Only the ones you need to issue the ticket, take payment and let that person in. Article 5.1.c) of Regulation (EU) 2016/679 requires data to be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed". Any mandatory field that doesn't pass that test is a needless risk: it doesn't improve the sale, and it does open the door to a complaint.
The difference between a sound form and a sanctionable one is almost never about the technology. It comes down to whether the organiser can explain, field by field, why each piece of data is being asked for. This guide covers what the Spanish Data Protection Agency (AEPD) and the GDPR require from an organiser in Spain: what you can ask for, who owns that data, what you can do with it afterwards, and how long you keep it.
Who owns the data of a ticket buyer?
The organiser's, if the organiser is the one who decides what it's used for. Article 4.7 of the GDPR defines the controller as whoever "determines the purposes and means of the processing", and 4.8 defines the processor as whoever "processes personal data on behalf of the controller". The ticketing platform is usually the processor: it processes the data following your instructions, under a contract that, per Article 28.3, must govern that processing.
This distinction matters when you sell through a third-party marketplace. Eventbrite's privacy policy, checked on 6 October 2026 and last updated on 15 September 2026, points the buyer towards the organiser: "any questions you may have relating to your Personal Data and your rights under data protection law should be addressed to the Organiser as the data controller, not to Eventbrite". Eventbrite publishes that policy in Spanish, with a detailed help centre — something not every platform does. Every contract is different: some platforms declare themselves controllers for part of the processing, which changes how obligations are split.
When two entities decide together — a promoter and a venue sharing the attendee database, for example — Article 26.1 makes both of them joint controllers and requires them to set out in writing, in advance, who handles data subject rights. The European Data Protection Board sets out these three roles in its Guidelines 07/2020, adopted on 7 July 2021.
What data can you ask for at checkout, and what's excessive?
The test is simple: write the purpose next to the field. If you can't come up with a specific sentence, the field is excessive, or shouldn't be mandatory. The AEPD's guide on data protection by default, from October 2020, puts it plainly: «No se deberían recabar por defecto los datos que serían necesarios para un potencial uso de todas las funcionalidades futuras, incluidas las que podrían ser a elección por el usuario» ("data that would be needed for a potential use of all future functionalities — including those left to the user's choice — should not be collected by default"). It adds a limit that applies directly to checkout: use cases must not present the user with «un dilema del tipo "lo tomas o lo dejas"» ("a 'take it or leave it' dilemma") in order to access the contracted service.
| Field | Purpose that justifies it | When it shouldn't be mandatory |
|---|---|---|
| Name and surname | Issuing the ticket and, if it's a named ticket, checking identity at entry | Never, if the ticket is a named one |
| Email address | Delivering the QR code and notices of changes or cancellation | Never; it's the delivery channel |
| Phone number | Urgent notice of cancellation or venue change | If it's only used for promotions |
| Date of birth | Age-based pricing or an age-restricted event | If there's no associated pricing tier or restriction |
| ID card or passport | Named ticket checked at the door, or a venue obligation | If no one checks it on the day of the event |
| Postal address | Physical delivery of tickets or a merchandise item | In a fully digital sale |
| Postcode and country | Tax treatment of the service provided, or declared logistics | If the stated purpose is "statistical" and nothing more |
Two practical rules. First: separate mandatory fields from optional ones, and make the optional ones look optional. Second: what you ask for at the point of purchase doesn't have to match what you ask for at accreditation; Article 11 of Organic Law 3/2018 allows layered information, with the basic details visible upfront and the rest one click away.
What happens if you ask for health data at the door?
You fall under Article 9 of the GDPR, which bans processing health data unless an exception applies — such as explicit consent under paragraph 2(a). The AEPD examined this in file EXP202405302, opened after a complaint filed on 15 March 2024 against PASIÓN DE EVENTOS MANAGEMENT, SL, promoter of Festival Conexión Valladolid 2024, held on 28 and 29 June.
The problem lay in a line of the terms of sale: «16. En el recinto del Evento no se puede acceder con comida ni bebida. En caso de necesidad médica (celíacos, etc.) deberá presentarse un justificante médico que lo acredite» ("No food or drink may be brought into the Event venue. In case of medical necessity (coeliac disease, etc.), a medical certificate must be presented as proof"). Asking for that certificate at the door means processing the health data of anyone entering with food.
The promoter submitted an impact assessment, the record of processing activities, a risk analysis, its privacy policy and the processing agreement with the security company to the Agency. In the assessment, it describes the processing as «Control del acceso a los eventos organizados por PASION EVENTOS» ("Access control for events organised by PASION EVENTOS"), with a volume of «aproximadamente 9.000 personas por evento» ("approximately 9,000 people per event"), and argues that the document is only visually checked: «No se coteja la información contenida en dicho documento ni se realiza acción alguna encaminada a determinar la veracidad de la misma» ("The information contained in the document is not cross-checked, nor is any action taken to determine its veracity").
The AEPD also found that on 20 June 2025 the promoter had rewritten the condition, which now read «salvo necesidad médica» ("except for medical necessity"), without requiring any document. It then closed the file: «no se han encontrado evidencias que acrediten la existencia de infracción al derecho fundamental a la protección de datos» ("no evidence has been found to establish an infringement of the fundamental right to data protection"). Our own reading, not the ruling's: what saved the case wasn't the clause itself, but the paperwork done beforehand — impact assessment, record of processing activities and processing agreement — together with the timely correction of the public wording.
Can you send marketing to someone who's already bought a ticket?
It depends on what you send. Article 21.1 of Law 34/2002 bans «el envío de comunicaciones publicitarias o promocionales por correo electrónico u otro medio de comunicación electrónica equivalente que previamente no hubieran sido solicitadas o expresamente autorizadas por los destinatarios» ("sending advertising or promotional communications by email or equivalent electronic means that have not been previously requested or expressly authorised by the recipients"). The exception in paragraph 2 is the one almost every organiser relies on: if you obtained the email address through a prior contractual relationship and the marketing concerns similar products or services, you can write to them, as long as you offer a «sencilla y gratuita» ("simple and free") way to opt out in every message.
Two limits people tend to forget. One: "similar" doesn't stretch to cover just anything. Someone who bought a ticket to an electronic music festival hasn't authorised you to sell them a season pass for a trade conference. Two: the exception covers your list, not your partner's; an email sent to a third party's database falls outside it.
The cost of getting it wrong is set out precisely. Article 38.3.c) classifies «el envío masivo de comunicaciones comerciales por correo electrónico (…) o su envío insistente o sistemático a un mismo destinatario» ("the mass sending of commercial communications by email (…) or sending them insistently or systematically to the same recipient") as a serious infringement when Article 21 isn't met, and Article 39.1 sets the fine for serious infringements at «de 30.001 hasta 150.000 euros» ("from €30,001 to €150,000"); minor infringements go up to €30,000. If you're going to build an audience this way, your approach to email marketing for events needs to be built from the outset around the opt-out checkbox and proof of where each address came from.
Can you pass the attendee list to a sponsor or venue?
Not simply because it's requested in the sponsorship contract. Handing names and email addresses to another company is a data disclosure, and it needs a legal basis under Article 6 of the GDPR plus prior information: Article 13.1.e) requires you to state the "recipients or categories of recipients" at the time the data is collected. If your privacy policy didn't name the sponsor or its category, the transfer has no legal cover.
In practice, there are only three clean routes. Specific attendee consent, via a separate, unticked box stating who the data goes to and why. A processing agreement, when the third party works for you rather than for itself — in which case you need an Article 28 contract, for which the AEPD publishes its guidelines on contracts. Or Article 26 joint controllership, with a written agreement, when the venue and promoter decide together.
There's a fourth route that needs no personal data at all: giving the sponsor aggregated results — attendance by time slot, origin by province, redemption rate — instead of the list. That's usually what they actually want, and it doesn't move a single piece of personal data. The same applies to press accreditation and access providers: the general principle is covered in our GDPR guide for organisers, and the specific case of biometrics at the door, with the AEPD's stance since November 2023, is covered in our guide to access control at festivals.
How long do you need to keep sales data?
Until liability periods expire, not until you get tired of keeping them. Article 32 of Organic Law 3/2018 defines blocking as «identificación y reserva de los mismos, adoptando medidas técnicas y organizativas, para impedir su tratamiento» ("identifying and setting the data aside, adopting technical and organisational measures to prevent its processing"): data isn't deleted the day after the event — it's blocked and kept available to courts and public authorities for the statutory periods.
| Data | Retention period | Rule |
|---|---|---|
| Invoices and tax records for the sale | 4 years | Article 66, Law 58/2003 General Tax Law |
| Books, correspondence and supporting business records | 6 years | Article 30, Commercial Code |
| Data processed solely for marketing communications | Until the data subject objects | Article 21, Law 34/2002 |
| Access data with no further declared purpose | For as long as the access-control purpose lasts | Article 5.1(e), GDPR |
The practical upshot is that your platform needs to distinguish between two things people often mix up: the accounting record, which is retained, and the marketing list, which is cleaned. The specific tax deadlines for ticket sales are covered in our guide to ticket sales taxation in Spain.
What do you do if the attendee database is leaked?
You start counting the hours from the moment you find out. Article 33.1 of the GDPR requires you to notify the supervisory authority of the security breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it", unless it's unlikely to result in a risk. Even if you decide not to report it, you still document the incident and the reasoning behind that decision.
The volume shows how routine this is. The AEPD received 2,765 personal data breach notifications in 2025, 80% from the private sector, and only eleven ended up referred for investigation. That works out to 7.6 notifications a day on average — our own calculation based on the Agency's figure — and the AEPD itself stresses that timely reporting demonstrates diligence and doesn't amount to opening an investigation.
What does get penalised is negligence. In its 2025 annual report, published on 6 May 2026, the Agency reports 30,931 complaints received, 64% more than the previous year, and fines totalling €48,108,765, with 77 breach-related proceedings compared with 30 in 2024. The ceiling under Article 83.5 of the GDPR is €20,000,000 or 4% of global annual turnover. For a promoter with a database of several thousand buyers, the real risk isn't the ceiling: it's keeping the list in a shared spreadsheet with no access controls.
And where does Futura Tickets fit in?
As a Spanish SaaS ticketing platform, Futura Tickets acts as the processor: the organiser decides which fields to ask for and why, and the platform processes them according to those instructions, under an Article 28 GDPR contract. With Futura Tickets, the attendee database belongs 100% to the organiser: emails and phone numbers are handed over in full, in line with the GDPR. That solves the ownership question, but not minimisation: any extra fields you configure remain your responsibility, not the tool's.
What to check before you open the sale
Six checks. None of them needs a lawyer to get started.
Print out your checkout and write the purpose next to each field. Any field left without a sentence becomes optional or gets removed. This is what the AEPD calls a critical review of each stage.
Check who's named as controller in your platform contract. Without a signed processing agreement covering Article 28.3, there's no basis for a third party to process your data.
Review which recipients your privacy policy declares. If you're going to share anything with the venue, the sponsor or the security company, they need to be named or placed in a category before the first sale.
Decide today what you'll hand over to a sponsor. Aggregates and metrics by default; lists only with specific consent collected at the point of purchase.
Separate the accounting record from the marketing list. Four and six years for the former; immediate removal for the latter when someone objects.
Write your breach procedure on a single page. Who detects it, who they notify, what gets logged, and who signs off the 72-hour notification. A leak at three in the morning on a festival Saturday is not the time to improvise this.
One last point of context: data protection isn't the only consumer-facing front open at an event. Terms of sale also get scrutinised through other channels, as shown by the consumer protection fine against Reggaeton Beach Festival. The purchase form is the document most people actually read on your event. It's worth making sure it holds up to a careful read.
Sources
- Regulation (EU) 2016/679, GDPR: Articles 4.7, 4.8, 5.1(c), 9, 13.1(e), 20.1, 26.1, 28.3, 33.1 and 83.5 (EUR-Lex)
- Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights: Articles 11 and 32 (consolidated text, BOE)
- Law 34/2002 on information society services: Articles 21, 38 and 39 (consolidated text, BOE)
- Law 58/2003, General Tax Law: Article 66, four-year limitation periods (consolidated text, BOE)
- Commercial Code: Article 30, six-year retention of books and supporting records (consolidated text, BOE)
- AEPD, decision to close file EXP202405302, Festival Conexión Valladolid 2024 (PDF)
- AEPD, Guide to data protection by default, October 2020 (PDF)
- AEPD, Guidelines for drafting contracts between controllers and processors (PDF)
- AEPD, press release on 2025 personal data breach notifications
- AEPD, press release on the 2025 annual report: complaints and fines, 6 May 2026
- European Data Protection Board, Guidelines 07/2020 on the concepts of controller and processor
- Eventbrite, privacy policy, updated 15 September 2026 (accessed 6 October 2026)