijnevent.nl/en/blog) 

  MijnEvent

## Read more

 [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/automatic-membership-renewal-dutch-law.webp) memberships 

 Jasper Koers · 27 July 2026 · 6 min read

## Automatic membership renewal: collecting fees within Dutch renewal law

Automatic renewal saves your club a pile of chasing work, but the law has rules about cancelling. Here is how renewal works in MijnEvent, and how to keep it clean.

 ](https://mijnevent.nl/en/blog/automatic-membership-renewal-dutch-law) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/ontruimingsverslag-evenement-bewijsstuk.webp) safety 

 MijnEvent · 27 July 2026 · 5 min read

## The evacuation record: why the day after your event matters for the next permit

An evacuation — real or drilled — is only finished once it is on paper. What belongs in an evacuation record, why the municipality asks for it, and how to make the record write itself instead of reconstructing it afterwards?

 ](https://mijnevent.nl/en/blog/evacuation-record-event-evidence) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/knmi-weeralerts-veiligheidsplan.webp) safety 

 MijnEvent · 27 July 2026 · 3 min read

## Weather monitoring in your safety plan: how KNMI warnings land in your alerts and logbook automatically

Almost every safety-plan format has a 'weather monitoring' section — and almost nobody fills it in concretely. The Safety &amp; Permit module pulls the KNMI warning code for your event location every hour and turns it into a demonstrable process.

 ](https://mijnevent.nl/en/blog/knmi-weather-alerts-event-safety-plan) 

   MijnEvent

## Ready to get started?

Create a free account and sell your first tickets today.

 [Start free](https://mijnevent.nl/registreer) [Pricing](https://mijnevent.nl/en/pricing)
