GDPR Roles and Data Processing
The controller-to-controller role matrix and limited operations carried out on the Organizer's instructions.
1. Purpose of the schedule and determination of roles
This document describes the working matrix for data within the platform-organizer relationship. The GDPR role is determined separately for each purpose and operation, not through a single label applied to the entire collaboration.
The final controller-to-controller, joint-controller, or processor clauses must be aligned with the actual flows and legally validated.
2. Purposes for which the parties may be independent controllers
- Platform: account, authentication, security, fraud prevention, its own support, commission invoicing, and establishment, exercise, or defense of its rights.
- Organizer: operation of the event, admission rules and checks, its own legal obligations, management of incidents at the venue, and its relationship with attendees.
- PSP: payment processing, its own checks, card-fraud prevention, and compliance with its regulated obligations.
- The platform and organizer inform individuals about their own purposes and respond separately to the requests for which they are responsible.
3. Operations limited to the organizer's instructions
Exporting an attendee list, sending a communication strictly commissioned by the organizer, or performing a technical operation exclusively for the organizer's purpose may fall under Article 28 GDPR. The instruction, purpose, duration, and fields must be documented for these operations.
The possible subject matter includes admission administration and event support; data subjects may include buyers, attendees, and admission staff; data may include identification, contact, order, ticket, and admission-status information. The final list is [TO BE COMPLETED FOR EACH FLOW].
4. Documented instructions and prohibited uses
- The platform processes data on instructions only within the limits of the agreement and authorized roles.
- An instruction that appears unlawful is flagged and may be suspended pending clarification.
- The organizer does not request excessive exports, data concerning other events, or use of lists for marketing without a legal basis.
- Data is not sold, combined, or used for incompatible purposes merely because it is technically accessible.
- Any change of purpose requires assessment and, where applicable, a new notice or agreement.
5. Confidentiality and security
The final technical and organizational measures, testing frequency, and provider standards are [TO BE COMPLETED IN THE SECURITY SCHEDULE].
- Minimum role-based access, strong authentication, and prompt revocation of users.
- Encryption of channels, protection of sensitive data, and payment hosted or tokenized by the PSP.
- Logs for administrative access, exports, refunds, and ticket actions.
- Backups, continuity, tested restoration, patching, and vulnerability management.
- Authorized personnel, confidentiality obligations, and training proportionate to the role.
6. Providers, subprocessors, and transfers
The platform maintains a list of providers that may access data, specifying their service, location, role, and safeguards. For Article 28 operations, a general or specific authorization mechanism and notification of changes are established.
Transfers outside the EEA are permitted only with an applicable legal mechanism and supplementary measures where necessary. The actual list of providers and transfers is [TO BE COMPLETED AFTER PRODUCTION IS CONFIGURED].
7. Data subject requests and cooperation
- The party receiving a request records it and identifies the competent controller.
- For processing on instructions, the platform assists the organizer within the limits of the service and agreed time frames.
- Neither party responds on behalf of the other for its own purposes without coordination.
- The requester's identity is verified proportionately, and the data of other persons is protected.
- Actions, exceptions, and the response are retained in the audit trail.
8. Security incidents
- The party that identifies the incident contains its effects and preserves evidence.
- The other party is notified without undue delay through the contractual emergency channel.
- The notice includes the nature of the incident, systems, data, individuals, likely effects, and known measures.
- The parties determine the controller responsible for assessment and notifications to the authority or individuals.
- Remediation, lessons learned, and preventive controls are documented.
9. Retention, return, and erasure
Data is retained by category in accordance with accounting and tax obligations, chargeback periods, limitation periods, security, and storage limitation. A legal hold suspends erasure of the relevant data.
Upon termination, data processed exclusively on instructions is returned or erased in accordance with the organizer's valid choice, except where retention is required by law. Backups follow the documented overwrite cycle.
10. Evidence, audit, and liability
- Each party maintains the records and evidence for which it is responsible.
- An audit is proportionate and planned and protects security and other customers' data.
- Independent reports or certifications may be used before direct access where they are sufficient.
- Audit costs and frequency, liability, and order of precedence among documents are [TO BE COMPLETED CONTRACTUALLY].
- Acceptance of this page does not replace the signed DPA where Article 28 applies.
11. Marketing separate from event operations
- Platform marketing and organizer marketing have separate choices and evidence.
- The buyer list is not automatically transferred to the organizer for advertising.
- Messages concerning tickets, admission, venue, cancellation, and security are operational.
- Unsubscribing is straightforward and does not block messages necessary to perform the ticket contract.

