The question is usually asked the wrong way round. It is not whether you can get at your list — you can, with practically every provider. It is who else has it.
What "own" means here
Under data protection law a list of people belongs to nobody. The data belongs to the people it is about. What exists is a role: whoever decides what happens to the data is the controller, and whoever processes it on instruction needs a contract saying so (Art. 28 GDPR).
So the practical questions for a host are three, and none of them is "is it mine":
- Can I get at the data, in full and in a usable format?
- Who else holds it, and what may they use it for?
- What happens to it if I leave?
The difference most people miss
A ticketing provider is usually a controller in its own right for its own purposes. It has a relationship with your attendees that is independent of you. This is not hidden — it is in the terms. But it does mean your guests are also its users after the event.
For a one-off concert that does not matter. For a weekly format that sees the same faces over years, it is the difference between having a community and having access to an export.
Three questions you can ask any provider
Whoever you use, including us:
"Am I the controller and you the processor, and is there a signed contract saying so?" If yes, there has to be a data processing agreement. No contract, no processing on instruction — that is how Art. 28 reads.
"What do you do with the data for your own purposes?" The answer is in the privacy policy. If it is hard to find, that is the answer.
"What do I get if I leave?" A CSV of email addresses is not the same thing as the attendance history that shows who was actually there regularly.
Our own answers
Because the same three questions apply to us.
The contract. Our data processing agreement exists in a law-firm-reviewed version and is concluded electronically with each operator contract. Without it, no operator goes live. Until the first contract is concluded, no member or attendance data is processed on any operator's behalf.
Our own purposes. We do not build a profile of your members for ourselves, and we do not sell or share one. What we store and what we do not see is set out in the privacy policy, which is the document that binds us rather than this page.
Leaving. You cannot yet build an export yourself. Today you write to datenschutz@conpeo.eu and we give you your data. That is a gap in the product, not in the right, and saying so here is cheaper than you discovering it later.
One more, if you run formats in Germany
If you and a provider decide something together about the same data, you may be joint controllers under Art. 26, which requires its own arrangement. It is worth asking who thinks they are what, before rather than after.
conpeo
- Regulation (EU) 2016/679 (GDPR), Art. 4(7), Art. 26 and Art. 28.
- conpeo: Privacy policy, conpeo.eu/de/legal/privacy.