Not legal advice. This sorts through the questions that come up over and over in practice. For a binding assessment of your specific situation you need someone qualified to give one.
A guest list is a collection of personal data: a name, usually an email address or phone number, and the fact that this person was at a particular place on a particular night. That last part is the one most people underestimate — an attendance history says more about someone than their name does.
1. Why are you allowed to hold it at all?
For entry itself this is usually straightforward: the guest signs up in order to get in, and the processing serves exactly that purpose. It gets harder for everything afterwards — newsletters, re-invitations, segments. That is a different purpose and needs its own basis, normally consent the guest gives knowingly.
In practice: the "keep me posted about upcoming events" checkbox belongs separately from the guest list sign-up, and it must not be pre-ticked.
2. How much do you actually need?
The most common source of trouble is not bad intent but habit: fields that are in the form because they have always been in the form. Date of birth, full address, Instagram handle.
Walk your sign-up form field by field and ask: what happens at the door if this is missing? If the answer is "nothing", the field can go. That does not just reduce your exposure, it also raises your sign-up completion rate.
3. How long do you keep it?
"Forever" is not a retention period. You need one that matches the purpose, and after it the data has to be deleted — automatically, not when somebody remembers.
It helps to separate the types. You do not need one night's raw check-in records after the payouts are settled. Aggregated statistics with no personal reference you can keep as long as you like.
4. Who has access — and in what role?
This is the question most often left open at venues. If an external promoter can see the full guest list, you are disclosing personal data to a third party. Whether that is permissible, and who is then responsible for what, depends on how the arrangement is set up.
The practically safest route is to limit access: a promoter sees their own sign-ups and their own count, not the whole night's list. That is entirely sufficient for payouts, as described in paying promoters fairly.
When a guest asks to be deleted
- They must be able to ask informally — an email address is enough of a channel
- Deletion has to reach backups and exports, not just the live list
- Check-ins that already happened may be kept in aggregated, non-personal form
- Answer within a month, even if the answer is simply "done"
EventSync separates promoter access from the full list and supports deletion requests across every event. The contractual documents — data processing agreement and subprocessors — are on the site.