Selling a ticket creates a record that says a named person will be in a particular seat at a particular time, paid for in a particular way. Companies think of that as a sale. It is also a file about somebody, and the obligations attached to it do not depend on whether anyone thought about them.
The field nobody notices is the sensitive one
Name, contact details, seat and payment reference are ordinary personal data. The access requirements box is not. A record stating that a patron uses a wheelchair, needs an assistive listening receiver or is attending with an assistance dog is information about their health, and in jurisdictions with data protection regimes of the European kind it sits in a category with a higher bar for processing, retention and security.
The common failure is that this information is collected in a free text box, stored indefinitely in the same database as the marketing list, and never reviewed. The remedy is structural: collect only what is operationally needed, store it separately from marketing, set a retention period tied to the performance rather than to the customer, and do not invite people to describe a medical condition when the question is which facilities they need.
Jurisdiction decides the rules, and there are several
European and United Kingdom regimes impose a lawful basis, purpose limitation, minimisation, retention limits, security obligations and individual rights including access and erasure. Several United States states have enacted their own frameworks with different definitions and different thresholds. A company selling to audiences in more than one territory is subject to more than one set of rules.
None of this is legal advice, and the applicable rule depends on where the audience is rather than where the venue is.
Card details are somebody else's problem, deliberately
Payment card data is governed by a security standard maintained by the card industry, and the practical consequence for a venue is straightforward: the less card data touches the venue's systems, the smaller the obligation. Using a processor whose fields collect the card directly, so that the venue receives only a token and a reference, is not laziness. It is the design that keeps a box office out of scope.
The failure mode here is old and persistent: card numbers written on paper for telephone bookings, or typed into a notes field so that a patron does not have to give them again.
Every copy is a place it can leak from
A ticketing record rarely stays in one system. It reaches the ticketing platform, a customer relationship tool, an email marketing service, an analytics product and whatever the website loads on the checkout page.
That last one deserves attention because it is invisible. Third party tags placed on a purchase page can transmit details of what was bought, by whom, to companies with no relationship to the transaction, and the venue is responsible for what its own page loads. Auditing the checkout path, and keeping it as bare as it can be, is a data protection measure as much as a performance one.
The list is the asset, and that is the pressure
Audience data is one of the few assets a company builds over decades, and every funding application, every marketing plan and every board conversation treats it as one. That pressure runs directly against minimisation and retention limits, and pretending otherwise makes the policy unenforceable.
The reconciliation that works in practice is to separate the two purposes at the point of collection. A marketing relationship is consented to, maintained, and can be withdrawn. An operational record of who sat where and what they needed is kept for as long as the production requires and then is not. Companies that hold both in one undifferentiated customer profile end up unable to honour either promise.
Retention is where good intentions accumulate
Nobody deletes a customer record, because it might be useful. Fifteen years later the database contains addresses people moved away from, telephone numbers reassigned to strangers, and access requirements from a production nobody remembers.
A retention schedule that says how long each category is kept and why is unglamorous and it is the single measure that most reduces the consequences of a breach, because data that was deleted cannot be disclosed.
Two rights that conflict, and how they are reconciled
A patron may ask for their data to be erased. A company also has to keep financial records for a statutory period. These are not actually in conflict: the transaction record required by tax law is kept, and the marketing profile, the preferences and the correspondence are not. The answer is separation, which has to exist in the system design before the request arrives.
What we cannot verify
Data protection law varies by jurisdiction, changes, and applies according to facts specific to each organisation. Nothing here is legal advice, and a company handling audience data should take advice on its own position. Security and compliance claims made by ticketing platforms come from those platforms; a venue remains accountable for its own choices regardless of what a supplier asserts. We have not examined any particular system.
The short version
- A ticket record is a file about a person, whatever the accounting calls it.
- The access requirements field is health information and needs a higher bar.
- Collect what is operationally needed, not a description of a condition.
- Keeping card data out of the venue's systems is a design decision, not laziness.
- Third party tags on a checkout page transmit purchases to companies with no part in them.
- A retention schedule is the cheapest reduction in the consequences of a breach.