Event accreditation: process, background checks and software
How accreditation works at festivals, stadiums and large events: allocations per contractor, data capture by the companies themselves, the reliability check (ZVÜ), passes by zone and day, issue to the wallet. With a checklist for choosing software.
En resumen
- Accreditation is the assignment of a personal access right to everyone who works on site: crew, contractors, press, artist teams, authorities. It defines per person which zones may be entered on which days.
- The process has six steps: allocations per company, data capture by the companies themselves, completeness and duplicate check, reliability check by the authority, pass assignment by rules, issue and control at the gate.
- Accreditation software has to do four things: companies enter their own people, duplicate check before the export to the authority, zones and days per pass from rules instead of by hand, the pass as a wallet pass with one scannable code.
- Art. 6 (1) GDPR
- Art. 13 GDPR
- Art. 28 GDPR
- § 38 MVStättVO
- § 43 MVStättVO

Accreditation at an event is the assignment of a personal access right to everyone who works on site. It defines per person which zones may be entered on which days and holds the data the authority needs for a reliability check (Zuverlässigkeitsüberprüfung, ZVÜ). Unlike a ticket, an accreditation pass is not transferable, and unlike a guest list, accreditation is tied to a work assignment.
Who gets accredited and who does not
| Group | Accreditation | Access | Typical credential |
|---|---|---|---|
| Build, strike, technical crew | yes | production, stage, backstage | crew pass with zones and days |
| Security and stewards | yes, usually with a reliability check | all zones per deployment plan | pass plus the company's own ID |
| Catering and stands | yes | stand area, deliveries | pass, often with a vehicle pass |
| Press and photographers | yes | photo pit, press centre | press pass with time window |
| Artists and their teams | yes | backstage, stage | artist pass, usually via the tour manager |
| Authorities, medical, fire service | yes | all zones | pass, captured through the control room |
| Guests with complimentary tickets | no | public areas | ticket from the guest list |
| Visitors | no | public areas | ticket |
The line is the work assignment. Whoever works is accredited. Whoever is invited is on the guest list. Whoever pays has a ticket. Systems that keep all three in one list lose track at the latest at the reliability check, because the authority only wants to see the people with access to security-relevant zones.
The process in six steps
1. Set allocations per company
The organiser defines which company may register how many people for which zones. The allocation is the first control: a security contractor with 80 slots cannot enter 120 people without someone approving it. Zones and days hang on the allocation, not on the person, so that the later pass assignment can come from rules.
2. Let the companies enter their own people
The most common accreditation mistake is the organiser retyping the contractors' lists. Every company knows its own people, their spellings and their ID numbers. One contact per company gets access to its allocation and enters its people itself, including the data for the reliability check where it is required. The organiser watches the progress per company and chases, instead of typing.
3. Check completeness and duplicates
Before the export to the authority the list has to be complete: date of birth, place of birth, address and ID data must not be missing, otherwise the list comes back. The second point is duplicates. The same person appears with two contractors, or three times in three spellings with one company. Every duplicate is checked twice by the authority, receives two passes and shows up at the gate with two codes. The check has to run before the export, not after.
4. Reliability check by the authority
At large events with a high risk potential the licensing authority requires, in the security concept, a reliability check of the people with access to security-relevant zones. The organiser exports the personal data in the authority's format, the authority checks and reports back per person. The feedback is stored on the person, because it decides whether a pass is issued. Which data the authority needs, who has to supply it and what data protection requires is covered in ZVÜ at the festival.
5. Assign passes by rules
A pass carries zones and days. With 600 people and eight zones, manual assignment is where the errors come from: the security night shift gets no access to the production zone, the photographer stands at the gate on build day without a permission. The assignment has to come from rules: company plus role gives zones and days. Exceptions are entered per person, the rest comes from the rule.
6. Issue and control at the gate
Printed passes are the last step at which changes get lost. A person registered late on the day before has no pass in the print pile. A pass as a wallet pass on the phone solves this: it is issued after approval, can be updated after a change and carries a code the gate scans. The same code can carry catering and a parking permit as additional credentials, instead of three wristbands.
What accreditation software has to do
| Criterion | Why it matters | How to recognise it |
|---|---|---|
| Companies enter their own people | Retyping creates errors and eats the days before the event | One link per company with an allocation, no account for every person |
| Allocation per company and zone | Without a cap, contractors register on spec | Progress per company, approval when exceeded |
| Reliability-check data in the same form | A second capture for the authority doubles the errors | Mandatory fields by zone, export in the authority's format |
| Duplicate check before the export | Double checks and double passes | Flagged across all companies, decision before the export |
| Authority feedback per person | Rejected people must not receive a pass | Status on the person, issue blocked until cleared |
| Zones and days from rules | Manual assignment does not scale past 200 people | Rule from company and role, exception per person |
| Pass as a wallet pass | Print freezes the state of the day before | Apple Wallet and Google Wallet, update after a change |
| One code for access, catering, parking | Three wristbands are three sources of error | Additional credentials on the same pass |
| Deletion after the event | Reliability-check data is particularly sensitive | Deletion period per event, proof of deletion |
| Price per accreditation | A package price punishes small events | Unit price without a base fee |
The first four criteria decide whether the software saves work before the event. The next four decide whether it works during the event. The last two decide whether you still want it next year.
Access management, accreditation, guest list, ticketing
The four terms get mixed up, but they mean different things.
| Term | Who | Credential | What the system has to know |
|---|---|---|---|
| Access management | everyone on site | scan at the gate | which code opens which zone at which time |
| Accreditation | working people | personal pass | company, role, zones, days, reliability-check status |
| Guest list | invited visitors | ticket from an allocation | host, allocation, companions |
| Ticketing | paying visitors | ticket | category, price, entry time |
Access management is the umbrella term: the control at the gate. Accreditation, guest list and ticketing supply the codes the gate scans. Accreditation software therefore does not have to replace ticketing, but its code has to be readable at the same gate as the ticket.
Data protection in accreditation
Accreditation data is personal data; reliability-check data contains date of birth, place of birth and ID number. The legal basis for capturing it is, for your own crew, the employment contract, Art. 6 (1)(b) GDPR; for contractors and press, the legitimate interest in the safety of the event, Art. 6 (1)(f) GDPR; and for the reliability check, the condition imposed by the authority. Three points matter in practice:
- Informing the people concerned. Whoever gives their data to a contractor for accreditation must know under Art. 13 GDPR who receives it and how long it is stored. The notice belongs in the form the company uses to enter its people.
- Processing on behalf. The software that stores the data is a processor under Art. 28 GDPR. A data processing agreement with hosting location and deletion periods is mandatory, not optional.
- Deletion. Reliability-check data has no purpose after the authority's feedback, unless the authority requires retention. Deletion shortly after the event is the normal case.
What the organiser has to prove to the authority follows from the security concept under § 43 of the German model ordinance on places of assembly (MVStättVO) and the operator's duties under § 38 MVStättVO in the respective state version. The accreditation list is part of that evidence.
Where accreditation breaks in practice
- The list arrives the day before. Contractors register late because the form is cumbersome or because they only know their crew shortly beforehand. A link per company with visible progress and a deadline in the system moves the problem from the day before to two weeks earlier.
- Same person, three passes. The stage technician works for the technical company and helps the rigging company with the strike. Both register him. Without a duplicate check he gets two passes and the authority checks him twice.
- The pass is printed, the person rejected. The authority's feedback arrives after the print run. Without a block on the person, the pass sits in the pile and gets handed out.
- The zone is missing. Manual assignment forgets the production zone for the night shift. Security stands at the gate without a permission.
- Catering runs on wristbands. A second system for catering, a third for parking. Three lists, three sources of error, three issue desks.
Each of these is a process error that software with allocations, duplicate check, rules and wallet passes catches before the event. What it does not catch is a company that does not know its own people. That remains a matter of the contract with the contractor.