ZVÜ at festivals: running a reliability check for crew and contractors cleanly
When a reliability check (Zuverlässigkeitsüberprüfung, ZVÜ) is required, what data the authority needs, who has to supply it, and how organizers organize the intake for hundreds of people without the list still being missing the day before.
In short
- The reliability check (Zuverlässigkeitsüberprüfung, ZVÜ) is not a nationwide uniform rule, but a condition imposed by the licensing authority or by the organizer for people in security-relevant areas: backstage, stage, access control, technical crew, security.
- What's usually required is name, date and place of birth, nationality, address, and ID details, a few weeks before the event, as a list per contractor. No clearance, no badge.
- The organizational problem isn't the authority — it's the intake: 30 contractors, 600 people, Excel lists in five formats. The fix is a form the person fills in themselves, with an export in the authority's format.
- Auflagen der Genehmigungsbehörde nach Landesrecht
- § 7 LuftSiG (Flughäfen)
- § 26 DSGVO / § 26 BDSG (Beschäftigtendaten)
- Art. 6 Abs. 1 lit. c DSGVO

The reliability check, usually abbreviated ZVÜ (Zuverlässigkeitsüberprüfung), is a comparison of crew and contractor personal data against police records before these people get access to security-relevant areas of an event. Unlike at an airport, where § 7 LuftSiG mandates it, there's no nationwide legal basis for festivals and stadiums. The obligation arises from the licensing authority's conditions, from the security concept, or from the contract with the organizer. For the organization, that changes nothing: no clearance, no badge, and the list has to be complete weeks in advance.
When a ZVÜ is required
Typical triggers:
- A condition in the permit notice for large-scale events, often above a certain attendance figure or in situations of particular risk.
- A police requirement for areas with access to the stage, backstage, artist area, power supply, or access control.
- The organizer's own requirement for security, technical crew, and anyone with all-area access.
- A requirement from artists or sponsors in their own contracts.
Affected are the organizer's own crew, contractor and subcontractor staff, and volunteers, insofar as they're deployed in the affected areas. Public-area entrance staff are usually not affected; backstage entrance staff are.

What data the authority needs
Requirements differ by state and authority, but the core is the same:
| Data point | Purpose |
|---|---|
| Last name, first name, birth name | Identification |
| Date and place of birth | Matching |
| Nationality | Matching |
| Registered address (Meldeanschrift) | Matching |
| ID type and number | Identity verification at the entrance |
| Company, role, area | Assignment to the access zone |
Some authorities additionally require a signed consent from the person, some an ID copy. Both should be clarified beforehand, because they change how the intake is designed.

Data protection
Processing is permitted if it's necessary to fulfill a legal obligation or the imposed condition. Three rules from practice:
- Purpose limitation. The data is collected for this event's ZVÜ, not for a personnel file. Anyone mixing it with application data needs a second legal basis.
- Deletion deadline. After the event, and once the retention condition ends, the data is deleted. A date built into the process, not a matter of intent.
- Access. ID data for 600 people doesn't belong in an Excel file emailed to thirty contractors and back. Access only for the people handling accreditation.
Why the intake is the actual problem
The authority receives a list and responds. The work before that: the organizer sends a template to thirty contractors, gets back five different formats, places of birth are missing, names are in all caps, one contractor reports ten more people two days before the deadline. Then the list gets merged, sent to the authority, the result comes back as a PDF and has to be transferred onto the badges.
How it works without Excel
- The person fills it in themselves. Everyone, whether own crew or contractor staff, gets a link and enters their data into a form with required fields. No transcription errors, no missing places of birth.
- The contractor sees their own status. How many of their people are complete, who's missing. They report additions instead of being asked.
- The organizer exports. One list in the authority's format, per event, with a status and a date.
- The result drives the badge. Cleared means: the badge gets printed or sent to the wallet. Rejected means: no badge, contractor is informed.
- Deadline with buffer. List complete two weeks before the authority's deadline, so additional reports are still possible.
Anyone who's set this up once repeats it next year with the same forms. The contractors know the link, the authority knows the format.
See also: ZVÜ in the documentation glossary.