Introduction: the portrait your outings paint
We keep an eye on our medical records, our bank statements, the cameras in our building. Almost nobody worries about their ticketing history.
And yet, take three years of outings and look at what they say. A rap concert in a 500-capacity venue. Two conferences organised by a faith-based association. An activist film festival. A children's show on a Saturday morning — so a four- or five-year-old. An exhibition about addiction. A "solidarity" reduced-rate subscription granted on proof of welfare benefits. A match at the stadium in the away supporters' stand. An LGBT play on a Tuesday evening, paid for alone, a single ticket.
Your leisure activities don't say what you do with your days. They say what matters to you — your convictions, your background, your income, your state of health, the make-up of your household and the town where you sleep. And unlike medical records, that portrait is protected by no professional confidentiality whatsoever.

This guide takes stock of what online ticketing, cashless wristbands, membership cards and access-control systems actually record, sets out what is mandatory and what is not — the difference is enormous — then offers practical steps for continuing to go out without feeding a file.
Part 1 — The inventory: who collects what, and why
Online ticketing: the real centre of gravity
When you buy a concert ticket, you almost never deal with the venue. You deal with a ticketing platform, a separate commercial player, often international, whose business model rests in part on knowing its audience.
Here is what ends up in the database, beyond the strict minimum:
| Data | Genuine usefulness for the event | What it reveals |
|---|---|---|
| Surname, first name | Low (unless a named ticket is required) | Legal identity |
| Postal address | None for an e-ticket | Home, neighbourhood, standard of living |
| Date of birth | Useful only for age-restricted or age-based pricing | Exact age |
| Mobile number | Cancellation alerts | The pivot identifier for your entire digital life |
| Purchase history | None once the event is over | Convictions, tastes, social circle |
| Rate applied | Accounting | Social status (student, jobseeker, disability, welfare benefits) |
| Number of seats | Logistics | Family situation or single status |
The reduced rate is the most talkative detail of all. Ticking "income support recipient", "jobseeker", "holder of a disability inclusion card" or "student" amounts to declaring socio-economic data — sometimes health data — to a private company whose business it is not.
Festival cashless systems: a bank statement for your weekend
The RFID wristband slipped onto your wrist at a festival entrance has replaced cardboard tokens. Technically, it is a prepaid account tied to an identifier, which is itself tied to your online registration — and therefore to your bank card and your email address.
The result: a timestamped history of everything you consumed. Number of beers, time of the last one, merchandise stand, the terminal where you topped up, the stage you walked past if the gates are instrumented. It is a behavioural statement, far more granular than an ordinary bank statement, and it often survives for several years "to manage balance refunds".
France's data protection authority, the CNIL, has ruled on these systems on several occasions: cashless is lawful, but it must remain proportionate, and above all must not result in individual profiling of festival-goers without a clear legal basis. In practice, consent is rarely freely given: no wristband, no purchases on site.
Museums: memberships, sensors and headcounts
A museum that sells you a single timestamped ticket barely knows you at all. A museum that sells you an annual membership with a photo knows you very well: visit frequency, times of day, exhibitions chosen, companions logged on joint entries.
Add to that systems the public often knows nothing about:
- Headcounting via cameras or flow sensors, in principle anonymous and statistical — but whose configuration (age estimation, gender estimation, measuring time spent in front of a work) tips it into personal data processing if it makes a visitor individually identifiable;
- Visitor apps that request indoor geolocation (Bluetooth beacons) and reconstruct your route room by room;
- Free wifi, a classic collection point where the MAC address and connection time are enough to prove you were there;
- Audio guides and headsets handed over in exchange for an ID document as a deposit.
On that last point: leaving your ID card as a deposit for an audio guide is a widespread and legally shaky practice. Supporting documents should not be retained, let alone photocopied. An equally effective alternative is to use your own kit: a pair of compact wired earphones is enough for visits that offer an online audio tour, and spares you handing over an identity document at the cloakroom.
Stadiums and large venues: the testing ground
This is where surveillance is most advanced. Strictly named, tamper-proof tickets, a ban on resale outside the official platform, ID checks at the gate, pat-downs, and sometimes so-called "augmented" cameras to detect crowd movements.
France has framed these algorithmic cameras within a legal trial, with the CNIL designated to oversee their use. An important point to know: facial recognition is not permitted in this framework — only event-detection use cases (crowd surges, abandoned objects, density) are covered. The boundary is technical and therefore fragile; it deserves to be understood rather than imagined.

Part 2 — What is mandatory, and what is not
This is the part the forms never explain. The GDPR requires data minimisation: only what is necessary for the stated purpose may be collected. Applied to your outings, that draws a clear dividing line.
Legitimate and hard to avoid:
- Your name on a ticket when named ticketing is legally required: major sporting events, large-capacity venues subject to a prefectural order, measures against speculative resale;
- Proof of age for a show that is off-limits to minors or for access to alcoholic drinks;
- Proof of eligibility for a reduced rate, to be shown on the day, in person, to a member of staff;
- A way of reaching you in case of cancellation: an email address is enough.
Not mandatory, even if the form marks it as a required field:
- Your full postal address for a digital ticket;
- Your mobile number when an email address is already on file;
- Your exact date of birth when an "over 18" checkbox would do;
- The retention of a copy of your reduced-rate documentation or your ID;
- Your consent to the newsletter, to partners, to targeted advertising: these boxes must be unticked by default and refusing cannot deprive you of the ticket;
- Creating an account when guest checkout is technically possible.
A simple rule of thumb: anything that serves a purpose after the performance belongs to marketing, not ticketing. And anything that belongs to marketing can be refused.
Retention periods
There is no single period set in law, but there is a rule: retention must be limited to what is necessary. In practice, the CNIL's reference frameworks on commercial management point to an order of magnitude of three years after the last contact for a prospecting database, with accounting records kept separately for the statutory period — without any need to keep your detailed profile.
A cultural purchase history kept "for life" so as to "recommend things better" has no solid basis. That is exactly what an erasure request is for.
Part 3 — Practical steps, from the easiest to the most demanding
Level 1 — Compartmentalise your "going out" identity
Most of the problem comes from the fact that your tickets, your purchases, your bank and your working life all share the same identifiers. Separate them.
- A dedicated email address for leisure, or better still, a different disposable alias for each platform. A compromised or resold alias can be cut off in three seconds, and you immediately know who leaked your address.
- Stop handing over your mobile number. It has become the pivot identifier that allows databases to be cross-matched. When SMS confirmation is required, a secondary number or a send-and-receive service unconnected to your main line settles the matter.
- Don't create an account when guest checkout exists. No account, no consolidated history.
- Turn off your browser's autofill on these forms: it completes fields you would never have filled in yourself.
Level 2 — Paying without telling your story
Your payment method is the seam joining your ticketing file to your banking file.
- Favour the single-use virtual card numbers offered by most banks: capped amount, limited validity, no exploitable link from one platform to another;
- For tickets bought at the box office, cash remains the only genuinely untraceable method. The physical box offices of municipal venues, theatres and independent cinemas still sell tickets over the counter;
- At a festival, top up your wristband with cash at a physical terminal rather than by card online: the link to your banking identity disappears;
- Remember to claim your cashless balance after the event: not only do you get your money back, you also close an active account.
Level 3 — Reducing the traces you leave on site
- Turn off your phone's wifi and Bluetooth when you walk into a cultural venue. This is the highest-return move on the whole list: in one go it cuts off route-tracking beacons, counting sensors and collection networks. An RFID-blocking sleeve for a badge or card is a useful complement for the travel passes and contactless cards you carry.
- Don't install the event's app if a paper map or a web version exists. If you do install it, refuse background location and delete it on your way out.
- Avoid posting photos of tickets on social media: a photographed QR code remains readable, and an order number is sometimes enough to access the booking.
- For outdoor visits or festivals, a compact power bank saves you plugging your phone into public charging points, some of which route through a data cable.
- Transport: a single ticket bought with cash is better than travelling on a named season pass when you are heading to a sensitive gathering.
Level 4 — Exercising your rights, once a year
One hour a year is enough to clean up most of it.
- Right of access: ask two or three ticketing platforms for a copy of your data. They have one month to reply. The contents are often eye-opening — full history, the marketing segment you've been assigned, the partners it was shared with.
- Right to erasure: request the deletion of dormant accounts and purchase histories more than three years old.
- Objection to marketing: an email is enough, with no justification required.
- Complaint to the CNIL if you get no reply or a refusal: the procedure is online and free.
For those who would rather understand the mechanics than endure them, a practical guide to the GDPR and personal data fits on a shelf and saves a lot of back-and-forth.

Part 4 — Three sensitive cases
The reduced rate that reveals your situation
You are a jobseeker, an income support recipient or the holder of a disability inclusion card. The rate exists, it is legitimate, it was designed for you — and it forces you to declare that information to a private platform.
Best practice: book at full price online if the amount is small, or buy at the box office, where your documentation is seen and handed back, with nothing recorded. When a platform insists on an upload, send a redacted document: only the details needed to verify your entitlement to the rate are required, not your social security number or a breakdown of your income.
The commitment that pigeonholes you
A trade union conference, an activist screening, a faith-based gathering, a community event: these registrations involve special categories of data under the GDPR — political opinions, religious beliefs, sexual orientation, health. Processing them is prohibited in principle, barring exceptions.
A serious organiser therefore asks for nothing more than a first name and an email address. If it demands a full address and a phone number for a free public meeting, the question deserves to be asked out loud.
The child you sign up
A museum workshop, a drama course, a music school, a cultural summer camp: these files pile up the child's identity, photos, sometimes a medical certificate and image-rights permissions. Permission to publish photos is always optional and can be separated from the registration itself. A written refusal, clear and dated, is legally solid. To keep the memories without feeding a cloud service, a small compact digital camera entrusted to the child does the job nicely, and the pictures stay at home.
Conclusion: going out without telling your story
Culture has never needed your identity. People used to walk into the theatre with a scrap of cardboard, into a museum with a coin, into a concert with a standing ticket bought that very evening. Anonymity was not a privilege: it was the norm.
What has changed is not the law — the GDPR is rather on the audience's side. It is habit. Forms display required fields that aren't, platforms consolidate histories they have no legitimate use for, and we fill it all in without thinking, because the concert starts in twenty minutes.
Three reflexes sum up the essentials: a dedicated email address, no mobile number, your phone's radios switched off at the door. The rest — compartmentalised payments, annual erasure requests, redacted documents — falls into place as the habit takes hold.
You have the right to love what you love without it becoming a file.



