Get a quote

The Price of Admission: The Privacy Risks Behind the Festival Experience

29 September 2026

Jacob Graham, Senior Data Auditor

Blog

Data Protection

GDPR

Privacy

Summer has officially come to an end. If you are like me, you may have spent some of it at one of the UK’s 592 music festivals. In the past year, 23.5 million of us attended a festival or two, while the wider live music industry contributed an estimated £7.6 billion to the UK economy in 2025.

At the heart of these festivals and events are everyday people like you and me, spending our hard-earned money enjoying the sun, dancing and living life to the max. However, delivering that experience means collecting more data than ever before – and every additional data point brings compliance obligations with it.

Privacy: the less obvious compliance risk

Event organisers already face a mammoth logistical task: months of planning, preparation, risk assessment and mitigation for their events before welcoming tens of thousands of attendees and staff, all while hoping that their preparation pays off.

Most people would recognise some of the compliance issues events may face, such as music licensing, food and drink licensing, and health and safety. Privacy risks, however, are less obvious.

To run these events, organisers must collect a huge amount of personal data from staff, artists, performers, attendees and volunteers. Some of this data is collected to meet a legal or contractual obligation, such as staff payroll or ticket sales, while other information is used to safeguard people or provide convenience. All of it will need to comply with the UK’s data protection legislation.

CCTV, drones and bodycams

CCTV cameras are commonplace in public places, and festivals and live events are no different. These events often take place in temporary locations such as fields, farms or airfields, so organisers often hire temporary CCTV towers. Positioned around the site, these towers monitor attendees and provide a live feed to an event control room, which monitors crowds and directs staff to areas of need.

Some providers now deploy drones to monitor crowds from above and patrol perimeter lines with security staff equipped with body-worn cameras, watching for suspicious activity. This surveillance is seen as an essential tool to prevent crime and maintain order, but it does not remove the need to comply with privacy legislation.

Where do you put a privacy notice in a field?

Event organisers must be aware of their obligation to uphold individuals’ data rights under the GDPR (General Data Protection Regulation). These include the right of access, which individuals can exercise by submitting a DSAR (data subject access request) and the right to be informed of how your data is used.

This raises a practical question for event organisers: where do you display a privacy notice in a field where it can withstand, rain, wind, mud and the occasional overenthusiastic festival-goer?

I reviewed the privacy notices of the two outdoor music festivals I attended this summer. Both clearly stated that images of me might be captured by CCTV to prevent and detect crime and damage – hardly surprising. I work in compliance and know I could find the privacy notices online within moments. But is online publication alone enough to meet transparency requirements?

The ICO (Information Commissioner’s Office) makes clear that an online privacy notice is not sufficient to meet transparency obligations. Adequate signage should explain that CCTV is in use, its purpose and whom to contact with a query. At one festival, a large LED sign at the site entrance read: “SMILE! YOU ARE ON CAMERA! CCTV in operation past this point.” This would fall short of the standard set by the ICO, because it doesn’t explain the purpose of CCTV or who to contact.

RFID wristbands: payments, sharing and tracking

A newer development in the events sector is the use of RFID (radio frequency identification) wristbands. These small chips are assigned to a user’s unique profile and can:

  • Replace a physical ticket;
  • Enable cashless payments;
  • Support social media integrations; and
  • Provide tap-to-share functions.

Some uses are straightforward: a ticket can be assigned to the chip, which stays with the individual, while a cashless payment can be triggered by connecting the user’s account to a payment card. This can reduce the risk of cards being lost or stolen at event sites and make fraudulent tickets harder to use.

RFID wristbands can also allow attendees to share social media links with new friends or businesses, enter giveaways with event sponsors, or access exclusive content.

Many people, including me, are likely to be more immediately concerned about being overzealous with cashless spending. Festivals and events are famously not cheap.

However, RFID wristbands have another side: user analytics and tracking. One company that develops and sells them promotes the ability to track attendance at gates and in zones, understand crowd-flow patterns, and identify average transaction values. The wristbands communicate with a reader via radio waves, with operating distances ranging from a few centimetres to hundreds of metres.

These systems can show how busy particular areas or amenities, such as toilets, may be. It could be questioned whether attendees are made aware that their wristband is tracking them across the site at all times. This raises additional questions about fairness and reasonable expectations: does an event need to know my location within the grounds at all times?

Tracking crowd movement to help prevent crushing incidents may be reasonable. However, when this technology is combined with CCTV or even facial recognition, does it begin to feel like Big Brother is watching?

What event organisers need to consider

Most organisers will have legitimate reasons to use CCTV and RFID wristbands, but they must carefully consider the associated compliance implications. These include:

  • Data retention and security;
  • Lawful bases for processing;
  • Any applicable special category conditions; and
  • Transparency obligations.

Cashless payments may also introduce wider requirements, such as PCI DSS (Payment Card Industry Data Security Standard) compliance. Another principle that is often overlooked is data protection by design and by default.

Organisers therefore need to ask several fundamental questions:

  • Will the processing be fair and proportionate?
  • Would individuals reasonably expect it?
  • Could the technology impair their rights and freedoms?

When assessing the potential data protection impact on individuals, organisers should seek independent input. This might come from a group of individuals, an internal data protection team or an external data protection consultant. Whoever is consulted, the assessment must balance the organiser’s aims and objectives against individual rights and freedoms.

We are in a time where innovation and privacy seem to be in conflict, and data-hungry practices are driving conscious consumers away. I have personally shied away from events and services that appear to be collecting too much data. While data and surveillance undeniably have their place in managing safety at large events, the real challenge for events businesses is where to draw the line. This leaves us with a critical question: is the technology protecting the attendees and enhancing their experience, or are you just collecting the data because you can?

Planning your next event?
Our data protection consultants can carry out a DPIA (data protection impact assessment) on your behalf or guide your team through the process, so your surveillance and attendee technology is fair, transparent and compliant.